Spartacus666 | 06.10.2015 17:11 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Error, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Update, Bad md5 or size: akadomains, 11,
Error, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Update, Bad md5 or size: akaips, 11,
Update, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Manual, AKA Domain Database, 0.0.0.0, 2015.9.11.2,
Update, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Manual, AKA IP Database, 0.0.0.0, 2015.9.11.2,
Update, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Manual, Domain Database, 0.0.0.0, 2015.10.6.3,
Update, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Manual, IP Database, 0.0.0.0, 2015.10.6.2,
Update, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Manual, Remediation Database, 2015.5.13.1, 2015.9.30.1,
Update, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Manual, Rootkit Database, 2015.6.2.1, 2015.10.6.1,
Update, 06.10.2015 15:59, SYSTEM, BIRK-LAPTOP, Manual, Malware Database, 2015.6.3.3, 2015.10.6.3,
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 10 Home x64
Ran by Birk on 06.10.2015 at 17:23:26,01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully deleted: [Service] drvagent64 [Reboot required]
~~~ Tasks
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\Gniguiluss
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\QQBrowser Udpater Task
Successfully deleted: [Task] C:\WINDOWS\system32\tasks\QQBrowser Udpater Task(Core)
Successfully deleted: [Task] C:\WINDOWS\Tasks\QQBrowser Udpater Task(Core).job
Successfully deleted: [Task] C:\WINDOWS\Tasks\QQBrowser Udpater Task.job
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
~~~ Files
Successfully deleted: [File] C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
~~~ Folders
Successfully deleted: [Folder] C:\Users\Birk\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Users\Birk\Appdata\Local\installer
Successfully deleted: [Folder] C:\Users\Birk\Appdata\LocalLow\company
Successfully deleted: [Folder] C:\Users\Public\qiyi
Successfully deleted: [Folder] C:\WINDOWS\SysWOW64\ai_recyclebin
Successfully deleted: [Folder] C:\ProgramData\uiksdl201591916
~~~ FireFox
Successfully deleted the following from C:\Users\Birk\AppData\Roaming\mozilla\firefox\profiles\aasdbd5n.default-1443433894913\prefs.js
user_pref(extensions.a6a1a03975fde4c8690f6b883c36bc17d88519bfe704d8cae3851239com74253.74253.internaldb.__ICM_LITE__fifty_test_rules.value, %7B%22DE%22%3A%7B%22ALL%22%3A%5B%
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.10.2015 at 17:27:59,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:27-09-2015 01
durchgeführt von Birk (Administrator) auf BIRK-LAPTOP (06-10-2015 17:31:32)
Gestartet von C:\Users\Birk\Downloads
Geladene Profile: Birk (Verfügbare Profile: UpdatusUser & Birk & Administrator & Gast)
Platform: Windows 10 Home (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Preventon Technologies Limited) C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVWatchService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Preventon Technologies Limited) C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVScanningService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [10590208 2013-03-14] (Broadcom Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3928264 2015-05-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8358680 2015-06-01] (Piriform Ltd)
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\...\Run: [Speech Recognition] => C:\WINDOWS\Speech\Common\sapisvr.exe [45056 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\...\MountPoints2: {461c7f39-cef7-11e3-824f-806e6f6e6963} - "D:\autorun.exe"
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\...\MountPoints2: {73e2bd98-6cc4-11e3-be74-0c84dcf636ac} - "E:\pushinst.exe"
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\...\MountPoints2: {ccb30605-9e88-11e4-be8a-0c84dcf636ac} - "F:\pushinst.exe"
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> none
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [Fatlfn] -> {646BAAE7-7538-4866-8EEE-974C0AA910AB} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => Keine Datei
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => Keine Datei
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
Tcpip\..\Interfaces\{75c84c69-d965-405d-9cde-0a6bf9d640f2}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{84d1984e-0943-4b0c-9323-5c23cffcdbae}: [NameServer] 192.168.178.1
Tcpip\..\Interfaces\{d10eb9e6-1147-4f35-b422-fb6163ee8e33}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{d10eb9e6-1147-4f35-b422-fb6163ee8e33}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130878428700418758&GUID=58F89681-4E70-4E55-A70E-4D8AAA245A35
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130878428710246746&GUID=58F89681-4E70-4E55-A70E-4D8AAA245A35
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130878428700441451&GUID=58F89681-4E70-4E55-A70E-4D8AAA245A35
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130878428700447701&GUID=58F89681-4E70-4E55-A70E-4D8AAA245A35
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130878650832125081&GUID=58F89681-4E70-4E55-A70E-4D8AAA245A35
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://vaioportal.sony.eu
HKU\S-1-5-21-2214603426-1893447350-2076376546-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://vaioportal.sony.eu
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2214603426-1893447350-2076376546-1002 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2214603426-1893447350-2076376546-1002 -> {F33BECA0-6B78-4D55-A67E-587BABFA0F3F} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-&_nkw={searchTerms}
FireFox:
========
FF ProfilePath: C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\aasdbd5n.default-1443433894913
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-10-01] ()
FF Plugin: @java.com/DTPlugin,version=10.13.2 -> C:\Windows\system32\npDeployJava1.dll [2013-09-03] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.13.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-09-03] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-10-01] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-01-23] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-01-23] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-09-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-09-03] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin-x32: @rising.com.cn/nprising -> C:\Program Files (x86)\Rising\RAV\nprising.dll [Keine Datei]
FF Plugin-x32: Adobe Reader -> c:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2214603426-1893447350-2076376546-1002: @rising.com.cn/nprising -> C:\Program Files (x86)\Rising\RAV\nprising.dll Keine Datei
FF Plugin HKU\S-1-5-21-2214603426-1893447350-2076376546-1002: intel.com/AppUp -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll [2013-02-19] (Intel)
FF Plugin HKU\S-1-5-21-2214603426-1893447350-2076376546-1002: intel.com/AppUpx64 -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll [2013-02-19] (Intel)
FF Extension: fbchathistoryfirechmcom - C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\aasdbd5n.default-1443433894913\Extensions\fbchathistory@firechm.com [2015-10-01]
FF Extension: resteasyquickmediasolutionscom - C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\aasdbd5n.default-1443433894913\Extensions\rest-easy@quickmediasolutions.com [2015-10-01]
FF Extension: SilentBlockschuzakjp - C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\aasdbd5n.default-1443433894913\Extensions\SilentBlock@schuzak.jp [2015-10-01]
FF Extension: A5475360A7EA437b9A7929208F476940 - C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\aasdbd5n.default-1443433894913\Extensions\{A5475360-A7EA-437b-9A79-29208F476940} [2015-10-01]
FF Extension: AF445D67154C4c69A17B7F392BCC36A3 - C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\aasdbd5n.default-1443433894913\Extensions\{AF445D67-154C-4c69-A17B-7F392BCC36A3} [2015-10-01]
FF Extension: Adblock Plus - C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\aasdbd5n.default-1443433894913\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-28]
FF HKLM-x32\...\Firefox\Extensions: [arthurj8283@gmail.com] - C:\Users\Birk\AppData\Roaming\Mozilla\Firefox\Profiles\bh8meza8.default-1425064794684\extensions\arthurj8283@gmail.com => nicht gefunden
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\browser\defaults\preferences\prefs.js [2015-09-27]
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R2 AV Engine Scanning Service; C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVScanningService.exe [2009912 2015-07-27] (Preventon Technologies Limited)
R2 AV Watch Service; C:\Program Files (x86)\Common Files\Common Toolkit Suite\AVEngine\AVWatchService.exe [400528 2015-07-27] (Preventon Technologies Limited)
S2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [Datei ist nicht signiert]
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2015-03-27] (Broadcom Corporation.)
S2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2015-09-02] (Hi-Rez Studios) [Datei ist nicht signiert]
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319888 2015-07-11] (Intel Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129824 2013-01-23] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166688 2013-01-23] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 NetworkSupport; C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe [629336 2013-09-28] (Sony Corporation)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3611808 2015-07-22] (INCA Internet Co., Ltd.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [972000 2013-01-06] (Sony Corporation)
S3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [6070272 2013-03-14] (Broadcom Corporation) [Datei ist nicht signiert]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 AVFSFilter; C:\Windows\system32\DRIVERS\avfsfilter.sys [13720 2015-07-27] ()
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [173312 2015-03-27] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7488176 2015-04-13] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [237568 2015-07-10] (Microsoft Corporation)
S3 dump_wmimmc; C:\Users\Birk\Desktop\Sonstiges\Tools\GameforgeLive\Metin 2\GameforgeLive\Games\DEU_deu\Metin2\GameGuard\dump_wmimmc.sys [183144 2015-09-04] ()
R3 fwlanusbn; C:\Windows\system32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH)
S3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-02-17] (LogMeIn Inc.)
R1 HyperVM; C:\WINDOWS\system32\drivers\hvm.sys [41784 2015-09-19] (Beijing Rising Information Technology Co., Ltd.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R1 rsutils; C:\Windows\System32\DRIVERS\rsutils.sys [71760 2015-04-09] (Beijing Rising Information Technology Co., Ltd.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-05-27] (Synaptics Incorporated)
R0 sysmon; C:\Windows\System32\DRIVERS\sysmon.sys [119168 2015-09-19] (Beijing Rising Information Technology Co., Ltd.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-06 17:27 - 2015-10-06 17:27 - 00002091 _____ C:\Users\Birk\Desktop\JRT.txt
2015-10-06 17:22 - 2015-10-06 17:23 - 01798976 _____ (Malwarebytes) C:\Users\Birk\Downloads\JRT.exe
2015-10-06 17:13 - 2015-10-06 17:13 - 00016148 _____ C:\WINDOWS\system32\BIRK-LAPTOP_Birk_HistoryPrediction.bin
2015-10-06 17:07 - 2015-10-06 17:07 - 00000923 _____ C:\Users\Birk\Desktop\mbam.txt
2015-10-06 15:58 - 2015-10-06 15:59 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-10-06 15:58 - 2015-10-06 15:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-10-06 15:58 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-10-06 15:58 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-06 15:58 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-06 15:56 - 2015-10-06 15:58 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Birk\Downloads\mbam-setup-2.1.8.1057.exe
2015-10-06 12:37 - 2015-10-06 12:37 - 00069907 ____C C:\Users\Birk\Desktop\FRST_06-10-2015_12-37-03.txt
2015-10-06 12:37 - 2015-10-06 12:37 - 00048512 ____C C:\Users\Birk\Desktop\Addition_06-10-2015_12-37-03.txt
2015-10-06 12:35 - 2015-10-06 12:36 - 00380416 _____ C:\Users\Birk\Downloads\Gmer-19357.exe
2015-10-06 12:29 - 2015-10-06 12:29 - 02193920 _____ (Farbar) C:\Users\Birk\Downloads\FRST64(1).exe
2015-10-06 12:28 - 2015-10-06 12:29 - 00000470 _____ C:\Users\Birk\Downloads\defogger_disable.log
2015-10-06 12:28 - 2015-10-06 12:28 - 00050477 _____ C:\Users\Birk\Downloads\Defogger.exe
2015-10-06 12:28 - 2015-10-06 12:28 - 00000000 _____ C:\Users\Birk\defogger_reenable
2015-10-06 11:43 - 2015-10-06 11:43 - 00688992 ____R (Swearware) C:\Users\Birk\Downloads\dds.com
2015-10-06 11:15 - 2015-10-06 11:15 - 00000795 _____ C:\WINDOWS\setupact.log
2015-10-06 11:15 - 2015-10-06 11:15 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-05 18:41 - 2015-10-05 18:41 - 707215728 _____ C:\WINDOWS\MEMORY.DMP
2015-10-05 18:41 - 2015-10-05 18:41 - 00357784 _____ C:\WINDOWS\Minidump\100515-33640-01.dmp
2015-10-03 13:35 - 2015-10-03 13:35 - 00000000 ____D C:\ProgramData\Rising
2015-10-03 13:28 - 2015-10-03 13:28 - 09907448 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RsCRIcon.dll
2015-10-03 13:28 - 2015-10-03 13:28 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-10-01 17:57 - 2015-10-06 17:14 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-01 17:57 - 2015-09-15 18:12 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-01 17:57 - 2015-09-15 18:12 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-01 17:55 - 2015-10-06 17:11 - 00015580 _____ C:\WINDOWS\PFRO.log
2015-10-01 17:55 - 2015-10-01 17:56 - 00223736 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-01 15:50 - 2015-10-01 15:51 - 36282350 _____ C:\Users\Birk\Downloads\install_flash_player_19.zip
2015-10-01 15:48 - 2015-10-01 15:48 - 01152716 _____ C:\Users\Birk\Downloads\2938740_hd.mp4.crdownload
2015-09-30 22:00 - 2015-09-17 08:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-09-30 22:00 - 2015-09-17 08:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-09-30 22:00 - 2015-09-17 08:12 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-09-30 22:00 - 2015-09-17 08:07 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-30 22:00 - 2015-09-17 08:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-09-30 22:00 - 2015-09-17 08:00 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-30 22:00 - 2015-09-17 07:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-09-30 22:00 - 2015-09-17 07:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-09-30 22:00 - 2015-09-17 07:51 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-09-30 22:00 - 2015-09-17 07:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-09-30 22:00 - 2015-09-17 07:47 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-09-30 22:00 - 2015-09-17 07:45 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-30 22:00 - 2015-09-17 07:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-09-30 22:00 - 2015-09-17 07:37 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-30 22:00 - 2015-09-17 07:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-09-30 21:59 - 2015-09-25 02:13 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-09-30 21:59 - 2015-09-25 01:17 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-09-30 21:59 - 2015-09-25 01:06 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-09-30 21:59 - 2015-09-25 01:01 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-09-30 21:59 - 2015-09-25 01:00 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-09-30 21:59 - 2015-09-25 00:42 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-09-30 21:59 - 2015-09-25 00:25 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-09-30 21:59 - 2015-09-25 00:25 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-09-30 21:59 - 2015-09-17 08:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-09-30 21:59 - 2015-09-17 08:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-09-30 21:59 - 2015-09-17 08:49 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-09-30 21:59 - 2015-09-17 08:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-09-30 21:59 - 2015-09-17 08:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-09-30 21:59 - 2015-09-17 08:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-09-30 21:59 - 2015-09-17 08:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-09-30 21:59 - 2015-09-17 08:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-09-30 21:59 - 2015-09-17 08:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-09-30 21:59 - 2015-09-17 08:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-09-30 21:59 - 2015-09-17 08:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-09-30 21:59 - 2015-09-17 08:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-09-30 21:59 - 2015-09-17 08:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-09-30 21:59 - 2015-09-17 08:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-09-30 21:59 - 2015-09-17 08:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-09-30 21:59 - 2015-09-17 08:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-09-30 21:59 - 2015-09-17 08:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-09-30 21:59 - 2015-09-17 08:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-09-30 21:59 - 2015-09-17 08:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-09-30 21:59 - 2015-09-17 08:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-09-30 21:59 - 2015-09-17 08:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-09-30 21:59 - 2015-09-17 08:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-09-30 21:59 - 2015-09-17 08:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-09-30 21:59 - 2015-09-17 08:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-09-30 21:59 - 2015-09-17 08:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-09-30 21:59 - 2015-09-17 08:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-09-30 21:59 - 2015-09-17 08:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-09-30 21:59 - 2015-09-17 08:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-09-30 21:59 - 2015-09-17 07:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-09-30 21:59 - 2015-09-17 07:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-09-30 21:59 - 2015-09-17 07:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-09-30 21:59 - 2015-09-17 07:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-09-30 21:59 - 2015-09-17 07:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-09-30 21:59 - 2015-09-17 07:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-09-30 21:59 - 2015-09-17 07:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-09-30 21:59 - 2015-09-17 07:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-09-30 21:59 - 2015-09-17 07:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-09-30 21:59 - 2015-09-17 07:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-09-30 21:59 - 2015-09-17 07:45 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-09-30 21:59 - 2015-09-17 07:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-09-30 21:59 - 2015-09-17 07:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-09-30 21:59 - 2015-09-17 07:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-09-30 21:59 - 2015-09-17 07:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-09-30 21:59 - 2015-09-17 07:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-09-30 21:59 - 2015-09-17 07:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-09-30 21:59 - 2015-09-17 07:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-09-30 21:59 - 2015-09-17 07:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-09-30 21:59 - 2015-09-17 07:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-09-30 21:59 - 2015-09-17 07:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-09-30 21:59 - 2015-09-17 07:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-09-30 21:59 - 2015-09-17 07:32 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-09-30 21:59 - 2015-09-17 07:31 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-09-30 21:59 - 2015-09-17 07:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-09-30 21:59 - 2015-09-17 07:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-09-30 21:59 - 2015-09-13 04:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-09-30 21:58 - 2015-09-25 01:24 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-09-30 21:58 - 2015-09-25 01:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-09-30 21:58 - 2015-09-25 01:23 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-30 21:58 - 2015-09-25 01:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-30 21:58 - 2015-09-25 01:07 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-30 21:58 - 2015-09-25 01:05 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-09-30 21:58 - 2015-09-25 01:01 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-09-30 21:58 - 2015-09-25 01:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-09-30 21:58 - 2015-09-25 01:00 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-09-30 21:58 - 2015-09-25 00:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-09-30 21:58 - 2015-09-25 00:43 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-09-30 21:58 - 2015-09-25 00:43 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-09-30 21:58 - 2015-09-25 00:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-09-30 21:58 - 2015-09-25 00:25 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-09-30 21:58 - 2015-09-25 00:25 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-09-30 21:58 - 2015-09-25 00:19 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-09-30 21:58 - 2015-09-19 07:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-09-30 21:58 - 2015-09-17 08:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-09-30 21:58 - 2015-09-17 08:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-09-30 21:58 - 2015-09-17 08:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-09-30 21:58 - 2015-09-17 08:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-09-30 21:58 - 2015-09-17 08:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-09-30 21:58 - 2015-09-17 08:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-09-30 21:58 - 2015-09-17 08:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-09-30 21:58 - 2015-09-17 08:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-09-30 21:58 - 2015-09-17 08:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-09-30 21:58 - 2015-09-17 08:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-09-30 21:58 - 2015-09-17 08:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-09-30 21:58 - 2015-09-17 08:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-09-30 21:58 - 2015-09-17 08:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-09-30 21:58 - 2015-09-17 08:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-09-30 21:58 - 2015-09-17 08:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-09-30 21:58 - 2015-09-17 08:39 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-30 21:58 - 2015-09-17 08:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-09-30 21:58 - 2015-09-17 08:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-09-30 21:58 - 2015-09-17 08:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-09-30 21:58 - 2015-09-17 08:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-09-30 21:58 - 2015-09-17 08:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-09-30 21:58 - 2015-09-17 08:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-09-30 21:58 - 2015-09-17 08:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-09-30 21:58 - 2015-09-17 08:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-09-30 21:58 - 2015-09-17 08:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-09-30 21:58 - 2015-09-17 08:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-09-30 21:58 - 2015-09-17 08:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-09-30 21:58 - 2015-09-17 08:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-09-30 21:58 - 2015-09-17 08:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-09-30 21:58 - 2015-09-17 08:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-09-30 21:58 - 2015-09-17 08:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-09-30 21:58 - 2015-09-17 08:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-09-30 21:58 - 2015-09-17 08:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-09-30 21:58 - 2015-09-17 08:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-09-30 21:58 - 2015-09-17 08:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-09-30 21:58 - 2015-09-17 08:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-09-30 21:58 - 2015-09-17 08:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-09-30 21:58 - 2015-09-17 08:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-09-30 21:58 - 2015-09-17 08:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-09-30 21:58 - 2015-09-17 07:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-09-30 21:58 - 2015-09-17 07:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-09-30 21:58 - 2015-09-17 07:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-09-30 21:58 - 2015-09-17 07:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-09-30 21:58 - 2015-09-17 07:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-09-30 21:58 - 2015-09-17 07:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-09-30 21:58 - 2015-09-17 07:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-09-30 21:58 - 2015-09-17 07:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-09-30 21:58 - 2015-09-17 07:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-09-30 21:58 - 2015-09-17 07:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-09-30 21:58 - 2015-09-17 07:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-09-30 21:58 - 2015-09-17 07:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-09-30 21:58 - 2015-09-17 07:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-09-30 21:58 - 2015-09-17 07:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-09-30 21:58 - 2015-09-17 07:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-09-30 21:58 - 2015-09-17 07:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-09-30 21:58 - 2015-09-17 07:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-09-30 21:58 - 2015-09-17 07:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-09-30 21:58 - 2015-09-17 07:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-09-30 21:58 - 2015-09-17 07:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-09-30 21:58 - 2015-09-17 07:50 - 00929280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-09-30 21:58 - 2015-09-17 07:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-09-30 21:58 - 2015-09-17 07:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-09-30 21:58 - 2015-09-17 07:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-09-30 21:58 - 2015-09-17 07:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-09-30 21:58 - 2015-09-17 07:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-09-30 21:58 - 2015-09-17 07:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-09-30 21:58 - 2015-09-17 07:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-09-30 21:58 - 2015-09-17 07:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-09-30 21:58 - 2015-09-17 07:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-09-30 21:58 - 2015-09-17 07:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-09-30 21:58 - 2015-09-17 07:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-09-30 21:58 - 2015-09-17 07:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-09-30 21:58 - 2015-09-17 07:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-09-30 21:58 - 2015-09-17 07:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-09-30 21:58 - 2015-09-17 07:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-09-30 21:58 - 2015-09-17 07:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-09-30 21:58 - 2015-09-17 07:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-09-30 21:58 - 2015-09-17 07:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-09-30 21:58 - 2015-09-17 07:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-09-30 21:58 - 2015-09-17 07:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-09-30 21:58 - 2015-09-17 07:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-09-30 21:58 - 2015-09-17 07:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-09-30 21:58 - 2015-09-17 07:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-09-30 21:58 - 2015-09-17 07:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-09-30 21:58 - 2015-09-17 07:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-09-30 21:58 - 2015-09-17 07:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-09-30 21:58 - 2015-09-17 07:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-09-30 21:58 - 2015-09-17 07:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-09-30 21:58 - 2015-09-17 07:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-09-30 21:58 - 2015-09-17 07:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-09-30 21:58 - 2015-09-17 07:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-09-30 21:58 - 2015-09-17 07:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-09-30 21:58 - 2015-09-17 07:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-09-30 21:58 - 2015-09-17 07:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-09-30 21:58 - 2015-09-17 07:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-09-30 21:58 - 2015-09-17 07:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-09-30 21:58 - 2015-09-17 07:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-09-30 21:58 - 2015-09-17 07:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-09-30 21:58 - 2015-09-17 07:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-09-30 21:58 - 2015-09-17 07:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-09-30 21:58 - 2015-09-17 07:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-09-30 21:58 - 2015-09-17 07:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-09-30 21:58 - 2015-09-17 07:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-09-30 21:58 - 2015-09-13 03:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-09-30 21:57 - 2015-09-25 02:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-09-30 21:57 - 2015-09-25 02:34 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-09-30 21:57 - 2015-09-25 01:34 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-09-30 21:57 - 2015-09-25 01:34 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-09-30 21:57 - 2015-09-25 01:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-09-30 21:57 - 2015-09-25 00:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-09-30 21:57 - 2015-09-17 08:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-09-30 21:57 - 2015-09-17 08:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-09-30 21:57 - 2015-09-17 08:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-09-30 21:57 - 2015-09-17 08:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-09-30 21:57 - 2015-09-17 08:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-09-30 21:57 - 2015-09-17 08:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-09-30 21:57 - 2015-09-17 08:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-09-30 21:57 - 2015-09-17 07:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-09-30 21:57 - 2015-09-17 07:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-09-30 21:57 - 2015-09-17 07:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-09-30 21:57 - 2015-09-17 07:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-09-30 21:57 - 2015-09-17 07:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-09-30 21:57 - 2015-09-17 07:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-09-30 21:57 - 2015-09-17 07:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-09-30 21:57 - 2015-09-17 07:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-09-30 21:57 - 2015-09-17 07:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-09-30 21:57 - 2015-09-17 07:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-09-30 21:57 - 2015-09-17 07:49 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-09-30 21:57 - 2015-09-17 07:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-09-30 21:57 - 2015-09-17 07:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-09-30 21:57 - 2015-09-17 07:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-09-30 21:57 - 2015-09-17 07:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-09-30 21:57 - 2015-09-17 07:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-09-30 21:57 - 2015-09-17 07:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-09-30 21:57 - 2015-09-17 07:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-09-30 21:57 - 2015-09-17 07:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-09-30 21:57 - 2015-09-17 07:33 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-09-30 21:57 - 2015-09-17 07:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-09-30 21:26 - 2015-09-30 21:25 - 00014080 _____ (Microsoft) C:\Users\Birk\AppData\Roaming\LaunchBrowser_ed.exe
2015-09-29 22:07 - 2015-10-06 17:15 - 00030639 _____ C:\WINDOWS\avmfwlanci.log
2015-09-28 20:52 - 2015-10-06 12:37 - 00048512 _____ C:\Users\Birk\Downloads\Addition.txt
2015-09-28 20:49 - 2015-10-06 17:31 - 00015630 _____ C:\Users\Birk\Downloads\FRST.txt
2015-09-28 20:49 - 2015-10-06 17:31 - 00000000 ___DC C:\FRST
2015-09-28 20:48 - 2015-09-28 20:49 - 02192384 _____ (Farbar) C:\Users\Birk\Downloads\FRST64.exe
2015-09-28 14:44 - 2015-09-28 14:44 - 00000000 ____D C:\Users\Birk\AppData\Local\ftblauncher
2015-09-28 11:41 - 2015-09-28 11:42 - 00912631 _____ C:\Users\Birk\Downloads\adblock_plus-2.6.10-an_sm_tb_fx.zip
2015-09-27 20:10 - 2015-09-27 20:10 - 00003276 _____ C:\WINDOWS\System32\Tasks\{19C21EC3-9429-4740-B815-79D2CC43123D}
2015-09-27 20:08 - 2015-09-27 20:08 - 00003388 _____ C:\WINDOWS\System32\Tasks\{F48EBD7B-8933-4080-9A67-B798F4097A09}
2015-09-27 20:04 - 2015-09-27 20:04 - 00003226 _____ C:\WINDOWS\System32\Tasks\{1691C428-799A-44EC-A3FA-5CF375BAD376}
2015-09-27 19:56 - 2015-09-27 21:07 - 00000000 ____D C:\Program Files (x86)\Feed Notifier
2015-09-27 16:01 - 2015-09-27 16:01 - 18819272 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-09-27 16:00 - 2015-09-27 16:00 - 00000000 ____D C:\Users\Birk\AppData\Local\Publishers
2015-09-22 22:06 - 2015-09-22 22:06 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-09-21 09:18 - 2015-09-28 00:31 - 00000000 ____D C:\Users\Birk\Documents\My Games
2015-09-21 09:17 - 2015-09-21 09:23 - 00000000 ____D C:\Users\Birk\AppData\Local\Darksiders2
2015-09-21 09:17 - 2015-09-21 09:17 - 00000000 ____D C:\Users\Birk\AppData\Local\Steam
2015-09-21 09:17 - 2015-09-21 09:17 - 00000000 ____D C:\Users\Birk\AppData\Local\CEF
2015-09-20 22:30 - 2015-09-28 21:17 - 00000000 ____D C:\Users\Birk\AppData\Local\VirtualStore
2015-09-20 17:38 - 2015-09-20 17:38 - 00000000 ____D C:\Users\Birk\AppData\Local\gegl-0.2
2015-09-20 06:46 - 2015-09-20 06:46 - 00000017 _____ C:\Users\Birk\AppData\Local\resmon.resmoncfg
2015-09-20 01:38 - 2015-09-28 20:33 - 00000000 ____D C:\WINDOWS\system32\log
2015-09-20 00:55 - 2015-09-20 00:55 - 00000000 ____D C:\Program Files (x86)\LucasArts
2015-09-20 00:36 - 2015-10-01 11:44 - 00000000 ____D C:\Users\Birk\AppData\Local\Adobe
2015-09-20 00:30 - 2015-09-25 15:15 - 00000000 ____D C:\Users\Birk\AppData\Roaming\Kalypso Media
2015-09-19 21:32 - 2015-09-19 21:24 - 00041784 ____N (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\hvm.sys
2015-09-19 21:32 - 2015-09-19 21:23 - 00119168 _____ (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\sysmon.sys
2015-09-19 21:25 - 2015-09-19 21:25 - 00000000 ____D C:\Users\Birk\AppData\Local\NetworkTiles
2015-09-19 21:10 - 2015-10-05 18:42 - 00000000 ____D C:\ProgramData\clp
2015-09-19 21:05 - 2015-09-19 21:05 - 00000000 ____D C:\ProgramData\Common Toolkit Suite
2015-09-19 21:02 - 2015-09-19 21:02 - 02381192 _____ (SPAMfighter ApS) C:\Users\Birk\Downloads\spywarefighter.exe
2015-09-19 19:16 - 2015-09-19 19:28 - 00000000 __RDC C:\RavBin
2015-09-19 19:16 - 2015-09-19 19:16 - 00003504 _____ C:\WINDOWS\System32\Tasks\RsDelayLauncher_{8A34248E-7D35-4832-8378-7659E0B0A380}
2015-09-19 19:16 - 2015-09-19 19:16 - 00000150 _RSHC C:\rising.ini
2015-09-19 19:16 - 2015-04-09 07:00 - 00071760 ____N (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\rsutils.sys
2015-09-19 19:16 - 2014-07-30 04:44 - 00091928 ____N (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\SysWOW64\vpatch.dll
2015-09-19 19:16 - 2014-01-02 09:37 - 00325400 ____N (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\system32\ravext64.dll
2015-09-19 19:16 - 2013-12-30 09:33 - 00256280 ____N (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\SysWOW64\ravext.dll
2015-09-19 19:16 - 2012-09-06 02:30 - 00240472 ____N (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\SysWOW64\bsmain.exe
2015-09-19 19:16 - 2012-02-29 09:49 - 00011888 ____N (Beijing Rising Information Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\rsndisp.sys
2015-09-19 18:41 - 2015-09-19 18:41 - 00000000 ____D C:\Users\Birk\AppData\Roaming\WB_CFG
2015-09-19 18:41 - 2015-09-19 18:41 - 00000000 _____ C:\ProgramData\inf.dat
2015-09-19 18:40 - 2015-10-06 17:30 - 00000462 _____ C:\WINDOWS\Tasks\Adobe Flash box Files Update Ver 2015919.job
2015-09-19 18:40 - 2015-09-20 06:46 - 00000000 ____D C:\ProgramData\4997GameBox_Data
2015-09-19 18:40 - 2015-09-19 18:41 - 00004824 _____ C:\WINDOWS\SysWOW64\Oatihpu.ini
2015-09-19 18:40 - 2015-09-19 18:41 - 00002536 _____ C:\WINDOWS\SysWOW64\OatihpuOff.ini
2015-09-19 18:40 - 2015-09-19 18:41 - 00002536 _____ C:\WINDOWS\system32\OatihpuOff.ini
2015-09-19 18:40 - 2015-09-19 18:40 - 00003614 _____ C:\WINDOWS\System32\Tasks\Adobe Flash box Files Update Ver 2015919
2015-09-19 18:40 - 2015-09-19 18:40 - 00000000 ____D C:\WINDOWS\system32\pap
2015-09-19 18:40 - 2015-09-19 18:40 - 00000000 ____D C:\Users\Birk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7k7k游戏盒子(919)
2015-09-19 18:40 - 2015-09-19 18:40 - 00000000 ____D C:\Users\Birk\AppData\Local\Tempfolder
2015-09-19 18:40 - 2015-09-19 18:40 - 00000000 ____D C:\ProgramData\adb
2015-09-19 18:39 - 2015-09-19 19:03 - 00000000 ____D C:\Users\Birk\AppData\Local\Unity
2015-09-19 18:38 - 2015-09-19 18:38 - 00000000 ____D C:\Users\Birk\AppData\Local\Sony Corporation
2015-09-19 18:37 - 2015-10-06 17:07 - 00000000 ____D C:\Program Files (x86)\baidu
2015-09-19 18:34 - 2015-09-19 19:56 - 00000000 ____D C:\Users\Birk\AppData\Local\Mozilla
2015-09-19 18:34 - 2015-09-19 18:34 - 00000000 ____D C:\Users\Birk\AppData\Local\Macromedia
2015-09-19 18:33 - 2015-09-20 01:54 - 00000000 ____D C:\Users\Birk\AppData\Roaming\Common
2015-09-19 18:30 - 2015-09-28 11:35 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-09-19 02:20 - 2013-08-22 15:25 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2015-09-19 02:18 - 2015-09-19 02:18 - 00000000 ____D C:\Users\Birk\AppData\Local\Geckofx
2015-09-18 01:19 - 2015-09-19 19:01 - 00000000 ____D C:\ProgramData\Screentime
2015-09-17 13:21 - 2015-09-17 13:21 - 00186880 _____ (TODO: <Company name>) C:\WINDOWS\system32\rsrcs.dll
2015-09-09 18:14 - 2015-08-27 08:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-09 18:14 - 2015-08-27 08:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-09 18:14 - 2015-08-27 07:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-09 18:14 - 2015-08-27 07:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-09 18:14 - 2015-08-27 07:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-09 18:14 - 2015-08-27 07:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-09 18:14 - 2015-08-27 07:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 18:14 - 2015-08-27 07:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-09 18:14 - 2015-08-27 07:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-09 18:14 - 2015-08-27 07:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-09 18:14 - 2015-08-27 07:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-09 18:14 - 2015-08-27 07:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-09 18:14 - 2015-08-27 07:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-09 18:14 - 2015-08-27 07:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-09 18:14 - 2015-08-27 07:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-09 18:14 - 2015-08-27 07:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-09 18:14 - 2015-08-27 07:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-09 18:14 - 2015-08-27 07:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-09 18:14 - 2015-08-27 07:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-09 18:14 - 2015-08-27 07:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-09 18:14 - 2015-08-27 07:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-09 18:14 - 2015-08-27 07:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-09 18:14 - 2015-08-27 07:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-09 18:14 - 2015-08-27 07:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-08 18:37 - 2015-09-08 18:37 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2015-09-07 20:58 - 2015-09-14 20:58 - 00000000 ____D C:\WINDOWS\System32\Tasks\NCH Software
2015-09-07 20:58 - 2015-09-07 20:58 - 00001259 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStage Diashow-Ersteller.lnk
2015-09-07 20:58 - 2015-09-07 20:58 - 00001229 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Audio-Editor.lnk
2015-09-07 20:58 - 2015-09-07 20:58 - 00001217 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Videodatei-Konverter.lnk
2015-09-07 20:58 - 2015-09-07 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Videoverwandte Programme
2015-09-07 20:57 - 2015-09-20 01:42 - 00000000 ____D C:\ProgramData\NCH Software
2015-09-07 20:57 - 2015-09-20 01:42 - 00000000 ____D C:\Program Files (x86)\NCH Software
2015-09-07 20:57 - 2015-09-08 20:31 - 00000000 ____D C:\Users\Birk\AppData\Roaming\NCH Software
2015-09-07 20:57 - 2015-09-07 20:57 - 00001245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoPad Video-Editor.lnk
2015-09-07 02:19 - 2015-09-07 02:19 - 00000939 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-09-07 02:18 - 2015-09-07 02:19 - 00000000 ____D C:\Program Files\GIMP 2
2015-09-07 01:22 - 2015-09-20 01:48 - 00000000 ____D C:\Users\Birk\.thumbnails
2015-09-07 01:16 - 2015-09-20 17:38 - 00000000 ____D C:\Users\Birk\.gimp-2.8
2015-09-07 01:08 - 2015-09-07 01:08 - 00000000 ____D C:\Users\Birk\AppData\Roaming\Avanquest Software
2015-09-06 21:02 - 2015-10-06 11:37 - 00000000 ____D C:\Program Files\OBS
2015-09-06 21:02 - 2015-10-06 11:37 - 00000000 ____D C:\Program Files (x86)\OBS
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2015-10-06 17:30 - 2014-02-23 13:35 - 00000000 ____D C:\Users\Birk\Desktop\Sonstiges
2015-10-06 17:23 - 2015-01-28 15:17 - 00004162 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{18F0F7A2-D14E-4364-A210-F284D1BA159C}
2015-10-06 17:12 - 2015-07-10 14:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-06 17:12 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-06 17:11 - 2015-07-10 11:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-06 17:08 - 2015-07-10 18:35 - 00000000 ____D C:\WINDOWS\SKB
2015-10-06 15:58 - 2014-12-30 17:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-10-06 15:53 - 2014-12-04 20:16 - 00000000 ____D C:\Program Files (x86)\Steam
2015-10-06 12:28 - 2015-08-05 22:41 - 00000000 ____D C:\Users\Birk
2015-10-06 11:23 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-06 11:20 - 2015-08-05 22:58 - 01790124 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-06 11:20 - 2015-07-10 18:34 - 00772342 _____ C:\WINDOWS\system32\perfh007.dat
2015-10-06 11:20 - 2015-07-10 18:34 - 00154170 _____ C:\WINDOWS\system32\perfc007.dat
2015-10-05 18:41 - 2015-09-03 19:36 - 00000000 ____D C:\WINDOWS\Minidump
2015-10-05 16:20 - 2015-04-26 14:29 - 00000000 ____D C:\Users\Birk\AppData\Roaming\.minecraft
2015-10-04 15:53 - 2015-08-28 17:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-10-03 17:04 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-03 13:37 - 2013-12-26 15:03 - 00000000 ___DC C:\Update
2015-10-03 13:28 - 2015-08-05 22:37 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2015-10-03 13:28 - 2015-06-04 06:05 - 00384760 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RtsPStor.sys
2015-10-03 13:28 - 2015-06-04 06:05 - 00100600 _____ (Realtek Semiconductor.) C:\WINDOWS\system32\RtCRX64.dll
2015-10-03 13:22 - 2014-04-16 10:22 - 00000000 ___DC C:\AdwCleaner
2015-10-03 13:02 - 2015-08-05 22:41 - 00000000 ___RD C:\Users\Birk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-01 17:57 - 2015-07-10 11:05 - 00000000 __RHD C:\Users\Default
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-01 17:53 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-01 17:52 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-01 15:23 - 2015-07-10 12:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-27 21:36 - 2015-01-12 17:06 - 00000000 ____D C:\Program Files\CCleaner
2015-09-27 20:06 - 2014-12-04 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-27 20:00 - 2013-09-03 01:59 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-24 23:32 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-22 08:38 - 2015-05-22 15:18 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-09-20 01:59 - 2013-09-03 01:46 - 00000000 ____D C:\Program Files (x86)\Sony
2015-09-20 01:59 - 2013-09-03 01:42 - 00000000 ____D C:\ProgramData\Sony Corporation
2015-09-20 01:59 - 2013-09-03 01:28 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-19 19:37 - 2014-12-03 18:57 - 00000000 ____D C:\Users\Birk\AppData\Local\Packages
2015-09-19 18:49 - 2015-07-18 10:19 - 00000085 _____ C:\WINDOWS\wininit.ini
2015-09-19 18:49 - 2015-05-22 15:18 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-09-19 18:40 - 2015-07-10 13:00 - 00680256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2015-09-19 18:40 - 2015-07-10 13:00 - 00534064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2015-09-19 00:52 - 2015-02-16 17:06 - 00000000 ____D C:\Program Files (x86)\Minecraft
2015-09-19 00:48 - 2015-08-05 23:22 - 00000000 ___RD C:\Users\Birk\OneDrive
2015-09-13 22:04 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2015-09-12 18:56 - 2015-07-20 20:20 - 00000000 ____D C:\Users\Birk\AppData\Roaming\.technic
2015-09-10 01:32 - 2015-07-10 18:46 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-09 18:28 - 2014-12-06 01:08 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-08 21:01 - 2015-08-05 23:25 - 00000000 ___DC C:\Windows.old
2015-09-08 18:37 - 2015-02-28 22:56 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2015-09-30 21:26 - 2015-09-30 21:26 - 0032038 _____ () C:\Users\Birk\AppData\Roaming\Edge.ico
2015-09-30 21:26 - 2015-09-30 21:25 - 0014080 _____ (Microsoft) C:\Users\Birk\AppData\Roaming\LaunchBrowser_ed.exe
2015-09-30 21:26 - 2015-09-30 21:25 - 0000182 _____ () C:\Users\Birk\AppData\Roaming\LaunchBrowser_ed.exe.config
2015-09-20 06:46 - 2015-09-20 06:46 - 0000017 _____ () C:\Users\Birk\AppData\Local\resmon.resmoncfg
2015-08-05 22:37 - 2015-08-05 22:37 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-09-19 18:41 - 2015-09-19 18:41 - 0000000 _____ () C:\ProgramData\inf.dat
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\ProgramData\inf.dat
Einige Dateien in TEMP:
====================
C:\Users\Birk\AppData\Local\Temp\beeddejbeh.exe
C:\Users\Birk\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\WINDOWS\system32\winlogon.exe => Datei ist digital signiert
C:\WINDOWS\system32\wininit.exe => Datei ist digital signiert
C:\WINDOWS\explorer.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\explorer.exe => Datei ist digital signiert
C:\WINDOWS\system32\svchost.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\svchost.exe => Datei ist digital signiert
C:\WINDOWS\system32\services.exe => Datei ist digital signiert
C:\WINDOWS\system32\User32.dll => Datei ist digital signiert
C:\WINDOWS\SysWOW64\User32.dll => Datei ist digital signiert
C:\WINDOWS\system32\userinit.exe => Datei ist digital signiert
C:\WINDOWS\SysWOW64\userinit.exe => Datei ist digital signiert
C:\WINDOWS\system32\rpcss.dll => Datei ist digital signiert
C:\WINDOWS\system32\dnsapi.dll
[2015-07-10 13:00] - [2015-09-19 18:40] - 0680256 ____A (Microsoft Corporation) 254A5B8551F4286937FAD84D2228BE37
C:\WINDOWS\SysWOW64\dnsapi.dll
[2015-07-10 13:00] - [2015-09-19 18:40] - 0534064 ____A (Microsoft Corporation) 7DCF6205A5CED02045FB7AA924EB0C7D
C:\WINDOWS\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2015-10-03 13:28
==================== Ende von FRST.txt ============================ Hey,
es ist derzeit irgendwie nicht möglich den AdwCleaner zu downloaden; weder auf chip.de , noch auf "eurer" Seite. Immer wenn der Download startet, endet er mit "Fehlgeschlagen". |