![]() |
|
Log-Analyse und Auswertung: Windows 7 (64bit) - hyperaktive timeserver.exe - Malwarebytes kann Befall nicht dauerhaft entfernenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Windows 7 (64bit) - hyperaktive timeserver.exe - Malwarebytes kann Befall nicht dauerhaft entfernen Hallo Werte Damen und Herren, Dass ich hier vorbei schaun muss ist mir etwas peinlich, fast schon peinlichst, da ich seit vielen, vielen Jahren keinen Virenbefall mehr hatte. Tja, da habe ich mich wohl getäuscht. Meine Sucht für Civilization V und mein nicht aufgeben wollen eines Spielstandes haben mich zu einem sog. "Trainer" geführt. Da selbst die (im Nachhinein) sauberen Trainer von meinem McAffee-Zugriffsscanner sogleich vernichtet wurden, habe ich ihn wider besseren Wissens abgeschaltet und die vermeintliche trainer.exe angeclickt...Nur leider war es wirklich Schadsoftware. Nun steinigt mich. ![]() Aufgefallen ist das Problem durch die hyperaktive TimeServer.exe, die auf ein mal enorm viel Speicherplatz verbraucht. Mit Malwarebytes habe ich daher einen Komplettscan durchgeführt und die Bedrohung entfernt, so dachte ich. Das hält bis zum nächsten reboot und dann ist es wieder der selbe Salat, die TimeServer.exe wieder im taskmanager mit verbrauchtem 40-42mb Zwischenspeicher. Hier nun erst mal die Logfiles meiner ursprünglichen Bekämpfung des Problems: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.05.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 mkwzbg :: MKWZBG-PC [Administrator] 05.08.2013 15:30:25 mbam-log-2013-08-05 (15-30-25).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 260673 Laufzeit: 4 Minute(n), 2 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage) -> Bösartig: (hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=DC6F00040ECDB007&affID=123976&tt=040813_10&tsp=4965) Gut: (hxxp://www.google.com) -> Keine Aktion durchgeführt. Infizierte Verzeichnisse: 1 C:\Users\mkwzbg\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 11 C:\Users\mkwzbg\AppData\Local\Temp\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Keine Aktion durchgeführt. C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\ccp.exe (PUP.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\MyDeltaTB.exe (PUP.Delta.A) -> Keine Aktion durchgeführt. C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\Setup.exe (PUP.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\mkwzbg\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\mkwzbg\Desktop\civilization5DX11_17trainer_custom.zip (HackTool.GamesCheat.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\LyricsPal_1060-8101_v122.exe (PUP.LyricsAd) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\OptimizerPro.exe (PUP.Optional.OptimizePro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\pricepeep_130001_0101.exe (Adware.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-21-905224183-1817278694-1461159428-1000\$R4A8VXE.zip (HackTool.GamesCheat.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-21-905224183-1817278694-1461159428-1000\$RCWKEKF.zip (HackTool.GamesCheat.Gen) -> Erfolgreich gelöscht und in Quarantäne gestellt. Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.05.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 mkwzbg :: MKWZBG-PC [Administrator] 05.08.2013 15:50:29 mbam-log-2013-08-05 (15-50-29).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 259938 Laufzeit: 3 Minute(n), 20 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage) -> Bösartig: (hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=DC6F00040ECDB007&affID=123976&tt=040813_10&tsp=4965) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 1 C:\Users\mkwzbg\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 5 C:\Users\mkwzbg\AppData\Local\Temp\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\ccp.exe (PUP.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\MyDeltaTB.exe (PUP.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\Setup.exe (PUP.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.05.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 mkwzbg :: MKWZBG-PC [Administrator] 10.08.2013 00:09:29 mbam-log-2013-08-10 (00-09-29).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 492796 Laufzeit: 1 Stunde(n), 16 Minute(n), 32 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Temporary\ieutil.exe (PUP.BitCoinMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GE3IY85V\pack[1].7z (PUP.Optional.BrowserDefender.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\f8d689b190207dc8cc11c65a624c9879\CheatEngine62.exe (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.05.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 mkwzbg :: MKWZBG-PC [Administrator] 10.08.2013 01:41:41 mbam-log-2013-08-10 (01-41-41).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 492840 Laufzeit: 1 Stunde(n), 8 Minute(n), Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.14.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 mkwzbg :: MKWZBG-PC [Administrator] 14.08.2013 15:53:55 mbam-log-2013-08-14 (15-53-55).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 494189 Laufzeit: 1 Stunde(n), 21 Minute(n), 17 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 3 C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\80CB50D9-BAB0-7891-A46C-E5BA8F276E43\Latest\NTRedirect.dll (PUP.Optional.Babylon.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\mkwzbg\AppData\Local\Temp\poclbm120222.cl (Trojan.BitcoinMiner) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) FRST: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-08-2013 01 Ran by mkwzbg (administrator) on 15-08-2013 03:39:38 Running from C:\Users\mkwzbg\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (Microsoft) C:\ProgramData\Microsoft\Windows\Time\Time-svc.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe (Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft) C:\ProgramData\Microsoft\Windows\Time\WindowsTime.exe () C:\ProgramData\Microsoft\Windows\Time\TimeServer.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\McTray.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe () C:\Users\mkwzbg\AppData\Local\Opera\Opera\temporary_downloads\Defogger.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-11-30] (Realtek Semiconductor) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1807272 2013-07-27] (Valve Corporation) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [McAfeeUpdaterUI] - C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe [161088 2011-01-12] (McAfee, Inc.) HKLM-x32\...\Run: [ShStatEXE] - C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE [215360 2011-01-12] (McAfee, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=DC6F00040ECDB007&affID=123976&tt=040813_10&tsp=4965 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={026C9A61-7CEB-4686-A0F8-2F3C1529C901}&mid=5b92e099f47b4cb793dd6b59a17ab577-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=en&ds=dw011&pr=sa&d=2012-07-05 21:42:30&v=11.1.0.12&sap=dsp&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111231154048.dll (McAfee, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111231154048.dll (McAfee, Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\mkwzbg\AppData\Roaming\Mozilla\Firefox\Profiles\3w1lq905.default FF user.js: detected! => C:\Users\mkwzbg\AppData\Roaming\Mozilla\Firefox\Profiles\3w1lq905.default\user.js FF Homepage: user_pref("browser.startup.homepage", ); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Users\mkwzbg\AppData\Roaming\Mozilla\Firefox\Profiles\3w1lq905.default\searchplugins\babylon.xml ==================== Services (Whitelisted) ================= R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 DAUpdaterSvc; C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2012-07-24] (BioWare) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 McAfeeFramework; C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [120128 2011-01-12] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [190256 2011-12-31] (McAfee, Inc.) R2 McTaskManager; C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe [209760 2011-01-12] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [156248 2011-12-31] (McAfee, Inc.) R2 Time; C:\ProgramData\Microsoft\Windows\Time\Time-svc.exe [10752 2013-08-05] (Microsoft) ==================== Drivers (Whitelisted) ==================== S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [153952 2011-12-31] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [217696 2011-12-31] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [607152 2011-12-31] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [97960 2011-12-31] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [281544 2011-12-31] (McAfee, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] U3 mfeavfk01; No ImagePath ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-15 03:38 - 2013-08-15 03:38 - 01575570 _____ (Farbar) C:\Users\mkwzbg\Desktop\FRST64.exe 2013-08-15 03:34 - 2013-08-15 03:34 - 00000000 _____ C:\Users\mkwzbg\defogger_reenable 2013-08-15 03:05 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 03:05 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 03:05 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 03:05 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 03:05 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 03:05 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 03:05 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 03:05 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 03:05 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 03:05 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 03:05 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 03:05 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 21:06 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 21:06 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 21:06 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 21:06 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 21:06 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 21:06 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 21:06 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 21:06 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 21:06 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 21:06 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 21:06 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 21:06 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 21:06 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 21:06 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 21:06 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 21:06 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 21:06 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 21:06 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 21:06 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 21:06 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 21:06 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 21:06 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 21:06 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 21:06 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 21:06 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 21:06 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 21:06 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 19:16 - 2013-08-14 19:16 - 00015858 _____ C:\ComboFix.txt 2013-08-14 19:07 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-14 19:07 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-14 19:07 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-14 19:06 - 2013-08-14 19:16 - 00000000 ____D C:\Qoobox 2013-08-14 19:06 - 2013-08-14 19:15 - 00000000 ____D C:\Windows\erdnt 2013-08-09 00:58 - 2013-08-09 00:58 - 00000000 ____D C:\ProgramData\Stardock 2013-08-05 15:29 - 2013-08-05 15:42 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\tor 2013-08-05 15:29 - 2013-08-05 15:30 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\Rydu 2013-08-05 14:21 - 2013-08-05 14:36 - 00000047 _____ C:\Users\mkwzbg\Documents\mt-x_hook.txt 2013-08-05 14:21 - 2013-08-05 14:36 - 00000007 _____ C:\Users\mkwzbg\Documents\mt-e_hook.txt 2013-08-05 12:27 - 2013-08-15 03:22 - 00009732 _____ C:\Windows\PFRO.log 2013-08-05 02:18 - 2013-08-05 02:18 - 00000000 ____D C:\ProgramData\Babylon 2013-08-04 18:49 - 2013-08-04 18:49 - 00064024 _____ C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-04 18:49 - 2013-08-04 18:49 - 00000000 ____D C:\Users\Gast\AppData\Roaming\NVIDIA 2013-08-03 14:35 - 2013-08-03 14:35 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\My Games 2013-08-03 14:10 - 2013-08-05 17:13 - 00000000 ____D C:\Program Files (x86)\Sid Meier's Civilization V 2013-07-29 12:24 - 2013-08-15 03:25 - 00003022 _____ C:\Windows\System32\Tasks\EVGAPrecision 2013-07-25 17:50 - 2013-07-25 17:50 - 00000205 _____ C:\Users\mkwzbg\Desktop\Batman Arkham City GOTY.url 2013-07-25 16:47 - 2013-07-25 16:47 - 00000222 _____ C:\Users\mkwzbg\Desktop\Alan Wake.url 2013-07-25 15:48 - 2013-08-15 03:00 - 00000000 ____D C:\Windows\system32\MRT 2013-07-22 13:29 - 2013-07-22 13:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\201280 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\Documents\WB Games 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\Downloaded Installations 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Program Files (x86)\AMD 2013-07-22 01:07 - 2013-08-09 00:57 - 00055533 _____ C:\Windows\DirectX.log ==================== One Month Modified Files and Folders ======= 2013-08-15 03:38 - 2013-08-15 03:38 - 01575570 _____ (Farbar) C:\Users\mkwzbg\Desktop\FRST64.exe 2013-08-15 03:34 - 2013-08-15 03:34 - 00000000 _____ C:\Users\mkwzbg\defogger_reenable 2013-08-15 03:34 - 2011-12-31 17:28 - 00000000 ____D C:\Program Files (x86)\Opera 2013-08-15 03:34 - 2011-12-31 10:36 - 00000000 ____D C:\Users\mkwzbg 2013-08-15 03:31 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-15 03:31 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-15 03:25 - 2013-07-29 12:24 - 00003022 _____ C:\Windows\System32\Tasks\EVGAPrecision 2013-08-15 03:25 - 2012-07-20 16:59 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-15 03:23 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-15 03:22 - 2013-08-05 12:27 - 00009732 _____ C:\Windows\PFRO.log 2013-08-15 03:22 - 2013-06-08 11:19 - 00008680 _____ C:\Windows\setupact.log 2013-08-15 03:22 - 2011-12-31 16:18 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-15 03:21 - 2011-12-31 10:29 - 01196488 _____ C:\Windows\WindowsUpdate.log 2013-08-15 03:03 - 2011-04-12 09:43 - 00696848 _____ C:\Windows\system32\perfh007.dat 2013-08-15 03:03 - 2011-04-12 09:43 - 00148144 _____ C:\Windows\system32\perfc007.dat 2013-08-15 03:03 - 2009-07-14 07:13 - 01634468 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-15 03:02 - 2013-07-25 15:48 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 03:00 - 2011-12-31 18:47 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 19:16 - 2013-08-14 19:16 - 00015858 _____ C:\ComboFix.txt 2013-08-14 19:16 - 2013-08-14 19:06 - 00000000 ____D C:\Qoobox 2013-08-14 19:16 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-08-14 19:15 - 2013-08-14 19:06 - 00000000 ____D C:\Windows\erdnt 2013-08-14 19:15 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-11 04:05 - 2011-12-31 17:30 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\vlc 2013-08-11 03:24 - 2012-01-30 01:40 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\QuickPar 2013-08-11 02:55 - 2012-03-27 19:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\GrabIt 2013-08-10 00:55 - 2013-03-06 21:28 - 00000000 ____D C:\Temporary 2013-08-10 00:55 - 2012-06-05 14:57 - 00000000 ____D C:\QUARANTINE 2013-08-09 02:51 - 2012-02-18 01:38 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\Media Player Classic 2013-08-09 00:58 - 2013-08-09 00:58 - 00000000 ____D C:\ProgramData\Stardock 2013-08-09 00:58 - 2012-02-01 10:50 - 00000000 ____D C:\Users\mkwzbg\Documents\My Games 2013-08-09 00:57 - 2013-07-22 01:07 - 00055533 _____ C:\Windows\DirectX.log 2013-08-05 17:13 - 2013-08-03 14:10 - 00000000 ____D C:\Program Files (x86)\Sid Meier's Civilization V 2013-08-05 15:42 - 2013-08-05 15:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\tor 2013-08-05 15:30 - 2013-08-05 15:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\Rydu 2013-08-05 14:36 - 2013-08-05 14:21 - 00000047 _____ C:\Users\mkwzbg\Documents\mt-x_hook.txt 2013-08-05 14:36 - 2013-08-05 14:21 - 00000007 _____ C:\Users\mkwzbg\Documents\mt-e_hook.txt 2013-08-05 02:18 - 2013-08-05 02:18 - 00000000 ____D C:\ProgramData\Babylon 2013-08-04 18:49 - 2013-08-04 18:49 - 00064024 _____ C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-04 18:49 - 2013-08-04 18:49 - 00000000 ____D C:\Users\Gast\AppData\Roaming\NVIDIA 2013-08-03 14:35 - 2013-08-03 14:35 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\My Games 2013-08-03 03:25 - 2012-07-05 21:50 - 00000000 ____D C:\Users\mkwzbg\.FBReader 2013-07-26 07:13 - 2013-08-15 03:05 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-15 03:05 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-15 03:05 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-15 03:05 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-15 03:05 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-15 03:05 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-15 03:05 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-15 03:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-15 03:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-15 03:05 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-15 03:05 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-15 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 17:50 - 2013-07-25 17:50 - 00000205 _____ C:\Users\mkwzbg\Desktop\Batman Arkham City GOTY.url 2013-07-25 16:47 - 2013-07-25 16:47 - 00000222 _____ C:\Users\mkwzbg\Desktop\Alan Wake.url 2013-07-25 11:25 - 2013-08-14 21:06 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 21:06 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 16:35 - 2012-05-21 22:04 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\dvdcss 2013-07-24 15:37 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-22 13:29 - 2013-07-22 13:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\201280 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\Documents\WB Games 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\Downloaded Installations 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Program Files (x86)\AMD 2013-07-22 01:05 - 2012-11-08 01:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-07-22 01:05 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-07-19 03:58 - 2013-08-14 21:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-07-19 03:41 - 2013-08-14 21:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-07-18 12:39 - 2013-07-12 12:39 - 00002046 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-07-18 12:39 - 2013-07-12 12:39 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan Files to move or delete: ==================== C:\Users\Gast\install_reader10_de_chra_aih.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 19:37 ==================== End Of Log ============================ Additions: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-08-2013 01 Ran by mkwzbg (administrator) on 15-08-2013 03:39:38 Running from C:\Users\mkwzbg\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (Microsoft) C:\ProgramData\Microsoft\Windows\Time\Time-svc.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\mfeann.exe (Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft) C:\ProgramData\Microsoft\Windows\Time\WindowsTime.exe () C:\ProgramData\Microsoft\Windows\Time\TimeServer.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\Common Framework\McTray.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe () C:\Users\mkwzbg\AppData\Local\Opera\Opera\temporary_downloads\Defogger.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-11-30] (Realtek Semiconductor) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1807272 2013-07-27] (Valve Corporation) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [McAfeeUpdaterUI] - C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe [161088 2011-01-12] (McAfee, Inc.) HKLM-x32\...\Run: [ShStatEXE] - C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE [215360 2011-01-12] (McAfee, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=DC6F00040ECDB007&affID=123976&tt=040813_10&tsp=4965 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={026C9A61-7CEB-4686-A0F8-2F3C1529C901}&mid=5b92e099f47b4cb793dd6b59a17ab577-ad1491be2ce6c122f6b66faa90e70c2decf7d34c&lang=en&ds=dw011&pr=sa&d=2012-07-05 21:42:30&v=11.1.0.12&sap=dsp&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=394&systemid=406&sr=0&q={searchTerms} BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111231154048.dll (McAfee, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111231154048.dll (McAfee, Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\mkwzbg\AppData\Roaming\Mozilla\Firefox\Profiles\3w1lq905.default FF user.js: detected! => C:\Users\mkwzbg\AppData\Roaming\Mozilla\Firefox\Profiles\3w1lq905.default\user.js FF Homepage: user_pref("browser.startup.homepage", ); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Users\mkwzbg\AppData\Roaming\Mozilla\Firefox\Profiles\3w1lq905.default\searchplugins\babylon.xml ==================== Services (Whitelisted) ================= R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 DAUpdaterSvc; C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2012-07-24] (BioWare) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 McAfeeFramework; C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [120128 2011-01-12] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [190256 2011-12-31] (McAfee, Inc.) R2 McTaskManager; C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe [209760 2011-01-12] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [156248 2011-12-31] (McAfee, Inc.) R2 Time; C:\ProgramData\Microsoft\Windows\Time\Time-svc.exe [10752 2013-08-05] (Microsoft) ==================== Drivers (Whitelisted) ==================== S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [153952 2011-12-31] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [217696 2011-12-31] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [607152 2011-12-31] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [97960 2011-12-31] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [281544 2011-12-31] (McAfee, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] U3 mfeavfk01; No ImagePath ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-15 03:38 - 2013-08-15 03:38 - 01575570 _____ (Farbar) C:\Users\mkwzbg\Desktop\FRST64.exe 2013-08-15 03:34 - 2013-08-15 03:34 - 00000000 _____ C:\Users\mkwzbg\defogger_reenable 2013-08-15 03:05 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 03:05 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 03:05 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 03:05 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 03:05 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 03:05 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 03:05 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 03:05 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 03:05 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 03:05 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 03:05 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 03:05 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 03:05 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 03:05 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 21:06 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 21:06 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 21:06 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 21:06 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 21:06 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 21:06 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 21:06 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 21:06 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 21:06 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 21:06 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 21:06 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 21:06 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 21:06 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 21:06 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 21:06 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 21:06 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 21:06 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 21:06 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 21:06 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 21:06 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 21:06 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 21:06 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 21:06 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 21:06 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 21:06 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 21:06 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 21:06 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 19:16 - 2013-08-14 19:16 - 00015858 _____ C:\ComboFix.txt 2013-08-14 19:07 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-14 19:07 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-14 19:07 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-14 19:07 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-14 19:06 - 2013-08-14 19:16 - 00000000 ____D C:\Qoobox 2013-08-14 19:06 - 2013-08-14 19:15 - 00000000 ____D C:\Windows\erdnt 2013-08-09 00:58 - 2013-08-09 00:58 - 00000000 ____D C:\ProgramData\Stardock 2013-08-05 15:29 - 2013-08-05 15:42 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\tor 2013-08-05 15:29 - 2013-08-05 15:30 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\Rydu 2013-08-05 14:21 - 2013-08-05 14:36 - 00000047 _____ C:\Users\mkwzbg\Documents\mt-x_hook.txt 2013-08-05 14:21 - 2013-08-05 14:36 - 00000007 _____ C:\Users\mkwzbg\Documents\mt-e_hook.txt 2013-08-05 12:27 - 2013-08-15 03:22 - 00009732 _____ C:\Windows\PFRO.log 2013-08-05 02:18 - 2013-08-05 02:18 - 00000000 ____D C:\ProgramData\Babylon 2013-08-04 18:49 - 2013-08-04 18:49 - 00064024 _____ C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-04 18:49 - 2013-08-04 18:49 - 00000000 ____D C:\Users\Gast\AppData\Roaming\NVIDIA 2013-08-03 14:35 - 2013-08-03 14:35 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\My Games 2013-08-03 14:10 - 2013-08-05 17:13 - 00000000 ____D C:\Program Files (x86)\Sid Meier's Civilization V 2013-07-29 12:24 - 2013-08-15 03:25 - 00003022 _____ C:\Windows\System32\Tasks\EVGAPrecision 2013-07-25 17:50 - 2013-07-25 17:50 - 00000205 _____ C:\Users\mkwzbg\Desktop\Batman Arkham City GOTY.url 2013-07-25 16:47 - 2013-07-25 16:47 - 00000222 _____ C:\Users\mkwzbg\Desktop\Alan Wake.url 2013-07-25 15:48 - 2013-08-15 03:00 - 00000000 ____D C:\Windows\system32\MRT 2013-07-22 13:29 - 2013-07-22 13:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\201280 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\Documents\WB Games 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\Downloaded Installations 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Program Files (x86)\AMD 2013-07-22 01:07 - 2013-08-09 00:57 - 00055533 _____ C:\Windows\DirectX.log ==================== One Month Modified Files and Folders ======= 2013-08-15 03:38 - 2013-08-15 03:38 - 01575570 _____ (Farbar) C:\Users\mkwzbg\Desktop\FRST64.exe 2013-08-15 03:34 - 2013-08-15 03:34 - 00000000 _____ C:\Users\mkwzbg\defogger_reenable 2013-08-15 03:34 - 2011-12-31 17:28 - 00000000 ____D C:\Program Files (x86)\Opera 2013-08-15 03:34 - 2011-12-31 10:36 - 00000000 ____D C:\Users\mkwzbg 2013-08-15 03:31 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-15 03:31 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-15 03:25 - 2013-07-29 12:24 - 00003022 _____ C:\Windows\System32\Tasks\EVGAPrecision 2013-08-15 03:25 - 2012-07-20 16:59 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-15 03:23 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-15 03:22 - 2013-08-05 12:27 - 00009732 _____ C:\Windows\PFRO.log 2013-08-15 03:22 - 2013-06-08 11:19 - 00008680 _____ C:\Windows\setupact.log 2013-08-15 03:22 - 2011-12-31 16:18 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-15 03:21 - 2011-12-31 10:29 - 01196488 _____ C:\Windows\WindowsUpdate.log 2013-08-15 03:03 - 2011-04-12 09:43 - 00696848 _____ C:\Windows\system32\perfh007.dat 2013-08-15 03:03 - 2011-04-12 09:43 - 00148144 _____ C:\Windows\system32\perfc007.dat 2013-08-15 03:03 - 2009-07-14 07:13 - 01634468 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-15 03:02 - 2013-07-25 15:48 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 03:00 - 2011-12-31 18:47 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 19:16 - 2013-08-14 19:16 - 00015858 _____ C:\ComboFix.txt 2013-08-14 19:16 - 2013-08-14 19:06 - 00000000 ____D C:\Qoobox 2013-08-14 19:16 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-08-14 19:15 - 2013-08-14 19:06 - 00000000 ____D C:\Windows\erdnt 2013-08-14 19:15 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-11 04:05 - 2011-12-31 17:30 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\vlc 2013-08-11 03:24 - 2012-01-30 01:40 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\QuickPar 2013-08-11 02:55 - 2012-03-27 19:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\GrabIt 2013-08-10 00:55 - 2013-03-06 21:28 - 00000000 ____D C:\Temporary 2013-08-10 00:55 - 2012-06-05 14:57 - 00000000 ____D C:\QUARANTINE 2013-08-09 02:51 - 2012-02-18 01:38 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\Media Player Classic 2013-08-09 00:58 - 2013-08-09 00:58 - 00000000 ____D C:\ProgramData\Stardock 2013-08-09 00:58 - 2012-02-01 10:50 - 00000000 ____D C:\Users\mkwzbg\Documents\My Games 2013-08-09 00:57 - 2013-07-22 01:07 - 00055533 _____ C:\Windows\DirectX.log 2013-08-05 17:13 - 2013-08-03 14:10 - 00000000 ____D C:\Program Files (x86)\Sid Meier's Civilization V 2013-08-05 15:42 - 2013-08-05 15:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\tor 2013-08-05 15:30 - 2013-08-05 15:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\Rydu 2013-08-05 14:36 - 2013-08-05 14:21 - 00000047 _____ C:\Users\mkwzbg\Documents\mt-x_hook.txt 2013-08-05 14:36 - 2013-08-05 14:21 - 00000007 _____ C:\Users\mkwzbg\Documents\mt-e_hook.txt 2013-08-05 02:18 - 2013-08-05 02:18 - 00000000 ____D C:\ProgramData\Babylon 2013-08-04 18:49 - 2013-08-04 18:49 - 00064024 _____ C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-04 18:49 - 2013-08-04 18:49 - 00000000 ____D C:\Users\Gast\AppData\Roaming\NVIDIA 2013-08-03 14:35 - 2013-08-03 14:35 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\My Games 2013-08-03 03:25 - 2012-07-05 21:50 - 00000000 ____D C:\Users\mkwzbg\.FBReader 2013-07-26 07:13 - 2013-08-15 03:05 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-15 03:05 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-15 03:05 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-15 03:05 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-15 03:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-15 03:05 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-15 03:05 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-15 03:05 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-15 03:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-15 03:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-15 03:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-15 03:05 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-15 03:05 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-15 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 17:50 - 2013-07-25 17:50 - 00000205 _____ C:\Users\mkwzbg\Desktop\Batman Arkham City GOTY.url 2013-07-25 16:47 - 2013-07-25 16:47 - 00000222 _____ C:\Users\mkwzbg\Desktop\Alan Wake.url 2013-07-25 11:25 - 2013-08-14 21:06 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 21:06 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 16:35 - 2012-05-21 22:04 - 00000000 ____D C:\Users\mkwzbg\AppData\Roaming\dvdcss 2013-07-24 15:37 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-22 13:29 - 2013-07-22 13:29 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\201280 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\Documents\WB Games 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Users\mkwzbg\AppData\Local\Downloaded Installations 2013-07-22 01:08 - 2013-07-22 01:08 - 00000000 ____D C:\Program Files (x86)\AMD 2013-07-22 01:05 - 2012-11-08 01:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-07-22 01:05 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-07-19 03:58 - 2013-08-14 21:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-07-19 03:41 - 2013-08-14 21:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-07-18 12:39 - 2013-07-12 12:39 - 00002046 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-07-18 12:39 - 2013-07-12 12:39 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan Files to move or delete: ==================== C:\Users\Gast\install_reader10_de_chra_aih.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 19:37 ==================== End Of Log ============================ GMER.txt Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-08-15 03:46:48 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD103SJ rev.1AJ10001 931,51GB Running: gmer_2.1.19163.exe; Driver: C:\Users\mkwzbg\AppData\Local\Temp\kwdiypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe[1572] C:\Windows\syswow64\PsApi.dll!GetModuleInformation + 69 0000000076721465 2 bytes [72, 76] .text C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe[1572] C:\Windows\syswow64\PsApi.dll!GetModuleInformation + 155 00000000767214bb 2 bytes [72, 76] .text ... * 2 .text C:\ProgramData\Microsoft\Windows\Time\Time-svc.exe[1752] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000076721465 2 bytes [72, 76] .text C:\ProgramData\Microsoft\Windows\Time\Time-svc.exe[1752] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000767214bb 2 bytes [72, 76] .text ... * 2 .text C:\ProgramData\Microsoft\Windows\Time\TimeServer.exe[3620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076721465 2 bytes [72, 76] .text C:\ProgramData\Microsoft\Windows\Time\TimeServer.exe[3620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767214bb 2 bytes [72, 76] .text ... * 2 .text C:\Program Files (x86)\Steam\Steam.exe[3804] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate 000000007542549c 5 bytes JMP 00000001000f0800 .text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5032] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate 000000007542549c 5 bytes JMP 0000000100090800 .text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5032] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076721465 2 bytes [72, 76] .text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5032] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767214bb 2 bytes [72, 76] .text ... * 2 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076721465 2 bytes [72, 76] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767214bb 2 bytes [72, 76] .text ... * 2 .text C:\Users\mkwzbg\AppData\Local\Opera\Opera\temporary_downloads\Defogger.exe[2568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076721465 2 bytes [72, 76] .text C:\Users\mkwzbg\AppData\Local\Opera\Opera\temporary_downloads\Defogger.exe[2568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767214bb 2 bytes [72, 76] .text ... * 2 ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Windows\system32\mfevtps.exe[1668] @ C:\Windows\system32\CRYPT32.dll[KERNEL32.dll!LoadLibraryA] [13f12c980] C:\Windows\system32\mfevtps.exe IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef90b741c] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef90b5f10] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef90b5674] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef90b5e2c] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef90b7f48] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef90b6a38] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef90b6ee8] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef90b7b58] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef90b7ea0] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef90b78b0] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef90b4fb4] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef90b5d38] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1116] @ c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef90b7584] c:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll ---- Threads - GMER 2.1 ---- Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2532:1240] 0000000076707587 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2532:2948] 00000000721e0cb3 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2532:556] 00000000779b2e65 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2532:3180] 00000000779b3e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2532:4804] 00000000779b3e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2532:3772] 00000000779b3e85 ---- EOF - GMER 2.1 ---- Vielen Dank für eure Bemühungen und einen frohen Feiertag an diejenigen in den katholischen Gebieten Deutschlands. ![]() lg Matthias |
Themen zu Windows 7 (64bit) - hyperaktive timeserver.exe - Malwarebytes kann Befall nicht dauerhaft entfernen |
.dll, adware.agent, coinminer, combofix, entfernen, explorer, farbar, farbar recovery scan tool, hacktool.gamescheat.gen, homepage, iexplore.exe, plug-in, pup.babylon.a, pup.bitcoinminer, pup.delta.a, pup.lyricsad, pup.optional.babylon.a, pup.optional.browserdefender.a, pup.optional.delta.a, pup.optional.optimizepro.a, pup.optional.somoto, pup.optional.startpage, pup.optional.sweetim, services.exe, speicherplatz, svchost.exe, taskmanager, trojan.bitcoinminer |