|
Plagegeister aller Art und deren Bekämpfung: Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen TrojanerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.09.2014, 20:48 | #1 |
| Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Servus Trojaner-Board, es scheint so, als hat es mich mal wieder erwischt. Heute habe ich routinemäßig einen Malwarebytes Scan durchgeführt und es wurde etwas gefunden. Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 02.09.2014 Scan Time: 20:20:04 Logfile: MWBLog.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.09.02.08 Rootkit Database: v2014.08.21.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 8.1 CPU: x64 File System: NTFS User: Philipp Scan Type: Custom Scan Result: Completed Objects Scanned: 475725 Time Elapsed: 1 hr, 0 min, 44 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 1 Trojan.Agent, C:\Users\Philipp\AppData\Local\Temp\is-IEFH0.tmp\netlogger.exe, , [4e4b4b7ebebdc76f3f12bbf77c85fc04], Physical Sectors: 0 (No malicious items detected) (end) MB hat die Datei anschließend in Quarantäne gestellt und ich habe sie gelöscht. Könnt ihr mir helfen meinen PC wieder zu 100% virenfrei zu bekommen? Wie sieht es mit Passwörtern aus, sollte ich die im Anschluss alle ändern? Vielen Dank für eure Hilfe! |
03.09.2014, 05:50 | #2 |
/// the machine /// TB-Ausbilder | Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
03.09.2014, 16:31 | #3 |
| Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen TrojanerFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02 Ran by Philipp (administrator) on COMPUTER on 03-09-2014 17:28:38 Running from C:\Users\Philipp\Desktop Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\nis.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (AMD) C:\Windows\System32\atieclxx.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\nis.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated) HKU\S-1-5-21-1180989676-4077080399-2706785428-1001\...\Run: [Amazon Music] => C:\Users\Philipp\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] () HKU\S-1-5-21-1180989676-4077080399-2706785428-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1939136 2014-08-28] (Valve Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.5.0.19\coIEPlg.dll (Symantec Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.5.0.19\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\coIEPlg.dll (Symantec Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\3bzaxb3b.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Philipp\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\3bzaxb3b.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-07-25] FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\3bzaxb3b.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-24] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.3.0.12\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.3.0.12\coFFPlgn [2014-09-02] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\Exts\Chrome.crx [2014-08-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation) R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation) S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation) S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\NIS.exe [276376 2014-07-31] (Symantec Corporation) S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation) S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R3 ArvoFltr; C:\Windows\system32\drivers\ArvoFltr.sys [15872 2009-05-06] (ROCCAT Development, Inc.) R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.) S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) [File not signed] R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.3.0.12\Definitions\BASHDefs\20140821.007\BHDrvx64.sys [1588016 2014-08-19] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1505000.013\ccSetx64.sys [162392 2014-02-21] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-07-24] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142128 2014-07-24] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.3.0.12\Definitions\IPSDefs\20140901.001\IDSvia64.sys [633560 2014-08-29] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.3.0.12\Definitions\VirusDefs\20140902.003\ENG64.SYS [129752 2014-08-21] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.3.0.12\Definitions\VirusDefs\20140902.003\EX64.SYS [2137304 2014-08-21] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1505000.013\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1505000.013\SRTSPX64.SYS [36952 2013-10-30] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1505000.013\SYMDS64.SYS [493656 2013-10-30] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1505000.013\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\NISx64\1505000.013\SymELAM.sys [23568 2013-10-30] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-07-24] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1505000.013\Ironx64.SYS [264280 2013-10-30] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1505000.013\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) R3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 17:28 - 2014-09-03 17:28 - 00011308 _____ () C:\Users\Philipp\Desktop\FRST.txt 2014-09-03 17:28 - 2014-09-03 17:28 - 00000000 ____D () C:\FRST 2014-09-03 17:27 - 2014-09-03 17:27 - 02104832 _____ (Farbar) C:\Users\Philipp\Desktop\frst64.exe 2014-09-02 21:29 - 2014-09-02 21:29 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Internet Security 2014-08-30 18:30 - 2014-08-30 18:30 - 00000144 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2014-08-30 16:54 - 2014-08-30 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-08-30 16:54 - 2014-08-30 16:54 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-08-30 16:52 - 2014-08-30 16:53 - 29605200 _____ (DVDVideoSoft Ltd. ) C:\Users\Philipp\Downloads\FreeYouTubeToMP3Converter3.12.44.820.exe 2014-08-30 14:26 - 2014-08-30 14:28 - 03636668 _____ () C:\Users\Philipp\Downloads\TRIXX_installer_635235030956777758.zip 2014-08-30 14:23 - 2014-08-30 14:27 - 320743024 _____ (AMD Inc.) C:\Users\Philipp\Downloads\amd-catalyst-14.7-rc3-windows-aug12.exe 2014-08-30 14:19 - 2014-08-30 14:19 - 00055860 _____ () C:\Windows\SysWOW64\CCCInstall_201408301419032801.log 2014-08-30 13:22 - 2014-08-30 13:22 - 00000451 _____ () C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2014-08-29 17:41 - 2014-08-29 17:47 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TIPP10 2014-08-29 17:41 - 2014-08-29 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TIPP10 2014-08-29 17:41 - 2014-08-29 17:41 - 00000000 ____D () C:\Program Files (x86)\Tipp10 2014-08-29 17:20 - 2014-08-23 02:42 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-29 17:20 - 2014-08-07 04:12 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-29 17:19 - 2014-08-02 05:56 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-27 20:32 - 2014-08-27 20:32 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-08-27 20:32 - 2014-08-27 20:32 - 00000000 ____D () C:\Intel 2014-08-27 20:31 - 2014-08-27 20:31 - 00000000 ____D () C:\Program Files\Intel 2014-08-27 19:52 - 2014-08-26 20:59 - 38957215 ____N () C:\Users\Philipp\Desktop\VID_20140826_205932.mp4 2014-08-27 19:51 - 2014-08-27 19:42 - 152461740 ____N () C:\Users\Philipp\Desktop\VID_20140827_194219.mp4 2014-08-27 19:51 - 2014-08-26 21:07 - 181162287 ____N () C:\Users\Philipp\Desktop\VID_20140826_210707.mp4 2014-08-27 19:50 - 2014-08-27 19:44 - 165064752 ____N () C:\Users\Philipp\Desktop\VID_20140827_194455.mp4 2014-08-26 18:42 - 2014-09-02 21:23 - 00003698 _____ () C:\Windows\PFRO.log 2014-08-25 19:53 - 2014-08-27 19:43 - 00000000 ____D () C:\Users\Philipp\Documents\ProfileCache 2014-08-25 19:53 - 2014-08-27 19:40 - 00000000 ____D () C:\Users\Philipp\Documents\The Crew 2014-08-25 19:52 - 2014-08-25 19:52 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Ubisoft 2014-08-25 19:21 - 2014-09-03 17:23 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS 2014-08-25 19:21 - 2014-08-26 17:28 - 00000000 ____D () C:\Windows\AutoKMS 2014-08-25 19:20 - 2014-08-25 19:20 - 00000000 ____D () C:\ProgramData\Microsoft Toolkit 2014-08-25 19:20 - 2013-08-22 14:40 - 00040664 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\tap0901.sys 2014-08-24 16:08 - 2014-08-24 16:08 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\LolClient 2014-08-24 13:20 - 2014-08-24 16:21 - 00000000 ____D () C:\Program Files (x86)\RaidCall 2014-08-24 13:20 - 2014-08-24 13:20 - 00001047 _____ () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk 2014-08-24 13:20 - 2014-08-24 13:20 - 00001023 _____ () C:\Users\Philipp\Desktop\RaidCall.lnk 2014-08-24 13:20 - 2014-08-24 13:20 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RaidCall 2014-08-24 13:20 - 2014-08-24 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall 2014-08-24 13:10 - 2014-08-24 13:10 - 00000000 ____D () C:\ProgramData\Riot Games 2014-08-24 13:07 - 2014-08-24 13:07 - 00001409 _____ () C:\Users\Public\Desktop\League of Legends.lnk 2014-08-24 13:07 - 2014-08-24 13:07 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-08-24 13:07 - 2014-08-24 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2014-08-24 13:07 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2014-08-24 13:07 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-08-24 13:07 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-08-24 13:03 - 2014-08-24 16:31 - 00000000 ____D () C:\Spiele 2014-08-24 13:03 - 2014-08-24 13:03 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-08-24 13:02 - 2014-08-24 13:03 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Riot Games 2014-08-23 16:34 - 2014-08-23 16:34 - 00000000 ____D () C:\Users\Philipp\Desktop\Tyga 2014-08-22 22:25 - 2014-08-22 22:25 - 00017551 _____ () C:\Windows\DirectX.log 2014-08-22 20:32 - 2014-08-22 20:32 - 00000219 _____ () C:\Users\Philipp\Desktop\Counter-Strike Global Offensive.url 2014-08-22 20:07 - 2014-08-27 20:32 - 00001899 _____ () C:\Windows\setupact.log 2014-08-22 20:07 - 2014-08-22 20:07 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-22 20:06 - 2014-08-22 20:06 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-08-18 20:08 - 2014-09-03 17:26 - 00969981 _____ () C:\Windows\WindowsUpdate.log 2014-08-17 12:37 - 2014-08-17 15:34 - 00000000 ____D () C:\Users\Philipp\Desktop\Bewerbungen (2015) 2014-08-17 10:48 - 2014-08-17 10:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tinypic 2014-08-17 10:48 - 2014-08-17 10:48 - 00000000 ____D () C:\Program Files (x86)\Tinypic 2014-08-17 10:36 - 2014-08-17 10:36 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\pdfforge 2014-08-17 10:36 - 2014-08-17 10:36 - 00000000 ____D () C:\ProgramData\PDF Architect 2 2014-08-17 10:36 - 2014-08-17 10:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator 2014-08-17 10:36 - 2014-04-25 17:44 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX 2014-08-17 10:36 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX 2014-08-17 10:36 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll 2014-08-17 10:35 - 2014-08-18 20:02 - 00000000 ____D () C:\Program Files (x86)\PDFCreator 2014-08-17 10:35 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMPIDE.DLL 2014-08-17 10:35 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL 2014-08-17 10:35 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL 2014-08-17 10:35 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL 2014-08-16 21:22 - 2014-08-18 19:56 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Battle.net 2014-08-16 21:22 - 2014-08-16 21:23 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Battle.net 2014-08-16 21:22 - 2014-08-16 21:22 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Blizzard Entertainment 2014-08-16 21:22 - 2014-08-16 21:22 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-08-16 21:19 - 2014-08-16 21:19 - 00000000 ____D () C:\ProgramData\Battle.net 2014-08-16 18:24 - 2014-08-16 18:24 - 00056720 _____ () C:\Windows\SysWOW64\CCCInstall_201408161824175161.log 2014-08-16 18:18 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-16 18:18 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-16 18:18 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-16 18:18 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-16 18:18 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-16 18:18 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-16 18:18 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-16 18:18 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-16 18:17 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-16 18:17 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-16 18:17 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-16 18:17 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-16 18:17 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-16 18:17 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-16 18:17 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-16 18:17 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-16 18:17 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-16 18:17 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-16 18:17 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-16 18:17 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-16 18:17 - 2014-07-25 13:43 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-16 18:17 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-16 18:17 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-16 18:17 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-16 18:17 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-16 18:17 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-16 18:17 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-16 18:17 - 2014-07-25 13:09 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-16 18:17 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-16 18:17 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-16 18:17 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-16 18:17 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-16 18:17 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-16 18:17 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-16 18:17 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-16 18:17 - 2014-07-15 20:16 - 03048880 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe 2014-08-16 18:17 - 2014-07-15 10:29 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-08-16 18:17 - 2014-07-15 10:22 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll 2014-08-16 18:17 - 2014-07-15 10:03 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-08-16 18:17 - 2014-06-20 03:48 - 01273184 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-16 18:17 - 2014-06-20 01:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-16 18:17 - 2014-06-13 03:15 - 00517528 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-08-16 18:17 - 2014-06-13 03:14 - 01557848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-16 18:17 - 2014-06-13 02:10 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2014-08-16 18:17 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-16 18:17 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-16 18:17 - 2014-06-06 13:34 - 02133504 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2014-08-16 18:16 - 2014-08-02 05:11 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2014-08-16 18:16 - 2014-07-12 06:17 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe 2014-08-16 18:16 - 2014-06-04 11:27 - 00114520 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-16 18:16 - 2014-06-04 07:31 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-16 18:16 - 2014-06-04 07:22 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-16 18:16 - 2014-06-04 06:43 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-16 18:16 - 2014-06-04 06:38 - 03304448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-16 18:16 - 2014-06-04 04:15 - 02642944 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-16 18:16 - 2014-06-04 04:14 - 02318336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 07102496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 06879016 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00127872 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00117584 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00117560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00099520 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2014-08-12 05:31 - 2014-08-12 05:31 - 08108312 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2014-08-12 05:31 - 2014-08-12 05:31 - 07892000 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2014-08-12 05:28 - 2014-08-12 05:28 - 00276192 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys 2014-08-12 05:24 - 2014-08-12 05:24 - 15961088 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2014-08-12 05:10 - 2014-08-12 05:10 - 00231424 _____ () C:\Windows\system32\clinfo.exe 2014-08-12 05:09 - 2014-08-12 05:09 - 32877056 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2014-08-12 05:06 - 2014-08-12 05:06 - 27843072 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2014-08-12 05:03 - 2014-08-12 05:03 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-08-12 05:03 - 2014-08-12 05:03 - 00058880 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-08-12 04:51 - 2014-08-12 04:51 - 00127488 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll 2014-08-12 04:50 - 2014-08-12 04:50 - 05225472 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll 2014-08-12 04:50 - 2014-08-12 04:50 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll 2014-08-12 04:45 - 2014-08-12 04:45 - 00134656 _____ () C:\Windows\system32\amdhdl64.dll 2014-08-12 04:45 - 2014-08-12 04:45 - 00123392 _____ () C:\Windows\SysWOW64\amdhdl32.dll 2014-08-12 04:44 - 2014-08-12 04:44 - 27529216 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2014-08-12 04:39 - 2014-08-12 04:39 - 00418304 _____ () C:\Windows\system32\amdmiracast.dll 2014-08-12 04:34 - 2014-08-12 04:34 - 04180992 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll 2014-08-12 04:24 - 2014-08-12 04:24 - 23028224 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2014-08-12 04:20 - 2014-08-12 04:20 - 00091648 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll 2014-08-12 04:19 - 2014-08-12 04:19 - 00598112 _____ () C:\Windows\SysWOW64\atiapfxx.blb 2014-08-12 04:19 - 2014-08-12 04:19 - 00598112 _____ () C:\Windows\system32\atiapfxx.blb 2014-08-12 04:19 - 2014-08-12 04:19 - 00085504 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00366592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2014-08-12 04:18 - 2014-08-12 04:18 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2014-08-12 04:14 - 2014-08-12 04:14 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2014-08-12 04:01 - 2014-08-12 04:01 - 00588800 _____ (AMD) C:\Windows\system32\atieclxx.exe 2014-08-12 04:01 - 2014-08-12 04:01 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2014-08-12 04:01 - 2014-08-12 04:01 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2014-08-12 04:00 - 2014-08-12 04:00 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2014-08-12 03:59 - 2014-08-12 03:59 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2014-08-12 03:57 - 2014-08-12 03:57 - 00048128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll 2014-08-12 03:57 - 2014-08-12 03:57 - 00037888 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll 2014-08-12 03:53 - 2014-08-12 03:53 - 03437632 _____ () C:\Windows\system32\atiumd6a.cap 2014-08-12 03:42 - 2014-08-12 03:42 - 03471376 _____ () C:\Windows\SysWOW64\atiumdva.cap 2014-08-12 03:34 - 2014-08-12 03:34 - 01207296 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00898560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00146944 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00133632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00095744 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2014-08-12 03:33 - 2014-08-12 03:33 - 00557056 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2014-08-12 03:33 - 2014-08-12 03:33 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2014-08-12 03:33 - 2014-08-12 03:33 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2014-08-12 03:32 - 2014-08-12 03:32 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 17:28 - 2014-09-03 17:28 - 00011308 _____ () C:\Users\Philipp\Desktop\FRST.txt 2014-09-03 17:28 - 2014-09-03 17:28 - 00000000 ____D () C:\FRST 2014-09-03 17:27 - 2014-09-03 17:27 - 02104832 _____ (Farbar) C:\Users\Philipp\Desktop\frst64.exe 2014-09-03 17:26 - 2014-08-18 20:08 - 00969981 _____ () C:\Windows\WindowsUpdate.log 2014-09-03 17:23 - 2014-08-25 19:21 - 00003758 _____ () C:\Windows\System32\Tasks\AutoKMS 2014-09-03 17:23 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2014-09-03 17:22 - 2014-07-24 12:39 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-09-02 21:54 - 2014-07-24 15:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-02 21:30 - 2014-07-24 11:52 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1180989676-4077080399-2706785428-1001 2014-09-02 21:30 - 2014-07-24 11:50 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-02 21:30 - 2013-08-23 01:24 - 00764340 _____ () C:\Windows\system32\perfh007.dat 2014-09-02 21:30 - 2013-08-23 01:24 - 00159160 _____ () C:\Windows\system32\perfc007.dat 2014-09-02 21:29 - 2014-09-02 21:29 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Internet Security 2014-09-02 21:24 - 2014-07-26 14:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-02 21:24 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-09-02 21:23 - 2014-08-26 18:42 - 00003698 _____ () C:\Windows\PFRO.log 2014-09-02 21:23 - 2014-07-24 12:32 - 00003234 _____ () C:\Windows\System32\Tasks\Norton WSC Integration 2014-09-02 21:23 - 2014-07-24 12:32 - 00002521 _____ () C:\Users\Public\Desktop\Norton Internet Security.lnk 2014-09-02 21:23 - 2014-07-24 12:31 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security 2014-09-02 21:23 - 2014-07-24 12:31 - 00000000 ____D () C:\Windows\system32\Drivers\NISx64 2014-09-02 21:23 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\ELAMBKUP 2014-09-02 21:23 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-02 21:22 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-08-30 19:03 - 2014-07-24 15:08 - 00000000 ___RD () C:\Users\Philipp\Desktop\Unbenutzt 2014-08-30 18:30 - 2014-08-30 18:30 - 00000144 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2014-08-30 17:12 - 2014-07-24 15:20 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Spotify 2014-08-30 17:07 - 2014-07-24 20:39 - 00401408 ___SH () C:\Users\Philipp\Desktop\Thumbs.db 2014-08-30 17:06 - 2014-07-24 15:55 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Spotify 2014-08-30 16:54 - 2014-08-30 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-08-30 16:54 - 2014-08-30 16:54 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-08-30 16:54 - 2014-07-24 12:41 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\DVDVideoSoft 2014-08-30 16:53 - 2014-08-30 16:52 - 29605200 _____ (DVDVideoSoft Ltd. ) C:\Users\Philipp\Downloads\FreeYouTubeToMP3Converter3.12.44.820.exe 2014-08-30 14:28 - 2014-08-30 14:26 - 03636668 _____ () C:\Users\Philipp\Downloads\TRIXX_installer_635235030956777758.zip 2014-08-30 14:27 - 2014-08-30 14:23 - 320743024 _____ (AMD Inc.) C:\Users\Philipp\Downloads\amd-catalyst-14.7-rc3-windows-aug12.exe 2014-08-30 14:20 - 2014-07-25 09:42 - 00000000 ____D () C:\Program Files\ATI 2014-08-30 14:19 - 2014-08-30 14:19 - 00055860 _____ () C:\Windows\SysWOW64\CCCInstall_201408301419032801.log 2014-08-30 14:19 - 2014-07-25 09:44 - 00000000 ____D () C:\ProgramData\AMD 2014-08-30 13:22 - 2014-08-30 13:22 - 00000451 _____ () C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat 2014-08-30 13:22 - 2014-07-24 11:47 - 00000000 ____D () C:\Users\Philipp 2014-08-30 13:18 - 2013-08-22 16:44 - 00482680 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-29 17:47 - 2014-08-29 17:41 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TIPP10 2014-08-29 17:41 - 2014-08-29 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TIPP10 2014-08-29 17:41 - 2014-08-29 17:41 - 00000000 ____D () C:\Program Files (x86)\Tipp10 2014-08-29 17:24 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2014-08-28 19:19 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-08-27 20:32 - 2014-08-27 20:32 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-08-27 20:32 - 2014-08-27 20:32 - 00000000 ____D () C:\Intel 2014-08-27 20:32 - 2014-08-22 20:07 - 00001899 _____ () C:\Windows\setupact.log 2014-08-27 20:31 - 2014-08-27 20:31 - 00000000 ____D () C:\Program Files\Intel 2014-08-27 19:44 - 2014-08-27 19:50 - 165064752 ____N () C:\Users\Philipp\Desktop\VID_20140827_194455.mp4 2014-08-27 19:43 - 2014-08-25 19:53 - 00000000 ____D () C:\Users\Philipp\Documents\ProfileCache 2014-08-27 19:42 - 2014-08-27 19:51 - 152461740 ____N () C:\Users\Philipp\Desktop\VID_20140827_194219.mp4 2014-08-27 19:40 - 2014-08-25 19:53 - 00000000 ____D () C:\Users\Philipp\Documents\The Crew 2014-08-26 21:07 - 2014-08-27 19:51 - 181162287 ____N () C:\Users\Philipp\Desktop\VID_20140826_210707.mp4 2014-08-26 20:59 - 2014-08-27 19:52 - 38957215 ____N () C:\Users\Philipp\Desktop\VID_20140826_205932.mp4 2014-08-26 18:41 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-26 18:12 - 2014-07-24 16:19 - 00000000 ____D () C:\Users\Philipp\AppData\Local\CrashDumps 2014-08-26 17:28 - 2014-08-25 19:21 - 00000000 ____D () C:\Windows\AutoKMS 2014-08-25 19:52 - 2014-08-25 19:52 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Ubisoft 2014-08-25 19:52 - 2014-07-24 11:58 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-25 19:20 - 2014-08-25 19:20 - 00000000 ____D () C:\ProgramData\Microsoft Toolkit 2014-08-24 16:31 - 2014-08-24 13:03 - 00000000 ____D () C:\Spiele 2014-08-24 16:21 - 2014-08-24 13:20 - 00000000 ____D () C:\Program Files (x86)\RaidCall 2014-08-24 16:08 - 2014-08-24 16:08 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\LolClient 2014-08-24 13:20 - 2014-08-24 13:20 - 00001047 _____ () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk 2014-08-24 13:20 - 2014-08-24 13:20 - 00001023 _____ () C:\Users\Philipp\Desktop\RaidCall.lnk 2014-08-24 13:20 - 2014-08-24 13:20 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RaidCall 2014-08-24 13:20 - 2014-08-24 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall 2014-08-24 13:10 - 2014-08-24 13:10 - 00000000 ____D () C:\ProgramData\Riot Games 2014-08-24 13:07 - 2014-08-24 13:07 - 00001409 _____ () C:\Users\Public\Desktop\League of Legends.lnk 2014-08-24 13:07 - 2014-08-24 13:07 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-08-24 13:07 - 2014-08-24 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2014-08-24 13:03 - 2014-08-24 13:03 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-08-24 13:03 - 2014-08-24 13:02 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Riot Games 2014-08-23 21:05 - 2014-07-25 23:50 - 00007831 _____ () C:\Users\Philipp\Documents\TombRaider.log 2014-08-23 16:34 - 2014-08-23 16:34 - 00000000 ____D () C:\Users\Philipp\Desktop\Tyga 2014-08-23 15:27 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2014-08-23 09:58 - 2014-07-24 13:25 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-08-23 02:42 - 2014-08-29 17:20 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-22 22:25 - 2014-08-22 22:25 - 00017551 _____ () C:\Windows\DirectX.log 2014-08-22 20:32 - 2014-08-22 20:32 - 00000219 _____ () C:\Users\Philipp\Desktop\Counter-Strike Global Offensive.url 2014-08-22 20:07 - 2014-08-22 20:07 - 00000000 _____ () C:\Windows\setuperr.log 2014-08-22 20:06 - 2014-08-22 20:06 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-08-22 19:27 - 2014-07-25 13:13 - 00000000 ____D () C:\Users\Philipp\Documents\My Games 2014-08-21 20:43 - 2014-07-24 12:40 - 00000000 ____D () C:\ProgramData\Origin 2014-08-21 20:41 - 2014-07-24 12:39 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-08-18 20:09 - 2014-07-26 10:55 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-08-18 20:09 - 2014-07-26 10:54 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-18 20:02 - 2014-08-17 10:35 - 00000000 ____D () C:\Program Files (x86)\PDFCreator 2014-08-18 19:56 - 2014-08-16 21:22 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Battle.net 2014-08-17 15:48 - 2014-07-24 11:47 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Packages 2014-08-17 15:34 - 2014-08-17 12:37 - 00000000 ____D () C:\Users\Philipp\Desktop\Bewerbungen (2015) 2014-08-17 12:49 - 2014-07-24 15:10 - 00000000 ___RD () C:\Users\Philipp\Desktop\Musik 2014-08-17 10:48 - 2014-08-17 10:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tinypic 2014-08-17 10:48 - 2014-08-17 10:48 - 00000000 ____D () C:\Program Files (x86)\Tinypic 2014-08-17 10:40 - 2014-07-24 11:54 - 00001235 _____ () C:\Users\Philipp\Desktop\Downloads.lnk 2014-08-17 10:36 - 2014-08-17 10:36 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\pdfforge 2014-08-17 10:36 - 2014-08-17 10:36 - 00000000 ____D () C:\ProgramData\PDF Architect 2 2014-08-17 10:36 - 2014-08-17 10:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator 2014-08-16 23:40 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2014-08-16 23:40 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-16 21:23 - 2014-08-16 21:22 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Battle.net 2014-08-16 21:22 - 2014-08-16 21:22 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Blizzard Entertainment 2014-08-16 21:22 - 2014-08-16 21:22 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-08-16 21:19 - 2014-08-16 21:19 - 00000000 ____D () C:\ProgramData\Battle.net 2014-08-16 21:12 - 2014-07-25 13:19 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Skyrim 2014-08-16 20:54 - 2014-07-24 12:46 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Ubisoft Game Launcher 2014-08-16 19:24 - 2014-07-24 12:42 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-16 19:24 - 2014-07-24 12:42 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-16 18:24 - 2014-08-16 18:24 - 00056720 _____ () C:\Windows\SysWOW64\CCCInstall_201408161824175161.log 2014-08-16 18:20 - 2014-07-24 11:58 - 00000000 ____D () C:\AMD 2014-08-16 18:07 - 2014-07-24 13:27 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-16 18:07 - 2014-07-24 11:55 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-16 18:07 - 2013-08-22 13:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-16 18:07 - 2013-08-22 13:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-16 18:07 - 2013-08-22 13:22 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-16 18:07 - 2013-08-22 13:21 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-16 18:07 - 2013-08-22 13:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-16 18:07 - 2013-08-22 13:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-16 18:07 - 2013-08-22 12:32 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 07102496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 06879016 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00127872 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00117584 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00117560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00099520 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2014-08-12 05:32 - 2014-08-12 05:32 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2014-08-12 05:32 - 2014-07-21 22:04 - 10521632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2014-08-12 05:32 - 2014-07-21 22:04 - 09018320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2014-08-12 05:32 - 2014-07-21 22:04 - 01331424 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2014-08-12 05:32 - 2014-07-21 22:04 - 01110992 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2014-08-12 05:32 - 2014-07-21 22:04 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2014-08-12 05:32 - 2014-07-21 22:04 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2014-08-12 05:31 - 2014-08-12 05:31 - 08108312 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2014-08-12 05:31 - 2014-08-12 05:31 - 07892000 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2014-08-12 05:28 - 2014-08-12 05:28 - 00276192 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys 2014-08-12 05:24 - 2014-08-12 05:24 - 15961088 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2014-08-12 05:10 - 2014-08-12 05:10 - 00231424 _____ () C:\Windows\system32\clinfo.exe 2014-08-12 05:09 - 2014-08-12 05:09 - 32877056 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2014-08-12 05:09 - 2014-08-12 05:09 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2014-08-12 05:06 - 2014-08-12 05:06 - 27843072 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2014-08-12 05:03 - 2014-08-12 05:03 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-08-12 05:03 - 2014-08-12 05:03 - 00058880 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-08-12 04:51 - 2014-08-12 04:51 - 00127488 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll 2014-08-12 04:50 - 2014-08-12 04:50 - 05225472 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll 2014-08-12 04:50 - 2014-08-12 04:50 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll 2014-08-12 04:45 - 2014-08-12 04:45 - 00134656 _____ () C:\Windows\system32\amdhdl64.dll 2014-08-12 04:45 - 2014-08-12 04:45 - 00123392 _____ () C:\Windows\SysWOW64\amdhdl32.dll 2014-08-12 04:44 - 2014-08-12 04:44 - 27529216 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2014-08-12 04:39 - 2014-08-12 04:39 - 00418304 _____ () C:\Windows\system32\amdmiracast.dll 2014-08-12 04:34 - 2014-08-12 04:34 - 04180992 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll 2014-08-12 04:24 - 2014-08-12 04:24 - 23028224 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2014-08-12 04:20 - 2014-08-12 04:20 - 00091648 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll 2014-08-12 04:19 - 2014-08-12 04:19 - 00598112 _____ () C:\Windows\SysWOW64\atiapfxx.blb 2014-08-12 04:19 - 2014-08-12 04:19 - 00598112 _____ () C:\Windows\system32\atiapfxx.blb 2014-08-12 04:19 - 2014-08-12 04:19 - 00085504 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00366592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2014-08-12 04:18 - 2014-08-12 04:18 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2014-08-12 04:18 - 2014-08-12 04:18 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2014-08-12 04:14 - 2014-08-12 04:14 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2014-08-12 04:01 - 2014-08-12 04:01 - 00588800 _____ (AMD) C:\Windows\system32\atieclxx.exe 2014-08-12 04:01 - 2014-08-12 04:01 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2014-08-12 04:01 - 2014-08-12 04:01 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2014-08-12 04:00 - 2014-08-12 04:00 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2014-08-12 03:59 - 2014-08-12 03:59 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2014-08-12 03:57 - 2014-08-12 03:57 - 00048128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll 2014-08-12 03:57 - 2014-08-12 03:57 - 00037888 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll 2014-08-12 03:53 - 2014-08-12 03:53 - 03437632 _____ () C:\Windows\system32\atiumd6a.cap 2014-08-12 03:43 - 2014-07-09 17:21 - 00826368 _____ (AMD) C:\Windows\system32\coinst_14.20.dll 2014-08-12 03:42 - 2014-08-12 03:42 - 03471376 _____ () C:\Windows\SysWOW64\atiumdva.cap 2014-08-12 03:34 - 2014-08-12 03:34 - 01207296 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00898560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00146944 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00133632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00095744 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2014-08-12 03:34 - 2014-08-12 03:34 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2014-08-12 03:33 - 2014-08-12 03:33 - 00557056 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2014-08-12 03:33 - 2014-08-12 03:33 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2014-08-12 03:33 - 2014-08-12 03:33 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2014-08-12 03:32 - 2014-08-12 03:32 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2014-08-07 04:12 - 2014-08-29 17:20 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll Some content of TEMP: ==================== C:\Users\Philipp\AppData\Local\Temp\swt-win32-3349.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-29 17:24 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-09-2014 02 Ran by Philipp at 2014-09-03 17:29:12 Running from C:\Users\Philipp\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton Internet Security (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton Internet Security (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton Internet Security (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Amazon Music (HKCU\...\Amazon Amazon Music) (Version: 3.2.0.591 - Amazon Services LLC) Apple Application Support (HKLM-x32\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center InstallProxy (x32 Version: 2014.0704.2133.36938 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CPUID HWMonitor 1.25 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Definition Update for Microsoft Office 2013 (KB2760587) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{0B79C91F-978F-4C2E-9FE4-D4B567808858}) (Version: - Microsoft) Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Fraps (HKLM-x32\...\Fraps) (Version: - ) Free YouTube to MP3 Converter version 3.12.44.820 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.44.820 - DVDVideoSoft Ltd.) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3621 - Intel Corporation) iTunes (HKLM\...\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Access MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft DCF MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Excel MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Groove MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft InfoPath MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Lync MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office 64-bit Components 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Korrekturhilfen 2013 - Deutsch (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office OSM UX MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - English (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2013 - Italiano (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2013 (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft OneNote MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Outlook MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft PowerPoint MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Publisher MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Word MUI (German) 2013 (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) Mp3tag v2.61a (HKLM-x32\...\Mp3tag) (Version: v2.61a - Florian Heidenreich) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.51.0 - Black Tree Gaming) Norton Internet Security (HKLM-x32\...\NIS) (Version: 21.5.0.19 - Symantec Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.4.11.2806 - Electronic Arts, Inc.) Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge) RaidCall (HKLM-x32\...\RaidCall) (Version: 7.3.6-1.0.12952.91 - raidcall.com) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (x32 Version: - Microsoft) Hidden SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts) Sniper Elite 3 (HKLM-x32\...\Steam App 238090) (Version: - Rebellion) Spotify (HKCU\...\Spotify) (Version: 0.9.12.10.g89b2a4fc - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) Tinypic 3.18 (HKLM-x32\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.18 - E. Fiedler) TIPP10 Version 2.1.0 (HKLM-x32\...\TIPP10_is1) (Version: - (c) 2006-2011, Tom Thielicke IT Solutions) Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Excel 2013 (KB2883061) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4CFCE804-3034-4F3A-84E2-3C97665F80EC}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881070) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{35E5FACD-A5AA-46AD-93C7-F6D7969044E7}) (Version: - Microsoft) Update for Microsoft Lync 2013 (KB2881083) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{4FC38705-B045-4DAC-A0B0-C573D31B8CD5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760249) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{8C07AD38-38EB-4332-BCB3-F55A77C927DF}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760344) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7610F07-E844-4444-8E1D-D5BC8AD0B4C5}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2760544) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{45B7D395-EB9B-414F-9E46-5849B42326E2}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2768012) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{66421820-D3CA-450A-898C-78D7E40108E6}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1644D7F6-90EE-4252-8884-18E4E330529D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2817302) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{1644D7F6-90EE-4252-8884-18E4E330529D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2826040) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B7EA8070-C37F-4617-82F4-52CF3304595A}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2837644) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{9BC5FF1D-9626-44D7-BC7F-EB44BD8BDB9F}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{AD7045B8-1D75-4B4C-8120-12F045D206C7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880457) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{D27F6360-AE1E-4C8C-8ECD-C0375E20B923}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{5D6439FF-D651-4B13-B52E-2508AB9DE19D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880462) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{5D6439FF-D651-4B13-B52E-2508AB9DE19D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2880478) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7C5CEE0F-6823-4BB7-A28F-76FEC14EB6AC}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881009) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7A3EF4FF-A9C8-4F7E-8020-A45F7D319387}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0016-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition (HKLM-x32\...\{90150000-0090-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01B80B63-C638-4004-9148-75B8C8518B1E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883036) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{B8E73381-09B1-4895-ACD0-34385B0F526D}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883049) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1C6260FD-A280-49FE-89D0-CCEC647FBD8E}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883052) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{3F3A95FF-9F40-4B19-8227-53DF683B4CF9}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883052) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{3F3A95FF-9F40-4B19-8227-53DF683B4CF9}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0F5FFEB6-2F66-4592-8A34-CC85FF318951}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0409-0000-0000000FF1CE}_Office15.PROPLUS_{DA288EB3-648C-433C-88AC-71AEAAFAACF7}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}_Office15.PROPLUS_{51865C36-97D4-4210-A33E-50BCC8CDDF72}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883060) 32-Bit Edition (HKLM-x32\...\{90150000-001F-0410-0000-0000000FF1CE}_Office15.PROPLUS_{D533D4E6-5056-487A-8F18-7FA51AF0E283}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883062) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{EE35EB6C-7768-433F-B9A0-73C97699A08C}) (Version: - Microsoft) Update for Microsoft Office 2013 (KB2883062) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{EE35EB6C-7768-433F-B9A0-73C97699A08C}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0407-1000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneDrive for Business (KB2883066) 32-Bit Edition (HKLM-x32\...\{90150000-00BA-0407-0000-0000000FF1CE}_Office15.PROPLUS_{90EEAEDF-CD51-4E8C-B781-7A071EC53C36}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version: - Microsoft) Update for Microsoft OneNote 2013 (KB2881082) 32-Bit Edition (HKLM-x32\...\{90150000-00A1-0407-0000-0000000FF1CE}_Office15.PROPLUS_{CA0F0611-10FB-47D4-A642-E3BABCC73393}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{1BCA67A6-5329-48D0-A088-C097AC7A14BD}) (Version: - Microsoft) Update for Microsoft Outlook 2013 (KB2880470) 32-Bit Edition (HKLM-x32\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{1BCA67A6-5329-48D0-A088-C097AC7A14BD}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2883051) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{01923A0F-BA34-4A75-8D43-97F536E44D95}) (Version: - Microsoft) Update for Microsoft PowerPoint 2013 (KB2883051) 32-Bit Edition (HKLM-x32\...\{90150000-0018-0407-0000-0000000FF1CE}_Office15.PROPLUS_{01923A0F-BA34-4A75-8D43-97F536E44D95}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7500AD77-83C6-400B-8B2F-F8E401A7B697}) (Version: - Microsoft) Update for Microsoft Publisher 2013 (KB2880999) 32-Bit Edition (HKLM-x32\...\{90150000-0019-0407-0000-0000000FF1CE}_Office15.PROPLUS_{7500AD77-83C6-400B-8B2F-F8E401A7B697}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition (HKLM-x32\...\{90150000-006E-0407-0000-0000000FF1CE}_Office15.PROPLUS_{25C61889-2E44-4BE1-9E96-9364BFDCF501}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2878319) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{A7CD05CC-CA85-428C-91FD-74A908D126E1}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-001A-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-001B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Update for Microsoft Word 2013 (KB2883058) 32-Bit Edition (HKLM-x32\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{78F4AB20-5992-425F-BCFB-ECCFF3531F55}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 4.6 - Ubisoft) WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1180989676-4077080399-2706785428-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation) ==================== Restore Points ========================= 23-08-2014 16:07:23 Geplanter Prüfpunkt 25-08-2014 17:52:27 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 29-08-2014 15:24:15 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0726C130-051F-426D-88FD-2BC0A9DAB8D2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {10CF8053-618A-4316-8965-4CAE5F2C0F21} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: {183C100F-BD02-4079-B94B-E5A2762A93F1} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {27B2D3A8-6D15-47C7-9BFC-E5FDA4A7DA4D} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {2DD1CD41-3ECD-49E6-A07A-00B54C3E91E3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-08-16] (Microsoft Corporation) Task: {3382F68A-5F7E-46EC-AE38-DF6BCFA4CA46} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {66B93C85-FCF1-416B-9DA5-C05816952DF0} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {73C646CF-4A71-4441-AFE2-2819730570C1} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8C5E534E-C1FA-4C02-B717-35EE74FFF16C} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {8CAC0121-58A4-44B5-A901-6E83111E2331} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\WSCStub.exe [2014-07-31] (Symantec Corporation) Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {918DBD67-B81C-4F58-A76F-9ECA83CB361D} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {92665B7A-0B38-4613-9E52-5CF9EE6EA648} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A20460F5-B774-44BB-BF9E-462E980CF09B} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-08-25] () Task: {A52B1E51-6685-4D5B-A85A-47EE24E990D0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation) Task: {C276C12F-1DCC-4512-9887-F72A3E9264B8} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.5.0.19\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D5CD7F4B-13E6-46CA-996F-8EF43AE35764} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-24] (Adobe Systems Incorporated) Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-08-29 17:19 - 2014-08-21 20:15 - 01171456 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2014-08-29 17:19 - 2014-08-21 20:15 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2014-08-29 17:19 - 2014-08-21 20:15 - 00442368 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2014-07-24 12:43 - 2014-08-21 00:38 - 00774656 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2014-07-24 12:43 - 2014-08-28 13:48 - 02224320 _____ () C:\Program Files (x86)\Steam\video.dll 2014-08-29 17:19 - 2014-08-21 20:15 - 00403968 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2014-08-29 17:19 - 2014-08-21 20:15 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2014-07-24 12:43 - 2014-08-28 13:48 - 00678080 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2014-07-24 12:43 - 2014-08-21 00:38 - 34589376 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2014-07-24 12:30 - 2014-07-17 07:42 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\Services: Apple Mobile Device => 2 MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: iPod Service => 3 MSCONFIG\Services: TeamViewer9 => 2 HKLM\...\StartupApproved\Run: => "MouseDriver" HKLM\...\StartupApproved\Run32: => "iTunesHelper" HKLM\...\StartupApproved\Run32: => "Adobe ARM" HKCU\...\StartupApproved\Run: => "Amazon Music" ==================== Faulty Device Manager Devices ============= Name: PCI-Kommunikationscontroller (einfach) Description: PCI-Kommunikationscontroller (einfach) Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: SM-Bus-Controller Description: SM-Bus-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (09/02/2014 07:13:24 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (09/01/2014 06:52:36 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (09/01/2014 06:36:11 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"2" in Zeile UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0". Definition: UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll4 Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (08/30/2014 04:54:33 PM) (Source: PerfNet) (EventID: 2004) (User: ) Description: Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: MSDTCC:\Windows\system32\msdtcuiu.DLL4 Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: LsaC:\Windows\System32\Secur32.dll4 Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: ESENTC:\Windows\system32\esentprf.dll4 Error: (08/30/2014 01:51:55 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 System errors: ============= Error: (09/03/2014 05:21:47 PM) (Source: Tcpip) (EventID: 4199) (User: ) Description: Das System hat einen Adressenkonflikt der IP-Adresse 192.168.1.4 mit dem Computer mit der Netzwerkhardwareadresse 08-96-D7-2E-56-6B ermittelt. Netzwerkvorgänge könnten daher auf diesem System unterbrochen werden. Error: (09/02/2014 08:01:15 PM) (Source: DCOM) (EventID: 10010) (User: Computer) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (09/02/2014 07:15:36 PM) (Source: NetBT) (EventID: 4319) (User: ) Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers, der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an der Eingabeaufforderung, um den doppelten Namen zu bestimmen. Error: (09/02/2014 07:15:35 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "COMPUTER :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.4 registriert werden. Der Computer mit IP-Adresse 192.168.1.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (09/02/2014 07:02:50 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "COMPUTER :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.4 registriert werden. Der Computer mit IP-Adresse 192.168.1.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (09/02/2014 07:02:50 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "COMPUTER :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.4 registriert werden. Der Computer mit IP-Adresse 192.168.1.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (09/02/2014 07:02:50 PM) (Source: Server) (EventID: 2505) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{37F2091E-9AD2-423B-94EB-EB74E00FCB62} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (09/02/2014 07:02:44 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "COMPUTER :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.5 registriert werden. Der Computer mit IP-Adresse 192.168.1.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (09/02/2014 07:02:44 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "COMPUTER :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.1.5 registriert werden. Der Computer mit IP-Adresse 192.168.1.6 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (09/02/2014 07:02:44 PM) (Source: Server) (EventID: 2505) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{37F2091E-9AD2-423B-94EB-EB74E00FCB62} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Microsoft Office Sessions: ========================= Error: (09/02/2014 07:13:24 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (09/01/2014 06:52:36 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 Error: (09/01/2014 06:36:11 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: UccApi,processorArchitecture="AMD64",type="win32",version="15.0.0.0"UccApi,processorArchitecture="x86",type="win32",version="15.0.0.0"c:\program files (x86)\microsoft office\Office15\lync.exe.Manifestc:\program files (x86)\microsoft office\Office15\UccApi.DLL1 Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: WmiApRplC:\Windows\system32\wbem\wmiaprpl.dll4 Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: rdyboost4 Error: (08/30/2014 04:54:33 PM) (Source: PerfNet) (EventID: 2004) (User: ) Description: Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: MSDTCC:\Windows\system32\msdtcuiu.DLL4 Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: LsaC:\Windows\System32\Secur32.dll4 Error: (08/30/2014 04:54:33 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: ESENTC:\Windows\system32\esentprf.dll4 Error: (08/30/2014 01:51:55 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: BITSC:\Windows\System32\bitsperf.dll8 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4590 CPU @ 3.30GHz Percentage of memory in use: 20% Total physical RAM: 7851.27 MB Available physical RAM: 6235.5 MB Total Pagefile: 9067.27 MB Available Pagefile: 7466.98 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.17 GB) (Free:762.34 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: DC6458E2) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931.2 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von N3mesis (03.09.2014 um 16:36 Uhr) |
04.09.2014, 11:23 | #4 |
/// the machine /// TB-Ausbilder | Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Bitte mal die angemeckerte Datei bei www.virustotal.com scannen lassen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.09.2014, 16:29 | #5 |
| Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Hallo Schrauber, wie in meinem ersten Post schon erwähnt, habe ich die Datei von MB in Quarantäne stellen und anschließend löschen lassen. Nach einem weiteren Scan zeigt mir MB zwar keine Bedrohung mehr an, aber ich weiß nicht was sich damit vielleicht noch alles eingeschlichen hat bzw. ob denn wirklich alles weg ist... Grüße |
05.09.2014, 09:59 | #6 |
/// the machine /// TB-Ausbilder | Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Logfiles sind sauber. Merkst du denn Probleme mit der Kiste?
__________________ --> Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner |
05.09.2014, 17:12 | #7 |
| Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Nein, der PC läuft ansonsten vollkommen rund! Gruß |
06.09.2014, 13:50 | #8 |
/// the machine /// TB-Ausbilder | Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Dann würde ich sagen das war nur der eine Fund in den Temps
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.09.2014, 14:24 | #9 |
| Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Fund in den Temps? Was kann ich mir darunter vorstellen? Kannst du grob einschätzen was für eine Gefahr davon ausging? Brauch in ansonsten nur meine Passwörter zu ändern? Und vielen Dank für deine Hilfe! |
07.09.2014, 12:19 | #10 |
/// the machine /// TB-Ausbilder | Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Na nur in dem temporären Dateien. MBAM hat dazwischen gefunkt. Passwörter ändern ist immer ne gute Idee
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.09.2014, 17:46 | #11 |
| Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Alles klar, danke! |
09.09.2014, 16:32 | #12 |
/// the machine /// TB-Ausbilder | Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Trojan.Agent - netlogger.exe - MalwareBytes findet nach Routinescan einen Trojaner |
100%, anschluss, appdata, code, datei, detected, durchgeführt, escan, heute, hilfe!, ics, malwarebytes, netlogger, passwörter, protection, quarantäne, scan, schließe, servus, system, temp, trojan.agent, trojaner, website, windows, wirklich, ändern |