|
Plagegeister aller Art und deren Bekämpfung: Es öffnet sich ständig einfach WerbungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.08.2015, 14:08 | #1 |
| Es öffnet sich ständig einfach Werbung Hallo, ich habe ein Problem das wenn ich in Chrome seiten öffne oder irgend was mache also (Browse/Surfe) dauernd neu Tabs mit Werbung kommen. |
11.08.2015, 14:09 | #2 |
/// the machine /// TB-Ausbilder | Es öffnet sich ständig einfach Werbung hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
11.08.2015, 14:27 | #3 |
| Es öffnet sich ständig einfach WerbungCode:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:09-08-2015 durchgeführt von Kevin (Administrator) auf KEVIN-PC (11-08-2015 15:14:14) Gestartet von C:\Users\Kevin\Desktop\Downloads Geladene Profile: Kevin (Verfügbare Profile: Kevin) Platform: Windows 7 Professional Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 11 (Standard-Browser: Chrome) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Nicht auf der Ausnahmeliste) ================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13776088 2014-12-11] (Realtek Semiconductor) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595848 2015-07-08] (ESET) HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [56080 2015-07-27] (Raptr, Inc) HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} HKU\S-1-5-21-3288466570-3956607681-561774039-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT HKU\S-1-5-21-3288466570-3956607681-561774039-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp HKU\S-1-5-21-3288466570-3956607681-561774039-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} SearchScopes: HKU\S-1-5-21-3288466570-3956607681-561774039-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&ts=1434339425&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3288466570-3956607681-561774039-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&ts=1434339425&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3288466570-3956607681-561774039-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&ts=1434339425&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3288466570-3956607681-561774039-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&ts=1434339425&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-3288466570-3956607681-561774039-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&ts=1434339425&type=default&q={searchTerms} BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-11-12] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-11-12] (Oracle Corporation) BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices) Winsock: Catalog9 01 C:\Windows\SysWOW64\Rofdhowal.dll [279040 2015-07-29] () Winsock: Catalog9 02 C:\Windows\SysWOW64\Rofdhowal.dll [279040 2015-07-29] () Winsock: Catalog9 03 C:\Windows\SysWOW64\Rofdhowal.dll [279040 2015-07-29] () Winsock: Catalog9 04 C:\Windows\SysWOW64\Rofdhowal.dll [279040 2015-07-29] () Winsock: Catalog9 15 C:\Windows\SysWOW64\Rofdhowal.dll [279040 2015-07-29] () Winsock: Catalog9-x64 01 C:\Windows\system32\Rofdhowal64.dll [349184 2015-07-29] () Winsock: Catalog9-x64 02 C:\Windows\system32\Rofdhowal64.dll [349184 2015-07-29] () Winsock: Catalog9-x64 03 C:\Windows\system32\Rofdhowal64.dll [349184 2015-07-29] () Winsock: Catalog9-x64 04 C:\Windows\system32\Rofdhowal64.dll [349184 2015-07-29] () Winsock: Catalog9-x64 15 C:\Windows\system32\Rofdhowal64.dll [349184 2015-07-29] () Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{AC41846C-6AE7-4212-B5FC-1D2A4CBDA2EA}: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [Keine Datei] FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [Keine Datei] FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-12] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-11-12] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2014-12-13] (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [Keine Datei] FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [Keine Datei] FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2014-12-13] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.5\npGoogleUpdate3.dll [2015-08-10] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.5\npGoogleUpdate3.dll [2015-08-10] (Google Inc.) FF Plugin HKU\S-1-5-21-3288466570-3956607681-561774039-1000: @nsroblox.roblox.com/launcher -> C:\Users\Kevin\AppData\Local\Roblox\Versions\version-4993687f79834cd9\\NPRobloxProxy.dll Keine Datei FF Plugin HKU\S-1-5-21-3288466570-3956607681-561774039-1000: @nsroblox.roblox.com/launcher64 -> C:\Users\Kevin\AppData\Local\Roblox\Versions\version-4993687f79834cd9\\NPRobloxProxy64.dll Keine Datei FF Plugin HKU\S-1-5-21-3288466570-3956607681-561774039-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Kevin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-3288466570-3956607681-561774039-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-07-12] () FF HKLM\...\Firefox\Extensions: [{628f215e-0803-40f0-a52d-25e9ab679f78}] - C:\Program Files\shopperz27072015\Firefox FF HKLM-x32\...\Firefox\Extensions: [{628f215e-0803-40f0-a52d-25e9ab679f78}] - C:\Program Files\shopperz27072015\Firefox Chrome: ======= CHR Profile: C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Assassin's Creed IV Black Flag) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\agibflpbghgmiinfaefgnldmfajdance [2015-08-10] CHR Extension: (Google Drive) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-10] CHR Extension: (YouTube) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-10] CHR Extension: (GMX MailCheck) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\camnampocfohlcgbajligmemmabnljcm [2015-08-10] CHR Extension: (Adblock Plus) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-08-10] CHR Extension: (Google Search) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-10] CHR Extension: (AdBlock) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-08-10] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-10] CHR Extension: (Chrome Web Store Payments) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-10] CHR Extension: (Adblock Pro) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2015-08-10] CHR Extension: (Gmail) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-10] ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-07-28] (Advanced Micro Devices, Inc.) [Datei ist nicht signiert] R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2015-06-22] (Advanced Micro Devices) [Datei ist nicht signiert] S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2014-11-12] (BitRaider, LLC) S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272592 2015-02-26] (Disc Soft Ltd) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [182304 2014-11-17] (EasyAntiCheat Ltd) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1353720 2015-07-08] (ESET) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Datei ist nicht signiert] R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-08-06] (LogMeIn, Inc.) S4 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [137528 2013-11-15] (Motorola Mobility LLC) S3 Origin Client Service; F:\Origin\OriginClientService.exe [2007048 2015-08-10] (Electronic Arts) S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1001200 2015-07-19] (Overwolf LTD) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-07-01] () R2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S3 BEService; "C:\Program Files (x86)\Common Files\BattlEye\BEService.exe" [X] S2 FreemakeVideoCapture; "F:\Freemake\CaptureLib\CaptureLibService.exe" [X] S3 ICCS; "C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe" [X] ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [297672 2015-07-29] (Advanced Micro Devices) R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] () S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-07-16] (BitRaider) R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30352 2015-05-08] (Disc Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [255240 2015-07-14] (ESET) U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [251632 2015-07-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [178520 2015-07-14] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [231520 2015-07-14] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [53360 2015-07-14] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [72400 2015-07-14] (ESET) S3 gdrv; C:\Windows\gdrv.sys [25640 2015-01-18] () [Datei ist nicht signiert] S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2015-01-12] () R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-09] (Intel Corporation) S3 iaStorS; C:\Windows\system32\drivers\iaStorS.sys [638896 2012-03-09] (Intel Corporation) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.) S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [51280 2010-11-02] (LSI Corporation) S3 megasr1; C:\Windows\system32\drivers\megasr1.sys [806696 2012-02-08] (LSI Corporation, Inc.) R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) R1 {04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64; C:\Windows\System32\drivers\{04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64.sys [48784 2015-07-22] (StdLib) S2 AODDriver4.2; \??\C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver2.sys [X] S1 cherimoya; system32\drivers\cherimoya.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-08-11 15:14 - 2015-08-11 15:14 - 00000000 ____D C:\FRST 2015-08-10 14:26 - 2015-08-10 14:26 - 00002257 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-08-10 14:26 - 2015-08-10 14:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-08-10 14:24 - 2015-08-11 14:36 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-08-10 14:24 - 2015-08-11 04:29 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-08-10 14:24 - 2015-08-10 14:26 - 00000000 ____D C:\Users\Kevin\AppData\Local\Google 2015-08-10 14:24 - 2015-08-10 14:25 - 00000000 ____D C:\Program Files (x86)\Google 2015-08-10 14:24 - 2015-08-10 14:24 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-08-10 14:24 - 2015-08-10 14:24 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-08-08 10:51 - 2015-08-08 10:57 - 00000019 _____ C:\Users\Kevin\Desktop\irgendwas.txt 2015-08-07 20:04 - 2015-08-07 20:04 - 00000936 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2015-08-07 20:04 - 2015-08-07 20:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2015-08-07 20:04 - 2015-08-07 20:04 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2015-08-07 19:10 - 2015-08-07 19:10 - 00058877 _____ C:\Windows\SysWOW64\CCCInstall_201508071910177393.log 2015-08-07 19:10 - 2015-08-07 19:10 - 00000000 ____D C:\ProgramData\ATI 2015-08-07 19:09 - 2015-08-07 19:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2015-08-07 18:32 - 2015-08-07 18:32 - 00000007 _____ C:\Users\Kevin\Desktop\american soda 10prozent rapat code.txt 2015-08-06 14:45 - 2015-08-06 14:45 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\Drivers\hamachi.sys 2015-07-31 09:47 - 2015-07-31 09:47 - 00000000 ____D C:\Users\Kevin\AppData\Local\CEF 2015-07-30 18:11 - 2015-07-30 18:11 - 00064808 _____ C:\Users\Kevin\AppData\Local\GDIPFONTCACHEV1.DAT 2015-07-30 15:00 - 2015-08-10 16:58 - 00000000 ____D C:\Users\Kevin\AppData\Local\CrashDumps 2015-07-30 00:24 - 2015-07-30 00:24 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\ESET 2015-07-30 00:24 - 2015-07-30 00:24 - 00000000 ____D C:\Users\Kevin\AppData\Local\ESET 2015-07-30 00:22 - 2015-07-30 00:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET 2015-07-30 00:22 - 2015-07-30 00:22 - 00000000 ____D C:\ProgramData\ESET 2015-07-30 00:22 - 2015-07-30 00:22 - 00000000 ____D C:\Program Files\ESET 2015-07-29 22:14 - 2015-07-29 22:14 - 00004664 _____ C:\Windows\SysWOW64\Rofdhowal.ini 2015-07-29 22:14 - 2015-07-29 22:14 - 00002384 _____ C:\Windows\SysWOW64\RofdhowalOff.ini 2015-07-29 22:14 - 2015-07-29 22:14 - 00002384 _____ C:\Windows\system32\RofdhowalOff.ini 2015-07-29 22:14 - 2015-07-20 13:35 - 00349184 _____ C:\Windows\system32\Rofdhowal64.dll 2015-07-29 22:14 - 2015-07-20 13:35 - 00279040 _____ C:\Windows\SysWOW64\Rofdhowal.dll 2015-07-29 22:13 - 2015-07-29 22:13 - 00000000 ____D C:\Windows\system32\simc 2015-07-29 22:11 - 2015-07-29 22:11 - 00000045 _____ C:\user.js 2015-07-29 10:34 - 2015-07-29 10:35 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\SpaceEngineers 2015-07-29 05:44 - 2015-07-29 05:44 - 00107784 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2015-07-29 05:43 - 2015-07-29 05:43 - 00141792 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2015-07-29 05:43 - 2015-07-29 05:43 - 00128384 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2015-07-29 05:43 - 2015-07-29 05:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2015-07-29 05:43 - 2015-07-29 05:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2015-07-29 05:42 - 2015-07-29 05:42 - 00120144 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2015-07-29 05:42 - 2015-07-29 05:42 - 00102616 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2015-07-29 05:42 - 2015-07-29 05:42 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2015-07-29 05:42 - 2015-07-29 05:42 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2015-07-29 05:40 - 2015-07-29 05:40 - 07408936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2015-07-29 05:39 - 2015-07-29 05:39 - 08893160 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2015-07-29 05:39 - 2015-07-29 05:39 - 08779872 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2015-07-29 05:26 - 2015-07-29 05:26 - 00297672 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys 2015-07-29 05:15 - 2015-07-29 05:15 - 21622784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2015-07-29 05:09 - 2015-07-29 05:09 - 47785472 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2015-07-29 05:09 - 2015-07-29 05:09 - 00235008 _____ C:\Windows\system32\clinfo.exe 2015-07-29 05:07 - 2015-07-29 05:07 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2015-07-29 05:07 - 2015-07-29 05:07 - 00059392 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2015-07-29 05:06 - 2015-07-29 05:06 - 27535872 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll 2015-07-29 04:41 - 2015-07-29 04:41 - 06477312 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll 2015-07-29 04:41 - 2015-07-29 04:41 - 00127488 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll 2015-07-29 04:41 - 2015-07-29 04:41 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll 2015-07-29 04:36 - 2015-07-29 04:36 - 05068288 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll 2015-07-29 04:34 - 2015-07-29 04:34 - 30752256 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2015-07-29 04:34 - 2015-07-29 04:34 - 00050688 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll 2015-07-29 04:34 - 2015-07-29 04:34 - 00039424 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll 2015-07-29 04:33 - 2015-07-29 04:33 - 00093696 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll 2015-07-29 04:33 - 2015-07-29 04:33 - 00086528 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll 2015-07-29 04:32 - 2015-07-29 04:32 - 03437632 _____ C:\Windows\system32\atiumd6a.cap 2015-07-29 04:30 - 2015-07-29 04:30 - 15716864 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2015-07-29 04:30 - 2015-07-29 04:30 - 00660928 _____ C:\Windows\SysWOW64\atiapfxx.blb 2015-07-29 04:30 - 2015-07-29 04:30 - 00660928 _____ C:\Windows\system32\atiapfxx.blb 2015-07-29 04:30 - 2015-07-29 04:30 - 00367104 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2015-07-29 04:30 - 2015-07-29 04:30 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2015-07-29 04:30 - 2015-07-29 04:30 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2015-07-29 04:30 - 2015-07-29 04:30 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2015-07-29 04:30 - 2015-07-29 04:30 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2015-07-29 04:29 - 2015-07-29 04:29 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2015-07-29 04:28 - 2015-07-29 04:28 - 25299968 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2015-07-29 04:28 - 2015-07-29 04:28 - 03471376 _____ C:\Windows\SysWOW64\atiumdva.cap 2015-07-29 04:26 - 2015-07-29 04:26 - 00672768 _____ (AMD) C:\Windows\system32\atieclxx.exe 2015-07-29 04:26 - 2015-07-29 04:26 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2015-07-29 04:26 - 2015-07-29 04:26 - 00204800 _____ C:\Windows\system32\amdgfxinfo64.dll 2015-07-29 04:26 - 2015-07-29 04:26 - 00189952 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll 2015-07-29 04:26 - 2015-07-29 04:26 - 00160256 _____ C:\Windows\system32\atieah64.exe 2015-07-29 04:26 - 2015-07-29 04:26 - 00143872 _____ C:\Windows\SysWOW64\atieah32.exe 2015-07-29 04:26 - 2015-07-29 04:26 - 00029696 _____ (AMD) C:\Windows\system32\atimuixx.dll 2015-07-29 04:25 - 2015-07-29 04:25 - 00246784 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2015-07-29 04:25 - 2015-07-29 04:25 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2015-07-29 04:24 - 2015-07-29 04:24 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2015-07-29 04:24 - 2015-07-29 04:24 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2015-07-29 04:23 - 2015-07-29 04:23 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2015-07-29 04:22 - 2015-07-29 04:22 - 01247744 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2015-07-29 04:22 - 2015-07-29 04:22 - 00926720 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll 2015-07-29 04:22 - 2015-07-29 04:22 - 00665088 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2015-07-29 04:22 - 2015-07-29 04:22 - 00156672 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2015-07-29 04:22 - 2015-07-29 04:22 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2015-07-29 04:22 - 2015-07-29 04:22 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2015-07-29 04:22 - 2015-07-29 04:22 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2015-07-29 04:19 - 2015-07-29 04:19 - 00102912 _____ C:\Windows\system32\hsa-thunk64.dll 2015-07-29 04:19 - 2015-07-29 04:19 - 00102400 _____ C:\Windows\SysWOW64\hsa-thunk.dll 2015-07-28 11:07 - 2015-07-28 11:24 - 00000000 ____D C:\Users\Kevin\Desktop\Kevin Handy viedeos 2015-07-28 11:00 - 2015-07-28 11:00 - 00000222 _____ C:\Users\Kevin\Desktop\Space Engineers.url 2015-07-27 11:21 - 2015-07-29 11:33 - 00000000 ____D C:\ProgramData\Frowaoprar 2015-07-27 11:15 - 2015-08-11 14:35 - 00000966 _____ C:\Windows\PFRO.log 2015-07-25 11:18 - 2015-08-11 14:36 - 00009623 _____ C:\Windows\setupact.log 2015-07-25 11:18 - 2015-07-25 11:18 - 00000000 _____ C:\Windows\setuperr.log 2015-07-25 08:29 - 2015-08-11 14:36 - 00000988 _____ C:\Windows\Tasks\wipCjjyi.job 2015-07-25 08:29 - 2015-07-25 08:30 - 00004014 _____ C:\Windows\System32\Tasks\wipCjjyi 2015-07-24 09:25 - 2015-07-24 09:25 - 00058877 _____ C:\Windows\SysWOW64\CCCInstall_201507240925115389.log 2015-07-24 07:39 - 2015-07-24 07:39 - 00000000 ____D C:\ProgramData\6b49f27b0000087a 2015-07-24 07:32 - 2015-07-30 00:29 - 00000000 ____D C:\ProgramData\{df97f9c9-a2ee-1ae3-df97-7f9c9a2ee726} 2015-07-23 08:45 - 2015-07-23 12:52 - 00000000 ____D C:\Users\Kevin\Documents\Camtasia Studio 2015-07-23 08:45 - 2015-07-23 08:45 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\TechSmith 2015-07-23 08:44 - 2015-07-23 08:44 - 00000000 ____D C:\Users\Kevin\AppData\Local\TechSmith 2015-07-23 08:43 - 2015-07-23 08:43 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith 2015-07-23 08:43 - 2015-07-23 08:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2015-07-23 08:43 - 2015-07-23 08:43 - 00000000 ____D C:\Program Files (x86)\QuickTime 2015-07-23 08:42 - 2015-07-23 08:42 - 00000000 ____D C:\Program Files (x86)\TechSmith 2015-07-23 07:09 - 2015-07-23 07:09 - 00003842 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1437628130 2015-07-23 07:09 - 2015-07-23 07:09 - 00000008 _____ C:\END 2015-07-23 07:09 - 2015-07-22 17:14 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64.sys 2015-07-23 07:08 - 2015-07-23 07:08 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-07-23 07:08 - 2015-07-23 07:08 - 00000000 ____D C:\Users\Kevin\AppData\Local\globalUpdate 2015-07-23 07:06 - 2015-08-11 14:36 - 00000336 _____ C:\Windows\Tasks\MNKXYDZYN1.job 2015-07-23 07:06 - 2015-08-10 17:02 - 00000000 ____D C:\ProgramData\Service1198 2015-07-23 07:06 - 2015-07-23 07:06 - 00002858 _____ C:\Windows\System32\Tasks\MNKXYDZYN1 2015-07-23 07:06 - 2015-07-23 07:06 - 00000000 ____D C:\ProgramData\7c0535b143fc4671b6ebd202fbffe066 2015-07-23 05:46 - 2015-07-15 05:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-07-23 05:46 - 2015-07-15 05:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-07-23 05:46 - 2015-07-15 05:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-07-23 05:46 - 2015-07-15 05:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-07-23 05:46 - 2015-07-15 04:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2015-07-23 05:46 - 2015-07-15 04:55 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-07-23 05:46 - 2015-07-15 04:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2015-07-23 05:46 - 2015-07-15 04:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2015-07-23 05:46 - 2015-07-15 03:59 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-07-23 05:46 - 2015-07-15 03:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-07-21 21:44 - 2015-07-25 11:18 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox 2015-07-18 18:18 - 2015-07-18 18:18 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Unity 2015-07-18 18:12 - 2015-07-18 18:12 - 00003728 _____ C:\Windows\System32\Tasks\Overwolf Updater Task 2015-07-18 18:12 - 2015-07-18 18:12 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf 2015-07-18 18:11 - 2015-07-27 00:12 - 00000000 ____D C:\Program Files (x86)\Overwolf 2015-07-18 18:11 - 2015-07-18 18:14 - 00000000 ____D C:\ProgramData\Overwolf 2015-07-18 18:06 - 2015-07-27 11:22 - 00000000 ____D C:\Users\Kevin\AppData\Local\Overwolf 2015-07-18 03:50 - 2015-06-25 20:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-07-18 03:50 - 2015-06-25 19:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-07-18 03:50 - 2015-06-20 22:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-07-18 03:50 - 2015-06-20 21:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-07-18 03:50 - 2015-06-20 21:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-07-18 03:50 - 2015-06-20 21:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-07-18 03:50 - 2015-06-20 21:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-07-18 03:50 - 2015-06-20 21:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-07-18 03:50 - 2015-06-20 21:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-07-18 03:50 - 2015-06-20 21:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-07-18 03:50 - 2015-06-20 21:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-07-18 03:50 - 2015-06-20 21:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-07-18 03:50 - 2015-06-20 21:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-07-18 03:50 - 2015-06-20 21:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-07-18 03:50 - 2015-06-20 21:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-07-18 03:50 - 2015-06-20 21:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-07-18 03:50 - 2015-06-20 21:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-07-18 03:50 - 2015-06-20 21:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-07-18 03:50 - 2015-06-20 21:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-07-18 03:50 - 2015-06-20 20:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-07-18 03:50 - 2015-06-20 20:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-07-18 03:50 - 2015-06-20 20:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-07-18 03:50 - 2015-06-20 20:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-07-18 03:50 - 2015-06-20 20:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-07-18 03:50 - 2015-06-20 20:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-07-18 03:50 - 2015-06-19 20:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-07-18 03:50 - 2015-06-19 20:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-07-18 03:50 - 2015-06-19 20:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2015-07-18 03:50 - 2015-06-19 20:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-07-18 03:50 - 2015-06-19 20:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-07-18 03:50 - 2015-06-19 20:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-07-18 03:50 - 2015-06-19 20:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-07-18 03:50 - 2015-06-19 20:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-07-18 03:50 - 2015-06-19 20:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-07-18 03:50 - 2015-06-19 20:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-07-18 03:50 - 2015-06-19 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-07-18 03:50 - 2015-06-19 19:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-07-18 03:50 - 2015-06-19 19:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-07-18 03:50 - 2015-06-19 19:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-07-18 03:50 - 2015-06-19 19:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-07-18 03:50 - 2015-06-19 19:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-07-18 03:50 - 2015-06-19 19:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-07-18 03:50 - 2015-06-19 19:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-07-18 03:50 - 2015-06-19 19:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-07-18 03:49 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-07-18 03:49 - 2015-07-02 23:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-07-18 03:49 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-07-18 03:49 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-07-18 03:49 - 2015-07-02 22:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-07-18 03:49 - 2015-07-02 22:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-07-18 03:49 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-07-18 03:49 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-07-18 03:49 - 2015-07-02 22:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-07-18 03:49 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-07-18 03:49 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-07-18 03:49 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-07-18 03:45 - 2015-07-09 19:58 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-07-18 03:45 - 2015-07-09 19:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-07-18 03:45 - 2015-07-09 19:58 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-07-18 03:45 - 2015-07-09 19:43 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-07-18 03:45 - 2015-07-09 19:43 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-07-18 03:45 - 2015-07-09 19:43 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-07-18 03:45 - 2015-07-09 19:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-07-18 03:45 - 2015-07-09 19:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-07-18 03:45 - 2015-07-04 20:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2015-07-18 03:45 - 2015-07-04 19:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2015-07-18 03:45 - 2015-06-27 04:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-07-18 03:45 - 2015-06-27 04:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-07-18 03:45 - 2015-06-27 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-07-18 03:45 - 2015-06-27 03:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-07-18 03:45 - 2015-06-25 10:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-07-18 03:45 - 2015-06-17 19:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-07-18 03:45 - 2015-06-17 19:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-07-18 03:45 - 2015-06-11 19:57 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-07-18 03:45 - 2015-06-11 19:57 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2015-07-18 03:45 - 2015-06-11 19:57 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2015-07-18 03:45 - 2015-06-11 19:56 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-07-18 03:45 - 2015-06-11 19:56 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2015-07-18 03:45 - 2015-06-11 19:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2015-07-18 03:45 - 2015-06-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2015-07-18 03:45 - 2015-06-09 20:03 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-07-18 03:45 - 2015-06-09 20:03 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2015-07-18 03:45 - 2015-06-02 02:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll 2015-07-18 03:45 - 2015-06-02 01:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll 2015-07-18 03:44 - 2015-07-01 22:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-07-18 03:44 - 2015-07-01 22:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-07-18 03:44 - 2015-07-01 22:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-07-18 03:44 - 2015-07-01 22:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-07-18 03:44 - 2015-07-01 22:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2015-07-18 03:44 - 2015-07-01 22:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-07-18 03:44 - 2015-07-01 22:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-07-18 03:44 - 2015-07-01 22:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-07-18 03:44 - 2015-07-01 22:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-07-18 03:44 - 2015-07-01 22:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-07-18 03:44 - 2015-07-01 22:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-07-18 03:44 - 2015-07-01 22:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-07-18 03:44 - 2015-07-01 22:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-07-18 03:44 - 2015-07-01 22:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-07-18 03:44 - 2015-07-01 22:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-07-18 03:44 - 2015-07-01 22:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-07-18 03:44 - 2015-07-01 22:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-07-18 03:44 - 2015-07-01 22:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-07-18 03:44 - 2015-07-01 21:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-07-18 03:44 - 2015-07-01 21:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-07-18 03:44 - 2015-07-01 21:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-07-18 03:44 - 2015-06-15 23:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2015-07-18 03:44 - 2015-06-15 23:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-07-18 03:44 - 2015-06-15 23:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-07-18 03:44 - 2015-06-15 23:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2015-07-18 03:44 - 2015-06-15 23:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2015-07-18 03:44 - 2015-06-15 23:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2015-07-18 03:44 - 2015-06-15 23:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2015-07-18 03:44 - 2015-06-15 23:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-07-18 03:44 - 2015-06-15 23:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2015-07-18 03:44 - 2015-06-15 23:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2015-07-18 03:44 - 2015-06-15 23:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2015-07-18 03:44 - 2015-06-15 23:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2015-07-16 22:11 - 2015-07-16 22:11 - 00000000 ____D C:\Users\Kevin\AppData\Local\SWTOR 2015-07-15 22:35 - 2015-07-15 22:35 - 00000000 ____D C:\Users\Kevin\AppData\Local\Unity 2015-07-15 21:39 - 2015-07-15 21:39 - 00000000 ____D C:\Users\Public\Documents\BitRaider 2015-07-15 21:39 - 2015-07-15 21:39 - 00000000 ____D C:\Users\Kevin\AppData\Local\SWTORPerf 2015-07-15 21:31 - 2015-07-15 21:31 - 00000732 _____ C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2015-07-15 21:30 - 2015-07-15 21:32 - 00014380 _____ C:\Users\Kevin\Documents\Install STAR WARS The Old Republic.log 2015-07-15 20:49 - 2015-07-15 20:49 - 00000712 _____ C:\Users\Kevin\Desktop\Assassin's Creed - Verknüpfung.lnk 2015-07-15 12:20 - 2015-07-15 12:20 - 00103424 _____ (Advanced Micro Devices) C:\Windows\system32\DelayAPO.dll 2015-07-15 12:20 - 2015-07-15 12:20 - 00096256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2015-07-14 18:33 - 2015-07-14 18:33 - 00000000 ____D C:\ProgramData\Ubisoft 2015-07-14 18:15 - 2015-07-14 18:15 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\InstallShield 2015-07-14 15:29 - 2015-07-14 15:29 - 00255240 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys 2015-07-14 15:29 - 2015-07-14 15:29 - 00251632 _____ (ESET) C:\Windows\system32\Drivers\edevmon.sys 2015-07-14 15:29 - 2015-07-14 15:29 - 00231520 _____ (ESET) C:\Windows\system32\Drivers\epfw.sys 2015-07-14 15:29 - 2015-07-14 15:29 - 00178520 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys 2015-07-14 15:29 - 2015-07-14 15:29 - 00072400 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys 2015-07-14 15:29 - 2015-07-14 15:29 - 00053360 _____ (ESET) C:\Windows\system32\Drivers\EpfwLWF.sys 2015-07-14 13:41 - 2015-07-23 07:16 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My.com Games 2015-07-13 17:19 - 2015-07-13 17:19 - 00169152 _____ C:\Windows\system32\ativce03.dat 2015-07-13 17:19 - 2015-07-13 17:19 - 00167456 _____ C:\Windows\system32\amde31a.dat ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-08-11 15:00 - 2014-11-11 18:10 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\TS3Client 2015-08-11 14:51 - 2009-07-14 06:45 - 00025904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-08-11 14:51 - 2009-07-14 06:45 - 00025904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-08-11 14:48 - 2014-11-30 20:12 - 00000000 ____D C:\Users\Kevin\AppData\Local\LogMeIn Hamachi 2015-08-11 14:43 - 2014-11-11 17:39 - 02008338 _____ C:\Windows\WindowsUpdate.log 2015-08-11 14:39 - 2015-01-24 19:13 - 00000000 ____D C:\Program Files (x86)\Steam 2015-08-11 14:37 - 2015-02-05 13:36 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Raptr 2015-08-11 14:36 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-08-11 05:21 - 2015-02-05 13:59 - 00065536 _____ C:\Windows\system32\spu_storage.bin 2015-08-10 20:15 - 2015-01-27 14:27 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5FCB82B3-5C49-4B2B-90A4-2572AA8E2FA0} 2015-08-10 15:23 - 2014-11-12 01:04 - 00000000 ____D C:\ProgramData\Origin 2015-08-10 14:24 - 2014-11-11 19:41 - 00000000 ____D C:\Users\Kevin\AppData\Local\Deployment 2015-08-10 14:21 - 2014-11-11 22:30 - 00000000 ____D C:\Users\Kevin\Documents\my games 2015-08-08 10:48 - 2014-11-11 18:10 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client 2015-08-07 19:09 - 2015-02-05 13:33 - 00000000 ____D C:\Program Files\AMD 2015-08-07 19:08 - 2015-02-05 13:33 - 00000000 ____D C:\ProgramData\AMD 2015-08-07 18:47 - 2015-02-05 13:36 - 00000000 ____D C:\AMD 2015-08-01 13:44 - 2015-02-05 13:36 - 00000000 ____D C:\Program Files (x86)\Raptr 2015-07-31 09:31 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2015-07-30 18:13 - 2014-11-11 19:28 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\uTorrent 2015-07-30 17:44 - 2015-02-15 01:15 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\.minecraft 2015-07-30 00:13 - 2015-02-10 12:38 - 00001912 _____ C:\Windows\epplauncher.mif 2015-07-29 22:14 - 2014-11-12 17:18 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2015-07-29 22:14 - 2014-11-12 17:18 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2015-07-29 20:52 - 2014-12-24 07:25 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\vlc 2015-07-29 05:44 - 2014-11-21 04:09 - 00100568 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2015-07-29 05:42 - 2015-06-23 04:08 - 00133016 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2015-07-29 05:42 - 2014-11-21 04:44 - 00152056 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2015-07-29 05:41 - 2014-11-21 04:44 - 11948704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2015-07-29 05:41 - 2014-11-21 04:44 - 01445224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2015-07-29 05:41 - 2014-04-18 04:42 - 01193904 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2015-07-29 05:40 - 2015-06-23 04:08 - 10094152 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2015-07-29 05:40 - 2014-11-21 04:43 - 07929616 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2015-07-29 05:08 - 2014-11-21 04:32 - 39714816 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2015-07-29 05:05 - 2015-06-23 03:55 - 22318592 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll 2015-07-29 04:22 - 2014-11-21 04:09 - 00926720 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2015-07-29 04:22 - 2014-11-21 04:08 - 00141824 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2015-07-29 04:17 - 2015-06-23 03:21 - 00865792 _____ (AMD) C:\Windows\system32\coinst_15.20.dll 2015-07-28 14:26 - 2014-11-12 02:34 - 00699416 _____ C:\Windows\system32\perfh007.dat 2015-07-28 14:26 - 2014-11-12 02:34 - 00149556 _____ C:\Windows\system32\perfc007.dat 2015-07-28 14:26 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-28 11:10 - 2014-12-20 20:03 - 00000000 ____D C:\Users\Kevin\Desktop\Kevin Handy Bilder 2015-07-27 11:16 - 2014-11-11 17:47 - 00001433 _____ C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-07-25 14:00 - 2014-11-12 21:48 - 00000000 ___RD C:\Users\Kevin\Desktop\Programme 2015-07-25 10:14 - 2014-11-11 19:36 - 00000000 ____D C:\Users\Kevin\AppData\Local\Spotify 2015-07-25 10:14 - 2014-11-11 19:34 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Spotify 2015-07-25 08:35 - 2015-03-30 12:59 - 00000000 ___SD C:\Windows\system32\GWX 2015-07-25 08:32 - 2015-02-05 13:55 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2015-07-24 09:25 - 2015-02-05 13:36 - 00000000 ____D C:\Program Files (x86)\AMD 2015-07-24 08:57 - 2009-07-14 06:45 - 00299744 _____ C:\Windows\system32\FNTCACHE.DAT 2015-07-23 13:08 - 2015-03-09 10:30 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Audacity 2015-07-23 08:44 - 2014-11-11 17:46 - 00000000 ____D C:\Users\Kevin 2015-07-23 08:42 - 2014-11-12 22:06 - 00000000 ____D C:\ProgramData\TechSmith 2015-07-23 07:09 - 2009-07-14 04:34 - 00000505 _____ C:\Windows\win.ini 2015-07-18 10:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2015-07-18 04:04 - 2015-03-25 22:42 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-07-18 03:59 - 2014-11-20 03:14 - 00000000 ____D C:\Windows\system32\MRT 2015-07-15 20:51 - 2015-07-03 02:27 - 00000000 ____D C:\Users\Kevin\AppData\Roaming\Ubisoft 2015-07-15 20:08 - 2014-11-11 19:42 - 00000000 ____D C:\Users\Kevin\AppData\Local\ftblauncher 2015-07-14 18:33 - 2014-12-16 18:43 - 00000000 __SHD C:\Users\Kevin\AppData\Local\EmieUserList 2015-07-14 18:33 - 2014-12-16 18:43 - 00000000 __SHD C:\Users\Kevin\AppData\Local\EmieSiteList 2015-07-14 18:33 - 2014-12-16 18:43 - 00000000 __SHD C:\Users\Kevin\AppData\Local\EmieBrowserModeList 2015-07-14 18:29 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-07-14 18:16 - 2015-07-05 19:26 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2015-07-14 18:16 - 2014-11-11 18:01 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information Einige Dateien in TEMP: ==================== C:\Users\Kevin\AppData\Local\Temp\InstHelper.exe C:\Users\Kevin\AppData\Local\Temp\oprun19603.exe C:\Users\Kevin\AppData\Local\Temp\SpOrder.dll C:\Users\Kevin\AppData\Local\Temp\tmpF4C.exe ==================== Bamital & volsnap Check ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll [2014-11-12 17:18] - [2015-07-29 22:14] - 0357888 ____A (Microsoft Corporation) 56384A4EE8B15B4A577146BB0C04DCBE C:\Windows\SysWOW64\dnsapi.dll => MD5 ist legitim C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-08-02 17:43 ==================== Ende von log ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:09-08-2015 durchgeführt von Kevin (2015-08-11 15:16:59) Gestartet von C:\Users\Kevin\Desktop\Downloads Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-3288466570-3956607681-561774039-500 - Administrator - Disabled) Gast (S-1-5-21-3288466570-3956607681-561774039-501 - Limited - Disabled) Kevin (S-1-5-21-3288466570-3956607681-561774039-1000 - Administrator - Enabled) => C:\Users\Kevin ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} FW: ESET Personal Firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) µTorrent (HKU\S-1-5-21-3288466570-3956607681-561774039-1000\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.) ACP Application (Version: 2.15.30.0019 - Advanced Micro Devices, Inc.) Hidden Adobe Flash Player 11 ActiveX (HKLM-x32\...\{E94EFAB6-653F-4837-9E8A-F6377CA1EC0D}) (Version: 11.8.800.175 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{F37078EA-4B6A-1D6F-6FED-3EDF2117B42C}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Anno 1404: Venice (HKLM-x32\...\Steam App 33350) (Version: - Blue Byte) Anno 2070 (HKLM-x32\...\Steam App 48240) (Version: - BlueByte) Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.02 - Ubisoft) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.) Audacity 2.0.6 (HKLM-x32\...\Audacity_is1) (Version: 2.0.6 - Audacity Team) BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC) Borderlands (HKLM-x32\...\Steam App 8980) (Version: - Gearbox Software) Camtasia Studio 8 (HKLM-x32\...\{1B57499B-1BEB-426A-A406-D9D004A1D2CE}) (Version: 8.5.0.1954 - TechSmith Corporation) CCleaner (HKLM\...\CCleaner) (Version: 5.06 - Piriform) Company of Heroes (New Steam Version) (HKLM-x32\...\Steam App 228200) (Version: - Relic) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0406 - Disc Soft Ltd) Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD) Dxtory version 2.0.122 (HKLM-x32\...\Dxtory2.0_is1) (Version: 2.0.122 - Dxtory Software) Empyrion - Galactic Survival (HKLM-x32\...\Steam App 383120) (Version: - Eleon Game Studios) ESET Smart Security (HKLM\...\{B06E39BF-C72B-446B-9462-1EE31789B3A2}) (Version: 8.0.319.1 - ESET, spol s r. o.) Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version: - SCS Software) Euro Truck Simulator 2 Multiplayer 0.1.6 R5 Alpha (HKLM-x32\...\{A227B892-C548-4490-9C5D-DB341F8194A6}_is1) (Version: 0.1.6 R5 Alpha - ETS2MP Team) Evil Genius (HKLM-x32\...\Steam App 3720) (Version: - Elixir Studios) Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Freemake Video Downloader (HKLM-x32\...\Freemake Video Downloader_is1) (Version: 3.7.1 - Ellora Assets Corporation) From The Depths (HKLM-x32\...\Steam App 268650) (Version: - Brilliant Skies Ltd.) FTL version 1.5.13 (HKLM-x32\...\{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1) (Version: 1.5.13 - Subset Games) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.130 - Google Inc.) Google Update Helper (x32 Version: 1.3.28.5 - Google Inc.) Hidden HIS iTurbo (HKLM-x32\...\HIS iTurbo) (Version: - ) Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle) Java SE Development Kit 7 Update 71 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170710}) (Version: 1.7.0.710 - Oracle) Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version: - ) Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.385 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.385 - LogMeIn, Inc.) Hidden Mass Effect (HKLM-x32\...\Steam App 17460) (Version: - BioWare) Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - 4A Games) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{59E4543A-D49D-4489-B445-473D763C79AF}) (Version: 2.0.672.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001B-0000-0000-0000000FF1CE}_WORD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Word 2007 (HKLM-x32\...\WORD) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang) MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com) Motorola Device Manager (HKLM-x32\...\{28DB8373-C1BB-444F-A427-A55585A12ED7}) (Version: 2.4.5 - Motorola Mobility) Motorola Device Software Update (x32 Version: 13.09.3001 - Motorola Mobility) Hidden Motorola Mobile Drivers Installation 6.3.0 (HKLM\...\{759E6A2F-1F01-45EF-A0C4-22F1B56CB975}) (Version: 6.3.0 - Motorola Mobility LLC) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.55.7 - Black Tree Gaming) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) ON_OFF Charge B12.1025.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) Origin (HKLM-x32\...\Origin) (Version: 9.5.20.5318 - Electronic Arts, Inc.) Overwolf (HKLM-x32\...\Overwolf) (Version: 0.87.58.0 - Overwolf Ltd.) PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Raptr (HKLM-x32\...\Raptr) (Version: - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7404 - Realtek Semiconductor Corp.) Robocraft (HKLM-x32\...\Steam App 301520) (Version: - Freejam) Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition) Space Engineers (HKLM-x32\...\Steam App 244850) (Version: - Keen Software House) Spotify (HKU\S-1-5-21-3288466570-3956607681-561774039-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Star Trek Online (HKLM-x32\...\Steam App 9900) (Version: - Cryptic Studios) Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: - Bioware/EA) Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Take On Mars (HKLM-x32\...\Steam App 244030) (Version: - Bohemia Interactive) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Terraria (HKLM-x32\...\Steam App 105600) (Version: - Re-Logic) The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version: - Edmund McMillen and Florian Himsl) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) Unity Web Player (HKU\S-1-5-21-3288466570-3956607681-561774039-1000\...\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-001B-0000-0000-0000000FF1CE}_WORD_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 7.1 - Ubisoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) War Thunder (HKLM-x32\...\Steam App 236390) (Version: - Gaijin Entertainment) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 5.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-3288466570-3956607681-561774039-1000_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Kevin\AppData\Local\Roblox\Versions\version-4993687f79834cd9\RobloxProxy64.dll Keine Datei ==================== Wiederherstellungspunkte ========================= 27-07-2015 11:32:24 Windows Update 07-08-2015 20:02:55 Installed LogMeIn Hamachi ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {1FCD10C2-0295-4407-A5E9-9355960A2CCA} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-10-31] () Task: {23B82265-AA3C-44C5-9DE3-406EBFD51EBC} - System32\Tasks\Motorola Device Manager Engine => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-10-31] () Task: {2DFD25D6-0714-4F32-B813-6AFB89473AF9} - System32\Tasks\wipCjjyi => C:\Users\Kevin\AppData\Roaming\wipCjjyi.exe <==== ACHTUNG Task: {5B45EB85-DA97-402C-9093-9137CE36CC57} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2015-07-19] (Overwolf LTD) Task: {5F321AB4-F558-4E53-86EB-884D2515D32B} - System32\Tasks\Motorola Device Manager Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-10-31] () Task: {6D2B53CA-9E13-42DD-AF85-8B49C057C028} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-10] (Google Inc.) Task: {974646AC-B52A-4439-AAB3-557DC36201E4} - System32\Tasks\{E492051C-8821-4428-9A78-24D37B95AE22} => pcalua.exe -a "F:\SteamLibrary\steamapps\common\Arma 2\BEsetup\setup_BattlEyeARMA2.exe" -d "F:\SteamLibrary\steamapps\common\Arma 2\BEsetup" Task: {BF1C3608-50AA-48BF-843F-CA28FBB58C1B} - System32\Tasks\{E15CBCC1-BD55-4A0C-A5C6-D3296B1A9E37} => pcalua.exe -a C:\Users\Kevin\AppData\Roaming\mystartsearch\UninstallManager.exe -c -ptid=cor Task: {E31A0E6E-6812-4378-8AF4-9DD7414960EF} - System32\Tasks\Opera scheduled Autoupdate 1437628130 => C:\Program Files (x86)\Opera\launcher.exe Task: {EE94ADB6-26AC-40E5-8AD3-A454F0226BD4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-10] (Google Inc.) Task: {F81ED7DA-3BCA-4713-963B-EFB49B4E47C8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd) Task: {FE4CBB70-BA14-4E38-A206-2C641C7638B1} - System32\Tasks\MNKXYDZYN1 => C:\ProgramData\EpsanDrive\EpsanDrive.exe <==== ACHTUNG (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\MNKXYDZYN1.job => C:\ProgramData\EpsanDrive\EpsanDrive.exe <==== ACHTUNG Task: C:\Windows\Tasks\wipCjjyi.job => C:\Users\Kevin\AppData\Roaming\wipCjjyi.exe <==== ACHTUNG ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2015-07-29 22:14 - 2015-07-20 13:35 - 00349184 _____ () C:\Windows\system32\Rofdhowal64.dll 2015-02-10 14:52 - 2015-07-01 01:10 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2015-07-28 22:45 - 2015-07-28 22:45 - 00102400 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2014-02-28 11:14 - 2015-08-08 10:48 - 00179176 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll 2014-08-04 15:43 - 2015-08-08 10:48 - 00103400 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2014-08-04 15:43 - 2015-08-08 10:48 - 00108008 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2014-08-04 15:46 - 2015-08-08 10:48 - 00312296 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2014-08-04 15:46 - 2015-08-08 10:48 - 00483816 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2014-06-05 15:48 - 2015-08-08 10:48 - 00318976 _____ () C:\Program Files\TeamSpeak 3 Client\ssleay32.dll 2014-06-05 15:48 - 2015-08-08 10:48 - 01718784 _____ () C:\Program Files\TeamSpeak 3 Client\LIBEAY32.dll 2015-01-24 19:18 - 2015-07-03 18:12 - 00778240 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2015-01-24 19:18 - 2015-07-03 18:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll 2015-01-24 19:18 - 2015-07-03 18:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2015-01-24 19:18 - 2015-07-03 18:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2015-01-24 19:18 - 2015-07-24 01:24 - 02410176 _____ () C:\Program Files (x86)\Steam\video.dll 2015-01-24 19:18 - 2014-12-01 23:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2015-01-24 19:18 - 2014-12-01 23:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2015-01-24 19:18 - 2014-12-01 23:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2015-01-24 19:18 - 2014-12-01 23:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2015-01-24 19:18 - 2014-12-01 23:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2015-01-24 19:18 - 2015-07-24 01:23 - 00703168 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2015-07-24 09:06 - 2015-07-07 22:41 - 00169984 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll 2015-01-24 19:18 - 2015-07-03 18:12 - 39553928 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2015-08-10 14:26 - 2015-07-31 08:19 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.130\libglesv2.dll 2015-08-10 14:26 - 2015-07-31 08:19 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.130\libegl.dll 2015-08-10 14:26 - 2015-07-31 08:19 - 16308040 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.130\PepperFlash\pepflashplayer.dll 2015-01-24 19:18 - 2015-07-25 03:53 - 00115968 _____ () C:\Program Files (x86)\Steam\winh264.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) IE trusted site: HKU\.DEFAULT\...\clonewarsadventures.com -> clonewarsadventures.com IE trusted site: HKU\.DEFAULT\...\freerealms.com -> freerealms.com IE trusted site: HKU\.DEFAULT\...\soe.com -> soe.com IE trusted site: HKU\.DEFAULT\...\sony.com -> sony.com ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-3288466570-3956607681-561774039-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) MSCONFIG\Services: Motorola Device Manager => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: EADM => "D:\Origin\Origin.exe" -AutoStart MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent MSCONFIG\startupreg: Spotify => "C:\Users\Kevin\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Kevin\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [{DFC5E2BE-D02C-4BBE-8285-F5368099C4E8}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{361465DD-EEC8-4169-A6FE-3204E91A3944}] => (Allow) D:\Steam\Steam.exe FirewallRules: [{781E89E8-9DC4-4F1B-B25F-65DCD264DEA9}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{3B397168-43CB-4A0D-9EC4-CE858E560AD7}] => (Allow) D:\Steam\bin\steamwebhelper.exe FirewallRules: [{EB4B8486-78C1-4702-95CF-79D102CB04A5}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{B7A8C7C5-E84C-409A-AFDF-FBFD443FADD5}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{D1A7DDC1-6D87-429B-BD79-3CA91C9797B4}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{BF2FA830-04E5-4C9C-B7A2-58195E2456D3}] => (Allow) D:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{73BA981E-F3A5-4CBE-B6E9-EAAEE5DFB42B}] => (Allow) D:\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe FirewallRules: [{1F2F787E-89C0-49CD-9FB9-8E347C5FDE25}] => (Allow) D:\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe FirewallRules: [TCP Query User{823172B2-492D-4972-8340-2BAE2D512553}D:\steam\steamapps\common\garrysmod\hl2.exe] => (Allow) D:\steam\steamapps\common\garrysmod\hl2.exe FirewallRules: [UDP Query User{7CAFDE48-6A39-451E-9DDB-674B2830227F}D:\steam\steamapps\common\garrysmod\hl2.exe] => (Allow) D:\steam\steamapps\common\garrysmod\hl2.exe FirewallRules: [{EDCBF0C0-72C3-43C1-B526-D16D3EF832EE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{8AEADF10-59BF-463F-A8A7-5C2C334F1198}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{56E6FF84-07BD-431F-A028-92373706D486}] => (Allow) F:\SteamLibrary\steamapps\common\Terraria\Terraria.exe FirewallRules: [{4D123860-A4CC-4F95-85F3-A273365003E8}] => (Allow) F:\SteamLibrary\steamapps\common\Terraria\Terraria.exe FirewallRules: [{7AAC1CF6-458F-4B59-B095-0E2DE954500A}] => (Allow) F:\SteamLibrary\steamapps\common\The Binding Of Isaac\Isaac.exe FirewallRules: [{BEF8957A-9CF2-4BA6-8637-299CFF910B2D}] => (Allow) F:\SteamLibrary\steamapps\common\The Binding Of Isaac\Isaac.exe FirewallRules: [{7D45C7F8-E0FD-4186-880E-AB8AFFDB2489}] => (Allow) F:\SteamLibrary\steamapps\common\Contagion\contagion.exe FirewallRules: [{CCE08523-0175-4E75-8532-2199EBF7F4A8}] => (Allow) F:\SteamLibrary\steamapps\common\Contagion\contagion.exe FirewallRules: [{F88D52B3-41EF-4674-BC7E-6607A7D1931F}] => (Allow) F:\SteamLibrary\steamapps\common\ConSim2015\ConSim2015.exe FirewallRules: [{605DEA77-EDAE-42D7-ADA8-B0439048409C}] => (Allow) F:\SteamLibrary\steamapps\common\ConSim2015\ConSim2015.exe FirewallRules: [{297E98D3-5CC0-439C-A35D-E0747D521A0D}] => (Allow) F:\SteamLibrary\steamapps\common\Contagion\contagionds.exe FirewallRules: [{D31879AF-CFAE-4043-98CA-7FC380E5C3C6}] => (Allow) F:\SteamLibrary\steamapps\common\Contagion\contagionds.exe FirewallRules: [{8CFF7AA7-6FED-47D7-89D8-5468BEC35819}] => (Allow) F:\SteamLibrary\steamapps\common\War Thunder\launcher.exe FirewallRules: [{817CAFAA-DD1E-4114-B556-FB53C4D4CEC8}] => (Allow) F:\SteamLibrary\steamapps\common\War Thunder\launcher.exe FirewallRules: [{06E7ACF5-FF54-416D-9F01-3EAFA1E820C9}] => (Allow) C:\Users\Kevin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{3ACD6F9D-39EF-4EE1-AF86-DF587225F31E}] => (Allow) C:\Users\Kevin\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{95F40468-527E-4C89-94AB-99D7E922AC58}] => (Allow) F:\SteamLibrary\steamapps\common\red faction armageddon\RedFactionArmageddon.exe FirewallRules: [{E8C93BD7-F15A-4C24-86D4-A9B23803B324}] => (Allow) F:\SteamLibrary\steamapps\common\red faction armageddon\RedFactionArmageddon.exe FirewallRules: [{9D87BB41-D3EE-4C27-A222-D67E99233DE7}] => (Allow) F:\SteamLibrary\steamapps\common\red faction armageddon\RedFactionArmageddon_DX11.exe FirewallRules: [{3893B896-30F2-4F6E-9D5A-A0935A60B049}] => (Allow) F:\SteamLibrary\steamapps\common\red faction armageddon\RedFactionArmageddon_DX11.exe FirewallRules: [TCP Query User{5A7B4F46-2DA1-4305-BEA5-247E3EDC3895}F:\steamlibrary\steamapps\common\war thunder\aces.exe] => (Allow) F:\steamlibrary\steamapps\common\war thunder\aces.exe FirewallRules: [UDP Query User{E210EC15-E335-4F24-B8B6-2CB80252F486}F:\steamlibrary\steamapps\common\war thunder\aces.exe] => (Allow) F:\steamlibrary\steamapps\common\war thunder\aces.exe FirewallRules: [TCP Query User{094D426A-83F9-4F17-A44E-34FF5F98CA52}F:\planetside 2\planetside2_x64.exe] => (Allow) F:\planetside 2\planetside2_x64.exe FirewallRules: [UDP Query User{41AC6745-4460-41C0-95A1-153CB5C6348E}F:\planetside 2\planetside2_x64.exe] => (Allow) F:\planetside 2\planetside2_x64.exe FirewallRules: [{36ECDD16-2E28-4D14-A97E-D55490011F53}] => (Allow) F:\SteamLibrary\steamapps\common\L.A.Noire\LANLauncher.exe FirewallRules: [{CDA26572-0DB9-4392-A88E-1C8FE5FEEE93}] => (Allow) F:\SteamLibrary\steamapps\common\L.A.Noire\LANLauncher.exe FirewallRules: [{D8484B18-26F2-4B44-9599-0AA02A57B8CB}] => (Allow) F:\SteamLibrary\steamapps\common\TurboDismount\TurboDismount.exe FirewallRules: [{8AD77116-5E00-4A35-8B4A-D348FE23FDFD}] => (Allow) F:\SteamLibrary\steamapps\common\TurboDismount\TurboDismount.exe FirewallRules: [{FF5178D0-F6D7-48CF-A07F-8D4C19D825DD}] => (Allow) F:\SteamLibrary\steamapps\common\From The Depths\From_The_Depths.exe FirewallRules: [{F0764758-2A28-4C6C-AD49-B968CD94434F}] => (Allow) F:\SteamLibrary\steamapps\common\From The Depths\From_The_Depths.exe FirewallRules: [{A08CE5AF-5460-4BBF-8A57-FEDA393B2B37}] => (Allow) F:\SteamLibrary\steamapps\common\Evil Genius\EvilGeniusLauncher.exe FirewallRules: [{F9F727C7-A3B8-4654-9B9C-83B694430506}] => (Allow) F:\SteamLibrary\steamapps\common\Evil Genius\EvilGeniusLauncher.exe FirewallRules: [{371D8E1B-6BC5-4336-9069-32E5EB22E879}] => (Allow) F:\SteamLibrary\steamapps\common\Take On Mars\TKOM_loader.exe FirewallRules: [{AFB24047-841D-42E9-90F3-7AE135CA9A28}] => (Allow) F:\SteamLibrary\steamapps\common\Take On Mars\TKOM_loader.exe FirewallRules: [{BDA64374-D497-4B9D-8B97-339C7E2107F5}] => (Allow) F:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{42D40A7F-0167-4231-A85E-2D5050740298}] => (Allow) F:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [TCP Query User{F525C9B2-C9A0-4351-B909-5A1167B0CEBE}F:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) F:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{AAE089E1-D563-4597-9C87-03F9A1EDE19D}F:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) F:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [{1F151495-B74B-4BD3-B917-F36144763147}] => (Allow) F:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{9B7882BB-4A97-4ABE-B33C-AE2DFED79986}] => (Allow) F:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{C0DE59C0-1E36-44D7-AA04-D418D374F2DA}] => (Allow) F:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{3AF1747B-BA3F-42EC-9400-EB9DBA620B85}] => (Allow) F:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{BB8DAD4E-1753-4A07-AC95-C76907EC0CB3}] => (Allow) F:\SteamLibrary\steamapps\common\Robocraft\Robocraft.exe FirewallRules: [{6E3E7A23-043C-43E4-B6FF-794400A47AA0}] => (Allow) F:\SteamLibrary\steamapps\common\Robocraft\Robocraft.exe FirewallRules: [TCP Query User{3D415108-9851-422F-A02D-25155126A93B}C:\program files\java\jdk1.7.0_71\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.7.0_71\jre\bin\javaw.exe FirewallRules: [UDP Query User{72863DF7-7B2F-4D5C-B7B2-FEBD4D7A3E91}C:\program files\java\jdk1.7.0_71\jre\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.7.0_71\jre\bin\javaw.exe FirewallRules: [{84C7EC6C-B4B6-4640-8ACA-152712E5CBD2}] => (Allow) F:\SteamLibrary\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{F485F667-3273-4280-B6B2-35A358610B38}] => (Allow) F:\SteamLibrary\steamapps\common\PAYDAY 2\payday2_win32_release.exe FirewallRules: [{CC83289C-5931-4FEB-A116-48322D1D65C5}] => (Allow) F:\SteamLibrary\steamapps\common\Borderlands\Binaries\Borderlands.exe FirewallRules: [{A3B3DBB0-F8A6-4FB4-A159-177F5EEB4D1B}] => (Allow) F:\SteamLibrary\steamapps\common\Borderlands\Binaries\Borderlands.exe FirewallRules: [{AD69C4AB-B81D-4287-8EE2-24A5FC01FA08}] => (Allow) F:\SteamLibrary\steamapps\common\Alan Wake\AlanWake.exe FirewallRules: [{5AE354ED-3D09-42F9-8FFA-4A7CC0B22083}] => (Allow) F:\SteamLibrary\steamapps\common\Alan Wake\AlanWake.exe FirewallRules: [{E98C3C58-3123-4928-B949-63BDCBD2F97F}] => (Allow) F:\SteamLibrary\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{B0CFE57D-C098-4199-A032-7CB674E42479}] => (Allow) F:\SteamLibrary\steamapps\common\Skyrim\SkyrimLauncher.exe FirewallRules: [{25E5973D-8449-46DC-A7E5-026F5B5A8B2C}] => (Allow) F:\SteamLibrary\steamapps\common\Star Trek Online\Star Trek Online.exe FirewallRules: [{2C2BE53B-354E-4216-BBFD-151E58A26751}] => (Allow) F:\SteamLibrary\steamapps\common\Star Trek Online\Star Trek Online.exe FirewallRules: [TCP Query User{0C943C93-D3DE-4D74-9C67-88AD3F5CE5C4}F:\steamlibrary\steamapps\common\star trek online\star trek online\live\gameclient.exe] => (Allow) F:\steamlibrary\steamapps\common\star trek online\star trek online\live\gameclient.exe FirewallRules: [UDP Query User{7F97A8C5-964E-4FB0-83E1-8E1DC2CF6C1C}F:\steamlibrary\steamapps\common\star trek online\star trek online\live\gameclient.exe] => (Allow) F:\steamlibrary\steamapps\common\star trek online\star trek online\live\gameclient.exe FirewallRules: [{A07C3C57-27BC-4ECC-8F62-DB84DC3EA092}] => (Allow) F:\SteamLibrary\steamapps\common\Metro 2033\metro2033.exe FirewallRules: [{256E0B61-3BFB-4830-8989-876152617B8D}] => (Allow) F:\SteamLibrary\steamapps\common\Metro 2033\metro2033.exe FirewallRules: [TCP Query User{E9562DA9-D801-4653-A8F7-2084DCB4DDD1}C:\program files\java\jdk1.7.0_71\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.7.0_71\bin\javaw.exe FirewallRules: [UDP Query User{AA4D70A7-9301-4172-BD0C-6EEE5B3ED2AD}C:\program files\java\jdk1.7.0_71\bin\javaw.exe] => (Allow) C:\program files\java\jdk1.7.0_71\bin\javaw.exe FirewallRules: [{60B6E427-6AC0-4573-AC85-A4FAA647AE4D}] => (Allow) F:\SteamLibrary\steamapps\common\Mass Effect\Binaries\MassEffect.exe FirewallRules: [{E71220F7-CEF1-4760-AD9C-C08E73580D6A}] => (Allow) F:\SteamLibrary\steamapps\common\Mass Effect\Binaries\MassEffect.exe FirewallRules: [{704D5FA5-33FF-4957-A90F-CAE203CD0BBE}] => (Allow) F:\Battle.net\Battle.net.exe FirewallRules: [{A7290F5E-4942-400B-9A27-5E8AA068C0A9}] => (Allow) F:\Battle.net\Battle.net.exe FirewallRules: [TCP Query User{869DF20D-814E-48A8-BBAE-1ABC6431A988}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [UDP Query User{BACF5F32-4A34-4326-8458-8F2C35C8DBDA}C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base34846\heroesofthestorm_x64.exe FirewallRules: [TCP Query User{B069FD51-AB96-4B03-8FBF-E86C809838C8}F:\dayzlauncher\dayzlauncher.exe] => (Allow) F:\dayzlauncher\dayzlauncher.exe FirewallRules: [UDP Query User{11E8F43F-4880-4D19-B9C9-1BCD6BDD1009}F:\dayzlauncher\dayzlauncher.exe] => (Allow) F:\dayzlauncher\dayzlauncher.exe FirewallRules: [{3F5E0755-7338-4391-96DC-36CFE00D34AB}] => (Allow) F:\SteamLibrary\steamapps\common\Space\spacegame\Binaries\Win64\spacegame-Win64-Shipping.exe FirewallRules: [{43C85B62-B134-4C0D-8234-7E34CB5F65A1}] => (Allow) F:\SteamLibrary\steamapps\common\Space\spacegame\Binaries\Win64\spacegame-Win64-Shipping.exe FirewallRules: [TCP Query User{47DF27E2-78C2-400D-9A86-781E6DDEE7B5}C:\users\kevin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kevin\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{AE3FC644-4225-4BF8-ABD3-4CB8FC0947A7}C:\users\kevin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kevin\appdata\roaming\spotify\spotify.exe FirewallRules: [{B918F195-6CCE-497B-B09C-F43433057E79}] => (Allow) F:\SteamLibrary\steamapps\common\Take On Mars\TKOM.exe FirewallRules: [{D34D2A79-3104-427C-973F-1C3233407AB0}] => (Allow) F:\SteamLibrary\steamapps\common\Take On Mars\TKOM.exe FirewallRules: [{D51C9367-177F-4812-94B5-326433B24E25}] => (Allow) F:\SteamLibrary\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{99AE0080-398D-44FF-A958-9F3F3823171F}] => (Allow) F:\SteamLibrary\steamapps\common\Saints Row IV\SaintsRowIV.exe FirewallRules: [{FE9243E3-A692-4C55-937C-F4B38F908E52}] => (Allow) F:\Die Sims 4\Game\Bin\TS4.exe FirewallRules: [{B3957249-E63F-41F3-9DDE-AD4CDAE9B34E}] => (Allow) F:\Die Sims 4\Game\Bin\TS4.exe FirewallRules: [{90B9BCE4-A740-4588-8F5A-B2115AC86EB5}] => (Allow) F:\SteamLibrary\steamapps\common\Take On Mars\TKOM_dev.exe FirewallRules: [{23F3B165-070C-4BD8-9306-66015CD63957}] => (Allow) F:\SteamLibrary\steamapps\common\Take On Mars\TKOM_dev.exe FirewallRules: [{314D1650-54BC-4D86-95CF-A9D129B137F6}] => (Allow) F:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{F9FFEA88-694A-4B59-BD9C-8ACC45C97BBF}] => (Allow) F:\SteamLibrary\steamapps\common\Left 4 Dead 2\left4dead2.exe FirewallRules: [{E3944955-0D1C-468A-BF0A-AB9951112C7E}] => (Allow) F:\SteamLibrary\steamapps\common\Company of Heroes Relaunch\RelicCOH.exe FirewallRules: [{5F19BA74-043D-4D56-878F-31128B44A920}] => (Allow) F:\SteamLibrary\steamapps\common\Company of Heroes Relaunch\RelicCOH.exe FirewallRules: [{2FCA6691-6A39-4724-A547-2A95F7275FD3}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{46839D7B-4242-4267-9C31-881F05FA3867}] => (Allow) LPort=2869 FirewallRules: [{C4A0DD34-5220-4A86-9451-BE0CA53811E5}] => (Allow) LPort=1900 FirewallRules: [{6CF0A715-CECB-41B8-8E88-07672D7B85B6}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{A5081CD9-9F0B-4193-8097-080CFCB92DC0}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{B7A87999-CB04-4D32-B715-6C02B8B69DB5}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{06972E9C-61EA-4D29-BF5D-7FE1E9CC8D24}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{9C433728-DE22-4F9A-87E6-00D15680E60A}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 1404\Addon.exe FirewallRules: [{FB211E3F-2B8A-469B-92F3-0D9051ED56AB}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 1404\Addon.exe FirewallRules: [{C1638799-775C-43C8-AEAC-2320253CBE11}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 1404\Anno4.exe FirewallRules: [{E423D05A-DA95-4598-BA0A-18A103245987}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 1404\Anno4.exe FirewallRules: [TCP Query User{D76A9D71-E0D2-43BB-A000-71A3DBBFE743}F:\steamlibrary\steamapps\common\anno 1404\tools\addonweb.exe] => (Allow) F:\steamlibrary\steamapps\common\anno 1404\tools\addonweb.exe FirewallRules: [UDP Query User{6C767906-4BC3-48BB-A9FA-7A9112A04B1A}F:\steamlibrary\steamapps\common\anno 1404\tools\addonweb.exe] => (Allow) F:\steamlibrary\steamapps\common\anno 1404\tools\addonweb.exe FirewallRules: [{537BC8FF-E179-4E78-83FB-A9A1A416F459}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{3CA8C9A6-D98B-4463-9F95-D23E31AA5556}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{3360D097-9D11-43FC-9D57-DD2A08000E14}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{BEA56F35-61A6-4E82-802E-F37BBB2FCC9B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{04A3D3BC-29EA-437E-AC24-57DA07AE735E}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{CB45AE37-E092-4971-B648-14F90FBC3D87}] => (Allow) F:\SteamLibrary\steamapps\common\Anno 2070\Anno5.exe FirewallRules: [{1314059F-1A20-4E1B-91F1-C25CF2225AFA}] => (Allow) F:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [{65AFCBD6-540A-471E-9476-F63B73AF5E51}] => (Allow) F:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe FirewallRules: [TCP Query User{AFD78488-2D2D-4278-9C7E-3B0507654139}C:\users\kevin\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\kevin\appdata\local\mycomgames\mycomgames.exe FirewallRules: [UDP Query User{C92F81B5-42C4-412C-8054-EB447207B3F7}C:\users\kevin\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\kevin\appdata\local\mycomgames\mycomgames.exe FirewallRules: [{00516EBF-0624-4C16-B473-2B57B43B5B15}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe FirewallRules: [{1FBC4828-0B44-4D33-A0D3-F6DD129AE004}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe FirewallRules: [{C8DC7273-612F-40C0-8661-80C05C893F41}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe FirewallRules: [{FD78E697-3FB2-4613-9C5B-3E1F51CE57C7}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe FirewallRules: [{2EE10B65-583D-4290-ADD2-4093F863D653}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe FirewallRules: [{16DC823A-6722-4CF9-9751-0FB3C4E56627}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe FirewallRules: [{BE83D49B-0232-4848-8940-1F90A8182007}] => (Allow) C:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{519651DF-7026-4168-9678-F9460B8DFFB5}] => (Allow) C:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{DA0BB515-FF8D-4BF2-BE42-8513BDA57B79}] => (Allow) C:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{758898FF-8F1E-4975-A480-8CACD467FC75}] => (Allow) C:\Star Wars-The Old Republic\launcher.exe FirewallRules: [{5AC8E0F2-8369-4D53-A404-40F6649FE5EA}] => (Allow) C:\Program Files (x86)\Max Driver Updater\maxdu.exe FirewallRules: [{7B0CBA25-86E5-4105-8778-6CC4A878D10D}] => (Allow) LPort=8317 FirewallRules: [{5587E4C5-9379-42E4-9091-5ACAAD788A1E}] => (Allow) F:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{E8FC8650-A33B-4161-8500-E111A6B4A6E0}] => (Allow) F:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe FirewallRules: [{8AC49C01-00CF-4C91-9142-5A9FFAE368FA}] => (Allow) F:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe FirewallRules: [{74736627-6B91-4440-BC6F-E1767831F045}] => (Allow) F:\SteamLibrary\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe FirewallRules: [{6294F8AB-D2F9-411A-B172-956BD94193B3}] => (Allow) F:\SteamLibrary\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{7B00D82C-B42B-482D-B925-52CC7128C85A}] => (Allow) F:\SteamLibrary\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe FirewallRules: [{B03FEDEA-767A-4665-9E74-CA6E677B3FE3}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{EB6C9925-1246-4337-B7F8-BAD5214B28A3}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{BA0F496A-EBB2-42CB-81C9-C0B39DAF369B}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{8433FCB2-B5E8-48D3-A1C7-2B0E3F5681DD}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{58A6F4A0-1CB3-4B09-9B80-A8ED5932C501}] => (Allow) F:\SteamLibrary\steamapps\common\Empyrion - Galactic Survival\Empyrion.exe FirewallRules: [{82F184BD-B67C-4B3D-9003-ED5266ABB359}] => (Allow) F:\SteamLibrary\steamapps\common\Empyrion - Galactic Survival\Empyrion.exe FirewallRules: [{11F1F389-D63E-4C23-ACEB-36FF18840CB5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= Name: AODDriver4.2 Description: AODDriver4.2 Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: AODDriver4.2 Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: cherimoya Description: cherimoya Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: cherimoya Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (08/11/2015 02:37:45 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/10/2015 05:04:19 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm KSP.exe, Version 4.6.4.63619 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 908 Startzeit: 01d0d37d8b95c29f Endzeit: 23 Anwendungspfad: C:\Users\Kevin\Desktop\Downloads\Kerbal.Space.Program.v1.0.4.861\Kerbal.Space.Program.v1.0.4.861\KSP.exe Berichts-ID: 10581efe-3f71-11e5-9c8b-74d4357e2d8d Error: (08/10/2015 04:58:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TitanFall.exe, Version: 1.0.0.0, Zeitstempel: 0x5420d832 Name des fehlerhaften Moduls: dxgi.dll, Version: 6.2.9200.16492, Zeitstempel: 0x50f30fbd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000022f56 ID des fehlerhaften Prozesses: 0x1c74 Startzeit der fehlerhaften Anwendung: 0xTitanFall.exe0 Pfad der fehlerhaften Anwendung: TitanFall.exe1 Pfad des fehlerhaften Moduls: TitanFall.exe2 Berichtskennung: TitanFall.exe3 Error: (08/10/2015 03:32:20 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: TitanFall.exe, Version: 1.0.0.0, Zeitstempel: 0x5420d832 Name des fehlerhaften Moduls: dxgi.dll, Version: 6.2.9200.16492, Zeitstempel: 0x50f30fbd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000022f56 ID des fehlerhaften Prozesses: 0x1cd4 Startzeit der fehlerhaften Anwendung: 0xTitanFall.exe0 Pfad der fehlerhaften Anwendung: TitanFall.exe1 Pfad des fehlerhaften Moduls: TitanFall.exe2 Berichtskennung: TitanFall.exe3 Error: (08/08/2015 12:18:34 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Empyrion.exe, Version 5.1.2.13792 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: d24 Startzeit: 01d0d1b8c2f6c420 Endzeit: 216 Anwendungspfad: F:\SteamLibrary\steamapps\common\Empyrion - Galactic Survival\Empyrion.exe Berichts-ID: cc542195-3db6-11e5-9c8b-74d4357e2d8d Error: (08/08/2015 10:37:58 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/07/2015 06:45:44 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Steam.exe, Version 2.89.12.34 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: de4 Startzeit: 01d0d130213c70c9 Endzeit: 26 Anwendungspfad: C:\Program Files (x86)\Steam\Steam.exe Berichts-ID: b1eb09fa-3d23-11e5-a9e6-74d4357e2d8d Error: (08/07/2015 06:08:38 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/02/2015 05:19:57 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/02/2015 11:24:01 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Systemfehler: ============= Error: (08/11/2015 02:36:27 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cherimoya Error: (08/11/2015 02:36:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "FreemakeVideoCapture" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (08/11/2015 02:36:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error: (08/11/2015 05:20:43 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {60A90A2F-858D-42AF-8929-82BE9D99E8A1} Error: (08/11/2015 02:26:45 AM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "LISA-IV", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{68AABF16-5806-4109-A971-989804BE9911}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (08/10/2015 04:58:11 AM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "WORKGROUP :1d" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.178.60 registriert werden. Der Computer mit IP-Adresse 192.168.178.23 hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (08/08/2015 10:37:26 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cherimoya Error: (08/08/2015 10:37:12 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "FreemakeVideoCapture" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (08/08/2015 10:37:11 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AODDriver4.2" wurde aufgrund folgenden Fehlers nicht gestartet: %%3 Error: (08/08/2015 02:19:47 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {60A90A2F-858D-42AF-8929-82BE9D99E8A1} Microsoft Office: ========================= CodeIntegrity: =================================== Date: 2014-12-20 18:37:55.891 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-20 18:37:55.833 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-20 18:37:17.471 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-20 18:37:17.410 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-20 16:12:42.551 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-20 16:12:42.492 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-20 15:08:59.114 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-20 15:08:59.055 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-16 16:12:30.891 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-12-16 16:12:30.839 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\motusbdevice.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Speicherinformationen =========================== Processor: AMD Athlon(tm) II X2 280 Processor Prozentuale Nutzung des RAM: 49% Installierter physikalischer RAM: 5117.55 MB Verfügbarer physikalischer RAM: 2568.33 MB Summe virtueller Speicher: 10233.32 MB Verfügbarer virtueller Speicher: 7185.84 MB ==================== Laufwerke ================================ Drive c: () (Fixed) (Total:286.87 GB) (Free:71.73 GB) NTFS ==>[Laufwerk mit Startkomponenten (eingeholt von BCD)] Drive f: () (Fixed) (Total:232.66 GB) (Free:28.89 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 3E91BAD7) Partition 1: (Not Active) - (Size=11.2 GB) - (Type=27) Partition 2: (Active) - (Size=286.9 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 232.9 GB) (Disk ID: 0337E758) Partition: GPT. ==================== Ende von log ============================ |
12.08.2015, 08:58 | #4 |
/// the machine /// TB-Ausbilder | Es öffnet sich ständig einfach Werbung hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.08.2015, 16:28 | #5 |
| Es öffnet sich ständig einfach WerbungCode:
ATTFilter ComboFix 15-08-08.01 - Kevin 12.08.2015 16:23:30.1.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.5118.2995 [GMT 2:00] ausgeführt von:: c:\users\Kevin\Desktop\ComboFix.exe AV: ESET Smart Security 8.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289} FW: ESET Personal Firewall *Disabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} SP: ESET Smart Security 8.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END c:\windows\msdownld.tmp c:\windows\SysWow64\drivers\10CF_FUJITSU_FTS_GA-78LMT-S2P_RC_Gigabyte Technology Co., Ltd._GA-78LMT-S2P_Award Modular BIOS v6.00PG_GBT - 42302e31_F3_AMD 760G (Microsoft Corporation WDDM 1.1) .MRK c:\windows\SysWow64\Packet.dll c:\windows\SysWow64\pthreadVC.dll c:\windows\SysWow64\wpcap.dll . c:\windows\SysWow64\dnsapi.dll . . . ist infiziert!! . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF -------\Service_npf . . ((((((((((((((((((((((( Dateien erstellt von 2015-07-12 bis 2015-08-12 )))))))))))))))))))))))))))))) . . 2015-08-12 14:50 . 2015-08-12 14:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-08-11 13:14 . 2015-08-11 13:17 -------- d-----w- C:\FRST 2015-08-10 12:24 . 2015-08-10 12:25 -------- d-----w- c:\program files (x86)\Google 2015-08-10 12:24 . 2015-08-10 12:26 -------- d-----w- c:\users\Kevin\AppData\Local\Google 2015-08-07 18:04 . 2015-08-07 18:04 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi 2015-08-07 17:10 . 2015-08-07 17:10 -------- d-----w- c:\programdata\ATI 2015-08-06 12:45 . 2015-08-06 12:45 33856 ---ha-w- c:\windows\system32\drivers\hamachi.sys 2015-07-31 07:47 . 2015-07-31 07:47 -------- d-----w- c:\users\Kevin\AppData\Local\CEF 2015-07-30 13:00 . 2015-08-10 14:58 -------- d-----w- c:\users\Kevin\AppData\Local\CrashDumps 2015-07-29 22:24 . 2015-07-29 22:24 -------- d-----w- c:\users\Kevin\AppData\Local\ESET 2015-07-29 22:22 . 2015-07-29 22:22 -------- d-----w- c:\program files\ESET 2015-07-29 20:14 . 2015-07-20 11:35 349184 ----a-w- c:\windows\system32\Rofdhowal64.dll 2015-07-29 20:14 . 2015-07-20 11:35 279040 ----a-w- c:\windows\SysWow64\Rofdhowal.dll 2015-07-29 20:13 . 2015-07-29 20:13 -------- d-----w- c:\windows\system32\simc 2015-07-29 20:11 . 2015-07-29 20:11 45 ----a-w- C:\user.js 2015-07-29 20:11 . 2015-07-29 20:11 -------- d-----w- c:\users\Kevin\AppData\Local\Programs 2015-07-29 08:34 . 2015-07-29 08:35 -------- d-----w- c:\users\Kevin\AppData\Roaming\SpaceEngineers 2015-07-29 03:44 . 2015-07-29 03:44 107784 ----a-w- c:\windows\system32\amdave64.dll 2015-07-29 03:43 . 2015-07-29 03:43 141792 ----a-w- c:\windows\system32\amdhcp64.dll 2015-07-29 03:43 . 2015-07-29 03:43 128384 ----a-w- c:\windows\SysWow64\amdhcp32.dll 2015-07-29 03:43 . 2015-07-29 03:43 78432 ----a-w- c:\windows\system32\atimpc64.dll 2015-07-29 03:43 . 2015-07-29 03:43 78432 ----a-w- c:\windows\system32\amdpcom64.dll 2015-07-29 03:42 . 2015-07-29 03:42 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll 2015-07-29 03:42 . 2015-07-29 03:42 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll 2015-07-29 03:42 . 2015-07-29 03:42 120144 ----a-w- c:\windows\system32\atiu9p64.dll 2015-07-29 03:42 . 2015-07-29 03:42 102616 ----a-w- c:\windows\SysWow64\atiu9pag.dll 2015-07-29 03:40 . 2015-07-29 03:40 7408936 ----a-w- c:\windows\SysWow64\atiumdag.dll 2015-07-29 03:39 . 2015-07-29 03:39 8893160 ----a-w- c:\windows\system32\atiumd6a.dll 2015-07-29 03:39 . 2015-07-29 03:39 8779872 ----a-w- c:\windows\system32\atiumd64.dll 2015-07-29 03:26 . 2015-07-29 03:26 297672 ----a-w- c:\windows\system32\drivers\amdacpksd.sys 2015-07-29 03:15 . 2015-07-29 03:15 21622784 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2015-07-29 03:09 . 2015-07-29 03:09 235008 ----a-w- c:\windows\system32\clinfo.exe 2015-07-29 03:09 . 2015-07-29 03:09 47785472 ----a-w- c:\windows\system32\amdocl64.dll 2015-07-29 03:07 . 2015-07-29 03:07 65024 ----a-w- c:\windows\system32\OpenCL.dll 2015-07-29 03:07 . 2015-07-29 03:07 59392 ----a-w- c:\windows\SysWow64\OpenCL.dll 2015-07-29 03:06 . 2015-07-29 03:06 27535872 ----a-w- c:\windows\system32\amdocl12cl64.dll 2015-07-29 02:41 . 2015-07-29 02:41 127488 ----a-w- c:\windows\system32\mantle64.dll 2015-07-29 02:41 . 2015-07-29 02:41 113664 ----a-w- c:\windows\SysWow64\mantle32.dll 2015-07-29 02:41 . 2015-07-29 02:41 6477312 ----a-w- c:\windows\system32\amdmantle64.dll 2015-07-29 02:36 . 2015-07-29 02:36 5068288 ----a-w- c:\windows\SysWow64\amdmantle32.dll 2015-07-29 02:34 . 2015-07-29 02:34 50688 ----a-w- c:\windows\system32\amdmmcl6.dll 2015-07-29 02:34 . 2015-07-29 02:34 39424 ----a-w- c:\windows\SysWow64\amdmmcl.dll 2015-07-29 02:34 . 2015-07-29 02:34 30752256 ----a-w- c:\windows\system32\atio6axx.dll 2015-07-29 02:33 . 2015-07-29 02:33 93696 ----a-w- c:\windows\system32\mantleaxl64.dll 2015-07-29 02:33 . 2015-07-29 02:33 86528 ----a-w- c:\windows\SysWow64\mantleaxl32.dll 2015-07-29 02:30 . 2015-07-29 02:30 367104 ----a-w- c:\windows\system32\atiapfxx.exe 2015-07-29 02:30 . 2015-07-29 02:30 62464 ----a-w- c:\windows\system32\aticalrt64.dll 2015-07-29 02:30 . 2015-07-29 02:30 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll 2015-07-29 02:30 . 2015-07-29 02:30 55808 ----a-w- c:\windows\system32\aticalcl64.dll 2015-07-29 02:30 . 2015-07-29 02:30 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll 2015-07-29 02:30 . 2015-07-29 02:30 15716864 ----a-w- c:\windows\system32\aticaldd64.dll 2015-07-29 02:29 . 2015-07-29 02:29 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll 2015-07-29 02:28 . 2015-07-29 02:28 25299968 ----a-w- c:\windows\SysWow64\atioglxx.dll 2015-07-29 02:26 . 2015-07-29 02:26 442368 ----a-w- c:\windows\system32\atidemgy.dll 2015-07-29 02:26 . 2015-07-29 02:26 160256 ----a-w- c:\windows\system32\atieah64.exe 2015-07-29 02:26 . 2015-07-29 02:26 204800 ----a-w- c:\windows\system32\amdgfxinfo64.dll 2015-07-29 02:26 . 2015-07-29 02:26 143872 ----a-w- c:\windows\SysWow64\atieah32.exe 2015-07-29 02:26 . 2015-07-29 02:26 29696 ----a-w- c:\windows\system32\atimuixx.dll 2015-07-29 02:26 . 2015-07-29 02:26 189952 ----a-w- c:\windows\SysWow64\amdgfxinfo32.dll 2015-07-29 02:26 . 2015-07-29 02:26 672768 ----a-w- c:\windows\system32\atieclxx.exe 2015-07-29 02:25 . 2015-07-29 02:25 246784 ----a-w- c:\windows\system32\atiesrxx.exe 2015-07-29 02:25 . 2015-07-29 02:25 190976 ----a-w- c:\windows\system32\atitmm64.dll 2015-07-29 02:24 . 2015-07-29 02:24 89088 ----a-w- c:\windows\system32\atisamu64.dll 2015-07-29 02:24 . 2015-07-29 02:24 80896 ----a-w- c:\windows\SysWow64\atisamu32.dll 2015-07-29 02:23 . 2015-07-29 02:23 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2015-07-29 02:22 . 2015-07-29 02:22 1247744 ----a-w- c:\windows\system32\atiadlxx.dll 2015-07-29 02:22 . 2015-07-29 02:22 926720 ----a-w- c:\windows\SysWow64\atiadlxx.dll 2015-07-29 02:22 . 2015-07-29 02:22 75264 ----a-w- c:\windows\system32\atig6pxx.dll 2015-07-29 02:22 . 2015-07-29 02:22 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll 2015-07-29 02:22 . 2015-07-29 02:22 69632 ----a-w- c:\windows\system32\atiglpxx.dll 2015-07-29 02:22 . 2015-07-29 02:22 156672 ----a-w- c:\windows\system32\atig6txx.dll 2015-07-29 02:22 . 2015-07-29 02:22 665088 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2015-07-29 02:19 . 2015-07-29 02:19 102912 ----a-w- c:\windows\system32\hsa-thunk64.dll 2015-07-29 02:19 . 2015-07-29 02:19 102400 ----a-w- c:\windows\SysWow64\hsa-thunk.dll 2015-07-27 09:21 . 2015-07-29 09:33 -------- d-----w- c:\programdata\Frowaoprar 2015-07-24 05:39 . 2015-07-24 05:39 -------- d-----w- c:\programdata\6b49f27b0000087a 2015-07-24 05:32 . 2015-07-29 22:29 -------- d-----w- c:\programdata\{df97f9c9-a2ee-1ae3-df97-7f9c9a2ee726} 2015-07-23 06:45 . 2015-07-23 06:45 -------- d-----w- c:\users\Kevin\AppData\Roaming\TechSmith 2015-07-23 06:44 . 2015-07-23 06:44 -------- d-----w- c:\users\Kevin\AppData\Local\TechSmith 2015-07-23 06:43 . 2015-07-23 06:43 -------- d-----w- c:\programdata\regid.1995-08.com.techsmith 2015-07-23 06:43 . 2015-07-23 06:43 -------- d-----w- c:\program files (x86)\QuickTime 2015-07-23 06:42 . 2015-07-23 06:42 -------- d-----w- c:\program files (x86)\Common Files\TechSmith Shared 2015-07-23 06:42 . 2015-07-23 06:42 -------- d-----w- c:\program files (x86)\TechSmith 2015-07-23 05:09 . 2015-07-22 15:14 48784 ----a-w- c:\windows\system32\drivers\{04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64.sys 2015-07-23 05:08 . 2015-07-23 05:08 -------- d-----w- c:\users\Kevin\AppData\Local\globalUpdate 2015-07-23 05:06 . 2015-08-10 15:02 -------- d-----w- c:\programdata\Service1198 2015-07-23 05:06 . 2015-07-23 05:06 -------- d-----w- c:\programdata\7c0535b143fc4671b6ebd202fbffe066 2015-07-23 03:46 . 2015-07-15 03:19 41984 ----a-w- c:\windows\system32\lpk.dll 2015-07-23 03:46 . 2015-07-15 03:19 14336 ----a-w- c:\windows\system32\dciman32.dll 2015-07-23 03:46 . 2015-07-15 03:19 46080 ----a-w- c:\windows\system32\atmlib.dll 2015-07-23 03:46 . 2015-07-15 02:55 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2015-07-23 03:46 . 2015-07-15 01:59 372224 ----a-w- c:\windows\system32\atmfd.dll 2015-07-23 03:46 . 2015-07-15 01:52 299008 ----a-w- c:\windows\SysWow64\atmfd.dll 2015-07-23 03:46 . 2015-07-15 03:19 100864 ----a-w- c:\windows\system32\fontsub.dll 2015-07-23 03:46 . 2015-07-15 02:55 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2015-07-23 03:46 . 2015-07-15 02:55 10240 ----a-w- c:\windows\SysWow64\dciman32.dll 2015-07-23 03:46 . 2015-07-15 02:54 25600 ----a-w- c:\windows\SysWow64\lpk.dll 2015-07-18 16:18 . 2015-07-18 16:18 -------- d-----w- c:\users\Kevin\AppData\Roaming\Unity 2015-07-18 16:11 . 2015-07-26 22:12 -------- d-----w- c:\program files (x86)\Overwolf 2015-07-18 16:11 . 2015-07-26 22:12 -------- d-----w- c:\program files (x86)\Common Files\Overwolf 2015-07-18 16:11 . 2015-07-18 16:14 -------- d-----w- c:\programdata\Overwolf 2015-07-18 16:06 . 2015-07-27 09:22 -------- d-----w- c:\users\Kevin\AppData\Local\Overwolf 2015-07-18 01:45 . 2015-06-17 17:47 404992 ----a-w- c:\windows\system32\gdi32.dll 2015-07-18 01:44 . 2015-07-01 20:49 1216512 ----a-w- c:\windows\system32\rpcrt4.dll 2015-07-16 20:11 . 2015-07-16 20:11 -------- d-----w- c:\users\Kevin\AppData\Local\SWTOR 2015-07-15 20:35 . 2015-07-15 20:35 -------- d-----w- c:\users\Kevin\AppData\Local\Unity 2015-07-15 19:31 . 2015-07-29 08:51 -------- d-----w- C:\Star Wars-The Old Republic 2015-07-15 19:31 . 2015-07-15 19:31 -------- d-----w- c:\program files (x86)\Common Files\BioWare 2015-07-15 10:20 . 2015-07-15 10:20 96256 ----a-w- c:\windows\system32\drivers\AtihdW76.sys 2015-07-15 10:20 . 2015-07-15 10:20 103424 ----a-w- c:\windows\system32\DelayAPO.dll 2015-07-14 16:33 . 2015-07-14 16:33 -------- d-----w- c:\programdata\Ubisoft 2015-07-14 16:15 . 2015-07-14 16:15 -------- d-----w- c:\users\Kevin\AppData\Roaming\InstallShield 2015-07-14 13:29 . 2015-07-14 13:29 72400 ----a-w- c:\windows\system32\drivers\epfwwfp.sys 2015-07-14 13:29 . 2015-07-14 13:29 53360 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys 2015-07-14 13:29 . 2015-07-14 13:29 255240 ----a-w- c:\windows\system32\drivers\eamonm.sys 2015-07-14 13:29 . 2015-07-14 13:29 251632 ----a-w- c:\windows\system32\drivers\edevmon.sys 2015-07-14 13:29 . 2015-07-14 13:29 231520 ----a-w- c:\windows\system32\drivers\epfw.sys 2015-07-14 13:29 . 2015-07-14 13:29 178520 ----a-w- c:\windows\system32\drivers\ehdrv.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-08-12 14:53 . 2015-02-05 11:59 65536 ----a-w- c:\windows\system32\spu_storage.bin 2015-07-29 20:14 . 2014-11-12 15:18 357888 ----a-w- c:\windows\system32\dnsapi.dll 2015-07-29 03:44 . 2014-11-21 02:09 100568 ----a-w- c:\windows\SysWow64\amdave32.dll 2015-07-29 03:42 . 2014-11-21 02:44 152056 ----a-w- c:\windows\system32\atiuxp64.dll 2015-07-29 03:42 . 2015-06-23 02:08 133016 ----a-w- c:\windows\SysWow64\atiuxpag.dll 2015-07-29 03:41 . 2014-11-21 02:44 1445224 ----a-w- c:\windows\system32\aticfx64.dll 2015-07-29 03:41 . 2014-04-18 02:42 1193904 ----a-w- c:\windows\SysWow64\aticfx32.dll 2015-07-29 03:41 . 2014-11-21 02:44 11948704 ----a-w- c:\windows\system32\atidxx64.dll 2015-07-29 03:40 . 2015-06-23 02:08 10094152 ----a-w- c:\windows\SysWow64\atidxx32.dll 2015-07-29 03:40 . 2014-11-21 02:43 7929616 ----a-w- c:\windows\SysWow64\atiumdva.dll 2015-07-29 03:08 . 2014-11-21 02:32 39714816 ----a-w- c:\windows\SysWow64\amdocl.dll 2015-07-29 03:05 . 2015-06-23 01:55 22318592 ----a-w- c:\windows\SysWow64\amdocl12cl.dll 2015-07-29 02:22 . 2014-11-21 02:09 926720 ----a-w- c:\windows\SysWow64\atiadlxy.dll 2015-07-29 02:22 . 2014-11-21 02:08 141824 ----a-w- c:\windows\SysWow64\atigktxx.dll 2015-07-29 02:17 . 2015-06-23 01:21 865792 ----a-w- c:\windows\system32\coinst_15.20.dll 2015-07-09 17:59 . 2015-07-11 03:57 17856 ----a-w- c:\windows\system32\CompatTelRunner.exe 2015-07-09 17:58 . 2015-07-11 03:57 726528 ----a-w- c:\windows\system32\generaltel.dll 2015-07-09 17:58 . 2015-07-11 03:57 765440 ----a-w- c:\windows\system32\invagent.dll 2015-07-09 17:58 . 2015-07-11 03:57 433664 ----a-w- c:\windows\system32\devinv.dll 2015-07-09 17:58 . 2015-07-11 03:57 1085440 ----a-w- c:\windows\system32\appraiser.dll 2015-07-09 17:58 . 2015-07-11 03:57 67584 ----a-w- c:\windows\system32\acmigration.dll 2015-07-09 17:58 . 2015-07-11 03:57 227328 ----a-w- c:\windows\system32\aepdu.dll 2015-07-09 17:50 . 2015-07-11 03:57 1145856 ----a-w- c:\windows\system32\aeinv.dll 2015-07-05 10:08 . 2010-11-21 03:27 300704 ------w- c:\windows\system32\MpSigStub.exe 2015-07-03 06:43 . 2014-11-20 01:14 130333168 ----a-w- c:\windows\system32\MRT.exe 2015-06-30 23:10 . 2015-02-10 12:52 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2015-06-30 23:10 . 2015-02-10 12:52 281872 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2015-06-30 23:10 . 2015-02-10 12:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe 2015-06-24 06:57 . 2012-07-17 12:37 23776 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2015-06-22 19:20 . 2015-06-22 19:20 363008 ----a-w- c:\windows\system32\amdacpusl.dll 2015-06-22 19:20 . 2015-06-22 19:20 247296 ----a-w- c:\windows\SysWow64\amdacpusl.dll 2015-06-16 23:01 . 2015-06-16 23:01 1202856 ----a-w- c:\windows\SysWow64\FM20.DLL 2015-05-25 18:24 . 2015-06-11 10:01 5569984 ----a-w- c:\windows\system32\ntoskrnl.exe 2015-05-25 18:21 . 2015-06-11 10:01 1728960 ----a-w- c:\windows\system32\ntdll.dll 2015-05-25 18:19 . 2015-06-11 10:01 243712 ----a-w- c:\windows\system32\wow64.dll 2015-05-25 18:19 . 2015-06-11 10:01 362496 ----a-w- c:\windows\system32\wow64win.dll 2015-05-25 18:19 . 2015-06-11 10:01 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2015-05-25 18:19 . 2015-06-11 10:01 215040 ----a-w- c:\windows\system32\winsrv.dll 2015-05-25 18:19 . 2015-06-11 10:01 1255424 ----a-w- c:\windows\system32\diagtrack.dll 2015-05-25 18:19 . 2015-06-11 10:01 879104 ----a-w- c:\windows\system32\tdh.dll 2015-05-25 18:19 . 2015-06-11 10:01 503808 ----a-w- c:\windows\system32\srcore.dll 2015-05-25 18:19 . 2015-06-11 10:01 113664 ----a-w- c:\windows\system32\sechost.dll 2015-05-25 18:19 . 2015-06-11 10:01 50176 ----a-w- c:\windows\system32\srclient.dll 2015-05-25 18:19 . 2015-06-11 10:01 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2015-05-25 18:19 . 2015-06-11 10:01 424960 ----a-w- c:\windows\system32\KernelBase.dll 2015-05-25 18:19 . 2015-06-11 10:01 1162752 ----a-w- c:\windows\system32\kernel32.dll 2015-05-25 18:18 . 2015-06-11 10:01 43520 ----a-w- c:\windows\system32\csrsrv.dll 2015-05-25 18:18 . 2015-06-11 10:01 879104 ----a-w- c:\windows\system32\advapi32.dll 2015-05-25 18:18 . 2015-06-11 10:01 404992 ----a-w- c:\windows\system32\tracerpt.exe 2015-05-25 18:18 . 2015-06-11 10:01 47104 ----a-w- c:\windows\system32\typeperf.exe 2015-05-25 18:18 . 2015-06-11 10:01 112640 ----a-w- c:\windows\system32\smss.exe 2015-05-25 18:18 . 2015-06-11 10:01 296960 ----a-w- c:\windows\system32\rstrui.exe 2015-05-25 18:18 . 2015-06-11 10:01 43008 ----a-w- c:\windows\system32\relog.exe 2015-05-25 18:18 . 2015-06-11 10:01 104448 ----a-w- c:\windows\system32\logman.exe 2015-05-25 18:18 . 2015-06-11 10:01 19456 ----a-w- c:\windows\system32\diskperf.exe 2015-05-25 18:18 . 2015-06-11 10:01 338432 ----a-w- c:\windows\system32\conhost.exe 2015-05-25 18:11 . 2015-06-11 10:01 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 6656 ----a-w- c:\windows\system32\apisetschema.dll 2015-05-25 18:11 . 2015-06-11 10:01 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-05-25 18:11 . 2015-06-11 10:01 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-05-25 18:07 . 2015-06-11 10:01 3989440 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2015-05-25 18:07 . 2015-06-11 10:01 3934144 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2015-05-25 18:04 . 2015-06-11 10:01 1310744 ----a-w- c:\windows\SysWow64\ntdll.dll 2015-05-25 18:01 . 2015-06-11 10:01 635392 ----a-w- c:\windows\SysWow64\tdh.dll 2015-05-25 18:01 . 2015-06-11 10:01 43008 ----a-w- c:\windows\SysWow64\srclient.dll 2015-05-25 18:01 . 2015-06-11 10:01 92160 ----a-w- c:\windows\SysWow64\sechost.dll 2015-05-25 18:01 . 2015-06-11 10:01 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2015-05-25 18:01 . 2015-06-11 10:01 641536 ----a-w- c:\windows\SysWow64\advapi32.dll 2015-05-25 18:01 . 2015-06-11 10:01 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2015-05-25 18:00 . 2015-06-11 10:01 40448 ----a-w- c:\windows\SysWow64\typeperf.exe 2015-05-25 18:00 . 2015-06-11 10:01 364544 ----a-w- c:\windows\SysWow64\tracerpt.exe 2015-05-25 18:00 . 2015-06-11 10:01 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2015-05-25 18:00 . 2015-06-11 10:01 37888 ----a-w- c:\windows\SysWow64\relog.exe 2015-05-25 18:00 . 2015-06-11 10:01 82944 ----a-w- c:\windows\SysWow64\logman.exe 2015-05-25 18:00 . 2015-06-11 10:01 17408 ----a-w- c:\windows\SysWow64\diskperf.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Raptr"="c:\program files (x86)\Raptr\raptrstub.exe" [2015-07-27 56080] "amd_dc_opt"="c:\program files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824] "StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2015-07-28 767176] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R1 cherimoya;cherimoya;c:\windows\system32\drivers\cherimoya.sys;c:\windows\SYSNATIVE\drivers\cherimoya.sys [x] R2 AODDriver4.2;AODDriver4.2;c:\program files (x86)\GIGABYTE\ET6\amd64\AODDriver2.sys;c:\program files (x86)\GIGABYTE\ET6\amd64\AODDriver2.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 FreemakeVideoCapture;FreemakeVideoCapture;f:\freemake\CaptureLib\CaptureLibService.exe;f:\freemake\CaptureLib\CaptureLibService.exe [x] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x] R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x] R3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [x] R3 BRSptStub;BitRaider Mini-Support Service Stub Loader;c:\programdata\BitRaider\BRSptStub.exe;c:\programdata\BitRaider\BRSptStub.exe [x] R3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys;c:\windows\SYSNATIVE\DRIVERS\motfilt.sys [x] R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe;c:\windows\SYSNATIVE\EasyAntiCheat.exe [x] R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x] R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x] R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys;c:\windows\SYSNATIVE\drivers\iaStorS.sys [x] R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x] R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x] R3 megasas2;megasas2;c:\windows\system32\drivers\megasas2.sys;c:\windows\SYSNATIVE\drivers\megasas2.sys [x] R3 megasr1;megasr1;c:\windows\system32\drivers\megasr1.sys;c:\windows\SYSNATIVE\drivers\megasr1.sys [x] R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys;c:\windows\SYSNATIVE\DRIVERS\motccgp.sys [x] R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x] R3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys;c:\windows\SYSNATIVE\DRIVERS\Motousbnet.sys [x] R3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\DRIVERS\motusbdevice.sys;c:\windows\SYSNATIVE\DRIVERS\motusbdevice.sys [x] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x] R3 Origin Client Service;Origin Client Service;f:\origin\OriginClientService.exe;f:\origin\OriginClientService.exe [x] R3 OverwolfUpdater;Overwolf Updater Windows SCM;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x] R3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys;c:\windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x] R3 tihub3;TI USB3 Hub Service;c:\windows\system32\drivers\tihub3.sys;c:\windows\SYSNATIVE\drivers\tihub3.sys [x] R3 tixhci;TI XHCI Service;c:\windows\system32\drivers\tixhci.sys;c:\windows\SYSNATIVE\drivers\tixhci.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [x] S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x] S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x] S1 {04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64;{04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64;c:\windows\system32\drivers\{04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64.sys;c:\windows\SYSNATIVE\drivers\{04cbd69d-8bfe-4f17-8811-c172dbc67a8b}Gw64.sys [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x] S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x] S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\AMD\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 amdacpksd;ACP Kernel Service Driver;c:\windows\system32\drivers\amdacpksd.sys;c:\windows\SYSNATIVE\drivers\amdacpksd.sys [x] S2 amdacpusrsvc;ACP User Service;c:\program files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe;c:\program files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [x] S2 AODDriver4.3;AODDriver4.3;c:\program files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x] S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x] S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-08-10 12:25 995144 ----a-w- c:\program files (x86)\Google\Chrome\Application\44.0.2403.130\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-08-10 12:24] . 2015-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-08-10 12:24] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-12-11 13776088] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2015-07-08 5595848] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT mDefault_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} mDefault_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT mStart Page = hxxp://www.mystartsearch.com/?type=hp&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1434339395&z=5988dc5dc2adc9a63860836g0zbcdzacfc4tfc7tbo&from=cor&uid=TOSHIBAXMK3252GSX_X8G8P75BTXXX8G8P75BT&q={searchTerms} uInternet Settings,ProxyOverride = <-loopback> Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-PunkBusterSvc - f:\program files (x86)\Origin Games\Battlefield 4\pbsvc.exe AddRemove-{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1 - f:\ftl\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\Google\Update\1.3.28.5\GoogleCrashHandler.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-08-12 17:24:49 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-08-12 15:24 . Vor Suchlauf: 9 Verzeichnis(se), 84.057.518.080 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 83.890.188.288 Bytes frei . - - End Of File - - D99D0306869592C420645AC7852D82EF A36C5E4F47E84449FF07ED3517B43A31 |
13.08.2015, 09:51 | #6 |
/// the machine /// TB-Ausbilder | Es öffnet sich ständig einfach Werbung Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Es öffnet sich ständig einfach Werbung |
Themen zu Es öffnet sich ständig einfach Werbung |
chrome, dauernd, einfach, irgend, neu, problem, seite, seiten, tabs mit werbung, werbun, werbung, öffnet, öffnet sich ständig |