|
Plagegeister aller Art und deren Bekämpfung: Nur Firefox kann Internetseiten aufrufen, keine andere AnwendungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
24.08.2014, 17:39 | #1 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Seit heute morgen kann ich nur noch mit Mozilla Firefox normal ins Internet. Normalerweise benutze ich Chrome. Seit heute wird mir bei fast jeder Seite folgende Fehlermeldung angezeigt: Verbindung zum Internet konnte nicht hergestellt werden. Google Chrome kann die Webseite nicht aufrufen, da Ihr Computer nicht mit dem Internet verbunden ist. Bitte überprüfen Sie Ihre Internetverbindung. Überprüfen Sie alle Kabel und starten Sie alle verwendeten Router, Modems und anderen Netzwerkgeräte neu. Erlauben Sie Chrome in Ihren Firewall- und Virenschutzeinstellungen den Zugriff auf das Netzwerk. Falls das Programm schon in der Liste mit erlaubtem Netzwerkzugriff eingetragen ist, entfernen Sie es aus der Liste und fügen Sie es erneut hinzu. Fehlercode: DNS_PROBE_FINISHED_NO_INTERNET Andere Anwendungen, wie z.B. Steam, bekommen keine Verbindung. Ich habe aber festgestellt, dass ein Ping auf "google.com" funktioniert und dass ich zweitens Internetseiten über die IP-Adresse aufrufen kann. Ich habe mein Antivirus einmal einen Komplettscan machen lassen und hab zwar auch einiges gefunden, das Problem wurde aber nicht behoben. (Ich habe den PC anschließend neu gestartet.) Ich benutze 360 Internet Security. Das Log zum Scan poste ich hier: 360 Internet Security Scan log Virus Database version: 2014-08-24 23:06 Date & time: 2014-08-24 11:56:01 Time elapsed: 05:49:50 Type: Full Scan Files scanned: 683564 Threats: 43 Threats cleared: 43 Current scan settings ---------------------- Scanned all files: No Scanned Zip files: No Resolution: User to decide on resolution Scanned disk Boot Sector: Yes Scanned for Rootkit: No Used Cloud Engine: Yes QVM Engine: Yes Automatically repair: Yes AV Engine settings: BitDefender Scan content ---------------------- Overall Whitelist ---------------------- Scan results ====================== Virus scan results ---------------------- C:\Program Files (x86)\Electronic Arts\Die*Sims*Mittelalter\Game\Bin\TSM.exe HEUR/QVM19.1.Malware.Gen Deleted C:\Program Files (x86)\Litecoin\daemon\litecoind.exe HEUR/QVM20.1.Malware.Gen Deleted C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\civ5 +14 trainer.exe Trojan.Generic(HEUR/QVM05.0.Malware.Gen) Deleted C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\civ5DX11 +17 trainer.exe HEUR/QVM05.0.Malware.Gen Deleted C:\Program Files (x86)\Steam\SteamApps\common\Trine\_enchanted_edition_\trine1_32bit.exe HEUR/QVM19.1.Malware.Gen Deleted C:\Program Files (x86)\THQ\Company of Heroes\Baathist_6_Trainer_for_CoH_ToV_2.602.EXE HEUR/QVM06.0.Malware.Gen Deleted C:\Users\Franky\AppData\Local\Temp\11353347\11353347.zipDir\UninstallManager.exe HEUR/Malware.QVM10.Gen Deleted C:\Users\Franky\AppData\Roaming\GameRanger\GameRanger\Data\Plug-Ins\Quake HEUR/QVM27.1.Malware.Gen Deleted C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\hotfix-update\FirefoxInstallLauncher.exe HEUR/QVM20.1.Malware.Gen Deleted C:\Users\Franky\Downloads\Die_Gilde_2_Renaissance_Patch_4.15_downloader.exe HEUR/QVM20.1.Malware.Gen Deleted C:\Users\Franky\Downloads\Gilde_2_Renaissance_Patch_4.15_downloader.exe HEUR/QVM20.1.Malware.Gen Deleted C:\Users\Franky\Downloads\Paint NET - CHIP-Downloader.exe HEUR/QVM06.0.Malware.Gen Deleted C:\Users\Franky\Downloads\Razer Game Booster - CHIP-Downloader.exe HEUR/QVM06.0.Malware.Gen Deleted C:\Users\Franky\Downloads\TERRARIA-KMOD_downloader.exe HEUR/QVM20.1.Malware.Gen Deleted C:\Users\Simon\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GY7J57OE\TeeveeWatchInstaller[1].exe Adware(Adware lurking in the computer ) Deleted C:\Users\Simon\AppData\Local\Temp\mlv_ar_2013625161442_qvo6.exe Trojan.Generic(Win32/Trojan.18f) Deleted C:\Users\Simon\AppData\Local\Temp\LyricsPal_1060-8101_v114.exe Adware(Adware lurking in the computer ) Deleted C:\Users\Simon\AppData\Local\Temp\pricepeep_130001_0101.exe HEUR/QVM06.0.Malware.Gen Deleted C:\Users\Simon\AppData\Roaming\B1Toolbar\hpet.exe HEUR/QVM06.0.Malware.Gen Deleted C:\Users\Simon\AppData\Roaming\eIntaller\E05B08560D8448868E76775AC99C78F6\eGdpSvc.exe Trojan.Generic(HEUR/QVM10.0.Malware.Gen) Deleted C:\Users\Simon\AppData\Roaming\eIntaller\E05B08560D8448868E76775AC99C78F6\eXQ.exe Adware(Adware lurking in the computer ) Deleted C:\Users\Simon\Downloads\Bandicam - CHIP-Downloader.exe HEUR/QVM06.0.Malware.Gen Deleted C:\Users\Simon\Downloads\Player Setup.exe HEUR/QVM06.0.Malware.Gen Deleted C:\Users\Simon\Downloads\Player-Chrome.exe HEUR/QVM10.0.Malware.Gen Deleted C:\Users\Simon\Downloads\SoftonicDownloader_for_terraria(1).exe HEUR/QVM18.1.Malware.Gen Deleted C:\Users\Simon\Downloads\SoftonicDownloader_fuer_minecraft-rezepte.exe HEUR/QVM18.1.Malware.Gen Deleted C:\Users\Simon\Downloads\VideoPerformerSetup(1).exe HEUR/QVM10.0.Malware.Gen Deleted C:\Users\Simon\Downloads\VideoPerformerSetup.exe HEUR/QVM10.0.Malware.Gen Deleted G:\Cheat Happens Trainer\Civilization 5 - Gods and Kings.exe HEUR/QVM05.0.Malware.Gen Deleted G:\Cheat Happens Trainer\Divinity - Dragon Commander.exe HEUR/QVM05.0.Malware.Gen Deleted G:\Dateien\Alte Dateien\GildeGold.exe HEUR/QVM06.0.Malware.Gen Deleted G:\Dateien\Alte Dateien\vom 05.05.2012\FlyForHerov2\FlyForHerov2\Neuz.exe Trojan.Generic(Win32/Trojan.89f) Deleted G:\Dateien\Programme\Installs und Images\HC214Setup.exe HEUR/QVM06.0.Malware.Gen Deleted G:\Dateien\Programme\Virtual Windows 98\Windows 98 II\WIN98\WIN98_21\ddrawex.dll HEUR/QVM21.1.Malware.Gen Deleted G:\Dateien\Programme\Virtual Windows 98\Windows 98 II\WIN98\WIN98_21\cmdial32.dll HEUR/QVM22.1.Malware.Gen Deleted G:\Dateien\Programme\Virtual Windows 98\Windows 98 II\WIN98\WIN98_21\esserver.exe HEUR/QVM02.0.Malware.Gen Deleted G:\Dateien\Programme\Virtual Windows 98\Windows 98 II\WIN98\WIN98_21\internat.exe HEUR/QVM02.0.Malware.Gen Deleted G:\Dateien\Programme\Virtual Windows 98\Windows 98 II\WIN98\WIN98_21\spool32.exe HEUR/QVM02.0.Malware.Gen Deleted G:\Dateien\Spiele\Call of Duty 2\CoD2HooK.exe Trojan.Generic(Win32/Trojan.4df) Deleted G:\SteamLibrary\SteamApps\common\Anno 1404\dvm_Addon.dll Junk(HEUR/QVM40.2.Malware.Gen) Deleted G:\SteamLibrary\SteamApps\common\Game Character Hub\GameCharacterHub.exe HEUR/QVM19.1.Malware.Gen Deleted G:\SteamLibrary\SteamApps\common\Safecracker 2\Safecracker.exe HEUR/QVM19.1.Malware.Gen Deleted G:\SteamLibrary\SteamApps\common\Safecracker 2\testapp.exe HEUR/QVM19.1.Malware.Gen Deleted Anschließend habe ich bis eben nach verschiedenen Tipps zu diesem Problem gesucht, aber nichts passendes gefunden. |
24.08.2014, 17:55 | #2 |
/// the machine /// TB-Ausbilder | Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
25.08.2014, 18:21 | #3 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2014 03 Ran by Franky (administrator) on FRANKY-PC on 25-08-2014 19:15:13 Running from C:\Users\Franky\Desktop Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360rps.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Windows\SysWOW64\ASGT.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (FileZilla Project) C:\xampp\FileZillaFTP\FileZillaServer.exe () C:\xampp\mysql\bin\mysqld.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe (Tobias Süllhöfer Software) C:\Windows\System32\wtmcore.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360sd.exe (hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360rp.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe () C:\Program Files (x86)\puush\puush.exe () C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Dropbox, Inc.) C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor) HKLM\...\Run: [Creative SB Monitoring Utility] => RunDll32 sbavmon.dll,SBAVMonitor HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Creative SB Monitoring Utility Launcher] => RunDll32 SBAVMonL.dll,SBAVMonitorLauncher HKLM\...\Run: [360sd] => C:\Program Files\360\360 Internet Security\360sdrun.exe [287560 2014-04-16] (Qihu 360 Software Co., Ltd.) HKLM-x32\...\Run: [Sound Blaster Recon3D SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe [1103872 2013-09-04] (Creative Technology Ltd) HKLM\...\Winlogon: [Shell] explorer.exe,wtmcore.exe HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [ISUSPM Startup] => c:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7283072 2013-04-26] (Binary Fortress Software) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2013-08-14] () HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [Amazon Music] => C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] () HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableClock] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [RestrictRun] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoNetworkConnections] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoCommonGroups] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\MountPoints2: {a820f432-b047-11e1-b4cb-806e6f6e6963} - D:\Audio\setup.exe HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\MountPoints2: {b1c28ea7-526b-11e2-a85c-001638c03071} - E:\autorun.exe Startup: C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0FB66E927017CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} SearchScopes: HKCU - DefaultScope {8B7A2BC3-75E1-4f5d-AA53-26176AE0EFEF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} SearchScopes: HKCU - {8B7A2BC3-75E1-4f5d-AA53-26176AE0EFEF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {DD1A1D91-E60E-46d0-A1D0-A2823A9C2B12} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms} SearchScopes: HKCU - {EE29A4DD-95C6-456c-A00A-C52454462FEF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files\360\360 Internet Security\safemon\safemon64.dll (Qihu 360 Software Co., Ltd.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog9 02 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 03 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 04 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 05 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 06 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 07 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 08 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 09 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 10 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 11 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9 21 %windir%\system32\wlsppc.dll File Not found () Winsock: Catalog9-x64 01 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 02 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 03 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 04 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 05 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 06 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 07 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 08 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 09 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 10 %windir%\system32\wlsppc.dll [442880] () Winsock: Catalog9-x64 21 %windir%\system32\wlsppc.dll [442880] () Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default FF NewTab: hxxp://www.sweet-page.com/newtab/?type=nt&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 FF Homepage: about:home FF NetworkProxy: "ftp", "proxyus1.stealthy.co" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "http", "proxyus1.stealthy.co" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "proxyus1.stealthy.co" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "proxyus1.stealthy.co" FF NetworkProxy: "ssl_port", 3128 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\sweet-page.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Amazon-Icon - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\amazon-icon@giga.de [2014-07-05] FF Extension: Fast Start - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\faststartff@gmail.com [2014-08-20] FF Extension: savenshare - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\o_08@wwnrgdbya.edu [2013-09-11] FF Extension: SearchNewTab - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\uuy0qpwgmv@t-oeua.org [2013-09-11] FF Extension: ReloadEvery - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-04-16] FF Extension: Adblock Plus - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-07-14] FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\extensions\faststartff@gmail.com Chrome: ======= CHR HomePage: CHR RestoreOnStartup: "" CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Unity Player) - C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (podcast.de) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\bofligbealbmofkgodhlglkefkpegjnb [2013-09-11] CHR Extension: (Adblock Plus) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-09-11] CHR Extension: (Adblock for Youtube™) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-09-11] CHR Extension: (9GAG Mini) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmkmihphgjhmeabggdcokmkjhbnmdml [2013-09-11] CHR Extension: (WeatherBug) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco [2013-09-11] CHR Extension: (Erweiterung \) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2013-09-11] CHR Extension: (Chrome In-App Payments service) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-07] CHR Extension: (360 WebShield Plug-in) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\pppagaglfkmlpgobnlenhknilehpmcbo [2014-08-22] CHR HKLM-x32\...\Chrome\Extension: [pppagaglfkmlpgobnlenhknilehpmcbo] - C:\Program Files\360\360 Internet Security\safemon\360webshield.crx [2014-07-18] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) ATTENTION: => Could not perform signature verification. Cryptographic Service is not running. R2 360rp; C:\Program Files\360\360 Internet Security\360rps.exe [310352 2014-04-16] (Qihu 360 Software Co., Ltd.) S2 Apache2.4; C:\xampp\apache\bin\httpd.exe [22016 2012-08-18] (Apache Software Foundation) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () S3 DAUpdaterSvc; G:\SteamLibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2013-12-10] (BioWare) R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [68136 2009-06-17] () R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1498000 2013-04-26] (Binary Fortress Software) R2 FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [632320 2012-05-11] (FileZilla Project) S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) R2 mysql; C:\xampp\mysql\bin\mysqld.exe [8186368 2012-07-20] () S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3975544 2012-05-09] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-30] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.) S3 scan; C:\Program Files\360\360 Internet Security\scan.dll [423144 2013-02-20] (S.C. BitDefender S.R.L) R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) R2 ZhuDongFangYu; C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe [236360 2014-04-23] (Qihu 360 Software Co., Ltd.) S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [97872 2014-04-21] (Qihu 360 Software Co., Ltd.) R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [67664 2014-04-23] (Qihu 360 Software Co., Ltd.) R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [305744 2014-04-29] (Qihu 360 Software Co., Ltd.) S3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [41552 2014-04-29] (Qihu 360 Software Co., Ltd.) R1 360fsflt; C:\Windows\System32\DRIVERS\360FsFlt.sys [304208 2014-05-07] (Qihu 360 Software Co., Ltd.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2013-02-02] () R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [116480 2013-09-25] (AVM Berlin) R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [180816 2014-04-18] (Qihu 360 Software Co., Ltd.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-31] (DT Soft Ltd) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-02-24] () R3 GWHid; C:\Windows\System32\DRIVERS\GWHid.sys [22648 2010-06-13] (Microsoft Corporation) S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [24088 2009-07-09] (H+H Software GmbH) R3 IOMap; C:\Windows\system32\drivers\IOMap64.sys [24824 2013-02-19] (ASUSTeK Computer Inc.) R3 ksaud; C:\Windows\System32\drivers\ksaud.sys [2033024 2013-08-05] (Creative Technology Ltd.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2013-02-02] () S1 mbmiodrvr; C:\Windows\syswow64\mbmiodrvr.sys [4608 2004-04-10] (cansoft@livewiredev.com) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) S3 PVUSB; C:\Windows\System32\DRIVERS\CESG64.sys [63808 2007-02-19] (CASIO COMPUTER CO.,LTD.) S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () S1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [223256 2011-04-19] (H+H Software GmbH) R3 VL807; C:\Windows\System32\DRIVERS\VL807.sys [36728 2010-06-13] () R3 VL807; C:\Windows\SysWOW64\DRIVERS\VL807.sys [28920 2010-06-13] () R1 vmm; C:\Windows\system32\Treiber\vmm.sys [294232 2012-12-31] (Microsoft Corporation) S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-25 19:15 - 2014-08-25 19:15 - 00033699 _____ () C:\Users\Franky\Desktop\FRST.txt 2014-08-25 19:15 - 2014-08-25 19:15 - 00000000 ____D () C:\FRST 2014-08-25 19:14 - 2014-08-25 19:14 - 02103296 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe 2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-24 00:02 - 2014-08-24 18:00 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger 2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3 2014-08-23 17:07 - 2014-08-23 21:33 - 00000000 ____D () C:\ProgramData\Firefly Studios 2014-08-23 17:05 - 2014-08-23 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2014-08-23 17:05 - 2014-08-23 17:07 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends 2014-08-23 17:04 - 2014-08-23 17:21 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade 2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar 2014-08-16 00:04 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-16 00:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-16 00:04 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-16 00:04 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-16 00:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-16 00:04 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-16 00:03 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-16 00:03 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-13 22:11 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-13 22:11 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-13 22:11 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-13 22:11 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-13 22:11 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-13 22:11 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-13 22:11 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-13 22:11 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-13 22:11 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-13 22:11 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-13 22:11 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-13 22:11 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-13 22:11 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-13 22:11 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-13 22:11 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-13 22:11 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-13 22:11 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-13 22:11 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-13 22:11 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-13 22:11 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-13 22:11 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-13 22:11 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-13 22:11 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-13 22:11 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-13 22:11 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-13 22:11 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-13 22:11 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-13 22:11 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-13 22:11 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-13 22:11 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-13 22:11 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-13 22:11 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-13 22:11 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-13 22:11 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-13 22:11 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-13 22:11 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-13 22:11 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-13 22:11 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-13 22:11 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-13 22:11 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-13 22:11 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-13 22:11 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-13 22:11 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-13 22:11 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-13 22:11 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-13 22:11 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-13 22:11 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-13 22:11 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-13 22:11 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-13 22:11 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-13 22:11 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-13 22:11 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-13 22:11 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-13 22:11 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-13 22:11 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-13 22:11 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-13 22:11 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-13 22:11 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-13 22:11 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-13 22:11 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-13 22:11 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-13 22:11 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-13 22:11 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-13 22:11 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-13 22:11 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-13 22:11 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-13 22:11 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-13 22:11 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-13 22:11 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-13 22:11 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-13 22:09 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-13 22:09 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-13 22:09 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-13 22:09 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp 2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp 2014-08-13 18:00 - 2014-08-06 07:10 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi 2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip 2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet 2014-08-07 19:59 - 2014-08-07 20:06 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe 2014-08-05 22:41 - 2014-08-05 22:42 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 00:36 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-03 00:36 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-03 00:36 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-03 00:36 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-03 00:35 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-03 00:35 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-03 00:35 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-03 00:35 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-03 00:35 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-03 00:35 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment 2014-07-31 22:00 - 2014-08-01 19:36 - 00000000 ____D () C:\Users\Franky\Documents\Shiner 2014-07-28 20:40 - 2014-07-28 20:40 - 00003432 _____ () C:\Users\Franky\Downloads\ManageDragonEncounters.zip 2014-07-27 21:17 - 2014-07-27 21:17 - 00483880 _____ () C:\Users\Franky\Downloads\c5gk-blackfranky-d016d69070e4161.rar 2014-07-26 12:45 - 2014-07-26 12:45 - 04298664 _____ () C:\Users\Franky\Downloads\MechJeb2-2.3.1.0 (2).zip 2014-07-26 12:45 - 2014-07-26 12:45 - 04298664 _____ () C:\Users\Franky\Downloads\MechJeb2-2.3.1.0 (1).zip ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-25 19:15 - 2014-08-25 19:15 - 00033699 _____ () C:\Users\Franky\Desktop\FRST.txt 2014-08-25 19:15 - 2014-08-25 19:15 - 00000000 ____D () C:\FRST 2014-08-25 19:15 - 2012-06-07 04:29 - 02068042 _____ () C:\Windows\WindowsUpdate.log 2014-08-25 19:14 - 2014-08-25 19:14 - 02103296 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe 2014-08-25 19:14 - 2014-07-18 18:55 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\360safe 2014-08-25 19:13 - 2012-06-06 23:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-25 19:10 - 2013-02-24 19:30 - 00000000 ____D () C:\Users\Franky\AppData\Local\TSVNCache 2014-08-25 19:09 - 2012-08-31 17:45 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-25 19:09 - 2009-07-14 06:51 - 00445162 _____ () C:\Windows\setupact.log 2014-08-25 19:08 - 2014-06-09 09:34 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-25 19:08 - 2012-06-06 23:06 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2014-08-25 19:08 - 2010-11-21 05:47 - 00580880 _____ () C:\Windows\PFRO.log 2014-08-25 19:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-24 21:09 - 2012-08-31 17:45 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-24 18:56 - 2013-02-24 14:03 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-24 18:03 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-24 18:03 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-24 18:00 - 2014-08-24 00:02 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger 2014-08-24 17:55 - 2009-07-14 06:45 - 00380848 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-24 17:48 - 2013-04-29 16:50 - 00000000 ____D () C:\Users\Simon\AppData\Roaming\B1Toolbar 2014-08-24 16:49 - 2014-05-27 19:52 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Spotify 2014-08-24 11:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-24 11:09 - 2013-05-20 14:36 - 00000000 ___RD () C:\Users\Franky\Dropbox 2014-08-24 11:05 - 2014-07-20 09:54 - 00000000 __SHD () C:\360Rec 2014-08-24 10:59 - 2013-05-20 14:34 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Dropbox 2014-08-24 01:50 - 2012-06-17 18:37 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Skype 2014-08-24 00:03 - 2012-06-09 00:29 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3 2014-08-23 21:33 - 2014-08-23 17:07 - 00000000 ____D () C:\ProgramData\Firefly Studios 2014-08-23 21:32 - 2012-06-06 23:31 - 00260032 _____ () C:\Windows\DirectX.log 2014-08-23 20:29 - 2014-04-13 18:31 - 00000000 ____D () C:\Users\Franky\AppData\Local\JDownloader v2.0 2014-08-23 17:21 - 2014-08-23 17:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2014-08-23 17:21 - 2014-08-23 17:04 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade 2014-08-23 17:07 - 2014-08-23 17:05 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends 2014-08-22 20:25 - 2012-08-01 02:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft 2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar 2014-08-16 09:54 - 2014-07-08 18:43 - 00000000 ____D () C:\Windows\rescache 2014-08-16 08:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-16 00:23 - 2012-12-18 19:59 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-16 00:19 - 2013-07-15 10:41 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-16 00:11 - 2012-11-20 19:13 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-16 00:03 - 2014-06-15 16:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-15 19:20 - 2014-07-18 18:55 - 00000000 _RSHD () C:\360SANDBOX 2014-08-14 18:23 - 2013-05-20 14:35 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-13 18:33 - 2014-02-15 20:50 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\TEdit 2014-08-13 18:18 - 2013-12-14 10:48 - 00248832 ___SH () C:\Users\Franky\Documents\Thumbs.db 2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp 2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp 2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TEdit 2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\Program Files (x86)\TEdit 2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip 2014-08-12 19:18 - 2013-12-31 13:25 - 00000000 ____D () C:\Users\Franky\AppData\Local\Game Dev Tycoon - Steam 2014-08-09 14:21 - 2012-08-15 11:11 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Audacity 2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet 2014-08-07 20:06 - 2014-08-07 19:59 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe 2014-08-07 04:06 - 2014-08-13 22:09 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-13 22:09 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-06 07:10 - 2014-08-13 18:00 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi 2014-08-05 22:42 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou 2014-08-04 16:53 - 2010-11-21 08:50 - 00701118 _____ () C:\Windows\system32\perfh007.dat 2014-08-04 16:53 - 2010-11-21 08:50 - 00150298 _____ () C:\Windows\system32\perfc007.dat 2014-08-04 16:53 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-04 16:47 - 2014-06-06 07:41 - 00000000 ____D () C:\Users\Franky\Desktop\Hörbucher 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-02 13:23 - 2013-09-24 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-01 19:36 - 2014-07-31 22:00 - 00000000 ____D () C:\Users\Franky\Documents\Shiner 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment 2014-08-01 01:41 - 2014-08-13 22:11 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-01 01:16 - 2014-08-13 22:11 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-28 20:40 - 2014-07-28 20:40 - 00003432 _____ () C:\Users\Franky\Downloads\ManageDragonEncounters.zip 2014-07-27 21:17 - 2014-07-27 21:17 - 00483880 _____ () C:\Users\Franky\Downloads\c5gk-blackfranky-d016d69070e4161.rar 2014-07-26 12:45 - 2014-07-26 12:45 - 04298664 _____ () C:\Users\Franky\Downloads\MechJeb2-2.3.1.0 (2).zip 2014-07-26 12:45 - 2014-07-26 12:45 - 04298664 _____ () C:\Users\Franky\Downloads\MechJeb2-2.3.1.0 (1).zip Files to move or delete: ==================== C:\Users\Franky\jagex_cl_runescape_LIVE.dat C:\Users\Franky\random.dat C:\Users\Simon\Dragonica_DE(1).exe C:\Users\Simon\Dragonica_DE_Phoenix_20120720.exe C:\Users\Simon\jagex_cl_runescape_LIVE.dat C:\Users\Simon\random.dat Some content of TEMP: ==================== C:\Users\Franky\AppData\Local\Temp\amazonicon_v6.exe C:\Users\Franky\AppData\Local\Temp\amazoninstallernircmdc.exe C:\Users\Franky\AppData\Local\Temp\avgnt.exe C:\Users\Franky\AppData\Local\Temp\CH.dll C:\Users\Franky\AppData\Local\Temp\CH2.dll C:\Users\Franky\AppData\Local\Temp\comver.dll C:\Users\Franky\AppData\Local\Temp\Copy.dll C:\Users\Franky\AppData\Local\Temp\drm_dyndata_7370014.dll C:\Users\Franky\AppData\Local\Temp\drm_dyndata_7380014.dll C:\Users\Franky\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgqwrsf.dll C:\Users\Franky\AppData\Local\Temp\ICReinstall_WinSetupFromUSB-1-4_CB-DL-Manager.exe C:\Users\Franky\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Franky\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Franky\AppData\Local\Temp\nvStInst.exe C:\Users\Franky\AppData\Local\Temp\ose00000.exe C:\Users\Franky\AppData\Local\Temp\proxy_vole449297819795212051.dll C:\Users\Franky\AppData\Local\Temp\sdanircmdc.exe C:\Users\Franky\AppData\Local\Temp\sdapskill.exe C:\Users\Franky\AppData\Local\Temp\sdaspwn.exe C:\Users\Franky\AppData\Local\Temp\SHSetup.exe C:\Users\Franky\AppData\Local\Temp\sweetpage294wld_n2.exe C:\Users\Franky\AppData\Local\Temp\ubiDC05.tmp.exe C:\Users\Franky\AppData\Local\Temp\Uninstall.exe C:\Users\Franky\AppData\Local\Temp\vlc-2.1.3-win32.exe C:\Users\Franky\AppData\Local\Temp\_is744.exe C:\Users\Franky\AppData\Local\Temp\_is7DB7.exe C:\Users\Simon\AppData\Local\Temp\avgnt.exe C:\Users\Simon\AppData\Local\Temp\banner.exe C:\Users\Simon\AppData\Local\Temp\BetterInstaller.exe C:\Users\Simon\AppData\Local\Temp\bundlesweetimsetup.exe C:\Users\Simon\AppData\Local\Temp\DeltaTB.exe C:\Users\Simon\AppData\Local\Temp\drm_dyndata_7370007.dll C:\Users\Simon\AppData\Local\Temp\drm_dyndata_7370010.dll C:\Users\Simon\AppData\Local\Temp\EmptySetup.exe C:\Users\Simon\AppData\Local\Temp\GenericUninstall.exe C:\Users\Simon\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih.exe C:\Users\Simon\AppData\Local\Temp\install_flashplayer12x32ax_gtba_chra_dy_aaa_aih.exe C:\Users\Simon\AppData\Local\Temp\install_flashplayer12x32ax_gtba_chra_dy_aaa_aih_1.exe C:\Users\Simon\AppData\Local\Temp\LEGOLOTR.exe C:\Users\Simon\AppData\Local\Temp\mconduitinstaller.exe C:\Users\Simon\AppData\Local\Temp\mgsqlite3.dll C:\Users\Simon\AppData\Local\Temp\mism.exe C:\Users\Simon\AppData\Local\Temp\Softonic_DE_1-5-1.exe C:\Users\Simon\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll C:\Users\Simon\AppData\Local\Temp\SweetIESetup.exe C:\Users\Simon\AppData\Local\Temp\swt-win32-3349.dll C:\Users\Simon\AppData\Local\Temp\uninstaller.exe C:\Users\Simon\AppData\Local\Temp\WSSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-08-17 09:04 ==================== End Of Log ============================ --- --- --- |
25.08.2014, 18:21 | #4 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung FRST Additional Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-08-2014 03 Ran by Franky at 2014-08-25 19:16:28 Running from C:\Users\Franky\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: 360 Internet Security (Enabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D} AS: 360 Internet Security (Enabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) @BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.11 - GIGABYTE) µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.32126 - BitTorrent Inc.) 360 Internet Security (HKLM-x32\...\360 Internet Security) (Version: 4.9.0.4900 - Qihu 360 Software Co., Ltd.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Ace of Spades (HKLM-x32\...\Steam App 224540) (Version: - Jagex Limited) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.8 - Adobe Systems Incorporated) Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios) Amazon Music (HKCU\...\Amazon Amazon Music) (Version: 3.2.0.591 - Amazon Services LLC) Angry Birds Star Wars II (HKLM-x32\...\{C4887610-6DE9-4538-A6CD-2B44673FE133}) (Version: 1.0.1 - Rovio Entertainment Ltd.) Anno 1404 (HKLM-x32\...\Steam App 33250) (Version: - Blue Byte) Anno 1404: Venice (HKLM-x32\...\Steam App 33350) (Version: - Blue Byte) Any Video Converter 5.6.3 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com) Apple Application Support (HKLM-x32\...\{CCE825DB-347A-4004-A186-5F4A6FDD8547}) (Version: 2.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}) (Version: 6.0.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASCII Art - Machine 1.2 (HKLM-x32\...\ASCII Art - Machine_is1) (Version: - ) Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft) Assassin's Creed(R) III v1.06 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.06 - Ubisoft) ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.4.2.4 - ASUSTek COMPUTER INC.) ASUS GPU Tweak (x32 Version: 2.4.2.4 - ASUSTek COMPUTER INC.) Hidden ASUS Product Register Program (HKLM-x32\...\{9D29D67C-315D-46A1-A3A9-3CAF24871578}) (Version: 1.0.022 - ASUSTek Computer Inc.) Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version: - Audacity Team) AudibleManager (HKLM-x32\...\AudibleManager) (Version: 1999912174.48.56.33885418 - Audible, Inc.) Audiobook Cutter Free Edition (HKLM-x32\...\{0C1D2DFD-9325-47C5-BC63-EBE68DEF7AFB}) (Version: 1.8.6 - Audiobook Software) Aufstieg des Hexenkönigs™ (HKLM-x32\...\{B931FB80-537A-4600-00AD-AC5DEDB6C25B}) (Version: - ) AutoGreen B10.1021.1 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) AutoGreen B10.1021.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden AutoHotkey 1.1.10.01 (HKLM\...\AutoHotkey) (Version: 1.1.10.01 - Lexikos) Battle for Wesnoth 1.10.4 (HKLM-x32\...\Battle for Wesnoth 1.10.4) (Version: 1.10.4 - ) BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version: - Irrational Games) Bitcoin (HKCU\...\Bitcoin) (Version: 0.8.6 - Bitcoin project) Black & White® 2 (HKLM-x32\...\{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}) (Version: 1.00.0000 - Lionhead Studios) Blade Symphony (HKLM-x32\...\Steam App 225600) (Version: - Puny Human Games) Blood Bowl: Legendary Edition (HKLM-x32\...\Steam App 58520) (Version: - Cyanide Studios) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Brick-Force (HKLM-x32\...\Brick-Force) (Version: - Infernum Productions AG) Bridge Project (HKLM-x32\...\Steam App 232950) (Version: - Halycon Media GmbH & Co. KG) Brütal Legend (HKLM-x32\...\Steam App 225260) (Version: - Double Fine Productions) CamStudio version 2.7 (HKLM-x32\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7 - CamStudio Open Source) Canon CanoScan Toolbox 4.1 (HKLM-x32\...\{BCE46757-7674-4416-BEDB-68205A60409E}) (Version: - ) CanoScan Toolbox Ver4.9 (HKLM-x32\...\{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}) (Version: - ) CASIO FA-124 (HKLM-x32\...\{FB47E710-6249-4EFA-BE36-E922B0612AF4}) (Version: 2.00.0001 - CASIO COMPUTER CO., LTD.) Castle Story (HKLM-x32\...\Steam App 227860) (Version: - Sauropod Studio) Catan - Die erste Insel (HKLM-x32\...\Catan) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version: - Cheat Engine) Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version: - Torn Banner Studios) Cities XL Platinum (HKLM-x32\...\Steam App 231140) (Version: - Focus Home Interactive) Clonk Endeavour 4.95.5 (HKLM-x32\...\Clonk Endeavour) (Version: 4.95.5 - RedWolf Design GmbH) Clonk Rage (HKLM-x32\...\Clonk Rage) (Version: - RedWolf Design GmbH) Combined Community Codec Pack 2013-04-20 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2013.04.20.0 - CCCP Project) Command and Conquer: Red Alert 3 - Uprising (HKLM-x32\...\Steam App 24800) (Version: - EA Los Angeles) Company of Heroes - FAKEMSI (x32 Version: 2.0.0.0 - THQ Inc.) Hidden Company of Heroes (HKLM-x32\...\Company of Heroes) (Version: 2.602.0 - THQ Inc.) Company of Heroes (HKLM-x32\...\Steam App 4560) (Version: - Relic Entertainment) Confrontation (HKLM-x32\...\Steam App 204560) (Version: - Cyanide Studios) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) Crazy Machines II (HKLM-x32\...\{112B0ED9-57F8-4883-8E6A-5BEAABDABBC1}) (Version: 1.00 - FAKT Software GmbH) Crazy Machines II Erweiterung "Zurück in die Werkstatt" (HKLM-x32\...\{763BFBA5-F598-4A2A-8A2A-FE93CBCC22BF}) (Version: 1.02 - FAKT Software GmbH) Creative Systeminformationen (HKLM-x32\...\SysInfo) (Version: 1.10 - Creative Technology Limited) 'Cultures Saga' (HKLM-x32\...\'Cultures Saga') (Version: - ) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0327 - DT Soft Ltd) Darwinia (HKLM-x32\...\Steam App 1500) (Version: - Introversion Software) Data Lifeguard Diagnostic for Windows 1.24 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version: - Western Digital Corporation) dBpoweramp DirectShow Decoder (HKLM-x32\...\dBpoweramp DirectShow Decoder) (Version: Release 2 - Illustrate) dBpoweramp Music Converter (HKLM-x32\...\dBpoweramp Music Converter) (Version: Release 14.3 - Illustrate) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{132D27B8-C656-44BD-8C16-73C54EA8A85F}) (Version: - Microsoft) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{132D27B8-C656-44BD-8C16-73C54EA8A85F}) (Version: - Microsoft) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{132D27B8-C656-44BD-8C16-73C54EA8A85F}) (Version: - Microsoft) DES 2.0 (HKLM-x32\...\{675F86A8-E093-4002-87D5-915CC2C45571}) (Version: 1.00.0000 - Gigabyte) Desura (HKLM-x32\...\Desura) (Version: 100.53 - Desura) Desura: Project Zomboid (HKLM-x32\...\Desura_62350040236064) (Version: Alpha - The Indie Stone) Dia (nur entfernen) (HKLM-x32\...\Dia) (Version: - ) Die Gilde Gold-Edition (HKLM-x32\...\Die Gilde Gold-Edition) (Version: 2.06 - JoWooD Productions Software AG) Die Schlacht um Mittelerde™ II (HKLM-x32\...\{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}) (Version: - ) DIE SIEDLER - Aufstieg eines Königreichs (HKLM-x32\...\{D3F80A98-05AB-4D8C-9272-766CCFA6A48D}) (Version: 1.00.0000 - Ubisoft) Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - ) Die Sims Mittelalter Piraten und Edelleute (HKLM-x32\...\{0CC21836-A5D6-4641-B4AE-6FA01D021E41}) (Version: 2.0.109 - Electronic Arts) Die*Sims*Mittelalter (HKLM-x32\...\{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}) (Version: 2.0.113 - Electronic Arts) DiRT 3 (HKLM-x32\...\Steam App 44320) (Version: - Codemasters Racing Studio) DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version: - Codemasters Racing Studio) DisplayFusion 5.0.1 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 5.0.1.0 - Binary Fortress Software) Divinity: Dragon Commander (HKLM-x32\...\Steam App 243950) (Version: - Larian Studios) DJ Java Decompiler v.3.12.12.96 (HKLM-x32\...\{0DB51EBE-ECD4-4308-A55C-3DFDC4E83814}) (Version: 1.8 - Atanas Neshkov 2009) Dogecoin (HKCU\...\Dogecoin) (Version: 1.5.2.0 - Dogecoin) Don't Starve (HKLM-x32\...\Steam App 219740) (Version: - Klei Entertainment) Dragon Age: Origins - Ultimate Edition (HKLM-x32\...\Steam App 47810) (Version: - BioWare) Driver Fusion (HKLM-x32\...\Driver Fusion) (Version: 2.0 - Treexy) Dropbox (HKCU\...\Dropbox) (Version: 2.10.27 - Dropbox, Inc.) DYNASTY WARRIORS 8: Xtreme Legends Complete Edition (HKLM-x32\...\Steam App 278080) (Version: - KOEI TECMO GAMES CO., LTD.) Easy Tune 6 B11.0309.1 (HKLM-x32\...\InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE) Easy Tune 6 B11.0309.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden EAX(tm) Unified (SHELL) (HKLM-x32\...\EAX(tm) Unified (SHELL)) (Version: - ) Elven Legacy (HKLM-x32\...\{40B8C652-42EE-479b-94FC-AEDE7F600D1A}_is1) (Version: 1.0.9.0 - Paradox Interactive) Epson Easy Photo Print 2 (HKLM-x32\...\{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION) EPSON S22 Series Handbuch (HKLM-x32\...\EPSON S22 Series Manual) (Version: - ) EPSON S22 Series Printer Uninstall (HKLM\...\EPSON S22 Series) (Version: - SEIKO EPSON Corporation) Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.98 - Etron Technology) Etron USB3.0 Host Controller (x32 Version: 0.98 - Etron Technology) Hidden EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) Explorer Suite III (HKLM\...\Explorer Suite_is1) (Version: - ) Exxter Gamepad (HKLM-x32\...\FTQ591) (Version: - ) Fable III (x32 Version: 1.0.0001.131 - Microsoft Game Studios) Hidden Factorio version 0.9.8 (HKLM\...\Factorio_is1) (Version: - ) Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft) FileZilla Client 3.6.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.6.0.2 - FileZilla Project) FINAL FANTASY VIII (HKLM-x32\...\Steam App 39150) (Version: - SQUARE ENIX) Fish Tycoon (remove only) (HKCU\...\Fish Tycoon) (Version: - ) Free 3GP Video Converter version 5.0.43.605 (HKLM-x32\...\Free 3GP Video Converter_is1) (Version: 5.0.43.605 - DVDVideoSoft Ltd.) Free Video Dub version 2.0.16.1212 (HKLM-x32\...\Free Video Dub_is1) (Version: 2.0.16.1212 - DVDVideoSoft Ltd.) FRITZ!Box USB-Fernanschluss (HKCU\...\2db37667170956ee) (Version: 2.3.1.0 - AVM Berlin) Future Pinball (HKLM-x32\...\Future Pinball_is1) (Version: Version 1.9.1.20101231 - Chris Leathley) Galactic Civilizations II: Ultimate Edition (HKLM-x32\...\Steam App 202200) (Version: - Stardock Entertainment) Game Character Hub (HKLM-x32\...\Steam App 292230) (Version: - Sebastien Bini) Game Dev Tycoon (HKLM-x32\...\Steam App 239820) (Version: - Greenheart Games) Game of Thrones (HKLM-x32\...\Steam App 208730) (Version: - Cyanide Studios) Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Team Garry) GetFoldersize 2.5.24 (HKLM-x32\...\GetFoldersize_is1) (Version: 2.5.24 - Michael Thummerer Software Design) GIMP 2.8.0 (HKLM\...\GIMP-2_is1) (Version: 2.8.0 - The GIMP Team) GlassFish Server Open Source Edition 3.1.2 (HKLM-x32\...\nbi-glassfish-mod-3.1.2.23.0) (Version: - ) Gnomoria (HKLM-x32\...\Steam App 224500) (Version: - Robotronic Games) Godus (HKLM-x32\...\Steam App 232810) (Version: - ) GoldWave v5.67 (HKLM-x32\...\GoldWave v5.67) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Gothic 3 (HKLM-x32\...\{17BADF87-3597-46FE-8D74-69C4FA78883E}) (Version: 1.0.0 - JoWood) Grand Theft Auto IV (HKLM-x32\...\Steam App 12210) (Version: - Rockstar North) Guilty Gear Isuka (HKLM-x32\...\Steam App 267900) (Version: - Arc System Works Co., Ltd.) Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve) Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve) Half-Life 2: Lost Coast (HKLM-x32\...\Steam App 340) (Version: - Valve) Hammerwatch (HKLM-x32\...\Steam App 239070) (Version: - ) HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software) HeidiSQL 7.0.0.4053 (HKLM-x32\...\HeidiSQL_is1) (Version: 7.0 - Ansgar Becker) Hero Fighter (HKLM-x32\...\Hero Fighter) (Version: - ) Hex-Editor MX (HKLM-x32\...\{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1) (Version: 6.0 - NEXT-Soft) Hexodius (HKLM-x32\...\Steam App 236490) (Version: - Brain Slap Studio) HiCDEject (HKLM-x32\...\HiCDEject) (Version: - ) Hippsoft hsWebCam 1.09.0002 (HKLM-x32\...\Hippsoft hsWebCam_is1) (Version: 1.09.0002 - Hippsoft) IL-2 Sturmovik: 1946 (HKLM-x32\...\Steam App 15320) (Version: - 1C: Maddox Games) IncrediMail (x32 Version: 6.6.0.5288 - IncrediMail) Hidden IncrediMail 2.5 (HKLM-x32\...\IncrediMail) (Version: 6.6.0.5288 - IncrediMail Ltd.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.35 - Irfan Skiljan) -Isamu- (HKLM-x32\...\{1512C6E7-CEBF-479D-9532-A36B27A1BE05}) (Version: 1.0.0 - Shoryuken Productions) iTunes (HKLM\...\{0E5D76AD-A3FB-48D5-8400-8903B10317D3}) (Version: 11.0.1.12 - Apple Inc.) Jade Empire: Special Edition (HKLM-x32\...\Steam App 7110) (Version: - BioWare Corporation) Java 7 Update 17 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017F0}) (Version: 7.0.170 - Oracle) Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java SE Development Kit 7 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170450}) (Version: 1.7.0.450 - Oracle) Java SE Development Kit 7 Update 5 (HKLM-x32\...\{32A3A4F4-B792-11D6-A78A-00B0D0170050}) (Version: 1.7.0.50 - Oracle) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) JavaFX 2.1.1 SDK (HKLM-x32\...\{2222706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH) Juice 2.2 (HKLM-x32\...\Juice) (Version: 2.2 - Juice Team) Just Cause 2 (HKLM-x32\...\Steam App 8190) (Version: - Avalanche) Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version: - Squad) Knights of Pen and Paper +1 (HKLM-x32\...\Steam App 231740) (Version: - Behold Studios) LEGO® Der Herr der Ringe™ (HKLM-x32\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment) Lernout & Hauspie TruVoice American English TTS Engine (HKLM-x32\...\tv_enua) (Version: - ) LinuxLive USB Creator (HKLM-x32\...\LinuxLive USB Creator) (Version: 2.8 - Thibaut Lauziere) Litecoin (HKCU\...\Litecoin) (Version: 0.8.6.2 - Litecoin project) Little Fighter 2 version 2.0a (HKLM-x32\...\Little Fighter 2) (Version: version 2.0a - ) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.109 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.109 - LogMeIn, Inc.) Hidden MacroX 3.1 (HKLM-x32\...\MacroX) (Version: 3.1 - Uhrzeit.org) Magicka (HKLM-x32\...\Steam App 42910) (Version: - Arrowhead Game Studios) Magicka: Wizard Wars (HKLM-x32\...\Steam App 202090) (Version: - Paradox North) ManiaPlanet (HKLM-x32\...\ManiaPlanet_is1) (Version: - Nadeo) Mark of the Ninja (HKLM-x32\...\Steam App 214560) (Version: - ) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Project MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Project Professional 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Visio 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Visio MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Project Professional 2010 (HKLM-x32\...\Office14.PRJPROR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Virtual PC 2007 (HKLM\...\{8A7CAA24-7B23-410B-A7C3-F994B0944160}) (Version: 6.0.156.0 - Microsoft Corporation) Microsoft Visio Professional 2010 (HKLM-x32\...\Office14.VISIOR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Mod Updater for NRaas mods (HKLM-x32\...\{E0112108-E4CA-4361-80F3-D337797F4F6A}) (Version: 1.10.3 - Tucknology) Mono for Windows 3.2.3 (HKLM-x32\...\{afbbbda2-1dd7-11e3-ae37-080027022fbf}_is1) (Version: 3.2.3 - Mono) Monster Loves You! (HKLM-x32\...\Steam App 226740) (Version: - Radial Games Corp) Motherboard Monitor 5 (HKLM-x32\...\Motherboard Monitor 5_is1) (Version: 5 - Alexander van Kaam) Mount & Blade (HKLM-x32\...\Steam App 22100) (Version: - Paradox Interactive) Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version: - Tale Worlds) Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML4 Parser (HKLM-x32\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios) NetBeans IDE 7.1.2 (HKLM-x32\...\nbi-nb-base-7.1.2.0.0) (Version: 7.1.2 - NetBeans.org) Network Stumbler 0.4.0 (remove only) (HKLM-x32\...\Network Stumbler) (Version: - ) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.34.0 - Black Tree Gaming) nLite 1.4.9.3 (HKLM-x32\...\nLite_is1) (Version: 1.4.9.3 - Dino Nuhagic (nuhi)) Nokia Connectivity Cable Driver (HKLM-x32\...\{0906982B-A432-4C06-8F01-C01BE1143779}) (Version: 7.1.92.0 - Nokia) Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.6.36.0 - Nokia) Nokia Suite (x32 Version: 3.6.36.0 - Nokia) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.3.2 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 2.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.22 (Version: 1.2.22 - NVIDIA Corporation) Hidden ON_OFF Charge B11.0110.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Orcs Must Die! 2 (HKLM-x32\...\Steam App 201790) (Version: - Robot Entertainment) Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC) Panzar (HKLM-x32\...\Steam App 240320) (Version: - Troxit Service) PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) PC Connectivity Solution (HKLM-x32\...\{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}) (Version: 12.0.48.0 - Nokia) Peggle Deluxe 1.03 (HKLM-x32\...\Peggle Deluxe 1.03) (Version: - ) Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.) Photo Notifier and Animation Creator (x32 Version: 1.0.0.1009 - Ihr Firmenname) Hidden Pixel Piracy (HKLM-x32\...\Steam App 264140) (Version: - Vitali Kirpu) Planet Explorers (HKLM-x32\...\Steam App 237870) (Version: - Pathea Games) Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version: - Uber Entertainment) Pokémon Play It! v2 (HKLM-x32\...\Pokémon Play It! v2) (Version: - D-Man) Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Prison Architect (HKLM-x32\...\Steam App 233450) (Version: - Introversion Software) PROTOTYPE 2 (HKLM-x32\...\Steam App 115320) (Version: - Radical Entertainment) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: 1.0.0.0 - Dean Herbert) RAMRush 1.0.6.917 (HKLM-x32\...\RAMRush_is1) (Version: - FTweak, Inc.) Rapture3D 2.4.8 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) Razer Game Booster (HKLM-x32\...\Razer Game Booster_is1) (Version: 4.2.42.0 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6307 - Realtek Semiconductor Corp.) Renegade X (HKLM-x32\...\UDK-4fc3a6b6-3d0e-4dce-b127-8e60191e2b1e) (Version: Open Beta 1 - Totem Arts) Reus (HKLM-x32\...\Steam App 222730) (Version: - Abbey Games) Rise Of Legends (HKLM-x32\...\InstallShield_{CADDE354-C78C-46CB-A006-E2B178EFC271}) (Version: 1.00.0000 - Microsoft Game Studios) Rise Of Legends (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden Rise of Nations (HKLM-x32\...\RiseOfNationsExpansion 1.0) (Version: 1.0 - Microsoft) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.0.9.5 - Rockstar Games) Rogue Legacy (HKLM-x32\...\Steam App 241600) (Version: - Cellar Door Games) RPG MAKER VX Ace (HKLM-x32\...\RPGVXAce_E_is1) (Version: 1.01a - Enterbrain) RPG Maker VX Ace (HKLM-x32\...\Steam App 220700) (Version: - Enterbrain) RPG MAKER VX Ace RTP (HKLM-x32\...\RPGVXAce_RTP_is1) (Version: 1.00 - Enterbrain) RuneScape Launcher 1.2.3 (HKLM-x32\...\{FAE99C85-0732-4C58-9C6B-10B5B12FA2E9}) (Version: 1.2.3 - Jagex Ltd) Safecracker: The Ultimate Puzzle Adventure (HKLM-x32\...\Steam App 3260) (Version: - Kheops Studio) Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition) Scribblenauts Unlimited (HKLM-x32\...\Steam App 218680) (Version: - 5th Cell Media) Secure Download Manager (HKLM-x32\...\{C58626D6-7EBD-460D-8B6C-75B3C3464879}) (Version: 3.1.60 - Kivuto Solutions Inc.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{359ADBEC-068A-4CC9-9174-77AB8EDB867A}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden SES Driver (HKLM\...\{D8CC254C-C671-4664-9A38-FA368D1E2C97}) (Version: 1.0.0 - Western Digital) SHIELD Streaming (Version: 1.8.323 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sigil 0.7.4 (HKLM-x32\...\Sigil_is1) (Version: - John Schember) Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) SlimDX Runtime .NET 4.0 x86 (January 2012) (HKLM-x32\...\{7EBD0E43-6AC0-4CA8-9990-00E50069AD29}) (Version: 2.0.13.43 - SlimDX Group) Smart 6 B10.1221.1 (HKLM-x32\...\{3B35725F-C623-4A1E-B5CC-99C0868679E3}) (Version: 1.00.0000 - GIGABYTE) SmartTools Publishing • Excel DateiLister (HKLM-x32\...\SmartToolsDateiListerv5.00) (Version: v5.00 - SmartTools Publishing) Sound Blaster Recon3D (HKLM-x32\...\{62F7CCBA-7F8C-4A91-9EA7-6E66941A686B}) (Version: 1.01.04 - Creative Technology Limited) Space Engineers (HKLM-x32\...\Steam App 244850) (Version: - ) Spelunky (HKLM-x32\...\Steam App 239350) (Version: - ) Spore (HKLM-x32\...\Steam App 17390) (Version: - Maxis™) Spore: Creepy & Cute Parts Pack (HKLM-x32\...\Steam App 17440) (Version: - Maxis™) Spore: Galactic Adventures (HKLM-x32\...\Steam App 24720) (Version: - EA - Maxis) Spotify (HKCU\...\Spotify) (Version: 0.9.10.22.gf87988f9 - Spotify AB) Star Wars Empire at War (HKLM-x32\...\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}) (Version: 1.0 - LucasArts) Star Wars(tm) Knights of the Old Republic(tm) II: The Sith Lords(tm) (HKLM-x32\...\{629F65FB-7F3C-4D66-A1C0-20722744B7B6}) (Version: 1.00.0000 - Obsidian) Starbound (HKLM-x32\...\Steam App 211820) (Version: - ) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Strike Suit Zero (HKLM-x32\...\Steam App 209540) (Version: - Born Ready Games Ltd.) Stronghold 3 (HKLM-x32\...\Steam App 47400) (Version: - FireFly Studios) Stronghold Crusader Extreme (HKLM-x32\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: 1.20.0000 - Firefly Studios) Stronghold Crusader Extreme HD (HKLM-x32\...\Steam App 16700) (Version: - Firefly Studios) Stronghold Crusader HD (HKLM-x32\...\Steam App 40970) (Version: - FireFly Studios) Stronghold Legends (HKLM-x32\...\Steam App 40980) (Version: - FireFly Studios) SUPER © v2012.build.52 (July 7, 2012) Version v2012.build.52 (HKLM-x32\...\{8F311E2E-C275-4CF0-8154-B63991832668}_is1) (Version: v2012.build.52 - eRightSoft) Superfrog HD (HKLM-x32\...\Steam App 234000) (Version: - Team17 Digital Ltd) SWF Opener (HKLM-x32\...\{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1) (Version: 1.3 - UnH Solutions) Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve) TeamSpeak 2 RC2 (HKLM-x32\...\Teamspeak 2 RC2_is1) (Version: 2.0.32.60 - Dominating Bytes Design) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29480 - TeamViewer) TEdit 3 (HKLM-x32\...\{37D643E8-8ACB-468A-B020-26C9D6CA52E3}) (Version: 3.5.14218.23 - BinaryConstruct) TEdit 3 (HKLM-x32\...\{B81207ED-C990-4AB1-B5D5-A191EA253C0D}) (Version: 3.5.14064.0 - BinaryConstruct) TEdit 3 (HKLM-x32\...\{F015942F-C1BD-4297-A8A4-C0B8D42B39C5}) (Version: 3.4.13358.0 - BinaryConstruct) Terrafirma (HKLM-x32\...\{9EA1E037-86B8-496B-9C8C-31B3E3017C53}) (Version: 2.2.2.0 - Sean Kasun) TerraMap (HKLM-x32\...\{CB86D44E-8906-4AFA-ACE8-C1C0D0B21FED}) (Version: 1.0.2.30729 - Jason Coon) Terraria (HKLM-x32\...\Steam App 105600) (Version: - Re-Logic) The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version: - Edmund McMillen and Florian Himsl) The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00) (Version: - ) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Guild II: Renaissance (HKLM-x32\...\Steam App 39680) (Version: - Rune Forge) The Sims 3 Ultimate Collection Version 1.67.2 (HKLM-x32\...\The Sims 3 Ultimate Collection_is1) (Version: 1.67.2 - EA Games) TL-WN951N Driver (HKLM-x32\...\{CCE177D2-8FE3-494A-82C9-958CC79E73AD}) (Version: 1.0.0 - TP-LINK) To the Moon (HKLM-x32\...\Steam App 206440) (Version: - Freebird Games) TortoiseSVN 1.7.11.23600 (64 bit) (HKLM\...\{6B13A3F1-F66A-42FB-9E62-98952D582187}) (Version: 1.7.23600 - TortoiseSVN) Toy Soldiers (HKLM-x32\...\Steam App 98300) (Version: - Signal Studios) TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.0.0 - TP-LINK) Trine (HKLM-x32\...\Steam App 35700) (Version: - Frozenbyte) TSLRCM 1.8.1 (HKLM-x32\...\The Sith Lords Restored Content Mod_is1) (Version: - ) Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version: - Tunngle.net GmbH) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Universe Sandbox (HKLM-x32\...\Steam App 72200) (Version: - ) Unlocker 1.9.1-x64 (HKLM\...\Unlocker) (Version: 1.9.1 - Cedrick Collomb) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PRJPROR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PRJPROR_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.VISIOR_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PRJPROR_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIOR_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-0054-0407-0000-0000000FF1CE}_Office14.VISIOR_{43C22E89-E170-4764-8E7E-7386E34F94E0}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 4.5 - Ubisoft) Virtual Audio Cable 4.9 (HKLM\...\Virtual Audio Cable 4.9) (Version: - ) VLC media player 2.0.8 (HKLM\...\VLC media player) (Version: 2.0.8 - VideoLAN) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Warframe (HKLM-x32\...\Steam App 230410) (Version: - ) Watch Dogs Digital Deluxe Edition Multi2 1.0 (HKLM-x32\...\Watch Dogs Digital Deluxe Edition Multi2 1.0) (Version: - ) Watch Dogs Digital Deluxe Edition Update 2 MULTi2 1.03.471 (HKLM-x32\...\Watch Dogs Digital Deluxe Edition Update 2 MULTi2 1.03.471) (Version: - ) Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) Webocton - Scriptly 0.8.95.6 (HKLM-x32\...\Webocton - Scriptly_is1) (Version: 0.8.95.6 - Webocton) WIDCOMM Bluetooth Software 6.0.1.5100 (HKLM\...\{03D1988F-469F-4843-8E6E-E5FE9D17889D}) (Version: 6.0.1.5100 - Broadcom Corporation) Widelands (HKLM-x32\...\{WIDELANDS-WIN32-IS}_is1) (Version: Widelands - Widelands Development Team) Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (01/19/2011 1.0.0009.0) (HKLM\...\4CA7CFBB29889F25ACB3DF6E3A42BAE29EB43B20) (Version: 01/19/2011 1.0.0009.0 - Western Digital Technologies) Windows Installer XML Toolset 3.5 (HKLM-x32\...\{CB509245-1245-4867-8BD4-6B2C5A734504}) (Version: 3.5.2519.0 - Microsoft Corporation) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version: - ) Windows Media Encoder 9 Series (x32 Version: 9.00.2980 - Microsoft Corporation) Hidden Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 4.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) Wireshark 1.10.2 (64-bit) (HKLM-x32\...\Wireshark) (Version: 1.10.2 - The Wireshark developer community, hxxp://www.wireshark.org) Worms Blast (HKLM-x32\...\{8874FD36-7C9D-4573-8956-E368D6753D90}) (Version: - ) Worms Clan Wars (HKLM-x32\...\Steam App 233840) (Version: - Team17 Digital Ltd) Worms Pinball (HKLM-x32\...\Steam App 70660) (Version: - Team17 Software Ltd.) Worms Revolution (HKLM-x32\...\Steam App 200170) (Version: - Team17 Digital Ltd.) Worms Ultimate Mayhem (HKLM-x32\...\Steam App 70600) (Version: - Team17 Software Ltd.) Worms World Party (HKLM-x32\...\{9A200E68-D5F4-4E70-910F-2871753A0E2B}) (Version: - ) XAMPP 1.8.1 (HKLM-x32\...\xampp) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2521981952-1457118651-2954859535-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0F68BF13-DFC4-45EF-B400-EB48F97440DC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd) Task: {48786C8B-9B89-4888-B162-9186D6E97B40} - System32\Tasks\{62973BA8-8F9D-422F-9E8D-EF4EC9E4AE6A} => C:\Program Files (x86)\Eidos\Hitman Contracts\HitmanContracts.exe Task: {738C65BD-C160-4B4B-9552-B3B3899E8F5B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31] (Google Inc.) Task: {8EE85849-429B-4714-BA89-98837D5E5046} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {C5BCD219-F569-4712-B26C-DC5F211123E3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31] (Google Inc.) Task: {DCBE8B17-4975-4CC8-B3D1-07BE8D9C8648} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2013-06-21] (ASUSTek Computer Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-06-24 09:20 - 2011-11-29 08:48 - 00442880 _____ () C:\Windows\system32\wlsppc.dll 2014-06-09 09:34 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2012-01-17 11:24 - 2012-01-17 11:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2012-06-06 23:00 - 2009-06-17 16:13 - 00068136 _____ () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe 2012-07-20 20:08 - 2012-07-20 20:08 - 08186368 _____ () C:\xampp\mysql\bin\mysqld.exe 2012-06-10 09:33 - 2014-05-30 19:26 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2012-12-12 22:37 - 2012-12-12 22:37 - 00088968 _____ () C:\Program Files\TortoiseSVN\bin\libsasl.dll 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-06-06 23:00 - 2012-06-06 23:00 - 00008704 _____ () C:\Windows\assembly\GAC_64\GBHO\1.0.0.0__709f1911357dc329\GBHO.dll 2012-06-07 00:01 - 2012-02-17 20:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2014-06-05 07:16 - 2013-07-23 16:55 - 00089600 _____ () C:\Windows\SYSTEM32\CmdRtr64.DLL 2014-06-05 07:16 - 2013-07-23 16:54 - 00350208 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2012-01-10 14:41 - 2013-08-14 23:25 - 00567880 _____ () C:\Program Files (x86)\puush\puush.exe 2014-07-19 21:11 - 2014-07-22 22:46 - 03356480 _____ () C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe 2012-11-28 15:13 - 2012-11-28 15:13 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-11-28 15:13 - 2012-11-28 15:13 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-06-06 23:00 - 2009-05-04 17:56 - 00102400 _____ () C:\Program Files (x86)\GIGABYTE\EnergySaver2\ycc.dll 2013-06-20 11:01 - 2013-06-20 11:01 - 00258048 _____ () C:\Program Files (x86)\ASUS\GPU Tweak\Vender.dll 2013-05-14 15:11 - 2013-05-14 15:11 - 00049152 _____ () C:\Program Files (x86)\ASUS\GPU Tweak\Exeio.dll 2009-07-13 23:03 - 2009-07-14 03:15 - 00364544 _____ () C:\Windows\SysWOW64\msjetoledb40.dll 2014-08-25 19:11 - 2014-08-25 19:11 - 00043008 _____ () c:\users\franky\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgqwrsf.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Franky\AppData\Roaming\Dropbox\bin\libcef.dll 2014-08-24 18:18 - 2014-08-24 18:18 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2012-12-12 21:30 - 2012-12-12 21:30 - 00070536 _____ () C:\Program Files\TortoiseSVN\bin\libsasl32.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksupmgr => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ksupmgr => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: Hamachi2Svc => 2 MSCONFIG\Services: LMIGuardianSvc => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BTTray.lnk => C:\Windows\pss\BTTray.lnk.CommonStartup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: avgnt => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: ISUSScheduler => "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: puush => C:\Program Files (x86)\puush\puush.exe MSCONFIG\startupreg: RazerGameBooster => C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe -autorun MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun MSCONFIG\startupreg: Spotify => "C:\Users\Franky\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Franky\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" ==================== Faulty Device Manager Devices ============= Name: TAP-Win32 Adapter V9 (Tunngle) Description: TAP-Win32 Adapter V9 (Tunngle) Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TAP-Win32 Provider V9 (Tunngle) Service: tap0901t Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Hamachi Network Interface Description: Hamachi Network Interface Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: LogMeIn, Inc. Service: hamachi Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Microsoft Virtual WiFi Miniport Adapter #10 Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (08/25/2014 07:09:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: httpd.exe, Version: 2.4.3.0, Zeitstempel: 0x502f70a3 Name des fehlerhaften Moduls: libhttpd.dll, Version: 2.4.3.0, Zeitstempel: 0x502f7161 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00019c82 ID des fehlerhaften Prozesses: 0x514 Startzeit der fehlerhaften Anwendung: 0xhttpd.exe0 Pfad der fehlerhaften Anwendung: httpd.exe1 Pfad des fehlerhaften Moduls: httpd.exe2 Berichtskennung: httpd.exe3 Error: (08/24/2014 05:55:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: httpd.exe, Version: 2.4.3.0, Zeitstempel: 0x502f70a3 Name des fehlerhaften Moduls: libhttpd.dll, Version: 2.4.3.0, Zeitstempel: 0x502f7161 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00019c82 ID des fehlerhaften Prozesses: 0x4b4 Startzeit der fehlerhaften Anwendung: 0xhttpd.exe0 Pfad der fehlerhaften Anwendung: httpd.exe1 Pfad des fehlerhaften Moduls: httpd.exe2 Berichtskennung: httpd.exe3 Error: (08/24/2014 05:55:52 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (08/24/2014 05:55:52 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (08/24/2014 05:55:52 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (08/24/2014 05:53:03 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: PnkBstrA.exe, Version: 0.0.0.0, Zeitstempel: 0x4f144d4e Name des fehlerhaften Moduls: wlsppc.dll, Version: 0.0.0.0, Zeitstempel: 0x4ed48e45 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000eb50 ID des fehlerhaften Prozesses: 0xc24 Startzeit der fehlerhaften Anwendung: 0xPnkBstrA.exe0 Pfad der fehlerhaften Anwendung: PnkBstrA.exe1 Pfad des fehlerhaften Moduls: PnkBstrA.exe2 Berichtskennung: PnkBstrA.exe3 Error: (08/24/2014 05:52:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: filezillaserver.exe, Version: 0.9.41.0, Zeitstempel: 0x4f4a44d4 Name des fehlerhaften Moduls: wlsppc.dll, Version: 0.0.0.0, Zeitstempel: 0x4ed48e45 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000eb50 ID des fehlerhaften Prozesses: 0x898 Startzeit der fehlerhaften Anwendung: 0xfilezillaserver.exe0 Pfad der fehlerhaften Anwendung: filezillaserver.exe1 Pfad des fehlerhaften Moduls: filezillaserver.exe2 Berichtskennung: filezillaserver.exe3 Error: (08/24/2014 05:52:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: httpd.exe, Version: 2.4.3.0, Zeitstempel: 0x502f70a3 Name des fehlerhaften Moduls: wlsppc.dll, Version: 0.0.0.0, Zeitstempel: 0x4ed48e45 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000eb50 ID des fehlerhaften Prozesses: 0x854 Startzeit der fehlerhaften Anwendung: 0xhttpd.exe0 Pfad der fehlerhaften Anwendung: httpd.exe1 Pfad des fehlerhaften Moduls: httpd.exe2 Berichtskennung: httpd.exe3 Error: (08/24/2014 05:52:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: httpd.exe, Version: 2.4.3.0, Zeitstempel: 0x502f70a3 Name des fehlerhaften Moduls: wlsppc.dll, Version: 0.0.0.0, Zeitstempel: 0x4ed48e45 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000eb50 ID des fehlerhaften Prozesses: 0x7ac Startzeit der fehlerhaften Anwendung: 0xhttpd.exe0 Pfad der fehlerhaften Anwendung: httpd.exe1 Pfad des fehlerhaften Moduls: httpd.exe2 Berichtskennung: httpd.exe3 Error: (08/24/2014 05:52:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: AppleMobileDeviceService.exe, Version: 17.96.0.8, Zeitstempel: 0x4fb5bca5 Name des fehlerhaften Moduls: wlsppc.dll, Version: 0.0.0.0, Zeitstempel: 0x4ed48e45 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000eb50 ID des fehlerhaften Prozesses: 0x7dc Startzeit der fehlerhaften Anwendung: 0xAppleMobileDeviceService.exe0 Pfad der fehlerhaften Anwendung: AppleMobileDeviceService.exe1 Pfad des fehlerhaften Moduls: AppleMobileDeviceService.exe2 Berichtskennung: AppleMobileDeviceService.exe3 System errors: ============= Error: (08/25/2014 07:17:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:17:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:17:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:17:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:17:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:17:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:16:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:16:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:16:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/25/2014 07:16:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Microsoft Office Sessions: ========================= Error: (08/25/2014 07:09:19 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: httpd.exe2.4.3.0502f70a3libhttpd.dll2.4.3.0502f7161c000000500019c8251401cfc0873ec5791eC:\xampp\apache\bin\httpd.exeC:\xampp\apache\bin\libhttpd.dll8c9b1b9b-2c7a-11e4-81d6-50e5493060fd Error: (08/24/2014 05:55:57 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: httpd.exe2.4.3.0502f70a3libhttpd.dll2.4.3.0502f7161c000000500019c824b401cfbfb3d75b83ecC:\xampp\apache\bin\httpd.exeC:\xampp\apache\bin\libhttpd.dll223049f0-2ba7-11e4-9bbe-50e5493060fd Error: (08/24/2014 05:55:52 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (08/24/2014 05:55:52 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (08/24/2014 05:55:52 PM) (Source: NvStreamSvc) (EventID: 1) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (08/24/2014 05:53:03 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: PnkBstrA.exe0.0.0.04f144d4ewlsppc.dll0.0.0.04ed48e45c00000050000eb50c2401cfbf77083ec2d1C:\Windows\SysWOW64\PnkBstrA.exeC:\Windows\system32\wlsppc.dllba6e9217-2ba6-11e4-b06a-f51177cfc99e Error: (08/24/2014 05:52:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: filezillaserver.exe0.9.41.04f4a44d4wlsppc.dll0.0.0.04ed48e45c00000050000eb5089801cfbf7706292720C:\xampp\filezillaftp\filezillaserver.exeC:\Windows\system32\wlsppc.dllb83ccd56-2ba6-11e4-b06a-f51177cfc99e Error: (08/24/2014 05:52:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: httpd.exe2.4.3.0502f70a3wlsppc.dll0.0.0.04ed48e45c00000050000eb5085401cfbf7705a1a5a4C:\xampp\apache\bin\httpd.exeC:\Windows\system32\wlsppc.dllb5f0d972-2ba6-11e4-b06a-f51177cfc99e Error: (08/24/2014 05:52:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: httpd.exe2.4.3.0502f70a3wlsppc.dll0.0.0.04ed48e45c00000050000eb507ac01cfbf7704bc2448C:\xampp\apache\bin\httpd.exeC:\Windows\system32\wlsppc.dllb19936d3-2ba6-11e4-b06a-f51177cfc99e Error: (08/24/2014 05:52:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: AppleMobileDeviceService.exe17.96.0.84fb5bca5wlsppc.dll0.0.0.04ed48e45c00000050000eb507dc01cfbf7705034073C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Windows\system32\wlsppc.dlla5368de6-2ba6-11e4-b06a-f51177cfc99e CodeIntegrity Errors: =================================== Date: 2014-08-25 19:07:59.640 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-25 19:07:59.562 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-24 17:55:07.604 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-24 17:55:07.542 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-24 10:39:43.339 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-24 10:39:43.292 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-23 08:24:54.730 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-23 08:24:54.668 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-22 20:31:02.153 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-22 20:31:02.075 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2550K CPU @ 3.40GHz Percentage of memory in use: 36% Total physical RAM: 8175.12 MB Available physical RAM: 5203.3 MB Total Pagefile: 16348.41 MB Available Pagefile: 13367.08 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:19.64 GB) NTFS Drive g: (Volume) (Fixed) (Total:2794.39 GB) (Free:447.44 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 04B704B6) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
26.08.2014, 18:47 | #5 |
/// the machine /// TB-Ausbilder | Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.08.2014, 19:38 | #6 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Ich habe ComboFix ausgeführt. Ich habe das Programm ausgeführt. Anschließend öffnete sich ein Fenster. Das wurde aber nach kurzer Zeit geschlossen und eine Fehlermeldung, dass versucht wurde einen nicht signierter Treiber zu installieren, wurde angezeigt. Anschließend habe ich versucht das Programm noch einmal auszuführen. Das wurde aber mit der Meldung abgebrochen, dass eine Datei nicht überschrieben werden konnte. Ich habe anschließend (nach einiger Zeit in der nichts passierte) den PC neugestartet. Anschließend habe ich ComboFix erneut gestartet. Diesmal funktionierte es ohne Probleme und Fehlermeldungen. Das Log ist zu groß deshalb poste ich es in zwei Teilen. Im folgenden die log.txt Teil1: Code:
ATTFilter ComboFix 14-08-26.02 - Franky 27.08.2014 20:04:31.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8175.5970 [GMT 2:00] ausgeführt von:: c:\users\Franky\Desktop\ComboFix.exe AV: 360 Internet Security *Disabled/Updated* {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D} SP: 360 Internet Security *Disabled/Updated* {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\360Rec c:\360rec\20140720\095BE6E.vir c:\360rec\20140723\230C22B.vir c:\360rec\20140725\162ACB4.vir c:\360rec\20140806\0753977.vir c:\360rec\20140816\1001797.vir c:\360rec\20140821\2046AF5.vir c:\360rec\20140824\1101AB1.vir C:\Install.exe c:\programdata\sAveNshare c:\programdata\sAveNshare\7iVpOqg.dat c:\programdata\sAveNshare\tMrvqg.dat c:\programdata\SearchNewTab c:\programdata\SearchNewTab\F6BjKd3sR.dat c:\programdata\SearchNewTab\n8Enuwaf.dat c:\users\Franky\AppData\Local\assembly\tmp c:\users\Franky\AppData\Roaming\jd-gui.exe c:\users\Franky\AppData\Roaming\Minecraft.exe c:\users\Simon\AppData\Local\assembly\tmp c:\users\Simon\AppData\Roaming\14001.019 c:\users\Simon\AppData\Roaming\14001.019\chrome.manifest c:\users\Simon\AppData\Roaming\14001.019\components\AcroFF.txt c:\users\Simon\AppData\Roaming\14001.019\install.rdf c:\users\Simon\AppData\Roaming\15001.001 c:\users\Simon\AppData\Roaming\15001.001\chrome.manifest c:\users\Simon\AppData\Roaming\15001.001\components\AcroFF.txt c:\users\Simon\AppData\Roaming\15001.001\install.rdf c:\users\Simon\AppData\Roaming\98aws5v5.default.tmp c:\users\Simon\AppData\Roaming\AcroIEHelpe.txt c:\users\Simon\AppData\Roaming\srvblck5.tmp c:\windows\IsUn0407.exe c:\windows\SysWow64\logs c:\windows\SysWow64\tmp9270.tmp c:\windows\SysWow64\tmp9271.tmp c:\windows\SysWow64\tmpAFA0.tmp c:\windows\SysWow64\tmpAFFF.tmp c:\windows\wininit.ini G:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-07-27 bis 2014-08-27 )))))))))))))))))))))))))))))) . . 2014-08-27 18:19 . 2014-08-27 18:19 -------- d-----w- c:\users\Simon\AppData\Local\temp 2014-08-27 18:19 . 2014-08-27 18:19 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-08-26 19:56 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B48FF078-5B23-48D1-B874-03ADAFE35D3D}\mpengine.dll 2014-08-25 17:15 . 2014-08-25 17:17 -------- d-----w- C:\FRST 2014-08-23 22:02 . 2014-08-24 16:00 -------- d-----w- c:\users\Franky\AppData\Roaming\GameRanger 2014-08-23 15:07 . 2014-08-23 19:33 -------- d-----w- c:\programdata\Firefly Studios 2014-08-23 15:04 . 2014-08-23 15:21 -------- d-----w- c:\program files (x86)\GameSpy Arcade 2014-08-15 22:04 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll 2014-08-15 22:04 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll 2014-08-15 22:04 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll 2014-08-15 22:04 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll 2014-08-15 22:04 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe 2014-08-15 22:04 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe 2014-08-15 22:03 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe 2014-08-15 22:03 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe 2014-08-13 20:09 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll 2014-08-13 20:09 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll 2014-08-13 20:09 . 2014-08-07 02:06 529920 ----a-w- c:\windows\system32\aepdu.dll 2014-08-13 20:09 . 2014-08-07 02:01 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-08-04 18:49 . 2014-08-04 18:49 -------- d-----w- c:\users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou 2014-08-02 22:36 . 2014-05-14 16:23 44512 ----a-w- c:\windows\system32\wups2.dll 2014-08-02 22:36 . 2014-05-14 16:23 58336 ----a-w- c:\windows\system32\wuauclt.exe 2014-08-02 22:36 . 2014-05-14 16:23 2477536 ----a-w- c:\windows\system32\wuaueng.dll 2014-08-02 22:36 . 2014-05-14 16:21 2620928 ----a-w- c:\windows\system32\wucltux.dll 2014-08-02 22:35 . 2014-05-14 16:23 38880 ----a-w- c:\windows\system32\wups.dll 2014-08-02 22:35 . 2014-05-14 16:23 700384 ----a-w- c:\windows\system32\wuapi.dll 2014-08-02 22:35 . 2014-05-14 16:20 97792 ----a-w- c:\windows\system32\wudriver.dll 2014-08-02 22:35 . 2014-05-14 16:17 92672 ----a-w- c:\windows\SysWow64\wudriver.dll 2014-08-02 22:35 . 2014-05-14 16:23 36320 ----a-w- c:\windows\SysWow64\wups.dll 2014-08-02 22:35 . 2014-05-14 16:23 581600 ----a-w- c:\windows\SysWow64\wuapi.dll 2014-08-02 22:35 . 2014-05-14 07:23 198600 ----a-w- c:\windows\system32\wuwebv.dll 2014-08-02 22:35 . 2014-05-14 07:23 179656 ----a-w- c:\windows\SysWow64\wuwebv.dll 2014-08-02 22:35 . 2014-05-14 07:20 36864 ----a-w- c:\windows\system32\wuapp.exe 2014-08-02 22:35 . 2014-05-14 07:17 33792 ----a-w- c:\windows\SysWow64\wuapp.exe 2014-08-01 16:23 . 2014-08-01 16:23 -------- d-----w- c:\users\Franky\AppData\Local\Robot Entertainment . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-08-27 17:53 . 2012-06-06 21:06 25640 ----a-w- c:\windows\gdrv.sys 2014-08-27 17:50 . 2014-05-18 16:37 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin 2014-08-15 22:11 . 2012-11-20 17:13 99218768 ----a-w- c:\windows\system32\MRT.exe 2014-08-05 07:20 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-06-19 16:18 . 2014-06-19 16:18 119808 ----a-r- c:\users\Franky\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe 2014-06-18 02:18 . 2014-07-09 16:16 692736 ----a-w- c:\windows\system32\osk.exe 2014-06-18 01:51 . 2014-07-09 16:16 646144 ----a-w- c:\windows\SysWow64\osk.exe 2014-06-07 15:31 . 2013-11-20 11:57 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2014-06-07 15:31 . 2012-07-01 17:18 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr 2014-06-07 08:31 . 2012-06-10 07:33 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2014-06-06 10:10 . 2014-07-09 16:16 624128 ----a-w- c:\windows\system32\qedit.dll 2014-06-06 09:44 . 2014-07-09 16:16 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-06-05 14:45 . 2014-07-09 16:12 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2014-06-05 14:26 . 2014-07-09 16:12 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2014-06-05 14:25 . 2014-07-09 16:12 96768 ----a-w- c:\windows\SysWow64\sspicli.dll 2014-06-02 20:07 . 2014-06-02 20:07 67584 ----a-w- c:\windows\system32\drivers\vrtaucbl.sys 2014-05-30 17:26 . 2012-06-10 07:33 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe 2014-05-30 08:08 . 2014-07-09 16:16 210944 ----a-w- c:\windows\system32\wdigest.dll 2014-05-30 08:08 . 2014-07-09 16:16 86528 ----a-w- c:\windows\system32\TSpkg.dll 2014-05-30 08:08 . 2014-07-09 16:16 340992 ----a-w- c:\windows\system32\schannel.dll 2014-05-30 08:08 . 2014-07-09 16:16 314880 ----a-w- c:\windows\system32\msv1_0.dll 2014-05-30 08:08 . 2014-07-09 16:16 307200 ----a-w- c:\windows\system32\ncrypt.dll 2014-05-30 08:08 . 2014-07-09 16:16 728064 ----a-w- c:\windows\system32\kerberos.dll 2014-05-30 08:08 . 2014-07-09 16:16 22016 ----a-w- c:\windows\system32\credssp.dll 2014-05-30 07:52 . 2014-07-09 16:16 172032 ----a-w- c:\windows\SysWow64\wdigest.dll 2014-05-30 07:52 . 2014-07-09 16:16 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll 2014-05-30 07:52 . 2014-07-09 16:16 247808 ----a-w- c:\windows\SysWow64\schannel.dll 2014-05-30 07:52 . 2014-07-09 16:16 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll 2014-05-30 07:52 . 2014-07-09 16:16 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll 2014-05-30 07:52 . 2014-07-09 16:16 550912 ----a-w- c:\windows\SysWow64\kerberos.dll 2014-05-30 07:52 . 2014-07-09 16:16 17408 ----a-w- c:\windows\SysWow64\credssp.dll 2014-05-30 06:45 . 2014-07-09 16:16 497152 ----a-w- c:\windows\system32\drivers\afd.sys 2006-05-03 10:06 163328 --sha-r- c:\windows\SysWOW64\flvDX.dll 2007-02-21 11:47 31232 --sha-r- c:\windows\SysWOW64\msfDX.dll 2008-03-16 13:30 216064 --sha-r- c:\windows\SysWOW64\nbDX.dll 2010-01-06 22:00 107520 --sha-r- c:\windows\SysWOW64\TAKDSDecoder.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2009-07-14 . 769765CE2CC62867468CEA93969B2242 . 23040 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-rasbase-asyncmac_31bf3856ad364e35_6.1.7600.16385_none_804cc08a4e8a4516\asyncmac.sys [-] 2009-07-14 . 769765CE2CC62867468CEA93969B2242 . 23040 . . [6.1.7600.16385] .. c:\windows\system32\drivers\asyncmac.sys . [-] 2009-07-13 . 9899284589F75FA8724FF3D16AED75C1 . 6144 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-null_31bf3856ad364e35_6.1.7600.16385_none_055adf2434ae116e\null.sys [-] 2009-07-13 . 9899284589F75FA8724FF3D16AED75C1 . 6144 . . [6.1.7600.16385] .. c:\windows\system32\drivers\null.sys . [-] 2010-11-21 . DDAD5A7AB24D8B65F8D724F5C20FD806 . 119296 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.1.7601.17514_none_4863cdbaf2b532f8\tdx.sys [-] 2010-11-21 . DDAD5A7AB24D8B65F8D724F5C20FD806 . 119296 . . [6.1.7601.17514] .. c:\windows\system32\drivers\tdx.sys . [-] 2012-07-04 . 05F5A0D14A2EE1D8255C2AA0E9E8E694 . 136704 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-browserservice_31bf3856ad364e35_6.1.7601.17887_none_d6c68344b4d406bf\browser.dll [-] 2012-07-04 . 156768ABAE1DAF29BA0B0C05C21FEF09 . 136704 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-browserservice_31bf3856ad364e35_6.1.7601.22044_none_d7783703cdd41e02\browser.dll [-] 2010-11-21 . 8EF0D5C41EC907751B8429162B1239ED . 136192 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-browserservice_31bf3856ad364e35_6.1.7601.17514_none_d70f2c28b49dffae\browser.dll [-] 2012-07-04 . 05F5A0D14A2EE1D8255C2AA0E9E8E694 . 136704 . . [6.1.7600.16385] .. c:\windows\system32\browser.dll . [-] 2014-05-30 . F23812F9F7B130854E4BC0389F7C688C . 31232 . . [6.1.7601.18489] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18489_none_0429c981739f213b\lsass.exe [-] 2014-05-30 . 04F6C08B30C599D301CE8530A6F6A703 . 31232 . . [6.1.7601.22705] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22705_none_0505e8508c7f766f\lsass.exe [-] 2014-04-12 . 6598EBC4D209318EBD81F76833ECBEDB . 31232 . . [6.1.7601.22653] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22653_none_04cdd63a8ca9d24f\lsass.exe [-] 2014-04-12 . 6598EBC4D209318EBD81F76833ECBEDB . 31232 . . [6.1.7601.22653] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22712_none_04f817868c8a465b\lsass.exe [-] 2014-04-12 . 204F3F58212B3E422C90BD9691A2DF28 . 31232 . . [6.1.7601.18443] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18443_none_044f07757384196d\lsass.exe [-] 2014-04-12 . 204F3F58212B3E422C90BD9691A2DF28 . 31232 . . [6.1.7601.18443] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18496_none_041bf8b773a9f127\lsass.exe [-] 2013-09-25 . F021DAFB1F87616FCEBA159C2ED7042F . 30720 . . [6.1.7601.22465] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22465_none_04c503168cb026a0\lsass.exe [-] 2013-09-25 . 4D71227301DD8D09097B9E4CC6527E5A . 30720 . . [6.1.7601.18270] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.18270_none_042b9307739f26ed\lsass.exe [-] 2012-08-24 . 77119F1F9B492B260030C34F9BE327FA . 31232 . . [6.1.7601.22099] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22099_none_04a88ce28cc4eb33\lsass.exe [-] 2012-06-04 . 79C908CAA6F43021EB05F4C733A927D1 . 31232 . . [6.1.7601.22010] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.22010_none_04f609a88c8c279c\lsass.exe [-] 2011-11-17 . C118A82CD78818C29AB228366EBF81C3 . 31232 . . [6.1.7601.17725] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17725_none_0466c45b7371f20d\lsass.exe [-] 2011-11-17 . C118A82CD78818C29AB228366EBF81C3 . 31232 . . [6.1.7601.17725] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17856_none_044756c773895c5e\lsass.exe [-] 2011-11-17 . C118A82CD78818C29AB228366EBF81C3 . 31232 . . [6.1.7601.17725] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17940_none_044c26dd7386a58a\lsass.exe [-] 2011-11-17 . 0A10B74FBB437FF9A23F1D5DE4446A83 . 31232 . . [6.1.7601.21861] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.21861_none_04c1204e8cb39c3f\lsass.exe [-] 2009-07-14 . 0793F40B9B8A1BDD266296409DBD91EA . 31232 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-lsa_31bf3856ad364e35_6.1.7601.17514_none_04709031736ac277\lsass.exe [-] 2014-04-12 . 204F3F58212B3E422C90BD9691A2DF28 . 31232 . . [6.1.7601.18443] .. c:\windows\system32\lsass.exe . [-] 2009-07-14 . 847D3AE376C0817161A14A82C8922A9E . 360448 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-netman_31bf3856ad364e35_6.1.7600.16385_none_6bb20d3d6b80d9da\netman.dll [-] 2009-07-14 . 847D3AE376C0817161A14A82C8922A9E . 360448 . . [6.1.7600.16385] .. c:\windows\system32\netman.dll . [-] 2010-11-21 . 1EA7969E3271CBC59E1730697DC74682 . 849920 . . [7.5.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.1.7601.17514_none_81b6ca5c101195cd\qmgr.dll [-] 2010-11-21 . 1EA7969E3271CBC59E1730697DC74682 . 849920 . . [7.5.7600.16385] .. c:\windows\system32\qmgr.dll . [-] 2010-11-21 . 5C627D1B1138676C0A7AB2C2C190D123 . 512000 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll [-] 2010-11-21 . 5C627D1B1138676C0A7AB2C2C190D123 . 512000 . . [6.1.7601.17514] .. c:\windows\system32\rpcss.dll . [-] 2009-07-14 . 24ACB7E5BE595468E3B9AA488B9B4FCB . 328704 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe [-] 2009-07-14 . 24ACB7E5BE595468E3B9AA488B9B4FCB . 328704 . . [6.1.7600.16385] .. c:\windows\system32\services.exe . [-] 2012-02-11 . 85DAA09A98C9286D4EA2BA8D0E644377 . 559104 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.1.7601.17777_none_3433cdb2d8563d50\spoolsv.exe [-] 2012-02-11 . B9D7A4858CF32A6A15D2763F1DE47E0E . 559616 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.1.7601.21921_none_34ed7a43f150b682\spoolsv.exe [-] 2010-11-21 . B96C17B5DC1424D56EEA3A99E97428CD . 559104 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.1.7601.17514_none_3471a890d8284f57\spoolsv.exe [-] 2012-02-11 . 85DAA09A98C9286D4EA2BA8D0E644377 . 559104 . . [6.1.7601.17514] .. c:\windows\system32\spoolsv.exe . [-] 2014-03-04 . 6CE2AE073BD21C542FC2C707CAE944CC . 455680 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_ce748d1d04acf24f\winlogon.exe [-] 2014-03-04 . 88AB9B72B4BF3963A0DE0820B4B0B06C . 455168 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_cdf8bf35eb848572\winlogon.exe [-] 2010-11-21 . 1151B1BAA6F350B1DB6598E0FEA7C457 . 390656 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe [-] 2014-03-04 . 88AB9B72B4BF3963A0DE0820B4B0B06C . 455168 . . [6.1.7601.17514] .. c:\windows\system32\winlogon.exe . [-] 2013-07-04 . 9028D1621C43DF8DFBD1C76860412A11 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.18201_none_97c9d703ee91c7f1\comctl32.dll [-] 2013-07-04 . 9028D1621C43DF8DFBD1C76860412A11 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll [-] 2013-07-04 . 4F3C5CE9EF990E1C62B7E7EBA0EBA1C2 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.22376_none_980cc5cd07e3aa05\comctl32.dll [-] 2013-07-04 . 4F3C5CE9EF990E1C62B7E7EBA0EBA1C2 . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.22376_none_a6ba9bf96e3dcd13\comctl32.dll [-] 2010-11-21 . 14DFDEAF4E589ED3F1FF187A86B9408C . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.17514_none_97c2246fee970dbb\comctl32.dll [-] 2010-11-21 . 14DFDEAF4E589ED3F1FF187A86B9408C . 633856 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll [-] 2010-11-21 . 7FA8FDC2C2A27817FD0F624E78D3B50C . 2030080 . . [5.82] .. c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac\comctl32.dll [-] 2013-07-04 . 9028D1621C43DF8DFBD1C76860412A11 . 633856 . . [5.82] .. c:\windows\system32\comctl32.dll . [-] 2009-07-14 . 1A47D52E303B7543E4E6026595B95422 . 1297408 . . [2001.12.8530.16385] .. c:\windows\winsxs\amd64_microsoft-windows-com-complus.res_31bf3856ad364e35_6.1.7600.16385_none_88a5cc7effe2dfca\comres.dll [-] 2009-07-14 . 1A47D52E303B7543E4E6026595B95422 . 1297408 . . [2001.12.8530.16385] .. c:\windows\system32\comres.dll . [-] 2013-10-05 . 509D31797A4B8A3D6ED78A330B19A919 . 186880 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22473_none_d46d4138cabe2596\cryptsvc.dll [-] 2013-07-09 . 434CCE8E7150CD1324C5FAA088D1D061 . 186880 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_d45f6e88cac8f85b\cryptsvc.dll [-] 2013-07-09 . 6B400F211BEE880A37A1ED0368776BF4 . 184320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_d431528fb165f7bc\cryptsvc.dll [-] 2013-05-13 . D8129C49798CBBFB2E4351D4B7B8EF9C . 184320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_d3f73fe5b19220ee\cryptsvc.dll [-] 2013-05-11 . 8122252F0A4ACFA92FA0C1D50D18493B . 186880 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_d4a24ea4ca968363\cryptsvc.dll [-] 2013-05-10 . 7FDC4626B01106A8EF328C88C7C0DEE3 . 184320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18150_none_d3f63f9bb1930797\cryptsvc.dll [-] 2013-05-10 . CA13C4F92BEE66DB48E58AB3223DDF6E . 186880 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22321_none_d4a14e5aca976a0c\cryptsvc.dll [-] 2012-06-04 . 7E7D2DACF65D750D466F36BD3D09AE20 . 186880 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_d4ab184aca903d4f\cryptsvc.dll [-] 2012-06-02 . 9C01375BE382E834CC26D1B7EAF2C4FE . 184320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_d3fc6569b18d7211\cryptsvc.dll [-] 2012-04-24 . 4F5414602E2544A4554D95517948B705 . 184320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_d41dd577b1743795\cryptsvc.dll [-] 2012-04-24 . B7337E9C9E5936355BB700AA33E0936E . 186880 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_d473633acab895c2\cryptsvc.dll [-] 2010-11-21 . 15597883FBE9B056F276ADA3AD87D9AF . 177152 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_d4259ed3b16ed82a\cryptsvc.dll [-] 2013-07-09 . 6B400F211BEE880A37A1ED0368776BF4 . 184320 . . [6.1.7600.16385] .. c:\windows\system32\cryptsvc.dll . [-] 2009-07-14 . 4166F82BE4D24938977DD1746BE9B8A0 . 402944 . . [2001.12.8530.16385] .. c:\windows\winsxs\amd64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.1.7600.16385_none_68e290c46b6ea6d0\es.dll [-] 2009-07-14 . 4166F82BE4D24938977DD1746BE9B8A0 . 402944 . . [2001.12.8530.16385] .. c:\windows\system32\es.dll . [-] 2009-07-14 . AA2C08CE85653B1A0D2E4AB407FA176C . 167424 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.1.7600.16385_none_b84b0fbd941c03a9\imm32.dll [-] 2009-07-14 . AA2C08CE85653B1A0D2E4AB407FA176C . 167424 . . [6.1.7600.16385] .. c:\windows\system32\imm32.dll . [-] 2014-04-25 . 088CF6AFCD5CDD44E40C0ACDE3C1A5E0 . 801280 . . [1.0626.7601.18454] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.18454_none_0af5261f6f3c76ad\usp10.dll [-] 2014-04-25 . BB2B03C6B6778A9B2866A049CC600D55 . 801792 . . [1.0626.7601.22666] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.22666_none_0b75f5788860623d\usp10.dll [-] 2012-11-22 . E4ACCC7927A1478DF636534864E03666 . 801280 . . [1.0626.7601.22171] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.22171_none_0b661a9c886d0db8\usp10.dll [-] 2012-11-22 . DBF99FD9CAF75CA66D042BD8D050FF71 . 800768 . . [1.0626.7601.18009] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.18009_none_0b302f956f0f750f\usp10.dll [-] 2010-11-21 . 2F8B1E3EE3545D3B5A8D56FA1AE07B65 . 800256 . . [1.0626.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.17514_none_0b207e7d6f1bea6f\usp10.dll [-] 2014-04-25 . 088CF6AFCD5CDD44E40C0ACDE3C1A5E0 . 801280 . . [1.0626.7601.18454] .. c:\windows\system32\usp10.dll . [-] 2014-04-12 . 77BBBF70BCE286CD19E1E68F248363FA . 1164800 . . [6.1.7601.22653] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22653_none_f24130b9862a22c7\kernel32.dll [-] 2014-03-04 . 52E77DC8E31C89FBB1E968699C8121C5 . 1164800 . . [6.1.7601.22616] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22616_none_f26f71478606ff08\kernel32.dll [-] 2014-03-04 . D2A513EE880D71BDE7F0257F38B9D019 . 1163264 . . [6.1.7601.18409] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18409_none_f1f3a3606cde922b\kernel32.dll [-] 2013-08-29 . 786D234A90FCAC72633AE6FC52653A49 . 1162240 . . [6.1.7601.22436] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22436_none_f259cda386173c9c\kernel32.dll [-] 2013-08-02 . C525D51A79B01342344F02E38866CF60 . 1162240 . . [6.1.7601.22411] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22411_none_f26a6c09860b8607\kernel32.dll [-] 2013-08-02 . D8973E71F1B35CD3F3DEA7C12D49D0F0 . 1161216 . . [6.1.7601.18229] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18229_none_f1ddffbc6ceecfbf\kernel32.dll [-] 2013-07-08 . 38E54D419A2962E24D35D868E4724AE7 . 1162240 . . [6.1.7601.22379] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22379_none_f2318ceb8634fb3e\kernel32.dll [-] 2013-01-04 . B844114B247D8EF1E5E4E93A282D2E6F . 1162240 . . [6.1.7601.22209] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22209_none_f27d3a7985fc3a80\kernel32.dll [-] 2012-11-30 . B3BEA6420D482356E53B7C728E05C637 . 1163264 . . [6.1.7601.22177] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22177_none_f22f888b8636ce42\kernel32.dll [-] 2012-11-30 . 65C113214F7B05820F6D8A65B1485196 . 1161216 . . [6.1.7601.18015] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18015_none_f1e4cab46cea5424\kernel32.dll [-] 2012-10-04 . 1DC3504CA4C57900F1557E9A3F01D272 . 1161216 . . [6.1.7601.17965] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17965_none_f1aee2f66d12ac97\kernel32.dll [-] 2012-10-04 . F3C594D0DA3ACFA6C7B781A490AB4282 . 1162240 . . [6.1.7601.22125] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22125_none_f263979386100fdf\kernel32.dll [-] 2012-08-20 . EAF41CFBA5281834CBC383C710AC7965 . 1162240 . . [6.1.7601.17932] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17932_none_f1cc51dc6cfd0cbf\kernel32.dll [-] 2012-08-20 . 624B34180C79D67C470C155DB81FFB8E . 1163264 . . [6.1.7601.22091] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22091_none_f213e511864c70f3\kernel32.dll [-] 2011-07-16 . B9B42A302325537D7B9DC52D47F33A73 . 1162752 . . [6.1.7601.17651] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17651_none_f1b5ac086d0e33d5\kernel32.dll [-] 2011-07-16 . 27AC02D8EE4C02E7648C41CB880151DA . 1163264 . . [6.1.7601.21772] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.21772_none_f22aa945863b24d8\kernel32.dll [-] 2010-11-21 . 7A6326D96D53048FDEC542DF23D875A0 . 1161216 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17514_none_f1e3eab06ceb12ef\kernel32.dll [-] 2014-03-04 . D2A513EE880D71BDE7F0257F38B9D019 . 1163264 . . [6.1.7601.18015] .. c:\windows\system32\kernel32.dll . [-] 2009-07-14 . A0A65D306A5490D2EB8E7DE66898ECFD . 29696 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-linkinfo_31bf3856ad364e35_6.1.7600.16385_none_945a23c3bf051859\linkinfo.dll [-] 2009-07-14 . A0A65D306A5490D2EB8E7DE66898ECFD . 29696 . . [6.1.7600.16385] .. c:\windows\system32\linkinfo.dll . [-] 2013-06-06 . 796B47A4B82EF1C39F13435B88834C48 . 41472 . . [6.1.7601.18177] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18177_none_07bb20dd7154003d\lpk.dll [-] 2013-06-06 . 22FC61B8E1EBA296FF416C3678E26DD3 . 41472 . . [6.1.7601.22350] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22350_none_08535d608a67b3eb\lpk.dll [-] 2009-07-14 . D202223587518B13D72D68937B7E3F70 . 41984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_07f91de77125e78d\lpk.dll [-] 2009-07-14 . D202223587518B13D72D68937B7E3F70 . 41984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17563_none_07c20e01714f59eb\lpk.dll [-] 2009-07-14 . D202223587518B13D72D68937B7E3F70 . 41984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17991_none_079fa54171696fac\lpk.dll [-] 2009-07-14 . D202223587518B13D72D68937B7E3F70 . 41984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18032_none_07e15d357138149f\lpk.dll [-] 2009-07-14 . D202223587518B13D72D68937B7E3F70 . 41984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21664_none_084cab168a6c130c\lpk.dll [-] 2009-07-14 . D202223587518B13D72D68937B7E3F70 . 41984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22153_none_08565a728a6505a2\lpk.dll [-] 2009-07-14 . D202223587518B13D72D68937B7E3F70 . 41984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_082d1b568a83a814\lpk.dll [-] 2013-06-06 . 796B47A4B82EF1C39F13435B88834C48 . 41472 . . [6.1.7601.18177] .. c:\windows\system32\lpk.dll . [-] 2009-07-14 . 3B367397320C26DBA890B260F80D1B1B . 424448 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-i..ectionsharingconfig_31bf3856ad364e35_6.1.7600.16385_none_0c2b375bae4a8d38\hnetcfg.dll [-] 2009-07-14 . 3B367397320C26DBA890B260F80D1B1B . 424448 . . [6.1.7600.16385] .. c:\windows\system32\hnetcfg.dll . [-] 2014-07-25 . ECA387DCD57F683C52171C766CF400F0 . 23645696 . . [11.00.9600.17239] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17239_none_f5b0b0ea3726a4ff\mshtml.dll [-] 2014-06-19 . FEC19C351EF1B2C998A85D1BFD765675 . 23464448 . . [11.00.9600.17207] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17207_none_f5addd9c372925b8\mshtml.dll [-] 2014-05-30 . 56803B20D168C1B740D12CE0BE4588F5 . 23414784 . . [11.00.9600.17126] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17126_none_f5bac4e4371f22d4\mshtml.dll [-] 2014-05-08 . 31121C313E2FF75BF4B1402B6B3B0842 . 23134208 . . [11.00.9600.16663] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16663_none_f588f8e23743c9db\mshtml.dll [-] 2014-03-31 . C3E3EFD320D0000BE6F9CDB00CD6086F . 23134208 . . [11.00.9600.16659] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16659_none_f5876fe837454a4a\mshtml.dll [-] 2014-03-06 . 37D0FB9E5E8EDA40B66FC3FB3D660261 . 23549440 . . [11.00.9600.17041] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17041_none_f5c8074c3714b96c\mshtml.dll [-] 2014-03-01 . 4E0709D9BB951AD1C22E4FF519B90839 . 23133696 . . [11.00.9600.16521] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16521_none_f58ff536373f154c\mshtml.dll [-] 2014-02-06 . D016F5092E4FFC41147E8555A71D2DDE . 23170048 . . [11.00.9600.16518] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16518_none_f58e55743740af5c\mshtml.dll [-] 2013-11-26 . 16B0A65F52531B769B891DC251ECC6C0 . 23183360 . . [11.00.9600.16476] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16476_none_f59f54ac3732f833\mshtml.dll [-] 2013-11-26 . D233E1A32CE6AF918C9DE1BC44AFEB2A . 23212032 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16428_none_f59a25aa3737acc2\mshtml.dll [-] 2013-10-12 . 25C356A79B7002E0A20AAF592ED59DE4 . 19269632 . . [10.00.9200.16736] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16736_none_91079aba92acea3d\mshtml.dll [-] 2013-10-12 . BED01C981AA5D47941F6BAF30B6FE12C . 19510784 . . [10.00.9200.20848] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20848_none_7a2ff6ecac5bb27c\mshtml.dll [-] 2013-09-22 . 9958430CE5BFC43D693D6138C31788CC . 19494912 . . [10.00.9200.20831] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20831_none_7a2f961aac5be5be\mshtml.dll [-] 2013-09-22 . F026C6F104758D0EB215B017016FAE27 . 19252224 . . [10.00.9200.16721] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16721_none_91070c5892ad50c1\mshtml.dll [-] 2013-08-10 . CC4AE7E2ECAEE7612B3C0D3AB302375C . 19246592 . . [10.00.9200.16686] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16686_none_91176c1892a04cff\mshtml.dll [-] 2013-08-10 . C2793FDC1EDB82635C538630FE192CC9 . 19488768 . . [10.00.9200.20794] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20794_none_7a40236aac4eaeba\mshtml.dll [-] 2013-07-26 . 396889142BD839DB8A055A0BE0AD2F79 . 19239424 . . [10.00.9200.16660] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16660_none_9115f43492a1808b\mshtml.dll [-] 2013-07-26 . 865EB4E69DAF2DE052E8D020F4F7D313 . 19482112 . . [10.00.9200.20768] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20768_none_7a3cc76cac51c939\mshtml.dll [-] 2013-07-02 . 5C41AF3F4B83340D2783CE8FDE30566A . 19233792 . . [10.00.9200.16618] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16618_none_91103c8292a6cee0\mshtml.dll [-] 2013-06-12 . 884691F819503DD2191A2641CC827A52 . 19482112 . . [10.00.9200.20742] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20742_none_7a3b4f88ac52fcc5\mshtml.dll [-] 2013-06-11 . 9586EC4E1CC39CCBA26A5E7DFE774C9E . 19238912 . . [10.00.9200.16635] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16635_none_9112816e92a4b4ab\mshtml.dll [-] 2013-05-17 . A820869140978CCAF33CF7770EEE19F5 . 17824768 . . [9.00.8112.16490] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16490_none_8794a11ff506e807\mshtml.dll [-] 2013-05-17 . CD451FEE119B7557633039CA39290331 . 17824768 . . [9.00.8112.20600] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20600_none_887f8f1d0ddb897f\mshtml.dll [-] 2013-05-05 . E139A28843F52F383D414BF0AAEF6CE4 . 17819136 . . [9.00.8112.20594] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20594_none_88223f130e20ed2d\mshtml.dll [-] 2013-05-05 . 7212340908E00AD2F28E58EA04CEB852 . 17818624 . . [9.00.8112.16484] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16484_none_87a37233f4fb3172\mshtml.dll [-] 2013-04-05 . F63D8615292792D36EDF24913636685D . 17818624 . . [9.00.8112.16483] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16483_none_87a271e9f4fc181b\mshtml.dll [-] 2013-04-05 . 43FEF944FF64BE0354A5C129C98EB13D . 17818624 . . [9.00.8112.20593] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20593_none_88213ec90e21d3d6\mshtml.dll [-] 2013-02-22 . 0E860BF2BCDDD94202A6AB9A10EE95EB . 17817600 . . [9.00.8112.20586] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20586_none_882f0f930e1703ea\mshtml.dll [-] 2013-02-22 . 1154FEFC73880A2EF44295EF0DBDC59F . 17817088 . . [9.00.8112.16476] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16476_none_87b042b3f4f1482f\mshtml.dll [-] 2013-02-02 . 1CD82D510D370CB04BB6BD1C660AA96F . 17815040 . . [9.00.8112.20580] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20580_none_88290dd70e1c6be0\mshtml.dll [-] 2013-02-02 . 460723A080D6F22E56D45BC8C1F15B2A . 17815040 . . [9.00.8112.16470] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16470_none_87aa40f7f4f6b025\mshtml.dll [-] 2013-01-09 . 14DEB733ACB08A71CC0783ED02FF1F8D . 17812992 . . [9.00.8112.16464] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16464_none_87b9120bf4eaf990\mshtml.dll [-] 2013-01-09 . B6C5BC6D4E1D79CB8DF107112A9F37CB . 17814528 . . [9.00.8112.20573] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20573_none_8836dea10e119bf4\mshtml.dll [-] 2012-11-14 . CFF3C4ABDCC5356B0674743BDF0FB674 . 17811968 . . [9.00.8112.16457] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16457_none_87c6e2d5f4e029a4\mshtml.dll [-] 2012-11-14 . 5024CACD183E4C0FCCDE6DB8A38EEC7B . 17811968 . . [9.00.8112.20565] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20565_none_8843af210e07b2b1\mshtml.dll [-] 2012-10-08 . 6D4F838E72EEEB3D6FB16A5A45632560 . 17811968 . . [9.00.8112.16455] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16455_none_87c4e241f4e1f6f6\mshtml.dll [-] 2012-10-08 . 1FB8062D4C3A4C7B8ECA7BBD1E743000 . 17812992 . . [9.00.8112.20562] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20562_none_8840ae430e0a66ac\mshtml.dll [-] 2012-08-24 . F244DA6DD2C365ABAFD076222C22C2BE . 17810944 . . [9.00.8112.16450] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16450_none_87bfe0cff4e67843\mshtml.dll [-] 2012-08-24 . 522A528C296A9AEF3F0C289FF7093315 . 17810944 . . [9.00.8112.20557] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20557_none_88507fa10dfdc96e\mshtml.dll [-] 2012-06-29 . 8415F4792D7BC07BE328DF56FE32045A . 17809920 . . [9.00.8112.16448] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16448_none_87d2b30bf4d7270a\mshtml.dll [-] 2012-06-29 . C4DE0E2B31F60ACB15E6B4154E26298A . 17809920 . . [9.00.8112.20554] .. c:\windows\winsxs\amd64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20554_none_884d7ec30e007d69\mshtml.dll [-] 2014-07-25 . ECA387DCD57F683C52171C766CF400F0 . 23645696 . . [11.00.9600.17239] .. c:\windows\system32\mshtml.dll . [-] 2011-12-16 . C391FC68282A000CDF953F8B6B55D2EF . 634880 . . [7.0.7601.17744] .. c:\windows\winsxs\amd64_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7601.17744_none_2f5acf97b59df60f\msvcrt.dll [-] 2011-12-16 . F9A4C695C86CC32048FE2C987A0BD387 . 634880 . . [7.0.7601.21878] .. c:\windows\winsxs\amd64_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7601.21878_none_2fc7fdc6ced04f08\msvcrt.dll [-] 2009-07-14 . 7319BB10FA1F86E49E3DCF4136F6C957 . 634880 . . [7.0.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7600.16385_none_2d4a27c7b8972454\msvcrt.dll [-] 2011-12-16 . C391FC68282A000CDF953F8B6B55D2EF . 634880 . . [7.0.7601.17744] .. c:\windows\system32\msvcrt.dll . [-] 2013-09-08 . 9A9F9F1A77D6A80EE28B57664F00013E . 327168 . . [6.1.7601.18254] .. c:\windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_164e004b440bdabf\mswsock.dll [-] 2013-09-07 . BDDB1FD258B92DEE00F222D3304B5D9C . 327168 . . [6.1.7601.22444] .. c:\windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.22444_none_16e26ee85d215bbf\mswsock.dll [-] 2010-11-21 . 1D5185A4C7E6695431AE4B55C3D7D333 . 326144 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_16795c7543eb48cf\mswsock.dll [-] 2013-09-08 . 9A9F9F1A77D6A80EE28B57664F00013E . 327168 . . [6.1.7600.16385] .. c:\windows\system32\mswsock.dll . [-] 2010-11-21 . AA339DD8BB128EF66660DFBBB59043D3 . 695808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll [-] 2010-11-21 . AA339DD8BB128EF66660DFBBB59043D3 . 695808 . . [6.1.7600.16385] .. c:\windows\system32\netlogon.dll . [-] 2009-07-14 . 716175021BDA290504CE434273F666BC . 167424 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.1.7600.16385_none_ff0e900816896618\powrprof.dll [-] 2009-07-14 . 716175021BDA290504CE434273F666BC . 167424 . . [6.1.7600.16385] .. c:\windows\system32\powrprof.dll . [-] 2010-11-21 . ED78427259134C63ED69804D2132B86C . 232960 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll [-] 2010-11-21 . ED78427259134C63ED69804D2132B86C . 232960 . . [6.1.7600.16385] .. c:\windows\system32\scecli.dll . [-] 2009-07-14 . C6DCD1D11ED6827F05C00773C3E7053C . 3072 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-sfc_31bf3856ad364e35_6.1.7600.16385_none_032ab4f375e2ac1f\sfc.dll [-] 2009-07-14 . C6DCD1D11ED6827F05C00773C3E7053C . 3072 . . [6.1.7600.16385] .. c:\windows\system32\sfc.dll . [-] 2009-07-14 . C78655BC80301D76ED4FEF1C1EA40A7D . 27136 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe [-] 2009-07-14 . C78655BC80301D76ED4FEF1C1EA40A7D . 27136 . . [6.1.7600.16385] .. c:\windows\system32\svchost.exe . [-] 2010-11-21 . 40F0849F65D13EE87B9A9AE3C1DD6823 . 316928 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-tapiservice_31bf3856ad364e35_6.1.7601.17514_none_4162de4afb9222c0\tapisrv.dll [-] 2010-11-21 . 40F0849F65D13EE87B9A9AE3C1DD6823 . 316928 . . [6.1.7600.16385] .. c:\windows\system32\tapisrv.dll . [-] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll [-] 2010-11-21 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll . [-] 2010-11-21 . BAFE84E637BF7388C96EF48D4D3FDD53 . 30720 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe [-] 2010-11-21 . BAFE84E637BF7388C96EF48D4D3FDD53 . 30720 . . [6.1.7600.16385] .. c:\windows\system32\userinit.exe . [-] 2014-07-25 . 8E71A5CB5312B8392D4DA4CA37BB5868 . 2266624 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17239_none_e45691cbb6d03bc9\wininet.dll [-] 2014-06-18 . 2EE102DF0EDD8A1EDD3D1E9B99A91BEC . 2266112 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17207_none_e453be7db6d2bc82\wininet.dll [-] 2014-05-30 . 40BFD9D6EC8E174145F012246CA73CCD . 2266112 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17126_none_e460a5c5b6c8b99e\wininet.dll [-] 2014-03-06 . F220BA78AB542C70211D73AE4729B2CD . 2260480 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17041_none_e46de82db6be5036\wininet.dll [-] 2014-03-01 . DF79CE9B950C62677D232154E93A81C7 . 2334208 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16521_none_e435d617b6e8ac16\wininet.dll [-] 2014-02-06 . 263B6E451526A90FF8B1CEC759F22956 . 2334208 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16518_none_e4343655b6ea4626\wininet.dll [-] 2013-11-26 . 9B6678DB9C6A232C5A84D2FDFFF8B0E1 . 2334208 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16476_none_e445358db6dc8efd\wininet.dll [-] 2013-11-26 . E6CB36B85BE59095337427E853A5B65A . 2332160 . . [11.00.9600.16428] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16428_none_e440068bb6e1438c\wininet.dll [-] 2013-10-12 . 9706C99DAEBE3FEAC811B239617E98C4 . 2241536 . . [10.00.9200.16736] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16736_none_7fad7b9c12568107\wininet.dll [-] 2013-10-12 . 7E7F32C588DA6A4554046804D8EEAC55 . 2249216 . . [10.00.9200.20848] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20848_none_68d5d7ce2c054946\wininet.dll [-] 2013-09-22 . 1377A310439639A610097ED56975AE19 . 2248704 . . [10.00.9200.20830] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20831_none_68d576fc2c057c88\wininet.dll [-] 2013-09-22 . D28B35DE88D27EFB27DF4B1E8319E3C0 . 2241024 . . [10.00.9200.16720] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16721_none_7faced3a1256e78b\wininet.dll [-] 2013-08-10 . AAFA952E774DDDB0956D3BDFAE5B5B99 . 2241024 . . [10.00.9200.16686] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16686_none_7fbd4cfa1249e3c9\wininet.dll [-] 2013-08-10 . 0A380C8E396975463E3F643E88AE8BDF . 2248704 . . [10.00.9200.20794] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20794_none_68e6044c2bf84584\wininet.dll [-] 2013-07-26 . AC155DD9BD1E6D3B740826A4D1C68AAE . 2241024 . . [10.00.9200.16660] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16660_none_7fbbd516124b1755\wininet.dll [-] 2013-07-26 . 5C49F5A791B944AD8247473ABD35602D . 2248704 . . [10.00.9200.20768] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20768_none_68e2a84e2bfb6003\wininet.dll [-] 2013-07-02 . 1E79B157B16DF86CBF2BC521AA07301D . 2241024 . . [10.00.9200.16618] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16618_none_7fb61d64125065aa\wininet.dll [-] 2013-06-12 . 09BF0D9701F9D846BBC5ABED003851CB . 2248704 . . [10.00.9200.20742] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20742_none_68e1306a2bfc938f\wininet.dll [-] 2013-06-11 . FAF6EC2460AD5FBBD38D8E1AE28B0D77 . 2241024 . . [10.00.9200.16635] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16635_none_7fb86250124e4b75\wininet.dll [-] 2013-05-17 . 4FBE96D97A1E070A06F76F67255C756D . 1392128 . . [9.00.8112.16490] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16490_none_763a820174b07ed1\wininet.dll [-] 2013-05-17 . 5548A99796DB5DDAA32ED9B53BC3AADC . 1392640 . . [9.00.8112.20600] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20600_none_77256ffe8d852049\wininet.dll [-] 2013-04-05 . 563C71A913CAC0C3DE5FFCD36EDB43A0 . 1392128 . . [9.00.8112.16483] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16483_none_764852cb74a5aee5\wininet.dll [-] 2013-04-04 . 7FD2D2BE22F9A319AB2FD23DD2C9968A . 1392640 . . [9.00.8112.20593] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20593_none_76c71faa8dcb6aa0\wininet.dll [-] 2013-02-22 . E6A459C8E90C4A873C923C44F3D9510B . 1392640 . . [9.00.8112.20586] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20586_none_76d4f0748dc09ab4\wininet.dll [-] 2013-02-22 . A4F6142CABA82FB7293ECE5FF864B440 . 1392128 . . [9.00.8112.16476] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16476_none_76562395749adef9\wininet.dll [-] 2013-02-02 . 4E0669B513805A7C2A303C8EDEDC8E03 . 1392128 . . [9.00.8112.20580] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20580_none_76ceeeb88dc602aa\wininet.dll [-] 2013-02-02 . FA274190682AA41A46B285208ED46A74 . 1392128 . . [9.00.8112.16470] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16470_none_765021d974a046ef\wininet.dll [-] 2013-01-09 . 435E9C764E1EF70058580996452BE6A2 . 1392128 . . [9.00.8112.16464] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16464_none_765ef2ed7494905a\wininet.dll [-] 2013-01-08 . 43A6A68F1F41B13CA4D580D40DFA57EE . 1392128 . . [9.00.8112.20573] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20573_none_76dcbf828dbb32be\wininet.dll [-] 2012-11-14 . 5121DB613E10A46A3C5085B479026AA7 . 1392128 . . [9.00.8112.16457] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16457_none_766cc3b77489c06e\wininet.dll [-] 2012-11-14 . 5CAF48F12E8CBD96D520F4EFD5B97F76 . 1392128 . . [9.00.8112.20565] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20565_none_76e990028db1497b\wininet.dll [-] 2012-10-08 . A19DB004D954BBC9C4EC125711E1D1C2 . 1392128 . . [9.00.8112.16455] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16455_none_766ac323748b8dc0\wininet.dll [-] 2012-10-08 . 789EAD6F3CE42F3322818988400986E9 . 1392128 . . [9.00.8112.20562] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20562_none_76e68f248db3fd76\wininet.dll [-] 2012-08-24 . 3D165C53E40236A68B7102D1A622D4E0 . 1392128 . . [9.00.8112.16450] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16450_none_7665c1b174900f0d\wininet.dll [-] 2012-08-24 . 456D4E9006DF149C250D40B813290471 . 1392128 . . [9.00.8112.20557] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20557_none_76f660828da76038\wininet.dll [-] 2012-06-29 . 8EA68FD3780DDDD5072F8CB830B3CB3D . 1392128 . . [9.00.8112.16448] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16448_none_767893ed7480bdd4\wininet.dll [-] 2012-06-29 . 8BA7EDA2656ED7FBC93BDD5CB02B8D4E . 1392128 . . [9.00.8112.20554] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20554_none_76f35fa48daa1433\wininet.dll [-] 2012-06-07 . B1AC85B6ADC005CF3F9EB4E28DFDCCE6 . 1390080 . . [9.00.8112.16441] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16441_none_767191e774870c73\wininet.dll [-] 2012-06-02 . 5A45FA344F4AD99D903F4B20E43B89EC . 1392128 . . [9.00.8112.16447] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16447_none_767793a37481a47d\wininet.dll [-] 2012-06-02 . 571E809181EBF0A04FEFAA9BC9961F5B . 1392128 . . [9.00.8112.20553] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20553_none_76f25f5a8daafadc\wininet.dll [-] 2012-05-18 . 870ECFEBD41C7B8F9C6777748368D51F . 1392128 . . [9.00.8112.16446] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16446_none_7676935974828b26\wininet.dll [-] 2012-05-18 . BDC16D105BF011D4B1C3F09CF7A64314 . 1392128 . . [9.00.8112.20551] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20551_none_76f05ec68dacc82e\wininet.dll [-] 2012-02-28 . 228443FF3A1FB0B974D278F7C6403FAD . 1390080 . . [9.00.8112.16443] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16443_none_7673927b74853f21\wininet.dll [-] 2012-02-28 . DE03C917EDED2A999C942A4F943D3068 . 1188864 . . [8.00.7601.17785] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17785_none_7a7e94c62fac6be0\wininet.dll [-] 2012-02-28 . 05ED629EB0A11CAFB87EFB7847943312 . 1189376 . . [8.00.7601.21931] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.21931_none_7b3a41eb48a517c0\wininet.dll [-] 2012-02-28 . B70CDC073F70E6D082A62AB5880D6B07 . 1390080 . . [9.00.8112.20548] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20548_none_770230b88d9e5d9e\wininet.dll [-] 2010-11-21 . F6C5302E1F4813D552F41A0AC82455E5 . 1188864 . . [8.00.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17514_none_7ac940242f7494a4\wininet.dll [-] 2014-07-25 . 8E71A5CB5312B8392D4DA4CA37BB5868 . 2266624 . . [11.00.9600.16428] .. c:\windows\system32\wininet.dll . [-] 2010-11-21 . 4BBFA57F594F7E8A8EDC8F377184C3F0 . 297984 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_50ddb631e4f59005\ws2_32.dll [-] 2010-11-21 . 4BBFA57F594F7E8A8EDC8F377184C3F0 . 297984 . . [6.1.7600.16385] .. c:\windows\system32\ws2_32.dll . [-] 2009-07-14 . 8396C6C26AADDFE4590CCEF0F419B6B7 . 4608 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\ws2help.dll [-] 2009-07-14 . 8396C6C26AADDFE4590CCEF0F419B6B7 . 4608 . . [6.1.7600.16385] .. c:\windows\system32\ws2help.dll . [-] 2010-11-21 . 6C60B5ACA7442EFB794082CDACFC001C . 2086912 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.1.7601.17514_none_0a43accb08f0eac5\ole32.dll [-] 2010-11-21 . 6C60B5ACA7442EFB794082CDACFC001C . 2086912 . . [6.1.7600.16385] .. c:\windows\system32\ole32.dll . [-] 2009-07-14 . 86FE1B1F8FD42CD0DB641AB1CDB13093 . 18944 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll [-] 2009-07-14 . 86FE1B1F8FD42CD0DB641AB1CDB13093 . 18944 . . [6.1.7600.16385] .. c:\windows\system32\cngaudit.dll . [-] 2009-07-14 . 94355C28C1970635A31B3FE52EB7CEBA . 129024 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_8ce7aa761e01ad49\wininit.exe [-] 2009-07-14 . 94355C28C1970635A31B3FE52EB7CEBA . 129024 . . [6.1.7600.16385] .. c:\windows\system32\wininit.exe . [-] 2009-07-14 . 42B6A94DD747DF2B5F628A2752E62A98 . 9728 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.1.7600.16385_none_f9257e7aaa4290ce\ctfmon.exe [-] 2009-07-14 . 42B6A94DD747DF2B5F628A2752E62A98 . 9728 . . [6.1.7600.16385] .. c:\windows\system32\ctfmon.exe . [-] 2010-11-21 . AAF932B4011D14052955D4B212A4DA8D . 370688 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.1.7601.17514_none_2b566299338d2123\shsvcs.dll [-] 2010-11-21 . AAF932B4011D14052955D4B212A4DA8D . 370688 . . [6.1.7600.16385] .. c:\windows\system32\shsvcs.dll . |
27.08.2014, 19:39 | #7 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung log.txt Teil 2: Code:
ATTFilter [-] 2009-07-14 . E4D94F24081440B5FC5AA556C7C62702 . 159232 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-remoteregistry-service_31bf3856ad364e35_6.1.7600.16385_none_e55af7609d2857a8\regsvc.dll [-] 2009-07-14 . E4D94F24081440B5FC5AA556C7C62702 . 159232 . . [6.1.7600.16385] .. c:\windows\system32\regsvc.dll . [-] 2010-11-21 . 262F6592C3299C005FD6BEC90FC4463A . 1110016 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.1.7601.17514_none_8d272400ada202f9\schedsvc.dll [-] 2010-11-21 . 262F6592C3299C005FD6BEC90FC4463A . 1110016 . . [6.1.7600.16385] .. c:\windows\system32\schedsvc.dll . [-] 2009-07-14 . 51B52FBD583CDE8AA9BA62B8B4298F33 . 193024 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-upnpssdp_31bf3856ad364e35_6.1.7600.16385_none_dbbe6492eae9505c\ssdpsrv.dll [-] 2009-07-14 . 51B52FBD583CDE8AA9BA62B8B4298F33 . 193024 . . [6.1.7600.16385] .. c:\windows\system32\ssdpsrv.dll . [-] 2010-11-21 . 2E648163254233755035B46DD7B89123 . 680960 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.1.7601.17514_none_ecc547376ae3a1a3\termsrv.dll [-] 2010-11-21 . 2E648163254233755035B46DD7B89123 . 680960 . . [6.1.7601.17514] .. c:\windows\system32\termsrv.dll . [-] 2009-07-14 . 8560FFFC8EB3A806DCD4F82252CFC8C6 . 5120 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-d..tshow-kernelsupport_31bf3856ad364e35_6.1.7601.17514_none_4627a1cbadebced2\ksuser.dll [-] 2009-07-14 . 8560FFFC8EB3A806DCD4F82252CFC8C6 . 5120 . . [6.1.7600.16385] .. c:\windows\system32\ksuser.dll . [-] 2009-07-14 . E424B3EF666B184CEE0B6871AAA8C9F6 . 8192 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi-painting_31bf3856ad364e35_6.1.7600.16385_none_d360c9c235bd1868\msimg32.dll [-] 2009-07-14 . E424B3EF666B184CEE0B6871AAA8C9F6 . 8192 . . [6.1.7600.16385] .. c:\windows\system32\msimg32.dll . [-] 2013-07-04 . 700BD5A6AA5381D1D8ADC4045149DBF6 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.22376_none_3bee2a494f8638cf\comctl32.dll [-] 2013-07-04 . 700BD5A6AA5381D1D8ADC4045149DBF6 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.22376_none_ee67d2d082b9f619\comctl32.dll [-] 2013-07-04 . 75F5E1FE8D55CF8E577E0EC5F2290D3F . 530432 . . [5.82] .. c:\windows\SysWOW64\comctl32.dll [-] 2013-07-04 . 75F5E1FE8D55CF8E577E0EC5F2290D3F . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.18201_none_3bab3b80363456bb\comctl32.dll [-] 2013-07-04 . 75F5E1FE8D55CF8E577E0EC5F2290D3F . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll [-] 2010-11-21 . BDAC1AA64495D0F7E1FF810EBBF1F018 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll [-] 2010-11-21 . BDAC1AA64495D0F7E1FF810EBBF1F018 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.17514_none_3ba388ec36399c85\comctl32.dll [-] 2010-11-21 . 352B3DC62A0D259A82A052238425C872 . 1680896 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll . [-] 2013-10-05 . F2D9242C3BBD1C36467FCAE1AE01733F . 142848 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22473_none_784ea5b51260b460\cryptsvc.dll [-] 2013-07-09 . 6DB499DEFCC827317C5371164A7CDB27 . 142848 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_7840d305126b8725\cryptsvc.dll [-] 2013-07-09 . 7CA1BECEA5DE2643ADDAD32670E7A4C9 . 140288 . . [6.1.7600.16385] .. c:\windows\SysWOW64\cryptsvc.dll [-] 2013-07-09 . 7CA1BECEA5DE2643ADDAD32670E7A4C9 . 140288 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_7812b70bf9088686\cryptsvc.dll [-] 2013-05-13 . 3897DFF247D9ED0006190349DE264E14 . 140288 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_77d8a461f934afb8\cryptsvc.dll [-] 2013-05-11 . AC04D05309BB2C418D0D80B9FB014642 . 142848 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_7883b3211239122d\cryptsvc.dll [-] 2013-05-10 . E122AA1C9A3CC46FF9DDDE46E5EB0C58 . 142848 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22321_none_7882b2d71239f8d6\cryptsvc.dll [-] 2013-05-10 . 33ADF6E0853AB39EA1723BE82842C1D3 . 140288 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18150_none_77d7a417f9359661\cryptsvc.dll [-] 2012-06-02 . 063DD65889D21035311463337BD268E7 . 142336 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_788c7cc71232cc19\cryptsvc.dll [-] 2012-06-02 . 96C0E38905CFD788313BE8E11DAE3F2F . 140288 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_77ddc9e5f93000db\cryptsvc.dll [-] 2012-04-24 . 06E771AA596B8761107AB57E99F128D7 . 140288 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17827_none_77ff39f3f916c65f\cryptsvc.dll [-] 2012-04-24 . 21993009E0CCB9B4FA195F14D3408626 . 142336 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.21979_none_7854c7b7125b248c\cryptsvc.dll [-] 2010-11-21 . A585BEBF7D054BD9618EDA0922D5484A . 136192 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll . [-] 2009-07-14 . F6916EFC29D9953D5D0DF06882AE8E16 . 271360 . . [2001.12.8530.16385] .. c:\windows\SysWOW64\es.dll [-] 2009-07-14 . F6916EFC29D9953D5D0DF06882AE8E16 . 271360 . . [2001.12.8530.16385] .. c:\windows\winsxs\wow64_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.1.7600.16385_none_73373b169fcf68cb\es.dll . [-] 2010-11-21 . A6F09E5669D9A19035F6D942CAA15882 . 119808 . . [6.1.7601.17514] .. c:\windows\SysWOW64\imm32.dll [-] 2010-11-21 . A6F09E5669D9A19035F6D942CAA15882 . 119808 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.1.7601.17514_none_c4d0cdd7c56b493e\imm32.dll . [-] 2014-04-12 . C8C41EBEE097FEB29FB816854D3AD1E7 . 1114112 . . [6.1.7601.22653] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22653_none_fc95db0bba8ae4c2\kernel32.dll [-] 2014-03-04 . 866696FBE24914047462E34812169954 . 1114112 . . [6.1.7601.22616] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22616_none_fcc41b99ba67c103\kernel32.dll [-] 2014-03-04 . 76161B9D78A275F8F28DD67436013110 . 1114112 . . [6.1.7601.18015] .. c:\windows\SysWOW64\kernel32.dll [-] 2014-03-04 . 76161B9D78A275F8F28DD67436013110 . 1114112 . . [6.1.7601.18015] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18409_none_fc484db2a13f5426\kernel32.dll [-] 2013-08-29 . EE751CBD5D0C332FDF3DF7187B612416 . 1114112 . . [6.1.7601.22436] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22436_none_fcae77f5ba77fe97\kernel32.dll [-] 2013-08-02 . 61579F821AB5FF7FA2966D64D1070BA8 . 1114112 . . [6.1.7601.22411] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22411_none_fcbf165bba6c4802\kernel32.dll [-] 2013-08-02 . 365A5034093AD9E04F433046C4CDF6AB . 1114112 . . [6.1.7601.18229] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18229_none_fc32aa0ea14f91ba\kernel32.dll [-] 2013-07-08 . 2997A7BC59E3EEFE8E86D1B0F3A3D748 . 1114112 . . [6.1.7601.22379] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22379_none_fc86373dba95bd39\kernel32.dll [-] 2013-01-04 . 7E55988F5CB3BA67E2732370E8D71BBB . 1114112 . . [6.1.7601.22209] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22209_none_fcd1e4cbba5cfc7b\kernel32.dll [-] 2012-11-30 . 9CC2571E3646B9A24296AD7ADCC71682 . 1114112 . . [6.1.7601.22177] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22177_none_fc8432ddba97903d\kernel32.dll [-] 2012-11-30 . AC0B6F41882FC6ED186962D770EBF1D2 . 1114112 . . [6.1.7601.18015] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18015_none_fc397506a14b161f\kernel32.dll [-] 2012-10-04 . D4F3176082566CEFA633B4945802D4C4 . 1114112 . . [6.1.7601.17965] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17965_none_fc038d48a1736e92\kernel32.dll [-] 2012-10-04 . 5FA395364EE727E4BEE6B1406C207F98 . 1114112 . . [6.1.7601.22125] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22125_none_fcb841e5ba70d1da\kernel32.dll [-] 2012-08-20 . 9B98D47916EAD4F69EF51B56B0C2323C . 1114112 . . [6.1.7601.17932] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17932_none_fc20fc2ea15dceba\kernel32.dll [-] 2012-08-20 . 305681B4B695D4A888B941965FFC2C17 . 1114112 . . [6.1.7601.22091] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22091_none_fc688f63baad32ee\kernel32.dll [-] 2011-07-16 . D3CB12854171DF61D117D7C2BF22C675 . 1114112 . . [6.1.7601.21772] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.21772_none_fc7f5397ba9be6d3\kernel32.dll [-] 2011-07-16 . 99C3F8E9CC59D95666EB8D8A8B4C2BEB . 1114112 . . [6.1.7601.17651] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17651_none_fc0a565aa16ef5d0\kernel32.dll [-] 2010-11-21 . E80758CF485DB142FCA1EE03A34EAD05 . 837632 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17514_none_fc389502a14bd4ea\kernel32.dll . [-] 2009-07-14 . 5987EA8A82C53359BCD2C29D6588583E . 22016 . . [6.1.7600.16385] .. c:\windows\SysWOW64\linkinfo.dll [-] 2009-07-14 . 5987EA8A82C53359BCD2C29D6588583E . 22016 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-linkinfo_31bf3856ad364e35_6.1.7600.16385_none_9eaece15f365da54\linkinfo.dll . [-] 2013-06-06 . 84CA3579EEB69D8E1EE67E4F721BF71C . 25600 . . [6.1.7601.22350] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22350_none_12a807b2bec875e6\lpk.dll [-] 2013-06-06 . CC23295DA8F7B5C53F93804D2F5D30EB . 25600 . . [6.1.7601.18177] .. c:\windows\SysWOW64\lpk.dll [-] 2013-06-06 . CC23295DA8F7B5C53F93804D2F5D30EB . 25600 . . [6.1.7601.18177] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18177_none_120fcb2fa5b4c238\lpk.dll [-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_124dc839a586a988\lpk.dll [-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17563_none_1216b853a5b01be6\lpk.dll [-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17991_none_11f44f93a5ca31a7\lpk.dll [-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18032_none_12360787a598d69a\lpk.dll [-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21664_none_12a15568beccd507\lpk.dll [-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22153_none_12ab04c4bec5c79d\lpk.dll [-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_1281c5a8bee46a0f\lpk.dll . [-] 2014-07-25 . 8453DDF167CE2986AA4AB04BC6824925 . 17524224 . . [11.00.9600.17239] .. c:\windows\SysWOW64\mshtml.dll [-] 2014-07-25 . 8453DDF167CE2986AA4AB04BC6824925 . 17524224 . . [11.00.9600.17239] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17239_none_00055b3c6b8766fa\mshtml.dll [-] 2014-06-19 . DFA59840BB1220AFD261FDAE83543959 . 17276416 . . [11.00.9600.17207] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17207_none_000287ee6b89e7b3\mshtml.dll [-] 2014-05-30 . D5ECBB3BFDC73A59440D9CA79AB3A342 . 17271296 . . [11.00.9600.17126] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17126_none_000f6f366b7fe4cf\mshtml.dll [-] 2014-05-08 . 0C81FB54D859FA2BA2680C7803A77CB6 . 17073152 . . [11.00.9600.16663] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16663_none_ffdda3346ba48bd6\mshtml.dll [-] 2014-03-30 . CCF19C82F6145E4A467F7CB9AF82026C . 17073152 . . [11.00.9600.16659] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16659_none_ffdc1a3a6ba60c45\mshtml.dll [-] 2014-03-06 . EA85144F35EDE6EE25C484D4242FF2C8 . 17387008 . . [11.00.9600.17041] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.17041_none_001cb19e6b757b67\mshtml.dll [-] 2014-03-01 . 70462E0A4E293FC80620AB945D8A59BB . 17074688 . . [11.00.9600.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16521_none_ffe49f886b9fd747\mshtml.dll [-] 2014-02-06 . C863E5A2417DF0F2A31ED32C3B2CB23F . 17103872 . . [11.00.9600.16518] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16518_none_ffe2ffc66ba17157\mshtml.dll [-] 2013-11-26 . BFAFE990C4A191E83843362B5AC64A9B . 17112576 . . [11.00.9600.16476] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16476_none_fff3fefe6b93ba2e\mshtml.dll [-] 2013-11-26 . F9F114B2A6F876C92D317A755494F233 . 17142784 . . [11.00.9600.16428] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_11.2.9600.16428_none_ffeecffc6b986ebd\mshtml.dll [-] 2013-10-12 . 02A04841906A8892AD6CC7BDBCB5F61D . 14355968 . . [10.00.9200.16736] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16736_none_9b5c450cc70dac38\mshtml.dll [-] 2013-10-12 . 9C2714E4CF56DD8CD27BF6DEE9E7A1BF . 14381568 . . [10.00.9200.20848] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20848_none_8484a13ee0bc7477\mshtml.dll [-] 2013-09-22 . 9D6D52AED095BC8C9023AA739E978EAC . 14364672 . . [10.00.9200.20831] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20831_none_8484406ce0bca7b9\mshtml.dll [-] 2013-09-22 . A7221924181C8EB92B64C5A2D888BEA5 . 14335488 . . [10.00.9200.16721] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16721_none_9b5bb6aac70e12bc\mshtml.dll [-] 2013-08-10 . A0FAB45701EFAA4EDA60B7614ED431BE . 14362624 . . [10.00.9200.20794] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20794_none_8494cdbce0af70b5\mshtml.dll [-] 2013-08-10 . 5D2D7E7850CE963C2F401D4DEE7BB32A . 14332928 . . [10.00.9200.16686] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16686_none_9b6c166ac7010efa\mshtml.dll [-] 2013-07-26 . E631B408882F8320739F6E0CAF444397 . 14329344 . . [10.00.9200.16660] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16660_none_9b6a9e86c7024286\mshtml.dll [-] 2013-07-26 . 523D2E830830FD6DA5B7FAAE3C251BC5 . 14356480 . . [10.00.9200.20768] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20768_none_849171bee0b28b34\mshtml.dll [-] 2013-07-02 . 05920BD009621D06722A1CD339DA6481 . 14327808 . . [10.00.9200.16618] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16618_none_9b64e6d4c70790db\mshtml.dll [-] 2013-06-12 . E6CC3F7EAA761794E13E0F99393EEB97 . 14358528 . . [10.00.9200.20742] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20742_none_848ff9dae0b3bec0\mshtml.dll [-] 2013-06-11 . AF31E7D2C385F647ADFD5F5736B3BA64 . 14329856 . . [10.00.9200.16635] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16635_none_9b672bc0c70576a6\mshtml.dll [-] 2013-05-16 . A6F5B25905CD01AE714990E02C7205A5 . 12329984 . . [9.00.8112.16490] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16490_none_91e94b722967aa02\mshtml.dll [-] 2013-05-16 . 097654708FE5F07278A1E36D9F78CA94 . 12330496 . . [9.00.8112.20600] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20600_none_92d4396f423c4b7a\mshtml.dll [-] 2013-05-05 . 1152DE9D7FE16EC92A12165D1CBE8406 . 12325888 . . [9.00.8112.20594] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20594_none_9276e9654281af28\mshtml.dll [-] 2013-05-05 . 26F30066B9FA78C97A0E92803D496211 . 12324864 . . [9.00.8112.16484] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16484_none_91f81c86295bf36d\mshtml.dll [-] 2013-04-04 . 79B0D843B26BEA808EA89BA2D8A026F2 . 12324864 . . [9.00.8112.16483] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16483_none_91f71c3c295cda16\mshtml.dll [-] 2013-04-04 . 4EBF337D1F52EA9202072348BA41CA95 . 12325376 . . [9.00.8112.20593] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20593_none_9275e91b428295d1\mshtml.dll [-] 2013-02-22 . 474D43D76E2A33FEE21C6F4BB7C4A3B7 . 12324864 . . [9.00.8112.20586] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20586_none_9283b9e54277c5e5\mshtml.dll [-] 2013-02-22 . 658EBC74BD38D16805648C4775F7FA82 . 12324352 . . [9.00.8112.16476] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16476_none_9204ed0629520a2a\mshtml.dll [-] 2013-02-02 . 88C27474E61271B49677F22CEE76FB3E . 12322304 . . [9.00.8112.20580] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20580_none_927db829427d2ddb\mshtml.dll [-] 2013-02-02 . 263963D93A3CA8F685EFA5966F1E6581 . 12321792 . . [9.00.8112.16470] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16470_none_91feeb4a29577220\mshtml.dll [-] 2013-01-08 . C97434C851C4821BD92D2831FDF1ECBE . 12321280 . . [9.00.8112.16464] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16464_none_920dbc5e294bbb8b\mshtml.dll [-] 2013-01-08 . B6AD225B3BCC07332FBB2C2824315534 . 12322304 . . [9.00.8112.20573] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20573_none_928b88f342725def\mshtml.dll [-] 2012-11-14 . 07F649CD36F266BBE33B814FA678AA43 . 12320256 . . [9.00.8112.16457] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16457_none_921b8d282940eb9f\mshtml.dll [-] 2012-11-14 . 8021EF27048F9ECE5286EA8C8EED23B8 . 12321280 . . [9.00.8112.20565] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20565_none_92985973426874ac\mshtml.dll [-] 2012-10-08 . 8D1BB1E5A033E8817EF94A9047630165 . 12320768 . . [9.00.8112.16455] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16455_none_92198c942942b8f1\mshtml.dll [-] 2012-10-08 . F7B251DA2FA89933771289793DCAA08B . 12321280 . . [9.00.8112.20562] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20562_none_92955895426b28a7\mshtml.dll [-] 2012-08-24 . 975D1EA99A0FE8104B72440995B3C20B . 12319744 . . [9.00.8112.20557] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20557_none_92a529f3425e8b69\mshtml.dll [-] 2012-08-24 . BB197F54A8F69EEA8356B7F70E6D3A20 . 12319744 . . [9.00.8112.16450] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16450_none_92148b2229473a3e\mshtml.dll [-] 2012-06-29 . 5E8E869E1342308752A37A2C90CCA79D . 12317184 . . [9.00.8112.16448] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16448_none_92275d5e2937e905\mshtml.dll [-] 2012-06-28 . AEC51857AEC2F5CE4520366240AFC671 . 12317184 . . [9.00.8112.20554] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20554_none_92a2291542613f64\mshtml.dll [-] 2012-06-07 . 497C9C3DB953A60EC4F43A097E15F75E . 12282368 . . [9.00.8112.16441] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16441_none_92205b58293e37a4\mshtml.dll [-] 2012-06-02 . 6820A9E91AFF7CB3A510360D8CCD9BDD . 12314624 . . [9.00.8112.16447] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16447_none_92265d142938cfae\mshtml.dll [-] 2012-06-02 . 1ABF770552EA9D4FE90F654468FAF4CE . 12314624 . . [9.00.8112.20553] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20553_none_92a128cb4262260d\mshtml.dll [-] 2012-05-17 . 9FB58F71104107D44540AF1195F7A14D . 12314624 . . [9.00.8112.16446] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16446_none_92255cca2939b657\mshtml.dll [-] 2012-05-17 . 761D9111F5A2619CB5060661D36FBFFF . 12314624 . . [9.00.8112.20551] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20551_none_929f28374263f35f\mshtml.dll [-] 2012-02-28 . 624A8FC27001639D08F3558FBB607187 . 5998080 . . [8.00.7601.17785] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17785_none_962d5e36e4639711\mshtml.dll [-] 2012-02-28 . 07B90528507189F3DD6AA132FDAA23BB . 5998592 . . [8.00.7601.21931] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.21931_none_96e90b5bfd5c42f1\mshtml.dll [-] 2012-02-28 . F82BF2CB075B49E9FAB5FF213C45C020 . 12281856 . . [9.00.8112.16443] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16443_none_92225bec293c6a52\mshtml.dll [-] 2012-02-28 . B9E083B14B1994F1255983F2DF31C7DF . 12281856 . . [9.00.8112.20548] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20548_none_92b0fa29425588cf\mshtml.dll [-] 2010-11-21 . C50799F0D47DFB9774F721521B6C41D5 . 5977600 . . [8.00.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17514_none_96780994e42bbfd5\mshtml.dll . [-] 2011-12-16 . 2F740C4B458331357E825E94AFB0953A . 690688 . . [7.0.7601.21878] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7601.21878_none_d3a962431672ddd2\msvcrt.dll [-] 2011-12-16 . 9DC80A8AAAAAC397BDAB3C67165A824E . 690688 . . [7.0.7601.17744] .. c:\windows\SysWOW64\msvcrt.dll [-] 2011-12-16 . 9DC80A8AAAAAC397BDAB3C67165A824E . 690688 . . [7.0.7601.17744] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7601.17744_none_d33c3413fd4084d9\msvcrt.dll [-] 2009-07-14 . E46D48A7FE961401F1CBF85531CDF05D . 690688 . . [7.0.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7600.16385_none_d12b8c440039b31e\msvcrt.dll . [-] 2013-09-08 . E94C583CDE2348950155F2AF2876F34D . 231424 . . [6.1.7600.16385] .. c:\windows\SysWOW64\mswsock.dll [-] 2013-09-08 . E94C583CDE2348950155F2AF2876F34D . 231424 . . [6.1.7601.18254] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_ba2f64c78bae6989\mswsock.dll [-] 2013-09-07 . 6547D445C4B69DC0083B619AC642DF04 . 231424 . . [6.1.7601.22444] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.22444_none_bac3d364a4c3ea89\mswsock.dll [-] 2010-11-21 . 8999B8631C7FD9F7F9EC3CAFD953BA24 . 232448 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll . [-] 2010-11-21 . C1809B9907ADEDAF16F50C894100883B . 563712 . . [6.1.7600.16385] .. c:\windows\SysWOW64\netlogon.dll [-] 2010-11-21 . C1809B9907ADEDAF16F50C894100883B . 563712 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll . [-] 2009-07-14 . 08DFDBD2FD4EA951DC46B1C7661ED35A . 145408 . . [6.1.7600.16385] .. c:\windows\SysWOW64\powrprof.dll [-] 2009-07-14 . 08DFDBD2FD4EA951DC46B1C7661ED35A . 145408 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.1.7600.16385_none_a2eff4845e2bf4e2\powrprof.dll . [-] 2010-11-21 . 8124944EC89D6A1815E4E53F5B96AAF4 . 175616 . . [6.1.7600.16385] .. c:\windows\SysWOW64\scecli.dll [-] 2010-11-21 . 8124944EC89D6A1815E4E53F5B96AAF4 . 175616 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll . [-] 2009-07-14 . 40CAEEE0EAF1B8569F7C8DF6420F2CB9 . 2560 . . [6.1.7600.16385] .. c:\windows\SysWOW64\sfc.dll [-] 2009-07-14 . 40CAEEE0EAF1B8569F7C8DF6420F2CB9 . 2560 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-sfc_31bf3856ad364e35_6.1.7600.16385_none_a70c196fbd853ae9\sfc.dll . [-] 2009-07-14 . 54A47F6B5E09A77E61649109C6A08866 . 20992 . . [6.1.7600.16385] .. c:\windows\SysWOW64\svchost.exe [-] 2009-07-14 . 54A47F6B5E09A77E61649109C6A08866 . 20992 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe . [-] 2010-11-21 . 613BF4820361543956909043A265C6AC . 242176 . . [6.1.7600.16385] .. c:\windows\SysWOW64\tapisrv.dll [-] 2010-11-21 . 613BF4820361543956909043A265C6AC . 242176 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-tapiservice_31bf3856ad364e35_6.1.7601.17514_none_e54442c74334b18a\tapisrv.dll . [-] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll [-] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll . [-] 2010-11-21 . 61AC3EFDFACFDD3F0F11DD4FD4044223 . 26624 . . [6.1.7600.16385] .. c:\windows\SysWOW64\userinit.exe [-] 2010-11-21 . 61AC3EFDFACFDD3F0F11DD4FD4044223 . 26624 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe . [-] 2014-07-25 . B945BAA81B4805AD6BDDF4D026DCFB47 . 1792512 . . [11.00.9600.16428] .. c:\windows\SysWOW64\wininet.dll [-] 2014-07-25 . B945BAA81B4805AD6BDDF4D026DCFB47 . 1792512 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17239_none_8837f647fe72ca93\wininet.dll [-] 2014-06-18 . CCC198257901BEEA2FBF8EB1E7678356 . 1791488 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17207_none_883522f9fe754b4c\wininet.dll [-] 2014-05-30 . 771CDBC3D62437D6DB070820BB1EDCCF . 1790976 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17126_none_88420a41fe6b4868\wininet.dll [-] 2014-03-06 . E4E829EE073E046B0EB19B5FECB19B8C . 1789440 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.17041_none_884f4ca9fe60df00\wininet.dll [-] 2014-03-01 . AAFEAB4FC9D70253F8C7E353E879E8A2 . 1820160 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16521_none_88173a93fe8b3ae0\wininet.dll [-] 2014-02-06 . 9C89246184979A070B0C6CCF61C68136 . 1820160 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16518_none_88159ad1fe8cd4f0\wininet.dll [-] 2013-11-26 . 927FA6456AD6D7630F6854828D2FD16B . 1820160 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16476_none_88269a09fe7f1dc7\wininet.dll [-] 2013-11-26 . B5EB5BD3066959611E1F7A80FD6CC172 . 1818112 . . [11.00.9600.16428] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.2.9600.16428_none_88216b07fe83d256\wininet.dll [-] 2013-10-12 . 5FD4335DCD343D0FEA9FA6B18ED408D9 . 1767936 . . [10.00.9200.16736] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16736_none_238ee01859f90fd1\wininet.dll [-] 2013-10-12 . 06715E12E72EFBC2D660A779FFF32944 . 1777152 . . [10.00.9200.20848] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20848_none_0cb73c4a73a7d810\wininet.dll [-] 2013-09-22 . 67220EB57550F10E1219D57D89937456 . 1777152 . . [10.00.9200.20830] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20831_none_0cb6db7873a80b52\wininet.dll [-] 2013-09-22 . E4FEB264B47360B7296AEA4E052F88D8 . 1767936 . . [10.00.9200.16720] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16721_none_238e51b659f97655\wininet.dll [-] 2013-08-10 . 26BD13BB9196C2D8F8155C3C6169BC22 . 1777664 . . [10.00.9200.20794] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20794_none_0cc768c8739ad44e\wininet.dll [-] 2013-08-10 . 535F6263035F2530A62D5D64EF6E73D3 . 1767936 . . [10.00.9200.16686] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16686_none_239eb17659ec7293\wininet.dll [-] 2013-07-26 . DAA3903F06116AE9EE7AC1D1B93684A4 . 1767936 . . [10.00.9200.16660] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16660_none_239d399259eda61f\wininet.dll [-] 2013-07-26 . DE581A5E0E70BB63898F8776EB274428 . 1777664 . . [10.00.9200.20768] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20768_none_0cc40cca739deecd\wininet.dll [-] 2013-07-02 . F352DB15FF74AC4A1C48AD12D423B4B1 . 1767936 . . [10.00.9200.16618] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16618_none_239781e059f2f474\wininet.dll [-] 2013-06-12 . 24AE444B165D11835EF3D38CF3CC7FA4 . 1777664 . . [10.00.9200.20742] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20742_none_0cc294e6739f2259\wininet.dll [-] 2013-06-11 . 9BF7C7654EFD098EE3A27B49492A382A . 1767936 . . [10.00.9200.16635] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16635_none_2399c6cc59f0da3f\wininet.dll [-] 2013-05-16 . 6A25377A76479A0C0BF3DB6FC42FE09A . 1129472 . . [9.00.8112.16490] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16490_none_1a1be67dbc530d9b\wininet.dll [-] 2013-05-16 . CC25EA1287613DC45D25A26037B4DBDD . 1129984 . . [9.00.8112.20600] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20600_none_1b06d47ad527af13\wininet.dll [-] 2013-04-04 . 2C96B3921B4CDE10DBAED5AAD760DB67 . 1129472 . . [9.00.8112.16483] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16483_none_1a29b747bc483daf\wininet.dll [-] 2013-04-04 . 28B2DD8DBAEE306290A74ED03DB3768F . 1129984 . . [9.00.8112.20593] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20593_none_1aa88426d56df96a\wininet.dll [-] 2013-02-22 . C5B6468422DB1C8AA36C32CBB0197E5E . 1129472 . . [9.00.8112.16476] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16476_none_1a378811bc3d6dc3\wininet.dll [-] 2013-02-22 . 490E24D5E427DFA55B1C1182F0DB861C . 1129984 . . [9.00.8112.20586] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20586_none_1ab654f0d563297e\wininet.dll [-] 2013-02-02 . 1284D72C04B553ED5382EA14303D66DB . 1129472 . . [9.00.8112.20580] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20580_none_1ab05334d5689174\wininet.dll [-] 2013-02-02 . 03728C624D05C2F157BBD46F6B7F6EA0 . 1129472 . . [9.00.8112.16470] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16470_none_1a318655bc42d5b9\wininet.dll [-] 2013-01-08 . B49B56B64F57699A1A663D2CF7D0A56F . 1129472 . . [9.00.8112.16464] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16464_none_1a405769bc371f24\wininet.dll [-] 2013-01-08 . 16C45E6881449C6330567E51C13920FA . 1129472 . . [9.00.8112.20573] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20573_none_1abe23fed55dc188\wininet.dll [-] 2012-11-14 . 7FA3A810F383588D46220967DE8B64FF . 1129472 . . [9.00.8112.16457] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16457_none_1a4e2833bc2c4f38\wininet.dll [-] 2012-11-14 . 0635D714351F842D43EA184E75C4A3FF . 1129472 . . [9.00.8112.20565] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20565_none_1acaf47ed553d845\wininet.dll [-] 2012-10-08 . 9CB0D2A9A77D91D9614355EE9FF00519 . 1129472 . . [9.00.8112.16455] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16455_none_1a4c279fbc2e1c8a\wininet.dll [-] 2012-10-08 . 6E3AC8A54A1881806BA2B58539483788 . 1129472 . . [9.00.8112.20562] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20562_none_1ac7f3a0d5568c40\wininet.dll [-] 2012-08-24 . 2895E29EFCFC0B1BCF8AEE1A0C67913C . 1129472 . . [9.00.8112.20557] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20557_none_1ad7c4fed549ef02\wininet.dll [-] 2012-08-24 . 5553611E2F9EA6F613079177F1233068 . 1129472 . . [9.00.8112.16450] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16450_none_1a47262dbc329dd7\wininet.dll [-] 2012-06-29 . 75A97A2C060E72AB49E071E08C7DD2BA . 1129472 . . [9.00.8112.16448] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16448_none_1a59f869bc234c9e\wininet.dll [-] 2012-06-28 . 54C30A4066A28F9A017E095E283B2762 . 1129472 . . [9.00.8112.20554] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20554_none_1ad4c420d54ca2fd\wininet.dll [-] 2012-06-07 . 1D94FA7C81D2FFE494AF094619BA706F . 1127424 . . [9.00.8112.16441] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16441_none_1a52f663bc299b3d\wininet.dll [-] 2012-06-02 . 8E87270C4704CF2951E1E7820D6C8A2B . 1129472 . . [9.00.8112.16447] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16447_none_1a58f81fbc243347\wininet.dll [-] 2012-06-02 . E430161A632F9A8FE512DE0CA5685559 . 1129472 . . [9.00.8112.20553] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20553_none_1ad3c3d6d54d89a6\wininet.dll [-] 2012-05-17 . 1C191A4F0960F21B5D58C8A65BAF5427 . 1129472 . . [9.00.8112.16446] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16446_none_1a57f7d5bc2519f0\wininet.dll [-] 2012-05-17 . 43BAC67996D8765A5F1B3A4EA6231E21 . 1129472 . . [9.00.8112.20551] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20551_none_1ad1c342d54f56f8\wininet.dll [-] 2012-02-28 . 7CCA8574A3B9BB41A4150739E21F1B23 . 981504 . . [8.00.7601.17785] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17785_none_1e5ff942774efaaa\wininet.dll [-] 2012-02-28 . 6A5778483A8023B4DB9C5A509D382392 . 982016 . . [8.00.7601.21931] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.21931_none_1f1ba6679047a68a\wininet.dll [-] 2012-02-28 . 44465367256D1C72B58F5ABAA19E7016 . 1127424 . . [9.00.8112.16443] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16443_none_1a54f6f7bc27cdeb\wininet.dll [-] 2012-02-28 . 11A34DCA08EB2A586246F2D6C2A81D58 . 1127424 . . [9.00.8112.20548] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20548_none_1ae39534d540ec68\wininet.dll [-] 2010-11-21 . 44214C94911C7CFB1D52CB64D5E8368D . 980992 . . [8.00.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17514_none_1eaaa4a07717236e\wininet.dll . [-] 2010-11-21 . 7FF15A4F092CD4A96055BA69F903E3E9 . 206848 . . [6.1.7600.16385] .. c:\windows\SysWOW64\ws2_32.dll [-] 2010-11-21 . 7FF15A4F092CD4A96055BA69F903E3E9 . 206848 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.1.7601.17514_none_f4bf1aae2c981ecf\ws2_32.dll . [-] 2009-07-14 . 808AABDF9337312195CAFF76D1804786 . 4608 . . [6.1.7600.16385] .. c:\windows\SysWOW64\ws2help.dll [-] 2009-07-14 . 808AABDF9337312195CAFF76D1804786 . 4608 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6ace9e67456cc40b\ws2help.dll . [-] 2011-02-26 . 3B69712041F3D63605529BD66DC00C48 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe [-] 2011-02-25 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7600.16385] .. c:\windows\explorer.exe [-] 2011-02-25 . 332FEAB1435662FC6C672E25BEB37BE3 . 2871808 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe [-] 2010-11-21 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe . [-] 2009-07-14 . 2E2C937846A0B8789E5E91739284D17A . 427008 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\regedit.exe [-] 2009-07-14 . 2E2C937846A0B8789E5E91739284D17A . 398336 . . [6.1.7600.16385] .. c:\windows\regedit.exe . [-] 2010-11-21 . 928CF7268086631F54C3D8E17238C6DD . 1414144 . . [6.1.7600.16385] .. c:\windows\SysWOW64\ole32.dll [-] 2010-11-21 . 928CF7268086631F54C3D8E17238C6DD . 1414144 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-com-base-qfe-ole32_31bf3856ad364e35_6.1.7601.17514_none_ae2511475093798f\ole32.dll . [-] 2014-04-25 . A5F833506BF6A1B5D693E1499DEE2444 . 626688 . . [1.0626.7601.18454] .. c:\windows\SysWOW64\usp10.dll [-] 2014-04-25 . A5F833506BF6A1B5D693E1499DEE2444 . 626688 . . [1.0626.7601.18454] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.18454_none_aed68a9bb6df0577\usp10.dll [-] 2014-04-25 . 5A7B3405C2AAE5369F6CB42FE248FBB0 . 626688 . . [1.0626.7601.22666] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.22666_none_af5759f4d002f107\usp10.dll [-] 2012-11-22 . CA68408922B02E8D955A2967C7CBF8CE . 626688 . . [1.0626.7601.22171] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.22171_none_af477f18d00f9c82\usp10.dll [-] 2012-11-22 . B7230010D97787AF3D25E4C82F2B06B9 . 626688 . . [1.0626.7601.18009] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.18009_none_af119411b6b203d9\usp10.dll [-] 2010-11-21 . 804AAAFEBB3AD5F49334DD906BCB1DE5 . 626176 . . [1.0626.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.17514_none_af01e2f9b6be7939\usp10.dll . [-] 2009-07-14 . 9C67F6BBDA3881CFD02095160CF91576 . 4608 . . [6.1.7600.16385] .. c:\windows\SysWOW64\ksuser.dll [-] 2009-07-14 . 9C67F6BBDA3881CFD02095160CF91576 . 4608 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-d..tshow-kernelsupport_31bf3856ad364e35_6.1.7601.17514_none_ea090647f58e5d9c\ksuser.dll . [-] 2009-07-14 . 4A3CDCEF8ED41B221F3DBEF5792FB52D . 8704 . . [6.1.7600.16385] .. c:\windows\SysWOW64\ctfmon.exe [-] 2009-07-14 . 4A3CDCEF8ED41B221F3DBEF5792FB52D . 8704 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.1.7600.16385_none_9d06e2f6f1e51f98\ctfmon.exe . [-] 2010-11-21 . 414DA952A35BF5D50192E28263B40577 . 328192 . . [6.1.7600.16385] .. c:\windows\SysWOW64\shsvcs.dll [-] 2010-11-21 . 414DA952A35BF5D50192E28263B40577 . 328192 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-shsvcs_31bf3856ad364e35_6.1.7601.17514_none_35ab0ceb67ede31e\shsvcs.dll . [-] 2009-07-14 . 18AB2E5A40064ED5F7791AC5946A90F3 . 4608 . . [6.1.7600.16385] .. c:\windows\SysWOW64\msimg32.dll [-] 2009-07-14 . 18AB2E5A40064ED5F7791AC5946A90F3 . 4608 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-gdi-painting_31bf3856ad364e35_6.1.7600.16385_none_77422e3e7d5fa732\msimg32.dll . [-] 2009-07-14 . 50BA656134F78AF64E4DD3C8B6FEFD7E . 12288 . . [6.1.7600.16385] .. c:\windows\SysWOW64\cngaudit.dll [-] 2009-07-14 . 50BA656134F78AF64E4DD3C8B6FEFD7E . 12288 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll . [-] 2009-07-14 . B5C5DCAD3899512020D135600129D665 . 96256 . . [6.1.7600.16385] .. c:\windows\SysWOW64\wininit.exe [-] 2009-07-14 . B5C5DCAD3899512020D135600129D665 . 96256 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe . [-] 2009-07-14 . A45D184DF6A8803DA13A0B329517A64A . 149504 . . [6.1.7600.16385] .. c:\windows\SysWOW64\appmgmts.dll [-] 2009-07-14 . A45D184DF6A8803DA13A0B329517A64A . 149504 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.1.7600.16385_none_e818845daa1b69db\appmgmts.dll . [-] 2009-07-14 . A1E91B5B5273573FC132B683E550B5E6 . 19456 . . [6.1.7600.16385] .. c:\windows\SysWOW64\ias.dll [-] 2009-07-14 . A1E91B5B5273573FC132B683E550B5E6 . 19456 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-n..ion_service_runtime_31bf3856ad364e35_6.1.7601.17514_none_fb08448fa0c85c23\ias.dll . [-] 2010-11-21 03:24 . AB9EB3745B03AE67AB241A82338DEA7B . 954288 . . [4.1.6140] .. c:\windows\SysWOW64\mfc40u.dll [-] 2010-11-21 03:24 . AB9EB3745B03AE67AB241A82338DEA7B . 954288 . . [4.1.6151] .. c:\windows\winsxs\x86_microsoft-windows-mfc40u_31bf3856ad364e35_6.1.7601.17514_none_f51a7bf0b3d25294\mfc40u.dll . [-] 2009-07-14 . 833FBB672460EFCE8011D262175FAD33 . 266752 . . [6.1.7600.16385] .. c:\windows\SysWOW64\upnphost.dll [-] 2009-07-14 . 833FBB672460EFCE8011D262175FAD33 . 266752 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-upnpdevicehost_31bf3856ad364e35_6.1.7600.16385_none_2831d06e8295c671\upnphost.dll . [-] 2009-07-14 . 0E85C11F8850D524B02181C6E02BA9AE . 453632 . . [6.1.7600.16385] .. c:\windows\SysWOW64\dsound.dll [-] 2009-07-14 . 0E85C11F8850D524B02181C6E02BA9AE . 453632 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-audio-dsound_31bf3856ad364e35_6.1.7600.16385_none_5872147ba3367471\dsound.dll . [-] 2010-11-21 . 6EF5F3F18413C367195F06E503AB86A6 . 1828352 . . [6.1.7601.17514] .. c:\windows\SysWOW64\d3d9.dll [-] 2010-11-21 . 6EF5F3F18413C367195F06E503AB86A6 . 1828352 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-directx-direct3d9_31bf3856ad364e35_6.1.7601.17514_none_c454d690bf084f04\d3d9.dll . [-] 2009-07-14 . 198552AEFECA69D646867EC8D792DE95 . 531968 . . [6.1.7600.16385] .. c:\windows\SysWOW64\ddraw.dll [-] 2009-07-14 . 198552AEFECA69D646867EC8D792DE95 . 531968 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-directx-directdraw_31bf3856ad364e35_6.1.7600.16385_none_04dbf9102154d42e\ddraw.dll . [-] 2010-11-21 03:24 . 703FFD301AB900B047337C5D40FD6F96 . 90112 . . [6.1.7601.17514] .. c:\windows\SysWOW64\olepro32.dll [-] 2010-11-21 03:24 . 703FFD301AB900B047337C5D40FD6F96 . 90112 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-ole-automation-legacy_31bf3856ad364e35_6.1.7601.17514_none_3c1b247e5ff65f89\olepro32.dll . [-] 2009-07-14 . EDD2AD141DEBD425D74A52A4D7BE6AC4 . 39424 . . [6.1.7600.16385] .. c:\windows\SysWOW64\perfctrs.dll [-] 2009-07-14 . EDD2AD141DEBD425D74A52A4D7BE6AC4 . 39424 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-p..ormancebasecounters_31bf3856ad364e35_6.1.7600.16385_none_97bcd9bcab2b9b3a\perfctrs.dll . [-] 2009-07-14 . 702254574E7E52052DE39408457B7149 . 21504 . . [6.1.7600.16385] .. c:\windows\SysWOW64\version.dll [-] 2009-07-14 . 702254574E7E52052DE39408457B7149 . 21504 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-version_31bf3856ad364e35_6.1.7600.16385_none_14d4a552b2395165\version.dll . [-] 2009-07-14 . 5A12C364AD1D4FCC0AD0E56DBBC34462 . 16896 . . [6.1.7600.16385] .. c:\windows\SysWOW64\midimap.dll [-] 2009-07-14 . 5A12C364AD1D4FCC0AD0E56DBBC34462 . 16896 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.1.7600.16385_none_8cd41e2771e37717\midimap.dll . [-] 2009-07-14 . ED6EE83D61EBC683C2CD8E899EA6FEBE . 11776 . . [6.1.7600.16385] .. c:\windows\SysWOW64\rasadhlp.dll [-] 2009-07-14 . ED6EE83D61EBC683C2CD8E899EA6FEBE . 11776 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-rasautodial_31bf3856ad364e35_6.1.7600.16385_none_76239aafb364e805\rasadhlp.dll . [-] 2009-07-14 . EE5C8E27C37B79CB54A2FCEEED2DC262 . 9216 . . [6.1.7600.16385] .. c:\windows\SysWOW64\WSHTCPIP.DLL [-] 2009-07-14 . EE5C8E27C37B79CB54A2FCEEED2DC262 . 9216 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-winsock-helper-tcpip_31bf3856ad364e35_6.1.7600.16385_none_cb895be592db1acb\WSHTCPIP.DLL . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 131480 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184] "DisplayFusion"="c:\program files (x86)\DisplayFusion\DisplayFusion.exe" [2013-04-26 7283072] "puush"="c:\program files (x86)\puush\puush.exe" [2013-08-14 567880] "Amazon Music"="c:\users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe" [2014-07-22 3356480] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Sound Blaster Recon3D SBX Control Panel"="c:\program files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe" [2013-09-04 1103872] . c:\users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-7-30 36414496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableClock"= 0 (0x0) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoCommonGroups"= 0 (0x0) . R1 vdrv1000;vdrv1000;c:\windows\system32\DRIVERS\vdrv1000.sys;c:\windows\SYSNATIVE\DRIVERS\vdrv1000.sys [x] R2 Apache2.4;Apache2.4;c:\xampp\apache\bin\httpd.exe;c:\xampp\apache\bin\httpd.exe [x] R2 ASGT;ASGT;c:\windows\SysWOW64\ASGT.exe;c:\windows\SysWOW64\ASGT.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 DisplayFusionService;DisplayFusionService;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 360Camera;360Safe Camera Filter Service;c:\windows\system32\Drivers\360Camera64.sys;c:\windows\SYSNATIVE\Drivers\360Camera64.sys [x] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;g:\steamlibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe;g:\steamlibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [x] R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe;c:\program files (x86)\Common Files\Desura\desura_service.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x] R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x] R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x] R3 HH10Help.sys;HH10Help.sys;c:\windows\system32\drivers\HH10Help.sys;c:\windows\SYSNATIVE\drivers\HH10Help.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr7364.sys;c:\windows\SYSNATIVE\DRIVERS\netr7364.sys [x] R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsucx64.sys [x] R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x] R3 PVUSB;CESG502 64bit USB Driver;c:\windows\system32\DRIVERS\CESG64.sys;c:\windows\SYSNATIVE\DRIVERS\CESG64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 TunngleService;TunngleService;c:\program files (x86)\Tunngle\TnglCtrl.exe;c:\program files (x86)\Tunngle\TnglCtrl.exe [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 vcd10bus;Virtual CD v10 Bus Enumerator;c:\windows\system32\DRIVERS\vcd10bus.sys;c:\windows\SYSNATIVE\DRIVERS\vcd10bus.sys [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x] R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] R4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] R4 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x] S1 360AntiHacker;360Safe Anti Hacker Service;c:\windows\system32\Drivers\360AntiHacker64.sys;c:\windows\SYSNATIVE\Drivers\360AntiHacker64.sys [x] S1 360Box64;360Box mini-filter driver;c:\windows\system32\DRIVERS\360Box64.sys;c:\windows\SYSNATIVE\DRIVERS\360Box64.sys [x] S1 360fsflt;360FsFlt mini-filter driver;c:\windows\system32\DRIVERS\360FsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\360FsFlt.sys [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x] S1 BAPIDRV;BAPIDRV;c:\windows\system32\DRIVERS\BAPIDRV64.sys;c:\windows\SYSNATIVE\DRIVERS\BAPIDRV64.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 360rp;360 Internet Security Real-time Protection Loading Service;c:\program files\360\360 Internet Security\360rps.exe;c:\program files\360\360 Internet Security\360rps.exe [x] S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [x] S2 FileZillaServer;FileZillaServer;c:\xampp\filezillaftp\filezillaserver.exe;c:\xampp\filezillaftp\filezillaserver.exe [x] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 RzKLService;RzKLService;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe;c:\program files (x86)\Razer\Razer Game Booster\RzKLService.exe [x] S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S2 ZhuDongFangYu;Proactive Defence;c:\program files\360\360 Internet Security\deepscan\QHActiveDefense.exe;c:\program files\360\360 Internet Security\deepscan\QHActiveDefense.exe [x] S3 360AvFlt;360AvFlt mini-filter driver;c:\windows\system32\DRIVERS\360AvFlt.sys;c:\windows\SYSNATIVE\DRIVERS\360AvFlt.sys [x] S3 avmaura;AVM USB-Fernanschluss;c:\windows\system32\DRIVERS\avmaura.sys;c:\windows\SYSNATIVE\DRIVERS\avmaura.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x] S3 GWHid;VL807 Miniport Driver;c:\windows\system32\DRIVERS\GWHid.sys;c:\windows\SYSNATIVE\DRIVERS\GWHid.sys [x] S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys;c:\windows\SYSNATIVE\drivers\ksaud.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 VL807;VL807 Filter;c:\windows\system32\DRIVERS\VL807.sys;c:\windows\SYSNATIVE\DRIVERS\VL807.sys [x] S4 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys;c:\windows\SYSNATIVE\drivers\IOMap64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-08-15 18:10 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31 15:45] . 2014-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-31 15:45] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}] 2010-11-21 03:23 444752 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2011-06-13 09:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 22:04 164760 ----a-w- c:\users\Franky\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104] "Creative SB Monitoring Utility"="sbavmon.dll" [2012-08-23 115712] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-04-02 2201032] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-04-02 1225920] "Creative SB Monitoring Utility Launcher"="SBAVMonL.dll" [2013-07-01 57856] "360sd"="c:\program files\360\360 Internet Security\360sdrun.exe" [2014-04-16 287560] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mDefault_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} mDefault_Page_URL = hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 mStart Page = hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878 mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms} uInternet Settings,ProxyOverride = <local> IE: An OneNote s&enden - c:\progra~2\MIF5BA~1\Office14\ONBttnIE.dll/105 IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MIF5BA~1\Office14\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm LSP: %windir%\system32\wlsppc.dll TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\ FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: network.proxy.ftp - proxyus1.stealthy.co FF - prefs.js: network.proxy.ftp_port - 3128 FF - prefs.js: network.proxy.http - proxyus1.stealthy.co FF - prefs.js: network.proxy.http_port - 3128 FF - prefs.js: network.proxy.socks - proxyus1.stealthy.co FF - prefs.js: network.proxy.socks_port - 3128 FF - prefs.js: network.proxy.ssl - proxyus1.stealthy.co FF - prefs.js: network.proxy.ssl_port - 3128 FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe SafeBoot-ksupmgr HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-'Cultures Saga' - c:\windows\IsUn0407.exe AddRemove-Catan - c:\windows\IsUn0407.exe AddRemove-dBpoweramp DirectShow Decoder - c:\windows\system32\SpoonUninstall.exe AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va011] "ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-2521981952-1457118651-2954859535-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*1*3*x*G@>I\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-08-27 20:26:58 ComboFix-quarantined-files.txt 2014-08-27 18:26 . Vor Suchlauf: 31 Verzeichnis(se), 36.116.066.304 Bytes frei Nach Suchlauf: 37 Verzeichnis(se), 40.229.158.912 Bytes frei . - - End Of File - - B29F1DCBC99F14C59C9E64DC900CC5E6 A36C5E4F47E84449FF07ED3517B43A31 |
28.08.2014, 08:41 | #8 |
/// the machine /// TB-Ausbilder | Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.08.2014, 19:20 | #9 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung mbam.txt Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 28.08.2014 Suchlauf-Zeit: 18:14:37 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.03.04.09 Rootkit Datenbank: v2014.02.20.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Franky Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 292071 Verstrichene Zeit: 11 Min, 12 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 9 Trojan.Banker, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C0F1636E-13A8-4C84-BB11-774BE45E1F83}, In Quarantäne, [2623ef10b1c93006840887c0e41eff01], Trojan.Banker, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C0F1636E-13A8-4C84-BB11-774BE45E1F83}, In Quarantäne, [2623ef10b1c93006840887c0e41eff01], Trojan.Banker, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C0F1636E-13A8-4C84-BB11-774BE45E1F83}, In Quarantäne, [2623ef10b1c93006840887c0e41eff01], PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [68e146b9a1d91b1bb6f0e8ce5ea52fd1], PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [57f2fc0397e38ea8971bc3fc1de642be], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [93b64bb44139b97d2d79e2d49073dd23], PUP.Optional.Qone8, HKU\S-1-5-21-2521981952-1457118651-2954859535-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [81c8fa054c2e70c6456015a18a79a65a], PUP.Optional.Qone8, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [1c2d6699f8821f17881dc4f256adbc44], PUP.Optional.SweetIM.A, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [24250cf3c9b176c01da0b3f845be35cb], Registrierungswerte: 2 Trojan.Agent, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Userinit, C:\Users\Simon\AppData\Roaming\appConf32.exe, In Quarantäne, [a4a53cc3d1a9221444eb1cefe81b2ed2] PUP.Optional.SweetIM.A, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {EF32ACD6-DCE9-11E2-8248-871FE912F296}, In Quarantäne, [24250cf3c9b176c01da0b3f845be35cb] Registrierungsdaten: 7 PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878),Ersetzt,[42071de212682f07d3df8fa0768ea957] PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[67e2ea151a602b0bd56e0728cd379a66] PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms}),Ersetzt,[fd4c619e314942f411a075ba2dd75da3] PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878),Ersetzt,[c980a95621590d290ea2200f34d0ad53] PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878),Ersetzt,[8cbde41b1763b97d486a38f77a8afe02] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[1930649b601a88aeb68d9f909b6915eb] Hijack.StartPage, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.qvo6.com/?utm_source=b&utm_medium=mlv&from=mlv&uid=3219913727_132775_6A9C8794&ts=1372245310, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.qvo6.com/?utm_source=b&utm_medium=mlv&from=mlv&uid=3219913727_132775_6A9C8794&ts=1372245310),Ersetzt,[1039ba45b0caa5914b9a7ab44cb8817f] Ordner: 0 (No malicious items detected) Dateien: 17 PUP.Optional.Softonic.A, C:\Users\Franky\Downloads\SoftonicDownloader_for_spotify-mobile.exe, In Quarantäne, [f356a25def8b2b0b05fec0a27b865ea2], PUP.Optional.Bandoo, C:\Users\Simon\Downloads\iLividSetup-r484-n-bc.exe, In Quarantäne, [88c19669f58559dd5d46eb6037caa759], PUP.Optional.Bandoo, C:\Users\Simon\Downloads\iLividSetup-r484-n-bf.exe, In Quarantäne, [94b5d22d67136bcb861d67e45da441bf], PUP.Optional.Softonic.A, C:\Users\Simon\Downloads\SoftonicDownloader_for_mcedit.exe, In Quarantäne, [2623996694e6f343b350a0c2b15010f0], PUP.Optional.Softonic, C:\Users\Simon\Downloads\SoftonicDownloader_for_terraria.exe, In Quarantäne, [51f821de7efc7bbbdbc86ed81fe2d12f], PUP.Optional.Softonic, C:\Users\Simon\Downloads\SoftonicDownloader_fuer_pflanzen-gegen-zombies.exe, In Quarantäne, [38117f80750554e2940f8db9bc45b14f], PUP.Optional.Softonic, C:\Users\Simon\Downloads\SoftonicDownloader_fuer_terraria.exe, In Quarantäne, [de6bcc33a7d3b87e396a1d299d64b050], PUP.Optional.Somoto, C:\Users\Simon\Downloads\MCPatcher_downloader_by_MCPatcher.exe, In Quarantäne, [0b3e77889bdf67cf62bcdb768084ec14], PUP.BundleInstaller.VG, C:\Users\Simon\Downloads\video_downloader(1).exe, In Quarantäne, [8cbd76898bef87af5a969535b848768a], HackTool.GamesCheat, C:\Users\Simon\Downloads\pvszv1201094+7trn.rar, In Quarantäne, [232649b6d8a2d2645cea7bc430d4768a], PUP.BundleInstaller.VG, C:\Users\Simon\Downloads\video_downloader.exe, In Quarantäne, [410867984733c86e1fd1d4f6956beb15], PUP.Optional.4Shared, C:\Users\Simon\Downloads\Terraria 1.1.2.exe, In Quarantäne, [d67355aa99e186b02b114e1e35cb58a8], PUP.Optional.Somoto, C:\Users\Simon\Downloads\etypesetup(1).exe, In Quarantäne, [ea5fc03f7cfe6fc731eddd74d430a55b], PUP.Optional.Somoto, C:\Users\Simon\Downloads\etypesetup.exe, In Quarantäne, [1a2fbd42453587af8b93e26fe024dd23], PUP.Optional.RegCleanerPro, C:\Users\Simon\Downloads\rcpsetup_softonic_new_sd_new_enrest(1).exe, In Quarantäne, [b792f30ced8d52e40bd2de6edd24ef11], PUP.Optional.RegCleanerPro, C:\Users\Simon\Downloads\rcpsetup_softonic_new_sd_new_enrest.exe, In Quarantäne, [3c0de619b9c1f04607d648049d64e51b], PUP.Optional.SweetPage.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml, In Quarantäne, [9dacf609a1d963d3b001f6c9e221cf31], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.308 - Bericht erstellt am 28/08/2014 um 19:42:38 # Aktualisiert 20/08/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Franky - FRANKY-PC # Gestartet von : C:\Users\Franky\Desktop\adwcleaner_3.308.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Device Ordner Gelöscht : C:\Users\Franky\AppData\Roaming\SendSpace Ordner Gelöscht : C:\Users\Simon\AppData\Local\b1e Ordner Gelöscht : C:\Users\Simon\AppData\Local\vghd Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\B1Toolbar Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\eIntaller Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\otshot Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\Smartbar Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\CT3241949 Ordner Gelöscht : C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\faststartff@gmail.com Ordner Gelöscht : C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\o_08@wwnrgdbya.edu Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\Extensions\{78e516ef-11de-47a1-8364-a99b917ec5ee} Ordner Gelöscht : C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajckffdklmhnklkigjoohdgjmkeehcah Datei Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\searchplugins\fileconverter-13-customized-web-search.xml Datei Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\user.js Datei Gelöscht : C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\SOFTWARE\Trymedia Systems ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17239 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Mozilla Firefox v31.0 (x86 de) [ Datei : C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\prefs.js ] Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.sweet-page.com/newtab/?type=nt&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878"); [ Datei : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\prefs.js ] Zeile gelöscht : user_pref("CT3241949.1000082.isDisplayHidden", "true"); Zeile gelöscht : user_pref("CT3241949.1000082.shrinkState", "shrinked"); Zeile gelöscht : user_pref("CT3241949.1000082.state", "{\"state\":\"stopped\",\"text\":\"NDR 2\",\"description\":\"NDR 2\",\"url\":\"hxxp://lsd.newmedia.tiscali-business.com/bb/redirect.lsc?content=live&media=ms&strea[...] Zeile gelöscht : user_pref("CT3241949.1000234.TWC_TMP_city", "BERLIN"); Zeile gelöscht : user_pref("CT3241949.1000234.TWC_TMP_country", "DE"); Zeile gelöscht : user_pref("CT3241949.1000234.TWC_locId", "GMXX0007"); Zeile gelöscht : user_pref("CT3241949.1000234.TWC_location", "Berlin, Deutschland"); Zeile gelöscht : user_pref("CT3241949.1000234.TWC_region", "DE"); Zeile gelöscht : user_pref("CT3241949.1000234.TWC_temp_dis", "c"); Zeile gelöscht : user_pref("CT3241949.1000234.TWC_wind_dis", "kmh"); Zeile gelöscht : user_pref("CT3241949.1000234.weatherData", "{\"icon\":\"20.png\",\"temperature\":\"2°C\",\"temperatureClear\":\"2°C\",\"highTemperature\":\"2°C\",\"lowTemperature\":\"0°C\",\"feelsLike\":\"2°C\",\"con[...] Zeile gelöscht : user_pref("CT3241949.1000515.APP_WIN_FEATURES", "%F8%EB%F9%EF%u0100%E7%E8%F2%EB%C3%B6%B2%EE%F9%E9%F8%F5%F2%F2%C3%B6%B2%FC%F9%E9%F8%F5%F2%F2%C3%B6%B2%FA%EF%FA%F2%EB%E8%E7%F8%C3%B7%B2%E9%F2%F5%F9%EB%E8%[...] Zeile gelöscht : user_pref("CT3241949.1000515.FacebookLanguageByUser", ""); Zeile gelöscht : user_pref("CT3241949.1000515.Facebook_Last_Visit_Tab", ""); Zeile gelöscht : user_pref("CT3241949.3174054215061172570.bornDate", "{\"dataType\":\"string\",\"data\":\"{\\\"Response\\\":\\\"08\\\\/13\\\\/2013 18\\\"}\"}"); Zeile gelöscht : user_pref("CT3241949.CBOpenMAMSettings.enc", "MA=="); Zeile gelöscht : user_pref("CT3241949.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.Facebook_Mode", "%B8"); Zeile gelöscht : user_pref("CT3241949.Facebook_Mode.enc", "Mg=="); Zeile gelöscht : user_pref("CT3241949.Facebook_User_Locale", "%EA%EB"); Zeile gelöscht : user_pref("CT3241949.Facebook_User_Locale.enc", "ZGU="); Zeile gelöscht : user_pref("CT3241949.FirstTime", "true"); Zeile gelöscht : user_pref("CT3241949.FirstTimeFF3", "true"); Zeile gelöscht : user_pref("CT3241949.LoginRevertSettingsEnabled", true); Zeile gelöscht : user_pref("CT3241949.RevertSettingsEnabled", true); Zeile gelöscht : user_pref("CT3241949.SF_JUST_INSTALLED.enc", "RkFMU0U="); Zeile gelöscht : user_pref("CT3241949.SF_STATUS.enc", "RU5BQkxFRA=="); Zeile gelöscht : user_pref("CT3241949.SF_USER_ID.enc", "Y2lkXzIyNDIwMTMxMTM4NTEzNDYyODAz"); Zeile gelöscht : user_pref("CT3241949.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241949&SearchSource=2&q="); Zeile gelöscht : user_pref("CT3241949.UserID", "UN91888041744268743"); Zeile gelöscht : user_pref("CT3241949.addressBarTakeOverEnabledInHidden", "true"); Zeile gelöscht : user_pref("CT3241949.browser.search.defaultthis.engineName", true); Zeile gelöscht : user_pref("CT3241949.cb_experience_000.enc", "Mjg="); Zeile gelöscht : user_pref("CT3241949.cb_firstuse0100.enc", "MQ=="); Zeile gelöscht : user_pref("CT3241949.cb_user_id_000.enc", "Q0I0NTAxMDU1MDY2OTNfMTM2NzI0NzIwNTYwMl9GaXJlZm94"); Zeile gelöscht : user_pref("CT3241949.cbcountry_001.enc", "REU="); Zeile gelöscht : user_pref("CT3241949.cbfirsttime.enc", "V2VkIERlYyAxOSAyMDEyIDE0OjMxOjI3IEdNVCswMTAw"); Zeile gelöscht : user_pref("CT3241949.embeddedsData", "[{\"appId\":\"129887071061272563\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...] Zeile gelöscht : user_pref("CT3241949.enableAlerts", "always"); Zeile gelöscht : user_pref("CT3241949.event_data.enc", "JTVCJTVE"); Zeile gelöscht : user_pref("CT3241949.fired_events.enc", "AA=="); Zeile gelöscht : user_pref("CT3241949.firstTimeDialogOpened", "true"); Zeile gelöscht : user_pref("CT3241949.fixPageNotFoundErrorInHidden", "true"); Zeile gelöscht : user_pref("CT3241949.fixUrls", true); Zeile gelöscht : user_pref("CT3241949.hxxp___facebook_conduitapps_com.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPTAsaHNjcm9sbD0wLHZzY3JvbGw9MCx0aXRsZWJhcj0xLGNsb3NlYnV0dG9uPTEsc2F2ZXJlc2l6ZWRzaXplPTAsb3BlbnBvc2l0aW9uPWFsaWd[...] Zeile gelöscht : user_pref("CT3241949.installType", "Unknown"); Zeile gelöscht : user_pref("CT3241949.isCheckedStartAsHidden", true); Zeile gelöscht : user_pref("CT3241949.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.isFirstTimeToolbarLoading", "false"); Zeile gelöscht : user_pref("CT3241949.isNewTabEnabled", true); Zeile gelöscht : user_pref("CT3241949.isPerformedSmartBarTransition", "true"); Zeile gelöscht : user_pref("CT3241949.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); Zeile gelöscht : user_pref("CT3241949.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.key_date.enc", "MTk="); Zeile gelöscht : user_pref("CT3241949.keyword", true); Zeile gelöscht : user_pref("CT3241949.mam_gk_appStateReportTime", "%B7%B9%BE%BA%B6%BE%B8%BD%B8%B8%BE%B9%BA"); Zeile gelöscht : user_pref("CT3241949.mam_gk_appStateReportTime.enc", "MTM4NDA4MjcyMjgzNA=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_CouponBuddy.enc", "b24="); Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_Easytobook.enc", "b24="); Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_Easytobook_targeted.enc", "b24="); Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_PriceGong.enc", "b24="); Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_WindowShopper.enc", "b24="); Zeile gelöscht : user_pref("CT3241949.mam_gk_appsConfig.enc", "eyJBcHBzQ29uZmlndXJhdGlvbiI6W3siaWQiOiJDbGFyaXR5X0FjdGl2ZSIsInVybCI6Imh0dHA6Ly9zdG9yYWdlLmNvbmR1aXQuY29tL21hbS8zcmRwYXJ0eWFwcHMvY2xhcml0eVJheS9jcl9hY3Rpdm[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_appsDefaultEnabled", "%F4%FB%F2%F2"); Zeile gelöscht : user_pref("CT3241949.mam_gk_appsDefaultEnabled.enc", "bnVsbA=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_calledSetupService.enc", "MQ=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_currentBadgeValue", "%BF%BB"); Zeile gelöscht : user_pref("CT3241949.mam_gk_currentBadgeValue.enc", "OTU="); Zeile gelöscht : user_pref("CT3241949.mam_gk_currentVersion", "%B7%B4%B7%B7%B4%BA%B4%B8"); Zeile gelöscht : user_pref("CT3241949.mam_gk_currentVersion.enc", "MS4xMS40LjI="); Zeile gelöscht : user_pref("CT3241949.mam_gk_eventsCache.enc", "eyI3YmYzYzQwNi0xMjc1LTQ0ZjItOWU3OS0zMjlmMjM4N2Q4NDAiOnsidG9waWMiOiJzZW5kVXNhZ2UiLCJkYXRhIjp7ImNhdGVnb3J5IjoiV2VsY29tZSIsImFjdGlvbiI6IlZpZXciLCJsYWJlbCI6I[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_existingUsersRecoveryDone.enc", "MQ=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_first_time", "%B7"); Zeile gelöscht : user_pref("CT3241949.mam_gk_first_time.enc", "MQ=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_gadgetOpen.enc", "bmV3QXBw"); Zeile gelöscht : user_pref("CT3241949.mam_gk_globalKeysMigratedToLocalStorage", "%B7"); Zeile gelöscht : user_pref("CT3241949.mam_gk_globalKeysMigratedToLocalStorage.enc", "MQ=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_lastLoginTime", "%B7%B9%BE%BA%B6%BE%B8%BD%B8%B9%BB%BA%B6"); Zeile gelöscht : user_pref("CT3241949.mam_gk_lastLoginTime.enc", "MTM4NDA4MjcyMzU0MA=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_localization", "%u0101%A8%ED%E7%EA%ED%EB%FA%C9%F5%F4%FA%EB%F4%FA%D6%F5%F2%EF%E9%FF%A8%C0%u0101%A8%DA%EB%FE%FA%A8%C0%A8%C9%F5%F4%FA%EB%F4%FA%B3%D8%EF%E9%EE%FA%F2%EF%F4%EF%EB[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50LVJpY2h0bGluaWUifSwiZ2FkZ2V0RGVzY3JpcHRpb25QcmltYXJ5Ijp7IlRleHQiOiJWYWx1ZSBBcHBzIGJlcmVpY2hlcnQgSWhy[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_newApps.enc", "W3siaWQiOiJDbGFyaXR5X0FjdGl2ZSIsIm5hbWUiOiJDbGFyaXR5IiwiZGVzY3JpcHRpb24iOm51bGwsImFkZGVkQXQiOiIxMzg0MDgyNzIyNzcxIn0seyJpZCI6ImVUb3JvIiwibmFtZSI6ImVUb3JvIiwiZ[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.10.2.5.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBl[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.10.4.0.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBl[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.11.4.2", "%u0101%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0%u0101%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%FA%EB%A8%C0%A8%B8%B6%B7%B[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.11.4.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMTAiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6IjQ2XzAiLCJpc1Rlc3QiOnRydWUsIlVzZXJDb3VudHJ5[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.6.0.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzA1XzAiLCJpc1Rlc3QiOnRydWUsImlzV2VsY29tZUV4cGVyaWVuY2VFbmFibGVkQnlEZWZhdWx0I[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.8.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBlc[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.9.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBlc[...] Zeile gelöscht : user_pref("CT3241949.mam_gk_showCloseButton.enc", "dHJ1ZQ=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_showWelcomeGadget", "%EC%E7%F2%F9%EB"); Zeile gelöscht : user_pref("CT3241949.mam_gk_showWelcomeGadget.enc", "ZmFsc2U="); Zeile gelöscht : user_pref("CT3241949.mam_gk_stamp", "%BA%BC%E5%B6"); Zeile gelöscht : user_pref("CT3241949.mam_gk_stamp.enc", "NDZfMA=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_userId", "%EA%BD%E9%BC%BD%BA%EC%B6%B3%BB%BA%BC%B6%B3%BA%BD%E8%B9%B3%BF%BE%E9%B7%B3%BB%B8%B8%B7%B6%BF%EA%E9%BF%EB%EA%B9"); Zeile gelöscht : user_pref("CT3241949.mam_gk_userId.enc", "ZDdjNjc0ZjAtNTQ2MC00N2IzLTk4YzEtNTIyMTA5ZGM5ZWQz"); Zeile gelöscht : user_pref("CT3241949.mam_gk_user_approval_interacted", "%B7"); Zeile gelöscht : user_pref("CT3241949.mam_gk_user_approval_interacted.enc", "MQ=="); Zeile gelöscht : user_pref("CT3241949.mam_gk_welcomeDialogMode", "%B7"); Zeile gelöscht : user_pref("CT3241949.mam_gk_welcomeDialogMode.enc", "MQ=="); Zeile gelöscht : user_pref("CT3241949.migrateAppsAndComponents", true); Zeile gelöscht : user_pref("CT3241949.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.amazon.de%2FMultifunktional-Adapter-MicroSDHC-MicroSDXC-schmaler%2Fdp%2FB00DYAZYF4%2Fref[...] Zeile gelöscht : user_pref("CT3241949.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.personalApps", "{\"dataType\":\"object\",\"data\":\"[\\\"BROWSER_COMPONENT\\\"]\"}"); Zeile gelöscht : user_pref("CT3241949.price-gong.bornDate", "{\"dataType\":\"string\",\"data\":\"{\\\"Response\\\":\\\"09\\\\/25\\\\/2013 14\\\"}\"}"); Zeile gelöscht : user_pref("CT3241949.search.searchAppId", "129887071061272563"); Zeile gelöscht : user_pref("CT3241949.search.searchCount", "2"); Zeile gelöscht : user_pref("CT3241949.searchInNewTabEnabledInHidden", "true"); Zeile gelöscht : user_pref("CT3241949.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"false\"}"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3241949\"}"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://FileConverter13.OurToolbar.com//xpi\"}"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"FileConverter 1.3\"}"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1383664203356"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_appsMetadata_lastUpdate", "1384086149492"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1383664203146"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_login_10.13.40.15_lastUpdate", "1398352391398"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_menu_769c590835a76d075fe33b9a87a87786_lastUpdate", "1384107152512"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_menu_d32f45618f5a02bd965c56155a643855_lastUpdate", "1384107152182"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1383664203166"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_searchAPI_lastUpdate", "1384107155909"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_serviceMap_lastUpdate", "1398352390782"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_toolbarContextMenu_lastUpdate", "1384107271862"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_toolbarSettings_lastUpdate", "1398352391127"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_translation_lastUpdate", "1398352391281"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_userApps7f5031f3-d548-4e84-b3af-0eadff483480_lastUpdate", "1384106925155"); Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_userApps_lastUpdate", "1384106925176"); Zeile gelöscht : user_pref("CT3241949.settingsINI", true); Zeile gelöscht : user_pref("CT3241949.smartbar.CTID", "CT3241949"); Zeile gelöscht : user_pref("CT3241949.smartbar.Uninstall", "0"); Zeile gelöscht : user_pref("CT3241949.smartbar.homepage", true); Zeile gelöscht : user_pref("CT3241949.smartbar.isHidden", true); Zeile gelöscht : user_pref("CT3241949.smartbar.toolbarName", "FileConverter 1.3 "); Zeile gelöscht : user_pref("CT3241949.startPage", "userChanged"); Zeile gelöscht : user_pref("CT3241949.toolbarBornServerTime", "19-12-2012"); Zeile gelöscht : user_pref("CT3241949.toolbarCurrentServerTime", "24-4-2014"); Zeile gelöscht : user_pref("CT3241949.url_history0001.enc", "aHR0cDovL2ZvcnVtcy5mbHlmb3JoZXJvdjE1LmNvbS9zaG93dGhyZWFkLnBocD90PTI0OTE3Ojo6Y2xpY2toYW5kbGVyOjo6MTM4MDExMDI3MzIwMywsLGh0dHA6Ly9mb3J1bXMuZmx5Zm9yaGVyb3YxNS5j[...] Zeile gelöscht : user_pref("CT3241949_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1399556081084,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]"); Zeile gelöscht : user_pref("Smartbar.ConduitHomepagesList", ""); Zeile gelöscht : user_pref("Smartbar.ConduitSearchEngineList", ""); Zeile gelöscht : user_pref("Smartbar.ConduitSearchUrlList", ""); Zeile gelöscht : user_pref("Smartbar.keywordURLSelectedCTID", "CT3241949"); Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=mlv&from=mlv&uid=3219913727_132775_6A9C8794&ts=1372245310"); Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241949&SearchSource=2&q="); Zeile gelöscht : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3241949&SearchSource=13&CUI=SB_CUI"); Zeile gelöscht : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241949&SearchSource=2&q="); Zeile gelöscht : user_pref("smartbar.originalHomepage", "chrome://branding/locale/browserconfig.properties"); Zeile gelöscht : user_pref("smartbar.originalSearchAddressUrl", ""); Zeile gelöscht : user_pref("smartbar.originalSearchEngine", false); -\\ Google Chrome v36.0.1985.143 [ Datei : C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo Gelöscht [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg Gelöscht [Extension] : hphibigbodkkohoglgfkddblldpfohjl Gelöscht [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej Gelöscht [Extension] : kincjchfokkeneeofpeefomkikfkiedl Gelöscht [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc Gelöscht [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc [ Datei : C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Extension] : ajckffdklmhnklkigjoohdgjmkeehcah ************************* AdwCleaner[R0].txt - [21220 octets] - [28/08/2014 19:02:05] AdwCleaner[S0].txt - [20924 octets] - [28/08/2014 19:42:38] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [20985 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by Franky on 28.08.2014 at 19:49:24,05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Franky\AppData\Roaming\mozilla\firefox\profiles\pmki85vq.default\minidumps [1 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.08.2014 at 19:56:34,03 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2014 03 Ran by Franky (administrator) on FRANKY-PC on 28-08-2014 20:13:25 Running from C:\Users\Franky\Desktop Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360rps.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Windows\SysWOW64\ASGT.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (FileZilla Project) C:\xampp\FileZillaFTP\FileZillaServer.exe () C:\xampp\mysql\bin\mysqld.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Tobias Süllhöfer Software) C:\Windows\System32\wtmcore.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360sd.exe (hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360rp.exe () C:\Program Files (x86)\puush\puush.exe () C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe (Dropbox, Inc.) C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor) HKLM\...\Run: [Creative SB Monitoring Utility] => RunDll32 sbavmon.dll,SBAVMonitor HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Creative SB Monitoring Utility Launcher] => RunDll32 SBAVMonL.dll,SBAVMonitorLauncher HKLM\...\Run: [360sd] => C:\Program Files\360\360 Internet Security\360sdrun.exe [287560 2014-04-16] (Qihu 360 Software Co., Ltd.) HKLM-x32\...\Run: [Sound Blaster Recon3D SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe [1103872 2013-09-04] (Creative Technology Ltd) HKLM\...\Winlogon: [Shell] explorer.exe,wtmcore.exe HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [ISUSPM Startup] => c:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7283072 2013-04-26] (Binary Fortress Software) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2013-08-14] () HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [Amazon Music] => C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] () HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\system32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableClock] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoNetworkConnections] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoCommonGroups] 0 Startup: C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0FB66E927017CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {8B7A2BC3-75E1-4f5d-AA53-26176AE0EFEF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {DD1A1D91-E60E-46d0-A1D0-A2823A9C2B12} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms} SearchScopes: HKCU - {EE29A4DD-95C6-456c-A00A-C52454462FEF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files\360\360 Internet Security\safemon\safemon64.dll (Qihu 360 Software Co., Ltd.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default FF Homepage: about:home FF NetworkProxy: "ftp", "proxyus1.stealthy.co" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "http", "proxyus1.stealthy.co" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "proxyus1.stealthy.co" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "proxyus1.stealthy.co" FF NetworkProxy: "ssl_port", 3128 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Amazon-Icon - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\amazon-icon@giga.de [2014-07-05] FF Extension: SearchNewTab - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\uuy0qpwgmv@t-oeua.org [2013-09-11] FF Extension: ReloadEvery - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-04-16] FF Extension: Adblock Plus - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-07-14] Chrome: ======= CHR HomePage: CHR RestoreOnStartup: "" CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Unity Player) - C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (podcast.de) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\bofligbealbmofkgodhlglkefkpegjnb [2013-09-11] CHR Extension: (Adblock Plus) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-09-11] CHR Extension: (Adblock for Youtube™) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-09-11] CHR Extension: (9GAG Mini) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmkmihphgjhmeabggdcokmkjhbnmdml [2013-09-11] CHR Extension: (WeatherBug) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco [2013-09-11] CHR Extension: (Erweiterung \) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2013-09-11] CHR Extension: (Chrome In-App Payments service) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-07] CHR Extension: (360 WebShield Plug-in) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\pppagaglfkmlpgobnlenhknilehpmcbo [2014-08-22] CHR HKLM-x32\...\Chrome\Extension: [pppagaglfkmlpgobnlenhknilehpmcbo] - C:\Program Files\360\360 Internet Security\safemon\360webshield.crx [2014-07-18] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) ATTENTION: => Could not perform signature verification. Cryptographic Service is not running. R2 360rp; C:\Program Files\360\360 Internet Security\360rps.exe [310352 2014-04-16] (Qihu 360 Software Co., Ltd.) R2 Apache2.4; C:\xampp\apache\bin\httpd.exe [22016 2012-08-18] (Apache Software Foundation) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () S3 DAUpdaterSvc; G:\SteamLibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2013-12-10] (BioWare) R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [68136 2009-06-17] () R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1498000 2013-04-26] (Binary Fortress Software) R2 FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [632320 2012-05-11] (FileZilla Project) S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) R2 mysql; C:\xampp\mysql\bin\mysqld.exe [8186368 2012-07-20] () S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3975544 2012-05-09] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-30] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.) S3 scan; C:\Program Files\360\360 Internet Security\scan.dll [423144 2013-02-20] (S.C. BitDefender S.R.L) R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) R2 ZhuDongFangYu; C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe [236360 2014-04-23] (Qihu 360 Software Co., Ltd.) S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [97872 2014-04-21] (Qihu 360 Software Co., Ltd.) R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [67664 2014-04-23] (Qihu 360 Software Co., Ltd.) R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [305744 2014-04-29] (Qihu 360 Software Co., Ltd.) S3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [41552 2014-04-29] (Qihu 360 Software Co., Ltd.) R1 360fsflt; C:\Windows\System32\DRIVERS\360FsFlt.sys [304208 2014-05-07] (Qihu 360 Software Co., Ltd.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2013-02-02] () R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [116480 2013-09-25] (AVM Berlin) R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [180816 2014-04-18] (Qihu 360 Software Co., Ltd.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-31] (DT Soft Ltd) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-02-24] () R3 GWHid; C:\Windows\System32\DRIVERS\GWHid.sys [22648 2010-06-13] (Microsoft Corporation) S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [24088 2009-07-09] (H+H Software GmbH) R3 IOMap; C:\Windows\system32\drivers\IOMap64.sys [24824 2013-02-19] (ASUSTeK Computer Inc.) R3 ksaud; C:\Windows\System32\drivers\ksaud.sys [2033024 2013-08-05] (Creative Technology Ltd.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2013-02-02] () S1 mbmiodrvr; C:\Windows\syswow64\mbmiodrvr.sys [4608 2004-04-10] (cansoft@livewiredev.com) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) S3 PVUSB; C:\Windows\System32\DRIVERS\CESG64.sys [63808 2007-02-19] (CASIO COMPUTER CO.,LTD.) S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [223256 2011-04-19] (H+H Software GmbH) R3 VL807; C:\Windows\System32\DRIVERS\VL807.sys [36728 2010-06-13] () R3 VL807; C:\Windows\SysWOW64\DRIVERS\VL807.sys [28920 2010-06-13] () R1 vmm; C:\Windows\system32\Treiber\vmm.sys [294232 2012-12-31] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-28 20:13 - 2014-08-28 20:13 - 00028011 _____ () C:\Users\Franky\Desktop\FRST.txt 2014-08-28 19:56 - 2014-08-28 19:56 - 00000758 _____ () C:\Users\Franky\Desktop\JRT.txt 2014-08-28 19:47 - 2014-08-28 19:47 - 00021074 _____ () C:\Users\Franky\Desktop\AdwCleaner[S0].txt 2014-08-28 19:01 - 2014-08-28 19:42 - 00000000 ____D () C:\AdwCleaner 2014-08-28 19:00 - 2014-08-28 19:00 - 01016261 _____ (Thisisu) C:\Users\Franky\Desktop\JRT(1).exe 2014-08-28 18:59 - 2014-08-28 19:00 - 01364531 _____ () C:\Users\Franky\Desktop\adwcleaner_3.308.exe 2014-08-28 18:13 - 2014-08-28 18:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-28 18:13 - 2014-08-28 18:13 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-28 18:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-28 18:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-28 18:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-28 18:11 - 2014-08-28 18:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Franky\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-28 18:09 - 2013-02-19 18:02 - 00024824 _____ (ASUSTeK Computer Inc.) C:\Windows\system32\Drivers\IOMap64.sys 2014-08-27 20:26 - 2014-08-27 20:26 - 00125611 _____ () C:\ComboFix.txt 2014-08-27 20:01 - 2014-08-27 20:27 - 00000000 ____D () C:\ComboFix 2014-08-27 20:01 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-08-27 20:01 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-08-27 20:01 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-08-27 19:47 - 2014-08-27 20:27 - 00000000 ____D () C:\Qoobox 2014-08-27 19:46 - 2014-08-27 20:20 - 00000000 ____D () C:\Windows\erdnt 2014-08-25 19:25 - 2014-08-25 19:26 - 00504236 _____ () C:\Users\Franky\Downloads\sh3-blackfranky-0b8881bb8de4a8b.rar 2014-08-25 19:15 - 2014-08-28 20:13 - 00000000 ____D () C:\FRST 2014-08-25 19:14 - 2014-08-25 19:14 - 02103296 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe 2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-24 00:02 - 2014-08-24 18:00 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger 2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3 2014-08-23 17:07 - 2014-08-23 21:33 - 00000000 ____D () C:\ProgramData\Firefly Studios 2014-08-23 17:05 - 2014-08-23 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2014-08-23 17:05 - 2014-08-23 17:07 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends 2014-08-23 17:04 - 2014-08-23 17:21 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade 2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar 2014-08-16 00:04 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-16 00:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-16 00:04 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-16 00:04 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-16 00:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-16 00:04 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-16 00:03 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-16 00:03 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-13 22:11 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-13 22:11 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-13 22:11 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-13 22:11 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-13 22:11 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-13 22:11 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-13 22:11 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-13 22:11 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-13 22:11 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-13 22:11 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-13 22:11 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-13 22:11 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-13 22:11 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-13 22:11 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-13 22:11 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-13 22:11 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-13 22:11 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-13 22:11 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-13 22:11 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-13 22:11 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-13 22:11 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-13 22:11 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-13 22:11 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-13 22:11 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-13 22:11 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-13 22:11 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-13 22:11 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-13 22:11 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-13 22:11 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-13 22:11 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-13 22:11 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-13 22:11 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-13 22:11 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-13 22:11 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-13 22:11 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-13 22:11 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-13 22:11 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-13 22:11 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-13 22:11 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-13 22:11 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-13 22:11 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-13 22:11 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-13 22:11 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-13 22:11 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-13 22:11 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-13 22:11 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-13 22:11 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-13 22:11 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-13 22:11 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-13 22:11 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-13 22:11 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-13 22:11 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-13 22:11 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-13 22:11 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-13 22:11 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-13 22:11 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-13 22:11 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-13 22:11 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-13 22:11 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-13 22:11 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-13 22:11 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-13 22:11 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-13 22:11 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-13 22:11 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-13 22:11 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-13 22:11 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-13 22:11 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-13 22:11 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-13 22:11 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-13 22:11 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-13 22:09 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-13 22:09 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-13 22:09 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-13 22:09 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp 2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp 2014-08-13 18:00 - 2014-08-06 07:10 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi 2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip 2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet 2014-08-07 19:59 - 2014-08-07 20:06 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe 2014-08-05 22:41 - 2014-08-05 22:42 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 00:36 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-03 00:36 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-03 00:36 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-03 00:36 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-03 00:35 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-03 00:35 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-03 00:35 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-03 00:35 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-03 00:35 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-03 00:35 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment 2014-07-31 22:00 - 2014-08-01 19:36 - 00000000 ____D () C:\Users\Franky\Documents\Shiner ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-28 20:13 - 2014-08-28 20:13 - 00028011 _____ () C:\Users\Franky\Desktop\FRST.txt 2014-08-28 20:13 - 2014-08-25 19:15 - 00000000 ____D () C:\FRST 2014-08-28 20:08 - 2012-08-31 17:45 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-28 19:56 - 2014-08-28 19:56 - 00000758 _____ () C:\Users\Franky\Desktop\JRT.txt 2014-08-28 19:53 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-28 19:53 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-28 19:47 - 2014-08-28 19:47 - 00021074 _____ () C:\Users\Franky\Desktop\AdwCleaner[S0].txt 2014-08-28 19:47 - 2013-05-20 14:36 - 00000000 ___RD () C:\Users\Franky\Dropbox 2014-08-28 19:47 - 2013-05-20 14:34 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Dropbox 2014-08-28 19:45 - 2012-08-31 17:45 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-28 19:44 - 2014-06-09 09:34 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-28 19:44 - 2012-06-06 23:06 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2014-08-28 19:44 - 2010-11-21 05:47 - 00600706 _____ () C:\Windows\PFRO.log 2014-08-28 19:44 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-28 19:44 - 2009-07-14 06:51 - 00446170 _____ () C:\Windows\setupact.log 2014-08-28 19:43 - 2012-06-07 04:29 - 01144878 _____ () C:\Windows\WindowsUpdate.log 2014-08-28 19:42 - 2014-08-28 19:01 - 00000000 ____D () C:\AdwCleaner 2014-08-28 19:00 - 2014-08-28 19:00 - 01016261 _____ (Thisisu) C:\Users\Franky\Desktop\JRT(1).exe 2014-08-28 19:00 - 2014-08-28 18:59 - 01364531 _____ () C:\Users\Franky\Desktop\adwcleaner_3.308.exe 2014-08-28 19:00 - 2014-07-18 18:55 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\360safe 2014-08-28 18:58 - 2014-04-30 00:33 - 00000000 ____D () C:\Users\Franky\Desktop\SaveDon'tStarve 2014-08-28 18:57 - 2013-02-24 19:30 - 00000000 ____D () C:\Users\Franky\AppData\Local\TSVNCache 2014-08-28 18:55 - 2009-07-14 06:45 - 00380848 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-28 18:13 - 2014-08-28 18:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-28 18:13 - 2014-08-28 18:13 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-28 18:12 - 2014-08-28 18:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Franky\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-27 21:26 - 2013-02-24 14:03 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-08-27 20:27 - 2014-08-27 20:01 - 00000000 ____D () C:\ComboFix 2014-08-27 20:27 - 2014-08-27 19:47 - 00000000 ____D () C:\Qoobox 2014-08-27 20:26 - 2014-08-27 20:26 - 00125611 _____ () C:\ComboFix.txt 2014-08-27 20:20 - 2014-08-27 19:46 - 00000000 ____D () C:\Windows\erdnt 2014-08-27 20:19 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-08-27 19:44 - 2014-06-30 22:17 - 00000000 ____D () C:\Users\Franky\Downloads\Verschiedene Dateien 2014-08-26 20:16 - 2012-06-06 23:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-25 19:26 - 2014-08-25 19:25 - 00504236 _____ () C:\Users\Franky\Downloads\sh3-blackfranky-0b8881bb8de4a8b.rar 2014-08-25 19:14 - 2014-08-25 19:14 - 02103296 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe 2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-24 18:00 - 2014-08-24 00:02 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger 2014-08-24 16:49 - 2014-05-27 19:52 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Spotify 2014-08-24 11:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-24 01:50 - 2012-06-17 18:37 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Skype 2014-08-24 00:03 - 2012-06-09 00:29 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3 2014-08-23 21:33 - 2014-08-23 17:07 - 00000000 ____D () C:\ProgramData\Firefly Studios 2014-08-23 21:32 - 2012-06-06 23:31 - 00260032 _____ () C:\Windows\DirectX.log 2014-08-23 20:29 - 2014-04-13 18:31 - 00000000 ____D () C:\Users\Franky\AppData\Local\JDownloader v2.0 2014-08-23 17:21 - 2014-08-23 17:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2014-08-23 17:21 - 2014-08-23 17:04 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade 2014-08-23 17:07 - 2014-08-23 17:05 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends 2014-08-22 20:25 - 2012-08-01 02:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft 2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar 2014-08-16 09:54 - 2014-07-08 18:43 - 00000000 ____D () C:\Windows\rescache 2014-08-16 08:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-16 00:23 - 2012-12-18 19:59 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-16 00:19 - 2013-07-15 10:41 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-16 00:11 - 2012-11-20 19:13 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-16 00:03 - 2014-06-15 16:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-15 19:20 - 2014-07-18 18:55 - 00000000 _RSHD () C:\360SANDBOX 2014-08-14 18:23 - 2013-05-20 14:35 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-13 18:33 - 2014-02-15 20:50 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\TEdit 2014-08-13 18:18 - 2013-12-14 10:48 - 00248832 ___SH () C:\Users\Franky\Documents\Thumbs.db 2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp 2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp 2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TEdit 2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\Program Files (x86)\TEdit 2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip 2014-08-12 19:18 - 2013-12-31 13:25 - 00000000 ____D () C:\Users\Franky\AppData\Local\Game Dev Tycoon - Steam 2014-08-09 14:21 - 2012-08-15 11:11 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Audacity 2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet 2014-08-07 20:06 - 2014-08-07 19:59 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe 2014-08-07 04:06 - 2014-08-13 22:09 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-13 22:09 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-06 07:10 - 2014-08-13 18:00 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi 2014-08-05 22:42 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou 2014-08-04 16:53 - 2010-11-21 08:50 - 00701118 _____ () C:\Windows\system32\perfh007.dat 2014-08-04 16:53 - 2010-11-21 08:50 - 00150298 _____ () C:\Windows\system32\perfc007.dat 2014-08-04 16:53 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-04 16:47 - 2014-06-06 07:41 - 00000000 ____D () C:\Users\Franky\Desktop\Hörbucher 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-02 13:23 - 2013-09-24 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-01 19:36 - 2014-07-31 22:00 - 00000000 ____D () C:\Users\Franky\Documents\Shiner 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment 2014-08-01 01:41 - 2014-08-13 22:11 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-01 01:16 - 2014-08-13 22:11 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll Files to move or delete: ==================== C:\Users\Franky\jagex_cl_runescape_LIVE.dat C:\Users\Franky\random.dat C:\Users\Simon\Dragonica_DE(1).exe C:\Users\Simon\Dragonica_DE_Phoenix_20120720.exe C:\Users\Simon\jagex_cl_runescape_LIVE.dat C:\Users\Simon\random.dat Some content of TEMP: ==================== C:\Users\Franky\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplrt7cy.dll C:\Users\Franky\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-08-28 18:38 ==================== End Of Log ============================ --- --- --- |
29.08.2014, 12:36 | #10 |
/// the machine /// TB-Ausbilder | Nur Firefox kann Internetseiten aufrufen, keine andere AnwendungESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.08.2014, 08:19 | #11 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Das Problem, dass die Namensschlüsselung nicht funktioniert (und damit eingeschränkte Konnektivität angezeigt wird) ist immernoch vorhanden. Eset-Log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=daf6528ce5175b42b98a3286e1e7af56 # engine=19906 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-30 03:53:45 # local_time=2014-08-30 05:53:45 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 287779 161000675 0 0 # compatibility_mode_1='360 Internet Security' # compatibility_mode=16386 16777213 100 98 45296 48096232 0 0 # scanned=1082791 # found=53 # cleaned=0 # scan_time=45097 sh=C3F40FA6674806552A891192BBACBA164E630B43 ft=1 fh=b1fbd04628adf8b1 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="C:\Program Files (x86)\Rockstar Games\Max Payne 3\gsrld.dll" sh=A32AA942597786B380ABDA361918B5E6BF4F26D1 ft=1 fh=e10233d53431d7f2 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="C:\Program Files (x86)\Warner Bros. Interactive Entertainment\LEGO® The Lord of the Rings™\rld.dll" sh=7C1B326387D941B03BF14B3D7A54B38099918F34 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-1723.BU Trojaner" ac=I fn="C:\Users\Franky\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\fb2e48e-4a7f00e8" sh=C9ED8090260F0F48A6821067B0D5351EEB99E18B ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Franky\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\4c6d7fe0-2dbfd245" sh=E8307B8D27573BED8AA5D976FB3C9092F7858D04 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Franky\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\3603bc28-50cbdaaa" sh=70669EF03D5F84D7CB8193CF8C48BE39140E2EB1 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-1723.Y Trojaner" ac=I fn="C:\Users\Franky\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\30756cac-1ee85581" sh=10A327D76D5FC13A722A34F0AC48D36BC138B361 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Franky\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\569ff2d-1c48167b" sh=18369372382C9B8458AE20066F61A1FF93E34D4F ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-1723.AQ Trojaner" ac=I fn="C:\Users\Franky\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\19a4e6bc-784c3721" sh=7C71A2E7B95045D403B159F03F27B4C3111D21E7 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-0507.CX Trojaner" ac=I fn="C:\Users\Franky\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\2ac0763f-53521d7a" sh=CC25EAF4482031F2D63033D9452CC9A598521AAF ft=1 fh=156034c6e795c0db vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franky\Downloads\Final-Fantasy-Tactics-A2--Grimoire-of-the-Rift-lnstall.exe" sh=372191254F3FA86DEB165684489FD2A312F134DA ft=1 fh=c71c0011fc1c3bf6 vn="Variante von Win32/InstallCore.PO evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Franky\Downloads\WinSetupFromUSB-1-4_CB-DL-Manager.exe" sh=7C3F638B840F7506FAC40C8F70504958D7E4A6DC ft=0 fh=0000000000000000 vn="Variante von Java/Exploit.CVE-2012-1723.CP Trojaner" ac=I fn="C:\Users\Simon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\86b4953-73ac3fb2" sh=EDAF3A499D9F4E7E529F069EA521CFBF32D69E05 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-4681.F Trojaner" ac=I fn="C:\Users\Simon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\22181b55-5e6fcac1" sh=625FD73A367C2243D22FF09F7F78C1D298B99F75 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Simon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\4ca0f5c3-6436cde9" sh=427DFDC9226A69A57FC5C1904E681E74BEF4FFBF ft=0 fh=0000000000000000 vn="Variante von Java/Exploit.CVE-2013-1493.FY Trojaner" ac=I fn="C:\Users\Simon\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\70dd8d7a-2d20856e" sh=5BAFD51453714E4815F80C01DA03F9DEF0CDE8C9 ft=1 fh=5b92e1356f69874e vn="Win32/DownloadAdmin.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Simon\Downloads\cbsidlm-tr1_8-RPG_Maker_XP-ORG2-10437117.exe" sh=56317548CABBAE9F60BF94CE456C5619632CBCAC ft=1 fh=c71c0011e48792bc vn="Win32/InstallCore.MF evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Simon\Downloads\COMPUTER_BILD-Download-Manager_fuer_Xpadder.exe" sh=7D26DFBD077CD598E5481774933C229396FC4B0F ft=1 fh=0085dd168c9c240e vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Simon\Downloads\RPG-Maker-XP-1.02_Installer.exe" sh=0F3AA61D80A4AC357E68B12463EA1690FE2A7DA5 ft=1 fh=eb8a56df19d248aa vn="Win32/Malavida.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Simon\Downloads\rpg-maker-xp-windows-downloader.exe" sh=3A4DE68EEF115C12E41C11CD2E0DC95E8ECA555E ft=1 fh=40edd108ad439e1b vn="Win32/Malavida.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Simon\Downloads\rpg-maker-xp-windows-malavida.exe" sh=F336F87A78849EFDA90BA8F8A6298DB37DBDFFFD ft=1 fh=f128cf84761fb9a3 vn="Variante von Win32/OpenInstall evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Simon\Downloads\SnakeClassics.exe" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="G:\Dateien\Downloads\leloofthrirld\LEGO.Lord.of.the.Rings-RELOADED\rld-legolotr.iso" sh=A57CFA9B2932848CC425C7C988C82845C1FEDCF4 ft=0 fh=0000000000000000 vn="Win32/Toolbar.AskSBar evtl. unerwünschte Anwendung" ac=I fn="G:\Dateien\Programme\Installs und Images\Nero 9\nero9.iso" sh=6E45431B698CDB7BE8F1A41266BE7B327F33AD38 ft=1 fh=e5f91a3476785862 vn="Win32/Adware.ADON evtl. unerwünschte Anwendung" ac=I fn="G:\Dateien\Programme\Nützliche Progs\Unlocker1.9.1.exe" sh=FCBEF7CC6D1E6A494385F49B7C38634D3EF0BD58 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-04-27 100001\Backup files 101.zip" sh=EE294EC2E1028D6EC15CC0049D94ACA71774C02F ft=0 fh=0000000000000000 vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-04-27 100001\Backup files 107.zip" sh=0013ADE0E50F4AD0AEBAC49E833063B9B9AE7636 ft=0 fh=0000000000000000 vn="Variante von Win32/ELEX.M evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-04-27 100001\Backup files 123.zip" sh=1D9088A978E075D1288D12E0BCABA4535F60A405 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-04-27 100001\Backup files 131.zip" sh=E785176C43290783CAA3180A07C8A895CE5C2607 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-04-27 100001\Backup files 132.zip" sh=825CC56D051FB9E8287438A919E8ACA770902E81 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-04-27 100001\Backup files 133.zip" sh=4173C8C17129EC82B8368914E2873B68978E9C92 ft=0 fh=0000000000000000 vn="Variante von Win32/Somoto.A evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-05-04 111254\Backup files 5.zip" sh=51F74A6A0F20B490EC9491A5672C31C7E76DB7AB ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-05-11 100002\Backup files 22.zip" sh=D82EDD8CE75B1827F18614F3398EB7238EED0DEF ft=0 fh=0000000000000000 vn="Variante von Win32/ExpressDownloader.J evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-05-18 104600\Backup files 4.zip" sh=6F541222E87ABEA70CB3F9288AB8247C04677165 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-05-25 161238\Backup files 4.zip" sh=651F29A87CB494138309B35F7622CE9A5C1F234B ft=0 fh=0000000000000000 vn="Variante von Win32/ExpressDownloader.J evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-06-01 100000\Backup files 5.zip" sh=860985EE0B41515D56D6CF2F779807CEB6CA66E8 ft=0 fh=0000000000000000 vn="Win32/SoftonicDownloader.G evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-06-15 100053\Backup files 7.zip" sh=693FCA8F1AD81A7B5A835B138F6E12C37337485E ft=0 fh=0000000000000000 vn="Variante von Win32/iLivid.A evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-06-15 100053\Backup files 9.zip" sh=23938BBE8AEC024C5D7AB74E25FB697B929700BF ft=0 fh=0000000000000000 vn="Variante von Win32/InstallCore.PO evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-06-22 100001\Backup files 10.zip" sh=9295D48F36E54FC8AA7DD37EB3A90ED00C59C861 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="G:\FRANKY-PC\Backup Set 2014-04-27 100001\Backup Files 2014-06-22 100001\Backup files 69.zip" sh=E9509EEB1A3122EF2B7EF9C78640ECB1CDCE38F5 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 117.zip" sh=6AD22CF27F205598BD7D757B0C4EDDDF50452CDE ft=0 fh=0000000000000000 vn="Variante von Win32/ExpressDownloader.J evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 122.zip" sh=F1AC0C43426F245F02BBA0D37764F3528922A7C4 ft=0 fh=0000000000000000 vn="Variante von Win32/ExpressDownloader.H evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 123.zip" sh=D12D01CE0E261603BF86C4A76788BAE808E72357 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 124.zip" sh=FE899FB881DBB4D2C6DAFDA4A718D06A5F8EF96C ft=0 fh=0000000000000000 vn="Variante von Win32/InstallCore.PO evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 125.zip" sh=1C440D39A03D353C48FC67BA492A2A7D067B2F30 ft=0 fh=0000000000000000 vn="Variante von Win32/ELEX.M evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 139.zip" sh=F02C741039348419C33F095815DEF32824C1A749 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 147.zip" sh=408D2ACBC231F920D6AE870BDE75F9DD9E01CDA9 ft=0 fh=0000000000000000 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 148.zip" sh=6C2E25E0B54A46C888D64447D73D817B721C3B33 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 149.zip" sh=A0BB11B3431A6AEA9B9E6F317BD25B9422C57A43 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 150.zip" sh=3A60B77E9F8A0CC2DE1D85A4E91D04C32CCAF6F3 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-06 102446\Backup files 647.zip" sh=7329CFC875DCBC4254796438FB8F10D2263656F8 ft=0 fh=0000000000000000 vn="Win32/TrojanDownloader.Elenoocka.A Trojaner" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-20 100001\Backup files 12.zip" sh=D469F737A93C2569B115F30C82F1C1483BCE140F ft=0 fh=0000000000000000 vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung" ac=I fn="G:\FRANKY-PC\Backup Set 2014-07-06 102446\Backup Files 2014-07-20 100001\Backup files 8.zip" sh=8871E6FA32DFAA68F84F8E87D81C3222996D41A9 ft=1 fh=9527eda5fc81439a vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="G:\Watch Dogs Digital Deluxe Edition\bin\Watch_Dogs_3dm.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.87 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` 360 Internet Security WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` DJ Java Decompiler v.3.12.12.96 JavaFX 2.1.1 JavaFX 2.1.1 SDK Java 7 Update 17 Java 7 Update 45 Java SE Development Kit 7 Update 5 Java version out of Date! Adobe Flash Player 11.9.900.117 Flash Player out of Date! Adobe Reader 10.1.8 Adobe Reader out of Date! Mozilla Firefox (31.0) Google Chrome 36.0.1985.125 Google Chrome 36.0.1985.143 ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-08-2014 01 Ran by Franky (administrator) on FRANKY-PC on 30-08-2014 09:17:02 Running from C:\Users\Franky\Desktop Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360rps.exe (Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Windows\SysWOW64\ASGT.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (FileZilla Project) C:\xampp\FileZillaFTP\FileZillaServer.exe () C:\xampp\mysql\bin\mysqld.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Tobias Süllhöfer Software) C:\Windows\System32\wtmcore.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe () C:\Program Files (x86)\puush\puush.exe () C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Dropbox, Inc.) C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Don HO don.h@free.fr) C:\Program Files (x86)\Notepad++\notepad++.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor) HKLM\...\Run: [Creative SB Monitoring Utility] => RunDll32 sbavmon.dll,SBAVMonitor HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Creative SB Monitoring Utility Launcher] => RunDll32 SBAVMonL.dll,SBAVMonitorLauncher HKLM\...\Run: [360sd] => C:\Program Files\360\360 Internet Security\360sdrun.exe [287560 2014-04-16] (Qihu 360 Software Co., Ltd.) HKLM-x32\...\Run: [Sound Blaster Recon3D SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe [1103872 2013-09-04] (Creative Technology Ltd) HKLM\...\Winlogon: [Shell] explorer.exe,wtmcore.exe HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [ISUSPM Startup] => c:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7283072 2013-04-26] (Binary Fortress Software) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2013-08-14] () HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [Amazon Music] => C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] () HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableClock] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoNetworkConnections] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoCommonGroups] 0 Startup: C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0FB66E927017CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {8B7A2BC3-75E1-4f5d-AA53-26176AE0EFEF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {DD1A1D91-E60E-46d0-A1D0-A2823A9C2B12} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms} SearchScopes: HKCU - {EE29A4DD-95C6-456c-A00A-C52454462FEF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files\360\360 Internet Security\safemon\safemon64.dll (Qihu 360 Software Co., Ltd.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default FF Homepage: about:home FF NetworkProxy: "ftp", "proxyus1.stealthy.co" FF NetworkProxy: "ftp_port", 3128 FF NetworkProxy: "http", "proxyus1.stealthy.co" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "proxyus1.stealthy.co" FF NetworkProxy: "socks_port", 3128 FF NetworkProxy: "ssl", "proxyus1.stealthy.co" FF NetworkProxy: "ssl_port", 3128 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Amazon-Icon - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\amazon-icon@giga.de [2014-07-05] FF Extension: SearchNewTab - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\uuy0qpwgmv@t-oeua.org [2013-09-11] FF Extension: ReloadEvery - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-04-16] FF Extension: Adblock Plus - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-07-14] Chrome: ======= CHR HomePage: Default -> CHR RestoreOnStartup: Default -> "" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Unity Player) - C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Profile: C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (podcast.de) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\bofligbealbmofkgodhlglkefkpegjnb [2013-09-11] CHR Extension: (Adblock Plus) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-09-11] CHR Extension: (Adblock for Youtube™) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-09-11] CHR Extension: (9GAG Mini) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmkmihphgjhmeabggdcokmkjhbnmdml [2013-09-11] CHR Extension: (WeatherBug) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco [2013-09-11] CHR Extension: (Erweiterung \) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2013-09-11] CHR Extension: (Chrome In-App Payments service) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-07] CHR Extension: (360 WebShield Plug-in) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\pppagaglfkmlpgobnlenhknilehpmcbo [2014-08-29] CHR HKLM-x32\...\Chrome\Extension: [pppagaglfkmlpgobnlenhknilehpmcbo] - C:\Program Files\360\360 Internet Security\safemon\360webshield.crx [2014-07-18] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) ATTENTION: => Could not perform signature verification. Cryptographic Service is not running. R2 360rp; C:\Program Files\360\360 Internet Security\360rps.exe [310352 2014-04-16] (Qihu 360 Software Co., Ltd.) R2 Apache2.4; C:\xampp\apache\bin\httpd.exe [22016 2012-08-18] (Apache Software Foundation) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () S3 DAUpdaterSvc; G:\SteamLibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2013-12-10] (BioWare) R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [68136 2009-06-17] () R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1498000 2013-04-26] (Binary Fortress Software) R2 FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [632320 2012-05-11] (FileZilla Project) S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) R2 mysql; C:\xampp\mysql\bin\mysqld.exe [8186368 2012-07-20] () S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3975544 2012-05-09] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-30] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.) S3 scan; C:\Program Files\360\360 Internet Security\scan.dll [423144 2013-02-20] (S.C. BitDefender S.R.L) R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) R2 ZhuDongFangYu; C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe [236360 2014-04-23] (Qihu 360 Software Co., Ltd.) S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [97872 2014-04-21] (Qihu 360 Software Co., Ltd.) R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [67664 2014-04-23] (Qihu 360 Software Co., Ltd.) R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [305744 2014-04-29] (Qihu 360 Software Co., Ltd.) S3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [41552 2014-04-29] (Qihu 360 Software Co., Ltd.) R1 360fsflt; C:\Windows\System32\DRIVERS\360FsFlt.sys [304208 2014-05-07] (Qihu 360 Software Co., Ltd.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2013-02-02] () R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [116480 2013-09-25] (AVM Berlin) R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [180816 2014-04-18] (Qihu 360 Software Co., Ltd.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-31] (DT Soft Ltd) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-02-24] () R3 GWHid; C:\Windows\System32\DRIVERS\GWHid.sys [22648 2010-06-13] (Microsoft Corporation) S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [24088 2009-07-09] (H+H Software GmbH) R3 IOMap; C:\Windows\system32\drivers\IOMap64.sys [24824 2013-02-19] (ASUSTeK Computer Inc.) R3 ksaud; C:\Windows\System32\drivers\ksaud.sys [2033024 2013-08-05] (Creative Technology Ltd.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2013-02-02] () S1 mbmiodrvr; C:\Windows\syswow64\mbmiodrvr.sys [4608 2004-04-10] (cansoft@livewiredev.com) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) S3 PVUSB; C:\Windows\System32\DRIVERS\CESG64.sys [63808 2007-02-19] (CASIO COMPUTER CO.,LTD.) S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [223256 2011-04-19] (H+H Software GmbH) R3 VL807; C:\Windows\System32\DRIVERS\VL807.sys [36728 2010-06-13] () R3 VL807; C:\Windows\SysWOW64\DRIVERS\VL807.sys [28920 2010-06-13] () R1 vmm; C:\Windows\system32\Treiber\vmm.sys [294232 2012-12-31] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-30 09:17 - 2014-08-30 09:17 - 00027932 _____ () C:\Users\Franky\Desktop\FRST.txt 2014-08-30 09:16 - 2014-08-30 09:16 - 00000000 ____D () C:\Users\Franky\Desktop\FRST-OlderVersion 2014-08-30 09:11 - 2014-08-30 09:11 - 00000000 ____D () C:\Windows\LastGood 2014-08-30 09:05 - 2014-08-30 09:05 - 00854417 _____ () C:\Users\Franky\Desktop\SecurityCheck.exe 2014-08-29 21:54 - 2014-08-29 21:59 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 2 2014-08-29 18:41 - 2014-08-29 18:41 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Trine1 2014-08-29 17:18 - 2014-08-29 17:18 - 02347384 _____ (ESET) C:\Users\Franky\Downloads\esetsmartinstaller_deu.exe 2014-08-28 20:38 - 2014-08-28 20:38 - 00000000 __SHD () C:\360Rec 2014-08-28 20:15 - 2014-08-28 20:15 - 00008393 _____ () C:\Users\Franky\Desktop\mbam.txt 2014-08-28 20:15 - 2014-08-28 20:15 - 00008393 _____ () C:\mbam.txt 2014-08-28 19:56 - 2014-08-28 19:56 - 00000758 _____ () C:\Users\Franky\Desktop\JRT.txt 2014-08-28 19:47 - 2014-08-28 19:47 - 00021074 _____ () C:\Users\Franky\Desktop\AdwCleaner[S0].txt 2014-08-28 19:01 - 2014-08-28 19:42 - 00000000 ____D () C:\AdwCleaner 2014-08-28 19:00 - 2014-08-28 19:00 - 01016261 _____ (Thisisu) C:\Users\Franky\Desktop\JRT(1).exe 2014-08-28 18:59 - 2014-08-28 19:00 - 01364531 _____ () C:\Users\Franky\Desktop\adwcleaner_3.308.exe 2014-08-28 18:13 - 2014-08-28 20:14 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-28 18:13 - 2014-08-28 18:13 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-28 18:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-28 18:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-28 18:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-28 18:11 - 2014-08-28 18:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Franky\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-28 18:09 - 2013-02-19 18:02 - 00024824 _____ (ASUSTeK Computer Inc.) C:\Windows\system32\Drivers\IOMap64.sys 2014-08-27 20:26 - 2014-08-27 20:26 - 00125611 _____ () C:\ComboFix.txt 2014-08-27 20:01 - 2014-08-27 20:27 - 00000000 ____D () C:\ComboFix 2014-08-27 20:01 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-08-27 20:01 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-08-27 20:01 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-08-27 20:01 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-08-27 19:47 - 2014-08-27 20:27 - 00000000 ____D () C:\Qoobox 2014-08-27 19:46 - 2014-08-27 20:20 - 00000000 ____D () C:\Windows\erdnt 2014-08-25 19:25 - 2014-08-25 19:26 - 00504236 _____ () C:\Users\Franky\Downloads\sh3-blackfranky-0b8881bb8de4a8b.rar 2014-08-25 19:15 - 2014-08-30 09:17 - 00000000 ____D () C:\FRST 2014-08-25 19:14 - 2014-08-30 09:16 - 02103808 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe 2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-24 00:02 - 2014-08-24 18:00 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger 2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3 2014-08-23 17:07 - 2014-08-29 21:54 - 00000000 ____D () C:\ProgramData\Firefly Studios 2014-08-23 17:05 - 2014-08-23 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2014-08-23 17:05 - 2014-08-23 17:07 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends 2014-08-23 17:04 - 2014-08-29 21:54 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade 2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar 2014-08-16 00:04 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-16 00:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-16 00:04 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-16 00:04 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-16 00:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-16 00:04 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-16 00:03 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-16 00:03 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-13 22:11 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-13 22:11 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-13 22:11 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-13 22:11 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-13 22:11 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-13 22:11 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-13 22:11 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-13 22:11 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-13 22:11 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-13 22:11 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-13 22:11 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-13 22:11 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-13 22:11 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-13 22:11 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-13 22:11 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-13 22:11 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-13 22:11 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-13 22:11 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-13 22:11 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-13 22:11 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-13 22:11 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-13 22:11 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-13 22:11 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-13 22:11 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-13 22:11 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-13 22:11 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-13 22:11 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-13 22:11 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-13 22:11 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-13 22:11 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-13 22:11 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-13 22:11 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-13 22:11 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-13 22:11 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-13 22:11 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-13 22:11 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-13 22:11 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-13 22:11 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-13 22:11 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-13 22:11 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-13 22:11 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-13 22:11 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-13 22:11 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-13 22:11 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-13 22:11 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-13 22:11 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-13 22:11 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-13 22:11 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-13 22:11 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-13 22:11 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-13 22:11 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-13 22:11 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-13 22:11 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-13 22:11 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-13 22:11 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-13 22:11 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-13 22:11 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-13 22:11 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-13 22:11 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-13 22:11 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-13 22:11 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-13 22:11 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-13 22:11 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-13 22:11 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-13 22:11 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-13 22:11 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-13 22:11 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-13 22:11 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-13 22:11 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-13 22:11 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-13 22:11 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-13 22:11 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-13 22:09 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-13 22:09 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-13 22:09 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-13 22:09 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp 2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp 2014-08-13 18:00 - 2014-08-06 07:10 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi 2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip 2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet 2014-08-07 19:59 - 2014-08-07 20:06 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe 2014-08-05 22:41 - 2014-08-05 22:42 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 00:36 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-03 00:36 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-03 00:36 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-03 00:36 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-03 00:35 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2014-08-03 00:35 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-03 00:35 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-08-03 00:35 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-03 00:35 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-08-03 00:35 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-03 00:35 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment 2014-07-31 22:00 - 2014-08-01 19:36 - 00000000 ____D () C:\Users\Franky\Documents\Shiner ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-30 09:17 - 2014-08-30 09:17 - 00027932 _____ () C:\Users\Franky\Desktop\FRST.txt 2014-08-30 09:17 - 2014-08-25 19:15 - 00000000 ____D () C:\FRST 2014-08-30 09:16 - 2014-08-30 09:16 - 00000000 ____D () C:\Users\Franky\Desktop\FRST-OlderVersion 2014-08-30 09:16 - 2014-08-25 19:14 - 02103808 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe 2014-08-30 09:11 - 2014-08-30 09:11 - 00000000 ____D () C:\Windows\LastGood 2014-08-30 09:08 - 2012-08-31 17:45 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-30 09:05 - 2014-08-30 09:05 - 00854417 _____ () C:\Users\Franky\Desktop\SecurityCheck.exe 2014-08-29 23:00 - 2013-02-24 14:03 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-08-29 21:59 - 2014-08-29 21:54 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 2 2014-08-29 21:54 - 2014-08-23 17:07 - 00000000 ____D () C:\ProgramData\Firefly Studios 2014-08-29 21:54 - 2014-08-23 17:04 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade 2014-08-29 21:54 - 2012-06-09 00:29 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-08-29 21:52 - 2012-06-06 23:31 - 00278543 _____ () C:\Windows\DirectX.log 2014-08-29 20:21 - 2012-06-07 04:29 - 01181360 _____ () C:\Windows\WindowsUpdate.log 2014-08-29 19:08 - 2012-08-31 17:45 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-29 18:41 - 2014-08-29 18:41 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Trine1 2014-08-29 17:19 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-29 17:19 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-29 17:18 - 2014-08-29 17:18 - 02347384 _____ (ESET) C:\Users\Franky\Downloads\esetsmartinstaller_deu.exe 2014-08-29 17:18 - 2014-07-18 18:55 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\360safe 2014-08-29 17:16 - 2013-05-20 14:36 - 00000000 ___RD () C:\Users\Franky\Dropbox 2014-08-29 17:15 - 2013-05-20 14:34 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Dropbox 2014-08-29 17:14 - 2013-02-24 19:30 - 00000000 ____D () C:\Users\Franky\AppData\Local\TSVNCache 2014-08-29 17:12 - 2014-06-09 09:34 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-29 17:12 - 2012-06-06 23:06 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2014-08-29 17:12 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-29 17:12 - 2009-07-14 06:51 - 00446338 _____ () C:\Windows\setupact.log 2014-08-29 17:12 - 2009-07-14 06:45 - 00380848 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-29 17:11 - 2010-11-21 05:47 - 00603168 _____ () C:\Windows\PFRO.log 2014-08-28 20:40 - 2013-02-24 16:09 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-08-28 20:38 - 2014-08-28 20:38 - 00000000 __SHD () C:\360Rec 2014-08-28 20:15 - 2014-08-28 20:15 - 00008393 _____ () C:\Users\Franky\Desktop\mbam.txt 2014-08-28 20:15 - 2014-08-28 20:15 - 00008393 _____ () C:\mbam.txt 2014-08-28 20:14 - 2014-08-28 18:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-28 19:56 - 2014-08-28 19:56 - 00000758 _____ () C:\Users\Franky\Desktop\JRT.txt 2014-08-28 19:47 - 2014-08-28 19:47 - 00021074 _____ () C:\Users\Franky\Desktop\AdwCleaner[S0].txt 2014-08-28 19:42 - 2014-08-28 19:01 - 00000000 ____D () C:\AdwCleaner 2014-08-28 19:00 - 2014-08-28 19:00 - 01016261 _____ (Thisisu) C:\Users\Franky\Desktop\JRT(1).exe 2014-08-28 19:00 - 2014-08-28 18:59 - 01364531 _____ () C:\Users\Franky\Desktop\adwcleaner_3.308.exe 2014-08-28 18:58 - 2014-04-30 00:33 - 00000000 ____D () C:\Users\Franky\Desktop\SaveDon'tStarve 2014-08-28 18:13 - 2014-08-28 18:13 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-28 18:12 - 2014-08-28 18:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Franky\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-27 20:27 - 2014-08-27 20:01 - 00000000 ____D () C:\ComboFix 2014-08-27 20:27 - 2014-08-27 19:47 - 00000000 ____D () C:\Qoobox 2014-08-27 20:26 - 2014-08-27 20:26 - 00125611 _____ () C:\ComboFix.txt 2014-08-27 20:20 - 2014-08-27 19:46 - 00000000 ____D () C:\Windows\erdnt 2014-08-27 20:19 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-08-27 19:44 - 2014-06-30 22:17 - 00000000 ____D () C:\Users\Franky\Downloads\Verschiedene Dateien 2014-08-26 20:16 - 2012-06-06 23:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-25 19:26 - 2014-08-25 19:25 - 00504236 _____ () C:\Users\Franky\Downloads\sh3-blackfranky-0b8881bb8de4a8b.rar 2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-08-24 18:00 - 2014-08-24 00:02 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger 2014-08-24 16:49 - 2014-05-27 19:52 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Spotify 2014-08-24 11:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-24 01:50 - 2012-06-17 18:37 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Skype 2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3 2014-08-23 20:29 - 2014-04-13 18:31 - 00000000 ____D () C:\Users\Franky\AppData\Local\JDownloader v2.0 2014-08-23 17:21 - 2014-08-23 17:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade 2014-08-23 17:07 - 2014-08-23 17:05 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends 2014-08-22 20:25 - 2012-08-01 02:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft 2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar 2014-08-16 09:54 - 2014-07-08 18:43 - 00000000 ____D () C:\Windows\rescache 2014-08-16 08:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-16 00:23 - 2012-12-18 19:59 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-16 00:19 - 2013-07-15 10:41 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-16 00:11 - 2012-11-20 19:13 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-16 00:03 - 2014-06-15 16:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-15 19:20 - 2014-07-18 18:55 - 00000000 _RSHD () C:\360SANDBOX 2014-08-14 18:23 - 2013-05-20 14:35 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-13 18:33 - 2014-02-15 20:50 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\TEdit 2014-08-13 18:18 - 2013-12-14 10:48 - 00248832 ___SH () C:\Users\Franky\Documents\Thumbs.db 2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp 2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp 2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TEdit 2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\Program Files (x86)\TEdit 2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip 2014-08-12 19:18 - 2013-12-31 13:25 - 00000000 ____D () C:\Users\Franky\AppData\Local\Game Dev Tycoon - Steam 2014-08-09 14:21 - 2012-08-15 11:11 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Audacity 2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk 2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet 2014-08-07 20:06 - 2014-08-07 19:59 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe 2014-08-07 04:06 - 2014-08-13 22:09 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-13 22:09 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-06 07:10 - 2014-08-13 18:00 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi 2014-08-05 22:42 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou 2014-08-04 16:53 - 2010-11-21 08:50 - 00701118 _____ () C:\Windows\system32\perfh007.dat 2014-08-04 16:53 - 2010-11-21 08:50 - 00150298 _____ () C:\Windows\system32\perfc007.dat 2014-08-04 16:53 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-04 16:47 - 2014-06-06 07:41 - 00000000 ____D () C:\Users\Franky\Desktop\Hörbucher 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh 2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-02 13:23 - 2013-09-24 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-01 19:36 - 2014-07-31 22:00 - 00000000 ____D () C:\Users\Franky\Documents\Shiner 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment 2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment 2014-08-01 01:41 - 2014-08-13 22:11 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-01 01:16 - 2014-08-13 22:11 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll Files to move or delete: ==================== C:\Users\Franky\jagex_cl_runescape_LIVE.dat C:\Users\Franky\random.dat C:\Users\Simon\Dragonica_DE(1).exe C:\Users\Simon\Dragonica_DE_Phoenix_20120720.exe C:\Users\Simon\jagex_cl_runescape_LIVE.dat C:\Users\Simon\random.dat Some content of TEMP: ==================== C:\Users\Franky\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp1cm0xr.dll C:\Users\Franky\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-08-28 18:38 ==================== End Of Log ============================ --- --- --- |
30.08.2014, 09:30 | #12 |
/// the machine /// TB-Ausbilder | Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Java, Flash und Adobe updaten. Download Ordner leren, Backups auf G löschen. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter cmd: ipconfig /flushdns Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.08.2014, 10:46 | #13 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Hat leider auch nicht geholfen. Hab auch danach neu gestartet. Fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-08-2014 01 Ran by Franky at 2014-08-30 11:45:07 Run:1 Running from C:\Users\Franky\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** cmd: ipconfig /flushdns ***************** ========= ipconfig /flushdns ========= Windows-IP-Konfiguration Der DNS-Aufl�sungscache wurde geleert. ========= End of CMD: ========= ==== End of Fixlog ==== Geändert von Franky1993 (30.08.2014 um 10:55 Uhr) |
30.08.2014, 15:36 | #14 |
/// the machine /// TB-Ausbilder | Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Downloade dir bitte Farbar's MiniToolBox auf deinen Desktop und starte das Tool Setze einen Haken bei folgenden Einträgen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.08.2014, 13:02 | #15 |
| Nur Firefox kann Internetseiten aufrufen, keine andere Anwendung Result.txt: Code:
ATTFilter MiniToolBox by Farbar Version: 21-07-2014 Ran by Franky (administrator) on 31-08-2014 at 12:35:09 Running from "C:\Users\Franky\Desktop" Microsoft Windows 7 Professional Service Pack 1 (X64) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows-IP-Konfiguration Der DNS-Auflճungscache wurde geleert. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= FF Proxy Settings: ============================== "network.proxy.ftp", "proxyus1.stealthy.co" "network.proxy.ftp_port", 3128 "network.proxy.http", "proxyus1.stealthy.co" "network.proxy.http_port", 3128 "network.proxy.no_proxies_on", "localhost, 127.0.0.1, stealthy.co" "network.proxy.share_proxy_settings", true "network.proxy.socks", "proxyus1.stealthy.co" "network.proxy.socks_port", 3128 "network.proxy.ssl", "proxyus1.stealthy.co" "network.proxy.ssl_port", 3128 "network.proxy.type", 0 "Reset FF Proxy Settings": Firefox Proxy settings were reset. ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ TP-LINK 300Mbps Wireless N Adapter = Drahtlosnetzwerkverbindung 10 (Connected) Realtek PCIe GBE Family Controller = LAN-Verbindung (Connected) TAP-Win32 Adapter V9 (Tunngle) = Tunngle (Hardware not present) Hamachi Network Interface = Hamachi (Hardware not present) Microsoft Virtual WiFi Miniport Adapter = Drahtlosnetzwerkverbindung 18 (Media disconnected) # ---------------------------------- # IPv4-Konfiguration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled set interface interface="Hamachi" forwarding=disabled advertise=disabled metric=9000 siteprefixlength=0 nud=disabled routerdiscovery=disabled managedaddress=disabled otherstateful=disabled weakhostsend=disabled weakhostreceive=disabled ignoredefaultroutes=disabled advertisedrouterlifetime=0 advertisedefaultroute=disabled currenthoplimit=0 forcearpndwolpattern=disabled enabledirectedmacwolpattern=disabled add address name="Drahtlosnetzwerkverbindung 4" address=192.168.137.1 mask=255.255.255.0 popd # Ende der IPv4-Konfiguration Windows-IP-Konfiguration Hostname . . . . . . . . . . . . : Franky-PC PrimŲes DNS-Suffix . . . . . . . : Knotentyp . . . . . . . . . . . . : Hybrid IP-Routing aktiviert . . . . . . : Nein WINS-Proxy aktiviert . . . . . . : Nein DNS-Suffixsuchliste . . . . . . . : fritz.box Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung 18: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter #11 Physikalische Adresse . . . . . . : 62-70-02-FC-A6-19 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Ethernet-Adapter LAN-Verbindung: Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Realtek PCIe GBE Family Controller Physikalische Adresse . . . . . . : 50-E5-49-30-60-FD DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Verbindungslokale IPv6-Adresse . : fe80::7d59:756c:dedd:85fe%59(Bevorzugt) IPv4-Adresse . . . . . . . . . . : 192.168.0.102(Bevorzugt) Subnetzmaske . . . . . . . . . . : 255.255.255.0 Lease erhalten. . . . . . . . . . : Sonntag, 31. August 2014 09:48:07 Lease lŵft ab. . . . . . . . . . : Sonntag, 31. August 2014 13:48:07 Standardgateway . . . . . . . . . : 192.168.0.1 DHCP-Server . . . . . . . . . . . : 192.168.0.1 DHCPv6-IAID . . . . . . . . . . . : 1079043401 DHCPv6-Client-DUID. . . . . . . . : 00-01-00-01-17-61-CB-53-00-1D-0F-B1-57-2C DNS-Server . . . . . . . . . . . : 192.168.0.1 NetBIOS ¢er TCP/IP . . . . . . . : Aktiviert Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung 10: Verbindungsspezifisches DNS-Suffix: fritz.box Beschreibung. . . . . . . . . . . : TP-LINK 300Mbps Wireless N Adapter Physikalische Adresse . . . . . . : 64-70-02-FC-A6-19 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja IPv6-Adresse. . . . . . . . . . . : 2a02:8108:2000:ed0:b000:5887:9ec5:1ac8(Bevorzugt) TemporŲe IPv6-Adresse. . . . . . : 2a02:8108:2000:ed0:e8af:67c0:ebe3:752b(Bevorzugt) IPv6-Adresse. . . . . . . . . . . : 4006:6da:c0a8:b22d:b000:5887:9ec5:1ac8(Verworfen) IPv6-Adresse. . . . . . . . . . . : 4006:8078:c0a8:b22d:b000:5887:9ec5:1ac8(Verworfen) IPv6-Adresse. . . . . . . . . . . : 4006:9056:c0a8:b22d:b000:5887:9ec5:1ac8(Verworfen) IPv6-Adresse. . . . . . . . . . . : 4006:ac21:c0a8:b22d:b000:5887:9ec5:1ac8(Verworfen) Verbindungslokale IPv6-Adresse . : fe80::b000:5887:9ec5:1ac8%57(Bevorzugt) IPv4-Adresse . . . . . . . . . . : 192.168.178.37(Bevorzugt) Subnetzmaske . . . . . . . . . . : 255.255.255.0 Lease erhalten. . . . . . . . . . : Sonntag, 31. August 2014 11:04:03 Lease lŵft ab. . . . . . . . . . : Mittwoch, 10. September 2014 11:04:04 Standardgateway . . . . . . . . . : fe80::9ec7:a6ff:fea7:b114%57 192.168.178.1 DHCP-Server . . . . . . . . . . . : 192.168.178.1 DHCPv6-IAID . . . . . . . . . . . : 207908866 DHCPv6-Client-DUID. . . . . . . . : 00-01-00-01-17-61-CB-53-00-1D-0F-B1-57-2C DNS-Server . . . . . . . . . . . : fd00::9ec7:a6ff:fea7:b114 192.168.178.1 NetBIOS ¢er TCP/IP . . . . . . . : Aktiviert Tunneladapter isatap.{FA968DCD-A7BE-4E4A-BC57-7A74F62E5770}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter isatap.{666CFB32-A1E2-4237-BA58-A042AFD75AA6}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #3 Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter isatap.{FB8D666E-CA7E-42CC-859A-6523971B21AA}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #2 Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter LAN-Verbindung* 30: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter isatap.fritz.box: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: fritz.box Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #5 Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Server: UnKnown Address: 192.168.0.1 Name: google.com Addresses: 2a00:1450:4005:809::1002 173.194.113.137 173.194.113.133 173.194.113.132 173.194.113.142 173.194.113.136 173.194.113.135 173.194.113.134 173.194.113.129 173.194.113.131 173.194.113.130 173.194.113.128 Ping wird ausgef¨rt f² google.com [173.194.113.137] mit 32 Bytes Daten: Antwort von 173.194.113.137: Bytes=32 Zeit=28ms TTL=54 Antwort von 173.194.113.137: Bytes=32 Zeit=16ms TTL=54 Ping-Statistik f² 173.194.113.137: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 16ms, Maximum = 28ms, Mittelwert = 22ms Server: UnKnown Address: 192.168.0.1 Name: yahoo.com Addresses: 206.190.36.45 98.139.183.24 98.138.253.109 Ping wird ausgef¨rt f² yahoo.com [206.190.36.45] mit 32 Bytes Daten: Antwort von 206.190.36.45: Bytes=32 Zeit=207ms TTL=47 Antwort von 206.190.36.45: Bytes=32 Zeit=211ms TTL=47 Ping-Statistik f² 206.190.36.45: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 207ms, Maximum = 211ms, Mittelwert = 209ms Ping wird ausgef¨rt f² 127.0.0.1 mit 32 Bytes Daten: Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128 Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128 Ping-Statistik f² 127.0.0.1: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 0ms, Maximum = 0ms, Mittelwert = 0ms =========================================================================== Schnittstellenliste 61...62 70 02 fc a6 19 ......Microsoft Virtual WiFi Miniport Adapter #11 59...50 e5 49 30 60 fd ......Realtek PCIe GBE Family Controller 57...64 70 02 fc a6 19 ......TP-LINK 300Mbps Wireless N Adapter 1...........................Software Loopback Interface 1 13...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter 26...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #3 56...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #2 55...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface 75...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #5 =========================================================================== IPv4-Routentabelle =========================================================================== Aktive Routen: Netzwerkziel Netzwerkmaske Gateway Schnittstelle Metrik 0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.102 20 0.0.0.0 0.0.0.0 192.168.178.1 192.168.178.37 20 127.0.0.0 255.0.0.0 Auf Verbindung 127.0.0.1 306 127.0.0.1 255.255.255.255 Auf Verbindung 127.0.0.1 306 127.255.255.255 255.255.255.255 Auf Verbindung 127.0.0.1 306 192.168.0.0 255.255.255.0 Auf Verbindung 192.168.0.102 276 192.168.0.102 255.255.255.255 Auf Verbindung 192.168.0.102 276 192.168.0.255 255.255.255.255 Auf Verbindung 192.168.0.102 276 192.168.178.0 255.255.255.0 Auf Verbindung 192.168.178.37 276 192.168.178.37 255.255.255.255 Auf Verbindung 192.168.178.37 276 192.168.178.255 255.255.255.255 Auf Verbindung 192.168.178.37 276 224.0.0.0 240.0.0.0 Auf Verbindung 127.0.0.1 306 224.0.0.0 240.0.0.0 Auf Verbindung 192.168.0.102 276 224.0.0.0 240.0.0.0 Auf Verbindung 192.168.178.37 276 255.255.255.255 255.255.255.255 Auf Verbindung 127.0.0.1 306 255.255.255.255 255.255.255.255 Auf Verbindung 192.168.0.102 276 255.255.255.255 255.255.255.255 Auf Verbindung 192.168.178.37 276 =========================================================================== StŮdige Routen: Keine IPv6-Routentabelle =========================================================================== Aktive Routen: If Metrik Netzwerkziel Gateway 57 36 ::/0 fe80::9ec7:a6ff:fea7:b114 1 306 ::1/128 Auf Verbindung 57 28 2a02:8108:2000:ed0::/64 Auf Verbindung 57 36 2a02:8108:2000:ed0::/64 fe80::9ec7:a6ff:fea7:b114 57 276 2a02:8108:2000:ed0:b000:5887:9ec5:1ac8/128 Auf Verbindung 57 276 2a02:8108:2000:ed0:e8af:67c0:ebe3:752b/128 Auf Verbindung 57 28 4006:6da:c0a8:b22d::/64 Auf Verbindung 57 36 4006:6da:c0a8:b22d::/64 fe80::9ec7:a6ff:fea7:b114 57 276 4006:6da:c0a8:b22d:b000:5887:9ec5:1ac8/128 Auf Verbindung 57 28 4006:8078:c0a8:b22d::/64 Auf Verbindung 57 36 4006:8078:c0a8:b22d::/64 fe80::9ec7:a6ff:fea7:b114 57 276 4006:8078:c0a8:b22d:b000:5887:9ec5:1ac8/128 Auf Verbindung 57 28 4006:9056:c0a8:b22d::/64 Auf Verbindung 57 36 4006:9056:c0a8:b22d::/64 fe80::9ec7:a6ff:fea7:b114 57 276 4006:9056:c0a8:b22d:b000:5887:9ec5:1ac8/128 Auf Verbindung 57 28 4006:ac21:c0a8:b22d::/64 Auf Verbindung 57 36 4006:ac21:c0a8:b22d::/64 fe80::9ec7:a6ff:fea7:b114 57 276 4006:ac21:c0a8:b22d:b000:5887:9ec5:1ac8/128 Auf Verbindung 59 276 fe80::/64 Auf Verbindung 57 276 fe80::/64 Auf Verbindung 59 276 fe80::7d59:756c:dedd:85fe/128 Auf Verbindung 57 276 fe80::b000:5887:9ec5:1ac8/128 Auf Verbindung 1 306 ff00::/8 Auf Verbindung 59 276 ff00::/8 Auf Verbindung 57 276 ff00::/8 Auf Verbindung =========================================================================== StŮdige Routen: If Metrik Netzwerkziel Gateway 0 4294967295 2620:9b::/96 Auf Verbindung 0 9000 ::/0 2620:9b::1900:1 =========================================================================== ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Catalog5 08 c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation) Catalog5 09 c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation) Catalog5 10 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.) x64-Catalog5 08 c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304] (Microsoft Corporation) x64-Catalog5 09 c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304] (Microsoft Corporation) x64-Catalog5 10 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 11 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (08/30/2014 08:38:31 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Godus.exe, Version: 1.0.0.1, Zeitstempel: 0x533f1cd9 Name des fehlerhaften Moduls: XAudio2_7.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x4c0641e5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x6c18a5e0 ID des fehlerhaften Prozesses: 0x1c2c Startzeit der fehlerhaften Anwendung: 0xGodus.exe0 Pfad der fehlerhaften Anwendung: Godus.exe1 Pfad des fehlerhaften Moduls: Godus.exe2 Berichtskennung: Godus.exe3 Error: (08/30/2014 03:21:45 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Godus.exe, Version: 1.0.0.1, Zeitstempel: 0x533f1cd9 Name des fehlerhaften Moduls: XAudio2_7.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x4c0641e5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x63a9a5e0 ID des fehlerhaften Prozesses: 0x1fb0 Startzeit der fehlerhaften Anwendung: 0xGodus.exe0 Pfad der fehlerhaften Anwendung: Godus.exe1 Pfad des fehlerhaften Moduls: Godus.exe2 Berichtskennung: Godus.exe3 Error: (08/30/2014 11:35:43 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 90080108 Error: (08/30/2014 11:25:14 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/30/2014 09:31:50 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (08/30/2014 09:31:50 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (08/30/2014 09:31:50 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (08/30/2014 09:02:14 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/30/2014 06:16:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/29/2014 05:19:26 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (08/31/2014 00:34:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Error: (08/31/2014 00:34:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Kryptografiedienste" wurde aufgrund folgenden Fehlers nicht gestartet: %%1079 Microsoft Office Sessions: ========================= Error: (08/30/2014 08:38:31 PM) (Source: Application Error)(User: ) Description: Godus.exe1.0.0.1533f1cd9XAudio2_7.dll_unloaded0.0.0.04c0641e5c00000056c18a5e01c2c01cfc46753485e47G:\SteamLibrary\steamapps\common\Godus\.\windows\Godus.exeXAudio2_7.dlld69c4e1e-3074-11e4-853f-50e5493060fd Error: (08/30/2014 03:21:45 PM) (Source: Application Error)(User: ) Description: Godus.exe1.0.0.1533f1cd9XAudio2_7.dll_unloaded0.0.0.04c0641e5c000000563a9a5e01fb001cfc442ae57fa72G:\SteamLibrary\steamapps\common\Godus\.\windows\Godus.exeXAudio2_7.dll9685c8d1-3048-11e4-853f-50e5493060fd Error: (08/30/2014 11:35:43 AM) (Source: Customer Experience Improvement Program)(User: ) Description: 90080108 Error: (08/30/2014 11:25:14 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Franky\Downloads\esetsmartinstaller_deu.exe Error: (08/30/2014 09:31:50 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (08/30/2014 09:31:50 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (08/30/2014 09:31:50 AM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (08/30/2014 09:02:14 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (08/30/2014 06:16:11 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (08/29/2014 05:19:26 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Franky\Downloads\esetsmartinstaller_deu.exe CodeIntegrity Errors: =================================== Date: 2014-08-31 09:47:28.262 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-31 09:47:28.184 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-30 11:47:57.422 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-30 11:47:57.375 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-30 09:31:25.467 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-30 09:31:25.420 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-29 17:11:47.668 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-29 17:11:47.622 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-28 19:44:29.294 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-08-28 19:44:29.247 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume4\Windows\SysWOW64\mbmiodrvr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. @BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.11 - GIGABYTE) =========================== Installed Programs ============================ µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.32126 - BitTorrent Inc.) 360 Internet Security (HKLM-x32\...\360 Internet Security) (Version: 4.9.0.4900 - Qihu 360 Software Co., Ltd.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Ace of Spades (HKLM-x32\...\Steam App 224540) (Version: - Jagex Limited) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version: - Hidden Path Entertainment, Ensemble Studios) Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version: - Ensemble Studios) Amazon Music (HKCU\...\Amazon Amazon Music) (Version: 3.2.0.591 - Amazon Services LLC) Angry Birds Star Wars II (HKLM-x32\...\{C4887610-6DE9-4538-A6CD-2B44673FE133}) (Version: 1.0.1 - Rovio Entertainment Ltd.) Anno 1404 (HKLM-x32\...\Steam App 33250) (Version: - Blue Byte) Anno 1404: Venice (HKLM-x32\...\Steam App 33350) (Version: - Blue Byte) Any Video Converter 5.6.3 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com) Apple Application Support (HKLM-x32\...\{CCE825DB-347A-4004-A186-5F4A6FDD8547}) (Version: 2.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}) (Version: 6.0.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASCII Art - Machine 1.2 (HKLM-x32\...\ASCII Art - Machine_is1) (Version: - ) Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft) Assassin's Creed(R) III v1.06 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.06 - Ubisoft) ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.4.2.4 - ASUSTek COMPUTER INC.) ASUS GPU Tweak (x32 Version: 2.4.2.4 - ASUSTek COMPUTER INC.) Hidden ASUS Product Register Program (HKLM-x32\...\{9D29D67C-315D-46A1-A3A9-3CAF24871578}) (Version: 1.0.022 - ASUSTek Computer Inc.) Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version: - Audacity Team) AudibleManager (HKLM-x32\...\AudibleManager) (Version: 1999912174.48.56.33885418 - Audible, Inc.) Audiobook Cutter Free Edition (HKLM-x32\...\{0C1D2DFD-9325-47C5-BC63-EBE68DEF7AFB}) (Version: 1.8.6 - Audiobook Software) Aufstieg des Hexenkönigs™ (HKLM-x32\...\{B931FB80-537A-4600-00AD-AC5DEDB6C25B}) (Version: - ) AutoGreen B10.1021.1 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) AutoGreen B10.1021.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden AutoHotkey 1.1.10.01 (HKLM\...\AutoHotkey) (Version: 1.1.10.01 - Lexikos) Battle for Wesnoth 1.10.4 (HKLM-x32\...\Battle for Wesnoth 1.10.4) (Version: 1.10.4 - ) BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version: - Irrational Games) Bitcoin (HKCU\...\Bitcoin) (Version: 0.8.6 - Bitcoin project) Black & White® 2 (HKLM-x32\...\{D9E52CD1-9DF1-4A8A-9BDC-1E5E53982F2B}) (Version: 1.00.0000 - Lionhead Studios) Blade Symphony (HKLM-x32\...\Steam App 225600) (Version: - Puny Human Games) Blood Bowl: Legendary Edition (HKLM-x32\...\Steam App 58520) (Version: - Cyanide Studios) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Brick-Force (HKLM-x32\...\Brick-Force) (Version: - Infernum Productions AG) Bridge Project (HKLM-x32\...\Steam App 232950) (Version: - Halycon Media GmbH & Co. KG) Brütal Legend (HKLM-x32\...\Steam App 225260) (Version: - Double Fine Productions) CamStudio version 2.7 (HKLM-x32\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7 - CamStudio Open Source) Canon CanoScan Toolbox 4.1 (HKLM-x32\...\{BCE46757-7674-4416-BEDB-68205A60409E}) (Version: - ) CanoScan Toolbox Ver4.9 (HKLM-x32\...\{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}) (Version: - ) CASIO FA-124 (HKLM-x32\...\{FB47E710-6249-4EFA-BE36-E922B0612AF4}) (Version: 2.00.0001 - CASIO COMPUTER CO., LTD.) Castle Story (HKLM-x32\...\Steam App 227860) (Version: - Sauropod Studio) Catan - Die erste Insel (HKLM-x32\...\Catan) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) Cheat Engine 6.3 (HKLM-x32\...\Cheat Engine 6.3_is1) (Version: - Cheat Engine) Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version: - Torn Banner Studios) Cities XL Platinum (HKLM-x32\...\Steam App 231140) (Version: - Focus Home Interactive) Clonk Endeavour 4.95.5 (HKLM-x32\...\Clonk Endeavour) (Version: 4.95.5 - RedWolf Design GmbH) Clonk Rage (HKLM-x32\...\Clonk Rage) (Version: - RedWolf Design GmbH) Combined Community Codec Pack 2013-04-20 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2013.04.20.0 - CCCP Project) Command and Conquer: Red Alert 3 - Uprising (HKLM-x32\...\Steam App 24800) (Version: - EA Los Angeles) Company of Heroes - FAKEMSI (x32 Version: 2.0.0.0 - THQ Inc.) Hidden Company of Heroes (HKLM-x32\...\Company of Heroes) (Version: 2.602.0 - THQ Inc.) Company of Heroes (HKLM-x32\...\Steam App 4560) (Version: - Relic Entertainment) Confrontation (HKLM-x32\...\Steam App 204560) (Version: - Cyanide Studios) Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) Crazy Machines II (HKLM-x32\...\{112B0ED9-57F8-4883-8E6A-5BEAABDABBC1}) (Version: 1.00 - FAKT Software GmbH) Crazy Machines II Erweiterung "Zurück in die Werkstatt" (HKLM-x32\...\{763BFBA5-F598-4A2A-8A2A-FE93CBCC22BF}) (Version: 1.02 - FAKT Software GmbH) Creative Systeminformationen (HKLM-x32\...\SysInfo) (Version: 1.10 - Creative Technology Limited) 'Cultures Saga' (HKLM-x32\...\'Cultures Saga') (Version: - ) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0327 - DT Soft Ltd) Darwinia (HKLM-x32\...\Steam App 1500) (Version: - Introversion Software) Data Lifeguard Diagnostic for Windows 1.24 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version: - Western Digital Corporation) dBpoweramp DirectShow Decoder (HKLM-x32\...\dBpoweramp DirectShow Decoder) (Version: Release 2 - Illustrate) dBpoweramp Music Converter (HKLM-x32\...\dBpoweramp Music Converter) (Version: Release 14.3 - Illustrate) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{132D27B8-C656-44BD-8C16-73C54EA8A85F}) (Version: - Microsoft) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{132D27B8-C656-44BD-8C16-73C54EA8A85F}) (Version: - Microsoft) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{132D27B8-C656-44BD-8C16-73C54EA8A85F}) (Version: - Microsoft) DES 2.0 (HKLM-x32\...\{675F86A8-E093-4002-87D5-915CC2C45571}) (Version: 1.00.0000 - Gigabyte) Desura (HKLM-x32\...\Desura) (Version: 100.53 - Desura) Desura: Project Zomboid (HKLM-x32\...\Desura_62350040236064) (Version: Alpha - The Indie Stone) Dia (nur entfernen) (HKLM-x32\...\Dia) (Version: - ) Die Gilde Gold-Edition (HKLM-x32\...\Die Gilde Gold-Edition) (Version: 2.06 - JoWooD Productions Software AG) Die Schlacht um Mittelerde™ II (HKLM-x32\...\{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}) (Version: - ) DIE SIEDLER - Aufstieg eines Königreichs (HKLM-x32\...\{D3F80A98-05AB-4D8C-9272-766CCFA6A48D}) (Version: 1.00.0000 - Ubisoft) Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - ) Die Sims Mittelalter Piraten und Edelleute (HKLM-x32\...\{0CC21836-A5D6-4641-B4AE-6FA01D021E41}) (Version: 2.0.109 - Electronic Arts) Die*Sims*Mittelalter (HKLM-x32\...\{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}) (Version: 2.0.113 - Electronic Arts) DiRT 3 (HKLM-x32\...\Steam App 44320) (Version: - Codemasters Racing Studio) DiRT Showdown (HKLM-x32\...\Steam App 201700) (Version: - Codemasters Racing Studio) DisplayFusion 5.0.1 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 5.0.1.0 - Binary Fortress Software) Divinity: Dragon Commander (HKLM-x32\...\Steam App 243950) (Version: - Larian Studios) DJ Java Decompiler v.3.12.12.96 (HKLM-x32\...\{0DB51EBE-ECD4-4308-A55C-3DFDC4E83814}) (Version: 1.8 - Atanas Neshkov 2009) Dogecoin (HKCU\...\Dogecoin) (Version: 1.5.2.0 - Dogecoin) Don't Starve (HKLM-x32\...\Steam App 219740) (Version: - Klei Entertainment) Dragon Age: Origins - Ultimate Edition (HKLM-x32\...\Steam App 47810) (Version: - BioWare) Driver Fusion (HKLM-x32\...\Driver Fusion) (Version: 2.0 - Treexy) Dropbox (HKCU\...\Dropbox) (Version: 2.10.27 - Dropbox, Inc.) DYNASTY WARRIORS 8: Xtreme Legends Complete Edition (HKLM-x32\...\Steam App 278080) (Version: - KOEI TECMO GAMES CO., LTD.) Easy Tune 6 B11.0309.1 (HKLM-x32\...\InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE) Easy Tune 6 B11.0309.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden EAX(tm) Unified (SHELL) (HKLM-x32\...\EAX(tm) Unified (SHELL)) (Version: - ) Elven Legacy (HKLM-x32\...\{40B8C652-42EE-479b-94FC-AEDE7F600D1A}_is1) (Version: 1.0.9.0 - Paradox Interactive) Epson Easy Photo Print 2 (HKLM-x32\...\{39F58DDB-B2B8-4B86-AF20-4706A80EB30D}) (Version: 2.2.0.0 - SEIKO EPSON CORPORATION) Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION) EPSON S22 Series Handbuch (HKLM-x32\...\EPSON S22 Series Manual) (Version: - ) EPSON S22 Series Printer Uninstall (HKLM\...\EPSON S22 Series) (Version: - SEIKO EPSON Corporation) Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.98 - Etron Technology) Etron USB3.0 Host Controller (x32 Version: 0.98 - Etron Technology) Hidden EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) Explorer Suite III (HKLM\...\Explorer Suite_is1) (Version: - ) Exxter Gamepad (HKLM-x32\...\FTQ591) (Version: - ) Fable III (x32 Version: 1.0.0001.131 - Microsoft Game Studios) Hidden Factorio version 0.9.8 (HKLM\...\Factorio_is1) (Version: - ) Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft) FileZilla Client 3.6.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.6.0.2 - FileZilla Project) FINAL FANTASY VIII (HKLM-x32\...\Steam App 39150) (Version: - SQUARE ENIX) Fish Tycoon (remove only) (HKCU\...\Fish Tycoon) (Version: - ) Free 3GP Video Converter version 5.0.43.605 (HKLM-x32\...\Free 3GP Video Converter_is1) (Version: 5.0.43.605 - DVDVideoSoft Ltd.) Free Video Dub version 2.0.16.1212 (HKLM-x32\...\Free Video Dub_is1) (Version: 2.0.16.1212 - DVDVideoSoft Ltd.) FRITZ!Box USB-Fernanschluss (HKCU\...\2db37667170956ee) (Version: 2.3.1.0 - AVM Berlin) Future Pinball (HKLM-x32\...\Future Pinball_is1) (Version: Version 1.9.1.20101231 - Chris Leathley) Galactic Civilizations II: Ultimate Edition (HKLM-x32\...\Steam App 202200) (Version: - Stardock Entertainment) Game Character Hub (HKLM-x32\...\Steam App 292230) (Version: - Sebastien Bini) Game Dev Tycoon (HKLM-x32\...\Steam App 239820) (Version: - Greenheart Games) Game of Thrones (HKLM-x32\...\Steam App 208730) (Version: - Cyanide Studios) GameRanger (HKCU\...\GameRanger) (Version: - GameRanger Technologies) Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Team Garry) GetFoldersize 2.5.24 (HKLM-x32\...\GetFoldersize_is1) (Version: 2.5.24 - Michael Thummerer Software Design) GIMP 2.8.0 (HKLM\...\GIMP-2_is1) (Version: 2.8.0 - The GIMP Team) GlassFish Server Open Source Edition 3.1.2 (HKLM-x32\...\nbi-glassfish-mod-3.1.2.23.0) (Version: - ) Gnomoria (HKLM-x32\...\Steam App 224500) (Version: - Robotronic Games) Godus (HKLM-x32\...\Steam App 232810) (Version: - ) GoldWave v5.67 (HKLM-x32\...\GoldWave v5.67) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.143 - Google Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Gothic 3 (HKLM-x32\...\{17BADF87-3597-46FE-8D74-69C4FA78883E}) (Version: 1.0.0 - JoWood) Grand Theft Auto IV (HKLM-x32\...\Steam App 12210) (Version: - Rockstar North) Guilty Gear Isuka (HKLM-x32\...\Steam App 267900) (Version: - Arc System Works Co., Ltd.) Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve) Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve) Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve) Half-Life 2: Lost Coast (HKLM-x32\...\Steam App 340) (Version: - Valve) Hammerwatch (HKLM-x32\...\Steam App 239070) (Version: - ) HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software) HeidiSQL 7.0.0.4053 (HKLM-x32\...\HeidiSQL_is1) (Version: 7.0 - Ansgar Becker) Hero Fighter (HKLM-x32\...\Hero Fighter) (Version: - ) Hex-Editor MX (HKLM-x32\...\{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1) (Version: 6.0 - NEXT-Soft) Hexodius (HKLM-x32\...\Steam App 236490) (Version: - Brain Slap Studio) HiCDEject (HKLM-x32\...\HiCDEject) (Version: - ) Hippsoft hsWebCam 1.09.0002 (HKLM-x32\...\Hippsoft hsWebCam_is1) (Version: 1.09.0002 - Hippsoft) IL-2 Sturmovik: 1946 (HKLM-x32\...\Steam App 15320) (Version: - 1C: Maddox Games) IncrediMail (x32 Version: 6.6.0.5288 - IncrediMail) Hidden IncrediMail 2.5 (HKLM-x32\...\IncrediMail) (Version: 6.6.0.5288 - IncrediMail Ltd.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.35 - Irfan Skiljan) -Isamu- (HKLM-x32\...\{1512C6E7-CEBF-479D-9532-A36B27A1BE05}) (Version: 1.0.0 - Shoryuken Productions) iTunes (HKLM\...\{0E5D76AD-A3FB-48D5-8400-8903B10317D3}) (Version: 11.0.1.12 - Apple Inc.) Jade Empire: Special Edition (HKLM-x32\...\Steam App 7110) (Version: - BioWare Corporation) Java 7 Update 17 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017F0}) (Version: 7.0.170 - Oracle) Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.670 - Oracle) Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden Java SE Development Kit 7 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170450}) (Version: 1.7.0.450 - Oracle) Java SE Development Kit 7 Update 5 (HKLM-x32\...\{32A3A4F4-B792-11D6-A78A-00B0D0170050}) (Version: 1.7.0.50 - Oracle) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) JavaFX 2.1.1 SDK (HKLM-x32\...\{2222706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH) Juice 2.2 (HKLM-x32\...\Juice) (Version: 2.2 - Juice Team) Just Cause 2 (HKLM-x32\...\Steam App 8190) (Version: - Avalanche) Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version: - Squad) Knights of Pen and Paper +1 (HKLM-x32\...\Steam App 231740) (Version: - Behold Studios) LEGO® Der Herr der Ringe™ (HKLM-x32\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment) Lernout & Hauspie TruVoice American English TTS Engine (HKLM-x32\...\tv_enua) (Version: - ) LinuxLive USB Creator (HKLM-x32\...\LinuxLive USB Creator) (Version: 2.8 - Thibaut Lauziere) Litecoin (HKCU\...\Litecoin) (Version: 0.8.6.2 - Litecoin project) Little Fighter 2 version 2.0a (HKLM-x32\...\Little Fighter 2) (Version: version 2.0a - ) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.109 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.109 - LogMeIn, Inc.) Hidden MacroX 3.1 (HKLM-x32\...\MacroX) (Version: 3.1 - Uhrzeit.org) Magicka (HKLM-x32\...\Steam App 42910) (Version: - Arrowhead Game Studios) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) ManiaPlanet (HKLM-x32\...\ManiaPlanet_is1) (Version: - Nadeo) Mark of the Ninja (HKLM-x32\...\Steam App 214560) (Version: - ) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Project MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Project Professional 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Visio 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Visio MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Project Professional 2010 (HKLM-x32\...\Office14.PRJPROR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Virtual PC 2007 (HKLM\...\{8A7CAA24-7B23-410B-A7C3-F994B0944160}) (Version: 6.0.156.0 - Microsoft Corporation) Microsoft Visio Professional 2010 (HKLM-x32\...\Office14.VISIOR) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Mod Updater for NRaas mods (HKLM-x32\...\{E0112108-E4CA-4361-80F3-D337797F4F6A}) (Version: 1.10.3 - Tucknology) Mono for Windows 3.2.3 (HKLM-x32\...\{afbbbda2-1dd7-11e3-ae37-080027022fbf}_is1) (Version: 3.2.3 - Mono) Monster Loves You! (HKLM-x32\...\Steam App 226740) (Version: - Radial Games Corp) Motherboard Monitor 5 (HKLM-x32\...\Motherboard Monitor 5_is1) (Version: 5 - Alexander van Kaam) Mount & Blade (HKLM-x32\...\Steam App 22100) (Version: - Paradox Interactive) Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version: - Tale Worlds) Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML4 Parser (HKLM-x32\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios) NetBeans IDE 7.1.2 (HKLM-x32\...\nbi-nb-base-7.1.2.0.0) (Version: 7.1.2 - NetBeans.org) Network Stumbler 0.4.0 (remove only) (HKLM-x32\...\Network Stumbler) (Version: - ) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.34.0 - Black Tree Gaming) nLite 1.4.9.3 (HKLM-x32\...\nLite_is1) (Version: 1.4.9.3 - Dino Nuhagic (nuhi)) Nokia Connectivity Cable Driver (HKLM-x32\...\{0906982B-A432-4C06-8F01-C01BE1143779}) (Version: 7.1.92.0 - Nokia) Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.6.36.0 - Nokia) Nokia Suite (x32 Version: 3.6.36.0 - Nokia) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.3.2 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 2.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.22 (Version: 1.2.22 - NVIDIA Corporation) Hidden ON_OFF Charge B11.0110.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Orcs Must Die! 2 (HKLM-x32\...\Steam App 201790) (Version: - Robot Entertainment) Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC) Panzar (HKLM-x32\...\Steam App 240320) (Version: - Troxit Service) PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) PC Connectivity Solution (HKLM-x32\...\{BA77F9D2-CD35-41EB-9BC9-769879DFF8A6}) (Version: 12.0.48.0 - Nokia) Peggle Deluxe 1.03 (HKLM-x32\...\Peggle Deluxe 1.03) (Version: - ) Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.) Photo Notifier and Animation Creator (x32 Version: 1.0.0.1009 - Ihr Firmenname) Hidden Pixel Piracy (HKLM-x32\...\Steam App 264140) (Version: - Vitali Kirpu) Planet Explorers (HKLM-x32\...\Steam App 237870) (Version: - Pathea Games) Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version: - Uber Entertainment) Pokémon Play It! v2 (HKLM-x32\...\Pokémon Play It! v2) (Version: - D-Man) Portal (HKLM-x32\...\Steam App 400) (Version: - Valve) Prison Architect (HKLM-x32\...\Steam App 233450) (Version: - Introversion Software) PROTOTYPE 2 (HKLM-x32\...\Steam App 115320) (Version: - Radical Entertainment) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.) puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: 1.0.0.0 - Dean Herbert) RAMRush 1.0.6.917 (HKLM-x32\...\RAMRush_is1) (Version: - FTweak, Inc.) Rapture3D 2.4.8 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) Razer Game Booster (HKLM-x32\...\Razer Game Booster_is1) (Version: 4.2.42.0 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6307 - Realtek Semiconductor Corp.) Renegade X (HKLM-x32\...\UDK-4fc3a6b6-3d0e-4dce-b127-8e60191e2b1e) (Version: Open Beta 1 - Totem Arts) Reus (HKLM-x32\...\Steam App 222730) (Version: - Abbey Games) Rise Of Legends (HKLM-x32\...\InstallShield_{CADDE354-C78C-46CB-A006-E2B178EFC271}) (Version: 1.00.0000 - Microsoft Game Studios) Rise Of Legends (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden Rise of Nations (HKLM-x32\...\RiseOfNationsExpansion 1.0) (Version: 1.0 - Microsoft) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.0.9.5 - Rockstar Games) Rogue Legacy (HKLM-x32\...\Steam App 241600) (Version: - Cellar Door Games) RPG MAKER VX Ace (HKLM-x32\...\RPGVXAce_E_is1) (Version: 1.01a - Enterbrain) RPG Maker VX Ace (HKLM-x32\...\Steam App 220700) (Version: - Enterbrain) RPG MAKER VX Ace RTP (HKLM-x32\...\RPGVXAce_RTP_is1) (Version: 1.00 - Enterbrain) RuneScape Launcher 1.2.3 (HKLM-x32\...\{FAE99C85-0732-4C58-9C6B-10B5B12FA2E9}) (Version: 1.2.3 - Jagex Ltd) Safecracker: The Ultimate Puzzle Adventure (HKLM-x32\...\Steam App 3260) (Version: - Kheops Studio) Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition) Scribblenauts Unlimited (HKLM-x32\...\Steam App 218680) (Version: - 5th Cell Media) Secure Download Manager (HKLM-x32\...\{C58626D6-7EBD-460D-8B6C-75B3C3464879}) (Version: 3.1.60 - Kivuto Solutions Inc.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{58FA40EF-ABA9-4FED-AD3D-318A6073934D}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{359ADBEC-068A-4CC9-9174-77AB8EDB867A}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden SES Driver (HKLM\...\{D8CC254C-C671-4664-9A38-FA368D1E2C97}) (Version: 1.0.0 - Western Digital) SHIELD Streaming (Version: 1.8.323 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Sigil 0.7.4 (HKLM-x32\...\Sigil_is1) (Version: - John Schember) Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) SlimDX Runtime .NET 4.0 x86 (January 2012) (HKLM-x32\...\{7EBD0E43-6AC0-4CA8-9990-00E50069AD29}) (Version: 2.0.13.43 - SlimDX Group) Smart 6 B10.1221.1 (HKLM-x32\...\{3B35725F-C623-4A1E-B5CC-99C0868679E3}) (Version: 1.00.0000 - GIGABYTE) SmartTools Publishing • Excel DateiLister (HKLM-x32\...\SmartToolsDateiListerv5.00) (Version: v5.00 - SmartTools Publishing) Sound Blaster Recon3D (HKLM-x32\...\{62F7CCBA-7F8C-4A91-9EA7-6E66941A686B}) (Version: 1.01.04 - Creative Technology Limited) Space Engineers (HKLM-x32\...\Steam App 244850) (Version: - ) Spelunky (HKLM-x32\...\Steam App 239350) (Version: - ) Spore (HKLM-x32\...\Steam App 17390) (Version: - Maxis™) Spore: Creepy & Cute Parts Pack (HKLM-x32\...\Steam App 17440) (Version: - Maxis™) Spore: Galactic Adventures (HKLM-x32\...\Steam App 24720) (Version: - EA - Maxis) Spotify (HKCU\...\Spotify) (Version: 0.9.10.22.gf87988f9 - Spotify AB) Star Wars Empire at War (HKLM-x32\...\{99AE7207-8612-4DBA-A8F8-BAE5C633390D}) (Version: 1.0 - LucasArts) Star Wars(tm) Knights of the Old Republic(tm) II: The Sith Lords(tm) (HKLM-x32\...\{629F65FB-7F3C-4D66-A1C0-20722744B7B6}) (Version: 1.00.0000 - Obsidian) Starbound (HKLM-x32\...\Steam App 211820) (Version: - ) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Strike Suit Zero (HKLM-x32\...\Steam App 209540) (Version: - Born Ready Games Ltd.) Stronghold 2 (HKLM-x32\...\Steam App 40960) (Version: - FireFly Studios) Stronghold 3 (HKLM-x32\...\Steam App 47400) (Version: - FireFly Studios) Stronghold Crusader Extreme (HKLM-x32\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: 1.20.0000 - Firefly Studios) Stronghold Crusader Extreme HD (HKLM-x32\...\Steam App 16700) (Version: - Firefly Studios) Stronghold Crusader HD (HKLM-x32\...\Steam App 40970) (Version: - FireFly Studios) Stronghold Legends (HKLM-x32\...\Steam App 40980) (Version: - FireFly Studios) SUPER © v2012.build.52 (July 7, 2012) Version v2012.build.52 (HKLM-x32\...\{8F311E2E-C275-4CF0-8154-B63991832668}_is1) (Version: v2012.build.52 - eRightSoft) SWF Opener (HKLM-x32\...\{01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1) (Version: 1.3 - UnH Solutions) TeamSpeak 2 RC2 (HKLM-x32\...\Teamspeak 2 RC2_is1) (Version: 2.0.32.60 - Dominating Bytes Design) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29480 - TeamViewer) TEdit 3 (HKLM-x32\...\{37D643E8-8ACB-468A-B020-26C9D6CA52E3}) (Version: 3.5.14218.23 - BinaryConstruct) TEdit 3 (HKLM-x32\...\{B81207ED-C990-4AB1-B5D5-A191EA253C0D}) (Version: 3.5.14064.0 - BinaryConstruct) TEdit 3 (HKLM-x32\...\{F015942F-C1BD-4297-A8A4-C0B8D42B39C5}) (Version: 3.4.13358.0 - BinaryConstruct) Terrafirma (HKLM-x32\...\{9EA1E037-86B8-496B-9C8C-31B3E3017C53}) (Version: 2.2.2.0 - Sean Kasun) TerraMap (HKLM-x32\...\{CB86D44E-8906-4AFA-ACE8-C1C0D0B21FED}) (Version: 1.0.2.30729 - Jason Coon) Terraria (HKLM-x32\...\Steam App 105600) (Version: - Re-Logic) The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version: - Edmund McMillen and Florian Himsl) The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00) (Version: - ) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) The Guild II: Renaissance (HKLM-x32\...\Steam App 39680) (Version: - Rune Forge) The Sims 3 Ultimate Collection Version 1.67.2 (HKLM-x32\...\The Sims 3 Ultimate Collection_is1) (Version: 1.67.2 - EA Games) TL-WN951N Driver (HKLM-x32\...\{CCE177D2-8FE3-494A-82C9-958CC79E73AD}) (Version: 1.0.0 - TP-LINK) To the Moon (HKLM-x32\...\Steam App 206440) (Version: - Freebird Games) TortoiseSVN 1.7.11.23600 (64 bit) (HKLM\...\{6B13A3F1-F66A-42FB-9E62-98952D582187}) (Version: 1.7.23600 - TortoiseSVN) TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.0.0 - TP-LINK) Trine (HKLM-x32\...\Steam App 35700) (Version: - Frozenbyte) TSLRCM 1.8.1 (HKLM-x32\...\The Sith Lords Restored Content Mod_is1) (Version: - ) Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version: - Tunngle.net GmbH) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Unlocker 1.9.1-x64 (HKLM\...\Unlocker) (Version: 1.9.1 - Cedrick Collomb) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PRJPROR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2687502) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{7DE7DF97-82FE-4B3A-AB8D-1621F9CC464A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-003B-0000-0000-0000000FF1CE}_Office14.PRJPROR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PRJPROR_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.VISIOR_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PRJPROR_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIOR_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PRJPROR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-0054-0407-0000-0000000FF1CE}_Office14.VISIOR_{43C22E89-E170-4764-8E7E-7386E34F94E0}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 4.5 - Ubisoft) Virtual Audio Cable 4.9 (HKLM\...\Virtual Audio Cable 4.9) (Version: - ) VLC media player 2.0.8 (HKLM\...\VLC media player) (Version: 2.0.8 - VideoLAN) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Warframe (HKLM-x32\...\Steam App 230410) (Version: - ) Watch Dogs Digital Deluxe Edition Multi2 1.0 (HKLM-x32\...\Watch Dogs Digital Deluxe Edition Multi2 1.0) (Version: - ) Watch Dogs Digital Deluxe Edition Update 2 MULTi2 1.03.471 (HKLM-x32\...\Watch Dogs Digital Deluxe Edition Update 2 MULTi2 1.03.471) (Version: - ) Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) Webocton - Scriptly 0.8.95.6 (HKLM-x32\...\Webocton - Scriptly_is1) (Version: 0.8.95.6 - Webocton) WIDCOMM Bluetooth Software 6.0.1.5100 (HKLM\...\{03D1988F-469F-4843-8E6E-E5FE9D17889D}) (Version: 6.0.1.5100 - Broadcom Corporation) Widelands (HKLM-x32\...\{WIDELANDS-WIN32-IS}_is1) (Version: Widelands - Widelands Development Team) Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (01/19/2011 1.0.0009.0) (HKLM\...\4CA7CFBB29889F25ACB3DF6E3A42BAE29EB43B20) (Version: 01/19/2011 1.0.0009.0 - Western Digital Technologies) Windows Installer XML Toolset 3.5 (HKLM-x32\...\{CB509245-1245-4867-8BD4-6B2C5A734504}) (Version: 3.5.2519.0 - Microsoft Corporation) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version: - ) Windows Media Encoder 9 Series (x32 Version: 9.00.2980 - Microsoft Corporation) Hidden Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 4.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) Wireshark 1.10.2 (64-bit) (HKLM-x32\...\Wireshark) (Version: 1.10.2 - The Wireshark developer community, hxxp://www.wireshark.org) Worms Blast (HKLM-x32\...\{8874FD36-7C9D-4573-8956-E368D6753D90}) (Version: - ) Worms Clan Wars (HKLM-x32\...\Steam App 233840) (Version: - Team17 Digital Ltd) Worms Pinball (HKLM-x32\...\Steam App 70660) (Version: - Team17 Software Ltd.) Worms Revolution (HKLM-x32\...\Steam App 200170) (Version: - Team17 Digital Ltd.) Worms Ultimate Mayhem (HKLM-x32\...\Steam App 70600) (Version: - Team17 Software Ltd.) Worms World Party (HKLM-x32\...\{9A200E68-D5F4-4E70-910F-2871753A0E2B}) (Version: - ) XAMPP 1.8.1 (HKLM-x32\...\xampp) (Version: - ) ========================= Memory info: =================================== Percentage of memory in use: 26% Total physical RAM: 8175.12 MB Available physical RAM: 5992.61 MB Total Pagefile: 16348.41 MB Available Pagefile: 13851.61 MB Total Virtual: 4095.88 MB Available Virtual: 3971.2 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:465.66 GB) (Free:58.28 GB) NTFS 4 Drive g: (Volume) (Fixed) (Total:2794.39 GB) (Free:401.5 GB) NTFS ========================= Users: ======================================== Benutzerkonten fr \\ Administrator Franky Gast Simon Der Befehl wurde mit einem oder mehreren Fehlern ausgefhrt. ========================= Minidump Files ================================== No minidump file found **** End of log **** |