Alt 15.06.2014, 20:56   #1
Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung - Standard

Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung


ich hab grade ein Suchlauf mit Malwarebytes Anti Malware gemacht. Dabei wurden potenzielle Bedrohungen erkannt. Ausschließlich mit dem Pfad C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com
Ich hab keine Ahnung, ob ich das in Quarantäne verschieben soll oder löschen oder ob das nix gefährliches ist...
 Malwarebytes Anti-Malware 

Suchlauf Datum: 15.06.2014
Suchlauf-Zeit: 21:09:09
Logdatei: mbam log.txt
Administrator: Ja

Malware Datenbank: v2014.06.15.05
Rootkit Datenbank: v2014.06.02.01
Lizenz: Premium
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Aktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Philipp

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 325970
Verstrichene Zeit: 20 Min, 49 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 5
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\mz, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\skin, , [ebc73d36b2c98fa78bbb9c03a260d729], 

Dateien: 22
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome.manifest, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\install.rdf, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\background.html, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\bg.js, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\button.xml, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\config.js, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\content.js, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\framework.js, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\framework.xul, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon128.png, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon16.png, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon24.ico, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon24.png, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon32.ico, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon32.png, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\icon48.png, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\jquery-1.6.2.min.js, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\options.xul, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\settings.json, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\mz\background.js, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\content\mz\content.js, , [ebc73d36b2c98fa78bbb9c03a260d729], 
PUP.Optional.SpeedAnalysis.A, C:\Users\Philipp\AppData\Roaming\Mozilla\Extensions\speedanalysis@SpeedAnalysis.com\chrome\skin\framework.css, , [ebc73d36b2c98fa78bbb9c03a260d729], 

Physische Sektoren: 0
(No malicious items detected)

Wäre dankbar für Hilfe ;D
MFG Philipp
Viele Grüße

Alt 16.06.2014, 06:10   #2
/// the machine
/// TB-Ausbilder

Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung - Standard

Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Alt 16.06.2014, 10:16   #3
Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung - Standard

Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung


hier die addition.txt und die frst.txt:

FRST Logfile:

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-06-2014
Ran by Philipp (administrator) on PHILIPPS-PC on 16-06-2014 11:13:08
Running from C:\Users\Philipp\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916112 2012-04-08] (Synaptics Incorporated)
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Philipp\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Philipp\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-23]

CHR Extension: (Adblock Plus) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-26]
CHR Extension: (Adblock Advisor) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplojogpbcbnjoemcalepfmbcpnkpjjo [2014-04-26]
CHR Extension: (Google Wallet) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2266296 2014-05-16] (Microsoft Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-18] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2014-06-04] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed]
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-09] (Atheros)

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [32896 2012-03-19] (Advanced Micro Devices, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R2 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-16] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-06-16 11:13 - 2014-06-16 11:13 - 00016290 _____ () C:\Users\Philipp\Downloads\FRST.txt
2014-06-16 11:12 - 2014-06-16 11:13 - 00000000 ____D () C:\FRST
2014-06-16 11:12 - 2014-06-16 11:12 - 02081280 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe
2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg
2014-06-12 10:27 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-12 10:27 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-12 10:27 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-12 10:27 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-12 10:27 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-12 10:27 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-12 10:27 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-12 10:27 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-12 10:27 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-12 10:27 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-12 10:27 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-12 10:27 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-12 10:27 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-12 10:27 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-12 10:27 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-12 10:27 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-12 10:27 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-12 10:27 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-12 10:27 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 10:27 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-12 10:27 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-12 10:27 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-06-12 10:27 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-12 10:27 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-12 10:27 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-12 10:27 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-12 10:27 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-12 10:27 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-12 10:27 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-12 10:27 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-06-12 10:27 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-12 10:27 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-06-12 10:27 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-06-12 10:27 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-12 10:27 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-12 10:27 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-12 10:27 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 10:27 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-12 10:27 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-12 10:27 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-12 10:27 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-12 10:27 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-12 10:27 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-12 10:27 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-12 10:27 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-12 10:27 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-12 10:27 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-12 10:27 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-12 10:27 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-12 10:27 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-12 10:27 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-12 10:27 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-06-12 10:27 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-06-12 10:27 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-12 10:27 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2014-06-12 10:27 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2014-06-12 10:27 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-12 10:27 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 10:27 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-12 10:27 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-12 10:27 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2014-06-12 10:27 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2014-06-12 10:25 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-12 10:25 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig
2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-06-06 15:21 - 2014-06-06 15:22 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe
2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR
2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR
2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe
2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory
2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk
2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-06-06 13:53 - 2014-06-06 13:55 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe
2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt
2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822
2014-06-03 17:24 - 2014-06-03 17:25 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp
2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP
2014-06-03 15:50 - 2014-06-07 00:33 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core
2014-06-02 18:50 - 2014-06-07 00:33 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2014-06-02 18:50 - 2014-06-07 00:32 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-06-01 20:39 - 2014-06-15 20:59 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-06-01 20:37 - 2014-06-03 18:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin
2014-06-01 20:37 - 2014-06-03 15:45 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin
2014-06-01 20:34 - 2014-06-15 22:05 - 00000000 ____D () C:\ProgramData\Origin
2014-06-01 20:34 - 2014-06-15 20:56 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-01 20:34 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk
2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D}
2014-05-31 18:01 - 2014-06-04 20:21 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-31 16:21 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-31 16:21 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-05-31 16:21 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-05-31 16:21 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-05-31 16:20 - 2014-05-31 16:21 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-27 16:39 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-05-27 16:39 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-05-26 20:01 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-05-26 20:01 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-26 20:01 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-26 20:01 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-05-26 20:01 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-05-26 20:01 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-05-26 20:01 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-05-26 20:01 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-05-26 20:01 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-05-26 20:01 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-05-26 20:01 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-05-26 20:01 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-05-26 20:01 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-05-26 20:01 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-05-26 20:01 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-05-26 20:01 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-05-26 20:00 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2014-05-26 20:00 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-23 14:31 - 2014-06-07 10:48 - 00010364 _____ () C:\windows\PFRO.log

==================== One Month Modified Files and Folders =======

2014-06-16 11:13 - 2014-06-16 11:13 - 00016290 _____ () C:\Users\Philipp\Downloads\FRST.txt
2014-06-16 11:13 - 2014-06-16 11:12 - 00000000 ____D () C:\FRST
2014-06-16 11:13 - 2013-07-14 23:17 - 01671541 _____ () C:\windows\WindowsUpdate.log
2014-06-16 11:13 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Temp
2014-06-16 11:12 - 2014-06-16 11:12 - 02081280 _____ (Farbar) C:\Users\Philipp\Downloads\FRST64.exe
2014-06-16 11:11 - 2014-04-11 17:40 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-16 11:09 - 2014-04-27 12:29 - 00005040 _____ () C:\windows\setupact.log
2014-06-16 11:09 - 2012-05-25 07:00 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-06-16 11:09 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-15 22:06 - 2013-01-14 18:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-06-15 22:05 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Origin
2014-06-15 22:03 - 2012-05-25 22:31 - 00700134 _____ () C:\windows\system32\perfh007.dat
2014-06-15 22:03 - 2012-05-25 22:31 - 00149984 _____ () C:\windows\system32\perfc007.dat
2014-06-15 22:03 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-15 21:50 - 2013-04-23 19:22 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-15 21:49 - 2013-04-02 20:58 - 00001128 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job
2014-06-15 21:07 - 2013-04-02 21:01 - 00002373 _____ () C:\Users\Philipp\Desktop\Google Chrome.lnk
2014-06-15 21:00 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-15 21:00 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-15 20:59 - 2014-06-01 20:39 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-06-15 20:56 - 2014-06-01 20:34 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-15 19:20 - 2012-05-25 06:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg
2014-06-15 19:09 - 2012-05-25 07:00 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-06-15 18:00 - 2013-04-02 20:58 - 00001076 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job
2014-06-15 18:00 - 2012-11-11 16:51 - 00000000 ____D () C:\Users\Philipp\AppData\Local\CrashDumps
2014-06-14 10:27 - 2013-08-16 21:15 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\.minecraft
2014-06-14 10:25 - 2013-07-15 14:17 - 00000000 ____D () C:\windows\system32\MRT
2014-06-14 10:23 - 2012-10-20 21:21 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-14 10:20 - 2014-05-06 22:19 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-08 11:13 - 2014-06-12 10:25 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 10:25 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK
2014-06-07 10:48 - 2014-05-23 14:31 - 00010364 _____ () C:\windows\PFRO.log
2014-06-07 00:33 - 2014-06-03 15:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2014-06-07 00:33 - 2014-06-02 18:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2014-06-07 00:32 - 2014-06-02 18:50 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig
2014-06-06 20:14 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp
2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-06-06 15:22 - 2014-06-06 15:21 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe
2014-06-06 15:17 - 2013-05-27 22:46 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\vlc
2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR
2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR
2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe
2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory
2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk
2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-06-06 13:56 - 2013-05-18 14:55 - 00000000 ____D () C:\Program Files (x86)\FreeTime
2014-06-06 13:55 - 2014-06-06 13:53 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe
2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt
2014-06-04 20:29 - 2014-06-02 18:50 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2014-06-04 20:21 - 2014-05-31 18:01 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp
2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822
2014-06-03 18:37 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin
2014-06-03 17:25 - 2014-06-03 17:24 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp
2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP
2014-06-03 17:24 - 2012-11-22 15:12 - 00000000 ____D () C:\windows\Minidump
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core
2014-06-03 15:45 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin
2014-06-03 15:45 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-06-02 18:50 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-02 18:49 - 2014-04-27 15:59 - 00018934 _____ () C:\windows\DirectX.log
2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk
2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-01 15:10 - 2012-11-25 17:18 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-06-01 00:32 - 2013-06-21 23:54 - 00007597 _____ () C:\Users\Philipp\AppData\Local\Resmon.ResmonCfg
2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D}
2014-05-31 17:55 - 2012-10-21 12:31 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\SoftGrid Client
2014-05-31 17:29 - 2014-03-27 23:55 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TS3Client
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-31 16:21 - 2014-05-31 16:20 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-31 16:21 - 2013-10-16 23:29 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-31 16:21 - 2013-06-23 18:37 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-05-30 22:12 - 2013-03-02 20:49 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-30 12:21 - 2014-06-12 10:27 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 10:27 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 10:27 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 10:27 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-12 10:27 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-12 10:27 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 10:27 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 10:27 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-12 10:27 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-12 10:27 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 10:27 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 10:27 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 10:27 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 10:27 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 10:27 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 10:27 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-12 10:27 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 10:27 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 10:27 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 10:27 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 10:27 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 10:27 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 10:27 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 10:27 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 10:27 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 10:27 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 10:27 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 10:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 10:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 10:27 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 10:27 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 10:27 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 10:27 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 10:27 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 10:27 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 10:27 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 10:27 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 10:27 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 10:27 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 10:27 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 10:27 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 10:27 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 10:27 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 10:27 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 10:27 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 10:27 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-05-29 16:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache
2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-26 16:37 - 2013-02-17 16:31 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Windows Live
2014-05-22 15:50 - 2013-03-04 22:23 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-05-17 11:52 - 2013-04-23 19:06 - 00000000 ____D () C:\windows\pss

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-05-29 16:39

==================== End Of Log ============================
--- --- ---

--- --- ---

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-06-2014
Ran by Philipp at 2014-06-16 11:14:11
Running from C:\Users\Philipp\Downloads
Boot Mode: Normal

==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

„Windows Live Essentials“ (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (x32 Version: 16.4.3505.0912 - „Microsoft Corporation“) Hidden
4Story DE 4.0.167 (HKLM-x32\...\4Story_DE_is1) (Version:  - )
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
Ace of Spades (HKLM-x32\...\Steam App 224540) (Version:  - Jagex Limited)
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Amazon MP3-Downloader 1.0.17 (HKLM-x32\...\Amazon MP3-Downloader) (Version: 1.0.17 - Amazon Services LLC)
AMD Accelerated Video Transcoding (Version: 2.00.0002 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.898.1 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{F81156E9-1687-E56A-E3B4-3CF3D17520E2}) (Version: 3.0.868.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.)
Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: - Atheros)
Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
AVG PC TuneUp 2014 (de-DE) (x32 Version: 14.0.1001.174 - AVG) Hidden
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.4.0 - EA Digital Illusions CE AB)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: - Apple Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.0418.0644.10054 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.0418.645.10054 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.02 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: - CDBurnerXP)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink Corp.)
CyberLink Media Suite (x32 Version: 8.0.2227 - CyberLink Corp.) Hidden
CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 - CyberLink Corp.)
CyberLink Media+ Player10 (x32 Version: 10.0.1110.00 - CyberLink Corp.) Hidden
CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1130a - CyberLink Corp.)
CyberLink MediaShow (x32 Version: 5.0.1130a - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink Corp.)
CyberLink Power2Go (x32 Version: 6.1.3802 - CyberLink Corp.) Hidden
CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3306 - CyberLink Corp.)
CyberLink PowerDirector (x32 Version: 8.0.3306 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.5016 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.1.5016 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DIE SIEDLER - Das Erbe der Könige - Gold Edition (HKLM-x32\...\{E08DE897-B6AF-4DFF-9E90-131E80C876B4}) (Version: 1.00.0000 - Blue Byte)
Easy File Share (HKLM-x32\...\{12F81925-F3C1-40DB-91F7-777817974319}) (Version: 1.3.1 - Samsung Electronics CO., LTD.)
Easy Migration (HKLM-x32\...\{EDE7A262-DB20-4432-A630-2ACEE186C416}) (Version: 1.0 - Samsung Electronics CO., LTD.)
Easy Settings (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.1 - Samsung Electronics CO., LTD.)
Easy Software Manager (HKLM-x32\...\{DE256D8B-D971-456D-BC02-CB64DA24F115}) (Version: - Samsung Electronics CO., LTD.)
Easy Support Center (HKLM\...\{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}) (Version: 1.2.23 - Samsung Electronics CO., LTD.)
E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
FormatFactory (HKLM-x32\...\FormatFactory) (Version: - Format Factory)
Formatwandler 2D zu 3D (HKLM-x32\...\{1F9E4FE1-5C7E-4501-0001-87D989B30F53}) (Version: - S.A.D.)
Fotoattēlu galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogaléria (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Foto-galerija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalleri (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotogalleriet (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free DVD Video Converter version (HKLM-x32\...\Free DVD Video Converter_is1) (Version: - DVDVideoSoft Ltd.)
Free Video Dub version (HKLM-x32\...\Free Video Dub_is1) (Version: - DVDVideoSoft Ltd.)
Free Video to DVD Converter version (HKLM-x32\...\Free Video to DVD Converter_is1) (Version: - DVDVideoSoft Ltd.)
Galeria de Fotografias (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galeria de Fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galeria fotografii (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerija fotografija (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Gameforge Live 1.10.1 "Legend" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 1.10.1 - Gameforge)
GIMP 2.8.8 (HKLM\...\GIMP-2_is1) (Version: 2.8.8 - The GIMP Team)
Google Chrome (HKCU\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: - Google)
Google Update Helper (x32 Version: - Google Inc.) Hidden
HAWKEN (HKLM-x32\...\Steam App 271290) (Version:  - Adhesive Games)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.23.943.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{1CF5754A-545B-4360-BFDE-2847BC728DFC}) (Version: - Apple Inc.)
Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (x32 Version: - Oracle, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
LEGO® Der Herr der Ringe™ (HKLM-x32\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: - Warner Bros. Interactive Entertainment)
LEGO® Star Wars™: Die Komplette Saga (HKLM-x32\...\InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}) (Version: 1.00.0000 - LucasArts)
LEGO® Star Wars™: The Complete Saga (x32 Version: 1.00.0000 - LucasArts) Hidden
Logitech Unifying-Software 2.10 (HKLM\...\Logitech Unifying) (Version: 2.10.37 - Logitech)
LUMIX Map Tool (HKLM-x32\...\InstallShield_{7DCF5B1D-79C2-4F24-9746-511436EBC6B4}) (Version: 1.1.0 - Panasonic Corporation)
LUMIX Map Tool (x32 Version: 1.1.0 - Panasonic Corporation) Hidden
Malwarebytes Anti-Malware Version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 15.0.4615.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2006.0314 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (Version: - Microsoft Corporation) Hidden
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 22.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
Multimedia POP (HKLM-x32\...\{CE3007FF-3E77-4B5B-8F94-662C9582C8A5}) (Version: 1.2 - Samsung Electronics CO., LTD.)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4615.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4615.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4615.1002 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: - Electronic Arts, Inc.)
Overwolf (HKLM-x32\...\{FB83467F-D8EB-43E6-8B3D-860B045C1C52}) (Version: 0.51.325 - Overwolf)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: - Pando Networks Inc.)
PDF24 Creator 5.4.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
PHOTOfunSTUDIO 9.1 PE (HKLM-x32\...\{C13FE7DE-D34D-48CC-9FA3-8DB9A3621B98}) (Version: 9.01.709 - Panasonic Corporation)
Poczta usługi Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
RarmaRadio 2.69 (HKLM-x32\...\RarmaRadio_is1) (Version:  - RaimerSoft)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.54.309.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39025 - Realtek Semiconductor Corp.)
S4 League_EU (HKLM-x32\...\{27E4F38F-8E97-4701-B620-E575A83D5EC9}) (Version: 1.00.0000 - )
Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: - Samsung Electronics CO., LTD.)
Seterra 4.02 (HKLM-x32\...\{7C7C274C-DBC8-47FE-923F-9AAD59A4F9F4}}_is1) (Version: 4.02 - Marianne Wartoft AB)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Software Launcher (HKLM-x32\...\{B750B5C2-CC17-4967-905B-29F4EB986131}) (Version: 1.0.2 - Samsung Electronics CO., LTD.)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: - Valve Corporation)
Stronghold Legends (HKLM-x32\...\{66A405D2-BA14-4594-BF36-B3B544F0754E}) (Version: 1.20.0000 - Firefly Studios)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: - Synaptics Incorporated)
System Requirements Lab CYRI (HKLM-x32\...\{F3FCB08B-E752-444D-86A0-0634A4F3B23D}) (Version: - Husdawg, LLC)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.26297 - TeamViewer)
The Lord of the Rings Online™ (HKLM-x32\...\Steam App 212500) (Version:  - Turbine, Inc.)
User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.2 - Samsung Electronics CO., LTD.)
Valokuvavalikoima (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Family Safety (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3505.0912 - společnost Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3505.0912 - společnost Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3505.0912 - Корпорация Майкрософт) Hidden
Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Pošta (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live 메일 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live 필수 패키지 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live 程式集 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live 软件包 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Liven peruspaketti (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Liven sähköposti (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Συλλογή φωτογραφιών (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 16.4.3505.0912 - Корпорация Майкрософт) Hidden
Фотоальбом (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Фотогалерия (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Фотографии (общедоступная версия) (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
גלריית התמונות (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
사진 갤러리 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
照片库 (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden

==================== Restore Points  =========================

10-06-2014 08:51:19 Windows Update
14-06-2014 08:19:31 Windows Update
15-06-2014 17:18:51 Entfernt League of Legends

==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-07-29 12:22 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {061B63E3-4702-4798-9A4C-44EDF6DED531} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {0D877A6A-DAFC-4706-92DE-ACAEEC9828FC} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2012-01-28] (SEC)
Task: {106A0457-C34C-467F-AD5B-7BE2FFD8FD55} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-01-31] (Samsung Electronics Co., Ltd.)
Task: {1B240628-46D9-4919-BF2D-EA60809CCB7A} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics)
Task: {2D458F6E-F3FF-48B6-9648-C6B89F61843C} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {43583B6E-C95B-4249-B8B9-5C6A581569A9} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [2012-04-19] (Samsung Electronics CO., LTD.)
Task: {595B2086-8717-4475-ADF3-34317656AAAE} - System32\Tasks\Easy Software Manager Agent => C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe [2012-04-12] (Samsung Electronics CO., LTD.)
Task: {6074B35D-C6A5-4464-8D76-F06C6B2163E8} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-15] (Adobe Systems Incorporated)
Task: {619A7A74-D5D5-4977-A82F-3FC2B87E3BBD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd)
Task: {628382A1-D753-4470-862B-787A23703886} - System32\Tasks\{A59A4412-F918-422E-8312-E52EC3A6ADE4} => C:\Program Files (x86)\Intel\Intel Control Center\IntelControlCenter.exe [2009-11-18] (Intel Corporation)
Task: {7149B2AA-8F61-45F8-9A31-828C6949AA65} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.)
Task: {7294C6FC-FA3D-4C3F-B4DE-57501CAC5B83} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {762C6DB5-6A3E-4460-860A-E821269AA442} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-04-15] (Microsoft Corporation)
Task: {7A0A3164-C5A9-462D-B461-97D0045EE6D9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.)
Task: {82E0BCD1-FF69-400B-84CF-2ED358EDEEE8} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: {994B5893-7320-4417-BD3F-B0C83F32673F} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-02-16] (CyberLink)
Task: {9C3DC8C1-6F2C-4B7E-AD51-261ABDDF334C} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation)
Task: {9FB3BC54-6143-4E17-95F7-EA5FA049ADEB} - System32\Tasks\{7176894E-22A2-4903-925E-9F3E1D4F4A60} => Chrome.exe hxxp://ui.skype.com/ui/0/
Task: {A289079E-5A5E-466E-AA92-3E99AB1EF0D7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-22] (Microsoft Corporation)
Task: {A52A91BB-6DFA-42E3-9CF1-F3B12982887E} - System32\Tasks\{6003407F-CA82-409D-9441-255F86102808} => C:\Users\Philipp\Desktop\4Story_DE_gflive_4.0.167.exe
Task: {ABB4245A-C9A9-41FE-A112-BAA5683F90FB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe [2013-04-02] (Google Inc.)
Task: {AF6E35AA-D638-4AFD-807B-7F47B72A27D6} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-03-27] (Samsung Electronics Co., Ltd.)
Task: {B0F3B2DF-CE80-4BDB-8523-5C84D5DAB82E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-23] (Google Inc.)
Task: {B6C71C8A-9C94-421E-A573-711B809B149A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-23] (Google Inc.)
Task: {C4063F29-E7ED-4D12-BE19-8C27EC1BB1C6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-22] (Microsoft Corporation)
Task: {D8689179-7317-4A6F-A06B-D4BC8C521FF0} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe [2012-01-31] (Samsung Electronics)
Task: {DB90A8B3-522B-45B9-98E4-34BB14322A29} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-04-17] (Samsung Electronics Co., Ltd.)
Task: {E25C0C07-448F-40C0-9775-A09A41E27956} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation)
Task: {F073AAC5-C82F-49B1-A28A-C120BC045192} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job => C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe

==================== Loaded Modules (whitelisted) =============

2014-03-20 18:47 - 2013-10-31 18:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2013-03-04 22:23 - 2014-04-15 03:39 - 00630952 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll
2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2012-05-25 08:04 - 2009-12-01 09:21 - 00244904 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2012-07-06 03:45 - 2012-02-13 08:02 - 00031624 _____ () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
2012-03-26 11:33 - 2012-03-26 11:33 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
2012-05-25 07:00 - 2012-04-18 12:49 - 00127320 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-07-06 03:45 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll
2012-07-06 03:46 - 2011-02-16 18:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll
2014-06-15 21:06 - 2014-06-05 15:58 - 00716616 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\libglesv2.dll
2014-06-15 21:06 - 2014-06-05 15:58 - 00126280 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\libegl.dll
2014-06-15 21:06 - 2014-06-05 15:58 - 04217672 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\pdf.dll
2014-06-15 21:06 - 2014-06-05 15:58 - 00414536 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll
2014-06-15 21:06 - 2014-06-05 15:58 - 01732424 _____ () C:\Users\Philipp\AppData\Local\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
2012-05-25 07:23 - 2011-09-08 12:40 - 01645056 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
2009-11-02 07:20 - 2009-11-02 07:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 07:23 - 2009-11-02 07:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2012-05-25 06:59 - 2011-11-29 13:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2012-05-25 07:00 - 2012-04-18 12:50 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (whitelisted) =========

==================== Safe Mode (whitelisted) ===================

==================== EXE Association (whitelisted) =============

==================== MSCONFIG/TASK MANAGER disabled items =========

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PHOTOfunSTUDIO 9.1 PE.lnk => C:\windows\pss\PHOTOfunSTUDIO 9.1 PE.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Philipp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^An OneNote senden.lnk => C:\windows\pss\An OneNote senden.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AthBtTray => "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
MSCONFIG\startupreg: AtherosBtStack => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
MSCONFIG\startupreg: Google Update => "C:\Users\Philipp\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Logitech Download Assistant => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
MSCONFIG\startupreg: Overwolf => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
MSCONFIG\startupreg: PDFPrint => C:\Program Files (x86)\PDF24\pdf24.exe
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15397

Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15397

Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6318

Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6318

Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5257

Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5257

Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/15/2014 10:01:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4243

System errors:
Error: (06/15/2014 10:10:16 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{65CCD3D7-2C99-4B7D-B1E3-EF3835655E6B}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (06/15/2014 10:05:38 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (06/15/2014 07:19:43 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (06/15/2014 07:19:42 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (06/15/2014 07:19:42 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (06/15/2014 07:19:41 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (06/15/2014 07:19:41 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.

Error: (06/14/2014 08:45:03 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1000) (User: NT-AUTORITÄT)
Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x8007045b

Error: (06/14/2014 08:42:06 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58}

Error: (06/14/2014 10:27:40 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Microsoft Office Sessions:
Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15397

Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15397

Error: (06/15/2014 10:01:38 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6318

Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6318

Error: (06/15/2014 10:01:29 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5257

Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5257

Error: (06/15/2014 10:01:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/15/2014 10:01:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4243

CodeIntegrity Errors:
  Date: 2013-06-15 11:39:05.946
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2013-06-15 11:39:05.899
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

==================== Memory info =========================== 

Percentage of memory in use: 28%
Total physical RAM: 8081.44 MB
Available physical RAM: 5815.67 MB
Total Pagefile: 16161.06 MB
Available Pagefile: 13647.34 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:674.67 GB) (Free:401.22 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (Size: 699 GB) (Disk ID: A44E69F2)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=675 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=24 GB) - (Type=27)

==================== End Of Log ============================
PS: die Sachen, die Mbam gefunden hat sind jetzt in Quarantäne.

Alt 16.06.2014, 21:39   #4
/// the machine
/// TB-Ausbilder

Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung - Standard

Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

und ein frisches FRST log bitte.

Alt 17.06.2014, 20:00   #5
Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung - Standard

Malwarebytes erkennt SpeedAnalysis.com als potenzielle Bedrohung


# AdwCleaner v3.212 - Bericht erstellt am 17/06/2014 um 20:18:41
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Philipp - PHILIPPS-PC
# Gestartet von : C:\Users\Philipp\Desktop\adwcleaner_3.212.exe
# Option : Löschen

***** [ Dienste ] *****

***** [ Dateien / Ordner ] *****

***** [ Verknüpfungen ] *****

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS
Schlüssel Gelöscht : HKCU\Software\OCS

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17126

-\\ Mozilla Firefox v29.0.1 (de)

[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\895ns92q.default\prefs.js ]

[ Datei : C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\prefs.js ]

-\\ Google Chrome v

[ Datei : C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\preferences ]


AdwCleaner[R0].txt - [1299 octets] - [28/09/2013 12:06:44]
AdwCleaner[R1].txt - [1161 octets] - [02/11/2013 17:59:30]
AdwCleaner[R2].txt - [1572 octets] - [23/01/2014 16:18:42]
AdwCleaner[R3].txt - [1637 octets] - [17/06/2014 16:52:33]
AdwCleaner[R4].txt - [1695 octets] - [17/06/2014 20:15:16]
AdwCleaner[S0].txt - [1362 octets] - [28/09/2013 12:08:18]
AdwCleaner[S1].txt - [1223 octets] - [02/11/2013 19:05:09]
AdwCleaner[S2].txt - [1633 octets] - [23/01/2014 16:20:23]
AdwCleaner[S3].txt - [1570 octets] - [17/06/2014 20:18:41]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1630 octets] ##########
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Philipp on 17.06.2014 at 20:24:01,14

~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3905478184-3407929709-2893840352-1000\Software\sweetim

~~~ Files

~~~ Folders

~~~ FireFox

Emptied folder: C:\Users\Philipp\AppData\Roaming\mozilla\firefox\profiles\yjwidrr9.default\minidumps [4 files]

~~~ Event Viewer Logs were cleared

Scan was completed on 17.06.2014 at 20:33:23,64
End of JRT log

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-06-2014
Ran by Philipp (administrator) on PHILIPPS-PC on 17-06-2014 20:57:10
Running from C:\Users\Philipp\Desktop\Virensuche
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916112 2012-04-08] (Synaptics Incorporated)
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Philipp\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Philipp\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-23]

CHR HomePage: 
CHR Extension: (Adblock Plus) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-26]
CHR Extension: (Adblock Advisor) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplojogpbcbnjoemcalepfmbcpnkpjjo [2014-04-26]
CHR Extension: (Google Wallet) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2279608 2014-05-21] (Microsoft Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-18] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2014-06-04] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed]
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-09] (Atheros)

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [32896 2012-03-19] (Advanced Micro Devices, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R2 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-17] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe
2014-06-17 20:14 - 2014-06-17 20:14 - 00364286 _____ () C:\Users\Philipp\Documents\Die Entdeckung Amerikas.pptx
2014-06-17 16:53 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO
2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt
2014-06-16 11:20 - 2014-06-17 20:57 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche
2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt
2014-06-16 11:13 - 2014-06-16 11:14 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt
2014-06-16 11:12 - 2014-06-17 20:57 - 00000000 ____D () C:\FRST
2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg
2014-06-12 10:27 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-12 10:27 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-12 10:27 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-12 10:27 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-12 10:27 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-12 10:27 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-12 10:27 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-12 10:27 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-12 10:27 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-12 10:27 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-12 10:27 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-12 10:27 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-12 10:27 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-12 10:27 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-12 10:27 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-12 10:27 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-12 10:27 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-12 10:27 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-12 10:27 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 10:27 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-12 10:27 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-12 10:27 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-06-12 10:27 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-12 10:27 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-12 10:27 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-12 10:27 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-12 10:27 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-12 10:27 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-12 10:27 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-12 10:27 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-06-12 10:27 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-12 10:27 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-06-12 10:27 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-06-12 10:27 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-12 10:27 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-12 10:27 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-12 10:27 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 10:27 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-12 10:27 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-12 10:27 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-12 10:27 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-12 10:27 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-12 10:27 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-12 10:27 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-12 10:27 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-12 10:27 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-12 10:27 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-12 10:27 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-12 10:27 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-12 10:27 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-12 10:27 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-12 10:27 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-06-12 10:27 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-06-12 10:27 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-12 10:27 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2014-06-12 10:27 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2014-06-12 10:27 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-12 10:27 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 10:27 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-12 10:27 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-12 10:27 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2014-06-12 10:27 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2014-06-12 10:25 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-12 10:25 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig
2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-06-06 15:21 - 2014-06-06 15:22 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe
2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR
2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR
2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe
2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory
2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk
2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-06-06 13:53 - 2014-06-06 13:55 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe
2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt
2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822
2014-06-03 17:24 - 2014-06-03 17:25 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp
2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP
2014-06-03 15:50 - 2014-06-16 14:20 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core
2014-06-02 18:50 - 2014-06-16 14:20 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2014-06-02 18:50 - 2014-06-16 14:20 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-06-01 20:39 - 2014-06-15 20:59 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-06-01 20:37 - 2014-06-03 18:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin
2014-06-01 20:37 - 2014-06-03 15:45 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin
2014-06-01 20:34 - 2014-06-16 14:58 - 00000000 ____D () C:\ProgramData\Origin
2014-06-01 20:34 - 2014-06-16 11:22 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-01 20:34 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk
2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D}
2014-05-31 18:01 - 2014-06-04 20:21 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-31 16:21 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-31 16:21 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-05-31 16:21 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-05-31 16:21 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-05-31 16:20 - 2014-05-31 16:21 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-27 16:39 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-05-27 16:39 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-05-26 20:01 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-05-26 20:01 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-26 20:01 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-26 20:01 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-05-26 20:01 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-05-26 20:01 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-05-26 20:01 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-05-26 20:01 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-05-26 20:01 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-05-26 20:01 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-05-26 20:01 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-05-26 20:01 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-05-26 20:01 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-05-26 20:01 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-05-26 20:01 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-05-26 20:01 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-05-26 20:00 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2014-05-26 20:00 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-23 14:31 - 2014-06-17 20:19 - 00016238 _____ () C:\windows\PFRO.log

==================== One Month Modified Files and Folders =======

2014-06-17 20:57 - 2014-06-16 11:20 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche
2014-06-17 20:57 - 2014-06-16 11:12 - 00000000 ____D () C:\FRST
2014-06-17 20:57 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Temp
2014-06-17 20:56 - 2013-04-23 19:22 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-17 20:56 - 2013-04-02 20:58 - 00001128 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job
2014-06-17 20:35 - 2014-04-11 17:40 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-17 20:27 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-17 20:27 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-17 20:24 - 2013-07-14 23:17 - 01724993 _____ () C:\windows\WindowsUpdate.log
2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe
2014-06-17 20:20 - 2012-05-25 07:00 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-06-17 20:19 - 2014-05-23 14:31 - 00016238 _____ () C:\windows\PFRO.log
2014-06-17 20:19 - 2014-04-27 12:29 - 00005208 _____ () C:\windows\setupact.log
2014-06-17 20:19 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-17 20:18 - 2013-09-28 12:06 - 00000000 ____D () C:\AdwCleaner
2014-06-17 20:14 - 2014-06-17 20:14 - 00364286 _____ () C:\Users\Philipp\Documents\Die Entdeckung Amerikas.pptx
2014-06-17 20:06 - 2013-01-14 18:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-06-17 19:45 - 2013-08-16 21:15 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\.minecraft
2014-06-17 19:31 - 2012-05-25 22:31 - 00700134 _____ () C:\windows\system32\perfh007.dat
2014-06-17 19:31 - 2012-05-25 22:31 - 00149984 _____ () C:\windows\system32\perfc007.dat
2014-06-17 19:31 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-17 19:29 - 2012-05-25 07:00 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-06-17 16:51 - 2013-04-02 20:58 - 00001076 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job
2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe
2014-06-16 14:58 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Origin
2014-06-16 14:20 - 2014-06-03 15:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2014-06-16 14:20 - 2014-06-02 18:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2014-06-16 14:20 - 2014-06-02 18:50 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO
2014-06-16 11:50 - 2013-03-04 22:23 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-06-16 11:49 - 2014-04-27 15:59 - 00037483 _____ () C:\windows\DirectX.log
2014-06-16 11:49 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt
2014-06-16 11:22 - 2014-06-01 20:34 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt
2014-06-16 11:14 - 2014-06-16 11:13 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt
2014-06-15 21:07 - 2013-04-02 21:01 - 00002373 _____ () C:\Users\Philipp\Desktop\Google Chrome.lnk
2014-06-15 20:59 - 2014-06-01 20:39 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-06-15 19:20 - 2012-05-25 06:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg
2014-06-15 18:00 - 2012-11-11 16:51 - 00000000 ____D () C:\Users\Philipp\AppData\Local\CrashDumps
2014-06-14 10:25 - 2013-07-15 14:17 - 00000000 ____D () C:\windows\system32\MRT
2014-06-14 10:23 - 2012-10-20 21:21 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-14 10:20 - 2014-05-06 22:19 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-08 11:13 - 2014-06-12 10:25 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 10:25 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig
2014-06-06 20:14 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp
2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-06-06 15:22 - 2014-06-06 15:21 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe
2014-06-06 15:17 - 2013-05-27 22:46 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\vlc
2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR
2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR
2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe
2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory
2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk
2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-06-06 13:56 - 2013-05-18 14:55 - 00000000 ____D () C:\Program Files (x86)\FreeTime
2014-06-06 13:55 - 2014-06-06 13:53 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe
2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt
2014-06-04 20:29 - 2014-06-02 18:50 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2014-06-04 20:21 - 2014-05-31 18:01 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp
2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822
2014-06-03 18:37 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin
2014-06-03 17:25 - 2014-06-03 17:24 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp
2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP
2014-06-03 17:24 - 2012-11-22 15:12 - 00000000 ____D () C:\windows\Minidump
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core
2014-06-03 15:45 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin
2014-06-03 15:45 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk
2014-06-01 15:14 - 2014-06-01 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-01 15:10 - 2012-11-25 17:18 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-06-01 00:32 - 2013-06-21 23:54 - 00007597 _____ () C:\Users\Philipp\AppData\Local\Resmon.ResmonCfg
2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D}
2014-05-31 17:55 - 2012-10-21 12:31 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\SoftGrid Client
2014-05-31 17:29 - 2014-03-27 23:55 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TS3Client
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-31 16:21 - 2014-05-31 16:20 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-31 16:21 - 2013-10-16 23:29 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-31 16:21 - 2013-06-23 18:37 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-05-30 22:12 - 2013-03-02 20:49 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-30 12:21 - 2014-06-12 10:27 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 10:27 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 10:27 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 10:27 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-12 10:27 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-12 10:27 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 10:27 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 10:27 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-12 10:27 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-12 10:27 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 10:27 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 10:27 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 10:27 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 10:27 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 10:27 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 10:27 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-12 10:27 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 10:27 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 10:27 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 10:27 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 10:27 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 10:27 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 10:27 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 10:27 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 10:27 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 10:27 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 10:27 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 10:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 10:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 10:27 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 10:27 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 10:27 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 10:27 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 10:27 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 10:27 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 10:27 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 10:27 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 10:27 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 10:27 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 10:27 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 10:27 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 10:27 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 10:27 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 10:27 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 10:27 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 10:27 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-05-29 16:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache
2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-26 16:37 - 2013-02-17 16:31 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Windows Live

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-05-29 16:39

==================== End Of Log ============================
--- --- ---

Viele Grüße

just take the coffee smiley

was mach ich mit den Funden von ESET? Entfernen lassen?

hier das Log:
C:\AdwCleaner\Quarantine\C\Users\Philipp\AppData\Local\cre\oolkekjjhnaeaahibbnfebmogackofpf.crx.vir	Variante von Win32/Toolbar.Conduit.AH evtl. unerwünschte Anwendung
C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\Ask\AskPIP_FF_.exe	Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung
C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe	Variante von Win32/Hao123.A evtl. unerwünschte Anwendung
C:\Program Files (x86)\Mozilla Firefox\components\sprotector.js	Win32/Conduit.SearchProtect.A evtl. unerwünschte Anwendung
C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe	Variante von Win32/Hao123.A evtl. unerwünschte Anwendung
C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe	Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung
Und die Sachen in der Quarantäne bei Malwarebytes? Soll ich die auch löschen?
Viele Grüße

just take the coffee smiley

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-06-2014
Ran by Philipp (administrator) on PHILIPPS-PC on 19-06-2014 23:34:51
Running from C:\Users\Philipp\Desktop\Virensuche
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\POWERPNT.EXE
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Philipp\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916112 2012-04-08] (Synaptics Incorporated)
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-01-31] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3905478184-3407929709-2893840352-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Philipp\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Philipp\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\yjwidrr9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-23]

CHR HomePage: 
CHR Extension: (Adblock Plus) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-26]
CHR Extension: (Adblock Advisor) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplojogpbcbnjoemcalepfmbcpnkpjjo [2014-04-26]
CHR Extension: (Google Wallet) - C:\Users\Philipp\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2279608 2014-05-21] (Microsoft Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-04-18] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [164184 2012-04-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2014-06-04] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [File not signed]
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed]
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-09] (Atheros)

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [32896 2012-03-19] (Advanced Micro Devices, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R2 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-19] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-06-19 23:11 - 2014-06-19 23:11 - 00003224 _____ () C:\windows\System32\Tasks\{C30FB847-060E-4DA6-B676-154FC9D4A79F}
2014-06-19 23:06 - 2014-06-19 23:11 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\GlarySoft
2014-06-19 23:06 - 2014-06-19 23:06 - 00001070 _____ () C:\Users\Philipp\Desktop\Absolute Uninstaller.lnk
2014-06-19 23:05 - 2014-06-19 23:05 - 02194784 _____ (Glarysoft.com ) C:\Users\Philipp\Downloads\au29setup.exe
2014-06-19 19:09 - 2014-06-19 19:09 - 00000165 ____H () C:\Users\Philipp\Desktop\~$Die Entdeckung Amerikas.pptx
2014-06-19 00:20 - 2014-06-19 00:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-18 18:52 - 2014-06-18 18:52 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe
2014-06-17 20:14 - 2014-06-19 19:08 - 01156526 _____ () C:\Users\Philipp\Desktop\Die Entdeckung Amerikas.pptx
2014-06-17 16:53 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO
2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt
2014-06-16 11:20 - 2014-06-19 23:34 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche
2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt
2014-06-16 11:13 - 2014-06-16 11:14 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt
2014-06-16 11:12 - 2014-06-19 23:34 - 00000000 ____D () C:\FRST
2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg
2014-06-12 10:27 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-12 10:27 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-12 10:27 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-12 10:27 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-12 10:27 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-12 10:27 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-12 10:27 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-12 10:27 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-12 10:27 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-12 10:27 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-12 10:27 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-12 10:27 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-12 10:27 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-12 10:27 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-12 10:27 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-12 10:27 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-12 10:27 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-12 10:27 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-12 10:27 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 10:27 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-12 10:27 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-12 10:27 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-06-12 10:27 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-12 10:27 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-12 10:27 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-12 10:27 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-12 10:27 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-12 10:27 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-12 10:27 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-12 10:27 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-06-12 10:27 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-12 10:27 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-06-12 10:27 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-06-12 10:27 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-12 10:27 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-12 10:27 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-12 10:27 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 10:27 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-12 10:27 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-12 10:27 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-12 10:27 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-12 10:27 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-12 10:27 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-12 10:27 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-12 10:27 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-12 10:27 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-12 10:27 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-12 10:27 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-12 10:27 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-12 10:27 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-12 10:27 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-12 10:27 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-06-12 10:27 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-06-12 10:27 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-12 10:27 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2014-06-12 10:27 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2014-06-12 10:27 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-12 10:27 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 10:27 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-12 10:27 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-12 10:27 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-12 10:27 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2014-06-12 10:27 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2014-06-12 10:27 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2014-06-12 10:25 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-12 10:25 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig
2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-06-06 15:21 - 2014-06-06 15:22 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe
2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR
2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR
2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe
2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory
2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk
2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-06-06 13:53 - 2014-06-06 13:55 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe
2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt
2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822
2014-06-03 17:24 - 2014-06-03 17:25 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp
2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP
2014-06-03 15:50 - 2014-06-19 18:25 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core
2014-06-02 18:50 - 2014-06-19 18:25 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2014-06-02 18:50 - 2014-06-19 18:25 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2014-06-02 18:50 - 2014-06-04 20:29 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-06-01 20:39 - 2014-06-15 20:59 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-06-01 20:37 - 2014-06-03 18:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin
2014-06-01 20:37 - 2014-06-03 15:45 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin
2014-06-01 20:34 - 2014-06-19 13:19 - 00000000 ____D () C:\ProgramData\Origin
2014-06-01 20:34 - 2014-06-19 13:19 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-01 20:34 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk
2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D}
2014-05-31 18:01 - 2014-06-04 20:21 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-31 16:21 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-31 16:21 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-05-31 16:21 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-05-31 16:21 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-05-31 16:20 - 2014-05-31 16:21 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-27 16:39 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-05-27 16:39 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-05-26 20:01 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-05-26 20:01 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-26 20:01 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-26 20:01 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-05-26 20:01 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-05-26 20:01 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-05-26 20:01 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-05-26 20:01 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-05-26 20:01 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-05-26 20:01 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-05-26 20:01 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-05-26 20:01 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-05-26 20:01 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-05-26 20:01 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-05-26 20:01 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-05-26 20:01 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-05-26 20:00 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2014-05-26 20:00 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-23 14:31 - 2014-06-17 20:19 - 00016238 _____ () C:\windows\PFRO.log

==================== One Month Modified Files and Folders =======

2014-06-19 23:34 - 2014-06-16 11:20 - 00000000 ____D () C:\Users\Philipp\Desktop\Virensuche
2014-06-19 23:34 - 2014-06-16 11:12 - 00000000 ____D () C:\FRST
2014-06-19 23:11 - 2014-06-19 23:11 - 00003224 _____ () C:\windows\System32\Tasks\{C30FB847-060E-4DA6-B676-154FC9D4A79F}
2014-06-19 23:11 - 2014-06-19 23:06 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\GlarySoft
2014-06-19 23:06 - 2014-06-19 23:06 - 00001070 _____ () C:\Users\Philipp\Desktop\Absolute Uninstaller.lnk
2014-06-19 23:06 - 2013-01-14 18:13 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-06-19 23:05 - 2014-06-19 23:05 - 02194784 _____ (Glarysoft.com ) C:\Users\Philipp\Downloads\au29setup.exe
2014-06-19 23:01 - 2013-04-23 19:22 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-19 22:49 - 2013-04-02 20:58 - 00001128 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000UA.job
2014-06-19 22:39 - 2014-04-11 17:40 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-19 21:31 - 2012-05-25 22:31 - 00700134 _____ () C:\windows\system32\perfh007.dat
2014-06-19 21:31 - 2012-05-25 22:31 - 00149984 _____ () C:\windows\system32\perfc007.dat
2014-06-19 21:31 - 2009-07-14 07:13 - 01622236 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-19 21:28 - 2013-07-14 23:17 - 01758705 _____ () C:\windows\WindowsUpdate.log
2014-06-19 19:09 - 2014-06-19 19:09 - 00000165 ____H () C:\Users\Philipp\Desktop\~$Die Entdeckung Amerikas.pptx
2014-06-19 19:09 - 2012-05-25 07:00 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-06-19 19:08 - 2014-06-17 20:14 - 01156526 _____ () C:\Users\Philipp\Desktop\Die Entdeckung Amerikas.pptx
2014-06-19 18:25 - 2014-06-03 15:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2014-06-19 18:25 - 2014-06-02 18:50 - 00290184 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2014-06-19 18:25 - 2014-06-02 18:50 - 00280904 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2014-06-19 15:49 - 2013-04-02 20:58 - 00001076 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3905478184-3407929709-2893840352-1000Core.job
2014-06-19 13:19 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Origin
2014-06-19 13:19 - 2014-06-01 20:34 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-19 11:56 - 2013-04-23 19:22 - 00004108 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-19 11:56 - 2013-04-23 19:22 - 00003858 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-19 11:56 - 2013-04-23 19:22 - 00001108 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-19 00:20 - 2014-06-19 00:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-18 18:52 - 2014-06-18 18:52 - 02347384 _____ (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_deu.exe
2014-06-18 12:06 - 2013-08-16 21:15 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\.minecraft
2014-06-18 11:28 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-18 11:28 - 2009-07-14 06:45 - 00021200 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-18 11:19 - 2014-04-27 12:29 - 00005264 _____ () C:\windows\setupact.log
2014-06-18 11:19 - 2012-05-25 07:00 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-06-18 11:19 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-17 22:37 - 2012-11-03 14:49 - 00016896 ___SH () C:\Users\Philipp\Documents\Thumbs.db
2014-06-17 20:23 - 2014-06-17 20:23 - 01016261 _____ (Thisisu) C:\Users\Philipp\Downloads\JRT.exe
2014-06-17 20:19 - 2014-05-23 14:31 - 00016238 _____ () C:\windows\PFRO.log
2014-06-17 20:18 - 2013-09-28 12:06 - 00000000 ____D () C:\AdwCleaner
2014-06-17 16:49 - 2014-06-17 16:49 - 01333465 _____ () C:\Users\Philipp\Desktop\adwcleaner_3.212.exe
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 __SHD () C:\ProgramData\DSS
2014-06-16 12:31 - 2014-06-16 12:31 - 00000000 ____D () C:\Users\Philipp\Documents\FIFA 14 DEMO
2014-06-16 11:50 - 2013-03-04 22:23 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-06-16 11:49 - 2014-04-27 15:59 - 00037483 _____ () C:\windows\DirectX.log
2014-06-16 11:49 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-16 11:47 - 2014-06-16 11:47 - 00000378 _____ () C:\Users\Philipp\Downloads\text-2.txt
2014-06-16 11:14 - 2014-06-16 11:14 - 00042738 _____ () C:\Users\Philipp\Downloads\Addition.txt
2014-06-16 11:14 - 2014-06-16 11:13 - 00048826 _____ () C:\Users\Philipp\Downloads\FRST.txt
2014-06-15 21:07 - 2013-04-02 21:01 - 00002373 _____ () C:\Users\Philipp\Desktop\Google Chrome.lnk
2014-06-15 20:59 - 2014-06-01 20:39 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-06-15 19:20 - 2012-05-25 06:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-15 19:17 - 2014-06-15 19:17 - 00041383 _____ () C:\Users\Philipp\AppData\Local\Perfmon.PerfmonCfg
2014-06-15 18:00 - 2012-11-11 16:51 - 00000000 ____D () C:\Users\Philipp\AppData\Local\CrashDumps
2014-06-14 10:25 - 2013-07-15 14:17 - 00000000 ____D () C:\windows\system32\MRT
2014-06-14 10:23 - 2012-10-20 21:21 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-14 10:20 - 2014-05-06 22:19 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-08 11:13 - 2014-06-12 10:25 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 10:25 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-07 15:31 - 2014-06-07 15:31 - 00000000 ____D () C:\Users\Philipp\Documents\DIE SIEDLER - DEdK
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\Neuer Ordner
2014-06-06 20:14 - 2014-06-06 20:14 - 00000000 ____D () C:\Users\Philipp\CD2 richtig
2014-06-06 20:14 - 2012-10-21 19:17 - 00000000 ____D () C:\Users\Philipp
2014-06-06 15:22 - 2014-06-06 15:22 - 00001913 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00001863 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-06-06 15:22 - 2014-06-06 15:22 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-06-06 15:22 - 2014-06-06 15:21 - 05405880 _____ (Canneverbe Limited ) C:\Users\Philipp\Downloads\cdbxp_setup_4.5.4.4852_minimal.exe
2014-06-06 15:17 - 2013-05-27 22:46 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\vlc
2014-06-06 14:49 - 2014-06-06 14:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\LoRd_MuldeR
2014-06-06 14:48 - 2014-06-06 14:48 - 00000000 ____D () C:\Program Files (x86)\MuldeR
2014-06-06 14:44 - 2014-06-06 14:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Philipp\Downloads\LameXP - CHIP-Installer.exe
2014-06-06 14:13 - 2014-06-06 14:13 - 00000000 ____D () C:\Users\Philipp\Documents\FormatFactory
2014-06-06 13:56 - 2014-06-06 13:56 - 00001162 _____ () C:\Users\Philipp\Desktop\Format Factory.lnk
2014-06-06 13:56 - 2014-06-06 13:56 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-06-06 13:56 - 2013-05-18 14:55 - 00000000 ____D () C:\Program Files (x86)\FreeTime
2014-06-06 13:55 - 2014-06-06 13:53 - 55003752 _____ (Free Time) C:\Users\Philipp\Downloads\FFSetup3.3.4.0.exe
2014-06-05 19:47 - 2014-06-05 19:47 - 00000096 _____ () C:\Users\Philipp\Downloads\ATT00001.txt
2014-06-04 20:29 - 2014-06-02 18:50 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2014-06-04 20:21 - 2014-05-31 18:01 - 00014814 ____H () C:\Users\Philipp\Desktop\~WRL3483.tmp
2014-06-04 16:51 - 2014-06-04 16:51 - 00001295 _____ () C:\Users\Philipp\Downloads\message-3.rfc822
2014-06-03 18:37 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\Origin
2014-06-03 17:25 - 2014-06-03 17:24 - 01166104 _____ () C:\windows\Minidump\060314-23961-01.dmp
2014-06-03 17:24 - 2014-06-03 17:24 - 715826328 _____ () C:\windows\MEMORY.DMP
2014-06-03 17:24 - 2012-11-22 15:12 - 00000000 ____D () C:\windows\Minidump
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\Documents\Battlefield 3
2014-06-03 15:50 - 2014-06-03 15:50 - 00000000 ____D () C:\Users\Philipp\AppData\Local\PunkBuster
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Users\Philipp\AppData\Local\ESN
2014-06-03 15:49 - 2014-06-03 15:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-06-03 15:45 - 2014-06-03 15:45 - 00000000 ____D () C:\ProgramData\EA Core
2014-06-03 15:45 - 2014-06-01 20:37 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Origin
2014-06-03 15:45 - 2014-06-01 20:34 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-06-02 18:50 - 2014-06-02 18:50 - 00001134 _____ () C:\Users\Public\Desktop\Battlefield 3.lnk
2014-06-02 18:50 - 2014-06-02 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-06-01 20:34 - 2014-06-01 20:34 - 00000943 _____ () C:\Users\Public\Desktop\Origin.lnk
2014-06-01 15:10 - 2012-11-25 17:18 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-06-01 00:32 - 2013-06-21 23:54 - 00007597 _____ () C:\Users\Philipp\AppData\Local\Resmon.ResmonCfg
2014-05-31 23:05 - 2014-05-31 23:05 - 00003146 _____ () C:\windows\System32\Tasks\{7D99506A-552D-45CF-A524-D1DA7615312D}
2014-05-31 17:55 - 2012-10-21 12:31 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\SoftGrid Client
2014-05-31 17:29 - 2014-03-27 23:55 - 00000000 ____D () C:\Users\Philipp\AppData\Roaming\TS3Client
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-05-31 16:22 - 2014-05-31 16:22 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-05-31 16:21 - 2014-05-31 16:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-31 16:21 - 2014-05-31 16:20 - 00004563 _____ () C:\windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-31 16:21 - 2013-10-16 23:29 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-31 16:21 - 2013-06-23 18:37 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-30 22:12 - 2014-04-11 17:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-05-30 22:12 - 2013-03-02 20:49 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-30 12:21 - 2014-06-12 10:27 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 10:27 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 10:27 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 10:27 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-12 10:27 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-12 10:27 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 10:27 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 10:27 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-12 10:27 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-12 10:27 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 10:27 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 10:27 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 10:27 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 10:27 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 10:27 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 10:27 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 10:27 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-12 10:27 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 10:27 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 10:27 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 10:27 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 10:27 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 10:27 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 10:27 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 10:27 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 10:27 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 10:27 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 10:27 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 10:27 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 10:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 10:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 10:27 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 10:27 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 10:27 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 10:27 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 10:27 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 10:27 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 10:27 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 10:27 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 10:27 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 10:27 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 10:27 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 10:27 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 10:27 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 10:27 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 10:27 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 10:27 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 10:27 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-05-29 16:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache
2014-05-26 19:56 - 2014-05-26 19:56 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iTunes
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files\iPod
2014-05-26 19:56 - 2014-05-26 19:56 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-05-26 16:37 - 2013-02-17 16:31 - 00000000 ____D () C:\Users\Philipp\AppData\Local\Windows Live

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-05-29 16:39

==================== End Of Log ============================
--- --- ---

 Results of screen317's Security Check version 0.99.83  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 AVG PC TuneUp 2014 (de-DE) 
 Java 7 Update 60  
 Java version out of Date! 
 Adobe Flash Player  
 Adobe Reader XI  
 Mozilla Firefox (30.0) 
 Google Chrome 35.0.1916.114  
 Google Chrome 35.0.1916.153  
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Malwarebytes Anti-Malware mbamscheduler.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
Quarantäne ist gelöscht ;D
Viele Grüße

just take the coffee smiley

Java updaten.


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.

Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.

Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.

Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.

Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.

Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.

Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )

  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

