![]() |
Log-Analyse und Auswertung: Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
![]() | #1 |
| ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? Hallo erstmal, Ich habe schon seit einiger Zeit das Problem, dass meine Verbindung zum Internet dauernd abbricht bzw. gestört ist. Ich habe dann im Ressourcenmonitor nachgeschaut ob irgendetwas auffällig aussieht. Also da ich kein Fachmann bin, würd ich jetzt sagen, dass meine TCP-Verbindungs Werte ziemlich hoch sind. Ich frage mich also ob das so normal ist oder ob da ein Virus hinterstecken könnte. defogger Code:
ATTFilter defogger_disable by jpshortstuff ( Log created at 19:12 on 25/09/2013 (*****) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2013 Ran by ***** (administrator) on *****S-PC on 25-09-2013 19:14:45 Running from C:\Users\*****\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\TouchControl.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Bison Inc.) C:\Program Files (x86)\BisonCam\PID_0361\DeLay.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Authentec) C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Razer USA Ltd) C:\Program Files (x86)\Razer\Imperator\RazerImperatorSysTray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Software 2000 Limited) C:\Windows\system32\spool\DRIVERS\x64\3\HP1006MC.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe (Microsoft Corporation) C:\Windows\System32\perfmon.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2817320 2011-07-28] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [DeLay] - C:\Program Files (x86)\BisonCam\PID_0361\DeLay.exe [53248 2008-12-05] (Bison Inc.) HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 HKLM\...\Run: [KeepSafe] - C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe [38728 2011-10-21] (Authentec) HKLM\...\Run: [] - [x] HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-26] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720 2010-11-01] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [Razer Imperator Driver] - C:\Program Files (x86)\Razer\Imperator\RazerImperatorSysTray.exe [979360 2012-02-09] (Razer USA Ltd) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [WD Quick View] - C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5537136 2013-08-14] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Users\*****\AppData\Local\DProtect\eBP.dll,C:\Users\*****\AppData\Local\DProtect\eBPSD.dll [ ] () Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Product Registration.lnk ShortcutTarget: Product Registration.lnk -> C:\Users\*****\AppData\Local\Temp\is-7O0VA.tmp\ATR1.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB5AEA1FDA0E2CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=420 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=420 BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.dll (AuthenTec Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5 05 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog9 01 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 02 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 03 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 04 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 05 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 06 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 17 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog5-x64 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 05 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll" Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 05 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 06 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 17 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\02rriite.default FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\02rriite.default\Extensions\763ab44b-71df-436c-906e-2ee8e1d7b302@af951efb-381e-47b2-ac45-80df41e44bc7.com FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions.sqlite FF Extension: gophoto - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\profiles\extensions\gophoto@gophoto.it.xpi FF Extension: movie2kdownloader - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\profiles\extensions\movie2kdownloader@movie2kdownloader.com.xpi FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.com/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\pdf.dll () CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Facebook Desktop) - C:\Users\*****\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll No File CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\*****\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File CHR Plugin: (Java Deployment Toolkit - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (ProxTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (Google Docs) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Facebook) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm\1.0.3_0 CHR Extension: (DUBSTEP!) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpdmlnllckeaoemfechahdjbldbjaikp\1.0_0 CHR Extension: (Adblock Plus) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0 CHR Extension: (Bypass Surveys) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjakedkphmphnlilokfkgkdclmhakhjg\1.1_0 CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (Website Logon) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\eioaimhbaiomogmbefipmnbpjmefhhoc\1.0_0 CHR Extension: (Stylish) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\1.2_0 CHR Extension: (Pok\u00E9balls) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdghocbdebppmiahcojameabkephedfo\1.0_0 CHR Extension: (AdBlock) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.7_0 CHR Extension: (Cookiemonster :3) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikliillbcfmaedhdfplflajkhmooaain\1.0_0 CHR Extension: (9GAG Mini) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmkmihphgjhmeabggdcokmkjhbnmdml\0.73_0 CHR Extension: (Dubstep) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldkncmnelaadenombphegfpenbbkinic\1.0_0 CHR Extension: (Toggle Adblock Plus) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdlpiobbbbdcaklklfalojacgifffohf\1.1.2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR Extension: (My Chrome Theme) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic\2.0_0 CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [eioaimhbaiomogmbefipmnbpjmefhhoc] - C:\Program Files\AuthenTec TrueSuite\x86\tschrome.crx ==================== Services (Whitelisted) ================= S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-25] (Adobe Systems) R2 FPLService; C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe [299848 2011-11-03] (AuthenTec, Inc) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [162648 2012-03-15] (Intel Corporation) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-02-03] () R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [35328 2011-02-18] () R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-08-14] (Western Digital Technologies, Inc.) S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270704 2013-08-14] (Western Digital Technologies, Inc.) S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] () S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x] U2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{39277a2d-c415-9360-3101-9b87aa7396cb}\ \...\???\{39277a2d-c415-9360-3101-9b87aa7396cb}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess) ==================== Drivers (Whitelisted) ==================== R3 Ak27x64; C:\Windows\System32\DRIVERS\Ak27x64.sys [3364720 2012-07-23] (Qualcomm Atheros, Inc.) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [66928 2012-07-23] (Qualcomm Atheros, Inc.) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation) S3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software) S3 cpuz134; \??\C:\Users\Administrator\Desktop\Install_Test\MIFcom\Support\pcwiz_x64.sys [x] S3 cpuz135; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x] S3 cpuz136; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 GPU-Z; \??\C:\Users\ADMINI~1\AppData\Local\Temp\GPU-Z.sys [x] S2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [x] S4 LMIRfsClientNP; No ImagePath S2 TVicPort; No ImagePath S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-25 19:14 - 2013-09-25 19:14 - 00000000 ____D C:\FRST 2013-09-25 19:12 - 2013-09-25 19:12 - 00000478 _____ C:\Users\*****\Desktop\defogger_disable.log 2013-09-25 19:12 - 2013-09-25 19:12 - 00000000 _____ C:\Users\*****\defogger_reenable 2013-09-25 19:10 - 2013-09-25 19:10 - 01955802 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe 2013-09-25 19:10 - 2013-09-25 19:10 - 00377856 _____ C:\Users\*****\Desktop\gmer_2.1.19163.exe 2013-09-25 19:09 - 2013-09-25 19:09 - 00050477 _____ C:\Users\*****\Desktop\Defogger.exe 2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\Users\*****\AppData\Local\Western_Digital_Technolog 2013-09-25 17:53 - 2013-09-25 18:15 - 00000022 _____ C:\Users\*****\Desktop\Neues Textdokument.txt 2013-09-25 14:40 - 2013-09-25 14:40 - 00000000 ____D C:\Users\*****\Desktop\mods_alt 2013-09-25 14:28 - 2013-09-25 14:28 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-25 14:28 - 2013-09-25 14:28 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-25 14:28 - 2013-09-25 14:28 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-25 14:28 - 2013-09-25 14:28 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-25 14:22 - 2013-09-25 14:23 - 131337120 _____ (Oracle Corporation) C:\Users\*****\Downloads\jdk-7u40-windows-x64.exe 2013-09-25 11:45 - 2013-09-25 11:45 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-09-25 11:35 - 2013-09-25 16:34 - 00000413 _____ C:\Users\*****\Desktop\Notes.txt 2013-09-25 11:35 - 2012-08-15 10:49 - 00009265 _____ C:\Users\*****\Desktop\win.txt 2013-09-25 11:29 - 2013-09-25 18:16 - 00008192 _____ C:\Windows\SysWOW64\WDPABKP.dat 2013-09-25 11:29 - 2013-09-25 11:29 - 00000000 ____D C:\Program Files\Western Digital 2013-09-25 11:29 - 2013-09-25 11:29 - 00000000 ____D C:\Program Files\Common Files\Western Digital 2013-09-25 11:29 - 2013-09-25 11:29 - 00000000 ____D C:\Program Files (x86)\Western Digital 2013-09-25 11:28 - 2013-09-25 11:28 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-25 11:28 - 2013-08-14 17:53 - 34605824 _____ (Western Digital Technologies, Inc.) C:\Users\*****\Downloads\WD SmartWare Installer.exe 2013-09-25 11:27 - 2013-09-25 11:27 - 34335877 _____ C:\Users\*****\Downloads\WD_SmartWare_Installer_2.2.0.8.zip 2013-09-25 10:27 - 2013-09-25 18:19 - 00000000 ____D C:\ProgramData\ParetoLogic 2013-09-25 10:27 - 2013-09-25 10:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\ParetoLogic 2013-09-25 10:27 - 2013-09-25 10:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\DriverCure 2013-09-25 10:26 - 2013-09-25 10:26 - 05249448 _____ (ParetoLogic Inc.) C:\Users\v\Downloads\ParetoLogic PC Health Advisor_de.exe 2013-09-23 20:03 - 2013-09-23 20:32 - 00000094 _____ C:\Users\*****\Desktop\cookie prog classic.txt 2013-09-23 19:59 - 2013-09-23 20:31 - 00000601 _____ C:\Users\*****\Desktop\cookie prog cheat.txt 2013-09-22 19:16 - 2013-09-22 19:16 - 00000000 ____D C:\Windows\de 2013-09-22 19:13 - 2013-09-22 19:13 - 01245168 _____ (Microsoft Corporation) C:\Users\*****\Downloads\wlsetup-web.exe 2013-09-22 19:10 - 2013-09-22 19:10 - 24277024 _____ (Microsoft) C:\Users\*****\Downloads\dotnetfx.exe 2013-09-20 19:07 - 2013-09-20 19:07 - 00161093 _____ C:\Users\*****\Downloads\proxtube_1.2.4 (1).crx 2013-09-19 20:48 - 2013-09-19 20:48 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-19 20:48 - 2013-09-19 20:48 - 00000000 ____D C:\Windows\system32\NV 2013-09-19 20:48 - 2013-09-19 20:48 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-19 20:47 - 2013-09-12 10:58 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-19 20:47 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-19 20:47 - 2013-09-12 10:58 - 00032032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2013-09-18 17:38 - 2013-09-18 17:38 - 00304718 _____ C:\Users\*****\Downloads\colleged.zip 2013-09-17 22:35 - 2013-09-17 22:35 - 04028984 _____ C:\Users\v\Downloads\ljP1000_P1500-HB-pnp-win64-de (1).exe 2013-09-17 22:10 - 2013-09-25 19:15 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-17 22:10 - 2013-09-25 18:16 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-17 22:10 - 2013-09-17 22:10 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-17 22:10 - 2013-09-17 22:10 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-17 21:17 - 2013-09-17 21:18 - 32478151 _____ C:\Users\*****\Downloads\spyhunterS4.rar 2013-09-17 21:03 - 2013-09-17 21:03 - 00000000 ____D C:\Program Files (x86)\Enigma Software Group 2013-09-17 21:02 - 2013-09-17 21:35 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP 2013-09-17 20:36 - 2013-09-17 21:02 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-09-17 20:36 - 2013-09-17 20:36 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-09-17 20:36 - 2013-09-17 20:36 - 00000000 _____ C:\autoexec.bat 2013-09-17 20:34 - 2013-09-17 20:34 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\*****\Downloads\SpyHunter-Installer.exe 2013-09-17 20:23 - 2013-09-17 22:36 - 00024795 _____ C:\HPLJP1000_P1500_Series.log 2013-09-17 20:23 - 2013-09-17 20:23 - 04028984 _____ C:\Users\*****\Downloads\ljP1000_P1500-HB-pnp-win64-de.exe 2013-09-17 17:28 - 2013-09-17 17:28 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\*****\Downloads\mbam-setup- 2013-09-17 17:28 - 2013-09-17 17:28 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-17 17:28 - 2013-09-17 17:28 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-09-17 17:28 - 2013-09-17 17:28 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-17 17:28 - 2013-09-17 17:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-17 17:28 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-17 16:03 - 2013-09-17 16:03 - 01039554 _____ C:\Users\*****\Downloads\adwcleaner004 (1).exe 2013-09-17 15:56 - 2013-09-25 18:16 - 00001916 _____ C:\Windows\Tasks\LyriXeeker-1-chromeinstaller.job 2013-09-17 15:56 - 2013-09-25 18:16 - 00001840 _____ C:\Windows\Tasks\LyriXeeker-1-firefoxinstaller.job 2013-09-17 15:56 - 2013-09-25 18:16 - 00001302 _____ C:\Windows\Tasks\LyriXeeker-1-updater.job 2013-09-17 15:56 - 2013-09-25 18:16 - 00001206 _____ C:\Windows\Tasks\LyriXeeker-1-codedownloader.job 2013-09-17 15:56 - 2013-09-25 18:16 - 00001106 _____ C:\Windows\Tasks\LyriXeeker-1-enabler.job 2013-09-17 15:56 - 2013-09-17 22:00 - 00000000 ____D C:\Program Files (x86)\LyriXeeker-1 2013-09-17 15:56 - 2013-09-17 15:56 - 22404568 _____ (Mozilla) C:\Users\*****\Downloads\Firefox_Setup [1].exe 2013-09-17 15:56 - 2013-09-17 15:56 - 00004332 _____ C:\Windows\System32\Tasks\LyriXeeker-1-updater 2013-09-17 15:56 - 2013-09-17 15:56 - 00004236 _____ C:\Windows\System32\Tasks\LyriXeeker-1-codedownloader 2013-09-17 15:56 - 2013-09-17 15:56 - 00004136 _____ C:\Windows\System32\Tasks\LyriXeeker-1-enabler 2013-09-17 15:54 - 2013-09-17 15:54 - 00676344 _____ C:\Users\*****\Downloads\Firefox_Setup.exe 2013-09-17 15:47 - 2013-09-17 16:08 - 00000000 ____D C:\AdwCleaner 2013-09-17 15:46 - 2013-09-17 15:47 - 01039554 _____ C:\Users\*****\Downloads\adwcleaner004.exe 2013-09-17 15:36 - 2013-09-17 15:36 - 00065312 _____ C:\Users\*****\Documents\cc_20130917_153613.reg 2013-09-17 15:08 - 2013-09-17 15:08 - 00000000 _____ C:\ProgramData\233b3a273b3b37293a5e242c_c 2013-09-16 23:15 - 2013-09-16 23:15 - 00014684 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-09-15 01:21 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-15 01:21 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-15 01:21 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-15 01:21 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-15 01:21 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-15 01:21 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-15 01:21 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-15 01:21 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-15 01:21 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-15 01:21 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-15 01:21 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-15 01:21 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-15 01:21 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-15 01:21 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-14 17:59 - 2013-09-14 17:59 - 00000000 __SHD C:\ProgramData\DSS 2013-09-14 17:57 - 2013-09-14 17:57 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP 2013-09-14 14:55 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-14 14:55 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-14 14:55 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-14 14:55 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-14 14:55 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-14 14:55 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-14 14:55 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-14 14:55 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-14 14:55 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-14 14:55 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-14 14:55 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-14 14:55 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-14 14:55 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-14 14:55 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-14 14:55 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-14 14:55 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-14 14:55 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-14 14:55 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-14 14:55 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-14 14:55 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-14 14:55 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-14 14:55 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-14 14:55 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-14 14:55 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-14 14:55 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-14 14:55 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-14 14:55 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-11 18:48 - 2013-09-23 19:47 - 00000595 _____ C:\Users\*****\Desktop\cookie prog.txt 2013-09-10 16:36 - 2013-09-11 16:13 - 00000000 ____D C:\Users\*****\AppData\Local\fabi.me 2013-09-10 16:34 - 2013-09-10 16:34 - 00093464 _____ C:\Users\*****\Downloads\SpeedAutoClicker.zip 2013-09-10 16:34 - 2012-05-15 21:32 - 00174080 _____ (fabi.me) C:\Users\*****\Desktop\SpeedAutoClicker.exe 2013-09-10 16:01 - 2013-09-10 16:01 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01005.Wdf 2013-09-10 15:59 - 2013-09-25 11:29 - 00015632 _____ C:\Windows\DPINST.LOG 2013-09-10 15:57 - 2013-09-10 15:57 - 18178216 _____ (Razer USA Ltd. ) C:\Users\*****\Downloads\Imperator_Firmware_Updater_v1.16.exe 2013-09-10 15:56 - 2013-09-10 15:56 - 25633928 _____ (Razer USA Ltd. ) C:\Users\*****\Downloads\Razer_Imperator_Driver_v2.02.exe 2013-09-07 15:23 - 2013-09-25 18:16 - 00000000 ____D C:\Users\Public\Documents\phase6_197_Daten 2013-09-07 15:21 - 2013-09-07 15:21 - 00001983 _____ C:\Users\Public\Desktop\phase-6_197.lnk 2013-09-07 15:21 - 2013-09-07 15:21 - 00000000 ____D C:\Program Files (x86)\phase-6 2013-09-07 15:21 - 2013-09-07 15:21 - 00000000 ____D C:\Program Files (x86)\phase6 2013-09-06 22:38 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-09-06 22:38 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-09-04 19:05 - 2013-09-04 19:05 - 00000000 ____D C:\Users\*****\AppData\Local\Criterion Games 2013-09-04 14:23 - 2013-09-04 14:23 - 00012444 _____ C:\Users\*****\Documents\Stundenplan 2013 2014 Hj 1.xlsx 2013-09-03 19:20 - 2013-09-14 17:59 - 00000000 ____D C:\Users\*****\Documents\EA Games 2013-09-02 14:26 - 2013-09-02 14:26 - 00161093 _____ C:\Users\*****\Downloads\proxtube_1.2.4.crx 2013-08-30 23:43 - 2013-08-30 23:43 - 00903080 _____ (Oracle Corporation) C:\Users\Kristina\Downloads\chromeinstall-7u25.exe 2013-08-30 23:39 - 2013-08-30 23:41 - 95060896 _____ (Oracle Corporation) C:\Users\*****\Downloads\jdk-7u25-windows-x64.exe 2013-08-27 23:08 - 2013-08-27 23:08 - 00000000 ____D C:\Users\*****\Desktop\Vox v0.37.2 2013-08-27 23:01 - 2013-08-27 23:08 - 36091436 _____ C:\Users\*****\Desktop\Vox_v0.37.2.zip ==================== One Month Modified Files and Folders ======= 2013-09-25 19:15 - 2013-09-17 22:10 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-25 19:14 - 2013-09-25 19:14 - 00000000 ____D C:\FRST 2013-09-25 19:12 - 2013-09-25 19:12 - 00000478 _____ C:\Users\*****\Desktop\defogger_disable.log 2013-09-25 19:12 - 2013-09-25 19:12 - 00000000 _____ C:\Users\*****\defogger_reenable 2013-09-25 19:12 - 2012-12-25 19:32 - 00000000 ____D C:\Users\*****\AppData\Roaming\Skype 2013-09-25 19:12 - 2012-12-24 23:11 - 00000000 ____D C:\Users\***** 2013-09-25 19:10 - 2013-09-25 19:10 - 01955802 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe 2013-09-25 19:10 - 2013-09-25 19:10 - 00377856 _____ C:\Users\*****\Desktop\gmer_2.1.19163.exe 2013-09-25 19:09 - 2013-09-25 19:09 - 00050477 _____ C:\Users\*****\Desktop\Defogger.exe 2013-09-25 18:43 - 2013-08-03 14:05 - 00007657 _____ C:\Users\*****\AppData\Local\Resmon.ResmonCfg 2013-09-25 18:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing 2013-09-25 18:23 - 2009-07-14 06:45 - 00021648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-25 18:23 - 2009-07-14 06:45 - 00021648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-25 18:20 - 2011-04-12 09:43 - 00708158 _____ C:\Windows\system32\perfh007.dat 2013-09-25 18:20 - 2011-04-12 09:43 - 00153612 _____ C:\Windows\system32\perfc007.dat 2013-09-25 18:20 - 2009-07-14 07:13 - 01644184 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-25 18:19 - 2013-09-25 10:27 - 00000000 ____D C:\ProgramData\ParetoLogic 2013-09-25 18:19 - 2012-12-26 00:53 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-09-25 18:19 - 2012-08-23 09:10 - 01259144 _____ C:\Windows\WindowsUpdate.log 2013-09-25 18:16 - 2013-09-25 11:29 - 00008192 _____ C:\Windows\SysWOW64\WDPABKP.dat 2013-09-25 18:16 - 2013-09-17 22:10 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-25 18:16 - 2013-09-17 15:56 - 00001916 _____ C:\Windows\Tasks\LyriXeeker-1-chromeinstaller.job 2013-09-25 18:16 - 2013-09-17 15:56 - 00001840 _____ C:\Windows\Tasks\LyriXeeker-1-firefoxinstaller.job 2013-09-25 18:16 - 2013-09-17 15:56 - 00001302 _____ C:\Windows\Tasks\LyriXeeker-1-updater.job 2013-09-25 18:16 - 2013-09-17 15:56 - 00001206 _____ C:\Windows\Tasks\LyriXeeker-1-codedownloader.job 2013-09-25 18:16 - 2013-09-17 15:56 - 00001106 _____ C:\Windows\Tasks\LyriXeeker-1-enabler.job 2013-09-25 18:16 - 2013-09-07 15:23 - 00000000 ____D C:\Users\Public\Documents\phase6_197_Daten 2013-09-25 18:16 - 2013-05-04 21:57 - 00000398 _____ C:\Windows\Tasks\FinalTorrent Update Checker.job 2013-09-25 18:16 - 2013-02-03 17:26 - 00000000 ___RD C:\Users\*****\Dropbox 2013-09-25 18:16 - 2013-02-03 17:21 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-09-25 18:16 - 2012-12-24 23:14 - 00134536 _____ C:\Users\*****\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-25 18:15 - 2013-09-25 17:53 - 00000022 _____ C:\Users\*****\Desktop\Neues Textdokument.txt 2013-09-25 18:15 - 2013-08-03 18:56 - 00032206 _____ C:\Windows\PFRO.log 2013-09-25 18:15 - 2013-08-03 13:31 - 00018491 _____ C:\Windows\setupact.log 2013-09-25 18:15 - 2013-01-06 02:48 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2013-09-25 18:15 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-25 18:15 - 2009-07-14 06:45 - 00436472 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-25 18:13 - 2012-12-28 14:25 - 00000000 ____D C:\Users\*****\AppData\Local\GameSpy 2013-09-25 18:00 - 2013-04-21 20:49 - 00000940 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1611356372-3225549263-3692715808-1001UA.job 2013-09-25 17:56 - 2013-09-25 17:56 - 00000000 ____D C:\Users\*****\AppData\Local\Western_Digital_Technolog 2013-09-25 16:34 - 2013-09-25 11:35 - 00000413 _____ C:\Users\*****\Desktop\Notes.txt 2013-09-25 15:30 - 2012-12-25 20:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\.minecraft 2013-09-25 15:00 - 2013-04-21 20:49 - 00000918 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1611356372-3225549263-3692715808-1001Core.job 2013-09-25 14:40 - 2013-09-25 14:40 - 00000000 ____D C:\Users\*****\Desktop\mods_alt 2013-09-25 14:28 - 2013-09-25 14:28 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-09-25 14:28 - 2013-09-25 14:28 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-09-25 14:28 - 2013-09-25 14:28 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-09-25 14:28 - 2013-09-25 14:28 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-09-25 14:28 - 2013-01-19 22:58 - 00000000 ____D C:\Program Files\Java 2013-09-25 14:28 - 2012-12-29 22:29 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-09-25 14:28 - 2012-12-29 22:29 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-09-25 14:23 - 2013-09-25 14:22 - 131337120 _____ (Oracle Corporation) C:\Users\*****\Downloads\jdk-7u40-windows-x64.exe 2013-09-25 11:50 - 2012-12-24 23:54 - 00000000 ____D C:\ProgramData\Adobe 2013-09-25 11:47 - 2012-12-24 23:54 - 00000000 ____D C:\Users\*****\AppData\Local\Adobe 2013-09-25 11:45 - 2013-09-25 11:45 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-09-25 11:45 - 2012-12-24 23:54 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-09-25 11:38 - 2013-02-04 18:38 - 00000000 ____D C:\Users\*****\Desktop\Snapshot 2013-09-25 11:29 - 2013-09-25 11:29 - 00000000 ____D C:\Program Files\Western Digital 2013-09-25 11:29 - 2013-09-25 11:29 - 00000000 ____D C:\Program Files\Common Files\Western Digital 2013-09-25 11:29 - 2013-09-25 11:29 - 00000000 ____D C:\Program Files (x86)\Western Digital 2013-09-25 11:29 - 2013-09-10 15:59 - 00015632 _____ C:\Windows\DPINST.LOG 2013-09-25 11:29 - 2013-08-25 12:37 - 00000000 ____D C:\ProgramData\Western Digital 2013-09-25 11:28 - 2013-09-25 11:28 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-25 11:27 - 2013-09-25 11:27 - 34335877 _____ C:\Users\*****\Downloads\WD_SmartWare_Installer_2.2.0.8.zip 2013-09-25 10:57 - 2012-12-25 16:49 - 00000000 ___RD C:\Users\*****\Desktop\Mein Zeug 2013-09-25 10:41 - 2013-08-03 13:30 - 00000000 ____D C:\Windows\pss 2013-09-25 10:41 - 2012-12-24 23:14 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-25 10:27 - 2013-09-25 10:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\ParetoLogic 2013-09-25 10:27 - 2013-09-25 10:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\DriverCure 2013-09-25 10:26 - 2013-09-25 10:26 - 05249448 _____ (ParetoLogic Inc.) C:\Users\*****\Downloads\ParetoLogic PC Health Advisor_de.exe 2013-09-23 20:32 - 2013-09-23 20:03 - 00000094 _____ C:\Users\*****\Desktop\cookie prog classic.txt 2013-09-23 20:31 - 2013-09-23 19:59 - 00000601 _____ C:\Users\*****\Desktop\cookie prog cheat.txt 2013-09-23 19:47 - 2013-09-11 18:48 - 00000595 _____ C:\Users\*****\Desktop\cookie prog.txt 2013-09-23 19:47 - 2013-01-21 16:44 - 00000000 ____D C:\Program Files (x86)\Steam 2013-09-22 19:18 - 2013-04-22 20:25 - 00000000 ____D C:\Users\*****\AppData\Local\Windows Live 2013-09-22 19:16 - 2013-09-22 19:16 - 00000000 ____D C:\Windows\de 2013-09-22 19:16 - 2013-08-05 23:55 - 00300888 _____ C:\Windows\DirectX.log 2013-09-22 19:16 - 2013-04-22 20:26 - 00000000 ____D C:\Program Files (x86)\Windows Live 2013-09-22 19:13 - 2013-09-22 19:13 - 01245168 _____ (Microsoft Corporation) C:\Users\*****\Downloads\wlsetup-web.exe 2013-09-22 19:12 - 2012-12-27 16:10 - 01671482 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-09-22 19:12 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Registration 2013-09-22 19:10 - 2013-09-22 19:10 - 24277024 _____ (Microsoft) C:\Users\*****\Downloads\dotnetfx.exe 2013-09-20 19:07 - 2013-09-20 19:07 - 00161093 _____ C:\Users\*****\Downloads\proxtube_1.2.4 (1).crx 2013-09-20 18:36 - 2013-04-21 00:19 - 00000000 ____D C:\Users\*****\Desktop\Fabi 2013-09-19 20:48 - 2013-09-19 20:48 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-19 20:48 - 2013-09-19 20:48 - 00000000 ____D C:\Windows\system32\NV 2013-09-19 20:48 - 2013-09-19 20:48 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-19 20:48 - 2012-08-23 09:35 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-19 20:48 - 2012-08-23 09:34 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-09-18 17:38 - 2013-09-18 17:38 - 00304718 _____ C:\Users\*****\Downloads\colleged.zip 2013-09-17 22:36 - 2013-09-17 20:23 - 00024795 _____ C:\HPLJP1000_P1500_Series.log 2013-09-17 22:35 - 2013-09-17 22:35 - 04028984 _____ C:\Users\*****\Downloads\ljP1000_P1500-HB-pnp-win64-de (1).exe 2013-09-17 22:12 - 2012-12-25 15:09 - 00000000 ____D C:\Users\*****\AppData\Local\Google 2013-09-17 22:11 - 2012-12-25 15:09 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-17 22:10 - 2013-09-17 22:10 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-17 22:10 - 2013-09-17 22:10 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-17 22:00 - 2013-09-17 15:56 - 00000000 ____D C:\Program Files (x86)\LyriXeeker-1 2013-09-17 21:35 - 2013-09-17 21:02 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP 2013-09-17 21:18 - 2013-09-17 21:17 - 32478151 _____ C:\Users\*****\Downloads\spyhunterS4.rar 2013-09-17 21:03 - 2013-09-17 21:03 - 00000000 ____D C:\Program Files (x86)\Enigma Software Group 2013-09-17 21:02 - 2013-09-17 20:36 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-09-17 20:36 - 2013-09-17 20:36 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-09-17 20:36 - 2013-09-17 20:36 - 00000000 _____ C:\autoexec.bat 2013-09-17 20:34 - 2013-09-17 20:34 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\*****\Downloads\SpyHunter-Installer.exe 2013-09-17 20:23 - 2013-09-17 20:23 - 04028984 _____ C:\Users\*****\Downloads\ljP1000_P1500-HB-pnp-win64-de.exe 2013-09-17 18:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-17 17:28 - 2013-09-17 17:28 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\*****\Downloads\mbam-setup- 2013-09-17 17:28 - 2013-09-17 17:28 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-17 17:28 - 2013-09-17 17:28 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-09-17 17:28 - 2013-09-17 17:28 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-17 17:28 - 2013-09-17 17:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-17 17:16 - 2012-12-24 23:54 - 00000000 ____D C:\Users\*****\AppData\Roaming\Adobe 2013-09-17 16:08 - 2013-09-17 15:47 - 00000000 ____D C:\AdwCleaner 2013-09-17 16:08 - 2013-07-30 21:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-17 16:07 - 2013-05-04 22:01 - 00000000 ____D C:\ProgramData\Uniblue 2013-09-17 16:03 - 2013-09-17 16:03 - 01039554 _____ C:\Users\*****\Downloads\adwcleaner004 (1).exe 2013-09-17 15:57 - 2013-02-16 19:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-17 15:56 - 2013-09-17 15:56 - 22404568 _____ (Mozilla) C:\Users\*****\Downloads\Firefox_Setup [1].exe 2013-09-17 15:56 - 2013-09-17 15:56 - 00004332 _____ C:\Windows\System32\Tasks\LyriXeeker-1-updater 2013-09-17 15:56 - 2013-09-17 15:56 - 00004236 _____ C:\Windows\System32\Tasks\LyriXeeker-1-codedownloader 2013-09-17 15:56 - 2013-09-17 15:56 - 00004136 _____ C:\Windows\System32\Tasks\LyriXeeker-1-enabler 2013-09-17 15:54 - 2013-09-17 15:54 - 00676344 _____ C:\Users\*****\Downloads\Firefox_Setup.exe 2013-09-17 15:47 - 2013-09-17 15:46 - 01039554 _____ C:\Users\*****\Downloads\adwcleaner004.exe 2013-09-17 15:36 - 2013-09-17 15:36 - 00065312 _____ C:\Users\*****\Documents\cc_20130917_153613.reg 2013-09-17 15:35 - 2013-08-07 13:47 - 00000000 ____D C:\Users\*****\AppData\Roaming\DAEMON Tools Lite 2013-09-17 15:35 - 2013-04-13 15:26 - 00000000 ____D C:\Windows\Minidump 2013-09-17 15:08 - 2013-09-17 15:08 - 00000000 _____ C:\ProgramData\233b3a273b3b37293a5e242c_c 2013-09-17 14:39 - 2013-08-05 17:03 - 00000000 ____D C:\ProgramData\SecTaskMan 2013-09-17 14:28 - 2013-01-19 22:57 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-16 23:15 - 2013-09-16 23:15 - 00014684 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-09-16 23:15 - 2012-12-26 01:49 - 00000000 ____D C:\Users\*****\.gimp-2.8 2013-09-16 21:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-15 14:09 - 2012-12-24 23:14 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-15 01:21 - 2013-07-27 23:14 - 00000000 ____D C:\Windows\system32\MRT 2013-09-15 01:21 - 2012-12-21 13:17 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-15 01:20 - 2012-12-31 01:36 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-14 17:59 - 2013-09-14 17:59 - 00000000 __SHD C:\ProgramData\DSS 2013-09-14 17:59 - 2013-09-03 19:20 - 00000000 ____D C:\Users\*****\Documents\EA Games 2013-09-14 17:58 - 2012-12-27 02:50 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-09-14 17:57 - 2013-09-14 17:57 - 00000000 ____D C:\Windows\1C4551A64743409391E41477CD655043.TMP 2013-09-14 15:18 - 2013-01-21 17:18 - 04751752 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-09-12 10:58 - 2013-09-19 20:47 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-12 10:58 - 2013-09-19 20:47 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00458528 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00388384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-12 10:58 - 2013-09-19 20:47 - 00032032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2013-09-12 10:58 - 2013-07-17 20:13 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-09-12 10:58 - 2012-08-23 09:33 - 00022814 _____ C:\Windows\system32\nvinfo.pb 2013-09-12 10:58 - 2012-08-23 09:32 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-09-12 10:58 - 2012-08-23 09:32 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-09-12 10:58 - 2012-08-23 09:32 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-12 09:25 - 2012-08-23 09:34 - 06599968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-09-12 09:25 - 2012-08-23 09:34 - 03452192 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-09-12 09:25 - 2012-08-23 09:34 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-09-12 09:25 - 2012-08-23 09:34 - 01042208 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2013-09-12 09:25 - 2012-08-23 09:34 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-09-12 09:25 - 2012-08-23 09:34 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-09-12 09:25 - 2012-08-23 09:34 - 00067072 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2013-09-12 09:25 - 2012-08-23 09:34 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-09-12 00:06 - 2012-08-23 09:34 - 03361114 _____ C:\Windows\system32\nvcoproc.bin 2013-09-11 16:13 - 2013-09-10 16:36 - 00000000 ____D C:\Users\*****\AppData\Local\fabi.me 2013-09-10 16:34 - 2013-09-10 16:34 - 00093464 _____ C:\Users\*****\Downloads\SpeedAutoClicker.zip 2013-09-10 16:01 - 2013-09-10 16:01 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01005.Wdf 2013-09-10 15:57 - 2013-09-10 15:57 - 18178216 _____ (Razer USA Ltd. ) C:\Users\*****\Downloads\Imperator_Firmware_Updater_v1.16.exe 2013-09-10 15:56 - 2013-09-10 15:56 - 25633928 _____ (Razer USA Ltd. ) C:\Users\*****\Downloads\Razer_Imperator_Driver_v2.02.exe 2013-09-09 19:35 - 2012-12-25 18:03 - 00000000 ____D C:\Users\*****\Documents\Camtasia Studio 2013-09-08 22:04 - 2013-07-19 13:33 - 00000000 ____D C:\Users\*****\AppData\Roaming\CodeBlocks 2013-09-07 15:21 - 2013-09-07 15:21 - 00001983 _____ C:\Users\Public\Desktop\phase-6_197.lnk 2013-09-07 15:21 - 2013-09-07 15:21 - 00000000 ____D C:\Program Files (x86)\phase-6 2013-09-07 15:21 - 2013-09-07 15:21 - 00000000 ____D C:\Program Files (x86)\phase6 2013-09-04 19:05 - 2013-09-04 19:05 - 00000000 ____D C:\Users\*****\AppData\Local\Criterion Games 2013-09-04 14:23 - 2013-09-04 14:23 - 00012444 _____ C:\Users\*****\Documents\Stundenplan 2013 2014 Hj 1.xlsx 2013-09-03 22:29 - 2012-12-26 15:24 - 00000000 ___RD C:\Users\*****\Desktop\Games 2013-09-02 14:26 - 2013-09-02 14:26 - 00161093 _____ C:\Users\*****\Downloads\proxtube_1.2.4.crx 2013-08-30 23:44 - 2012-12-26 14:17 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-08-30 23:44 - 2012-12-26 14:17 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-30 23:43 - 2013-08-30 23:43 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\chromeinstall-7u25.exe 2013-08-30 23:41 - 2013-08-30 23:39 - 95060896 _____ (Oracle Corporation) C:\Users\*****\Downloads\jdk-7u25-windows-x64.exe 2013-08-27 23:08 - 2013-08-27 23:08 - 00000000 ____D C:\Users\*****\Desktop\Vox v0.37.2 2013-08-27 23:08 - 2013-08-27 23:01 - 36091436 _____ C:\Users\*****\Desktop\Vox_v0.37.2.zip ZeroAccess: C:\Windows\assembly\GAC_32\Desktop.ini ZeroAccess: C:\Windows\assembly\GAC_64\Desktop.ini Files to move or delete: ==================== ZeroAccess: C:\Users\*****\AppData\Local\Google\Desktop\Install ZeroAccess: C:\Program Files (x86)\Google\Desktop\Install Some content of TEMP: ==================== C:\Users\*****\AppData\Local\Temp\drm_dyndata_7400006.dll C:\Users\*****\AppData\Local\Temp\j3dcore-ogl.dll C:\Users\*****\AppData\Local\Temp\Quarantine.exe C:\Users\*****\AppData\Local\Temp\SHSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit C:\Program Files\Windows Defender\mpsvc.dll => ATTENTION: ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender LastRegBack: 2013-09-12 20:04 ==================== End Of Log ============================ --- --- --- Gmer Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-09-25 19:42:10 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 M4-CT512 rev.010G 476,94GB Running: gmer_2.1.19163.exe; Driver: C:\Users\*****\AppData\Local\Temp\fxdyiuow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2180] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076621465 2 bytes [62, 76] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2180] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766214bb 2 bytes [62, 76] .text ... * 2 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076621465 2 bytes [62, 76] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766214bb 2 bytes [62, 76] .text ... * 2 .text C:\Windows\SysWOW64\PnkBstrA.exe[2412] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000073381a22 2 bytes [38, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2412] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000073381ad0 2 bytes [38, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2412] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000073381b08 2 bytes [38, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2412] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000073381bba 2 bytes [38, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2412] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000073381bda 2 bytes [38, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[2412] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076621465 2 bytes [62, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2412] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766214bb 2 bytes [62, 76] .text ... * 2 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefddd2db0 5 bytes JMP 000007fffdd60180 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefddd37d0 7 bytes JMP 000007fffdd600d8 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefddd8ef0 6 bytes JMP 000007fffdd60148 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefddeaf60 5 bytes JMP 000007fffdd60110 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe1c89e0 8 bytes JMP 000007fffdd601f0 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe1cbe40 8 bytes JMP 000007fffdd601b8 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef828dc88 5 bytes JMP 000007fff80800d8 .text C:\Windows\system32\Dwm.exe[3248] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef828de10 5 bytes JMP 000007fff8080110 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076621465 2 bytes [62, 76] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[1588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766214bb 2 bytes [62, 76] .text ... * 2 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\ Reg HKLM\SYSTEM\CurrentControlSet\services\@Parameters\0\x202e\x2764 448 Reg HKLM\SYSTEM\ControlSet002\services\ (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\@Parameters\0\x202e\x2764 448 ---- EOF - GMER 2.1 ---- ![]() Addition.txt ist angehängt. Vielen Dank für Eure Hilfe ![]() Geändert von fabianst2 (25.09.2013 um 20:04 Uhr) |
![]() | #2 | |||
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? Hallo und
__________________![]() Zitat:
Oder ist das rein zufällig ein Büro-/Firmen-PC bzw. ein Uni-Rechner? Zitat:
Wieso lädst du Filme von hochriskanten Malwareschleudern? Dass es obendrein nicht völlig legal ist kommt noch hinzu. Zitat:
![]() Rootkit-Warnung Dein Computer wurde mit einem besonderen Schädling infiziert, der sich vor herkömmlichen Virenscannern und dem Betriebssystem selbst verstecken kann. Zusätzlich hat so ein Schädling meist auch Backdoor-Funktionalität, reißt also ganz bewußt Löcher durch alle Schutzmaßnahmen, damit er weiteren Schadcode nachladen oder die Daten, die er so sammelt, an die "bösen Jungs" weiterleiten kann. Was heißt das jetzt für dich?
__________________ |
![]() | #3 |
| ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? Vielen Dank erstmal für die Hilfe, was noch zu erwähnen wäre, ist dass ich den Account meiner Freundin zu Verfügung gestellt habe.
__________________1. Wieso sie das Windows pack hat, ist mir nicht bekannt, wird aber als privat pc benutzt. 2. Ich persönlich distanziere mich zu diesen Seiten, wie soll die Film Industrie denn sonst noch Geld verdienen? 3. Sie meinte dass sie das mit der Neuinstallation macht. Sie lässt Fragen ob sie bedenkenlos Word Dokumente, spiele saves und Bilder sichern und dann wieder auf den neuinstalllierten Rechner ziehen kann?. Nochmals vielen dank für die schnelle und gute Hilfe |
![]() | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus?Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
| ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? Also sie schrieb mich an, da ihr Internet dauernd abbrach. Wir sind dann auf die tpc Werte gestoßen. Och habe dann gegooglet und bin auf diese Seiten hier gestoßen. Da ich sie dannn ganz interessant fand hab ich mich hier angemeldet. Ich schrieb ihr dann dass sie sich mit ihrem Problem an euch in diesem Forum wenden solte. Sie schrieb dann dass man hier sich ja anmelden muss, hab ihr dann um den Vorgang zu verschnellern da ich mit ihr wieder schnellst möglich skypen wollte, meinen Account und mein passwort zu Verfügung gestellt |
![]() | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? Du hast ihr also deinen TB-Account zur Verfügung gestellt? Das erste Posting hatte sie verfasst, dann hast du geantwortet? ![]() Wie auch immer, sowas ist unschön, das erste Posting wurde aus der Ich-Perspektive verfasst und dann gehe ich davon aus, dass der eigentlich Autor auch so von seinem Rechner und nicht bei der nächsten Antwort wieder von einer dritten Person spricht Sag deiner Freundin, sie soll ein legales Windows installieren. Wenn sie das Win7 Ultimate legal hat ist ja alles kein Problem. Aber die Finger von illegalen Streamingseiten sollte sie unbedingt unterlassen. Bzgl der letzten Frage: ![]() Sichern von Daten eines infizierten Systems Mit einem Live-System sind keine Schädlinge des infizierten Windows-Systems aktiv, damit ist dann auch eine negative Beeinflussung des Backups durch Schädlinge ausgeschlossen. Du brauchst natürlich auch ein Sicherungsmedium, am besten dürfte eine externe Platte sein. Sofern du nicht allzuviel sichern musst, kann auch ein USB-Stick ausreichen. Anleitung: Parted Magic
__________________ --> Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? |
![]() | #7 |
| ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? 1. Genauso ![]() 2. das ultimate is legal gekauft, inzwischen is der pc neuinstalliert. -Close- danke für deine Hilfe |
![]() | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? Dann ist ja alles gut. Viel Erfolg! ![]()
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() |
Themen zu Windows 7: Ist mein TCP-Verbindungs Wert zu hoch? Hab ich einen Virus? |
.dll, adblock, adobe, defender, explorer, farbar, farbar recovery scan tool, frage, google, gophoto, homepage, iexplore.exe, internet, launch, monitor, mozilla, plug-in, problem, realtek, registry, ressourcenmonitor, rootkit, rundll, scan, services.exe, software, svchost.exe, system, temp, usb, virus, windows |