|
Plagegeister aller Art und deren Bekämpfung: GPU AUslastung 98%Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.08.2013, 14:06 | #1 |
| GPU AUslastung 98% HalloLeute. Meine Grafikkarte ( Sapphire Radeon 7970 ) wird seit einigen Tagen heiß. Bis letzte Woche hat mein PC ganz normal funktioniert, zocken etc. lief problemlos. Dann ist mir aufgefallen, dass der Rechner plötzlich sehr laut wurde, wie bisher noch gar nicht ( Lüfter ) und manche Spiele anfingen zu ruckeln. Ich habe Temperatur des CPU gecheckt, die ist normal. Dann habe ich mittels TechPowerUp die GPU Termperatur gecheckt und diese ist recht hoch. Im Leerlauf ist die Karte kurze Zeit nach dem Hochfahren bei 92° , bei Zocken ( Black Ops 2 ) bei 98° - 102°. Ich habe den Rechner aus einander gebaut , Graka gecheckt, Kühler gecheckt ( funktioniert alles ) , alles entstaubt - nun hab eich im Leerlauf eine Temperatur von 86°~88° und beim Zocken 90°~93° - die Spiele ruckeln dabei. Hat jemand eine Idee? Der Rechner ist 1 1/2 Jahre alt. Wenn ich nun die Internetverbindung kappe, geht die Auslastung samt Temperatur in den Keller ( bzw. Normalzustand ). Gestern habe ich Malwarebyte und Avira scannen lassen. Maleware hatte einen Befund, diesen lies ich löschen, allerdings stellt sich die Problematik nach dem Neustart wieder ein. Hat jemand ne Idee? |
21.08.2013, 14:10 | #2 | |
/// TB-Ausbilder | GPU AUslastung 98% Hallo,
__________________Zitat:
Und zusätzlich: Wenn du deinen Rechner nach Malware untersuchen lassen willst, dann arbeite bitte diese Anleitung ab und poste die resultierenden Logfiles hier.
__________________ |
21.08.2013, 14:53 | #3 |
| GPU AUslastung 98% Einen Interessanten Fund habe ich über TM gemacht.
__________________Prozess poclbm.exe läuft... und befindet sich in C:\Users\Privat\AppData\Roaming\Adobe - könnte es was damit zu tun haben? Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.17.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 Privat :: PRIVAT1 [Administrator] 20.08.2013 23:54:18 mbam-log-2013-08-20 (23-54-18).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|I:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 526118 Laufzeit: 1 Stunde(n), 26 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Privat\Downloads\SoftonicDownloader_fuer_nvidia-gpu-temp.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. Habe nochmal Adware drüber laufen lassen hier log: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.000 - Report created 21/08/2013 at 15:31:59 # Updated 20/08/2013 by Xplode # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits) # Username : Privat - PRIVAT1 # Running from : C:\Users\Privat\Downloads\adwcleaner_3.0.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\Winamp Toolbar Folder Deleted : C:\Program Files (x86)\Ask.com Folder Deleted : C:\Program Files (x86)\Mail.Ru Folder Deleted : C:\Program Files (x86)\Winamp Toolbar Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility Folder Deleted : C:\Users\Privat\AppData\Local\APN Folder Deleted : C:\Users\Privat\AppData\Local\AskToolbar Folder Deleted : C:\Users\Privat\AppData\Local\Mail.Ru Folder Deleted : C:\Users\Privat\AppData\Local\Smartbar Folder Deleted : C:\Users\Privat\AppData\Local\Winamp Toolbar Folder Deleted : C:\Users\Privat\AppData\Local\Temp\Smartbar Folder Deleted : C:\Users\Privat\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\Privat\AppData\Roaming\OpenCandy Folder Deleted : C:\Users\Elja\AppData\Local\AskToolbar Folder Deleted : C:\Users\Elja\AppData\Local\Winamp Toolbar Folder Deleted : C:\Users\Elja\AppData\LocalLow\AskToolbar Folder Deleted : C:\Users\test\AppData\Local\AskToolbar Folder Deleted : C:\Users\test\AppData\Local\Winamp Toolbar Folder Deleted : C:\Users\test\AppData\LocalLow\AskToolbar File Deleted : C:\Users\Privat\AppData\Roaming\Mozilla\Firefox\Profiles\r8io4ibi.default-1357988702778\searchplugins\Web Search.xml File Deleted : C:\Users\Privat\AppData\Roaming\Mozilla\Firefox\Profiles\r8io4ibi.default-1357988702778\.autoreg File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt File Deleted : C:\Users\Privat\AppData\Roaming\Mozilla\Firefox\Profiles\r8io4ibi.default-1357988702778\user.js File Deleted : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1 Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1 Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BHO Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool Key Deleted : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1 Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper.1 Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper] Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Key Deleted : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4D71-963D-FB7A94FDD678} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{05366194-3126-4601-AC1A-DDE573E093DC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{061F450C-37B9-4330-9235-0F25D9F75B33} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{26249267-15F4-4DA3-8247-C5A78E4FA918} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{39B217B4-8C69-4E45-A8DC-8CC4DAD3CF0A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CB4CE45-8849-4638-9226-D6B615A15827} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{43AB7B5D-4C40-4103-A549-7002A116A7D5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45A2-B558-1755C3F6253B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{996ED20F-A740-47A2-A7EF-9620D422BB4E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F20F11FD-203E-45A9-B7BB-AFC1B4FEA7A6} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{061F450C-37B9-4330-9235-0F25D9F75B33} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{22FEB0F5-0BA0-4D4B-8A66-55A21667BC31} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2B79F7D-2D7D-4420-B2A9-ECE52C7C83A0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D55DAA5-04AC-4036-B0BE-DA81EE9676CD} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{58CBF821-A0C7-4AE8-9430-77DD1AF38E99} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{72BCBFF7-2837-4CA0-B3B5-3DAED7F54601} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{824125FD-7732-4DA2-9277-3A7D0A0A0813} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A8C2644D-BF72-4A89-A88C-D85F565F2F46} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C17DC5CF-54FF-4E63-8AC7-94335D6DA231} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D14D0EE2-2DD1-4230-BE70-3F3AD6172C40} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\Ask.com Key Deleted : HKCU\Software\AskToolbar Key Deleted : HKCU\Software\SmartBar Key Deleted : HKCU\Software\SmartbarBackup Key Deleted : HKCU\Software\SmartbarLog Key Deleted : HKCU\Software\Winamp Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar Key Deleted : HKLM\Software\APN Key Deleted : HKLM\Software\AskToolbar Key Deleted : HKLM\Software\FirstSearch\Winamp Toolbar Key Deleted : HKLM\Software\Winamp Toolbar Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v20.0.1 (de) [ File : C:\Users\Privat\AppData\Roaming\Mozilla\Firefox\Profiles\r8io4ibi.default-1357988702778\prefs.js ] [ File : C:\Users\test\AppData\Roaming\Mozilla\Firefox\Profiles\7md9n3vp.default-1363478880915\prefs.js ] -\\ Google Chrome v28.0.1500.95 [ File : C:\Users\Privat\AppData\Local\Google\Chrome\User Data\Default\preferences ] [ File : C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [15342 octets] - [21/08/2013 15:30:58] AdwCleaner[S0].txt - [15202 octets] - [21/08/2013 15:31:59] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15263 octets] ########## Was ich schon mal auf jeden Fall sagen kann ist, dass wenn ich den Prozess poclbm.exe im Taskmanager ausschalte die Auslastung sinkt. Weiß jemand wie man den Prozess isolieren löschen kann? Geändert von Nau_001 (21.08.2013 um 14:29 Uhr) |
21.08.2013, 15:02 | #4 |
/// TB-Ausbilder | GPU AUslastung 98% Die von dir erwähnte Datei ist wohl ein GPU Bitcoin-Miner.. Passt also.. Mach bitte noch den FRST-Scan, sonst kann ich weiter nichts sagen.. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ cheers, Leo |
21.08.2013, 15:17 | #5 | |
| GPU AUslastung 98% FRST FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-08-2013 Ran by Privat (administrator) on 21-08-2013 16:14:06 Running from C:\Users\Privat\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (The Within Network, LLC) C:\Windows\UnsignedThemesSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel Corporation) C:\Windows\system32\IProsetMonitor.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Speedbit Ltd.) C:\Program Files\Common Files\SpeedBit\SBUpdate\sbu.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (SPEEDbit) C:\PROGRA~2\SPEEDB~1\VideoAcceleratorService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Saitek) C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek) C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (SPEEDbit) C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAccelerator.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Windows\DAODx.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11842152 2011-05-03] (Realtek Semiconductor) HKLM\...\Run: [ProfilerU] - C:\Program Files\Saitek\SD6\Software\ProfilerU.exe [378880 2010-04-21] (Saitek) HKLM\...\Run: [SaiMfd] - C:\Program Files\Saitek\SD6\Software\SaiMfd.exe [195072 2010-04-21] (Saitek) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-10-10] (Google Inc.) HKCU\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3341464 2012-09-18] (Electronic Arts) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [SpeedBitVideoAccelerator] - C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAccelerator.exe [1515688 2013-04-14] (SPEEDbit) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-18] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) IMEO\bf3.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IMEO\origin.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IMEO\originuninstall.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635018037012847848.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635023103368191935.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635031622392503034.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635033098100302534.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635035276698507957.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635039828872774105.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635040448059621494.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635041740410240704.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635043761706785383.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635045595653104664.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635047401226817185.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635048640160512425.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635050838023087637.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635052350977221369.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635054461459547224.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635055835764902638.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635058640204406661.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635059312903929024.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635061245112877593.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635064730967399591.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635066514444034807.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635067940740572283.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635069381410259296.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635073228079848422.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635076633142010535.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635080276007759162.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635081898264278805.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635083810182268126.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635085216597034209.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635087137296052346.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635089136099524239.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635092283739359291.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635104426715294720.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635106209267944212.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635107392760638784.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635109120800555532.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635113989991357900.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635116480592288445.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635118148276728403.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635119737759461466.exe () Startup: C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\635121941046683163.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=da08d77b-c6cb-2e61-cb40-217b107f1ded&searchtype=ds&q={searchTerms}&installDate=21/08/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=da08d77b-c6cb-2e61-cb40-217b107f1ded&searchtype=hp&installDate=21/08/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=da08d77b-c6cb-2e61-cb40-217b107f1ded&searchtype=ds&q={searchTerms}&installDate=21/08/2013 URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKCU - {9EB8C847-273B-4638-A9D9-83BC51AAC02E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=3ae549f4-f896-4512-9f40-0a15c491e014&apn_sauid=54CBDE5C-ABEF-42D8-AB23-24F28C8D6E74 SearchScopes: HKCU - {CFCC03EB-DB3A-4ED7-9BEA-DD07EDEA0A10} URL = hxxp://suche.aol.de/aol/search?s_it=tb50winamp&q={searchTerms} SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/search?utf8in=1&fr=ietb&q={SearchTerms} BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Privat\AppData\Roaming\Mozilla\Firefox\Profiles\r8io4ibi.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.138.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR DefaultSearchURL: (Web) - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=da08d77b-c6cb-2e61-cb40-217b107f1ded&searchtype=ds&q={searchTerms}&installDate={installDate} CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll (ESN Social Software AB) CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll () CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (Docs) - C:\Users\Privat\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\Privat\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\Privat\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\Privat\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Gmail) - C:\Users\Privat\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Users\Privat\AppData\Local\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.5.0.crx ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-18] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-10-14] () R2 SBUpd; C:\Program Files\Common Files\SpeedBit\SBUpdate\sbu.exe [1097848 2013-02-27] (Speedbit Ltd.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2401632 2012-11-29] (TuneUp Software) R2 UnsignedThemes; C:\Windows\UnsignedThemesSvc.exe [24168 2009-07-13] (The Within Network, LLC) R2 VideoAcceleratorService; C:\PROGRA~2\SPEEDB~1\VideoAcceleratorService.exe [281768 2013-04-14] (SPEEDbit) S2 Guard.Mail.ru; "C:\Program Files (x86)\Mail.Ru\Guard\GuardMailRu.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.01; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) S2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [36448 2011-03-23] (Asmedia Technology) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-07-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-06] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-21] (DT Soft Ltd) R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [18816 2008-01-17] (Razer USA Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SaiK0CC3; C:\Windows\System32\DRIVERS\SaiK0CC3.sys [171016 2010-04-22] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [22664 2010-04-22] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [49928 2010-04-22] (Saitek) R3 SaiU0CC3; C:\Windows\System32\DRIVERS\SaiU0CC3.sys [41096 2010-04-22] (Saitek) R3 SBUpdd; C:\Program Files\Common Files\SpeedBit\SBUpdate\sbw.sys [40856 2013-02-27] () R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-09-19] (TuneUp Software) R2 uxpatch; C:\Windows\system32\drivers\uxpatch.sys [30568 2009-07-13] () S3 ALSysIO; \??\C:\Users\Privat\AppData\Local\Temp\ALSysIO64.sys [x] U3 JavaQuickStarterService; S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-21 16:13 - 2013-08-21 16:13 - 00000000 ____D C:\FRST 2013-08-21 16:12 - 2013-08-21 16:11 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-21 15:30 - 2013-08-21 16:02 - 00000000 ____D C:\AdwCleaner 2013-08-21 15:26 - 2013-08-21 15:26 - 00975858 _____ C:\Users\Privat\Downloads\adwcleaner_3.0.exe 2013-08-21 15:25 - 2013-08-21 15:25 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Privat\Downloads\tdsskiller.exe 2013-08-21 15:04 - 2013-08-21 15:04 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-21 15:04 - 2013-08-21 15:04 - 00001974 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2013-08-21 15:02 - 2013-08-21 15:07 - 00000000 ____D C:\Users\Privat\AppData\Roaming\DAEMON Tools Lite 2013-08-21 15:02 - 2013-08-21 15:02 - 00283200 _____ (DT Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2013-08-21 15:02 - 2013-08-21 15:02 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite 2013-08-21 15:01 - 2013-08-21 15:07 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite 2013-08-21 15:00 - 2013-08-21 15:00 - 13901152 _____ (Disc Soft Ltd) C:\Users\Privat\Downloads\DTLite4471-0333.exe 2013-08-21 14:56 - 2013-08-21 14:59 - 337504256 _____ C:\Users\Privat\Downloads\kav_rescue_10 (1).iso 2013-08-21 14:54 - 2013-08-21 14:56 - 337504256 _____ C:\Users\Privat\Downloads\kav_rescue_10.iso 2013-08-21 06:05 - 2013-08-21 06:05 - 00034526 _____ C:\Users\Privat\Desktop\AVSCAN-20130820-231244-32B7E679.LOG 2013-08-20 22:06 - 2013-07-18 08:02 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-20 21:55 - 2013-08-20 21:56 - 110344048 _____ C:\Users\Privat\Downloads\avira_free_antivirus85_de.exe 2013-08-20 21:26 - 2013-08-20 21:26 - 00001110 _____ C:\Users\Privat\Desktop\MSI Afterburner.lnk 2013-08-20 21:26 - 2013-08-20 21:26 - 00000000 ___HD C:\Windows\msdownld.tmp 2013-08-20 21:26 - 2013-08-20 21:26 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-08-20 21:26 - 2013-08-20 21:26 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2013-08-20 21:25 - 2013-08-20 21:26 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-08-20 21:24 - 2013-08-20 21:24 - 22990573 _____ C:\Users\Privat\Downloads\MSIAfterburnerSetup231.zip 2013-08-20 21:03 - 2013-08-20 21:03 - 00114412 _____ C:\Users\Privat\Desktop\cpuz-2013.txt 2013-08-20 21:03 - 2013-08-20 21:03 - 00003912 _____ C:\Users\Privat\Desktop\cpuz.cvf 2013-08-20 20:56 - 2013-08-20 20:56 - 00114412 _____ C:\Users\Privat\Desktop\PRIVAT1.txt 2013-08-20 20:55 - 2013-08-20 20:55 - 01458776 _____ ( ) C:\Users\Privat\Downloads\cpu-z_1.66-setup-en.exe 2013-08-20 20:55 - 2013-08-20 20:55 - 00000889 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-08-20 20:55 - 2013-08-20 20:55 - 00000000 ____D C:\Program Files\CPUID 2013-08-19 11:11 - 2013-08-19 11:11 - 00003104 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-18 16:26 - 2013-08-18 17:07 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z 2013-08-18 16:26 - 2013-08-18 16:26 - 00001889 _____ C:\Users\Privat\Desktop\TechPowerUp GPU-Z.lnk 2013-08-18 16:26 - 2013-08-18 16:26 - 00000000 ____D C:\Program Files (x86)\GPU-Z 2013-08-18 16:25 - 2013-08-18 16:25 - 01344480 _____ (techPowerUp (www.techpowerup.com)) C:\Users\Privat\Downloads\gpu-z.0.7.2.exe 2013-08-18 16:23 - 2013-08-18 16:23 - 00338140 _____ C:\Users\Privat\Downloads\CoreTemp32_rc5.zip 2013-08-18 16:23 - 2013-08-18 16:23 - 00338140 _____ C:\Users\Privat\Downloads\CoreTemp32_rc5 (1).zip 2013-08-15 21:14 - 2013-08-15 21:14 - 00000552 _____ C:\Windows\system32\Drivers\635121941046683163.exe 2013-08-15 21:12 - 2013-08-15 21:12 - 00000552 _____ C:\Windows\system32\config\635121941046683163.exe 2013-08-15 21:01 - 2013-08-15 21:02 - 00000552 _____ C:\Program Files\Common Files\635121941046683163.exe 2013-08-14 22:28 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 22:28 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 22:28 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 22:28 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 22:28 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 22:28 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 22:28 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 22:28 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 22:28 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 22:28 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 22:28 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 22:28 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 22:28 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 22:28 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 22:23 - 2013-08-14 22:25 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 19:50 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 19:50 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 19:50 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 19:50 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 19:50 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 19:50 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 19:50 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 19:50 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 19:50 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 19:50 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 19:50 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 19:50 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 19:49 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 19:49 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 19:49 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 19:49 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 19:49 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 19:49 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 19:49 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 19:49 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 19:49 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 19:49 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 19:49 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 19:49 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 19:49 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 19:49 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 19:49 - 2013-06-15 06:35 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-08-14 19:49 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 19:44 - 2013-08-14 19:48 - 599912448 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e08.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-08-13 07:05 - 2013-08-13 07:05 - 00000552 _____ C:\Windows\System32\Tasks\635119737759461466.exe 2013-08-13 07:02 - 2013-08-13 07:02 - 00000552 _____ C:\Windows\system32\Drivers\635119737759461466.exe 2013-08-13 07:02 - 2013-08-13 07:02 - 00000552 _____ C:\Windows\system32\config\635119737759461466.exe 2013-08-13 07:01 - 2013-08-13 07:01 - 00000552 _____ C:\Program Files\Common Files\635119737759461466.exe 2013-08-11 11:04 - 2013-08-11 11:04 - 00000552 _____ C:\Windows\System32\Tasks\635118148276728403.exe 2013-08-11 11:01 - 2013-08-11 11:01 - 00000552 _____ C:\Windows\system32\Drivers\635118148276728403.exe 2013-08-11 11:01 - 2013-08-11 11:01 - 00000552 _____ C:\Windows\system32\config\635118148276728403.exe 2013-08-11 11:00 - 2013-08-11 11:00 - 00000552 _____ C:\Program Files\Common Files\635118148276728403.exe 2013-08-09 19:27 - 2013-08-09 19:38 - 1473724416 ____R C:\Users\Privat\Downloads\Kolonija.2013.P.DVDRip.1400MB.avi 2013-08-09 19:26 - 2013-08-09 19:27 - 106629120 ____R C:\Users\Privat\Downloads\Серия 34. Фотография 9х12.avi 2013-08-09 13:32 - 2013-08-09 13:33 - 00000552 _____ C:\Program Files\Common Files\635116480592288445.exe 2013-08-07 19:50 - 2013-08-07 19:57 - 536546836 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e07.WEB-DLRip.avi 2013-08-06 17:30 - 2013-08-06 17:30 - 00000000 ____D C:\Users\Privat\Desktop\Ostsee 2013-08-06 15:52 - 2013-08-06 15:52 - 00002232 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Windows\System32\Tasks\635113989991357900.exe 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Windows\system32\Drivers\635113989991357900.exe 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Windows\system32\config\635113989991357900.exe 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Program Files\Common Files\635113989991357900.exe 2013-08-01 00:50 - 2013-08-01 00:50 - 00000000 ____D C:\Users\Privat\Desktop\Ukraine 2013-08-01 00:37 - 2013-08-01 00:37 - 00002259 _____ C:\Windows\System32\Tasks\635109120800555532.exe 2013-08-01 00:36 - 2013-08-01 00:36 - 00002259 _____ C:\Windows\system32\Drivers\635109120800555532.exe 2013-08-01 00:36 - 2013-08-01 00:36 - 00002259 _____ C:\Windows\system32\config\635109120800555532.exe 2013-08-01 00:36 - 2013-08-01 00:36 - 00002259 _____ C:\Program Files\Common Files\635109120800555532.exe 2013-07-31 22:07 - 2013-07-31 22:13 - 589694976 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e06.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 21:59 - 2013-07-31 22:10 - 599040000 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e05.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 21:58 - 2013-07-31 22:11 - 601718784 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e02.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 21:58 - 2013-07-31 22:07 - 601378816 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e04.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 21:58 - 2013-07-31 22:07 - 601073664 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e03.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 21:57 - 2013-07-31 22:10 - 611250176 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e01.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-30 18:43 - 2013-07-30 18:52 - 1567921049 ____R C:\Users\Privat\Downloads\Zloveshwie.Mertvecy.Chernaja.Kniga.2013.D.BDRip.x264.potroks..mkv 2013-07-30 00:25 - 2013-07-30 00:25 - 00000552 _____ C:\Windows\System32\Tasks\635107392760638784.exe 2013-07-30 00:24 - 2013-07-30 00:24 - 00000552 _____ C:\Windows\system32\Drivers\635107392760638784.exe 2013-07-30 00:24 - 2013-07-30 00:24 - 00000552 _____ C:\Windows\system32\config\635107392760638784.exe 2013-07-30 00:23 - 2013-07-30 00:23 - 00000552 _____ C:\Program Files\Common Files\635107392760638784.exe 2013-07-29 11:06 - 2013-07-29 11:15 - 1450774528 ____R C:\Users\Privat\Downloads\High.School.2010.D.HDRip.avi 2013-07-29 11:05 - 2013-07-29 11:18 - 1467840512 ____R C:\Users\Privat\Downloads\Yliki.2013.D.WEBDLRip.1400Mb.avi 2013-07-28 15:13 - 2013-07-28 15:13 - 00000552 _____ C:\Windows\System32\Tasks\635106209267944212.exe 2013-07-28 15:12 - 2013-07-28 15:12 - 00000552 _____ C:\Windows\system32\Drivers\635106209267944212.exe 2013-07-28 15:12 - 2013-07-28 15:12 - 00000552 _____ C:\Windows\system32\config\635106209267944212.exe 2013-07-28 15:12 - 2013-07-28 15:12 - 00000552 _____ C:\Program Files\Common Files\635106209267944212.exe 2013-07-26 14:40 - 2013-07-26 15:04 - 3369449577 ____R C:\Users\Privat\Downloads\Hummingbird.2013.D.720p.WEB-DL.mkv 2013-07-26 13:57 - 2013-07-26 14:12 - 2867646985 ____R C:\Users\Privat\Downloads\Sudnaja.Noch.2013.D.WEBDL.720p.INTERCINEMA.mkv 2013-07-26 13:56 - 2013-07-26 13:56 - 00000552 _____ C:\Windows\System32\Tasks\635104426715294720.exe 2013-07-26 13:55 - 2013-07-26 13:55 - 00000552 _____ C:\Windows\system32\Drivers\635104426715294720.exe 2013-07-26 13:55 - 2013-07-26 13:55 - 00000552 _____ C:\Windows\system32\config\635104426715294720.exe 2013-07-26 13:55 - 2013-07-26 13:55 - 00000552 _____ C:\Program Files\Common Files\635104426715294720.exe ==================== One Month Modified Files and Folders ======= 2013-08-21 16:13 - 2013-08-21 16:13 - 01576164 _____ (Farbar) C:\Users\Privat\Downloads\FRST64.exe 2013-08-21 16:13 - 2013-08-21 16:13 - 00000000 ____D C:\FRST 2013-08-21 16:11 - 2013-08-21 16:12 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-21 16:02 - 2013-08-21 15:30 - 00000000 ____D C:\AdwCleaner 2013-08-21 15:51 - 2012-10-10 16:42 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-21 15:44 - 2009-07-14 06:45 - 00013728 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-21 15:44 - 2009-07-14 06:45 - 00013728 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-21 15:41 - 2013-04-29 23:15 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-21 15:36 - 2012-11-30 08:46 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-21 15:36 - 2012-10-12 12:52 - 00000000 ____D C:\Users\Privat\AppData\Local\Adobe 2013-08-21 15:35 - 2012-10-10 16:42 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-21 15:34 - 2012-12-05 18:08 - 00250832 _____ C:\Windows\PFRO.log 2013-08-21 15:34 - 2012-12-03 21:19 - 00043968 _____ C:\Windows\setupact.log 2013-08-21 15:34 - 2012-10-02 22:16 - 01061421 _____ C:\Windows\WindowsUpdate.log 2013-08-21 15:34 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-21 15:26 - 2013-08-21 15:26 - 00975858 _____ C:\Users\Privat\Downloads\adwcleaner_3.0.exe 2013-08-21 15:25 - 2013-08-21 15:25 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Privat\Downloads\tdsskiller.exe 2013-08-21 15:15 - 2012-10-10 17:59 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Winamp 2013-08-21 15:10 - 2009-07-14 19:58 - 00656044 _____ C:\Windows\system32\perfh007.dat 2013-08-21 15:10 - 2009-07-14 19:58 - 00130676 _____ C:\Windows\system32\perfc007.dat 2013-08-21 15:10 - 2009-07-14 07:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 15:07 - 2013-08-21 15:02 - 00000000 ____D C:\Users\Privat\AppData\Roaming\DAEMON Tools Lite 2013-08-21 15:07 - 2013-08-21 15:01 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite 2013-08-21 15:04 - 2013-08-21 15:04 - 00003160 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-21 15:04 - 2013-08-21 15:04 - 00001974 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2013-08-21 15:02 - 2013-08-21 15:02 - 00283200 _____ (DT Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2013-08-21 15:02 - 2013-08-21 15:02 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite 2013-08-21 15:00 - 2013-08-21 15:00 - 13901152 _____ (Disc Soft Ltd) C:\Users\Privat\Downloads\DTLite4471-0333.exe 2013-08-21 14:59 - 2013-08-21 14:56 - 337504256 _____ C:\Users\Privat\Downloads\kav_rescue_10 (1).iso 2013-08-21 14:56 - 2013-08-21 14:54 - 337504256 _____ C:\Users\Privat\Downloads\kav_rescue_10.iso 2013-08-21 06:05 - 2013-08-21 06:05 - 00034526 _____ C:\Users\Privat\Desktop\AVSCAN-20130820-231244-32B7E679.LOG 2013-08-21 06:05 - 2012-10-10 17:26 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Adobe 2013-08-20 22:06 - 2012-10-10 18:04 - 00002090 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-08-20 22:06 - 2012-10-10 18:04 - 00000000 ____D C:\ProgramData\Avira 2013-08-20 21:56 - 2013-08-20 21:55 - 110344048 _____ C:\Users\Privat\Downloads\avira_free_antivirus85_de.exe 2013-08-20 21:26 - 2013-08-20 21:26 - 00001110 _____ C:\Users\Privat\Desktop\MSI Afterburner.lnk 2013-08-20 21:26 - 2013-08-20 21:26 - 00000000 ___HD C:\Windows\msdownld.tmp 2013-08-20 21:26 - 2013-08-20 21:26 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-08-20 21:26 - 2013-08-20 21:26 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2013-08-20 21:26 - 2013-08-20 21:25 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-08-20 21:24 - 2013-08-20 21:24 - 22990573 _____ C:\Users\Privat\Downloads\MSIAfterburnerSetup231.zip 2013-08-20 21:03 - 2013-08-20 21:03 - 00114412 _____ C:\Users\Privat\Desktop\cpuz-2013.txt 2013-08-20 21:03 - 2013-08-20 21:03 - 00003912 _____ C:\Users\Privat\Desktop\cpuz.cvf 2013-08-20 20:56 - 2013-08-20 20:56 - 00114412 _____ C:\Users\Privat\Desktop\PRIVAT1.txt 2013-08-20 20:55 - 2013-08-20 20:55 - 01458776 _____ ( ) C:\Users\Privat\Downloads\cpu-z_1.66-setup-en.exe 2013-08-20 20:55 - 2013-08-20 20:55 - 00000889 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-08-20 20:55 - 2013-08-20 20:55 - 00000000 ____D C:\Program Files\CPUID 2013-08-20 15:12 - 2012-12-03 22:22 - 01142808 _____ C:\Users\Privat\Desktop\Orochi-CEG(1).zip 2013-08-19 11:11 - 2013-08-19 11:11 - 00003104 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-18 17:07 - 2013-08-18 16:26 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z 2013-08-18 16:45 - 2012-10-10 17:58 - 00000000 ____D C:\Users\Privat\AppData\Roaming\vlc 2013-08-18 16:26 - 2013-08-18 16:26 - 00001889 _____ C:\Users\Privat\Desktop\TechPowerUp GPU-Z.lnk 2013-08-18 16:26 - 2013-08-18 16:26 - 00000000 ____D C:\Program Files (x86)\GPU-Z 2013-08-18 16:25 - 2013-08-18 16:25 - 01344480 _____ (techPowerUp (www.techpowerup.com)) C:\Users\Privat\Downloads\gpu-z.0.7.2.exe 2013-08-18 16:23 - 2013-08-18 16:23 - 00338140 _____ C:\Users\Privat\Downloads\CoreTemp32_rc5.zip 2013-08-18 16:23 - 2013-08-18 16:23 - 00338140 _____ C:\Users\Privat\Downloads\CoreTemp32_rc5 (1).zip 2013-08-17 12:29 - 2012-10-02 22:26 - 00000000 ___RD C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-08-17 12:14 - 2013-03-25 18:15 - 00000000 ____D C:\Users\Privat\Documents\SimCity 4 2013-08-17 12:13 - 2013-04-05 23:39 - 00000000 ____D C:\Users\Privat\Documents\Rockstar Games 2013-08-17 12:13 - 2013-01-17 18:49 - 00000000 ____D C:\Users\Privat\Documents\kostjume 2013-08-17 12:13 - 2012-12-25 23:47 - 00000000 ____D C:\Users\Privat\Documents\RCT3 2013-08-17 12:12 - 2012-10-12 12:20 - 00000000 ____D C:\Users\Privat\Documents\FUSSBALL MANAGER 12 2013-08-17 12:12 - 2012-10-10 20:14 - 00000000 ____D C:\Users\Privat\Documents\Electronic Arts 2013-08-17 12:11 - 2013-05-02 21:00 - 00000000 ____D C:\Users\Privat\Documents\Eigene Scans 2013-08-17 12:10 - 2012-11-05 20:52 - 00000000 ____D C:\Users\Privat\Documents\Criterion Games 2013-08-17 12:10 - 2012-10-11 11:44 - 00000000 ____D C:\Users\Privat\Documents\Battlefield 3 2013-08-17 12:09 - 2013-05-19 20:17 - 00000000 ____D C:\Users\Privat\Documents\4A Games 2013-08-17 12:09 - 2012-11-26 18:11 - 00000000 ____D C:\Users\Privat\Documents\Adobe 2013-08-17 12:09 - 2012-11-05 13:18 - 00000000 ____D C:\Users\Privat\Documents\ANNO 1404 Venedig 2013-08-17 12:03 - 2013-01-11 14:16 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Xeug 2013-08-17 12:03 - 2012-11-25 19:43 - 00000000 ____D C:\Users\Privat\AppData\Roaming\WinRAR 2013-08-17 12:02 - 2012-10-14 10:15 - 00000000 ____D C:\Users\Privat\AppData\Roaming\uTorrent 2013-08-17 12:01 - 2012-11-26 17:55 - 00000000 ____D C:\Users\Privat\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 2013-08-17 12:01 - 2012-10-11 14:52 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Ubisoft 2013-08-17 12:01 - 2012-10-10 17:59 - 00000000 ____D C:\Users\Privat\AppData\Roaming\TuneUp Software 2013-08-17 12:00 - 2012-11-26 18:11 - 00000000 ____D C:\Users\Privat\AppData\Roaming\PACE Anti-Piracy 2013-08-17 12:00 - 2012-10-10 20:51 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Origin 2013-08-17 12:00 - 2012-10-10 20:15 - 00000000 __RHD C:\Users\Privat\AppData\Roaming\SecuROM 2013-08-17 11:59 - 2012-10-10 17:28 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Mozilla 2013-08-17 11:58 - 2013-05-18 15:06 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Metro Last Light 2013-08-17 11:57 - 2012-11-08 12:43 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Malwarebytes 2013-08-17 11:57 - 2012-10-10 17:36 - 00000000 ____D C:\Users\Privat\AppData\Roaming\InstallShield 2013-08-17 11:57 - 2012-10-10 17:26 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Macromedia 2013-08-17 11:56 - 2013-04-06 14:41 - 00000000 ____D C:\Users\Privat\AppData\Roaming\HP 2013-08-17 11:56 - 2012-10-10 17:18 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Google 2013-08-17 11:55 - 2013-02-07 22:36 - 00000000 ____D C:\Users\Privat\AppData\Roaming\dvdcss 2013-08-17 11:55 - 2013-02-07 22:25 - 00000000 ____D C:\Users\Privat\AppData\Roaming\FreePDF 2013-08-17 11:55 - 2013-01-11 14:16 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Cufi 2013-08-17 11:54 - 2012-11-25 19:37 - 00000000 ____D C:\Users\Privat\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2013-08-17 11:54 - 2012-10-10 18:09 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Avira 2013-08-17 11:54 - 2012-10-10 16:56 - 00000000 ____D C:\Users\Privat\AppData\Roaming\ATI 2013-08-17 11:53 - 2012-12-25 23:47 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Atari 2013-08-17 11:53 - 2012-11-13 18:23 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Apple Computer 2013-08-17 11:52 - 2013-01-11 14:16 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Amsiix 2013-08-16 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-15 21:14 - 2013-08-15 21:14 - 00000552 _____ C:\Windows\system32\Drivers\635121941046683163.exe 2013-08-15 21:14 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Dism 2013-08-15 21:13 - 2009-07-14 19:58 - 00000000 ____D C:\Windows\system32\de 2013-08-15 21:12 - 2013-08-15 21:12 - 00000552 _____ C:\Windows\system32\config\635121941046683163.exe 2013-08-15 21:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\com 2013-08-15 21:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\bg-BG 2013-08-15 21:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-08-15 21:09 - 2012-11-25 19:15 - 00000000 ____D C:\Windows\system32\appmgmt 2013-08-15 21:09 - 2012-10-02 22:22 - 00000000 ____D C:\Program Files\Windows XP Mode 2013-08-15 21:09 - 2009-07-14 19:58 - 00000000 ____D C:\Windows\system32\0407 2013-08-15 21:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-08-15 21:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Portable Devices 2013-08-15 21:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2013-08-15 21:07 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2013-08-15 21:06 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal 2013-08-15 21:06 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-08-15 21:05 - 2012-10-10 17:44 - 00000000 ____D C:\Program Files\Saitek 2013-08-15 21:05 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Reference Assemblies 2013-08-15 21:04 - 2013-03-13 07:46 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-08-15 21:04 - 2012-10-10 16:45 - 00000000 ____D C:\Program Files\Realtek 2013-08-15 21:04 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\MSBuild 2013-08-15 21:03 - 2012-10-02 22:24 - 00000000 ____D C:\Program Files\Java 2013-08-15 21:03 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games 2013-08-15 21:02 - 2013-08-15 21:01 - 00000552 _____ C:\Program Files\Common Files\635121941046683163.exe 2013-08-15 21:02 - 2012-10-10 17:17 - 00000000 ____D C:\Program Files\Intel 2013-08-15 21:02 - 2012-10-10 16:42 - 00000000 ____D C:\Program Files\Google 2013-08-15 21:01 - 2012-11-25 19:29 - 00000000 ____D C:\Program Files\CCleaner 2013-08-15 21:01 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker 2013-08-15 21:00 - 2012-10-11 08:52 - 00000000 ____D C:\Program Files\AMD 2013-08-15 21:00 - 2012-10-10 16:52 - 00000000 ____D C:\Program Files\ATI Technologies 2013-08-15 21:00 - 2012-10-10 16:44 - 00000000 ____D C:\Program Files\ATI 2013-08-15 20:59 - 2012-11-26 15:12 - 00000000 ____D C:\Program Files\Adobe 2013-08-15 20:59 - 2012-11-25 19:43 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-08-15 20:58 - 2012-11-30 08:49 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-08-15 20:58 - 2012-10-10 17:59 - 00000000 ____D C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-08-15 20:58 - 2012-10-02 22:27 - 00000000 ___RD C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-15 20:57 - 2012-10-02 22:27 - 00000000 ___RD C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-08-15 20:57 - 2012-10-02 22:26 - 00000000 ___RD C:\Users\Privat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-08-14 22:25 - 2013-08-14 22:23 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 22:23 - 2012-10-02 22:23 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 19:48 - 2013-08-14 19:44 - 599912448 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e08.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-08-13 07:05 - 2013-08-13 07:05 - 00000552 _____ C:\Windows\System32\Tasks\635119737759461466.exe 2013-08-13 07:05 - 2009-07-14 19:58 - 00000000 ____D C:\Windows\system32\winrm 2013-08-13 07:05 - 2009-07-14 19:58 - 00000000 ____D C:\Windows\system32\WCN 2013-08-13 07:05 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WindowsPowerShell 2013-08-13 07:05 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2013-08-13 07:05 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioDatabase 2013-08-13 07:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-08-13 07:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\winevt 2013-08-13 07:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\uk-UA 2013-08-13 07:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-08-13 07:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\th-TH 2013-08-13 07:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep 2013-08-13 07:05 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sr-Latn-CS 2013-08-13 07:04 - 2013-03-20 15:32 - 00000000 ____D C:\Windows\system32\SPReview 2013-08-13 07:04 - 2009-07-14 19:58 - 00000000 ____D C:\Windows\system32\slmgr 2013-08-13 07:04 - 2009-07-14 19:58 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2013-08-13 07:04 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\restore 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sppui 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\spp 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\spool 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Speech 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\SMI 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sl-SI 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sk-SK 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ro-RO 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ras 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\oobe 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NetworkList 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-13 07:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\MUI 2013-08-13 07:03 - 2013-03-20 15:30 - 00000000 ____D C:\Windows\system32\EventProviders 2013-08-13 07:03 - 2012-10-10 17:25 - 00000000 ____D C:\Windows\system32\Macromed 2013-08-13 07:03 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Msdtc 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\migwiz 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\manifeststore 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lv-LV 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lt-LT 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\inetsrv 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\IME 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\ias 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\hr-HR 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\GroupPolicy 2013-08-13 07:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\et-EE 2013-08-13 07:02 - 2013-08-13 07:02 - 00000552 _____ C:\Windows\system32\Drivers\635119737759461466.exe 2013-08-13 07:02 - 2013-08-13 07:02 - 00000552 _____ C:\Windows\system32\config\635119737759461466.exe 2013-08-13 07:01 - 2013-08-13 07:01 - 00000552 _____ C:\Program Files\Common Files\635119737759461466.exe 2013-08-11 14:11 - 2012-10-13 14:06 - 00000047 _____ C:\Users\Privat\Documents\mt-x_hook.txt 2013-08-11 14:11 - 2012-10-13 14:06 - 00000007 _____ C:\Users\Privat\Documents\mt-e_hook.txt 2013-08-11 14:11 - 2012-10-12 12:28 - 00173448 _____ C:\shared.log 2013-08-11 11:04 - 2013-08-11 11:04 - 00000552 _____ C:\Windows\System32\Tasks\635118148276728403.exe 2013-08-11 11:01 - 2013-08-11 11:01 - 00000552 _____ C:\Windows\system32\Drivers\635118148276728403.exe 2013-08-11 11:01 - 2013-08-11 11:01 - 00000552 _____ C:\Windows\system32\config\635118148276728403.exe 2013-08-11 11:00 - 2013-08-11 11:00 - 00000552 _____ C:\Program Files\Common Files\635118148276728403.exe 2013-08-09 19:38 - 2013-08-09 19:27 - 1473724416 ____R C:\Users\Privat\Downloads\Kolonija.2013.P.DVDRip.1400MB.avi 2013-08-09 19:27 - 2013-08-09 19:26 - 106629120 ____R C:\Users\Privat\Downloads\Серия 34. Фотография 9х12.avi 2013-08-09 13:33 - 2013-08-09 13:32 - 00000552 _____ C:\Program Files\Common Files\635116480592288445.exe 2013-08-07 19:57 - 2013-08-07 19:50 - 536546836 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e07.WEB-DLRip.avi 2013-08-06 17:30 - 2013-08-06 17:30 - 00000000 ____D C:\Users\Privat\Desktop\Ostsee 2013-08-06 15:52 - 2013-08-06 15:52 - 00002232 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-06 15:51 - 2012-10-10 16:42 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Windows\System32\Tasks\635113989991357900.exe 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Windows\system32\Drivers\635113989991357900.exe 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Windows\system32\config\635113989991357900.exe 2013-08-06 15:17 - 2013-08-06 15:17 - 00000552 _____ C:\Program Files\Common Files\635113989991357900.exe 2013-08-01 00:50 - 2013-08-01 00:50 - 00000000 ____D C:\Users\Privat\Desktop\Ukraine 2013-08-01 00:37 - 2013-08-01 00:37 - 00002259 _____ C:\Windows\System32\Tasks\635109120800555532.exe 2013-08-01 00:36 - 2013-08-01 00:36 - 00002259 _____ C:\Windows\system32\Drivers\635109120800555532.exe 2013-08-01 00:36 - 2013-08-01 00:36 - 00002259 _____ C:\Windows\system32\config\635109120800555532.exe 2013-08-01 00:36 - 2013-08-01 00:36 - 00002259 _____ C:\Program Files\Common Files\635109120800555532.exe 2013-07-31 22:13 - 2013-07-31 22:07 - 589694976 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e06.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 22:11 - 2013-07-31 21:58 - 601718784 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e02.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 22:10 - 2013-07-31 21:59 - 599040000 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e05.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 22:10 - 2013-07-31 21:57 - 611250176 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e01.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 22:07 - 2013-07-31 21:58 - 601378816 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e04.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 22:07 - 2013-07-31 21:58 - 601073664 ____R C:\Users\Privat\Downloads\Under.the.Dome.s01e03.WEB-DLRip.XviD.Rus.Eng.BaibaKo.tv.avi 2013-07-31 00:53 - 2012-10-10 16:43 - 00002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-30 18:52 - 2013-07-30 18:43 - 1567921049 ____R C:\Users\Privat\Downloads\Zloveshwie.Mertvecy.Chernaja.Kniga.2013.D.BDRip.x264.potroks..mkv 2013-07-30 00:25 - 2013-07-30 00:25 - 00000552 _____ C:\Windows\System32\Tasks\635107392760638784.exe 2013-07-30 00:24 - 2013-07-30 00:24 - 00000552 _____ C:\Windows\system32\Drivers\635107392760638784.exe 2013-07-30 00:24 - 2013-07-30 00:24 - 00000552 _____ C:\Windows\system32\config\635107392760638784.exe 2013-07-30 00:23 - 2013-07-30 00:23 - 00000552 _____ C:\Program Files\Common Files\635107392760638784.exe 2013-07-29 11:18 - 2013-07-29 11:05 - 1467840512 ____R C:\Users\Privat\Downloads\Yliki.2013.D.WEBDLRip.1400Mb.avi 2013-07-29 11:15 - 2013-07-29 11:06 - 1450774528 ____R C:\Users\Privat\Downloads\High.School.2010.D.HDRip.avi 2013-07-28 15:13 - 2013-07-28 15:13 - 00000552 _____ C:\Windows\System32\Tasks\635106209267944212.exe 2013-07-28 15:12 - 2013-07-28 15:12 - 00000552 _____ C:\Windows\system32\Drivers\635106209267944212.exe 2013-07-28 15:12 - 2013-07-28 15:12 - 00000552 _____ C:\Windows\system32\config\635106209267944212.exe 2013-07-28 15:12 - 2013-07-28 15:12 - 00000552 _____ C:\Program Files\Common Files\635106209267944212.exe 2013-07-26 15:04 - 2013-07-26 14:40 - 3369449577 ____R C:\Users\Privat\Downloads\Hummingbird.2013.D.720p.WEB-DL.mkv 2013-07-26 14:12 - 2013-07-26 13:57 - 2867646985 ____R C:\Users\Privat\Downloads\Sudnaja.Noch.2013.D.WEBDL.720p.INTERCINEMA.mkv 2013-07-26 13:56 - 2013-07-26 13:56 - 00000552 _____ C:\Windows\System32\Tasks\635104426715294720.exe 2013-07-26 13:55 - 2013-07-26 13:55 - 00000552 _____ C:\Windows\system32\Drivers\635104426715294720.exe 2013-07-26 13:55 - 2013-07-26 13:55 - 00000552 _____ C:\Windows\system32\config\635104426715294720.exe 2013-07-26 13:55 - 2013-07-26 13:55 - 00000552 _____ C:\Program Files\Common Files\635104426715294720.exe 2013-07-26 13:46 - 2012-10-10 16:42 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-26 13:46 - 2012-10-10 16:42 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-26 07:13 - 2013-08-14 22:28 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-14 22:28 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-14 22:28 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-14 22:28 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-14 22:28 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-14 22:28 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-14 22:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-14 22:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-14 22:28 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-14 22:28 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-14 22:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-14 22:28 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-14 22:28 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-14 22:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 11:25 - 2013-08-14 19:50 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 19:50 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 20:02 ==================== End Of Log ============================ --- --- --- Additional Zitat:
|
21.08.2013, 18:48 | #6 |
/// TB-Ausbilder | GPU AUslastung 98% Hi, ich hab bei der ersten schnelle Durchsicht der Logs gesehen, dass du unsaubere Software nutzt. Das unterstützen wir nicht: http://www.trojaner-board.de/95394-c...-software.html Wenn ich dir helfen soll, dann deinstalliere und entferne jetzt zuerst restlos alle illegale Software (Cracks, Keygens, etc.). Sobald alles weg ist, können wir loslegen. Sollte ich im weiteren Verlauf aber trotz dieser Warnung nochmals sowas sehen, ist Schluss. Gib mir Bescheid, sobald es hier weiter geht.
__________________ --> GPU AUslastung 98% |
26.08.2013, 15:08 | #7 |
/// TB-Ausbilder | GPU AUslastung 98% Hi, ich hab schon länger keine Antwort mehr von dir erhalten. Brauchst du weiterhin noch Hilfe? Wenn ich in den nächsten 24 Stunden nichts von dir höre, gehe ich davon aus, dass sich das Thema erledigt hat und lösche es aus meinen Abos.
__________________ cheers, Leo |
28.08.2013, 01:52 | #8 |
/// TB-Ausbilder | GPU AUslastung 98% Fehlende Rückmeldung Dieses Thema wurde aus meinen Abos gelöscht. Somit bekomme ich keine Benachrichtigung mehr über neue Antworten. Schreib mir eine PM, falls du das Thema doch wieder fortsetzen möchtest. Dann machen wir hier weiter. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass dein Rechner schon sauber ist. Jeder andere bitte diese Anleitung lesen und einen eigenen Thread erstellen.
__________________ cheers, Leo |
Themen zu GPU AUslastung 98% |
auslastung, avira, black, cpu, funktioniert, grafikkarte, hochfahren, interne, internetverbindung, jahre, kurze, lüfter, löschen, maleware, neustart, plötzlich, radeon, rechner, recht, ruckel, scan, scannen, spiele, temperatur, verbindung, woche |