Feurerify | 14.10.2013 15:44 | so, hier die Log-Dateien von Malwarebytes: Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.10.14.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
Ferdinand :: FERDIS-PC [Administrator]
14.10.2013 15:30:27
mbam-log-2013-10-14 (15-30-27).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 230294
Laufzeit: 5 Minute(n), 2 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
C:\Users\Ferdinand\AppData\Local\Temp\plus-hd-2-6.exe (PUP.Optional.CrossRider) -> Keine Aktion durchgeführt.
(Ende) Die .txt vom Adw-Cleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v3.004 - Bericht erstellt am 16/09/2013 um 20:18:55
# Updated 15/09/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Ferdinand - FERDIS-PC
# Gestartet von : C:\Users\Ferdinand\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\Users\Ferdinand\AppData\Roaming\Common\LuaRT
Ordner Gelöscht : C:\Users\Ferdinand\AppData\Roaming\Intermediate
Ordner Gelöscht : C:\Users\Ferdinand\AppData\Roaming\SCheck
Ordner Gelöscht : C:\Users\Ferdinand\AppData\Roaming\SeeSimilar
Ordner Gelöscht : C:\Users\Ferdinand\AppData\Roaming\SSync
Datei Gelöscht : C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\searchplugins\safesearch.xml
Datei Gelöscht : C:\Windows\System32\Tasks\FreeDriverScout
Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater Ui
Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKCU\Software\httogroup
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2573 octets] - [16/09/2013 19:20:21]
AdwCleaner[S0].txt - [2174 octets] - [16/09/2013 20:18:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2234 octets] ########## --- --- ---
AdwCleaner Logfile: Code:
# AdwCleaner v3.007 - Bericht erstellt am 14/10/2013 um 15:48:51
# Updated 09/10/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Ferdinand - FERDIS-PC
# Gestartet von : C:\Users\Ferdinand\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\searchplugins\safesearch.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16720
-\\ Mozilla Firefox v24.0 (de)
[ Datei : C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.InstallationThankYouPage", false);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.InstallationTime", 1380210656);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.active", true);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.addressbar", "NA");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.addressbarenhanced", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.asyncdb_dbWasSet", true);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.asyncinternaldb_dbWasSet", true);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.backgroundver", 26);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.certdomaininstaller", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.changeprevious", false);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.InstallationTime.value", "1380210656");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.geo.expiration", "Sun Oct 20 2013 02:08:04 GMT+0200");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.geo.value", "%22DE%22");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.load_balancer.expiration", "Mon Oct 14 2013 00:08:57 GMT+0200");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%201%2C%5C%22Endpoint%5C%22%3A%20%5C%2[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.previous_page.value", "%22hxxp%3A//www.youtube.com/%3Fgl%3Dde%26hl%3Dde%22");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.cookie.user_id.value", "%221415af74299d23a20a6874d1b6074bb4%22");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.description", "Turn YouTube videos to High Definition by default");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.domain", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.enablesearch", false);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.homepage", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.iframe", false);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%2247381D582BC94B95B99196F487E7F[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_appVer.value", "117");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_lastVersion.value", "32");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_meta.value", "%7B%22tmp/lightbox.css%22%3A%7B%22id%22%3A309680%2C%22ver%22%3A[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_nextCheck.expiration", "Mon Oct 14 2013 00:08:57 GMT+0200");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_nextCheck.value", "true");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_queue.value", "%7B%7D");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309680.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309680.value", "%22.backdrop%5Cr%5Cn%5Ct%5Ct%7B%5Cr%5Cn%5Ct%5Ct%5Ctp[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309681.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309681.value", "%22%3Cdiv%20id%3D%5C%22%3C%25%3DdialogId%25%3E_dialo[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309682.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309682.value", "%22/*%21%20jQuery%20UI%20-%20v1.10.3%20-%202013-05-0[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309683.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309683.value", "%22%5Cr%5Cn//%5Ctfunction%20close_box%28%29%5Cr%5Cn/[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309684.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309684.value", "%22%3F%20Optional%20-%20add%20localization%20support[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309685.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309685.value", "%22%5Ct%5Ct//UA-43911980-1%5Cr%5Cn%5Ct%5Ct//appAPI.a[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309687.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309687.value", "%22%7B%5Cr%5Cn%5C%22mobile%5C%22%3A%5B%5C%22com.ea.g[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309688.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309688.value", "%22%7B%5Cr%5Cn%5C%22youtube.com%5C%22%3A%5B%5C%22com[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309689.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309689.value", "%22%5B%5Cr%5Cn%5Ct%5Ct%7B%5Cr%5Cn%5Ct%5Ct%5Ct%5C%22i[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309692.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309692.value", "%22%3Cdiv%20class%3D%5C%22w2m_slider_hash2313523ff4w[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309693.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309693.value", "%22%3Cdiv%20class%3D%5C%22w2m_slider_hash2313523ff4w[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309695.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309695.value", "%22a%20img%2C%20%3Alink%20img%2C%20%3Avisited%20img%[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309697.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309697.value", "%22jQuery.easing.jswing%3DjQuery.easing.swing%3B%5Cr[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309699.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309699.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEU[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309700.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309700.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEU[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309701.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309701.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEU[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309702.expiration", "Sat Jan 04 2014 10:38:27 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.Resources_resource_309702.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEU[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb._country_code_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb._country_code_.value", "%22DE%22");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%2247381D58[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.monetization_plugin_last_executable_request.expiration", "Mon Oct 14 2013 10:35:26 GMT+[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.internaldb.monetization_plugin_last_executable_request.value", "%22hxxp%3A//download.gamestar.de/p[...]
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.lastDailyReport", "1381680535625");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.lastUpdate", "1381680536760");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.manifesturl", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.name", "Plus-HD-2.6");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.newtab", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.opensearch", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.pluginsurl", "hxxps://w9u6a2p6.ssl.hwcdn.net/plugin/apps/33440/plugins/092/ff/plugins.json");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.pluginsversion", 85);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.publisher", "Plus HD");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.searchstatus", 0);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.setnewtab", false);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.thankyou", "");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.updateinterval", 360);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.33440.ver", 117);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.apps", "33440");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.bic", "1415af74299d23a20a6874d1b6074bb4");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.cid", 33440);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.firstrun", false);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.hadappinstalled", true);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.installationdate", 1380210656);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.modetype", "production");
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.reportInstall", true);
Zeile gelöscht : user_pref("extensions.a7f404cccb0a94fafb3c089ceea949aeaa6724a0593804ebebe02e67e35a3402ccom33440.statsDailyCounter", 22);
Zeile gelöscht : user_pref("extensions.crossrider.bic", "1415af74299d23a20a6874d1b6074bb4");
*************************
AdwCleaner[R0].txt - [22850 octets] - [16/09/2013 19:20:21]
AdwCleaner[S0].txt - [22400 octets] - [16/09/2013 20:18:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [22461 octets] ########## --- --- ---
und die JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.4 (10.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by Ferdinand on 14.10.2013 at 16:02:50,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Ferdinand\AppData\Roaming\mozilla\firefox\profiles\zxdsn7yi.default\minidumps [5 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.10.2013 at 16:07:10,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und nebenbei habe ich noch eine andere Frage: Kümmert ihr euch auch um Systemfehler und änliches, oder nur um Schadsoftware? Da hätte ich nämlich auch noch was.
Gruß,
Feurerify
EDIT: Und keine Ahnung wieso, aber ich habe anscheindend 2 .txt Dateien vom Adw-Cleaner. Die eine ist aber schon fast 1 Monat alt^^
Und die FRST-Log hab ich vergessen :rolleyes:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Ferdinand (administrator) on FERDIS-PC on 14-10-2013 16:42:33
Running from C:\Users\Ferdinand\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUSTeK Computer Inc.) C:\Windows\Chipset\AsusSetup.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dell Inc.) C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.0.1.3\NIS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Hama\Common\RalinkRegistryWriter.exe
(VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe
(Microsoft Corp.) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Dell Inc.) C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
(Microsoft Corp.) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Dell Inc.) C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpsp.exe
(Dell Inc.) C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\dlupdr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Valve\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.0.1.3\NIS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunes.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(XMedia Recode) C:\Program Files (x86)\XMedia Recode\XMedia Recode.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXTranscode.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [DLPSP] - C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE [432368 2009-07-08] (Dell Inc.)
HKLM\...\Run: [DLUPDR] - C:\Program Files\Dell Printers\Additional Color Laser Software\Updater\DLUPDR.EXE [261872 2009-07-08] (Dell Inc.)
HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5015040 2012-02-11] (VIA)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [163328 2010-11-21] (Microsoft Corporation)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Valve\Steam\steam.exe [1813928 2013-10-09] (Valve Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5015040 2012-02-11] (VIA)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Razer Synapse] - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [442200 2013-09-28] (Razer Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xBE64B7E0F965CA01
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.0.1.3\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.0.1.3\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Flagfox - {BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} - C:\Users\Ferdinand\AppData\LocalLow\Flagfox\IE\Flagfox.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.0.1.3\coIEPlg.dll (Symantec Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default
FF Homepage: hxxp://www.youtube.com/?gl=de&hl=de
FF NetworkProxy: "backup.ftp", "www-proxy.t-online.de"
FF NetworkProxy: "backup.ftp_port", 80
FF NetworkProxy: "backup.socks", "www-proxy.t-online.de"
FF NetworkProxy: "backup.socks_port", 80
FF NetworkProxy: "backup.ssl", "www-proxy.t-online.de"
FF NetworkProxy: "backup.ssl_port", 80
FF NetworkProxy: "ftp", "www-proxy.t-online.de"
FF NetworkProxy: "ftp_port", 80
FF NetworkProxy: "http", "www-proxy.t-online.de"
FF NetworkProxy: "http_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "www-proxy.t-online.de"
FF NetworkProxy: "socks_port", 80
FF NetworkProxy: "ssl", "www-proxy.t-online.de"
FF NetworkProxy: "ssl_port", 80
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\searchplugins\stupidedia-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Flagfox - C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\Extensions\info@flagfox.net
FF Extension: Flagfox - C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: info - C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\Extensions\info@maltegoetz.de.xpi
FF Extension: paulsaintuzb - C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\Extensions\paulsaintuzb@gmail.com.xpi
FF Extension: No Name - C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Users\Ferdinand\AppData\Roaming\Mozilla\Firefox\Profiles\zxdsn7yi.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.1.3\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.1.3\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.1.3\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.1.3\IPSFF
==================== Services (Whitelisted) =================
R2 DLPWD; C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE [154352 2009-08-28] (Dell Inc.)
R2 DLSDB; C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE [191896 2006-12-07] (Dell Inc.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.0.1.3\NIS.exe [275696 2013-08-31] (Symantec Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 RalinkRegistryWriter; C:\Program Files (x86)\Hama\Common\RalinkRegistryWriter.exe [69632 2008-05-13] (Ralink Technology, Corp.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-11-13] (VIA Technologies, Inc.)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\BASHDefs\20130924.001\BHDrvx64.sys [1525848 2013-09-24] (Symantec Corporation)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\BASHDefs\20130924.001\BHDrvx64.sys [1525848 2013-09-24] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1500010.003\ccSetx64.sys [150104 2013-07-30] (Symantec Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-29] (DT Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-09-05] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-09-05] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-09-05] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\IPSDefs\20131011.001\IDSvia64.sys [520280 2013-10-09] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\IPSDefs\20131011.001\IDSvia64.sys [520280 2013-10-09] (Symantec Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\VirusDefs\20131013.021\ENG64.SYS [126040 2013-09-05] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\VirusDefs\20131013.021\ENG64.SYS [126040 2013-09-05] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\VirusDefs\20131013.021\EX64.SYS [2099288 2013-09-05] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.0.1.3\Definitions\VirusDefs\20131013.021\EX64.SYS [2099288 2013-09-05] (Symantec Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39096 2013-09-13] (Razer Inc)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-06-19] (Duplex Secure Ltd.)
R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1500010.003\SRTSP64.SYS [854616 2013-07-31] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1500010.003\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1500010.003\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1500010.003\SYMEFA64.SYS [1147480 2013-08-05] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-09-05] (Symantec Corporation)
R1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-08-07] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1500010.003\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1500010.003\SYMNETS.SYS [590424 2013-07-31] (Symantec Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-14 16:27 - 2013-10-14 16:27 - 00000000 ____D C:\Users\Ferdinand\Desktop\tweaking.com_windows_repair_aio
2013-10-14 16:15 - 2013-10-14 16:15 - 02804464 _____ C:\Users\Ferdinand\Desktop\tweaking.com_windows_repair_aio.zip
2013-10-14 16:01 - 2013-10-14 16:01 - 01032220 _____ (Thisisu) C:\Users\Ferdinand\Desktop\JRT.exe
2013-10-14 15:31 - 2013-10-14 15:31 - 01048960 _____ C:\Users\Ferdinand\Desktop\adwcleaner.exe
2013-10-14 15:28 - 2013-10-14 15:28 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-14 15:28 - 2013-10-14 15:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-14 15:28 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-14 15:25 - 2013-10-14 15:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ferdinand\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-13 23:39 - 2013-10-13 23:39 - 01954124 _____ (Farbar) C:\Users\Ferdinand\Desktop\FRST64.exe
2013-10-13 23:39 - 2013-10-13 23:39 - 00000000 ____D C:\FRST
2013-10-12 14:56 - 2013-10-12 14:56 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_rzudd_01009.Wdf
2013-10-12 14:56 - 2013-10-12 14:56 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_rzendpt_01009.Wdf
2013-10-12 14:55 - 2013-10-12 14:56 - 00077654 _____ C:\Windows\DPINST.LOG
2013-10-12 14:51 - 2013-10-12 14:51 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Razer
2013-10-12 14:49 - 2013-10-12 14:55 - 00000000 ____D C:\Program Files (x86)\Razer
2013-10-12 14:49 - 2013-10-12 14:49 - 00000000 ____D C:\ProgramData\Razer
2013-10-12 14:45 - 2013-10-12 14:45 - 13290440 _____ (Razer Inc.) C:\Users\Ferdinand\Desktop\Razer_Synapse_Framework_V1.14.04.exe
2013-10-11 16:19 - 2013-10-11 16:19 - 00000000 ____D C:\Users\Ferdinand\Documents\Electrontic Arts
2013-10-11 13:26 - 2013-10-11 13:26 - 00000000 ____D C:\Windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
2013-10-09 18:50 - 2013-10-09 18:50 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-10-09 18:06 - 2013-10-09 18:06 - 00052607 _____ C:\Users\Ferdinand\AppData\Local\recently-used.xbel
2013-10-09 17:11 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-09 17:11 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-09 17:11 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-09 17:11 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-09 17:11 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-09 17:11 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-09 17:11 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-09 17:11 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-09 17:11 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-09 17:11 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-09 17:11 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-09 17:11 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-09 17:11 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-09 17:11 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-09 17:11 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-09 17:10 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-09 17:10 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-09 17:10 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-09 17:10 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-09 17:10 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-09 17:10 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-09 17:10 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-09 17:10 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-09 17:10 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-09 17:10 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-09 17:10 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-09 17:10 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-09 17:10 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-09 17:10 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-09 17:10 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-09 17:10 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-09 10:30 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-09 10:30 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-09 10:30 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-09 10:30 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-09 10:30 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-09 10:30 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-09 10:30 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-09 10:30 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-09 10:30 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-09 10:30 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-09 10:30 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-09 10:30 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-09 10:30 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-09 10:30 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-09 10:30 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-09 10:30 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-09 10:30 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-09 10:30 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-09 10:30 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-09 10:30 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-09 10:30 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-09 10:30 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-09 10:30 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 10:30 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 10:30 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-09 10:30 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-09 10:30 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-09 10:30 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-09 10:30 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-09 10:30 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-09 10:30 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 10:30 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-09 10:30 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-09 10:30 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-09 10:30 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 10:30 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-09 10:30 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-09 10:30 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-09 10:30 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-09 10:30 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-09 10:30 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-09 10:30 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-09 10:30 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 10:30 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 10:30 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-09 10:29 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-09 10:29 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-09 10:29 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-09 10:29 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-09 10:29 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-09 10:29 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-09 10:29 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-08 18:00 - 2013-10-08 18:00 - 00004009 _____ C:\Users\Ferdinand\Documents\Mein Film.wlmp
2013-10-08 17:59 - 2013-10-09 21:23 - 00000000 ____D C:\Users\Ferdinand\Desktop\Neuer Ordner (2)
2013-10-08 15:14 - 2013-10-08 15:14 - 00001071 _____ C:\Users\Public\Desktop\XMedia Recode.lnk
2013-10-05 23:15 - 2013-10-05 23:17 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-05 23:15 - 2013-10-05 23:17 - 00000000 ____D C:\Program Files\iTunes
2013-10-05 23:15 - 2013-10-05 23:15 - 00000000 ____D C:\Program Files\iPod
2013-09-27 13:25 - 2013-09-27 13:25 - 00799744 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevicedll.dll
2013-09-26 17:38 - 2013-09-26 17:38 - 00001011 _____ C:\Users\Ferdinand\Desktop\Audacity.lnk
2013-09-26 17:38 - 2013-09-26 17:38 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-09-25 19:45 - 2013-09-25 19:45 - 00001206 _____ C:\Users\Public\Desktop\HD VDeck.lnk
2013-09-25 19:44 - 2011-11-13 07:50 - 02915440 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIAPropPageExt.dll
2013-09-25 19:44 - 2011-11-13 07:50 - 02182768 _____ (VIA Technologies, Inc.) C:\Windows\system32\Drivers\viahduaa.sys
2013-09-25 19:44 - 2011-11-13 07:50 - 01161328 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaKaraokeApo.dll
2013-09-25 19:44 - 2011-11-13 07:50 - 00675952 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIASysFx.dll
2013-09-25 19:44 - 2011-11-13 07:50 - 00202864 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaMicArrayAPO.dll
2013-09-25 19:44 - 2011-11-13 07:50 - 00116848 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaKaraokePropPageExt.dll
2013-09-25 19:44 - 2011-11-13 07:50 - 00091760 _____ (VIA Technologies, Inc.) C:\Windows\system32\Dts2PropPageExt.dll
2013-09-25 19:44 - 2011-11-13 07:50 - 00090224 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaMicArrayPropPageExt.dll
2013-09-25 19:44 - 2011-11-13 07:50 - 00027760 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViakaraokeSrv.exe
2013-09-25 19:44 - 2011-06-10 04:19 - 00085504 _____ (QSound Labs, Inc.) C:\Windows\system32\nQPropPageExt.dll
2013-09-25 19:40 - 2013-09-25 19:40 - 00000000 ____D C:\Windows\System32\Tasks\ASUS
2013-09-25 19:39 - 2013-09-25 19:39 - 00016896 _____ (ASUS) C:\Windows\AsTaskSched.dll
2013-09-25 19:39 - 2013-09-25 19:39 - 00000000 ____D C:\Windows\Chipset
2013-09-25 19:38 - 2011-02-25 08:25 - 00296320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2013-09-25 19:03 - 2012-09-06 11:56 - 00000000 ____D C:\Windows\AsDmiHtm
2013-09-25 14:20 - 2013-09-25 14:20 - 00000000 ____D C:\Windows\system32\SRSLabs
2013-09-25 14:20 - 2013-09-25 14:20 - 00000000 ____D C:\Program Files\VIA
2013-09-25 14:20 - 2012-10-22 10:44 - 00070776 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\VtSrdAPO.dll
2013-09-25 14:20 - 2012-10-22 10:43 - 00055416 _____ (TODO: <Company name>) C:\Windows\system32\PropPageExt.dll
2013-09-25 14:20 - 2012-09-24 10:33 - 03141496 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVIA64.dll
2013-09-25 14:20 - 2012-09-24 10:32 - 02080120 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2013-09-25 14:20 - 2012-09-05 11:12 - 00860024 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2013-09-25 14:20 - 2012-07-15 07:16 - 00394104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 07163744 _____ (Dolby Laboratories) C:\Windows\system32\EEP64H.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00433504 _____ (Dolby Laboratories) C:\Windows\system32\EED64H.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00433504 _____ (Dolby Laboratories) C:\Windows\system32\EED64A.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00137056 _____ (Dolby Laboratories) C:\Windows\system32\EEL64H.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00137056 _____ (Dolby Laboratories) C:\Windows\system32\EEL64A.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00120160 _____ (Dolby Laboratories) C:\Windows\system32\EEA64H.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00120160 _____ (Dolby Laboratories) C:\Windows\system32\EEA64A.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00075104 _____ (Dolby Laboratories) C:\Windows\system32\EEG64H.dll
2013-09-25 14:20 - 2011-12-15 07:16 - 00075104 _____ (Dolby Laboratories) C:\Windows\system32\EEG64A.dll
2013-09-25 14:20 - 2011-09-27 12:13 - 00879616 _____ (Creative Technology Ltd.) C:\Windows\system32\VMAPO64.DLL
2013-09-25 14:20 - 2011-09-27 12:13 - 00739328 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMAPO32.DLL
2013-09-25 14:20 - 2011-09-27 12:13 - 00619520 _____ (Creative Technology Ltd.) C:\Windows\system32\VMTHX64.DLL
2013-09-25 14:20 - 2011-09-27 12:13 - 00554496 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMTHX32.DLL
2013-09-25 14:20 - 2011-09-27 12:13 - 00057856 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPLD64.DLL
2013-09-25 14:20 - 2010-10-26 12:55 - 00074240 _____ (Creative Technology Ltd.) C:\Windows\system32\VMWRP64.DLL
2013-09-25 14:20 - 2010-10-26 12:54 - 00053760 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPCN64.DLL
2013-09-25 14:20 - 2009-07-31 05:40 - 00025600 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\VMfilt64.sys
2013-09-20 23:30 - 2013-09-20 23:30 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-20 22:48 - 2013-09-12 10:58 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-09-20 22:48 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-09-20 22:48 - 2013-09-12 10:58 - 00022814 _____ C:\Windows\system32\nvinfo.pb
2013-09-20 22:48 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-09-20 22:48 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-09-20 22:48 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2013-09-20 22:48 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2013-09-20 22:20 - 2013-09-20 22:19 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-20 22:19 - 2013-09-20 22:19 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-20 22:19 - 2013-09-20 22:19 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-20 22:19 - 2013-09-20 22:19 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-09-20 21:18 - 2013-09-20 21:18 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\Arrowhead
2013-09-20 21:17 - 2013-09-20 21:17 - 00000000 ____D C:\Windows\9530AE42DAE146199594B23487285D17.TMP
2013-09-20 21:16 - 2013-10-11 16:20 - 00037945 _____ C:\Windows\DirectX.log
2013-09-19 04:09 - 2013-09-19 04:09 - 00296448 _____ (Razer Inc) C:\Windows\SysWOW64\rzaudiodll.dll
2013-09-19 04:09 - 2013-09-19 04:09 - 00154112 _____ (Razer Inc) C:\Windows\SysWOW64\rztouchdll.dll
2013-09-19 04:09 - 2013-09-19 04:09 - 00117248 _____ (Razer Inc) C:\Windows\SysWOW64\rzdisplaydll.dll
2013-09-19 04:09 - 2013-09-19 04:09 - 00057344 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevinfo.dll
2013-09-18 21:30 - 2013-09-18 21:30 - 00307511 ____N C:\Windows\Minidump\091913-32853-01.dmp
2013-09-17 22:34 - 2013-09-20 22:20 - 00000000 ____D C:\ProgramData\Oracle
2013-09-17 22:33 - 2013-09-17 22:33 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-17 22:33 - 2013-09-17 22:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-17 22:33 - 2013-09-17 22:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-17 22:33 - 2013-09-17 22:33 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-17 22:33 - 2013-09-17 22:33 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-17 16:48 - 2013-09-17 16:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-16 20:28 - 2013-09-17 23:15 - 00000000 ____D C:\Windows\ERUNT
2013-09-16 19:19 - 2013-10-14 15:48 - 00000000 ____D C:\AdwCleaner
2013-09-15 17:28 - 2013-10-06 16:34 - 00004174 _____ C:\Windows\PFRO.log
2013-09-15 16:53 - 2013-09-17 23:10 - 00000000 ____D C:\Windows\erdnt
2013-09-15 16:42 - 2013-10-14 16:27 - 09200221 _____ C:\Windows\setupact.log
2013-09-15 16:42 - 2013-09-15 16:42 - 00000000 _____ C:\Windows\setuperr.log
2013-09-15 16:34 - 2013-09-15 16:34 - 00010444 _____ C:\Users\Ferdinand\Documents\cc_20130915_163410.reg
2013-09-15 13:00 - 2013-09-15 13:00 - 00000000 ____D C:\Windows\Uninstall
2013-09-14 22:47 - 2013-09-14 22:47 - 00007607 _____ C:\Users\Ferdinand\AppData\Local\Resmon.ResmonCfg
==================== One Month Modified Files and Folders =======
2013-10-14 16:42 - 2013-04-28 16:28 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Windows Live
2013-10-14 16:40 - 2009-11-02 17:07 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-14 16:40 - 2009-11-02 17:07 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-14 16:30 - 2011-09-09 22:02 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\Skype
2013-10-14 16:27 - 2013-10-14 16:27 - 00000000 ____D C:\Users\Ferdinand\Desktop\tweaking.com_windows_repair_aio
2013-10-14 16:27 - 2013-09-15 16:42 - 09200221 _____ C:\Windows\setupact.log
2013-10-14 16:15 - 2013-10-14 16:15 - 02804464 _____ C:\Users\Ferdinand\Desktop\tweaking.com_windows_repair_aio.zip
2013-10-14 16:15 - 2013-03-04 16:17 - 00010896 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-14 16:15 - 2013-03-04 16:17 - 00010896 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-14 16:01 - 2013-10-14 16:01 - 01032220 _____ (Thisisu) C:\Users\Ferdinand\Desktop\JRT.exe
2013-10-14 15:57 - 2011-10-26 20:21 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\CrashDumps
2013-10-14 15:51 - 2013-03-04 16:17 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-14 15:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-14 15:49 - 2013-03-04 17:32 - 01893030 _____ C:\Windows\WindowsUpdate.log
2013-10-14 15:49 - 2012-04-02 14:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-14 15:48 - 2013-09-16 19:19 - 00000000 ____D C:\AdwCleaner
2013-10-14 15:31 - 2013-10-14 15:31 - 01048960 _____ C:\Users\Ferdinand\Desktop\adwcleaner.exe
2013-10-14 15:28 - 2013-10-14 15:28 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-14 15:28 - 2013-10-14 15:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-14 15:25 - 2013-10-14 15:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ferdinand\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-13 23:39 - 2013-10-13 23:39 - 01954124 _____ (Farbar) C:\Users\Ferdinand\Desktop\FRST64.exe
2013-10-13 23:39 - 2013-10-13 23:39 - 00000000 ____D C:\FRST
2013-10-13 23:14 - 2009-10-31 11:18 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-10-13 23:14 - 2009-10-27 17:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-13 21:23 - 2012-03-18 17:52 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\vlc
2013-10-13 21:01 - 2013-03-17 17:41 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\.minecraft
2013-10-13 16:35 - 2009-11-02 17:07 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-13 16:35 - 2009-11-02 17:07 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-13 15:36 - 2009-10-27 18:12 - 00000000 ____D C:\Users\Ferdinand\Documents\My Games
2013-10-12 15:05 - 2011-09-09 22:00 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-12 15:05 - 2011-09-09 22:00 - 00000000 ____D C:\ProgramData\Skype
2013-10-12 14:59 - 2013-04-03 16:15 - 00387080 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-12 14:56 - 2013-10-12 14:56 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_rzudd_01009.Wdf
2013-10-12 14:56 - 2013-10-12 14:56 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_rzendpt_01009.Wdf
2013-10-12 14:56 - 2013-10-12 14:55 - 00077654 _____ C:\Windows\DPINST.LOG
2013-10-12 14:55 - 2013-10-12 14:49 - 00000000 ____D C:\Program Files (x86)\Razer
2013-10-12 14:55 - 2013-04-03 16:16 - 00095336 _____ C:\Users\Ferdinand\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-12 14:51 - 2013-10-12 14:51 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Razer
2013-10-12 14:49 - 2013-10-12 14:49 - 00000000 ____D C:\ProgramData\Razer
2013-10-12 14:45 - 2013-10-12 14:45 - 13290440 _____ (Razer Inc.) C:\Users\Ferdinand\Desktop\Razer_Synapse_Framework_V1.14.04.exe
2013-10-12 14:31 - 2011-04-12 09:43 - 00706122 _____ C:\Windows\system32\perfh007.dat
2013-10-12 14:31 - 2011-04-12 09:43 - 00151850 _____ C:\Windows\system32\perfc007.dat
2013-10-12 14:31 - 2009-07-14 07:13 - 01639496 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-12 01:22 - 2010-12-17 20:33 - 00000000 ____D C:\Users\Ferdinand\Documents\Geschichten
2013-10-11 16:21 - 2010-10-09 21:40 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Electronic Arts
2013-10-11 16:21 - 2010-08-21 11:47 - 00000000 ____D C:\Users\Ferdinand\Documents\Electronic Arts
2013-10-11 16:20 - 2013-09-20 21:16 - 00037945 _____ C:\Windows\DirectX.log
2013-10-11 16:19 - 2013-10-11 16:19 - 00000000 ____D C:\Users\Ferdinand\Documents\Electrontic Arts
2013-10-11 13:26 - 2013-10-11 13:26 - 00000000 ____D C:\Windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
2013-10-10 20:47 - 2013-08-09 20:17 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\Audacity
2013-10-10 18:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-10-09 21:23 - 2013-10-08 17:59 - 00000000 ____D C:\Users\Ferdinand\Desktop\Neuer Ordner (2)
2013-10-09 18:50 - 2013-10-09 18:50 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-10-09 18:50 - 2012-04-02 14:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 18:50 - 2012-04-02 14:40 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 18:50 - 2011-05-19 21:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-09 18:06 - 2013-10-09 18:06 - 00052607 _____ C:\Users\Ferdinand\AppData\Local\recently-used.xbel
2013-10-09 18:06 - 2013-08-03 23:25 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\gtk-2.0
2013-10-09 18:06 - 2013-07-30 00:11 - 00000000 ____D C:\Users\Ferdinand\.gimp-2.8
2013-10-09 17:36 - 2013-03-04 16:11 - 00000000 ____D C:\Windows\Panther
2013-10-09 17:34 - 2013-04-28 15:56 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-09 17:34 - 2013-04-28 15:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-09 17:07 - 2013-08-15 22:12 - 00000000 ____D C:\Windows\system32\MRT
2013-10-09 17:03 - 2013-03-05 15:26 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-08 18:00 - 2013-10-08 18:00 - 00004009 _____ C:\Users\Ferdinand\Documents\Mein Film.wlmp
2013-10-08 15:14 - 2013-10-08 15:14 - 00001071 _____ C:\Users\Public\Desktop\XMedia Recode.lnk
2013-10-08 15:14 - 2013-09-02 14:53 - 00000000 ____D C:\Program Files (x86)\XMedia Recode
2013-10-08 14:44 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-08 01:16 - 2013-07-12 21:07 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-10-06 16:34 - 2013-09-15 17:28 - 00004174 _____ C:\Windows\PFRO.log
2013-10-05 23:17 - 2013-10-05 23:15 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-05 23:17 - 2013-10-05 23:15 - 00000000 ____D C:\Program Files\iTunes
2013-10-05 23:17 - 2013-02-24 11:40 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-10-05 23:15 - 2013-10-05 23:15 - 00000000 ____D C:\Program Files\iPod
2013-09-27 13:25 - 2013-09-27 13:25 - 00799744 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevicedll.dll
2013-09-26 17:38 - 2013-09-26 17:38 - 00001011 _____ C:\Users\Ferdinand\Desktop\Audacity.lnk
2013-09-26 17:38 - 2013-09-26 17:38 - 00000000 ____D C:\Program Files (x86)\Audacity
2013-09-25 19:45 - 2013-09-25 19:45 - 00001206 _____ C:\Users\Public\Desktop\HD VDeck.lnk
2013-09-25 19:45 - 2013-02-22 15:16 - 00000000 ____D C:\Program Files (x86)\VIA
2013-09-25 19:40 - 2013-09-25 19:40 - 00000000 ____D C:\Windows\System32\Tasks\ASUS
2013-09-25 19:39 - 2013-09-25 19:39 - 00016896 _____ (ASUS) C:\Windows\AsTaskSched.dll
2013-09-25 19:39 - 2013-09-25 19:39 - 00000000 ____D C:\Windows\Chipset
2013-09-25 19:37 - 2013-02-22 14:57 - 00041293 _____ C:\Windows\Ascd_tmp.ini
2013-09-25 14:20 - 2013-09-25 14:20 - 00000000 ____D C:\Windows\system32\SRSLabs
2013-09-25 14:20 - 2013-09-25 14:20 - 00000000 ____D C:\Program Files\VIA
2013-09-23 01:28 - 2013-10-09 17:10 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-23 01:28 - 2013-10-09 17:10 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-23 01:27 - 2013-10-09 17:11 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-23 01:27 - 2013-10-09 17:11 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-23 01:27 - 2013-10-09 17:11 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-23 01:27 - 2013-10-09 17:11 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-23 01:27 - 2013-10-09 17:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-23 01:27 - 2013-10-09 17:10 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-23 01:27 - 2013-10-09 17:10 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-23 01:27 - 2013-10-09 17:10 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-23 01:27 - 2013-10-09 17:10 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-23 01:27 - 2013-10-09 17:10 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-23 01:27 - 2013-10-09 17:10 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-23 00:55 - 2013-10-09 17:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-23 00:55 - 2013-10-09 17:10 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-23 00:55 - 2013-10-09 17:10 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-23 00:54 - 2013-10-09 17:11 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-23 00:54 - 2013-10-09 17:11 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-23 00:54 - 2013-10-09 17:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-23 00:54 - 2013-10-09 17:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-23 00:54 - 2013-10-09 17:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-23 00:54 - 2013-10-09 17:10 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-23 00:54 - 2013-10-09 17:10 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-23 00:54 - 2013-10-09 17:10 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-23 00:54 - 2013-10-09 17:10 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-23 00:54 - 2013-10-09 17:10 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-23 00:54 - 2013-10-09 17:10 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-22 20:13 - 2013-02-16 16:54 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\Origin
2013-09-22 20:13 - 2013-02-16 16:54 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Origin
2013-09-22 20:13 - 2010-05-06 17:14 - 00000000 ____D C:\ProgramData\Origin
2013-09-22 20:06 - 2013-02-16 16:53 - 00000000 ____D C:\Program Files (x86)\Origin
2013-09-21 05:38 - 2013-10-09 17:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-21 05:30 - 2013-10-09 17:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-21 04:48 - 2013-10-09 17:11 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-21 04:39 - 2013-10-09 17:11 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-20 23:37 - 2013-03-04 16:16 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-09-20 23:30 - 2013-09-20 23:30 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-20 22:20 - 2013-09-17 22:34 - 00000000 ____D C:\ProgramData\Oracle
2013-09-20 22:19 - 2013-09-20 22:20 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-20 22:19 - 2013-09-20 22:19 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-20 22:19 - 2013-09-20 22:19 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-20 22:19 - 2013-09-20 22:19 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-09-20 22:19 - 2013-03-10 20:36 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-20 22:19 - 2011-11-24 22:02 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-09-20 21:18 - 2013-09-20 21:18 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\Arrowhead
2013-09-20 21:17 - 2013-09-20 21:17 - 00000000 ____D C:\Windows\9530AE42DAE146199594B23487285D17.TMP
2013-09-19 14:40 - 2013-07-23 20:13 - 00000000 ____D C:\Windows\Minidump
2013-09-19 04:09 - 2013-09-19 04:09 - 00296448 _____ (Razer Inc) C:\Windows\SysWOW64\rzaudiodll.dll
2013-09-19 04:09 - 2013-09-19 04:09 - 00154112 _____ (Razer Inc) C:\Windows\SysWOW64\rztouchdll.dll
2013-09-19 04:09 - 2013-09-19 04:09 - 00117248 _____ (Razer Inc) C:\Windows\SysWOW64\rzdisplaydll.dll
2013-09-19 04:09 - 2013-09-19 04:09 - 00057344 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevinfo.dll
2013-09-18 21:30 - 2013-09-18 21:30 - 00307511 ____N C:\Windows\Minidump\091913-32853-01.dmp
2013-09-17 23:15 - 2013-09-16 20:28 - 00000000 ____D C:\Windows\ERUNT
2013-09-17 23:10 - 2013-09-15 16:53 - 00000000 ____D C:\Windows\erdnt
2013-09-17 23:03 - 2012-05-03 19:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-17 22:56 - 2009-12-16 12:06 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Adobe
2013-09-17 22:55 - 2010-04-09 14:02 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-17 22:55 - 2009-12-16 12:12 - 00000000 ____D C:\ProgramData\Adobe
2013-09-17 22:33 - 2013-09-17 22:33 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-09-17 22:33 - 2013-09-17 22:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-09-17 22:33 - 2013-09-17 22:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-09-17 22:33 - 2013-09-17 22:33 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-09-17 22:33 - 2013-09-17 22:33 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-17 22:33 - 2012-06-19 18:24 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2013-09-17 22:33 - 2010-10-19 20:09 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-09-17 20:56 - 2009-10-28 14:10 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Mozilla
2013-09-17 16:48 - 2013-09-17 16:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-16 20:18 - 2013-07-10 20:03 - 00000000 ____D C:\Users\Ferdinand\AppData\Roaming\Common
2013-09-15 17:39 - 2011-03-26 16:51 - 00000000 ___RD C:\Users\Ferdinand\Desktop\Krams
2013-09-15 17:23 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-09-15 17:21 - 2013-03-04 16:20 - 00000000 ____D C:\Users\Ferdinand
2013-09-15 16:42 - 2013-09-15 16:42 - 00000000 _____ C:\Windows\setuperr.log
2013-09-15 16:34 - 2013-09-15 16:34 - 00010444 _____ C:\Users\Ferdinand\Documents\cc_20130915_163410.reg
2013-09-15 13:00 - 2013-09-15 13:00 - 00000000 ____D C:\Windows\Uninstall
2013-09-15 12:50 - 2009-11-02 17:07 - 00000000 ____D C:\Users\Ferdinand\AppData\Local\Google
2013-09-15 12:50 - 2009-11-02 17:07 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-14 22:47 - 2013-09-14 22:47 - 00007607 _____ C:\Users\Ferdinand\AppData\Local\Resmon.ResmonCfg
2013-09-14 03:10 - 2013-10-09 10:30 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
Some content of TEMP:
====================
C:\Users\Ferdinand\AppData\Local\Temp\drm_dyndata_7390004.dll
C:\Users\Ferdinand\AppData\Local\Temp\drm_dyndata_7410004.dll
C:\Users\Ferdinand\AppData\Local\Temp\nvStInst.exe
C:\Users\Ferdinand\AppData\Local\Temp\plus-hd-2-6.exe
C:\Users\Ferdinand\AppData\Local\Temp\Quarantine.exe
C:\Users\Ferdinand\AppData\Local\Temp\vlc-2.0.8-win32.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-11 15:20
==================== End Of Log ============================ --- --- ---
--- --- --- |