TORFdaniel | 27.12.2013 13:28 | AdwCleaner
AdwCleaner Logfile: Code:
# AdwCleaner v3.016 - Bericht erstellt am 26/12/2013 um 20:37:32
# Aktualisiert 23/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Julian - JULIAN-PC
# Gestartet von : C:\Users\Julian\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\wincert
Ordner Gelöscht : C:\Program Files (x86)\Music Toolbar
Ordner Gelöscht : C:\Program Files (x86)\weDownload Manager Pro
Ordner Gelöscht : C:\Users\Julian\AppData\Local\Searchprotect
Ordner Gelöscht : C:\Users\Julian\AppData\Local\torch
Ordner Gelöscht : C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\3o037z6f.default\Extensions\008abed2-b43a-46c9-9a5b-a771c87b82da@1ad61d53-2bdc-4484-a26b-b888ecae1906.com
Ordner Gelöscht : C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\kikjpgpbpnapbimplfcbcbakjacpgceb
Datei Gelöscht : C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\3o037z6f.default\searchplugins\conduit-search.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422362228}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455365528}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466366628}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{13a747ac-0f75-4834-889a-033e8f849beb}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2ff0943e-3ec4-4e3a-94c4-b7a2d3650ff6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c325bb22-92cd-42c3-99e5-6cb47d88377c}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c93b67c2-12bf-469d-9b8c-a20a807e7d99}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d71aadf3-fa71-478f-bd7a-c531dd46acb2}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422362228}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455365528}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466366628}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{13a747ac-0f75-4834-889a-033e8f849beb}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2ff0943e-3ec4-4e3a-94c4-b7a2d3650ff6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c325bb22-92cd-42c3-99e5-6cb47d88377c}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c93b67c2-12bf-469d-9b8c-a20a807e7d99}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d71aadf3-fa71-478f-bd7a-c531dd46acb2}
Schlüssel Gelöscht : HKCU\Software\APN DTX
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\WEDLMNGR
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\weDownload Manager Pro
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKLM\Software\weDownload Manager Pro
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\weDownload Manager Pro
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\wincert\win32c~1.dll
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\Wincert\WIN64C~1.DLL
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\MUSICT~1\Datamngr\x64\mgrldr.dll
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v25.0 (de)
[ Datei : C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\3o037z6f.default\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3314759&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP63232A2A-22D0-4661-BD8E-27E30D9AAA69");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Conduit Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Conduit Search");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.InstallationThankYouPage", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.InstallationTime", 1386876073);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.active", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.addressbar", "NA");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.addressbarenhanced", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.asyncdb_dbWasSet", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.asyncdb_dbWasSet_FF25_FIX", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.asyncinternaldb_dbWasSet", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.asyncinternaldb_dbWasSet_FF25_FIX", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.backgroundver", 1);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.certdomaininstaller", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.changeprevious", false);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.cookie.InstallationTime.value", "1386876073");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.description", "Enhance your search results with direct download links and information for apps and[...]
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.domain", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.enablesearch", false);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.homepage", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.iframe", false);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%223499CFFAF0FF4320AB9FB81F745BF[...]
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22000529%22%2C%22sub_id%22%3A%22ver[...]
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%223499CFFAF0FF4320AB9F[...]
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_appVer.value", "47");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_lastVersion.value", "2");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_meta.value", "%7B%22extension.css%22%3A%7B%22id%22%3A311159%2C%22ver%22%3A2%2[...]
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_nextCheck.expiration", "Fri Dec 13 2013 02:21:23 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_nextCheck.value", "true");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_queue.value", "%7B%7D");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_resource_311159.expiration", "Wed Mar 12 2014 20:21:23 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.Resources_resource_311159.value", "%22.crossrider-nofity-34345-body-theme-white-black%2[...]
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%223499CFFA[...]
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.lastDailyReport", "1386876082097");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.lastUpdate", "1386876074762");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.manifesturl", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.name", "weDownload Manager Pro");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.newtab", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.opensearch", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.pluginsurl", "hxxps://w9u6a2p6.ssl.hwcdn.net/plugin/apps/43628/plugins/093/ff/plugins.json");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.pluginsversion", 43);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.publisher", "weDownload");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.searchstatus", 0);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.setnewtab", false);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.thankyou", "");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.updateinterval", 360);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.43628.ver", 47);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.apps", "43628");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.bic", "142e8417514356514baaacbc8879aad1");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.cid", 43628);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.firstrun", false);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.hadappinstalled", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.installationdate", 1386876073);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.modetype", "production");
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.reportInstall", true);
Zeile gelöscht : user_pref("extensions.a008abed2b43a46c99a5ba771c87b82da1ad61d532bdc4484a26bb888ecae1906com43628.statsDailyCounter", 1);
Zeile gelöscht : user_pref("extensions.crossrider.bic", "142e8417514356514baaacbc8879aad1");
-\\ Google Chrome v31.0.1650.63
[ Datei : C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : icon_url
*************************
AdwCleaner[R0].txt - [20119 octets] - [26/12/2013 20:36:45]
AdwCleaner[S0].txt - [16173 octets] - [26/12/2013 20:37:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16234 octets] ########## --- --- ---
JRT Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Julian on 26.12.2013 at 20:42:10,26
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2459}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2459}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Julian\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Emptied folder: C:\Users\Julian\AppData\Roaming\mozilla\firefox\profiles\3o037z6f.default\minidumps [7 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.12.2013 at 20:47:04,11
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
neues FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-12-2013
Ran by Julian (administrator) on JULIAN-PC on 26-12-2013 21:20:09
Running from C:\Users\Julian\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BBSvc.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Overwolf) C:\Program Files (x86)\Overwolf\Overwolf.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper.exe
(Overwolf) C:\Program Files (x86)\Common Files\Overwolf\OverwolfHelper64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\SeaPort.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7174728 2013-03-29] (Realtek Semiconductor)
HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\WLanGUI.exe [2105344 2010-10-22] (AVM Berlin)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [Desura] - C:\Program Files (x86)\Desura\desura.exe [2529096 2013-12-25] (Desura Pty Ltd)
HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf)
HKCU\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000
AppInit_DLLs: [ ] ()
AppInit_DLLs-x32: [ ] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFFE2435FF7D1CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://syb.msn.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2459} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=153&systemid=459&v=n10354-192&apn_uid=0121630953114636&apn_dtid=BND103&o=APN10652&apn_ptnrs=AGD&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll No File
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll (Microsoft Corporation.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\3o037z6f.default
FF Homepage: hxxp://www.google.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Julian\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\3o037z6f.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Chrome:
=======
CHR Extension: (Music Toolbar) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajjdggclgejkckppicefnelmoefjp\27.64617_0
CHR Extension: (Google Docs) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Adblock Plus) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0
CHR Extension: (Google Search) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Night Time In New York City) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek\1.2_0
CHR Extension: (Google Wallet) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Julian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [aaaajjdggclgejkckppicefnelmoefjp] - C:\Users\Julian\AppData\Local\fuzezipmusictoolbardla\GC\toolbar.crx
==================== Services (Whitelisted) =================
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-11-23] ()
S2 JetDrive WindowsClosingService; C:\Windows\System32\WindowsClosingService [x]
==================== Drivers (Whitelisted) ====================
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin)
S3 EtronSTOR; C:\Windows\System32\Drivers\EtronSTOR.sys [32512 2012-06-13] (Etron Technology Inc)
S3 FLxHCIh; C:\Windows\system32\drivers\FLxHCIh.sys [77480 2013-02-25] (Fresco Logic)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28656 2013-04-22] (Intel Corporation)
S3 irstrtdv; C:\Windows\system32\drivers\irstrtdv.sys [43800 2012-07-20] (Intel Corporation)
S3 ISCT; C:\Windows\system32\drivers\ISCTD64.sys [46016 2012-07-24] ()
S3 jetdrive; C:\Windows\System32\DRIVERS\jddrv.sys [37248 2012-05-22] (Abelssoft GmbH)
S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [39704 2012-12-21] (Atheros)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)
R3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-05-14] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
S3 rusb3hub; C:\Windows\system32\drivers\rusb3hub.sys [114568 2012-08-27] (Renesas Electronics Corporation)
S3 rusb3xhc; C:\Windows\system32\drivers\rusb3xhc.sys [230280 2012-08-27] (Renesas Electronics Corporation)
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2013-11-21] (Razer, Inc.)
R0 RzFilter; C:\Windows\System32\drivers\RzFilter.sys [74432 2013-11-21] (Razer, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-26 20:47 - 2013-12-26 20:47 - 00001197 _____ C:\Users\Julian\Desktop\JRT.txt
2013-12-26 20:42 - 2013-12-26 20:42 - 00000000 ____D C:\Windows\ERUNT
2013-12-26 20:41 - 2013-12-26 20:41 - 01034531 _____ (Thisisu) C:\Users\Julian\Downloads\JRT.exe
2013-12-26 20:36 - 2013-12-26 20:37 - 00000000 ____D C:\AdwCleaner
2013-12-26 20:35 - 2013-12-26 20:36 - 01233962 _____ C:\Users\Julian\Downloads\adwcleaner.exe
2013-12-26 18:35 - 2013-12-26 18:35 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-26 18:35 - 2013-12-26 18:35 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Malwarebytes
2013-12-26 18:35 - 2013-12-26 18:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-26 18:35 - 2013-12-26 18:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-26 18:35 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-26 18:34 - 2013-12-26 18:34 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Julian\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-26 18:31 - 2013-12-26 18:32 - 00000000 ____D C:\32788R22FWJFW
2013-12-26 16:52 - 2013-12-26 16:54 - 00001971 _____ C:\Users\Public\Desktop\Overwolf.lnk
2013-12-26 16:50 - 2013-12-26 16:52 - 00001211 _____ C:\Users\Julian\Desktop\TeamSpeak 3 Client.lnk
2013-12-26 16:47 - 2013-12-26 16:49 - 32520760 _____ (TeamSpeak Systems GmbH) C:\Users\Julian\Downloads\TeamSpeak3-Client-win64-3.0.13.1.exe
2013-12-26 14:45 - 2013-12-26 14:45 - 00000219 _____ C:\Users\Julian\Desktop\Left 4 Dead 2.url
2013-12-25 18:17 - 2013-12-25 18:17 - 01214299 _____ C:\Users\Julian\Downloads\Julian.htm
2013-12-25 18:17 - 2013-12-25 18:17 - 00000000 ____D C:\Users\Julian\Downloads\Julian_files
2013-12-23 10:50 - 2013-12-25 19:12 - 00001859 _____ C:\Users\Public\Desktop\Desura.lnk
2013-12-23 00:13 - 2013-12-23 00:13 - 00000000 ____D C:\Users\Julian\AppData\Local\Desura
2013-12-23 00:03 - 2013-12-23 00:04 - 21452408 _____ C:\Users\Julian\Downloads\AC_Mod_Pack.rar
2013-12-22 23:55 - 2013-12-25 19:13 - 00000000 ____D C:\Program Files (x86)\Desura
2013-12-22 23:55 - 2013-12-22 23:55 - 00000000 ____D C:\ProgramData\Desura
2013-12-22 23:54 - 2013-12-22 23:55 - 01252424 _____ C:\Users\Julian\Downloads\DesuraInstaller.exe
2013-12-22 16:12 - 2013-12-22 23:57 - 00034308 _____ C:\Windows\SysWOW64\bassmod.dll
2013-12-22 16:12 - 2013-12-22 16:12 - 00403463 _____ C:\Users\Julian\Downloads\d2a536_4e9f41d31ec4c.zip
2013-12-22 16:12 - 2013-12-22 16:12 - 00003180 _____ C:\Windows\System32\Tasks\{72480F35-5D47-411B-9910-6C607904743A}
2013-12-22 15:57 - 2013-12-22 15:57 - 00009094 _____ C:\Users\Julian\Downloads\SweetFX_Settings_Assassin's Creed II_AC2 total improvements .txt
2013-12-22 15:51 - 2013-12-22 15:51 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SweetFX Configurator
2013-12-22 15:50 - 2013-12-22 15:50 - 00492398 _____ C:\Users\Julian\Downloads\SweetFX-Configurator_1.3.3.zip
2013-12-22 15:50 - 2013-12-22 15:50 - 00281567 _____ C:\Users\Julian\Downloads\SweetFX-Configurator_standalone_1.3.3.zip
2013-12-21 21:33 - 2013-12-21 21:33 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Ubisoft
2013-12-21 21:33 - 2013-12-21 21:33 - 00000000 ____D C:\ProgramData\Ubisoft
2013-12-20 20:12 - 2013-12-20 20:12 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien
2013-12-20 20:07 - 2013-12-20 20:07 - 00003048 _____ C:\Windows\System32\Tasks\{4651D125-218E-4E31-9687-62E6ACBE8661}
2013-12-20 20:04 - 2013-12-20 20:04 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-12-20 20:04 - 2013-12-20 20:04 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
2013-12-20 20:00 - 2013-12-21 21:28 - 00049017 _____ C:\Windows\DirectX.log
2013-12-20 19:54 - 2013-12-20 20:08 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-12-20 19:52 - 2013-12-20 19:52 - 00003048 _____ C:\Windows\System32\Tasks\{7CA66842-3541-4E5E-9177-D1BF627B43F4}
2013-12-20 17:21 - 2013-12-05 09:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-12-20 17:21 - 2013-12-05 09:42 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-12-19 21:33 - 2013-12-19 21:33 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
2013-12-18 10:50 - 2013-12-18 10:50 - 00000000 ____D C:\Users\Julian\AppData\Local\Abelssoft
2013-12-18 10:50 - 2013-12-18 10:50 - 00000000 ____D C:\Program Files (x86)\JetDrive
2013-12-18 10:50 - 2013-11-11 11:20 - 00009728 _____ C:\Windows\SysWOW64\WindowsClosingService.exe
2013-12-18 10:50 - 2012-05-22 11:21 - 00037248 _____ (Abelssoft GmbH) C:\Windows\system32\Drivers\jddrv.sys
2013-12-18 10:50 - 2012-05-22 11:21 - 00023040 _____ () C:\Windows\system32\jddac.dll
2013-12-18 10:50 - 2012-05-22 11:21 - 00022016 _____ () C:\Windows\system32\jdnat.dll
2013-12-18 10:50 - 2012-05-22 11:21 - 00008192 _____ () C:\Windows\system32\jdboot.exe
2013-12-18 10:47 - 2013-12-18 10:48 - 30588821 _____ C:\Users\Julian\Downloads\tag18jetdrive.zip
2013-12-16 16:04 - 2013-12-26 20:13 - 00000000 ____D C:\Schule-Bewerbung
2013-12-15 14:00 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-12-15 14:00 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-12-15 14:00 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-12-15 14:00 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-12-15 14:00 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-12-15 14:00 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-12-15 14:00 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-12-15 14:00 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-12-15 13:59 - 2013-12-15 14:26 - 00000000 ____D C:\ComboFix
2013-12-15 12:50 - 2013-12-15 14:00 - 00000000 ____D C:\Qoobox
2013-12-15 12:50 - 2013-12-15 12:50 - 00000000 ____D C:\Windows\erdnt
2013-12-15 12:49 - 2013-12-26 18:32 - 05158590 ____R (Swearware) C:\Users\Julian\Downloads\ComboFix.exe
2013-12-14 14:23 - 2013-12-14 14:24 - 00026944 _____ C:\Addition.txt
2013-12-14 14:22 - 2013-12-26 21:20 - 00015006 _____ C:\Users\Julian\Desktop\FRST.txt
2013-12-14 14:21 - 2013-12-26 21:20 - 01928716 _____ (Farbar) C:\Users\Julian\Desktop\FRST64.exe
2013-12-14 14:21 - 2013-12-26 21:20 - 00000000 ____D C:\Users\Julian\Desktop\FRST-OlderVersion
2013-12-13 23:13 - 2013-12-14 12:05 - 00026530 _____ C:\Users\Julian\Downloads\Addition.txt
2013-12-13 23:12 - 2013-12-14 12:41 - 00090096 _____ C:\Users\Julian\Downloads\FRST.txt
2013-12-13 23:11 - 2013-12-26 21:20 - 00000000 ____D C:\FRST
2013-12-13 23:10 - 2013-12-23 18:22 - 00000000 ____D C:\Users\Julian\AppData\Local\CrashDumps
2013-12-13 18:41 - 2013-12-13 18:42 - 129598176 _____ C:\Users\Julian\Downloads\avira_free_antivirus_de_14.0.2.286.exe
2013-12-13 18:16 - 2013-12-13 18:16 - 00000084 _____ C:\Users\Julian\Downloads\PIMMEL.txt
2013-12-12 14:40 - 2013-12-12 14:40 - 00000000 ____D C:\Users\Julian\AppData\Local\Razer
2013-12-11 21:02 - 2013-12-11 21:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_RzFilter_01009.Wdf
2013-12-11 21:01 - 2013-12-11 21:01 - 00000000 ____D C:\Windows\Razer Core
2013-12-11 21:01 - 2013-12-11 21:01 - 00000000 ____D C:\ProgramData\Razer
2013-12-11 21:01 - 2013-12-11 21:01 - 00000000 ____D C:\Program Files (x86)\Razer
2013-12-11 21:01 - 2013-11-21 05:37 - 00129472 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzDxgk.sys
2013-12-11 21:01 - 2013-11-21 05:37 - 00074432 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzFilter.sys
2013-12-11 20:59 - 2013-12-11 21:00 - 47307072 _____ (Razer Inc.) C:\Users\Julian\Downloads\RazerComms1.81.20.exe
2013-12-11 20:54 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 20:54 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 20:54 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-11 20:54 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-11 20:53 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 20:53 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 20:53 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 20:53 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 20:53 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 20:53 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 20:53 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 20:53 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 20:53 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 20:53 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 20:53 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 20:53 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 20:53 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 20:53 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 20:53 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 20:53 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 20:53 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 20:53 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 20:53 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 20:53 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 20:53 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 20:53 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 20:53 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 20:53 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 20:53 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 20:53 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 20:53 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 20:53 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 20:53 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 20:53 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 20:53 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 19:36 - 2013-12-11 20:52 - 03135866 _____ C:\Users\Julian\Downloads\675999.m.mp4.opdownload
2013-12-11 17:09 - 2013-12-26 21:04 - 00000378 _____ C:\Windows\Tasks\SmartPCFix Task.job
2013-12-11 17:09 - 2013-12-13 18:51 - 00000000 ____D C:\Program Files (x86)\SmartPCFix
2013-12-11 17:09 - 2013-12-11 17:10 - 09009660 _____ (Microsoft Corporation) C:\Users\Julian\Downloads\downloadmanager_8d590f63-da00-4058-ab93-bf04be3483b6.tmp
2013-12-11 17:09 - 2013-12-11 17:09 - 00002806 _____ C:\Windows\System32\Tasks\SmartPCFix Task
2013-12-11 17:09 - 2013-12-11 17:09 - 00000000 ____D C:\Users\Julian\AppData\Roaming\SmartPCFix
2013-12-11 13:38 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 13:38 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 13:38 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 13:38 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 13:38 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 13:38 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 13:38 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 13:38 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 13:38 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 13:38 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 13:38 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 13:38 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 13:38 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 13:38 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 13:38 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 13:38 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 13:38 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 13:38 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 13:38 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 21:00 - 2013-12-10 21:00 - 00021472 _____ C:\Users\Julian\Desktop\Nawi 2.odt
2013-12-10 20:47 - 2013-12-10 20:47 - 00000000 ____D C:\Users\Julian\AppData\Local\Adobe
2013-12-10 20:23 - 2013-12-10 20:23 - 00001045 _____ C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FuzeZip.lnk
2013-12-10 20:23 - 2013-12-10 20:23 - 00000000 ____D C:\Users\Julian\AppData\Local\FuzeZip
2013-12-10 20:22 - 2013-12-10 20:22 - 00000000 ____D C:\Users\Julian\AppData\Local\fuzezipmusictoolbardla
2013-12-10 20:21 - 2013-12-10 20:23 - 00000000 ____D C:\Program Files (x86)\FuzeZip
2013-12-10 20:21 - 2013-12-10 20:21 - 01327776 _____ (Koyote-Lab Inc.) C:\Users\Julian\Downloads\FuzeZipSetup-r153-w-bc.exe
2013-12-10 20:19 - 2013-12-10 20:20 - 00000000 ____D C:\ProgramData\EPSON
2013-12-10 20:19 - 2013-12-10 20:19 - 00000000 ____D C:\Program Files (x86)\epson
2013-12-10 20:19 - 2009-05-01 00:00 - 00128392 _____ (Seiko Epson Corporation) C:\Windows\system32\esdevapp.exe
2013-12-10 20:19 - 2009-05-01 00:00 - 00017408 _____ (SEIKO EPSON CORP.) C:\Windows\system32\esxcdev.dll
2013-12-10 20:19 - 2008-11-17 00:00 - 00459776 _____ (Seiko Epson Corporation) C:\Windows\system32\esxwiaud.dll
2013-12-10 20:19 - 2008-08-08 02:09 - 00108032 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_ILMFDE.DLL
2013-12-10 20:19 - 2007-12-07 02:01 - 00081408 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_IBCBFDE.DLL
2013-12-10 20:19 - 2007-04-10 01:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\Windows\system32\E_GCINST.DLL
2013-12-10 20:18 - 2013-12-10 20:18 - 16489472 _____ C:\Users\Julian\Downloads\epson323814eu.exe
2013-12-10 20:18 - 2013-12-10 20:18 - 12872704 _____ C:\Users\Julian\Downloads\epson323810eu.exe
2013-12-10 16:45 - 2013-12-16 16:35 - 00000000 ____D C:\Program Files (x86)\Opera
2013-12-10 16:45 - 2013-12-10 16:45 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Opera Software
2013-12-10 16:45 - 2013-12-10 16:45 - 00000000 ____D C:\Users\Julian\AppData\Local\Opera Software
2013-12-10 16:41 - 2013-12-10 16:44 - 33806104 _____ (Opera Software ASA) C:\Users\Julian\Desktop\Opera_18.0.1284.63_Setup.exe
2013-12-10 16:25 - 2013-12-10 16:25 - 00022843 _____ C:\Users\Julian\Downloads\Unbenannt 1 (2).odt
2013-12-10 16:24 - 2013-12-10 16:24 - 00022843 _____ C:\Users\Julian\Downloads\Unbenannt 1 (1).odt
2013-12-10 16:16 - 2013-12-10 16:28 - 00693973 _____ C:\Users\Julian\Desktop\Nawi-Projekt !.odt
2013-12-07 20:39 - 2013-12-07 20:39 - 00080988 _____ C:\Users\Julian\Downloads\watch_later (1)
2013-12-07 20:38 - 2013-12-07 20:38 - 00080988 _____ C:\Users\Julian\Downloads\watch_later
2013-12-06 12:31 - 2013-12-06 12:33 - 00000000 ____D C:\Users\Julian\Desktop\Gute Filme
2013-12-05 19:21 - 2013-12-05 19:21 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Frhed
2013-12-05 19:21 - 2013-12-05 19:21 - 00000000 ____D C:\Program Files (x86)\Frhed
2013-12-05 19:20 - 2013-12-05 19:20 - 00725124 _____ C:\Users\Julian\Downloads\Frhed-1.6.0-Setup.exe
2013-12-05 19:07 - 2013-12-05 19:07 - 00000000 ____D C:\Users\Julian\AppData\Local\Realmware
2013-12-05 19:06 - 2013-12-05 19:06 - 03276413 _____ (Realmware) C:\Users\Julian\Downloads\BF3SE-2.3.exe
2013-12-05 19:06 - 2013-12-05 19:06 - 00000000 ____D C:\Program Files\Realmware
2013-12-04 13:49 - 2013-12-26 20:16 - 00383942 _____ C:\Windows\PFRO.log
2013-12-01 19:59 - 2013-12-01 19:59 - 00670304 _____ (Shark Labs) C:\Users\Julian\Downloads\CFSetup342.exe
2013-12-01 13:13 - 2013-12-01 13:14 - 00000000 ____D C:\Users\Julian\AppData\Local\Windows Live Writer
2013-12-01 13:13 - 2013-12-01 13:13 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Windows Live Writer
2013-11-30 20:00 - 2013-12-26 21:04 - 00015841 _____ C:\Windows\setupact.log
2013-11-30 20:00 - 2013-11-30 20:00 - 00000000 _____ C:\Windows\setuperr.log
2013-11-28 18:06 - 2013-11-28 18:06 - 03821064 _____ C:\Users\Julian\Downloads\battlelog-web-plugins_2.3.2_130.exe
2013-11-27 14:52 - 2013-11-27 14:52 - 03820448 _____ C:\Users\Julian\Downloads\battlelog-web-plugins_2.3.2_129.exe
==================== One Month Modified Files and Folders =======
2013-12-26 21:20 - 2013-12-14 14:22 - 00015006 _____ C:\Users\Julian\Desktop\FRST.txt
2013-12-26 21:20 - 2013-12-14 14:21 - 01928716 _____ (Farbar) C:\Users\Julian\Desktop\FRST64.exe
2013-12-26 21:20 - 2013-12-14 14:21 - 00000000 ____D C:\Users\Julian\Desktop\FRST-OlderVersion
2013-12-26 21:20 - 2013-12-13 23:11 - 00000000 ____D C:\FRST
2013-12-26 21:19 - 2013-09-04 11:30 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Skype
2013-12-26 21:16 - 2013-05-21 09:53 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-26 21:11 - 2009-07-14 05:45 - 00031856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-26 21:11 - 2009-07-14 05:45 - 00031856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-26 21:07 - 2013-09-04 09:53 - 02064429 _____ C:\Windows\WindowsUpdate.log
2013-12-26 21:04 - 2013-12-11 17:09 - 00000378 _____ C:\Windows\Tasks\SmartPCFix Task.job
2013-12-26 21:04 - 2013-11-30 20:00 - 00015841 _____ C:\Windows\setupact.log
2013-12-26 21:04 - 2013-11-18 15:06 - 00000000 ____D C:\Users\Julian\AppData\Local\Overwolf
2013-12-26 21:04 - 2013-09-04 11:28 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-26 21:04 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-26 21:03 - 2013-09-02 14:05 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-26 20:51 - 2013-09-04 11:28 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-26 20:47 - 2013-12-26 20:47 - 00001197 _____ C:\Users\Julian\Desktop\JRT.txt
2013-12-26 20:42 - 2013-12-26 20:42 - 00000000 ____D C:\Windows\ERUNT
2013-12-26 20:41 - 2013-12-26 20:41 - 01034531 _____ (Thisisu) C:\Users\Julian\Downloads\JRT.exe
2013-12-26 20:37 - 2013-12-26 20:36 - 00000000 ____D C:\AdwCleaner
2013-12-26 20:36 - 2013-12-26 20:35 - 01233962 _____ C:\Users\Julian\Downloads\adwcleaner.exe
2013-12-26 20:21 - 2013-10-04 13:16 - 00000932 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2124055722-383917122-1893886807-1001UA.job
2013-12-26 20:16 - 2013-12-04 13:49 - 00383942 _____ C:\Windows\PFRO.log
2013-12-26 20:13 - 2013-12-16 16:04 - 00000000 ____D C:\Schule-Bewerbung
2013-12-26 18:35 - 2013-12-26 18:35 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-26 18:35 - 2013-12-26 18:35 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Malwarebytes
2013-12-26 18:35 - 2013-12-26 18:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-26 18:35 - 2013-12-26 18:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-26 18:34 - 2013-12-26 18:34 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Julian\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-26 18:32 - 2013-12-26 18:31 - 00000000 ____D C:\32788R22FWJFW
2013-12-26 18:32 - 2013-12-15 12:49 - 05158590 ____R (Swearware) C:\Users\Julian\Downloads\ComboFix.exe
2013-12-26 18:26 - 2013-09-04 11:33 - 00000000 ____D C:\Users\Julian\AppData\Local\PMB Files
2013-12-26 17:09 - 2013-09-04 12:17 - 00000000 ____D C:\Users\Julian\AppData\Roaming\TS3Client
2013-12-26 16:54 - 2013-12-26 16:52 - 00001971 _____ C:\Users\Public\Desktop\Overwolf.lnk
2013-12-26 16:54 - 2013-11-19 13:58 - 00000000 ____D C:\Program Files (x86)\Overwolf
2013-12-26 16:52 - 2013-12-26 16:50 - 00001211 _____ C:\Users\Julian\Desktop\TeamSpeak 3 Client.lnk
2013-12-26 16:49 - 2013-12-26 16:47 - 32520760 _____ (TeamSpeak Systems GmbH) C:\Users\Julian\Downloads\TeamSpeak3-Client-win64-3.0.13.1.exe
2013-12-26 15:16 - 2013-09-05 08:58 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-26 14:45 - 2013-12-26 14:45 - 00000219 _____ C:\Users\Julian\Desktop\Left 4 Dead 2.url
2013-12-26 14:45 - 2013-09-04 11:33 - 00000000 ____D C:\ProgramData\PMB Files
2013-12-26 14:21 - 2013-10-04 13:16 - 00000910 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2124055722-383917122-1893886807-1001Core.job
2013-12-25 19:13 - 2013-12-22 23:55 - 00000000 ____D C:\Program Files (x86)\Desura
2013-12-25 19:12 - 2013-12-23 10:50 - 00001859 _____ C:\Users\Public\Desktop\Desura.lnk
2013-12-25 18:17 - 2013-12-25 18:17 - 01214299 _____ C:\Users\Julian\Downloads\Julian.htm
2013-12-25 18:17 - 2013-12-25 18:17 - 00000000 ____D C:\Users\Julian\Downloads\Julian_files
2013-12-23 20:52 - 2013-10-27 13:54 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-12-23 20:52 - 2013-10-27 13:43 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-23 20:52 - 2013-10-27 13:43 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-12-23 20:51 - 2013-10-26 15:03 - 00000000 ____D C:\Program Files (x86)\Origin
2013-12-23 18:22 - 2013-12-13 23:10 - 00000000 ____D C:\Users\Julian\AppData\Local\CrashDumps
2013-12-23 00:13 - 2013-12-23 00:13 - 00000000 ____D C:\Users\Julian\AppData\Local\Desura
2013-12-23 00:11 - 2013-09-04 11:28 - 00000000 ____D C:\Users\Julian\AppData\Local\Deployment
2013-12-23 00:04 - 2013-12-23 00:03 - 21452408 _____ C:\Users\Julian\Downloads\AC_Mod_Pack.rar
2013-12-22 23:57 - 2013-12-22 16:12 - 00034308 _____ C:\Windows\SysWOW64\bassmod.dll
2013-12-22 23:55 - 2013-12-22 23:55 - 00000000 ____D C:\ProgramData\Desura
2013-12-22 23:55 - 2013-12-22 23:54 - 01252424 _____ C:\Users\Julian\Downloads\DesuraInstaller.exe
2013-12-22 16:24 - 2013-11-15 13:03 - 00000000 ____D C:\Users\Julian\Desktop\Riot Games
2013-12-22 16:12 - 2013-12-22 16:12 - 00403463 _____ C:\Users\Julian\Downloads\d2a536_4e9f41d31ec4c.zip
2013-12-22 16:12 - 2013-12-22 16:12 - 00003180 _____ C:\Windows\System32\Tasks\{72480F35-5D47-411B-9910-6C607904743A}
2013-12-22 15:57 - 2013-12-22 15:57 - 00009094 _____ C:\Users\Julian\Downloads\SweetFX_Settings_Assassin's Creed II_AC2 total improvements .txt
2013-12-22 15:51 - 2013-12-22 15:51 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SweetFX Configurator
2013-12-22 15:51 - 2013-09-04 11:28 - 00000000 ____D C:\Users\Julian\AppData\Local\Apps\2.0
2013-12-22 15:50 - 2013-12-22 15:50 - 00492398 _____ C:\Users\Julian\Downloads\SweetFX-Configurator_1.3.3.zip
2013-12-22 15:50 - 2013-12-22 15:50 - 00281567 _____ C:\Users\Julian\Downloads\SweetFX-Configurator_standalone_1.3.3.zip
2013-12-21 21:33 - 2013-12-21 21:33 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Ubisoft
2013-12-21 21:33 - 2013-12-21 21:33 - 00000000 ____D C:\ProgramData\Ubisoft
2013-12-21 21:28 - 2013-12-20 20:00 - 00049017 _____ C:\Windows\DirectX.log
2013-12-21 21:20 - 2013-11-10 13:48 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-12-21 21:20 - 2013-09-20 17:31 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-20 20:12 - 2013-12-20 20:12 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Meine Der Herr der Ringe™, Aufstieg des Hexenkönigs™-Dateien
2013-12-20 20:12 - 2013-10-14 21:08 - 00000000 ___RD C:\Users\Julian\Desktop\Games
2013-12-20 20:11 - 2013-09-04 09:53 - 00000000 ____D C:\Users\Julian\AppData\Local\Windows Live
2013-12-20 20:08 - 2013-12-20 19:54 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-12-20 20:07 - 2013-12-20 20:07 - 00003048 _____ C:\Windows\System32\Tasks\{4651D125-218E-4E31-9687-62E6ACBE8661}
2013-12-20 20:04 - 2013-12-20 20:04 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-12-20 20:04 - 2013-12-20 20:04 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien
2013-12-20 20:04 - 2013-09-04 09:54 - 00000000 ____D C:\Users\Julian\AppData\Local\VirtualStore
2013-12-20 19:52 - 2013-12-20 19:52 - 00003048 _____ C:\Windows\System32\Tasks\{7CA66842-3541-4E5E-9177-D1BF627B43F4}
2013-12-20 19:46 - 2013-11-07 10:18 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Spotify
2013-12-20 11:49 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-19 21:33 - 2013-12-19 21:33 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
2013-12-19 14:40 - 2013-11-07 10:18 - 00000000 ____D C:\Users\Julian\AppData\Local\Spotify
2013-12-18 11:01 - 2013-11-07 10:18 - 00001797 _____ C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2013-12-18 10:50 - 2013-12-18 10:50 - 00000000 ____D C:\Users\Julian\AppData\Local\Abelssoft
2013-12-18 10:50 - 2013-12-18 10:50 - 00000000 ____D C:\Program Files (x86)\JetDrive
2013-12-18 10:48 - 2013-12-18 10:47 - 30588821 _____ C:\Users\Julian\Downloads\tag18jetdrive.zip
2013-12-16 16:35 - 2013-12-10 16:45 - 00000000 ____D C:\Program Files (x86)\Opera
2013-12-15 19:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-15 14:26 - 2013-12-15 13:59 - 00000000 ____D C:\ComboFix
2013-12-15 14:22 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2013-12-15 14:00 - 2013-12-15 12:50 - 00000000 ____D C:\Qoobox
2013-12-15 12:50 - 2013-12-15 12:50 - 00000000 ____D C:\Windows\erdnt
2013-12-14 14:24 - 2013-12-14 14:23 - 00026944 _____ C:\Addition.txt
2013-12-14 12:41 - 2013-12-13 23:12 - 00090096 _____ C:\Users\Julian\Downloads\FRST.txt
2013-12-14 12:05 - 2013-12-13 23:13 - 00026530 _____ C:\Users\Julian\Downloads\Addition.txt
2013-12-14 12:02 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-13 18:51 - 2013-12-11 17:09 - 00000000 ____D C:\Program Files (x86)\SmartPCFix
2013-12-13 18:42 - 2013-12-13 18:41 - 129598176 _____ C:\Users\Julian\Downloads\avira_free_antivirus_de_14.0.2.286.exe
2013-12-13 18:16 - 2013-12-13 18:16 - 00000084 _____ C:\Users\Julian\Downloads\PIMMEL.txt
2013-12-13 14:56 - 2010-11-21 07:50 - 00696620 _____ C:\Windows\system32\perfh007.dat
2013-12-13 14:56 - 2010-11-21 07:50 - 00147916 _____ C:\Windows\system32\perfc007.dat
2013-12-13 14:56 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-12 14:40 - 2013-12-12 14:40 - 00000000 ____D C:\Users\Julian\AppData\Local\Razer
2013-12-12 14:40 - 2009-07-14 05:45 - 00304696 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 21:02 - 2013-12-11 21:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_RzFilter_01009.Wdf
2013-12-11 21:02 - 2013-09-04 09:54 - 00068040 _____ C:\Users\Julian\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-11 21:01 - 2013-12-11 21:01 - 00000000 ____D C:\Windows\Razer Core
2013-12-11 21:01 - 2013-12-11 21:01 - 00000000 ____D C:\ProgramData\Razer
2013-12-11 21:01 - 2013-12-11 21:01 - 00000000 ____D C:\Program Files (x86)\Razer
2013-12-11 21:00 - 2013-12-11 20:59 - 47307072 _____ (Razer Inc.) C:\Users\Julian\Downloads\RazerComms1.81.20.exe
2013-12-11 20:52 - 2013-12-11 19:36 - 03135866 _____ C:\Users\Julian\Downloads\675999.m.mp4.opdownload
2013-12-11 20:16 - 2013-05-21 09:53 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 20:16 - 2012-04-16 09:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 20:16 - 2012-01-13 14:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 17:10 - 2013-12-11 17:09 - 09009660 _____ (Microsoft Corporation) C:\Users\Julian\Downloads\downloadmanager_8d590f63-da00-4058-ab93-bf04be3483b6.tmp
2013-12-11 17:09 - 2013-12-11 17:09 - 00002806 _____ C:\Windows\System32\Tasks\SmartPCFix Task
2013-12-11 17:09 - 2013-12-11 17:09 - 00000000 ____D C:\Users\Julian\AppData\Roaming\SmartPCFix
2013-12-10 21:00 - 2013-12-10 21:00 - 00021472 _____ C:\Users\Julian\Desktop\Nawi 2.odt
2013-12-10 20:47 - 2013-12-10 20:47 - 00000000 ____D C:\Users\Julian\AppData\Local\Adobe
2013-12-10 20:47 - 2013-09-04 09:53 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Adobe
2013-12-10 20:23 - 2013-12-10 20:23 - 00001045 _____ C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FuzeZip.lnk
2013-12-10 20:23 - 2013-12-10 20:23 - 00000000 ____D C:\Users\Julian\AppData\Local\FuzeZip
2013-12-10 20:23 - 2013-12-10 20:21 - 00000000 ____D C:\Program Files (x86)\FuzeZip
2013-12-10 20:22 - 2013-12-10 20:22 - 00000000 ____D C:\Users\Julian\AppData\Local\fuzezipmusictoolbardla
2013-12-10 20:21 - 2013-12-10 20:21 - 01327776 _____ (Koyote-Lab Inc.) C:\Users\Julian\Downloads\FuzeZipSetup-r153-w-bc.exe
2013-12-10 20:20 - 2013-12-10 20:19 - 00000000 ____D C:\ProgramData\EPSON
2013-12-10 20:20 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-12-10 20:19 - 2013-12-10 20:19 - 00000000 ____D C:\Program Files (x86)\epson
2013-12-10 20:18 - 2013-12-10 20:18 - 16489472 _____ C:\Users\Julian\Downloads\epson323814eu.exe
2013-12-10 20:18 - 2013-12-10 20:18 - 12872704 _____ C:\Users\Julian\Downloads\epson323810eu.exe
2013-12-10 16:45 - 2013-12-10 16:45 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Opera Software
2013-12-10 16:45 - 2013-12-10 16:45 - 00000000 ____D C:\Users\Julian\AppData\Local\Opera Software
2013-12-10 16:44 - 2013-12-10 16:41 - 33806104 _____ (Opera Software ASA) C:\Users\Julian\Desktop\Opera_18.0.1284.63_Setup.exe
2013-12-10 16:28 - 2013-12-10 16:16 - 00693973 _____ C:\Users\Julian\Desktop\Nawi-Projekt !.odt
2013-12-10 16:26 - 2013-09-22 11:40 - 00000000 ____D C:\Users\Julian\Desktop\Informatik
2013-12-10 16:25 - 2013-12-10 16:25 - 00022843 _____ C:\Users\Julian\Downloads\Unbenannt 1 (2).odt
2013-12-10 16:24 - 2013-12-10 16:24 - 00022843 _____ C:\Users\Julian\Downloads\Unbenannt 1 (1).odt
2013-12-10 15:51 - 2013-10-16 06:41 - 00009734 _____ C:\Windows\system32\lvcoinst.log
2013-12-10 03:13 - 2013-10-29 17:54 - 01100248 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-12-10 03:13 - 2013-10-29 17:54 - 00982232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-12-09 21:19 - 2013-10-16 06:41 - 00000000 ____D C:\Program Files\Common Files\logishrd
2013-12-07 20:39 - 2013-12-07 20:39 - 00080988 _____ C:\Users\Julian\Downloads\watch_later (1)
2013-12-07 20:38 - 2013-12-07 20:38 - 00080988 _____ C:\Users\Julian\Downloads\watch_later
2013-12-06 16:43 - 2013-11-22 03:53 - 00000000 ____D C:\Users\Julian\Documents\Assassin's Creed IV Black Flag
2013-12-06 12:33 - 2013-12-06 12:31 - 00000000 ____D C:\Users\Julian\Desktop\Gute Filme
2013-12-05 21:07 - 2013-09-04 09:56 - 00000000 ____D C:\Users\Julian\AppData\Local\NVIDIA
2013-12-05 21:06 - 2013-11-16 11:49 - 00000000 ____D C:\Users\Julian\AppData\Local\NVIDIA Corporation
2013-12-05 21:06 - 2013-09-02 14:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-12-05 21:06 - 2013-09-02 14:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-12-05 21:06 - 2013-09-02 13:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-12-05 19:21 - 2013-12-05 19:21 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Frhed
2013-12-05 19:21 - 2013-12-05 19:21 - 00000000 ____D C:\Program Files (x86)\Frhed
2013-12-05 19:20 - 2013-12-05 19:20 - 00725124 _____ C:\Users\Julian\Downloads\Frhed-1.6.0-Setup.exe
2013-12-05 19:07 - 2013-12-05 19:07 - 00000000 ____D C:\Users\Julian\AppData\Local\Realmware
2013-12-05 19:06 - 2013-12-05 19:06 - 03276413 _____ (Realmware) C:\Users\Julian\Downloads\BF3SE-2.3.exe
2013-12-05 19:06 - 2013-12-05 19:06 - 00000000 ____D C:\Program Files\Realmware
2013-12-05 09:42 - 2013-12-20 17:21 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-12-05 09:42 - 2013-12-20 17:21 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-12-05 09:42 - 2013-09-04 11:24 - 00035104 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-12-03 20:53 - 2013-11-20 15:04 - 00000000 ____D C:\Users\Julian\AppData\Roaming\TeamViewer
2013-12-03 20:51 - 2013-09-28 17:45 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-12-01 19:59 - 2013-12-01 19:59 - 00670304 _____ (Shark Labs) C:\Users\Julian\Downloads\CFSetup342.exe
2013-12-01 13:14 - 2013-12-01 13:13 - 00000000 ____D C:\Users\Julian\AppData\Local\Windows Live Writer
2013-12-01 13:13 - 2013-12-01 13:13 - 00000000 ____D C:\Users\Julian\AppData\Roaming\Windows Live Writer
2013-11-30 20:00 - 2013-11-30 20:00 - 00000000 _____ C:\Windows\setuperr.log
2013-11-30 18:35 - 2013-11-13 14:12 - 00000000 ____D C:\Users\Julian\Desktop\Windows 7
2013-11-28 18:06 - 2013-11-28 18:06 - 03821064 _____ C:\Users\Julian\Downloads\battlelog-web-plugins_2.3.2_130.exe
2013-11-28 18:06 - 2013-10-27 13:50 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-11-28 15:46 - 2013-09-04 11:28 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-11-28 15:46 - 2013-09-04 11:28 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-11-27 14:52 - 2013-11-27 14:52 - 03820448 _____ C:\Users\Julian\Downloads\battlelog-web-plugins_2.3.2_129.exe
2013-11-26 12:54 - 2013-12-11 20:53 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 11:19 - 2013-12-11 20:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 11:18 - 2013-12-11 20:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 11:11 - 2013-12-11 20:53 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 10:48 - 2013-12-11 20:53 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 10:46 - 2013-12-11 20:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 10:41 - 2013-12-11 20:53 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 10:29 - 2013-12-11 20:53 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 10:27 - 2013-12-11 20:53 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 10:23 - 2013-12-11 20:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 10:21 - 2013-12-11 20:53 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 10:18 - 2013-12-11 20:53 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 10:18 - 2013-12-11 20:53 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 10:16 - 2013-12-11 20:53 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 09:57 - 2013-12-11 20:53 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 09:38 - 2013-12-11 20:53 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 09:38 - 2013-12-11 20:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 09:35 - 2013-12-11 20:53 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 09:32 - 2013-12-11 20:53 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 09:28 - 2013-12-11 20:53 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 09:16 - 2013-12-11 20:53 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 09:02 - 2013-12-11 20:53 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 08:48 - 2013-12-11 20:53 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 08:32 - 2013-12-11 20:53 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 08:26 - 2013-12-11 20:53 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 08:07 - 2013-12-11 20:53 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 07:40 - 2013-12-11 20:53 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 07:34 - 2013-12-11 20:53 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 07:34 - 2013-12-11 20:53 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 07:33 - 2013-12-11 20:53 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 07:27 - 2013-12-11 20:53 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
Some content of TEMP:
====================
C:\Users\Julian\AppData\Local\Temp\AutoRun.exe
C:\Users\Julian\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Julian\AppData\Local\Temp\avgnt.exe
C:\Users\Julian\AppData\Local\Temp\EAInstall.dll
C:\Users\Julian\AppData\Local\Temp\eauninstall.exe
C:\Users\Julian\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-20 20:43
==================== End Of Log ============================ --- --- ---
--- --- ---
Übrigens das mit Combofix hat irgendwie nicht funktioniert.. |