Windows 8 - TrojanDropper in 6 Varianten und Adware Hallo,
nachdem ich auf meinem Notebook den Trojaner entdeckte, habe ich auch das Notebook meines Sohnes geprüft ... auch er hat den "Dropper", und zwar gleich in 6 Varianten.
Könnte das auch der Grund sein, weshalb er in letzter Zeit Skype nicht öffnen konnte?
Auf jeden Fall habe ich erstmal die entsprechenden Scans laut eurer "Anleitung für Hilfesuchende" gemacht. GMER hat zwar gescannt, aber konnte anscheinend zwei Systemdateien nicht prüfen - ich hoffe, das ist im Logfile notiert.
Hier die 4 Logfiles: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 15:46 on 11/01/2014 (Budller)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-01-2014 03
Ran by Budller (administrator) on SIMONSGAMINGPC on 11-01-2014 15:55:08
Running from C:\Users\Budller\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(GamersFirst) C:\Users\Budller\AppData\Local\GamersFirst\LIVE!\Live.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Google Inc.) C:\Users\Budller\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Budller\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Budller\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Budller\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Google Inc.) C:\Users\Budller\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2874168 2012-09-17] (Synaptics Incorporated)
HKLM\...\Run: [SynLenovoGestureMgr] - C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [656896 2012-09-20] (Synaptics)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-09-14] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-09-14] (Realtek Semiconductor)
HKLM\...\Run: [OnekeyStudio] - C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-08-10] (Lenovo)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-12-24] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [191544 2012-12-24] (Lenovo(beijing) Limited)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7477016 2013-04-24] (Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-08-16] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2013-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCEPServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Budller\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-10] (Google Inc.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1815464 2014-01-07] (Valve Corporation)
MountPoints2: F - "F:\AutoRun.exe"
MountPoints2: {4489f8ca-c469-11e2-be77-e006e6c05782} - "F:\AutoRun.exe"
MountPoints2: {bfcf8dac-d1ec-11e2-be7a-e006e6c05782} - "F:\AutoRun.exe"
MountPoints2: {bfcf99e1-d1ec-11e2-be7a-e006e6c05782} - "F:\AutoRun.exe"
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-02] (NVIDIA Corporation)
Startup: C:\Users\Budller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
ShortcutTarget: GamersFirst LIVE!.lnk -> C:\Users\Budller\AppData\Local\GamersFirst\LIVE!\Live.exe (GamersFirst)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=F84C9C4E368ECDC9&affID=123884&tsp=4958
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
SearchScopes: HKLM - DefaultScope {0AC1F723-45D8-4389-A97B-9AAF9F4A7F6C} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
SearchScopes: HKLM - {0AC1F723-45D8-4389-A97B-9AAF9F4A7F6C} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
SearchScopes: HKLM - {255A6681-375D-C64C-442C-496E0FAF5979} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM-x32 - DefaultScope {0AC1F723-45D8-4389-A97B-9AAF9F4A7F6C} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
SearchScopes: HKLM-x32 - {0AC1F723-45D8-4389-A97B-9AAF9F4A7F6C} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
SearchScopes: HKLM-x32 - {52A74A32-923C-7822-CD53-30D6C2D09E5A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKCU - DefaultScope {0AC1F723-45D8-4389-A97B-9AAF9F4A7F6C} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {0AC1F723-45D8-4389-A97B-9AAF9F4A7F6C} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=spubmsd&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyC0CtDyDyBzztBtBtBtDyCtN0D0Tzu0CyCtCzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1B1E2Y1S1H1B1Q&cr=872864145&ir=
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=F84C9C4E368ECDC9&affID=123884&tsp=4958
SearchScopes: HKCU - {255A6681-375D-C64C-442C-496E0FAF5979} URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: OKitSpace - {3543619C-D563-43f7-95EA-4DA7E1CC396A} - C:\Users\Budller\AppData\Roaming\okitspace\IE\OKitSpace.dll ()
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{77F820CC-674D-4C57-8C7B-0BAF5EB0BF0B}: [NameServer]213.162.69.1 213.162.69.169
Tcpip\..\Interfaces\{A1192F62-467D-48F1-AEA9-E60DFE45717E}: [NameServer]213.162.69.170 213.162.69.2
Tcpip\..\Interfaces\{A6008AA1-5830-4E2B-B5BA-B03BF9E11FD2}: [NameServer]213.162.69.169 213.162.69.1
Chrome:
=======
CHR HomePage: hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=F84C9C4E368ECDC9&affID=123884&tsp=4958
CHR RestoreOnStartup: "https://www.google.at/"
CHR Plugin: (Shockwave Flash) - C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Budller\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\WINDOWS\SysWOW64\npDeployJava1.dll No File
CHR Extension: (OKitSpace) - C:\Users\Budller\AppData\Local\Google\Chrome\User Data\Default\Extensions\mggiecmcgkpfmegnobeimepgndgdhbjm\1.0_0
CHR Extension: (Google Wallet) - C:\Users\Budller\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (WebSite Recommendation) - C:\Users\Budller\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj\1.81_0
CHR Extension: (MySearchDial __MSG_newtab__) - C:\Users\Budller\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.4.8_0
CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\Budller\AppData\Local\mysearchdial_speedial_v9.0.2.crx
CHR HKCU\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\Budller\AppData\Local\mysearchdial_speedial_v9.0.2.crx
CHR HKLM-x32\...\Chrome\Extension: [iidmoehhpbghchkaogkhmcckhlhebekn] - C:\Program Files (x86)\iRobinHood\iRobinHood Addon\iRobinHoodPartnersVExtension1_52.crx
CHR HKLM-x32\...\Chrome\Extension: [mggiecmcgkpfmegnobeimepgndgdhbjm] - C:\Users\Budller\AppData\Roaming\okitspace\Chrome\OKitSpace.crx
CHR HKLM-x32\...\Chrome\Extension: [mmiopbgcekanlhpjkonogoljpfmhpkhf] - C:\Program Files (x86)\LyricsPal\125.crx
CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\Budller\AppData\Local\mysearchdial_speedial_v9.0.2.crx
CHR HKLM-x32\...\Chrome\Extension: [pnbbffeddnekkhjmokkhdebbfbibbflc] - C:\Program Files (x86)\LyricsPal\128.crx
==================== Services (Whitelisted) =================
U2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2012-10-01] (Broadcom Corporation.)
U2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [957816 2012-10-21] (Broadcom Corporation.)
U2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [344928 2011-01-28] ()
U2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2013-05-26] ()
U2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
U2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
U3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] ()
U2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-11-02] (Microsoft Corporation)
U2 SrvUpdater; C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe [32256 2013-09-26] ()
U2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
U2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
U3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2012-10-01] (Broadcom Corporation.)
U0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2013-05-26] (Bytemobile, Inc.)
U3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
U3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2013-11-29] (LogMeIn Inc.)
U3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [212992 2013-05-26] (Huawei Technologies Co., Ltd.)
U3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.)
U3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4273192 2012-08-19] (Intel Corporation)
U3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8229264 2012-09-28] (Realtek Semiconductor Corp.)
U3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-09-17] (Synaptics Incorporated)
U1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2013-05-26] (Bytemobile, Inc.)
U3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-10-09] (Windows (R) Win 7 DDK provider)
U3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
U3 XENfiltv; C:\Windows\system32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.)
U3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-09] (Windows (R) Win 7 DDK provider)
U3 X6va011; \??\C:\WINDOWS\SysWOW64\Drivers\X6va011 [x]
U3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-11 15:55 - 2014-01-11 15:55 - 00020363 _____ C:\Users\Budller\Downloads\FRST.txt
2014-01-11 15:54 - 2014-01-11 15:54 - 02076160 _____ (Farbar) C:\Users\Budller\Downloads\FRST64.exe
2014-01-11 15:54 - 2014-01-11 15:54 - 00000000 ____D C:\FRST
2014-01-11 15:53 - 2014-01-11 15:53 - 00000478 _____ C:\Users\Budller\Desktop\defogger_disable.log
2014-01-11 15:46 - 2014-01-11 15:46 - 00000476 _____ C:\Users\Budller\Downloads\defogger_disable.log
2014-01-11 15:46 - 2014-01-11 15:46 - 00000000 _____ C:\Users\Budller\defogger_reenable
2014-01-11 15:43 - 2014-01-11 15:43 - 00050477 _____ C:\Users\Budller\Downloads\Defogger.exe
2014-01-08 20:33 - 2014-01-08 20:33 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2014-01-08 20:30 - 2014-01-08 20:31 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Budller\Downloads\Skype611SetupFull.exe
2014-01-08 19:36 - 2014-01-08 19:39 - 953505980 _____ C:\Users\Budller\Documents\Minecraft Backup vom 08.01.2014.mvc
2014-01-05 02:12 - 2014-01-05 02:12 - 00000000 ____D C:\Crash
2014-01-05 00:35 - 2014-01-05 00:35 - 00000000 ____D C:\Users\Budller\AppData\Local\SCE
2014-01-04 23:41 - 2014-01-04 23:50 - 00000000 ____D C:\Users\Budller\Planetside 2
2014-01-04 22:35 - 2014-01-05 00:29 - 00000222 _____ C:\Users\Budller\Desktop\PlanetSide 2.url
2014-01-03 16:51 - 2014-01-03 16:51 - 00000222 _____ C:\Users\Budller\Desktop\Starbound.url
2013-12-28 16:32 - 2013-12-28 16:32 - 35098272 _____ (Skype Technologies S.A.) C:\Users\Budller\Downloads\SkypeSetupFull.exe
2013-12-28 13:25 - 2014-01-11 15:26 - 00000330 _____ C:\WINDOWS\Tasks\MySearchDial.job
2013-12-28 13:25 - 2014-01-04 00:25 - 00000071 _____ C:\Users\Budller\AppData\Roaming\WB.CFG
2013-12-28 13:25 - 2013-12-28 13:25 - 00002664 _____ C:\WINDOWS\System32\Tasks\MySearchDial
2013-12-26 22:05 - 2013-12-26 22:05 - 00000221 _____ C:\Users\Budller\Desktop\Magicka.url
2013-12-26 10:14 - 2013-12-26 10:15 - 05089728 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-26 10:10 - 2013-12-26 10:10 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2013-12-26 10:09 - 2013-12-26 10:09 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-26 10:07 - 2013-12-26 10:07 - 00000000 ____D C:\Users\Budller\Downloads\omegavesko-SimpleADBBackup-0790701
2013-12-25 12:23 - 2013-12-25 12:27 - 00000000 ____D C:\Users\Budller\AppData\Local\DayZ
2013-12-25 12:23 - 2013-12-25 12:23 - 00000000 ____D C:\Users\Budller\Documents\DayZ
2013-12-25 12:23 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2013-12-25 12:23 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2013-12-25 12:23 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2013-12-25 12:23 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2013-12-25 12:23 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2013-12-25 12:23 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2013-12-25 12:23 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2013-12-25 12:23 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2013-12-25 12:23 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2013-12-25 12:23 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2013-12-25 12:23 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2013-12-25 12:23 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2013-12-25 12:23 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2013-12-25 12:23 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2013-12-25 12:23 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2013-12-25 12:23 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2013-12-25 12:23 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2013-12-25 12:23 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
2013-12-25 12:23 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2013-12-25 12:23 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2013-12-25 12:23 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2013-12-25 12:23 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2013-12-25 12:23 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2013-12-25 12:23 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2013-12-25 12:23 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2013-12-25 12:23 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2013-12-25 12:23 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
2013-12-25 12:23 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2013-12-25 12:23 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2013-12-25 12:23 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
2013-12-25 12:23 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2013-12-25 12:23 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2013-12-25 12:23 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2013-12-25 12:23 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2013-12-25 12:23 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2013-12-25 12:23 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2013-12-25 12:23 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2013-12-25 12:23 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2013-12-25 12:23 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2013-12-25 12:23 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2013-12-25 12:23 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2013-12-25 12:23 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2013-12-25 12:23 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2013-12-25 12:23 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2013-12-25 12:23 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2013-12-25 12:23 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2013-12-25 12:23 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2013-12-25 12:23 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2013-12-25 12:23 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2013-12-25 12:23 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2013-12-25 12:23 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2013-12-25 12:23 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2013-12-25 12:23 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2013-12-25 12:23 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2013-12-25 12:23 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2013-12-25 12:23 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2013-12-25 12:23 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2013-12-25 12:23 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2013-12-25 12:23 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2013-12-25 12:23 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2013-12-25 12:23 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2013-12-25 12:23 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2013-12-25 12:23 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2013-12-25 12:23 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2013-12-25 12:23 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2013-12-25 12:23 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2013-12-25 12:23 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2013-12-25 12:23 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2013-12-25 12:23 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2013-12-25 12:23 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2013-12-25 12:23 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2013-12-25 12:23 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2013-12-25 12:23 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2013-12-25 12:23 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2013-12-25 12:23 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2013-12-25 12:23 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2013-12-25 12:23 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2013-12-25 12:23 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2013-12-25 12:23 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2013-12-25 12:23 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2013-12-25 12:23 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2013-12-25 12:23 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2013-12-25 12:23 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2013-12-25 12:23 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2013-12-25 12:23 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2013-12-25 12:22 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2013-12-25 12:22 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2013-12-25 12:22 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2013-12-25 12:22 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2013-12-25 12:22 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2013-12-25 12:22 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2013-12-25 12:22 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2013-12-25 12:22 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2013-12-25 12:22 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2013-12-25 12:22 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2013-12-25 12:22 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2013-12-25 12:22 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2013-12-25 12:22 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2013-12-25 12:22 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2013-12-25 12:22 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2013-12-25 12:22 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2013-12-25 12:22 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2013-12-25 12:22 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2013-12-25 12:22 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2013-12-25 12:22 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2013-12-25 12:22 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2013-12-25 12:22 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2013-12-25 12:22 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2013-12-25 12:22 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2013-12-25 12:22 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
2013-12-25 12:22 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2013-12-25 12:22 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2013-12-25 12:22 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2013-12-25 12:22 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
2013-12-25 12:22 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
2013-12-25 12:22 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2013-12-25 12:22 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2013-12-25 12:22 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
2013-12-25 12:22 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2013-12-25 12:22 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2013-12-25 12:22 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2013-12-25 12:22 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
2013-12-25 12:22 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
2013-12-25 12:22 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
2013-12-25 12:22 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2013-12-25 12:22 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2013-12-25 12:22 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2013-12-25 12:22 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2013-12-25 12:22 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
2013-12-25 12:22 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2013-12-25 12:22 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
2013-12-25 12:22 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2013-12-25 12:22 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
2013-12-25 12:22 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2013-12-25 12:22 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
2013-12-25 12:22 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2013-12-25 12:22 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
2013-12-25 12:22 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2013-12-25 12:22 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2013-12-25 12:22 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2013-12-25 12:22 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
2013-12-25 12:22 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2013-12-25 12:22 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
2013-12-25 12:22 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2013-12-25 12:22 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
2013-12-25 12:22 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2013-12-25 12:22 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
2013-12-25 11:37 - 2013-12-25 11:37 - 00000222 _____ C:\Users\Budller\Desktop\DayZ.url
2013-12-21 23:07 - 2013-12-21 23:07 - 00320632 _____ (QuickSet) C:\Users\Budller\Downloads\minecraftdl_1659.exe
2013-12-21 10:56 - 2013-12-21 10:56 - 00000000 ____D C:\Users\Budller\.android
2013-12-21 10:55 - 2013-12-21 10:55 - 00003518 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-SimonsGamingPC-Budller
2013-12-21 10:55 - 2013-12-21 10:55 - 00000000 ____D C:\Users\Budller\AppData\Roaming\PDAppFlex
2013-12-21 10:54 - 2013-12-21 10:55 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-12-21 10:47 - 2013-12-21 10:47 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-12-21 10:47 - 2013-12-21 10:47 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-12-21 10:34 - 2013-12-21 10:36 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-12-21 10:33 - 2013-12-21 10:48 - 00000000 ____D C:\Program Files\Adobe
2013-12-21 10:15 - 2013-12-21 10:47 - 00000000 ____D C:\ProgramData\Adobe
2013-12-21 10:13 - 2013-12-21 10:13 - 00001074 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2013-12-21 10:12 - 2013-12-21 10:47 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-12-21 10:11 - 2014-01-11 15:22 - 00000000 ____D C:\Users\Budller\AppData\Local\Adobe
2013-12-21 10:11 - 2013-12-21 10:11 - 02844536 _____ (Adobe Systems Incorporated) C:\Users\Budller\Downloads\CreativeCloudSet-Up.exe
2013-12-17 20:25 - 2013-12-17 20:25 - 00004886 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log
2013-12-17 20:25 - 2013-12-17 20:25 - 00000000 ____D C:\ProgramData\Oracle
2013-12-17 20:25 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2013-12-17 20:25 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2013-12-17 20:25 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2013-12-17 20:25 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2013-12-15 19:30 - 2013-11-07 00:18 - 04036608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-12-15 19:30 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-12-15 19:30 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-12-15 19:30 - 2013-10-25 07:19 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2013-12-15 19:30 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-12-15 19:30 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-12-15 19:30 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-12-15 19:30 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-12-15 19:30 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-12-15 19:30 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-12-15 19:30 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2013-12-15 19:30 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-12-15 19:30 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-12-15 19:30 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-12-15 19:30 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-12-15 19:30 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-12-15 19:30 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-12-15 19:30 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2013-12-15 19:30 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2013-12-15 19:30 - 2013-10-19 06:45 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2013-12-15 19:30 - 2013-10-19 05:04 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2013-12-15 19:30 - 2013-09-28 04:35 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2013-12-15 19:29 - 2013-11-23 07:43 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2013-12-15 19:29 - 2013-11-23 06:05 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2013-12-15 19:29 - 2013-11-01 06:38 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll
2013-12-15 19:29 - 2013-11-01 04:49 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll
2013-12-15 19:29 - 2013-10-10 10:32 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2013-12-15 19:29 - 2013-10-10 10:30 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2013-12-15 19:29 - 2013-10-10 10:30 - 00156160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2013-12-15 19:29 - 2013-10-10 10:24 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2013-12-15 19:29 - 2013-10-10 10:23 - 00146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2013-12-15 19:29 - 2013-10-10 10:22 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2013-12-15 19:29 - 2013-10-10 10:22 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2013-12-15 19:29 - 2013-10-09 02:33 - 00059416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-12-15 19:29 - 2013-10-08 23:30 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2013-12-15 19:29 - 2013-10-08 23:30 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2013-12-15 19:29 - 2013-10-08 23:30 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2013-12-15 19:29 - 2013-10-08 23:30 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2013-12-15 19:29 - 2013-10-08 23:28 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2013-12-15 19:29 - 2013-10-08 23:27 - 03279872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-12-15 19:29 - 2013-10-08 23:27 - 01622016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-12-15 19:29 - 2013-10-08 23:27 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2013-12-15 19:29 - 2013-10-08 23:27 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-12-15 19:29 - 2013-10-08 23:27 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2013-12-15 19:29 - 2013-10-08 23:27 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2013-12-15 19:29 - 2013-10-08 23:27 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2013-12-15 19:29 - 2013-10-05 07:10 - 00285016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-12-15 19:29 - 2013-10-03 23:09 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-12-15 19:29 - 2013-10-02 03:50 - 00447320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2013-12-15 19:29 - 2013-09-28 06:48 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2013-12-15 19:29 - 2013-09-28 04:58 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2013-12-15 19:29 - 2013-09-19 08:32 - 01455448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-12-15 19:29 - 2013-08-30 06:19 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2013-12-15 19:29 - 2013-08-30 06:18 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2013-12-15 19:29 - 2013-08-30 00:48 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2013-12-15 19:29 - 2013-08-30 00:47 - 00302080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
==================== One Month Modified Files and Folders =======
2014-01-11 15:55 - 2014-01-11 15:55 - 00020363 _____ C:\Users\Budller\Downloads\FRST.txt
2014-01-11 15:54 - 2014-01-11 15:54 - 02076160 _____ (Farbar) C:\Users\Budller\Downloads\FRST64.exe
2014-01-11 15:54 - 2014-01-11 15:54 - 00000000 ____D C:\FRST
2014-01-11 15:53 - 2014-01-11 15:53 - 00000478 _____ C:\Users\Budller\Desktop\defogger_disable.log
2014-01-11 15:47 - 2012-12-24 01:21 - 01435082 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-11 15:46 - 2014-01-11 15:46 - 00000476 _____ C:\Users\Budller\Downloads\defogger_disable.log
2014-01-11 15:46 - 2014-01-11 15:46 - 00000000 _____ C:\Users\Budller\defogger_reenable
2014-01-11 15:46 - 2013-05-22 00:18 - 00000000 ____D C:\Users\Budller
2014-01-11 15:43 - 2014-01-11 15:43 - 00050477 _____ C:\Users\Budller\Downloads\Defogger.exe
2014-01-11 15:37 - 2012-12-24 09:26 - 00754172 _____ C:\WINDOWS\system32\perfh007.dat
2014-01-11 15:37 - 2012-12-24 09:26 - 00156362 _____ C:\WINDOWS\system32\perfc007.dat
2014-01-11 15:37 - 2012-07-26 08:28 - 01748838 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2014-01-11 15:36 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\NDF
2014-01-11 15:30 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2014-01-11 15:29 - 2013-07-10 12:58 - 00001158 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1345534544-3441952132-2937486482-1002UA.job
2014-01-11 15:26 - 2013-12-28 13:25 - 00000330 _____ C:\WINDOWS\Tasks\MySearchDial.job
2014-01-11 15:25 - 2013-05-22 00:24 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1345534544-3441952132-2937486482-1002
2014-01-11 15:24 - 2013-08-07 14:04 - 00000000 ____D C:\Program Files (x86)\Steam
2014-01-11 15:22 - 2013-12-21 10:11 - 00000000 ____D C:\Users\Budller\AppData\Local\Adobe
2014-01-11 15:21 - 2013-11-22 18:13 - 00000000 ____D C:\Users\Budller\AppData\Local\LogMeIn Hamachi
2014-01-11 15:20 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\sru
2014-01-10 12:50 - 2013-09-11 16:05 - 00000634 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2014-01-10 12:50 - 2012-07-26 08:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-10 12:48 - 2012-07-26 06:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2014-01-09 21:35 - 2013-05-21 17:45 - 00000000 ____D C:\Users\Budller\AppData\Roaming\.minecraft
2014-01-09 19:27 - 2013-07-10 12:58 - 00001106 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1345534544-3441952132-2937486482-1002Core.job
2014-01-09 19:01 - 2013-09-21 16:32 - 00000000 ____D C:\Users\Budller\AppData\Roaming\Craften Terminal
2014-01-08 21:34 - 2013-05-21 20:20 - 00000000 ____D C:\Users\Budller\AppData\Roaming\Skype
2014-01-08 20:34 - 2013-05-21 20:19 - 00000000 ____D C:\ProgramData\Skype
2014-01-08 20:33 - 2014-01-08 20:33 - 00002699 _____ C:\Users\Public\Desktop\Skype.lnk
2014-01-08 20:33 - 2013-07-07 19:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2014-01-08 20:31 - 2014-01-08 20:30 - 35095200 _____ (Skype Technologies S.A.) C:\Users\Budller\Downloads\Skype611SetupFull.exe
2014-01-08 19:39 - 2014-01-08 19:36 - 953505980 _____ C:\Users\Budller\Documents\Minecraft Backup vom 08.01.2014.mvc
2014-01-06 10:14 - 2013-09-14 11:45 - 00000000 ____D C:\Users\Budller\AppData\Roaming\TS3Client
2014-01-05 02:12 - 2014-01-05 02:12 - 00000000 ____D C:\Crash
2014-01-05 00:35 - 2014-01-05 00:35 - 00000000 ____D C:\Users\Budller\AppData\Local\SCE
2014-01-05 00:34 - 2013-06-22 16:36 - 00080138 _____ C:\WINDOWS\DirectX.log
2014-01-05 00:29 - 2014-01-04 22:35 - 00000222 _____ C:\Users\Budller\Desktop\PlanetSide 2.url
2014-01-04 23:50 - 2014-01-04 23:41 - 00000000 ____D C:\Users\Budller\Planetside 2
2014-01-04 20:09 - 2013-05-22 00:18 - 00000000 ____D C:\Users\Budller\AppData\Local\Packages
2014-01-04 00:25 - 2013-12-28 13:25 - 00000071 _____ C:\Users\Budller\AppData\Roaming\WB.CFG
2014-01-03 16:51 - 2014-01-03 16:51 - 00000222 _____ C:\Users\Budller\Desktop\Starbound.url
2014-01-03 14:38 - 2013-11-11 15:55 - 00000000 ____D C:\Users\Budller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-12-28 16:32 - 2013-12-28 16:32 - 35098272 _____ (Skype Technologies S.A.) C:\Users\Budller\Downloads\SkypeSetupFull.exe
2013-12-28 13:25 - 2013-12-28 13:25 - 00002664 _____ C:\WINDOWS\System32\Tasks\MySearchDial
2013-12-26 22:05 - 2013-12-26 22:05 - 00000221 _____ C:\Users\Budller\Desktop\Magicka.url
2013-12-26 10:18 - 2012-07-26 08:21 - 00048221 _____ C:\WINDOWS\setupact.log
2013-12-26 10:15 - 2013-12-26 10:14 - 05089728 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-26 10:10 - 2013-12-26 10:10 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2013-12-26 10:09 - 2013-12-26 10:09 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-26 10:07 - 2013-12-26 10:07 - 00000000 ____D C:\Users\Budller\Downloads\omegavesko-SimpleADBBackup-0790701
2013-12-25 12:27 - 2013-12-25 12:23 - 00000000 ____D C:\Users\Budller\AppData\Local\DayZ
2013-12-25 12:23 - 2013-12-25 12:23 - 00000000 ____D C:\Users\Budller\Documents\DayZ
2013-12-25 11:37 - 2013-12-25 11:37 - 00000222 _____ C:\Users\Budller\Desktop\DayZ.url
2013-12-21 23:07 - 2013-12-21 23:07 - 00320632 _____ (QuickSet) C:\Users\Budller\Downloads\minecraftdl_1659.exe
2013-12-21 10:56 - 2013-12-21 10:56 - 00000000 ____D C:\Users\Budller\.android
2013-12-21 10:56 - 2013-05-22 00:19 - 00000000 ____D C:\Users\Budller\AppData\Roaming\Adobe
2013-12-21 10:55 - 2013-12-21 10:55 - 00003518 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-SimonsGamingPC-Budller
2013-12-21 10:55 - 2013-12-21 10:55 - 00000000 ____D C:\Users\Budller\AppData\Roaming\PDAppFlex
2013-12-21 10:55 - 2013-12-21 10:54 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-12-21 10:48 - 2013-12-21 10:33 - 00000000 ____D C:\Program Files\Adobe
2013-12-21 10:47 - 2013-12-21 10:47 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2013-12-21 10:47 - 2013-12-21 10:47 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2013-12-21 10:47 - 2013-12-21 10:15 - 00000000 ____D C:\ProgramData\Adobe
2013-12-21 10:47 - 2013-12-21 10:12 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-12-21 10:36 - 2013-12-21 10:34 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-12-21 10:13 - 2013-12-21 10:13 - 00001074 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2013-12-21 10:11 - 2013-12-21 10:11 - 02844536 _____ (Adobe Systems Incorporated) C:\Users\Budller\Downloads\CreativeCloudSet-Up.exe
2013-12-17 20:25 - 2013-12-17 20:25 - 00004886 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log
2013-12-17 20:25 - 2013-12-17 20:25 - 00000000 ____D C:\ProgramData\Oracle
2013-12-17 20:25 - 2013-07-25 06:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-12-17 19:25 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\rescache
2013-12-17 16:01 - 2012-10-10 00:08 - 00045590 _____ C:\WINDOWS\PFRO.log
2013-12-16 21:57 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2013-12-15 19:52 - 2013-08-02 08:12 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-15 19:51 - 2013-05-22 14:00 - 90708896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-12-15 19:50 - 2012-07-26 06:38 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-12-15 19:35 - 2013-05-21 19:08 - 00000000 ____D C:\Program Files\Microsoft Office 15
Some content of TEMP:
====================
C:\Users\Budller\AppData\Local\Temp\101e357447ef18aa8e5c2fbf1e90d297.dll
C:\Users\Budller\AppData\Local\Temp\57817uninstall.exe
C:\Users\Budller\AppData\Local\Temp\APNSetup.exe
C:\Users\Budller\AppData\Local\Temp\BingBarSetup-Partner.exe
C:\Users\Budller\AppData\Local\Temp\CheatEngine63Clean.exe
C:\Users\Budller\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Budller\AppData\Local\Temp\DeltaTB.exe
C:\Users\Budller\AppData\Local\Temp\dxwebsetup.exe
C:\Users\Budller\AppData\Local\Temp\instloffer.exe
C:\Users\Budller\AppData\Local\Temp\jansi-64-git-Bukkit-1.5.2-R1.0-30-g74f60d8-b2818jnks.dll
C:\Users\Budller\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Budller\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Budller\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Budller\AppData\Local\Temp\pricepeep_130001_0101.exe
C:\Users\Budller\AppData\Local\Temp\riftuninstall.exe
C:\Users\Budller\AppData\Local\Temp\setup_fsu_cid.exe
C:\Users\Budller\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Budller\AppData\Local\Temp\Sqlite3.dll
C:\Users\Budller\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Budller\AppData\Local\Temp\uninst1.exe
C:\Users\Budller\AppData\Local\Temp\Xvid.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-07 12:07
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-01-2014 03
Ran by Budller at 2014-01-11 15:56:03
Running from C:\Users\Budller\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe AIR (x32 Version: 3.8.0.1430 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.8.0.1430 - Adobe Systems Incorporated) Hidden
Adobe Creative Cloud (x32 Version: 2.3.0.322 - Adobe Systems Incorporated)
Adobe InDesign CC (x32 Version: 9.0 - Adobe Systems Incorporated)
Adobe® Content Viewer (x32 Version: 3.3.0 - Adobe Systems Incorporated)
Adobe® Content Viewer (x32 Version: 3.3.0 - Adobe Systems Incorporated) Hidden
AirMech (x32 Version: - GamersFirst)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.7 - Atheros Communications Inc.)
Audacity 2.0.5 (x32 Version: 2.0.5 - Audacity Team)
Benutzerhandbuch (x32 Version: 1.0.0.9 - Lenovo) Hidden
Brick-Force (x32 Version: - Infernum Productions AG)
Bundled software uninstaller (x32 Version: - ) <==== ATTENTION
Canon My Printer (x32 Version: 3.1.0 - Canon Inc.)
Cheat Engine 6.3 (x32 Version: - Cheat Engine)
Craften Terminal 3.4.5 (x32 Version: 3.4.5 - Craften.de)
Creative Systeminformationen (x32 Version: 1.10 - Creative Technology Limited)
Cube World version 0.0.1 (x32 Version: 0.0.1 - Picroma)
DayZ (x32 Version: - Bohemia Interactive)
Dolby Home Theater v4 (x32 Version: 7.2.8000.16 - Dolby Laboratories Inc)
Energy Management (x32 Version: 8.0.2.4 - Lenovo)
Energy Management (x32 Version: 8.0.2.4 - Lenovo) Hidden
FlvPlayer (x32 Version: ${VERSION} - )
Fraps (x32 Version: - )
Gameforge Live 1.9.0 "Legend" (x32 Version: 1.9.0 - Gameforge)
GamersFirst LIVE! (HKCU Version: - GamersFirst)
Google Chrome (HKCU Version: 31.0.1650.63 - Google Inc.)
Hawken (HKCU Version: - Meteor Entertainment)
Intel AppUp(SM) center (x32 Version: 3.6.1.33057.10 - Intel)
Intel PROSet Wireless (Version: - ) Hidden
Intel(R) Control Center (x32 Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (x32 Version: 9.17.10.2843 - Intel Corporation)
Intel(R) Rapid Storage Technology (x32 Version: 11.5.4.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149 - Intel Corporation)
Intel(R) WiDi (Version: 3.5.40.0 - Intel Corporation)
Intel® PROSet/Wireless WiFi-Software (Version: 15.05.2000.1462 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Intelligent Touchpad (x32 Version: 2.00.0012.0723 - Lenovo)
Internet Manager (x32 Version: 22.001.18.19.55 - Huawei Technologies Co.,Ltd)
Java 7 Update 21 (64-bit) (Version: 7.0.210 - Oracle)
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JMicron Flash Media Controller Driver (x32 Version: 1.0.71.1 - JMicron Technology Corp.)
Lenovo Bluetooth with Enhanced Data Rate Software (Version: 12.0.0.3600 - Broadcom Corporation)
Lenovo EasyCamera (x32 Version: 6.2.8400.10189 - Realtek Semiconductor Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.0828 - CyberLink Corp.) Hidden
Lenovo OneKey Recovery (x32 Version: 8.0.0.0828 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.4331.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.4331.52 - CyberLink Corp.) Hidden
Lenovo YouCam (x32 Version: 4.1.3127 - CyberLink Corp.)
Lenovo YouCam (x32 Version: 4.1.3127 - CyberLink Corp.) Hidden
Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden
Logitech Gaming Software 8.46 (Version: 8.46.27 - Logitech Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.109 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.109 - LogMeIn, Inc.) Hidden
Magicka (x32 Version: - Arrowhead Game Studios)
Microsoft Office 365 Home Premium - de-de (Version: 15.0.4551.1011 - Microsoft Corporation)
Microsoft Silverlight (x32 Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU Version: 17.0.2003.1112 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation)
NVIDIA Grafiktreiber 306.97 (Version: 306.97 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.85.551 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.10.8 (Version: 1.10.8 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.12.0604 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.12.0604 (Version: 9.12.0604 - NVIDIA Corporation)
NVIDIA Systemsteuerung 306.97 (Version: 306.97 - NVIDIA Corporation) Hidden
NVIDIA Update 1.10.8 (Version: 1.10.8 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.10.8 - NVIDIA Corporation) Hidden
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4551.1011 - Microsoft Corporation) Hidden
Onekey Theater (x32 Version: 3.0.0.9 - Lenovo)
Pando Media Booster (x32 Version: 2.6.0.7 - Pando Networks Inc.)
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
PlanetSide 2 (x32 Version: - Sony Online Entertainment)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6680 - Realtek Semiconductor Corp.)
RIFT (HKCU Version: - Trion Worlds, Inc.)
S.K.I.L.L. - Special Force 2 (x32 Version: - )
Shared C Run-time for x64 (Version: 10.0.0 - McAfee)
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
SoftwareUpdater (x32 Version: - )
Sound Blaster Tactic(3D) Alpha (x32 Version: 1.0 - Creative Technology Limited)
Starbound (x32 Version: - )
Steam (x32 Version: 1.0.0.0 - Valve Corporation)
Synaptics Pointing Device Driver (Version: 16.2.15.1 - Synaptics Incorporated)
TeamSpeak 3 Client (Version: 3.0.13.1 - TeamSpeak Systems GmbH)
Terraria (x32 Version: - Re-Logic)
Update for MySearchDial (HKCU Version: - Update for MySearchDial) <==== ATTENTION
UserGuide (x32 Version: 1.0.0.9 - Lenovo)
VLC media player 2.0.8 (x32 Version: 2.0.8 - VideoLAN)
Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1 - Lenovo)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733 - Lenovo)
World of Warplanes (x32 Version: - Wargaming.net)
==================== Restore Points =========================
25-12-2013 10:13:11 Geplanter Prüfpunkt
26-12-2013 21:37:09 DirectX wurde installiert
26-12-2013 21:37:44 DirectX wurde installiert
28-12-2013 15:29:27 Removed Skype™ 6.11
04-01-2014 23:33:18 DirectX wurde installiert
08-01-2014 19:24:05 Removed Skype™ 6.11
==================== Hosts content: ==========================
2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {11F19840-25C3-4446-BCEA-7F6D2DFC1EA0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1345534544-3441952132-2937486482-1002UA => C:\Users\Budller\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-10] (Google Inc.)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {27591483-3F4E-40BB-873A-FD8298AECDA2} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {5E741E3F-292E-4687-8DCC-450B70F76CE0} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {667921C5-5DA1-422E-8C9D-960667EAB017} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2013-12-15] (Microsoft Corporation)
Task: {867A458C-A792-402B-941A-C352B9835308} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1345534544-3441952132-2937486482-1002Core => C:\Users\Budller\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-10] (Google Inc.)
Task: {9B3B676B-E3DE-44E3-BC23-E6978DE00F6D} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-11-02] (Microsoft Corporation)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {D8C056EF-4AB9-45C4-9CC0-EBAD9D47A566} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {F53353CE-2E6F-4947-8494-4AD79521410B} - System32\Tasks\MySearchDial => C:\Users\Budller\AppData\Roaming\mysearchdial\UpdateProc\UpdateTask.exe [2013-04-30] () <==== ATTENTION
Task: {FBB124CD-04D6-4FCC-8442-3FF068F2C97B} - System32\Tasks\AdobeAAMUpdater-1.0-SimonsGamingPC-Budller => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-12-10] (Adobe Systems Incorporated)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1345534544-3441952132-2937486482-1002Core.job => C:\Users\Budller\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1345534544-3441952132-2937486482-1002UA.job => C:\Users\Budller\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\MySearchDial.job => C:\Users\Budller\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2013-12-13 12:20 - 2013-12-13 12:20 - 03359600 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
2012-07-26 08:55 - 2012-07-26 08:53 - 00170864 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2012-08-31 06:54 - 2012-08-24 00:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-05-26 10:02 - 2013-05-26 10:01 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll
2013-05-26 10:02 - 2013-05-26 10:01 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll
2013-05-26 10:02 - 2013-05-26 10:01 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll
2013-05-26 10:02 - 2013-05-26 10:01 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll
2013-09-09 12:48 - 2013-09-09 12:48 - 00017920 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\9b61416a45a6322490dbb27382930695\PSIClient.ni.dll
2012-12-24 00:47 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-12-19 10:49 - 2013-12-19 10:49 - 32733080 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
2012-04-26 23:38 - 2012-04-26 23:38 - 20758016 _____ () C:\Users\Budller\AppData\Local\GamersFirst\LIVE!\libcef.dll
2013-12-04 20:23 - 2013-12-04 03:47 - 00702416 _____ () C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\libglesv2.dll
2013-12-04 20:23 - 2013-12-04 03:47 - 00099792 _____ () C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\libegl.dll
2013-12-04 20:23 - 2013-12-04 03:48 - 04055504 _____ () C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll
2013-12-04 20:23 - 2013-12-04 03:48 - 00399312 _____ () C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
2013-12-04 20:23 - 2013-12-04 03:47 - 01619408 _____ () C:\Users\Budller\AppData\Local\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:373E1720
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Could not start eventlog service, could not read events.
Der angeforderte Dienst wurde bereits gestartet.
Sie erhalten weitere Hilfe, wenn Sie NET HELPMSG 2182 eingeben.
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 8057.77 MB
Available physical RAM: 5733.66 MB
Total Pagefile: 9721.77 MB
Available Pagefile: 7375.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:884.18 GB) (Free:770.31 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.92 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 20D814ED)
Partition: GPT Partition Type
==================== End Of Log ============================ Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2014-01-11 16:05:24
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000041 ST1000LM024_HN-M101MBB rev.2AR10001 931,51GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Budller\AppData\Local\Temp\kwtcypob.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960000bc100 7 bytes [40, 4F, 82, 01, 00, 51, F2]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 8 fffff960000bc108 7 bytes [01, 15, C0, FF, 00, 12, DB]
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\spoolsv.exe[1768] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\System32\spoolsv.exe[1768] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\system32\BtwRSupportService.exe[1984] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\BtwRSupportService.exe[1984] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\BtwRSupportService.exe[1984] C:\WINDOWS\system32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1452] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1452] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1452] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1452] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1452] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1452] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fd53681b32 4 bytes [68, 53, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1452] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fd53681b3a 4 bytes [68, 53, FD, 07]
.text C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe[2932] C:\WINDOWS\system32\PsApi.dll!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe[2932] C:\WINDOWS\system32\PsApi.dll!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe[2976] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe[2976] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3048] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3048] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3048] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3048] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[3048] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3236] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3236] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3236] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3236] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3236] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe[3436] C:\WINDOWS\system32\PsApi.dll!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe[3436] C:\WINDOWS\system32\PsApi.dll!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3668] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3668] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3668] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3668] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3668] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1240] C:\WINDOWS\system32\psapi.dll!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1240] C:\WINDOWS\system32\psapi.dll!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\System32\LogonUI.exe[3956] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\System32\LogonUI.exe[3956] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\System32\LogonUI.exe[3956] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2720] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2720] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2720] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[872] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[872] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[872] C:\WINDOWS\system32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[872] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[872] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\Explorer.EXE[4104] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fd53681b32 4 bytes [68, 53, FD, 07]
.text C:\WINDOWS\Explorer.EXE[4104] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fd53681b3a 4 bytes [68, 53, FD, 07]
.text C:\WINDOWS\Explorer.EXE[4104] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\Explorer.EXE[4104] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6748] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6748] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6748] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Windows\System32\igfxpers.exe[4572] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Windows\System32\igfxpers.exe[4572] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4232] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4232] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6000] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6000] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3276] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3276] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3276] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[5748] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[5748] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[5748] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe[88] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe[88] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe[88] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6732] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6732] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6732] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[4260] C:\WINDOWS\system32\psapi.dll!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[4260] C:\WINDOWS\system32\psapi.dll!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4400] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4400] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4400] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4400] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fd53681b32 4 bytes [68, 53, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4400] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fd53681b3a 4 bytes [68, 53, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4400] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[4400] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[6524] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007fd53681b32 4 bytes [68, 53, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[6524] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007fd53681b3a 4 bytes [68, 53, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[6524] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[6524] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[6524] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\WLANExt.exe[5180] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fd5e02177a 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\system32\WLANExt.exe[5180] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fd5e021782 4 bytes [02, 5E, FD, 07]
.text C:\WINDOWS\system32\WLANExt.exe[5180] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 690 000007fd57d81532 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\WLANExt.exe[5180] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 698 000007fd57d8153a 4 bytes [D8, 57, FD, 07]
.text C:\WINDOWS\system32\WLANExt.exe[5180] C:\WINDOWS\system32\MSIMG32.dll!TransparentBlt + 246 000007fd57d8165a 4 bytes [D8, 57, FD, 07]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [6500:5292] fffff9600095d5e8
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Als Anhang noch ein Screenshot vom Prüfergebnis des WindowsDefender.
Danke für die Hilfe!
Lg
baumgti |