![]() |
|
Log-Analyse und Auswertung: PUP.Optional.Installcore / Windows 7 / Neuer PCWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() ![]() | ![]() PUP.Optional.Installcore / Windows 7 / Neuer PC Hey Leute Man glaubt es kaum aber mein neuer PC hat schon wieder irgendwas eingefangen. Das Ding ist erst 2 Wochen alt. Könnt ihr mir sagen was das ist? Schrauber hilf mir bitte ![]() Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 08.05.2014 Scan Time: 15:45:29 Logfile: Administrator: Yes Version: 2.00.1.1004 Malware Database: v2014.05.08.05 Rootkit Database: v2014.03.27.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Chameleon: Disabled OS: Windows 7 CPU: x64 File System: NTFS User: David Scan Type: Threat Scan Result: Completed Objects Scanned: 250200 Time Elapsed: 8 min, 17 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Shuriken: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 6 PUP.Optional.Speedial.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLCORE\Speedial, , [1cd93618cab18caa90693f3a30d27b85], PUP.Optional.Speedial.A, HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\speedial, , [e411183657242c0a01fc94e562a0fa06], PUP.Optional.InstallCore.A, HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [07eea2acc8b3053102fbade423df47b9], PUP.Optional.Speedial.A, HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\Speedial, , [19dc163874073cfa48b24b2e28dac33d], PUP.Optional.InstallCore.A, HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [ae47fd51255662d4b76cf4b4fb08768a], PUP.Optional.Speedial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Speedial, , [c62faba3e596bb7b7108c3b6639f56aa], Registry Values: 1 PUP.Optional.InstallCore.A, HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, , [ae47fd51255662d4b76cf4b4fb08768a] Registry Data: 4 PUP.Optional.Speedial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=, Good: (www.google.com), Bad: (hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=),,[f1043618285354e245b73ef6ca3a3ec2] PUP.Optional.Speedial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|Tabs, hxxp://speedial.com/?f=2&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=, Good: (www.google.com), Bad: (hxxp://speedial.com/?f=2&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=),,[d61f044a39424aece51963d1887c718f] PUP.Optional.Speedial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=, Good: (www.google.com), Bad: (hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=),,[27cec6888af12c0a6399d65ed034d828] PUP.Optional.Speedial.A, HKU\S-1-5-21-2520808294-4166714027-1215053595-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=, Good: (www.google.com), Bad: (hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir=),,[2fc6fe50c9b2c472649934009e66817f] Folders: 6 PUP.Optional.Speedial.A, C:\Program Files (x86)\Speedial, , [c62faba3e596bb7b7108c3b6639f56aa], PUP.Optional.Speedial.A, C:\Program Files (x86)\Speedial\1.8.29.15, , [c62faba3e596bb7b7108c3b6639f56aa], PUP.Optional.Speedial.A, C:\Program Files (x86)\Speedial\1.8.29.15\bh, , [c62faba3e596bb7b7108c3b6639f56aa], PUP.Optional.Speedial.A, C:\Users\David\AppData\Roaming\Speedial, , [936287c7f5860234bcc0f485f111c838], PUP.Optional.Speedial.A, C:\Users\David\AppData\Roaming\Speedial\icons_2.20.6.0, , [936287c7f5860234bcc0f485f111c838], PUP.Optional.Speedial.A, C:\Users\David\AppData\Roaming\Speedial\UpdateProc, , [936287c7f5860234bcc0f485f111c838], Files: 10 PUP.Optional.InstallCore, C:\$Recycle.Bin\S-1-5-21-2520808294-4166714027-1215053595-1000\$RI2Q0PF.exe, , [48ad2d2103780a2c030c6dc6e024e61a], PUP.Optional.InstallCore, C:\Users\David\AppData\Local\Temp\ICReinstall_UltimateCodec.exe, , [6491212d94e773c356b922118f7557a9], PUP.Optional.Speedial.A, C:\Program Files (x86)\Speedial\1.8.29.15\FavIcon.ico, , [c62faba3e596bb7b7108c3b6639f56aa], PUP.Optional.Speedial.A, C:\Program Files (x86)\Speedial\1.8.29.15\Sqlite3.dll, , [c62faba3e596bb7b7108c3b6639f56aa], PUP.Optional.Speedial.A, C:\Program Files (x86)\Speedial\1.8.29.15\uninst.dat, , [c62faba3e596bb7b7108c3b6639f56aa], PUP.Optional.Speedial.A, C:\Program Files (x86)\Speedial\1.8.29.15\uninstall.exe, , [c62faba3e596bb7b7108c3b6639f56aa], PUP.Optional.Speedial.A, C:\Users\David\AppData\Roaming\Speedial\UpdateProc\config.dat, , [936287c7f5860234bcc0f485f111c838], PUP.Optional.Speedial.A, C:\Users\David\AppData\Roaming\Speedial\UpdateProc\info.dat, , [936287c7f5860234bcc0f485f111c838], PUP.Optional.Speedial.A, C:\Users\David\AppData\Roaming\Speedial\UpdateProc\STTL.DAT, , [936287c7f5860234bcc0f485f111c838], PUP.Optional.Speedial.A, C:\Users\David\AppData\Roaming\Speedial\UpdateProc\TTL.DAT, , [936287c7f5860234bcc0f485f111c838], Physical Sectors: 0 (No malicious items detected) (end) Edit: Hier die 2 FRST LOG´s Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-05-2014 01 Ran by David at 2014-05-08 15:54:46 Running from C:\Users\David\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.5.0.367 - Adobe Systems Incorporated) Adobe Dreamweaver CC (HKLM-x32\...\{00E094E1-A852-11E2-803D-ACEA632352B4}) (Version: 13 - Adobe Systems Incorporated) Adobe Extension Manager CC (HKLM-x32\...\{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}) (Version: 7.1.1 - Adobe Systems Incorporated) Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.20.100.30911 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.0911.2154.37488 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{00957033-C081-5235-665A-A014A6E2FF7B}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80911.2216 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden Arma 2 (HKLM-x32\...\Steam App 33900) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead (HKLM-x32\...\Steam App 33930) (Version: - Bohemia Interactive) Avira (HKLM-x32\...\{e932572a-a65f-40cb-bdb9-fde856c8b6f5}) (Version: 1.1.12.20001 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.12.20001 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0911.2154.37488 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0911.2154.37488 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0911.2154.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0911.2153.37488 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0911.2154.37488 - Advanced Micro Devices, Inc.) Hidden Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve) DayZ Commander (HKLM-x32\...\{B3653588-3AC0-4A1D-950F-D96531E84374}) (Version: 0.92.91 - Dotjosh Studios) Free YouTube to MP3 Converter version 3.12.34.430 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.34.430 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.115 - Google Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation) Intel(R) Network Connections 18.5.54.0 (HKLM\...\PROSetDX) (Version: 18.5.54.0 - Intel) Intel(R) Network Connections 18.5.54.0 (Version: 18.5.54.0 - Intel) Hidden Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve) Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.154 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) ROCCAT Kone XTD Mouse Driver (HKLM-x32\...\{7133137D-DF48-4522-AD88-13C82B7D0A63}) (Version: - Roccat GmbH) RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Speedial (HKLM-x32\...\Speedial) (Version: - Speedial) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) USB Multi-Channel Audio Device (HKLM\...\C-Media CM106 Like Sound Driver) (Version: - ) VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) ==================== Restore Points ========================= 01-05-2014 15:03:50 Installed Intel(R) Network Connections. 01-05-2014 15:11:11 Microsoft Visual C++ 2005 Redistributable (x64) wird installiert 01-05-2014 15:11:49 Microsoft Visual C++ 2005 Redistributable wird installiert 01-05-2014 15:12:23 Installed League of Legends 01-05-2014 15:12:45 DirectX wurde installiert 01-05-2014 15:14:31 Removed League of Legends 01-05-2014 15:15:26 Installed League of Legends 01-05-2014 15:16:26 Windows Update 01-05-2014 15:30:24 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 01-05-2014 15:31:14 Windows Update 01-05-2014 15:32:30 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 01-05-2014 15:39:10 IIF_MSI 01-05-2014 16:23:08 DirectX wurde installiert 01-05-2014 16:44:05 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 01-05-2014 16:50:26 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 03-05-2014 16:58:55 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 03-05-2014 17:05:15 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 05-05-2014 20:19:34 Installed DayZ Commander 05-05-2014 20:20:31 Installed DayZ Commander 06-05-2014 21:41:30 DirectX wurde installiert ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {312E2046-82A0-450F-8497-4FFBC6FEC623} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {321826E4-3D5B-4EA4-A7F2-A06FFD4092D3} - System32\Tasks\AdobeAAMUpdater-1.0-Mongrel-David => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated) Task: {7FB71025-B02D-4B48-A07D-6BDD38B91116} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-01] (Google Inc.) Task: {B7274294-22D5-4BD5-B85E-291E39DD24CE} - System32\Tasks\Speedial => C:\Users\David\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Speedial.job => C:\Users\David\AppData\Roaming\Speedial\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-03-20 11:24 - 2014-03-20 11:24 - 00667808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00860160 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 01043968 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-02-11 20:21 - 2014-02-11 20:21 - 00052736 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-02-11 20:22 - 2014-02-11 20:22 - 00236032 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-05-01 17:56 - 2007-09-02 13:58 - 00495616 _____ () D:\Programme\RocketDock\RocketDock.exe 2014-05-01 18:11 - 2009-11-12 14:25 - 00221184 _____ () C:\Windows\system\Cm106eye.exe 2014-03-20 11:24 - 2014-03-20 11:24 - 05288608 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe 2014-05-07 00:03 - 2014-02-25 11:41 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-04-30 11:38 - 2014-04-30 11:38 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-04-30 11:38 - 2014-04-30 11:38 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-05-01 17:56 - 2007-09-02 13:57 - 00069632 _____ () D:\Programme\RocketDock\RocketDock.dll 2014-05-01 18:11 - 2006-09-13 13:08 - 00491520 _____ () C:\Windows\system\CmAu106.dll 2014-05-01 18:40 - 2012-06-17 11:20 - 00061440 _____ () C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\hiddriver.dll 2014-03-18 23:22 - 2014-03-18 23:22 - 32733088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll 2014-05-07 00:03 - 2014-04-30 11:38 - 00049744 _____ () C:\Users\David\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-03-18 23:22 - 2014-03-18 23:22 - 00742816 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libglesv2.dll 2014-03-18 23:22 - 2014-03-18 23:22 - 00136608 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libegl.dll 2014-05-01 17:40 - 2013-09-03 16:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2014-05-08 13:05 - 2014-05-08 13:05 - 00014336 _____ () C:\Users\David\AppData\Local\Temp\WDE2828.tmp\ml_online.lng 2014-05-08 13:05 - 2014-05-08 13:05 - 00036352 _____ () C:\Users\David\AppData\Local\Temp\WDE2828.tmp\ombrowser.lng 2013-12-13 04:47 - 2013-12-13 04:47 - 00333824 _____ () D:\Programme\Winamp\Plugins\freeform\wacs\freetype\freetype.wac 2014-05-01 17:03 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll 2014-05-01 17:03 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll 2014-05-01 17:03 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 02:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. Error: (05/08/2014 02:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll (596)SUS20ClientDataStore: Die Kopfzeile der Protokolldatei C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log konnte nicht gelesen werden. Fehler -546. System errors: ============= Error: (05/06/2014 11:42:51 PM) (Source: DCOM) (User: ) (EventID: 10010) Description: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} Error: (05/03/2014 06:54:48 PM) (Source: DCOM) (User: ) (EventID: 10010) Description: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} Error: (05/01/2014 06:40:28 PM) (Source: Service Control Manager) (User: ) (EventID: 7000) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (05/01/2014 06:40:28 PM) (Source: Service Control Manager) (User: ) (EventID: 7009) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (05/01/2014 06:39:59 PM) (Source: DCOM) (User: ) (EventID: 10010) Description: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} Error: (05/01/2014 05:45:28 PM) (Source: Service Control Manager) (User: ) (EventID: 7000) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (05/01/2014 05:45:28 PM) (Source: Service Control Manager) (User: ) (EventID: 7009) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (05/01/2014 05:45:28 PM) (Source: DCOM) (User: ) (EventID: 10005) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (05/01/2014 05:45:04 PM) (Source: Service Control Manager) (User: ) (EventID: 7031) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (05/01/2014 05:45:04 PM) (Source: Service Control Manager) (User: ) (EventID: 7024) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Microsoft Office Sessions: ========================= Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 03:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 03:10:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 02:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 Error: (05/08/2014 02:40:59 PM) (Source: ESENT) (User: ) (EventID: 412) Description: wuaueng.dll596SUS20ClientDataStore: C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log-546 ==================== Memory info =========================== Percentage of memory in use: 33% Total physical RAM: 8111.09 MB Available physical RAM: 5372 MB Total Pagefile: 16220.33 MB Available Pagefile: 12893.91 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.31 GB) (Free:153.98 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:292.87 GB) (Free:292.64 GB) NTFS Drive e: () (Fixed) (Total:443.23 GB) (Free:410.33 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: DA688F2A) Partition 1: (Active) - (Size=195 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=443 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-05-2014 01 Ran by David (administrator) on MONGREL on 08-05-2014 15:54:26 Running from C:\Users\David\Downloads Windows 7 Professional (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe () D:\Programme\RocketDock\RocketDock.exe () C:\Windows\system\cm106eye.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Nullsoft, Inc.) D:\Programme\Winamp\winamp.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [Cm106Sound] => C:\Windows\Syswow64\cm106.dll [8151040 2009-10-20] (C-Media Corporation) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-11] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-09-03] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [RoccatKoneXTD] => C:\Program Files (x86)\ROCCAT\Kone XTD Mouse\KoneXTDMonitor.EXE [552960 2013-10-25] (ROCCAT GmbH) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2691480 2014-03-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [182352 2014-04-30] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-25] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-2520808294-4166714027-1215053595-1000\...\Run: [RocketDock] => D:\Programme\RocketDock\RocketDock.exe [495616 2007-09-02] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://speedial.com/?f=1&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= SearchScopes: HKCU - DefaultScope {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_dvd_14_18_ch&cd=2XzuyEtN2Y1L1Qzu0DtDyDtDzyzytD0FtBtCyD0F0AyDzzyDtN0D0Tzu0SzzyDtBtN1L2XzutBtFtBtDtFyCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0FyE0DyCzztAtCtGzz0FzyzytG0B0DtBzytG0Dzz0F0FtGtDyC0CyEtB0EyD0FyBzyyB0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtDyE0B0CzyyCtBtGtAtD0DtAtG0EyD0EtCtGzyzztBtDtGyEyD0FzzyEyBtDtDyEyE0F0B2Q&cr=1358686003&ir= BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect32 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems) FF Plugin HKCU: adobe.com/AdobeExManCCDetect64 - C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://google.de/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-01] CHR Extension: (Adblock Plus) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-01] CHR Extension: (Type Scout) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\fedokkaolmkkoeedicihicdeppjjeamj [2014-05-01] CHR Extension: (AdBlock) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-01] CHR Extension: (TabJump - Intelligenter Tab-Navigator) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokofmgcicpnjchllaccgedmmmbbnbmf [2014-05-01] CHR Extension: (Google Mail-Checker) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-05-01] CHR Extension: (WGT Golf Game) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb [2014-05-01] CHR Extension: (Google Mail) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-01] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-05-01] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [125008 2014-04-30] (Avira Operations GmbH & Co. KG) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-08] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) R3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2009-10-01] (C-Media Electronics Inc) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-08 15:54 - 2014-05-08 15:54 - 00015797 _____ () C:\Users\David\Downloads\FRST.txt 2014-05-08 15:54 - 2014-05-08 15:54 - 00000000 ____D () C:\FRST 2014-05-08 15:53 - 2014-05-08 15:54 - 02063872 _____ (Farbar) C:\Users\David\Downloads\FRST64.exe 2014-05-08 15:45 - 2014-05-08 15:45 - 00007687 _____ () C:\Users\David\Desktop\Neues Textdokument.txt 2014-05-08 15:36 - 2014-05-08 15:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-08 15:36 - 2014-05-08 15:36 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-08 15:36 - 2014-05-08 15:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-08 15:36 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-08 15:36 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-08 15:36 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-08 15:35 - 2014-05-08 15:35 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\David\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-07 17:46 - 2014-05-07 17:46 - 00000000 ____D () C:\Users\David\AppData\Roaming\Avira 2014-05-07 16:46 - 2014-05-07 16:45 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-05-07 00:03 - 2014-02-25 11:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-07 00:03 - 2014-02-25 11:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-07 00:03 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-06 23:46 - 2014-05-07 00:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-06 23:46 - 2014-05-07 00:03 - 00000000 ____D () C:\ProgramData\Avira 2014-05-06 23:46 - 2014-05-07 00:03 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-06 23:42 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-05-06 23:42 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2014-05-06 23:42 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-05-06 23:42 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2014-05-06 23:41 - 2014-05-06 23:41 - 00010009 _____ () C:\Windows\DirectX.log 2014-05-06 23:41 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00069448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-05-06 23:41 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-05-06 23:41 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-05-06 23:41 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-05-06 23:41 - 2008-10-15 07:03 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-05-06 23:41 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-05-06 23:41 - 2008-07-30 06:20 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-05-06 23:41 - 2008-07-30 06:20 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-05-06 23:41 - 2008-07-30 06:20 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-05-06 23:41 - 2008-07-30 06:20 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-05-06 23:41 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-05-06 23:41 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-05-06 23:41 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-05-06 23:41 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-05-06 23:41 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-05-06 23:41 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-05-06 23:41 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-05-06 23:41 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-05-06 23:41 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-05-06 23:41 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-05-06 23:41 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-05-06 23:41 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-05-06 23:41 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-05-06 23:41 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-05-06 23:41 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-05-06 23:41 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-05-06 23:41 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-05-06 23:41 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-05-06 23:41 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-05-06 23:41 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-05-06 23:41 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-05-06 23:41 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-05-06 23:41 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-05-06 23:41 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-05-06 23:41 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-05-06 23:41 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-05-06 23:41 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-05-06 23:41 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-05-06 23:41 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-05-06 23:41 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-05-06 23:41 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-05-06 23:41 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-05-06 23:41 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-05-06 23:41 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-05-06 23:41 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-05-06 23:41 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-05-06 23:41 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-05-06 23:41 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-05-06 23:41 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-05-06 23:41 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-05-06 23:41 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-05-06 23:41 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-05-06 23:41 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-05-06 23:41 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-05-06 23:41 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-05-06 23:41 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-05-06 23:41 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-05-06 23:41 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-05-06 23:41 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-05-06 23:41 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-05-06 23:41 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-05-06 23:41 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-05-06 23:41 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-05-06 23:41 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-05-06 23:41 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-05-06 23:41 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-05-06 23:41 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-05-06 23:41 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-05-06 23:41 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-05-06 23:41 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-05-06 23:41 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-05-06 23:41 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-05-06 23:41 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-05-06 23:41 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-05-06 23:41 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-05-06 23:41 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-05-06 23:41 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-05-06 23:41 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-05-06 23:41 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-05-06 23:41 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-05-06 23:41 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-05-06 23:41 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-05-06 23:41 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-05-06 23:41 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-05-06 23:41 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-05-06 23:41 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-05-06 23:41 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2014-05-06 23:41 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-05-06 23:41 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-05-06 23:40 - 2014-05-06 23:40 - 04530864 _____ (Avira Operations GmbH & Co. KG) C:\Users\David\Downloads\avira_de_av___ws.exe 2014-05-05 22:20 - 2014-05-05 22:20 - 00000767 _____ () C:\Users\Public\Desktop\DayZ Commander.lnk 2014-05-05 22:20 - 2014-05-05 22:20 - 00000000 ____D () C:\Users\David\AppData\Local\DayZCommander 2014-05-05 22:20 - 2014-05-05 22:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios 2014-05-05 22:18 - 2014-05-05 22:19 - 02945024 _____ () C:\Users\David\Downloads\Dotjosh.DayZCommander.Installer.msi 2014-05-04 23:44 - 2014-05-04 23:45 - 00000000 ___RD () C:\Users\David\Desktop\Games 2014-05-04 22:01 - 2014-05-04 23:38 - 00000000 ____D () C:\Users\David\Desktop\Schwingkreis 2014-05-04 17:00 - 2014-05-04 17:00 - 00001204 _____ () C:\Users\David\Desktop\Adobe Photoshop CC.lnk 2014-05-04 13:32 - 2014-05-04 13:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-05-04 13:32 - 2014-05-04 13:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf 2014-05-03 20:40 - 2014-05-03 20:40 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CC.lnk 2014-05-03 20:27 - 2014-05-03 20:27 - 00003500 _____ () C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Mongrel-David 2014-05-03 20:27 - 2014-05-03 20:27 - 00000000 ____D () C:\Users\David\AppData\Roaming\PDAppFlex 2014-05-03 20:27 - 2014-05-03 20:27 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-05-03 20:14 - 2014-05-03 20:14 - 00001228 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Dreamweaver CC.lnk 2014-05-03 19:49 - 2014-05-03 20:04 - 00000000 ____D () C:\Program Files\Adobe 2014-05-03 19:49 - 2014-05-03 19:49 - 00001068 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC (64 Bit).lnk 2014-05-03 19:48 - 2014-05-03 19:48 - 00001204 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC.lnk 2014-05-03 19:47 - 2014-05-03 20:03 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-05-03 19:05 - 2014-05-03 19:05 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2014-05-03 19:05 - 2014-05-03 19:05 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2014-05-03 18:52 - 2014-05-03 20:40 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-05-03 18:47 - 2014-05-08 12:47 - 00000000 ____D () C:\Users\David\AppData\Local\Adobe 2014-05-03 18:47 - 2014-05-03 18:47 - 02808712 _____ (Adobe Systems Incorporated) C:\Users\David\Downloads\CreativeCloudSet-Up.exe 2014-05-03 18:40 - 2014-05-03 19:49 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-01 23:22 - 2014-05-01 23:22 - 00000000 ____D () C:\Users\David\AppData\Local\Logitech 2014-05-01 23:22 - 2014-05-01 23:22 - 00000000 ____D () C:\ProgramData\ROCCAT 2014-05-01 19:37 - 2014-05-03 20:27 - 00000000 ____D () C:\Users\David\AppData\Roaming\Adobe 2014-05-01 19:37 - 2014-05-01 19:37 - 00000000 ____D () C:\Users\David\AppData\Roaming\Macromedia 2014-05-01 19:37 - 2014-05-01 19:37 - 00000000 ____D () C:\Users\David\AppData\Roaming\LolClient 2014-05-01 18:50 - 2014-05-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2014-05-01 18:50 - 2014-05-01 18:50 - 00000000 ____D () C:\Program Files\Logitech Gaming Software 2014-05-01 18:40 - 2014-05-01 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT 2014-05-01 18:40 - 2014-05-01 18:40 - 00000000 ____D () C:\Program Files (x86)\ROCCAT 2014-05-01 18:39 - 2014-05-08 15:39 - 00000292 _____ () C:\Windows\Tasks\Speedial.job 2014-05-01 18:39 - 2014-05-01 18:39 - 00003230 _____ () C:\Windows\System32\Tasks\Speedial 2014-05-01 18:39 - 2014-05-01 18:39 - 00001243 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\Speedial 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\DVDVideoSoft 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Program Files (x86)\Speedial 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-05-01 18:35 - 2014-05-01 18:35 - 00627176 _____ () C:\Users\David\Downloads\FreeYouTubeToMP3Converter.exe 2014-05-01 18:35 - 2014-05-01 18:35 - 00000000 ____D () C:\Users\David\AppData\Roaming\Logitech 2014-05-01 18:35 - 2014-05-01 18:35 - 00000000 ____D () C:\Users\David\AppData\Roaming\Logishrd 2014-05-01 18:30 - 2014-05-01 18:35 - 62122112 _____ (Logitech Inc.) C:\Users\David\Downloads\LGS_8.53.154_x64_Logitech.exe 2014-05-01 18:29 - 2014-05-01 18:31 - 25305708 _____ () C:\Users\David\Downloads\ROCCAT_KoneXTD_DRV1.17_FW1.17.zip 2014-05-01 18:28 - 2014-05-01 18:28 - 00000606 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 18:28 - 2014-05-01 18:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 18:27 - 2014-05-01 18:27 - 01141680 _____ () C:\Users\David\Downloads\SteamSetup.exe 2014-05-01 18:23 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-05-01 18:23 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2014-05-01 18:22 - 2014-05-01 23:21 - 00000000 ____D () C:\Users\David\AppData\Roaming\Winamp 2014-05-01 18:19 - 2014-05-01 18:20 - 17163336 _____ (Nullsoft, Inc.) C:\Users\David\Downloads\winamp5666_full_all.exe 2014-05-01 18:11 - 2014-05-01 18:11 - 00000354 _____ () C:\Windows\Cm106.ini.imi 2014-05-01 18:11 - 2014-05-01 18:11 - 00000336 _____ () C:\Windows\Cm106.ini.cfl 2014-05-01 18:11 - 2014-05-01 18:11 - 00000303 _____ () C:\Windows\system\Cm106.ini 2014-05-01 18:11 - 2014-05-01 18:11 - 00000137 _____ () C:\Windows\system\Dlap.pfx 2014-05-01 18:11 - 2014-05-01 18:11 - 00000000 ____D () C:\Program Files\Muse 2014-05-01 18:11 - 2009-11-12 15:30 - 00000874 _____ () C:\Windows\cm106.ini 2014-05-01 18:11 - 2009-11-12 15:29 - 00007168 ___SH () C:\Windows\Thumbs.db 2014-05-01 18:11 - 2009-11-12 14:25 - 00221184 _____ () C:\Windows\system\cm106eye.exe 2014-05-01 18:11 - 2009-10-20 21:43 - 08151040 _____ (C-Media Corporation) C:\Windows\SysWOW64\CM106.dll 2014-05-01 18:11 - 2009-09-17 13:11 - 00787456 _____ () C:\Windows\system32\Cmeau106.exe 2014-05-01 18:11 - 2009-08-19 16:00 - 00359424 _____ () C:\Windows\system32\CmiInstallResAll64.dll 2014-05-01 18:11 - 2009-06-29 10:20 - 00011254 _____ () C:\Windows\hercules_logo.bmp 2014-05-01 18:11 - 2009-04-02 16:59 - 00143360 _____ () C:\Windows\Vmix106.dll 2014-05-01 18:11 - 2008-11-07 18:31 - 00002391 _____ () C:\Windows\Cm106.ini.cfg 2014-05-01 18:11 - 2008-07-23 19:00 - 00389120 _____ () C:\Windows\system32\CM106.cpl 2014-05-01 18:11 - 2006-10-06 05:45 - 00524768 _____ (Microsoft Corporation) C:\Windows\difxapi.dll 2014-05-01 18:11 - 2006-09-13 13:08 - 00491520 _____ () C:\Windows\system\cmau106.dll 2014-05-01 18:11 - 2006-09-13 10:21 - 00200704 _____ (C-Media) C:\Windows\SysWOW64\cmpa106.dll 2014-05-01 18:01 - 2014-05-01 18:01 - 07407883 _____ (Hercules) C:\Users\David\Downloads\2009_GMXLPLT3_2_Win7.exe 2014-05-01 17:57 - 2014-05-08 15:25 - 00000000 ____D () C:\Users\David\AppData\Roaming\TS3Client 2014-05-01 17:57 - 2014-05-01 17:57 - 00000738 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-05-01 17:56 - 2014-05-01 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RocketDock 2014-05-01 17:53 - 2014-05-01 17:53 - 06463660 _____ (Punk Software ) C:\Users\David\Downloads\RocketDock-v1.3.5.exe 2014-05-01 17:53 - 2014-05-01 17:53 - 00000000 ____D () C:\Users\David\AppData\Local\Skype 2014-05-01 17:52 - 2014-05-01 18:08 - 00000000 ____D () C:\Users\David\AppData\Roaming\Skype 2014-05-01 17:52 - 2014-05-01 17:52 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-05-01 17:52 - 2014-05-01 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-05-01 17:52 - 2014-05-01 17:52 - 00000000 ____D () C:\ProgramData\Skype 2014-05-01 17:52 - 2014-05-01 17:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-05-01 17:50 - 2014-05-01 17:53 - 27601296 _____ (TeamSpeak Systems GmbH) C:\Users\David\Downloads\TeamSpeak3-Client-win32-3.0.14.exe 2014-05-01 17:50 - 2014-05-01 17:50 - 01678496 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup.exe 2014-05-01 17:48 - 2014-05-01 17:48 - 00000355 _____ () C:\Users\David\Desktop\Netzwerk.lnk 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Users\David\AppData\Roaming\ATI 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Users\David\AppData\Local\ATI 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\ProgramData\ATI 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner 2014-05-01 17:43 - 2014-05-07 14:20 - 00083156 _____ () C:\Windows\PFRO.log 2014-05-01 17:43 - 2014-05-01 17:43 - 00000000 _____ () C:\Windows\ativpsrm.bin 2014-05-01 17:41 - 2014-05-01 17:41 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf 2014-05-01 17:41 - 2013-09-03 16:52 - 00016344 _____ (Intel Corporation) C:\Windows\system32\Drivers\IntelMEFWVer.dll 2014-05-01 17:41 - 2013-04-26 04:24 - 00786416 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3xhc.sys 2014-05-01 17:41 - 2013-04-26 04:24 - 00368112 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hub.sys 2014-05-01 17:41 - 2013-04-26 04:24 - 00020464 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hcs.sys 2014-05-01 17:40 - 2014-05-01 17:40 - 00000000 ____H () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf 2014-05-01 17:40 - 2014-05-01 17:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf 2014-05-01 17:40 - 2012-07-26 06:55 - 00785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2014-05-01 17:40 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2014-05-01 17:40 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2014-05-01 17:40 - 2012-06-02 16:35 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2014-05-01 17:39 - 2014-05-03 20:27 - 00059728 _____ () C:\Users\David\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-01 17:39 - 2014-05-01 17:41 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-05-01 17:39 - 2014-05-01 17:41 - 00000000 ____D () C:\ProgramData\Intel 2014-05-01 17:39 - 2014-05-01 17:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\Intel Corporation 2014-05-01 17:39 - 2014-05-01 17:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\InstallShield 2014-05-01 17:39 - 2013-09-03 16:52 - 01795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll 2014-05-01 17:39 - 2013-09-03 16:52 - 00099288 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys 2014-05-01 17:34 - 2014-05-01 17:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-05-01 17:34 - 2014-05-01 17:34 - 00000000 ____D () C:\ProgramData\AMD 2014-05-01 17:34 - 2014-05-01 17:34 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-05-01 17:33 - 2014-05-01 17:33 - 00000000 ____D () C:\AMD 2014-05-01 17:33 - 2013-09-24 16:53 - 00094208 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2014-05-01 17:33 - 2013-09-24 16:51 - 00110080 _____ (TODO: <Company name>) C:\Windows\system32\DelayAPO.dll 2014-05-01 17:33 - 2013-09-12 04:26 - 01187342 _____ () C:\Windows\system32\amdocl_as64.exe 2014-05-01 17:33 - 2013-09-12 04:26 - 01061902 _____ () C:\Windows\system32\amdocl_ld64.exe 2014-05-01 17:33 - 2013-09-12 04:26 - 00995342 _____ () C:\Windows\SysWOW64\amdocl_as32.exe 2014-05-01 17:33 - 2013-09-12 04:26 - 00798734 _____ () C:\Windows\SysWOW64\amdocl_ld32.exe 2014-05-01 17:33 - 2013-09-12 04:26 - 00229888 _____ () C:\Windows\system32\clinfo.exe 2014-05-01 17:33 - 2013-09-12 04:26 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.20.dll 2014-05-01 17:33 - 2013-09-12 04:26 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2014-05-01 17:33 - 2013-09-12 04:26 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2014-05-01 17:33 - 2013-09-12 04:25 - 28469248 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2014-05-01 17:33 - 2013-09-12 04:25 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2014-05-01 17:33 - 2013-09-12 04:25 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2014-05-01 17:33 - 2013-09-12 04:23 - 24008704 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2014-05-01 17:33 - 2013-09-12 04:21 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-05-01 17:33 - 2013-09-12 04:21 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-05-01 17:33 - 2013-09-12 04:09 - 00555744 _____ () C:\Windows\SysWOW64\atiapfxx.blb 2014-05-01 17:33 - 2013-09-12 04:09 - 00555744 _____ () C:\Windows\system32\atiapfxx.blb 2014-05-01 17:33 - 2013-09-12 03:48 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2014-05-01 17:33 - 2013-09-12 03:26 - 00204952 _____ () C:\Windows\SysWOW64\ativvsvl.dat 2014-05-01 17:33 - 2013-09-12 03:26 - 00204952 _____ () C:\Windows\system32\ativvsvl.dat 2014-05-01 17:33 - 2013-09-12 03:26 - 00157144 _____ () C:\Windows\SysWOW64\ativvsva.dat 2014-05-01 17:33 - 2013-09-12 03:26 - 00157144 _____ () C:\Windows\system32\ativvsva.dat 2014-05-01 17:33 - 2013-08-27 22:15 - 00083392 _____ () C:\Windows\system32\ativce02.dat 2014-05-01 17:33 - 2013-07-25 23:50 - 00234292 _____ () C:\Windows\system32\ativvaxy_cik.dat 2014-05-01 17:33 - 2013-07-18 17:47 - 00231856 _____ () C:\Windows\system32\ativvaxy_cik_nd.dat 2014-05-01 17:33 - 2011-09-13 00:06 - 00003917 _____ () C:\Windows\SysWOW64\atipblag.dat 2014-05-01 17:33 - 2011-09-13 00:06 - 00003917 _____ () C:\Windows\system32\atipblag.dat 2014-05-01 17:32 - 2014-05-01 17:39 - 01645874 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-05-01 17:32 - 2014-05-01 17:32 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies 2014-05-01 17:32 - 2014-05-01 17:32 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-05-01 17:32 - 2013-08-14 04:23 - 00047427 _____ () C:\Windows\atiogl.xml 2014-05-01 17:31 - 2009-11-25 11:47 - 01942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-05-01 17:31 - 2009-11-25 11:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-05-01 17:31 - 2009-11-25 11:47 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2014-05-01 17:31 - 2009-11-25 11:47 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2014-05-01 17:31 - 2009-11-25 11:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll 2014-05-01 17:31 - 2009-11-25 11:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe 2014-05-01 17:31 - 2009-11-25 11:47 - 00109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2014-05-01 17:31 - 2009-11-25 11:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll 2014-05-01 17:31 - 2009-11-25 11:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll 2014-05-01 17:31 - 2009-11-25 11:47 - 00048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2014-05-01 17:30 - 2014-05-06 23:46 - 00000000 ____D () C:\ProgramData\Package Cache 2014-05-01 17:30 - 2014-05-01 17:30 - 00000000 ____D () C:\Program Files\ATI 2014-05-01 17:27 - 2014-05-01 17:34 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-05-01 17:20 - 2014-05-01 17:20 - 00000680 _____ () C:\Users\David\Desktop\David.lnk 2014-05-01 17:16 - 2014-03-31 09:35 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-05-01 17:15 - 2014-05-08 13:09 - 00000000 ____D () C:\Users\David\AppData\Local\PMB Files 2014-05-01 17:15 - 2014-05-07 17:10 - 00000000 ____D () C:\ProgramData\PMB Files 2014-05-01 17:15 - 2014-05-01 17:15 - 00001407 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk 2014-05-01 17:15 - 2014-05-01 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2014-05-01 17:13 - 2014-05-01 17:13 - 00000000 ____D () C:\Users\David\Intel 2014-05-01 17:12 - 2014-05-01 17:15 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-05-01 17:12 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-05-01 17:12 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-05-01 17:12 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2014-05-01 17:12 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-05-01 17:12 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-05-01 17:11 - 2014-05-01 17:11 - 00003438 _____ () C:\Windows\System32\Tasks\{09D2087F-DC95-4838-AEAA-F43870B2ED31} 2014-05-01 17:11 - 2014-05-01 17:11 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-05-01 17:10 - 2014-05-01 17:15 - 00000000 ____D () C:\Users\David\AppData\Roaming\Riot Games 2014-05-01 17:09 - 2014-05-01 18:40 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Windows\system32\SRSLabs 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Program Files\Realtek 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Program Files (x86)\Realtek 2014-05-01 17:09 - 2013-07-30 14:16 - 03564376 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2014-05-01 17:09 - 2013-07-30 11:14 - 02585304 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2014-05-01 17:09 - 2013-07-30 07:47 - 00620273 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT 2014-05-01 17:09 - 2013-07-29 12:41 - 00147672 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2014-05-01 17:09 - 2013-07-26 08:05 - 00617176 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2014-05-01 17:09 - 2013-07-22 09:37 - 01004248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2014-05-01 17:09 - 2013-07-19 09:55 - 02080472 ____R (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2014-05-01 17:09 - 2013-07-18 08:48 - 02795224 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2014-05-01 17:09 - 2013-07-17 10:17 - 02743328 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2014-05-01 17:09 - 2013-06-05 15:42 - 00208072 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2014-05-01 17:09 - 2013-04-24 11:16 - 01662024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2014-05-01 17:09 - 2013-02-20 12:55 - 01284680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2014-05-01 17:09 - 2012-06-20 11:26 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2014-05-01 17:09 - 2012-03-08 05:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2014-05-01 17:09 - 2012-01-30 05:43 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll 2014-05-01 17:09 - 2012-01-10 04:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll 2014-05-01 17:09 - 2011-12-20 09:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2014-05-01 17:09 - 2011-11-22 10:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2014-05-01 17:09 - 2011-03-17 06:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2014-05-01 17:09 - 2011-03-07 11:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2014-05-01 17:09 - 2010-11-08 01:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2014-05-01 17:09 - 2010-11-08 01:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2014-05-01 17:09 - 2010-11-08 01:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2014-05-01 17:09 - 2010-11-08 01:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2014-05-01 17:09 - 2010-11-08 01:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2014-05-01 17:09 - 2010-11-08 01:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2014-05-01 17:09 - 2010-11-03 12:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2014-05-01 17:08 - 2014-05-01 17:09 - 34888568 _____ (Riot Games) C:\Users\David\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe 2014-05-01 17:06 - 2014-05-01 17:41 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-05-01 17:06 - 2014-05-01 17:06 - 00000000 ____D () C:\Intel 2014-05-01 17:06 - 2013-08-05 05:50 - 00053248 ____R (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2014-05-01 17:04 - 2014-05-01 17:40 - 00000000 ____D () C:\Program Files\Intel 2014-05-01 17:04 - 2013-07-03 20:05 - 00552760 ____R (Intel Corporation) C:\Windows\system32\PROUnstl.exe 2014-05-01 17:04 - 2013-05-30 02:54 - 00495376 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1d62x64.sys 2014-05-01 17:04 - 2013-05-10 21:48 - 00073480 _____ (Intel Corporation) C:\Windows\system32\e1dmsg.dll 2014-05-01 17:04 - 2013-03-01 22:42 - 00101152 _____ (Intel Corporation) C:\Windows\system32\NicInstD.dll 2014-05-01 17:04 - 2012-01-06 08:03 - 00003114 _____ () C:\Windows\system32\e1d62x64.din 2014-05-01 17:04 - 2009-05-26 04:05 - 00036472 _____ (Intel Corporation) C:\Windows\system32\NicCo36.dll 2014-05-01 17:04 - 2006-01-12 09:52 - 00001904 ____N () C:\Windows\system32\SetupBD.din 2014-05-01 17:03 - 2014-05-08 15:08 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-01 17:03 - 2014-05-08 12:38 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-01 17:03 - 2014-05-01 17:03 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-01 17:03 - 2014-05-01 17:03 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-01 17:03 - 2014-05-01 17:03 - 00000000 ____D () C:\Users\David\AppData\Local\Google 2014-05-01 17:03 - 2014-05-01 17:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-01 17:03 - 2014-05-01 17:03 - 00000000 ____D () C:\Program Files (x86)\Google 2014-05-01 17:02 - 2014-05-01 17:42 - 00000000 ____D () C:\Users\David\Downloads\ASRSetup 2014-05-01 16:57 - 2014-05-01 16:57 - 00331894 __RSH () C:\GTHKP 2014-05-01 16:57 - 2014-05-01 16:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-05-01 16:56 - 2014-05-08 15:41 - 00364305 _____ () C:\Windows\WindowsUpdate.log 2014-05-01 16:56 - 2014-05-04 23:44 - 00000000 ____D () C:\Users\David 2014-05-01 16:56 - 2014-05-01 23:22 - 00000000 ____D () C:\Users\David\AppData\Local\VirtualStore 2014-05-01 16:56 - 2014-05-01 16:56 - 00001443 _____ () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-01 16:56 - 2014-05-01 16:56 - 00001409 _____ () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-05-01 16:56 - 2014-05-01 16:56 - 00000020 ___SH () C:\Users\David\ntuser.ini 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Vorlagen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Startmenü 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Netzwerkumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Lokale Einstellungen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Eigene Dateien 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Druckumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\AppData\Local\Verlauf 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\AppData\Local\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Favoriten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 __SHD () C:\Recovery 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 ___RD () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 ___RD () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-01 16:56 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-05-01 16:56 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-05-01 16:55 - 2014-05-01 16:56 - 00000000 ____D () C:\Windows\Panther 2014-05-01 16:55 - 2014-05-01 16:55 - 00008192 __RSH () C:\BOOTSECT.BAK 2014-05-01 16:55 - 2009-07-14 03:38 - 00383562 __RSH () C:\bootmgr 2014-05-01 15:58 - 2014-05-01 15:58 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2014-05-01 15:58 - 2014-05-01 15:58 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2014-05-01 15:58 - 2014-05-01 15:58 - 00001313 _____ () C:\Windows\TSSysprep.log ==================== One Month Modified Files and Folders ======= 2014-05-08 15:54 - 2014-05-08 15:54 - 00015797 _____ () C:\Users\David\Downloads\FRST.txt 2014-05-08 15:54 - 2014-05-08 15:54 - 00000000 ____D () C:\FRST 2014-05-08 15:54 - 2014-05-08 15:53 - 02063872 _____ (Farbar) C:\Users\David\Downloads\FRST64.exe 2014-05-08 15:45 - 2014-05-08 15:45 - 00007687 _____ () C:\Users\David\Desktop\Neues Textdokument.txt 2014-05-08 15:41 - 2014-05-01 16:56 - 00364305 _____ () C:\Windows\WindowsUpdate.log 2014-05-08 15:39 - 2014-05-01 18:39 - 00000292 _____ () C:\Windows\Tasks\Speedial.job 2014-05-08 15:36 - 2014-05-08 15:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-08 15:36 - 2014-05-08 15:36 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-08 15:36 - 2014-05-08 15:36 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-08 15:35 - 2014-05-08 15:35 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\David\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-08 15:25 - 2014-05-01 17:57 - 00000000 ____D () C:\Users\David\AppData\Roaming\TS3Client 2014-05-08 15:08 - 2014-05-01 17:03 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-08 13:09 - 2014-05-01 17:15 - 00000000 ____D () C:\Users\David\AppData\Local\PMB Files 2014-05-08 12:47 - 2014-05-03 18:47 - 00000000 ____D () C:\Users\David\AppData\Local\Adobe 2014-05-08 12:45 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-08 12:45 - 2009-07-14 06:45 - 00014032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-08 12:43 - 2009-07-14 19:58 - 00699726 _____ () C:\Windows\system32\perfh007.dat 2014-05-08 12:43 - 2009-07-14 19:58 - 00149364 _____ () C:\Windows\system32\perfc007.dat 2014-05-08 12:43 - 2009-07-14 07:13 - 01621742 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-08 12:38 - 2014-05-01 17:03 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-08 12:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-08 12:37 - 2009-07-14 06:51 - 00023482 _____ () C:\Windows\setupact.log 2014-05-07 17:46 - 2014-05-07 17:46 - 00000000 ____D () C:\Users\David\AppData\Roaming\Avira 2014-05-07 17:10 - 2014-05-01 17:15 - 00000000 ____D () C:\ProgramData\PMB Files 2014-05-07 16:45 - 2014-05-07 16:46 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-05-07 14:20 - 2014-05-01 17:43 - 00083156 _____ () C:\Windows\PFRO.log 2014-05-07 00:03 - 2014-05-06 23:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-07 00:03 - 2014-05-06 23:46 - 00000000 ____D () C:\ProgramData\Avira 2014-05-07 00:03 - 2014-05-06 23:46 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-06 23:46 - 2014-05-01 17:30 - 00000000 ____D () C:\ProgramData\Package Cache 2014-05-06 23:41 - 2014-05-06 23:41 - 00010009 _____ () C:\Windows\DirectX.log 2014-05-06 23:40 - 2014-05-06 23:40 - 04530864 _____ (Avira Operations GmbH & Co. KG) C:\Users\David\Downloads\avira_de_av___ws.exe 2014-05-05 22:20 - 2014-05-05 22:20 - 00000767 _____ () C:\Users\Public\Desktop\DayZ Commander.lnk 2014-05-05 22:20 - 2014-05-05 22:20 - 00000000 ____D () C:\Users\David\AppData\Local\DayZCommander 2014-05-05 22:20 - 2014-05-05 22:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios 2014-05-05 22:19 - 2014-05-05 22:18 - 02945024 _____ () C:\Users\David\Downloads\Dotjosh.DayZCommander.Installer.msi 2014-05-04 23:45 - 2014-05-04 23:44 - 00000000 ___RD () C:\Users\David\Desktop\Games 2014-05-04 23:44 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David 2014-05-04 23:38 - 2014-05-04 22:01 - 00000000 ____D () C:\Users\David\Desktop\Schwingkreis 2014-05-04 17:00 - 2014-05-04 17:00 - 00001204 _____ () C:\Users\David\Desktop\Adobe Photoshop CC.lnk 2014-05-04 13:32 - 2014-05-04 13:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-05-04 13:32 - 2014-05-04 13:32 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf 2014-05-04 13:31 - 2009-07-14 06:45 - 04937056 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-03 21:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-03 20:40 - 2014-05-03 20:40 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CC.lnk 2014-05-03 20:40 - 2014-05-03 18:52 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-05-03 20:27 - 2014-05-03 20:27 - 00003500 _____ () C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Mongrel-David 2014-05-03 20:27 - 2014-05-03 20:27 - 00000000 ____D () C:\Users\David\AppData\Roaming\PDAppFlex 2014-05-03 20:27 - 2014-05-03 20:27 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-05-03 20:27 - 2014-05-01 19:37 - 00000000 ____D () C:\Users\David\AppData\Roaming\Adobe 2014-05-03 20:27 - 2014-05-01 17:39 - 00059728 _____ () C:\Users\David\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-03 20:14 - 2014-05-03 20:14 - 00001228 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Dreamweaver CC.lnk 2014-05-03 20:04 - 2014-05-03 19:49 - 00000000 ____D () C:\Program Files\Adobe 2014-05-03 20:03 - 2014-05-03 19:47 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-05-03 19:49 - 2014-05-03 19:49 - 00001068 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC (64 Bit).lnk 2014-05-03 19:49 - 2014-05-03 18:40 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-03 19:48 - 2014-05-03 19:48 - 00001204 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC.lnk 2014-05-03 19:05 - 2014-05-03 19:05 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2014-05-03 19:05 - 2014-05-03 19:05 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2014-05-03 18:47 - 2014-05-03 18:47 - 02808712 _____ (Adobe Systems Incorporated) C:\Users\David\Downloads\CreativeCloudSet-Up.exe 2014-05-01 23:22 - 2014-05-01 23:22 - 00000000 ____D () C:\Users\David\AppData\Local\Logitech 2014-05-01 23:22 - 2014-05-01 23:22 - 00000000 ____D () C:\ProgramData\ROCCAT 2014-05-01 23:22 - 2014-05-01 16:56 - 00000000 ____D () C:\Users\David\AppData\Local\VirtualStore 2014-05-01 23:21 - 2014-05-01 18:22 - 00000000 ____D () C:\Users\David\AppData\Roaming\Winamp 2014-05-01 19:37 - 2014-05-01 19:37 - 00000000 ____D () C:\Users\David\AppData\Roaming\Macromedia 2014-05-01 19:37 - 2014-05-01 19:37 - 00000000 ____D () C:\Users\David\AppData\Roaming\LolClient 2014-05-01 18:50 - 2014-05-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2014-05-01 18:50 - 2014-05-01 18:50 - 00000000 ____D () C:\Program Files\Logitech Gaming Software 2014-05-01 18:40 - 2014-05-01 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ROCCAT 2014-05-01 18:40 - 2014-05-01 18:40 - 00000000 ____D () C:\Program Files (x86)\ROCCAT 2014-05-01 18:40 - 2014-05-01 17:09 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-05-01 18:39 - 2014-05-01 18:39 - 00003230 _____ () C:\Windows\System32\Tasks\Speedial 2014-05-01 18:39 - 2014-05-01 18:39 - 00001243 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\Speedial 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\DVDVideoSoft 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Program Files (x86)\Speedial 2014-05-01 18:39 - 2014-05-01 18:39 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-05-01 18:35 - 2014-05-01 18:35 - 00627176 _____ () C:\Users\David\Downloads\FreeYouTubeToMP3Converter.exe 2014-05-01 18:35 - 2014-05-01 18:35 - 00000000 ____D () C:\Users\David\AppData\Roaming\Logitech 2014-05-01 18:35 - 2014-05-01 18:35 - 00000000 ____D () C:\Users\David\AppData\Roaming\Logishrd 2014-05-01 18:35 - 2014-05-01 18:30 - 62122112 _____ (Logitech Inc.) C:\Users\David\Downloads\LGS_8.53.154_x64_Logitech.exe 2014-05-01 18:31 - 2014-05-01 18:29 - 25305708 _____ () C:\Users\David\Downloads\ROCCAT_KoneXTD_DRV1.17_FW1.17.zip 2014-05-01 18:28 - 2014-05-01 18:28 - 00000606 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 18:28 - 2014-05-01 18:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 18:27 - 2014-05-01 18:27 - 01141680 _____ () C:\Users\David\Downloads\SteamSetup.exe 2014-05-01 18:20 - 2014-05-01 18:19 - 17163336 _____ (Nullsoft, Inc.) C:\Users\David\Downloads\winamp5666_full_all.exe 2014-05-01 18:11 - 2014-05-01 18:11 - 00000354 _____ () C:\Windows\Cm106.ini.imi 2014-05-01 18:11 - 2014-05-01 18:11 - 00000336 _____ () C:\Windows\Cm106.ini.cfl 2014-05-01 18:11 - 2014-05-01 18:11 - 00000303 _____ () C:\Windows\system\Cm106.ini 2014-05-01 18:11 - 2014-05-01 18:11 - 00000137 _____ () C:\Windows\system\Dlap.pfx 2014-05-01 18:11 - 2014-05-01 18:11 - 00000000 ____D () C:\Program Files\Muse 2014-05-01 18:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system 2014-05-01 18:08 - 2014-05-01 17:52 - 00000000 ____D () C:\Users\David\AppData\Roaming\Skype 2014-05-01 18:01 - 2014-05-01 18:01 - 07407883 _____ (Hercules) C:\Users\David\Downloads\2009_GMXLPLT3_2_Win7.exe 2014-05-01 17:57 - 2014-05-01 17:57 - 00000738 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk 2014-05-01 17:56 - 2014-05-01 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RocketDock 2014-05-01 17:53 - 2014-05-01 17:53 - 06463660 _____ (Punk Software ) C:\Users\David\Downloads\RocketDock-v1.3.5.exe 2014-05-01 17:53 - 2014-05-01 17:53 - 00000000 ____D () C:\Users\David\AppData\Local\Skype 2014-05-01 17:53 - 2014-05-01 17:50 - 27601296 _____ (TeamSpeak Systems GmbH) C:\Users\David\Downloads\TeamSpeak3-Client-win32-3.0.14.exe 2014-05-01 17:52 - 2014-05-01 17:52 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-05-01 17:52 - 2014-05-01 17:52 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-05-01 17:52 - 2014-05-01 17:52 - 00000000 ____D () C:\ProgramData\Skype 2014-05-01 17:52 - 2014-05-01 17:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-05-01 17:50 - 2014-05-01 17:50 - 01678496 _____ (Skype Technologies S.A.) C:\Users\David\Downloads\SkypeSetup.exe 2014-05-01 17:48 - 2014-05-01 17:48 - 00000355 _____ () C:\Users\David\Desktop\Netzwerk.lnk 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Users\David\AppData\Roaming\ATI 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Users\David\AppData\Local\ATI 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\ProgramData\ATI 2014-05-01 17:45 - 2014-05-01 17:45 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner 2014-05-01 17:43 - 2014-05-01 17:43 - 00000000 _____ () C:\Windows\ativpsrm.bin 2014-05-01 17:42 - 2014-05-01 17:02 - 00000000 ____D () C:\Users\David\Downloads\ASRSetup 2014-05-01 17:41 - 2014-05-01 17:41 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf 2014-05-01 17:41 - 2014-05-01 17:39 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel 2014-05-01 17:41 - 2014-05-01 17:39 - 00000000 ____D () C:\ProgramData\Intel 2014-05-01 17:41 - 2014-05-01 17:06 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-05-01 17:40 - 2014-05-01 17:40 - 00000000 ____H () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf 2014-05-01 17:40 - 2014-05-01 17:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf 2014-05-01 17:40 - 2014-05-01 17:04 - 00000000 ____D () C:\Program Files\Intel 2014-05-01 17:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-05-01 17:39 - 2014-05-01 17:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\Intel Corporation 2014-05-01 17:39 - 2014-05-01 17:39 - 00000000 ____D () C:\Users\David\AppData\Roaming\InstallShield 2014-05-01 17:39 - 2014-05-01 17:32 - 01645874 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-05-01 17:34 - 2014-05-01 17:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2014-05-01 17:34 - 2014-05-01 17:34 - 00000000 ____D () C:\ProgramData\AMD 2014-05-01 17:34 - 2014-05-01 17:34 - 00000000 ____D () C:\Program Files (x86)\AMD AVT 2014-05-01 17:34 - 2014-05-01 17:27 - 00000000 ____D () C:\Program Files\ATI Technologies 2014-05-01 17:33 - 2014-05-01 17:33 - 00000000 ____D () C:\AMD 2014-05-01 17:32 - 2014-05-01 17:32 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies 2014-05-01 17:32 - 2014-05-01 17:32 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-05-01 17:30 - 2014-05-01 17:30 - 00000000 ____D () C:\Program Files\ATI 2014-05-01 17:20 - 2014-05-01 17:20 - 00000680 _____ () C:\Users\David\Desktop\David.lnk 2014-05-01 17:15 - 2014-05-01 17:15 - 00001407 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk 2014-05-01 17:15 - 2014-05-01 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends 2014-05-01 17:15 - 2014-05-01 17:12 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin 2014-05-01 17:15 - 2014-05-01 17:10 - 00000000 ____D () C:\Users\David\AppData\Roaming\Riot Games 2014-05-01 17:13 - 2014-05-01 17:13 - 00000000 ____D () C:\Users\David\Intel 2014-05-01 17:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-01 17:11 - 2014-05-01 17:11 - 00003438 _____ () C:\Windows\System32\Tasks\{09D2087F-DC95-4838-AEAA-F43870B2ED31} 2014-05-01 17:11 - 2014-05-01 17:11 - 00000000 ____D () C:\Program Files (x86)\Pando Networks 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Windows\system32\SRSLabs 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Program Files\Realtek 2014-05-01 17:09 - 2014-05-01 17:09 - 00000000 ____D () C:\Program Files (x86)\Realtek 2014-05-01 17:09 - 2014-05-01 17:08 - 34888568 _____ (Riot Games) C:\Users\David\Downloads\LeagueofLegends_EUW_Installer_06_12_13.exe 2014-05-01 17:06 - 2014-05-01 17:06 - 00000000 ____D () C:\Intel 2014-05-01 17:05 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-05-01 17:03 - 2014-05-01 17:03 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-01 17:03 - 2014-05-01 17:03 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-01 17:03 - 2014-05-01 17:03 - 00000000 ____D () C:\Users\David\AppData\Local\Google 2014-05-01 17:03 - 2014-05-01 17:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-01 17:03 - 2014-05-01 17:03 - 00000000 ____D () C:\Program Files (x86)\Google 2014-05-01 17:03 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore 2014-05-01 16:57 - 2014-05-01 16:57 - 00331894 __RSH () C:\GTHKP 2014-05-01 16:57 - 2014-05-01 16:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-05-01 16:56 - 2014-05-01 16:56 - 00001443 _____ () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-01 16:56 - 2014-05-01 16:56 - 00001409 _____ () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2014-05-01 16:56 - 2014-05-01 16:56 - 00000020 ___SH () C:\Users\David\ntuser.ini 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Vorlagen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Startmenü 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Netzwerkumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Lokale Einstellungen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Eigene Dateien 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Druckumgebung 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Documents\Eigene Musik 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Documents\Eigene Bilder 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\AppData\Local\Verlauf 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\AppData\Local\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Users\David\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Favoriten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 _SHDL () C:\Dokumente und Einstellungen 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 __SHD () C:\Recovery 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 ___RD () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-01 16:56 - 2014-05-01 16:56 - 00000000 ___RD () C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-01 16:56 - 2014-05-01 16:55 - 00000000 ____D () C:\Windows\Panther 2014-05-01 16:56 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-05-01 16:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Windows NT 2014-05-01 16:55 - 2014-05-01 16:55 - 00008192 __RSH () C:\BOOTSECT.BAK 2014-05-01 16:55 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2014-05-01 16:55 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2014-05-01 15:58 - 2014-05-01 15:58 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2014-05-01 15:58 - 2014-05-01 15:58 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2014-05-01 15:58 - 2014-05-01 15:58 - 00001313 _____ () C:\Windows\TSSysprep.log 2014-05-01 15:58 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-01 15:58 - 2009-07-14 06:46 - 00001774 _____ () C:\Windows\DtcInstall.log 2014-05-01 15:58 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-05-01 15:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep 2014-05-01 15:56 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\CSC Some content of TEMP: ==================== C:\Users\David\AppData\Local\Temp\avgnt.exe C:\Users\David\AppData\Local\Temp\ICReinstall_UltimateCodec.exe C:\Users\David\AppData\Local\Temp\MSIAFTERBURNERSETUP.EXE C:\Users\David\AppData\Local\Temp\SETUP_AFTERBURNER.EXE C:\Users\David\AppData\Local\Temp\swt-win32-3349.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-03 21:10 ==================== End Of Log ============================ Geändert von xXFenrizXx (08.05.2014 um 14:57 Uhr) |
Themen zu PUP.Optional.Installcore / Windows 7 / Neuer PC |
association, branding, code, detected, dvdvideosoft ltd., explorer, icreinstall, install.exe, interne, internet, internet explorer, launch, malwarebytes, microsoft, pup.optional.installcore, pup.optional.installcore.a, pup.optional.speedial.a, roaming, software, temp, uninstall.exe, website, windows, windows 7, woche, wochen |