Danke für die schnelle Antwort, hier die neuen Ergebnisse:
FRST-log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-12-2013 01
Ran by Stefan (administrator) on STEFANS_LAPTOP on 13-12-2013 12:52:31
Running from C:\Users\Stefan_2\Desktop
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Geek Software GmbH) D:\Programme\PDF24\pdf24.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - "C:\WINDOWS\system32\hkcmd.exe"
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2864528 2012-08-20] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-31] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-31] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] - C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7477016 2013-04-24] (Logitech Inc.)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
HKLM\...\Policies\Explorer\Run: [BtvStack] - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-01-28] ( (Atheros Communications))
HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [456768 2013-10-19] (BillP Studios)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Dolby PCEE4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [LManager] - [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PDFPrint] - D:\Programme\PDF24\pdf24.exe [186408 2013-12-06] (Geek Software GmbH)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
Startup: C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/search?q={searchTerms}
SearchScopes: HKLM - DefaultScope {F6A1D37F-3624-4E95-B8F9-663E6183A03D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM - {F6A1D37F-3624-4E95-B8F9-663E6183A03D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - DefaultScope {F6A1D37F-3624-4E95-B8F9-663E6183A03D} URL =
SearchScopes: HKCU - {F6A1D37F-3624-4E95-B8F9-663E6183A03D} URL =
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\a4egchbj.default
FF NewTab: about:blank
FF SelectedSearchEngine: Google
FF Homepage: www.facebook.com
FF Keyword.URL: hxxp://www.google.com/search?rls=org.mozilla:en-US:official&client=firefox-a&q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: noscript - C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\a4egchbj.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: Adblock Plus - C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\a4egchbj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-23] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-22] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-09-14] (Dritek System INC.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-10-08] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-09-14] (Dritek System Inc.)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
U3 kxloykoc; \??\C:\Users\Stefan\AppData\Local\Temp\kxloykoc.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-13 12:52 - 2013-12-13 12:52 - 00014287 _____ C:\Users\Stefan_2\Desktop\FRST.txt
2013-12-13 12:02 - 2013-12-13 12:08 - 00011876 _____ C:\Users\Stefan_2\Desktop\Avira-Funde.txt
2013-12-13 11:49 - 2013-12-13 11:49 - 00009834 _____ C:\Users\Stefan\Desktop\GMER_log.log
2013-12-13 11:29 - 2013-12-13 11:29 - 00000000 ____D C:\FRST
2013-12-13 11:28 - 2013-12-13 11:28 - 00000000 _____ C:\Users\Stefan\defogger_reenable
2013-12-13 10:37 - 2013-12-13 10:37 - 01927462 _____ (Farbar) C:\Users\Stefan_2\Desktop\FRST64.exe
2013-12-13 10:37 - 2013-12-13 10:37 - 00377856 _____ C:\Users\Stefan_2\Desktop\gmer_2.1.19163.exe
2013-12-13 10:36 - 2013-12-13 10:36 - 00050477 _____ C:\Users\Stefan_2\Desktop\Defogger.exe
2013-12-12 00:18 - 2013-12-12 00:18 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Malwarebytes
2013-12-11 21:49 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-12-11 21:49 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-12-11 21:49 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-12-11 21:49 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-12-11 21:49 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-12-11 21:49 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-12-11 21:49 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-12-11 21:49 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-12-11 21:49 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-12-11 21:49 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-12-11 21:49 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-12-11 21:49 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-12-11 21:49 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-12-11 21:49 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2013-12-11 21:49 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2013-12-11 21:49 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-12-11 21:49 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-12-11 21:49 - 2013-11-23 05:34 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2013-12-11 21:49 - 2013-11-23 05:13 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2013-12-11 21:49 - 2013-11-23 04:32 - 04105728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-12-11 21:49 - 2013-11-23 04:10 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2013-12-11 21:49 - 2013-11-09 07:34 - 00615936 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2013-12-11 21:49 - 2013-11-09 07:34 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2013-12-11 21:49 - 2013-11-09 06:52 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2013-12-11 21:49 - 2013-11-08 08:21 - 04191744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-12-11 21:49 - 2013-10-19 09:53 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2013-12-11 21:49 - 2013-10-19 08:14 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2013-12-11 21:49 - 2013-10-15 09:54 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2013-12-11 21:49 - 2013-10-15 09:03 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2013-12-11 10:23 - 2013-12-11 10:23 - 00000000 ____D C:\Users\Stefan_2\AppData\Local\PDF24
2013-12-11 10:22 - 2013-12-11 10:22 - 16202248 _____ (Geek Software GmbH ) C:\Users\Stefan_2\Downloads\pdf24-creator-6.1.0.exe
2013-12-10 21:00 - 2013-12-13 10:35 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Ynzy
2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Uzteyk
2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Iqil
2013-12-10 20:56 - 2013-12-13 10:35 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Tuoqra
2013-12-10 20:56 - 2013-12-13 10:35 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Rugany
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Urgimu
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Udilbu
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Otona
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Laky
2013-12-10 20:55 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\Documents\rechnung
2013-12-10 20:17 - 2013-12-13 10:33 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Koufco
2013-12-10 20:17 - 2013-12-10 20:34 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Enimy
2013-12-10 20:17 - 2013-12-10 20:17 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Yqwys
2013-12-10 19:45 - 2013-12-10 19:45 - 09272200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2013-12-03 23:35 - 2013-12-04 01:22 - 00000064 _____ C:\Users\Stefan_2\Desktop\Jobs Links.txt
2013-11-27 23:44 - 2013-11-27 23:44 - 01755649 _____ C:\Users\Stefan_2\Downloads\DBM-Core-5.4.5.zip
2013-11-17 15:44 - 2013-11-17 15:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-16 06:21 - 2013-10-10 12:26 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2013-11-16 06:21 - 2013-10-10 12:05 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2013-11-16 06:21 - 2013-10-10 11:34 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2013-11-16 06:21 - 2013-10-10 11:27 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2013-11-16 06:20 - 2013-11-05 21:21 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2013-11-16 06:20 - 2013-11-05 19:51 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2013-11-16 06:20 - 2013-11-05 17:20 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-16 06:20 - 2013-11-05 17:11 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-16 06:20 - 2013-11-05 15:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-11-16 06:20 - 2013-11-05 15:29 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-11-16 06:20 - 2013-10-23 12:29 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2013-11-16 06:20 - 2013-10-23 12:21 - 00155480 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2013-11-16 06:20 - 2013-10-23 12:13 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll
2013-11-16 06:20 - 2013-10-23 06:27 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-16 06:20 - 2013-10-23 06:04 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-16 06:20 - 2013-10-23 05:55 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-16 06:20 - 2013-10-23 05:46 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-16 06:20 - 2013-10-22 09:18 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2013-11-16 06:20 - 2013-10-22 08:55 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-11-16 06:20 - 2013-10-22 07:03 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-11-16 06:20 - 2013-10-22 06:15 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2013-11-16 06:20 - 2013-10-22 05:04 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2013-11-16 06:20 - 2013-10-22 05:02 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2013-11-16 06:20 - 2013-10-22 04:56 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2013-11-16 06:20 - 2013-10-22 04:44 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2013-11-16 06:20 - 2013-10-22 03:38 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2013-11-16 06:20 - 2013-10-22 03:22 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-16 06:20 - 2013-10-22 03:13 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-16 06:20 - 2013-10-22 03:07 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-16 06:20 - 2013-10-22 02:53 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2013-11-16 06:20 - 2013-10-22 02:47 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2013-11-16 06:20 - 2013-10-19 10:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-16 06:20 - 2013-10-19 09:51 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2013-11-16 06:20 - 2013-10-19 08:12 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2013-11-16 06:20 - 2013-10-19 05:48 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2013-11-16 06:20 - 2013-10-19 05:03 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2013-11-16 06:20 - 2013-10-19 04:57 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-16 06:20 - 2013-10-19 04:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-16 06:20 - 2013-10-19 04:26 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2013-11-16 06:20 - 2013-10-19 04:14 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2013-11-16 06:20 - 2013-10-17 16:42 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2013-11-16 06:20 - 2013-10-17 16:42 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2013-11-16 06:20 - 2013-10-17 15:04 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2013-11-16 06:20 - 2013-10-16 10:34 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2013-11-16 06:20 - 2013-10-16 10:33 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2013-11-16 06:20 - 2013-10-13 04:06 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2013-11-16 06:20 - 2013-10-13 03:43 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2013-11-16 06:20 - 2013-10-11 16:11 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-11-16 06:20 - 2013-10-11 15:22 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-11-16 06:20 - 2013-10-11 14:24 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-16 06:20 - 2013-10-11 14:04 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-11-16 06:20 - 2013-10-11 14:03 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-16 06:20 - 2013-10-10 17:44 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2013-11-16 06:20 - 2013-10-10 17:26 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2013-11-16 06:20 - 2013-10-10 17:26 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2013-11-16 06:20 - 2013-10-10 17:23 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2013-11-16 06:20 - 2013-10-10 15:53 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2013-11-16 06:20 - 2013-10-10 15:53 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2013-11-16 06:20 - 2013-10-10 12:53 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2013-11-16 06:20 - 2013-10-10 12:38 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2013-11-16 06:20 - 2013-10-10 12:21 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2013-11-16 06:20 - 2013-10-10 11:40 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-11-16 06:20 - 2013-10-10 11:19 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-11-16 06:20 - 2013-10-09 06:40 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-11-16 06:20 - 2013-10-08 12:07 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-11-16 06:20 - 2013-10-08 11:28 - 00523096 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2013-11-16 06:20 - 2013-10-08 11:13 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-11-16 06:20 - 2013-10-08 07:46 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2013-11-16 06:20 - 2013-10-08 06:58 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2013-11-16 06:20 - 2013-10-08 06:50 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2013-11-16 06:20 - 2013-10-08 06:48 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2013-11-16 06:20 - 2013-10-08 06:15 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2013-11-16 06:20 - 2013-10-08 06:09 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2013-11-16 06:20 - 2013-10-08 05:50 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2013-11-16 06:20 - 2013-10-08 05:50 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2013-11-16 06:20 - 2013-10-07 08:21 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-11-16 06:20 - 2013-10-07 08:21 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-16 06:20 - 2013-10-07 03:13 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-16 06:20 - 2013-10-05 16:25 - 00371032 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-11-16 06:20 - 2013-10-05 16:25 - 00057176 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2013-11-16 06:20 - 2013-10-05 15:21 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2013-11-16 06:20 - 2013-10-05 13:05 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2013-11-16 06:20 - 2013-10-05 12:01 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2013-11-16 06:20 - 2013-10-05 10:36 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2013-11-16 06:20 - 2013-10-05 10:18 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2013-11-16 06:20 - 2013-10-05 10:07 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-11-16 06:20 - 2013-10-05 09:56 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-16 06:20 - 2013-10-05 09:55 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll
2013-11-16 06:20 - 2013-10-05 09:40 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2013-11-16 06:20 - 2013-10-05 09:24 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll
2013-11-16 06:20 - 2013-10-05 09:21 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2013-11-16 06:20 - 2013-10-05 09:15 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2013-11-16 06:20 - 2013-10-05 08:43 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2013-11-16 06:20 - 2013-10-05 08:39 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2013-11-16 06:20 - 2013-10-05 08:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-11-16 06:20 - 2013-10-05 08:32 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2013-11-16 06:20 - 2013-10-04 09:10 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2013-11-16 06:20 - 2013-09-19 06:04 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2013-11-16 06:20 - 2013-09-17 10:06 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-11-16 06:20 - 2013-09-17 10:06 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2013-11-16 06:20 - 2013-09-17 07:31 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-11-16 06:20 - 2013-09-17 07:31 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2013-11-16 06:20 - 2013-09-17 05:37 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2013-11-16 06:20 - 2013-09-14 15:07 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2013-11-16 06:20 - 2013-09-14 15:00 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2013-11-16 06:20 - 2013-09-14 13:39 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2013-11-16 06:20 - 2013-09-14 13:33 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2013-11-16 06:20 - 2013-09-14 11:05 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2013-11-16 06:20 - 2013-09-14 10:11 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2013-11-16 06:20 - 2013-09-13 09:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe
2013-11-16 06:20 - 2013-09-13 08:47 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe
2013-11-16 06:20 - 2013-09-12 09:45 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2013-11-16 06:20 - 2013-09-12 09:08 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2013-11-16 06:20 - 2013-09-12 09:08 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2013-11-16 06:20 - 2013-09-12 09:02 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2013-11-16 06:20 - 2013-09-12 08:44 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2013-11-16 06:20 - 2013-09-12 08:37 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2013-11-16 06:20 - 2013-09-12 08:37 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2013-11-16 06:20 - 2013-09-12 08:21 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2013-11-16 06:20 - 2013-09-12 08:16 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2013-11-16 06:20 - 2013-09-12 08:01 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2013-11-16 06:20 - 2013-09-11 13:46 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-11-16 06:20 - 2013-09-10 06:26 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2013-11-16 06:20 - 2013-09-10 05:52 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll
2013-11-16 06:20 - 2013-09-10 05:34 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2013-11-14 18:44 - 2013-11-14 18:44 - 104278918 _____ C:\WINDOWS\SysWOW64\䨂嵙瀄Z
2013-11-14 09:15 - 2013-11-14 09:15 - 104179408 _____ C:\WINDOWS\SysWOW64\뽗宭瀄ª
2013-11-13 10:01 - 2013-11-13 10:01 - 104004073 _____ C:\WINDOWS\SysWOW64\ⷖꃿ瀄ò
==================== One Month Modified Files and Folders =======
2013-12-13 12:52 - 2013-12-13 12:52 - 00014287 _____ C:\Users\Stefan_2\Desktop\FRST.txt
2013-12-13 12:45 - 2013-05-08 21:04 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-13 12:14 - 2013-11-05 15:56 - 00000533 _____ C:\Users\Stefan_2\Desktop\....txt
2013-12-13 12:08 - 2013-12-13 12:02 - 00011876 _____ C:\Users\Stefan_2\Desktop\Avira-Funde.txt
2013-12-13 12:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2013-12-13 11:49 - 2013-12-13 11:49 - 00009834 _____ C:\Users\Stefan\Desktop\GMER_log.log
2013-12-13 11:43 - 2013-10-21 16:33 - 01778679 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-13 11:39 - 2013-11-05 15:37 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3536570932-3064348446-823945434-1008
2013-12-13 11:29 - 2013-12-13 11:29 - 00000000 ____D C:\FRST
2013-12-13 11:28 - 2013-12-13 11:28 - 00000000 _____ C:\Users\Stefan\defogger_reenable
2013-12-13 11:28 - 2013-10-21 16:38 - 00000000 ____D C:\Users\Stefan
2013-12-13 11:23 - 2013-10-21 16:30 - 00053284 _____ C:\WINDOWS\system32\wpbbin.exe
2013-12-13 11:23 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-13 10:43 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-12-13 10:37 - 2013-12-13 10:37 - 01927462 _____ (Farbar) C:\Users\Stefan_2\Desktop\FRST64.exe
2013-12-13 10:37 - 2013-12-13 10:37 - 00377856 _____ C:\Users\Stefan_2\Desktop\gmer_2.1.19163.exe
2013-12-13 10:36 - 2013-12-13 10:36 - 00050477 _____ C:\Users\Stefan_2\Desktop\Defogger.exe
2013-12-13 10:35 - 2013-12-10 21:00 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Ynzy
2013-12-13 10:35 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Tuoqra
2013-12-13 10:35 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Rugany
2013-12-13 10:33 - 2013-12-10 20:17 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Koufco
2013-12-13 09:47 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2013-12-12 23:44 - 2013-11-05 16:01 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\TS3Client
2013-12-12 10:35 - 2013-05-09 03:04 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2013-12-12 10:35 - 2013-05-08 20:58 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2013-12-12 10:35 - 2013-05-08 20:58 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2013-12-12 00:28 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-12-12 00:18 - 2013-12-12 00:18 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Malwarebytes
2013-12-12 00:09 - 2013-08-22 15:44 - 00360464 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-11 10:23 - 2013-12-11 10:23 - 00000000 ____D C:\Users\Stefan_2\AppData\Local\PDF24
2013-12-11 10:22 - 2013-12-11 10:22 - 16202248 _____ (Geek Software GmbH ) C:\Users\Stefan_2\Downloads\pdf24-creator-6.1.0.exe
2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Uzteyk
2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Iqil
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Urgimu
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Udilbu
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Otona
2013-12-10 20:56 - 2013-12-10 20:56 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Laky
2013-12-10 20:56 - 2013-12-10 20:55 - 00000000 ____D C:\Users\Stefan_2\Documents\rechnung
2013-12-10 20:34 - 2013-12-10 20:17 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Enimy
2013-12-10 20:17 - 2013-12-10 20:17 - 00000000 ____D C:\Users\Stefan_2\AppData\Roaming\Yqwys
2013-12-10 19:45 - 2013-12-10 19:45 - 09272200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2013-12-10 19:45 - 2013-05-08 21:04 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2013-12-10 08:21 - 2013-11-05 15:56 - 00012825 _____ C:\Users\Stefan_2\Desktop\Jobs.odt
2013-12-04 01:22 - 2013-12-03 23:35 - 00000064 _____ C:\Users\Stefan_2\Desktop\Jobs Links.txt
2013-12-04 01:05 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-12-04 01:05 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-29 14:25 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-29 14:25 - 2013-09-30 04:56 - 00765582 _____ C:\WINDOWS\system32\perfh007.dat
2013-11-29 14:25 - 2013-09-30 04:56 - 00159366 _____ C:\WINDOWS\system32\perfc007.dat
2013-11-27 23:44 - 2013-11-27 23:44 - 01755649 _____ C:\Users\Stefan_2\Downloads\DBM-Core-5.4.5.zip
2013-11-26 12:54 - 2013-12-11 21:49 - 23183360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-26 11:11 - 2013-12-11 21:49 - 17112576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-26 10:41 - 2013-12-11 21:49 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-26 09:57 - 2013-12-11 21:49 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-26 09:38 - 2013-12-11 21:49 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-26 09:35 - 2013-12-11 21:49 - 05769216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-26 09:16 - 2013-12-11 21:49 - 04243968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-26 09:02 - 2013-12-11 21:49 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-26 08:48 - 2013-12-11 21:49 - 12996608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-26 08:32 - 2013-12-11 21:49 - 01928192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-26 08:26 - 2013-12-11 21:49 - 11221504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-26 08:07 - 2013-12-11 21:49 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-26 07:40 - 2013-12-11 21:49 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-26 07:34 - 2013-12-11 21:49 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2013-11-26 07:34 - 2013-12-11 21:49 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2013-11-26 07:33 - 2013-12-11 21:49 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-26 07:27 - 2013-12-11 21:49 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-25 23:10 - 2013-05-08 20:58 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2013-11-25 23:05 - 2013-05-07 00:45 - 00000000 ___RD C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-25 23:04 - 2013-10-21 22:05 - 00000000 __RDO C:\Users\Stefan\SkyDrive
2013-11-25 23:04 - 2013-05-07 00:45 - 00000000 ___RD C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-23 05:34 - 2013-12-11 21:49 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2013-11-23 05:13 - 2013-12-11 21:49 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2013-11-23 04:32 - 2013-12-11 21:49 - 04105728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-11-23 04:10 - 2013-12-11 21:49 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2013-11-22 15:09 - 2013-10-21 16:34 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2013-11-22 15:09 - 2013-10-21 16:34 - 00004068 _____ C:\WINDOWS\LkmdfCoInst.log
2013-11-22 11:50 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2013-11-18 17:18 - 2013-11-05 15:57 - 00008990 _____ C:\Users\Stefan_2\Desktop\Zwischenspeicher.txt
2013-11-18 09:38 - 2013-05-08 20:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-17 15:44 - 2013-11-17 15:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-17 15:24 - 2013-11-05 15:31 - 00000000 ___RD C:\Users\Stefan_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-17 15:24 - 2013-11-05 15:31 - 00000000 ___RD C:\Users\Stefan_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-16 23:17 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData
2013-11-16 23:17 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-16 23:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\migwiz
2013-11-16 23:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-11-14 23:20 - 2013-11-05 15:30 - 00000000 ____D C:\Users\Stefan_2
2013-11-14 18:44 - 2013-11-14 18:44 - 104278918 _____ C:\WINDOWS\SysWOW64\䨂嵙瀄Z
2013-11-14 09:15 - 2013-11-14 09:15 - 104179408 _____ C:\WINDOWS\SysWOW64\뽗宭瀄ª
2013-11-13 10:12 - 2013-05-11 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\Adobe
2013-11-13 10:01 - 2013-11-13 10:01 - 104004073 _____ C:\WINDOWS\SysWOW64\ⷖꃿ瀄ò
Some content of TEMP:
====================
C:\Users\Stefan_2\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-13 11:39
==================== End Of Log ============================ --- --- ---
GMER-log:
[CODE]
GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-12-13 12:55:44
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002d Hitachi_HTS545050A7E380 rev.GG2OA6C0 465,76GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Stefan\AppData\Local\Temp\kxloykoc.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960001c0700 15 bytes [00, EA, 0F, 02, 00, 7F, 6F, ...]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff960001c0710 11 bytes [00, 1F, FC, FF, 80, 52, DE, ...]
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleInformation 00007ff941f930e0 7 bytes JMP 00007ffa404f02d0
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!RegQueryValueExW 00007ff941f94478 7 bytes JMP 00007ffa404f0308
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!RegDeleteValueW 00007ff9420411a8 7 bytes JMP 00007ffa404f0340
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExW 00007ff94204121c 7 bytes JMP 00007ffa404f03b0
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!RegSetValueExA 00007ff942041668 7 bytes JMP 00007ffa404f0378
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!K32GetModuleFileNameExW 00007ff9420472d0 7 bytes JMP 00007ffa404f0260
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ff94206d5a4 7 bytes JMP 00007ffa404f0228
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ff94206d614 7 bytes JMP 00007ffa404f0298
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleW 00007ff940502124 7 bytes JMP 00007ffa404f00d8
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNELBASE.dll!FreeLibrary 00007ff9405050e8 5 bytes JMP 00007ffa404f0180
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW 00007ff9405052a0 5 bytes JMP 00007ffa404f0148
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\KERNELBASE.dll!GetModuleHandleExW 00007ff94050a9b0 5 bytes JMP 00007ffa404f0110
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\USER32.dll!CreateWindowExW 00007ff9428a7b64 10 bytes JMP 00007ffa404f0490
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesA 00007ff9428c2910 5 bytes JMP 00007ffa404f0420
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\USER32.dll!EnumDisplayDevicesW 00007ff9428c4578 5 bytes JMP 00007ffa404f0458
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ff9428c4980 9 bytes JMP 00007ffa404f03e8
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ff942b51500 8 bytes JMP 00007ffa404f01b8
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ff942b51750 8 bytes JMP 00007ffa404f01f0
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\dxgi.dll!CreateDXGIFactory 00007ff93e14705c 5 bytes JMP 00007ffa3e1300d8
.text C:\WINDOWS\system32\dwm.exe[972] C:\WINDOWS\system32\dxgi.dll!CreateDXGIFactory1 00007ff93e147678 5 bytes JMP 00007ffa3e130110
.text C:\WINDOWS\system32\nvvsvc.exe[868] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff942a8169a 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[868] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff942a816a2 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[868] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff942a8181a 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[868] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff942a81832 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1532] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff942a8169a 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1532] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff942a816a2 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1532] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff942a8181a 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1532] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff942a81832 4 bytes [A8, 42, F9, 7F]
.text C:\WINDOWS\Explorer.EXE[2888] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff92d341f6a 4 bytes [34, 2D, F9, 7F]
.text C:\WINDOWS\Explorer.EXE[2888] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff92d341f82 4 bytes [34, 2D, F9, 7F]
.text C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe[3348] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff92d341f6a 4 bytes [34, 2D, F9, 7F]
.text C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe[3348] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff92d341f82 4 bytes [34, 2D, F9, 7F]
.text C:\Windows\System32\igfxpers.exe[3500] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff942a8169a 4 bytes [A8, 42, F9, 7F]
.text C:\Windows\System32\igfxpers.exe[3500] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff942a816a2 4 bytes [A8, 42, F9, 7F]
.text C:\Windows\System32\igfxpers.exe[3500] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff942a8181a 4 bytes [A8, 42, F9, 7F]
.text C:\Windows\System32\igfxpers.exe[3500] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff942a81832 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3820] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ff942a8169a 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3820] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ff942a816a2 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3820] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ff942a8181a 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[3820] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ff942a81832 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[3992] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ff92d341f6a 4 bytes [34, 2D, F9, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[3992] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ff92d341f82 4 bytes [34, 2D, F9, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[3992] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff942a8169a 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[3992] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff942a816a2 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[3992] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff942a8181a 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[3992] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff942a81832 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4320] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ff942a8169a 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4320] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ff942a816a2 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4320] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ff942a8181a 4 bytes [A8, 42, F9, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4320] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ff942a81832 4 bytes [A8, 42, F9, 7F]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [672:696] fffff960008a34d0
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- --- --- ---
lg Stefan |