Plagegeister aller Art und deren Bekämpfung: Delta Toolbar, Babylon, FilesFrogUpdater durch Free-Tool installier. Infektion zu befürchten?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
Hallo beisammen,

vor gut 2 Wochen habe ich mir das Tool "Logon Screen" von einer vollkommen vertrauenswürdigen Quelle heruntergerladen und die Zusatzsoftware (TuneUp) beim Installieren abgewählt. Dennoch hat dieses ***-Tool folgenden Krempel ungefragt mitinstalliert:

- FilesFrog Updater Checker
- Delta Toolbar
- Babylon "Irgendetwas"
- Bundled Software Uninstaller

Ich habe alle diese Programme deinstalliert, teilweise auch noch Reste manuell aus der Registrierung geworfen. Zudem habe ich den Adware Cleaner laufen lassen.

Da ich unsicher wurde, habe ich MBAM und OTL laufen lassen direkt danach, beide waren unauffällig. Die Logs hänge ich noch an. Das lässt mir aber keine Ruhe, darum habe ich noch mehrere Rootkit-Scanner (z.B. TDSS Killer) laufen lassen, nix gefunden.

Mir geht es jetzt konkret darum, ob diese lästigen Programme nun weg sind oder nicht bzw. ob ich Schlimmeres befürchten muss. Sofern der Rechner nicht befallen ist, würde ich ungern neu installieren.

Ich bemerke weder ein auffälliges Verhalten, noch wird der Rechner langsamer, Internet geht normal, keine verdächtigen Pop-Ups oder Fenster, keine schrägen Skype-Meldungen, die Auslastung der Prozessoren ist niedrig wie immer. Ich erwähne das mal weil es mir nur darum geht, ob da überhaupt was sein könnte.

Nach meinem Kenntnisstand würde ich davon ausgehen, dass der Rechner nicht befallen ist, aber die Meinung von Euch ist mir mehr als wichtig damit ich die Kiste beruhigt weiter nutzen kann.

Als Schutz habe ich avast Vollversion sowie den Spyware Terminator.

Logs im nächsten Post.

Danke!!

Grüße
Nebelwand
Bitte verschiebe FRST auf deinen Desktop und führe das Tool dort nochmals wie folgt aus:

Kontrollscan mit FRST
Führe wie zuvor beschrieben einen Scan mit FRST aus.
Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan.
Es werden wieder zwei Logdateien erzeugt. Poste mir diese.

Danach kanns mit der Bereinigung losgehen.

Zudem möche ich gerne, dass du mir die Logdatei von AdwCleaner postest. Diese ist hier zu finden:
C:\AdwCleaner\AdwCleaner[Sx].txt
![]() | #6 |
![]() | ![]() Delta Toolbar, Babylon, FilesFrogUpdater durch Free-Tool installier. Infektion zu befürchten? Hallo Matthias, zunächst vielen Dank für Deine Unterstützung ![]() Hier kommen also erst mal die Logs; alle vom Desktop (c: ) ausgeführt unter Admin. FRST 64bit Log: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-09-2013 Ran by Benutzer (administrator) on Benutzer-PC on 21-09-2013 16:07:17 Running from C:\Users\Benutzer\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\WINDOWS\SYSTEM32\NVVSVC.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\PROGRAM FILES\AVAST\AVASTSVC.EXE (NVIDIA Corporation) C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVXDSYNC.EXE (NVIDIA Corporation) C:\WINDOWS\SYSTEM32\NVVSVC.EXE (AVAST Software) C:\PROGRAM FILES\AVAST\AFWSERV.EXE (SUPERAntiSpyware.com) C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE (Microsoft Corporation.) C:\PROGRAM FILES (X86)\MICROSOFT\BINGBAR\7.1.362.0\BBSVC.EXE (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NVIDIA UPDATE CORE\DAEMONU.EXE () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe () C:\PROGRAM FILES\QUALCOMM ATHEROS\KILLER NETWORK MANAGER\BFNSERVICE.EXE (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (Microsoft Corp.) C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\PROGRAM FILES (X86)\CORETEMP\CORE TEMP.EXE (NVIDIA Corporation) C:\PROGRAM FILES (X86)\NVIDIA CORPORATION\NVIDIA UPDATE CORE\NVTMRU.EXE (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE (The Eraser Project) C:\PROGRAM FILES\ERASER\ERASER.EXE (NVIDIA Corporation) C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVTRAY.EXE (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE (Logitech Inc.) C:\PROGRAM FILES\LOGITECH GAMING SOFTWARE\LCORE.EXE (Valve Corporation) C:\PROGRAM FILES (X86)\STEAM\STEAM.EXE (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (TrueCrypt Foundation) C:\Program Files\TrueCrypt\TrueCrypt.exe (Skype Technologies S.A.) C:\PROGRAM FILES (X86)\SKYPE\PHONE\SKYPE.EXE (SUPERAntiSpyware) C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE () C:\PROGRAM FILES\QUALCOMM ATHEROS\KILLER NETWORK MANAGER\KILLERNETMANAGER.EXE (Microsoft Corporation) C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE12\ONENOTEM.EXE (Intel Corporation) C:\PROGRAM FILES (X86)\INTEL\INTEL(R) USB 3.0 EXTENSIBLE HOST CONTROLLER DRIVER\APPLICATION\IUSB3MON.EXE (AVAST Software) C:\PROGRAM FILES\AVAST\AVASTUI.EXE (Oracle Corporation) C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE (Valve Corporation) C:\PROGRAM FILES (X86)\COMMON FILES\STEAM\STEAMSERVICE.EXE (Mozilla Corporation) C:\PROGRAM FILES (X86)\FIREFOX\FIREFOX.EXE (Mozilla Corporation) C:\PROGRAM FILES (X86)\THUNDERBIRD\THUNDERBIRD.EXE (Ghisler Software GmbH) C:\PROGRAM FILES (X86)\TOTALCOMMANDER\TOTALCMD.EXE (VideoLAN) C:\PROGRAM FILES (X86)\VLC\VLC.EXE (Intel Corporation) C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STORAGE TECHNOLOGY\IASTORICON.EXE (Intel Corporation) C:\PROGRAM FILES\INTEL\INTEL(R) RAPID STORAGE TECHNOLOGY\IASTORDATAMGRSVC.EXE (Intel Corporation) C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\DAL\JHI_SERVICE.EXE (Intel Corporation) C:\PROGRAM FILES (X86)\INTEL\INTEL(R) MANAGEMENT ENGINE COMPONENTS\LMS\LMS.EXE (Intel(R) Corporation) C:\PROGRAM FILES (X86)\INTEL\EXTREME TUNING UTILITY\XTUSERVICE.EXE (Intel Corporation) C:\PROGRAM FILES (X86)\INTEL\INTEL(R) INTEGRATED CLOCK CONTROLLER SERVICE\ICCPROXY.EXE (Farbar) C:\USERS\Benutzer\DESKTOP\FRST64(1).EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM\...\Run: [Eraser] - C:\PROGRA~1\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7477016 2013-04-25] (Logitech Inc.) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1811368 2013-09-06] (Valve Corporation) HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [TrueCrypt] - C:\Program Files\TrueCrypt\TrueCrypt.exe [1516496 2013-07-23] (TrueCrypt Foundation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.) HKCU\...\Run: [SUPERAntiSpyware] - C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE [6581488 2013-08-15] (SUPERAntiSpyware) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [avast] - C:\Program Files\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2249352 2013-06-20] (Microsoft Corp.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Startup: C:\Users\Benutzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x71BA8C29D4ABCE01 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default FF NewTab: https://www.google.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Deutsches Wörterbuch - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\de-DE@dictionaries.addons.mozilla.org FF Extension: British English Dictionary (Updated) - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\en-gb@flyingtophat.co.uk FF Extension: GoogleSharing - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\googlesharing@extension.thoughtcrime.org FF Extension: WOT - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: DownloadHelper - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: elemhidehelper - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\elemhidehelper@adblockplus.org.xpi FF Extension: langpack-en-GB - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\langpack-en-GB@firefox.mozilla.org.xpi FF Extension: Noia4Options - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\Noia4Options@ArisT2.xpi FF Extension: No Name - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: No Name - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF Extension: No Name - C:\Users\Benutzer\AppData\Roaming\Mozilla\Firefox\Profiles\lacdvedv.default\Extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\Avast\WebRep\FF FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Firefox\firefox.exe ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com) R2 avast! Antivirus; C:\Program Files\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 avast! Firewall; C:\Program Files\Avast\afwServ.exe [137960 2013-08-30] (AVAST Software) R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173192 2013-06-20] (Microsoft Corp.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75064 2013-08-15] () R2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [189248 2013-08-15] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2013-04-11] () S3 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [15888 2013-04-01] (Intel(R) Corporation) S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x] ==================== Drivers (Whitelisted) ==================== R3 AcpiCtlDrv; C:\Windows\System32\DRIVERS\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R0 aswNdis; C:\Windows\System32\DRIVERS\aswNdis.sys [12368 2013-03-13] (ALWIL Software) R0 aswNdis2; C:\Windows\System32\Drivers\aswNdis2.sys [270824 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [66928 2013-04-11] (Qualcomm Atheros, Inc.) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28656 2013-03-22] (Intel Corporation) R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [25448 2013-01-07] (Intel Corporation) R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [25448 2013-01-07] (Intel Corporation) R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [165824 2013-04-11] (Qualcomm Atheros, Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [142072 2013-06-14] (Ray Hinchliffe) S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [142072 2013-06-14] (Ray Hinchliffe) R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2013-07-12] (Windows (R) Win 7 DDK provider) R3 ALSysIO; \??\C:\Users\Benutzer\AppData\Local\Temp\ALSysIO64.sys [x] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x] S3 MSICDSetup; \??\E:\CDriver64.sys [x] S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [x] S4 SecureLockWare_EncryptFilterDriver; \SystemRoot\SYSTEM32\DRIVERS\ENCRFIL.SYS [x] S4 SecureLockWare_EncryptFilterDriver2; \SystemRoot\SYSTEM32\DRIVERS\SLWFIL.SYS [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-21 16:06 - 2013-09-21 16:05 - 01956670 _____ (Farbar) C:\Users\Benutzer\Desktop\FRST64(1).exe 2013-09-20 23:39 - 2013-09-20 23:39 - 00016206 _____ C:\Users\Benutzer\Desktop\HitmanPro_20130920_2339.log 2013-09-20 23:33 - 2013-09-20 23:43 - 00000000 ____D C:\ProgramData\HitmanPro 2013-09-20 19:06 - 2013-09-20 19:06 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\SUPERAntiSpyware.com 2013-09-20 19:05 - 2013-09-20 19:06 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-09-20 19:05 - 2013-09-20 19:05 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-09-19 20:15 - 2013-09-19 20:15 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-19 20:13 - 2013-09-19 20:13 - 00000000 ____D C:\NVIDIA 2013-09-19 20:13 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-19 20:13 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-19 20:13 - 2013-09-12 10:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-19 20:13 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-09-19 20:13 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-09-19 16:26 - 2013-09-19 16:26 - 00000000 ____D C:\FRST 2013-09-19 16:21 - 2013-09-19 16:21 - 00000000 ____D C:\Windows\ERUNT 2013-09-18 20:05 - 2013-09-18 20:05 - 00000000 ____D C:\Program Files (x86)\Firefox 2013-09-15 22:59 - 2013-09-15 22:59 - 00000000 ____D C:\Users\Benutzer\Documents\Hard Reset Extended 2013-09-15 22:11 - 2013-09-15 22:11 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-15 22:11 - 2013-09-15 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-15 22:11 - 2013-09-15 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-15 22:11 - 2013-09-15 22:11 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-15 22:11 - 2013-09-15 22:11 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-15 22:08 - 2013-09-15 22:08 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-15 22:08 - 2013-09-15 22:08 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-15 22:08 - 2013-09-15 22:08 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-15 22:08 - 2013-09-15 22:08 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-15 22:08 - 2013-09-15 22:08 - 00000000 ____D C:\Program Files\Java 2013-09-15 22:06 - 2013-09-15 22:11 - 00000000 ____D C:\ProgramData\Oracle 2013-09-15 22:06 - 2013-09-15 22:08 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-09-15 22:06 - 2013-09-15 22:08 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-09-15 19:21 - 2013-09-15 19:23 - 00000000 ____D C:\Users\Benutzer\AppData\Local\Sniper Elite Zombie Army 2013-09-15 19:05 - 1997-08-14 16:31 - 00098816 _____ (Eidos plc) C:\Windows\SysWOW64\Dec130.dll 2013-09-15 19:05 - 1997-08-14 16:24 - 00089600 _____ (EIDOS Technologies) C:\Windows\SysWOW64\Winsdec.dll 2013-09-15 19:05 - 1997-08-14 16:17 - 00117248 _____ (EIDOS Technologies) C:\Windows\SysWOW64\Edec.dll 2013-09-15 19:05 - 1997-08-14 16:06 - 00060416 _____ (EIDOS Technologies) C:\Windows\SysWOW64\Winplay.dll 2013-09-15 19:05 - 1997-08-14 11:10 - 00080896 _____ (EIDOS Technologies) C:\Windows\SysWOW64\Winstr.dll 2013-09-15 18:45 - 1998-10-21 18:43 - 00328704 _____ (InstallShield Software Corporation ) C:\Windows\IsUn0407.exe 2013-09-15 14:39 - 2013-09-15 14:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-10 23:57 - 2013-09-19 16:37 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster 2013-09-10 23:57 - 2013-09-10 23:57 - 00000000 ____D C:\ProgramData\Licenses 2013-09-10 23:46 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-10 23:46 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-10 23:46 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-10 23:46 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-10 23:46 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-10 23:46 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-10 23:46 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-10 23:46 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-10 23:46 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-10 23:46 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-10 23:46 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-10 23:46 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-10 23:46 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-10 23:46 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-10 23:30 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-10 23:30 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-10 23:30 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-10 23:30 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-10 23:30 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-10 23:30 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-10 23:30 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-10 23:30 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-10 23:30 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-10 23:30 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-10 23:30 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-10 23:30 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-10 23:30 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-10 23:30 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-10 23:30 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-10 23:30 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-10 23:30 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-10 23:30 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-10 23:30 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-10 23:30 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-10 23:30 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-10 23:30 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-10 23:30 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-10 23:30 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-10 23:30 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-10 23:30 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-10 23:30 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-10 22:12 - 2013-09-10 22:12 - 00000000 ____D C:\Users\Benutzer\Pavark 2013-09-10 00:09 - 2013-09-11 01:24 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-09-07 16:18 - 2013-09-07 16:18 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Safer Networking 2013-09-07 16:18 - 2013-09-07 16:18 - 00000000 ____D C:\Program Files (x86)\Safer Networking 2013-09-07 14:13 - 2013-09-07 15:07 - 00000000 ____D C:\Program Files\Logon Screen 2013-09-06 17:29 - 2013-09-21 16:06 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Skype 2013-09-06 17:29 - 2013-09-07 17:34 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-09-06 17:29 - 2013-09-07 17:34 - 00000000 ____D C:\ProgramData\Skype 2013-08-31 14:28 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-08-31 14:28 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-08-25 20:33 - 2013-08-25 20:35 - 00008107 _____ C:\Windows\w7dsd.reg 2013-08-25 20:33 - 2013-08-25 20:35 - 00008089 _____ C:\Windows\w7dse.reg 2013-08-25 20:33 - 2013-08-25 20:33 - 00275360 _____ (Microsoft Corporation) C:\Windows\system32\DreamScene.dll 2013-08-25 20:15 - 2008-03-18 04:07 - 00275360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DreamScene.dll 2013-08-23 11:54 - 2013-09-09 19:42 - 00000000 ____D C:\AdwCleaner ==================== One Month Modified Files and Folders ======= 2013-09-21 16:07 - 2009-07-14 06:45 - 00025392 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-21 16:07 - 2009-07-14 06:45 - 00025392 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-21 16:06 - 2013-09-06 17:29 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Skype 2013-09-21 16:06 - 2011-04-12 09:43 - 00708288 _____ C:\Windows\system32\perfh007.dat 2013-09-21 16:06 - 2011-04-12 09:43 - 00153378 _____ C:\Windows\system32\perfc007.dat 2013-09-21 16:06 - 2009-07-14 07:13 - 01645378 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-21 16:05 - 2013-09-21 16:06 - 01956670 _____ (Farbar) C:\Users\Benutzer\Desktop\FRST64(1).exe 2013-09-21 16:04 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-09-21 16:03 - 2013-07-12 13:52 - 01273862 _____ C:\Windows\WindowsUpdate.log 2013-09-21 16:00 - 2013-07-15 12:04 - 00026188 _____ C:\Windows\setupact.log 2013-09-21 16:00 - 2013-07-12 18:55 - 00000000 ____D C:\Program Files (x86)\Steam 2013-09-21 16:00 - 2013-07-12 14:14 - 00000000 ____D C:\ProgramData\Spyware Terminator 2013-09-21 16:00 - 2013-07-10 13:29 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-21 16:00 - 2013-07-10 13:24 - 00000000 ____D C:\ProgramData\Bigfoot Networks 2013-09-21 16:00 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-20 23:51 - 2013-08-12 17:34 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\vlc 2013-09-20 23:51 - 2013-07-12 15:01 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-20 23:43 - 2013-09-20 23:33 - 00000000 ____D C:\ProgramData\HitmanPro 2013-09-20 23:39 - 2013-09-20 23:39 - 00016206 _____ C:\Users\Benutzer\Desktop\HitmanPro_20130920_2339.log 2013-09-20 19:28 - 2013-07-25 10:51 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-09-20 19:06 - 2013-09-20 19:06 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\SUPERAntiSpyware.com 2013-09-20 19:06 - 2013-09-20 19:05 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-09-20 19:05 - 2013-09-20 19:05 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-09-19 20:15 - 2013-09-19 20:15 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-19 20:15 - 2013-07-10 13:28 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-09-19 20:13 - 2013-09-19 20:13 - 00000000 ____D C:\NVIDIA 2013-09-19 20:10 - 2013-07-16 19:31 - 00000000 ____D C:\Users\Benutzer\AppData\Local\CrashDumps 2013-09-19 16:37 - 2013-09-10 23:57 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster 2013-09-19 16:26 - 2013-09-19 16:26 - 00000000 ____D C:\FRST 2013-09-19 16:23 - 2013-07-17 10:01 - 00003688 _____ C:\Windows\PFRO.log 2013-09-19 16:23 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-19 16:21 - 2013-09-19 16:21 - 00000000 ____D C:\Windows\ERUNT 2013-09-18 20:50 - 2013-07-17 00:59 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\dvdcss 2013-09-18 20:08 - 2013-07-12 14:18 - 00000000 ____D C:\Users\Benutzer\AppData\Local\Mozilla 2013-09-18 20:06 - 2013-08-18 11:26 - 00000000 ____D C:\Program Files (x86)\Firefox.bak 2013-09-18 20:06 - 2013-07-12 14:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-18 20:05 - 2013-09-18 20:05 - 00000000 ____D C:\Program Files (x86)\Firefox 2013-09-15 22:59 - 2013-09-15 22:59 - 00000000 ____D C:\Users\Benutzer\Documents\Hard Reset Extended 2013-09-15 22:11 - 2013-09-15 22:11 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-15 22:11 - 2013-09-15 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-15 22:11 - 2013-09-15 22:11 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-15 22:11 - 2013-09-15 22:11 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-15 22:11 - 2013-09-15 22:11 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-15 22:11 - 2013-09-15 22:06 - 00000000 ____D C:\ProgramData\Oracle 2013-09-15 22:11 - 2013-07-23 15:22 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-15 22:11 - 2013-07-23 15:22 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-09-15 22:08 - 2013-09-15 22:08 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-15 22:08 - 2013-09-15 22:08 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-15 22:08 - 2013-09-15 22:08 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-15 22:08 - 2013-09-15 22:08 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-15 22:08 - 2013-09-15 22:08 - 00000000 ____D C:\Program Files\Java 2013-09-15 22:08 - 2013-09-15 22:06 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-09-15 22:08 - 2013-09-15 22:06 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-09-15 22:03 - 2013-07-12 15:01 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-15 22:02 - 2013-07-12 15:01 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-15 22:02 - 2013-07-12 15:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-15 19:23 - 2013-09-15 19:21 - 00000000 ____D C:\Users\Benutzer\AppData\Local\Sniper Elite Zombie Army 2013-09-15 19:19 - 2013-07-15 16:23 - 00440244 _____ C:\Windows\DirectX.log 2013-09-15 14:55 - 2013-07-25 10:51 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Winamp 2013-09-15 14:39 - 2013-09-15 14:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf 2013-09-12 20:35 - 2013-07-16 22:41 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-12 10:58 - 2013-09-19 20:13 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-12 10:58 - 2013-09-19 20:13 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-12 10:58 - 2013-09-19 20:13 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-09-12 10:58 - 2013-07-10 13:28 - 00022814 _____ C:\Windows\system32\nvinfo.pb 2013-09-12 09:25 - 2013-07-10 13:28 - 06599968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-09-12 09:25 - 2013-07-10 13:28 - 03452192 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-09-12 09:25 - 2013-07-10 13:28 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-09-12 09:25 - 2013-07-10 13:28 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-09-12 09:25 - 2013-07-10 13:28 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-09-12 09:25 - 2013-07-10 13:28 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-12 00:06 - 2013-07-10 13:28 - 03361114 _____ C:\Windows\system32\nvcoproc.bin 2013-09-11 01:24 - 2013-09-10 00:09 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-09-10 23:57 - 2013-09-10 23:57 - 00000000 ____D C:\ProgramData\Licenses 2013-09-10 23:48 - 2013-07-12 13:54 - 00000000 ___RD C:\Users\Benutzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-10 23:48 - 2013-07-12 13:54 - 00000000 ___RD C:\Users\Benutzer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-10 23:47 - 2009-07-14 06:45 - 00400608 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-10 23:46 - 2013-07-12 14:34 - 00000000 ____D C:\Windows\system32\MRT 2013-09-10 23:45 - 2013-04-22 13:35 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-10 22:12 - 2013-09-10 22:12 - 00000000 ____D C:\Users\Benutzer\Pavark 2013-09-10 22:12 - 2013-07-12 13:52 - 00000000 ____D C:\Users\Benutzer 2013-09-10 21:38 - 2013-08-13 16:52 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-09-09 19:42 - 2013-08-23 11:54 - 00000000 ____D C:\AdwCleaner 2013-09-07 17:34 - 2013-09-06 17:29 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-09-07 17:34 - 2013-09-06 17:29 - 00000000 ____D C:\ProgramData\Skype 2013-09-07 16:34 - 2013-07-12 14:13 - 00003894 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-07 16:34 - 2013-07-12 14:13 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-09-07 16:34 - 2013-07-12 14:12 - 00000000 ____D C:\Program Files\Avast 2013-09-07 16:18 - 2013-09-07 16:18 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\Safer Networking 2013-09-07 16:18 - 2013-09-07 16:18 - 00000000 ____D C:\Program Files (x86)\Safer Networking 2013-09-07 15:45 - 2012-04-13 03:15 - 00376320 _____ (hxxp://www.julien-manici.com/) C:\Users\Benutzer\Desktop\Win7LogonBackgroundChanger.exe 2013-09-07 15:07 - 2013-09-07 14:13 - 00000000 ____D C:\Program Files\Logon Screen 2013-09-07 15:07 - 2013-07-15 17:14 - 00000000 ____D C:\Users\Globuli 2013-09-07 15:07 - 2013-07-13 02:21 - 00000000 ____D C:\Program Files\CCleaner portable 2013-09-07 15:07 - 2013-07-12 14:37 - 00000000 ____D C:\Users\Benutzer\AppData\Roaming\GHISLER 2013-09-07 15:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-07 15:07 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-08-30 09:48 - 2013-07-12 22:08 - 00270824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdis2.sys 2013-08-30 09:48 - 2013-07-12 22:08 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys 2013-08-30 09:48 - 2013-07-12 22:08 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-30 09:48 - 2013-07-12 14:13 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-30 09:47 - 2013-07-12 14:13 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-30 09:47 - 2013-07-12 14:12 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-25 20:35 - 2013-08-25 20:33 - 00008107 _____ C:\Windows\w7dsd.reg 2013-08-25 20:35 - 2013-08-25 20:33 - 00008089 _____ C:\Windows\w7dse.reg 2013-08-25 20:33 - 2013-08-25 20:33 - 00275360 _____ (Microsoft Corporation) C:\Windows\system32\DreamScene.dll Files to move or delete: ==================== C:\Users\Benutzer\AppData\Roaming\Camdata.ini C:\Users\Benutzer\AppData\Roaming\CamLayout.ini C:\Users\Benutzer\AppData\Roaming\CamShapes.ini Some content of TEMP: ==================== C:\Users\Benutzer\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Benutzer\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Benutzer\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Benutzer\AppData\Local\Temp\nvStInst.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 12:59 ==================== End Of Log ============================ --- --- --- --- --- --- FRST Addition: Code:
Servus,

Spybot und SUPERAntiSpyware hättest du nicht installieren brauchen.

Die zwei Dateien, die AdwCleaner anzeigt, zeigen nur, wo Adwcleaner nach Adware sucht, nicht, dass die Dateien selbst bösartig sind.

Scan mit Combofix
[Instructions follow]
![]() | ![]() Delta Toolbar, Babylon, FilesFrogUpdater durch Free-Tool installier. Infektion zu befürchten? Hi Matthias, Spybot habe ich doch gar nicht installiert ;-). Ich mache nachher weiter mit Combofix, einen Wiederherstellungspunkt habe ich bereits erstellt. AdwCleaner war also ok vom Log her? Bis später!! Danke und Grüße Nebelwand Hallo Matthias, hier der Log von Combofix. Ich hatte avast, SpywareTerminator und SUPERAntiSpyware (ist eh nur on-demand) deaktiviert, alle weiteren Programme beendet. Die Maus habe ich ab und an bewegt weil der Bildschirmschoner im Scanvorgang lief... Steam etc war auch abgeschaltet und Internet deaktiviert. Gemeckert hat er trotzdem und meldete, dass avast angeblich aktiv sei, aber sowohl Antivirus als auch Firewall waren aus: ![]() Code:
Servus,

ja, sieht nach einem FP von ComboFix aus.

wir können die Dateien mit ComboFix wiederherstellen.

Dazu benötige ich folgende Datei:
C:\Qoobox\ComboFix-quarantined-files.txt
ATTFilter C:\Qoobox\ComboFix-quarantined-files.txt
![]() | #10 |
Hi M-K-D-B,

hat was gedauert mit meiner Antwort, war heute unterwegs.

Hier kommt der gewünschte Log:
[Quarantine file list provided]

Kannst Du denn vom aktuellen Stand her abschätzen ob sich da überhaupt was Böses versteckt?

VG
Nebelwand
Servus,

bisher sehe ich nichts böses.

So geht es weiter:

Schritt 1
Combofix-Skript
[Instructions for restoring files]

Schritt 2
ESET Online Scanner
[Scan instructions]

Schritt 3
Downloade Dir bitte SecurityCheck
[Instructions]

Bitte poste mit deiner nächsten Antwort die Logdateien von ESET und SecurityCheck.
Schritt 3 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
![]() | #12 |
![]() | #13 | |
![]() | #14 |
Guten Abend,

alles klar. Heute bzw. vermutlich auch morgen komme ich nicht dazu, mich um die Sache zu kümmern, aber diese Woche schaffe ich das auf jeden Fall.

Was ist mit Combofix? Kann man prüfen ob die Dateien wiederhergestellt worden sind?

Schönen Abend und danke

Nebelwand
![]() | #15 | |
![]() |
Themen zu Delta Toolbar, Babylon, FilesFrogUpdater durch Free-Tool installier. Infektion zu befürchten? |
adware, avast, babylon toolbar, befallen, bingbar, cleaner, delta, delta toolbar, direkt, folge, folgende, infektion, installieren, installiert, laufen, launch, mbam, plug-in, programme, pup.adbundle, rechner, registrierung, schutz, screen, secunia psi, spyware, tdss, tool, ungefragt, vollversion, woche, wochen |