|
Log-Analyse und Auswertung: MS-DOS Datei runtergeladen! ;(Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.10.2013, 21:29 | #1 |
| MS-DOS Datei runtergeladen! ;( Hallo neues Forum, Meine Mutter hat heute eine E-mail bekommen in der sie eine Rechnung als Anhang öfnnen sollte. Ich habe daraufhin diese datei runtergeladen und die .zip datei entpackt. Daraufhin wollte ich die Heruntergeladenedatei gestartet doch als ich das tat war sie verschwunden. Toll Gleich gedacht Trjaner. im Internet gelesen und mein verdacht war richtig. ;( Jetzt habe ich die frage wie werde ich es wieder los ? ich habe es auf meiner Festplatte E:\ insterliert hilft mir das? mfg. F41L |
02.10.2013, 21:33 | #2 |
/// the machine /// TB-Ausbilder | MS-DOS Datei runtergeladen! ;( hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
02.10.2013, 21:52 | #3 |
| MS-DOS Datei runtergeladen! ;( FRST Logfile:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Jorrit (administrator) on JORRIT-PC on 02-10-2013 22:38:55 Running from C:\Users\Jorrit\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (cFos Software GmbH) C:\Program Files (x86)\ASRock Utility\XFast Lan\spd.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (cFos Software GmbH) C:\Program Files (x86)\ASRock Utility\XFast Lan\cfosspeed.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Saitek) C:\Program Files\Saitek\VolumeTracker\SaiVolume.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\SeaPort.exe (ESN Social Software AB) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 HKLM\...\Run: [XFast LAN] - C:\Program Files (x86)\ASRock Utility\XFast Lan\cFosSpeed.exe [1441152 2011-10-19] (cFos Software GmbH) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.) HKLM\...\Run: [SaiVolume] - C:\Program Files\Saitek\VolumeTracker\SaiVolume.exe [152064 2012-10-15] (Saitek) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [bobviyxb] - C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi\nrgqafiyxb.exe [83669 2013-10-02] () MountPoints2: H - H:\pushinst.exe MountPoints2: {45f733cf-6e4a-11e2-a681-806e6f6e6963} - F:\SETUP.EXE MountPoints2: {6dbea0a9-d9bd-11e2-9301-806e6f6e6963} - H:\pushinst.exe MountPoints2: {acdff396-6eb8-11e2-8796-806e6f6e6963} - G:\HTC_Sync_Manager_PC.exe MountPoints2: {aff99121-1459-11e3-a9c5-bc5ff46f17c0} - H:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {aff9912b-1459-11e3-a9c5-bc5ff46f17c0} - H:\setup_vmc_lite.exe /checkApplicationPresence HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation) HKLM-x32\...\Run: [THX TruStudio NB Settings] - C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation) HKLM-x32\...\Run: [XFastUSB] - C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-02-04] (FNet Co., Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-10-02] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-09-24] (APN) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-12] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x397BA609B66ACE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKCU - {5DF4CD1D-12DB-4EE9-A31B-B346F6E2399D} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=AFD3BD6C-67CC-43CC-BBD4-5A65726EA8C4&apn_sauid=80D5709F-1B73-4CFB-AFF1-EF0E82388B41 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jorrit\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File FF SearchPlugin: C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\searchplugins\bingp.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\ich@maltegoetz.de FF Extension: savedpasswordeditor - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\savedpasswordeditor@daniel.dawson.xpi FF Extension: toolbar_AVIRA-V7 - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi FF Extension: No Name - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "urls_to_restore_on_startup": [ CHR DefaultSearchURL: (Bing) - hxxp://www.bing.com/search?setmkt=de-DE&q={searchTerms} CHR DefaultSuggestURL: (Bing) - hxxp://api.bing.com/osjson.aspx?query={searchTerms}&language={language} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll () CHR Extension: (Angry Birds) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0 CHR Extension: (Google Docs) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (Turn Off the Lights) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.2.0.22_0 CHR Extension: (YouTube) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Apple Shooter) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbcjjgkapdombcilbfbjapkbpnocbkcf\2.0.0_0 CHR Extension: (The QR Code Generator) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcmhlmapohffdglflokbgknlknnmogbb\0.2.4_0 CHR Extension: (AdBlock) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.7_0 CHR Extension: (Dropbox) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.8_0 CHR Extension: (Freemake Video Converter) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0 CHR Extension: (Google Mail Checker) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Chrome to Phone) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.2_0 CHR Extension: (Battlefield 3) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pagmklehiaheilihklokljahmoihkjni\1_0 CHR Extension: (Gmail) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-10-02] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-10-02] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-10-02] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-09-24] (APN LLC.) R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-06-20] () R2 cFosSpeedS; C:\Program Files (x86)\ASRock Utility\XFast Lan\spd.exe [395136 2011-10-19] (cFos Software GmbH) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] () R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-01] () ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-10-02] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-10-02] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-02] (Avira Operations GmbH & Co. KG) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [132608 2009-06-29] (Huawei Technologies Co., Ltd.) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2013-05-11] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-02-04] (FNet Co., Ltd.) S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation) S3 RZMAELSTROMVADService; C:\Windows\System32\drivers\RzMaelstromVAD.sys [40696 2013-05-17] (Windows (R) Win 7 DDK provider) R3 SaiK0728; C:\Windows\System32\DRIVERS\SaiK0728.sys [180584 2012-12-05] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-10-02] () S3 cpuz136; \??\C:\Users\Jorrit\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 GPU-Z; \??\C:\Users\Jorrit\AppData\Local\Temp\GPU-Z.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-02 22:38 - 2013-10-02 22:38 - 00000000 ____D C:\FRST 2013-10-02 22:36 - 2013-10-02 22:37 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe 2013-10-02 22:36 - 2013-10-02 22:36 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe.part 2013-10-02 22:14 - 2013-10-02 22:14 - 00006856 _____ C:\Users\Jorrit\Documents\AdwCleaner[S0].txt 2013-10-02 22:10 - 2013-10-02 22:10 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-10-02 22:01 - 2013-10-02 22:15 - 00000000 ____D C:\AdwCleaner 2013-10-02 22:01 - 2013-10-02 22:00 - 01045226 _____ C:\Users\Jorrit\Downloads\adwcleaner_3.0.0.6.exe 2013-10-02 21:39 - 2013-10-02 21:39 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Avira 2013-10-02 21:38 - 2013-10-02 21:38 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-02 21:37 - 2013-10-02 21:37 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-10-02 21:37 - 2013-10-02 21:37 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2013-10-02 21:36 - 2013-10-02 21:36 - 00000000 ____D C:\ProgramData\APN 2013-10-02 21:35 - 2013-10-02 21:35 - 00002066 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-10-02 21:35 - 2013-10-02 21:35 - 00000000 ____D C:\ProgramData\Avira 2013-10-02 21:35 - 2013-10-02 21:35 - 00000000 ____D C:\Program Files (x86)\Avira 2013-10-02 21:35 - 2013-10-02 21:33 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-02 21:35 - 2013-10-02 21:33 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-02 21:35 - 2013-10-02 21:33 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-10-02 21:23 - 2013-10-02 21:23 - 02296952 _____ C:\Users\Jorrit\Downloads\avira_free_antivirus.exe 2013-10-02 21:20 - 2013-10-02 21:20 - 00000000 ___HD C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi 2013-10-02 21:19 - 2013-10-02 18:21 - 00083929 _____ C:\Users\Jorrit\Downloads\Forderung Inga Biernatzki 02.10.2013 der abgewiesenen Zahlung Ihrer Bestellung.zip 2013-10-01 17:43 - 2013-10-01 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-01 16:51 - 2013-10-01 16:51 - 00000000 ____D C:\Users\Jorrit\Documents\Battlefield 4 2013-09-30 16:27 - 2013-09-30 16:28 - 03820328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-09-27 18:40 - 2013-09-27 18:41 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118(1).exe 2013-09-26 21:06 - 2013-09-26 21:06 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118.exe 2013-09-26 17:53 - 2013-09-26 17:29 - 06040688 _____ (Microsoft Corporation) C:\Users\Jorrit\Downloads\SkyDriveSetup(1).exe 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SaiK0728_01009.Wdf 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____D C:\Program Files\Saitek 2013-09-21 21:25 - 2013-09-21 21:25 - 00000000 ____D C:\Users\Jorrit\Documents\Logitech Gaming Software 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Logitech 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\ProgramData\LogiShrd 2013-09-21 21:19 - 2013-09-21 21:19 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-21 21:19 - 2013-09-21 21:19 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Leadertech 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logitech 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logishrd 2013-09-21 21:12 - 2013-09-21 21:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\SmartTechnology 2013-09-21 20:44 - 2013-09-21 21:16 - 00000000 ____D C:\Program Files\SmartTechnology 2013-09-21 19:41 - 2013-09-21 19:41 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-21 19:40 - 2013-09-21 19:41 - 04502536 _____ (Mad catz ) C:\Users\Jorrit\Downloads\V7_Keyboard_SD7_0_23_0_x64_Drivers.exe 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\system32\NV 2013-09-21 19:39 - 2013-09-21 19:56 - 129201056 _____ (Mad catz ) C:\Users\Jorrit\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-09-21 19:35 - 2013-09-12 10:58 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-21 19:35 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-21 19:35 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-09-21 19:35 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-09-21 19:34 - 2013-09-21 19:49 - 56514904 _____ (Logitech Inc.) C:\Users\Jorrit\Downloads\LGS_8.50.281_x64_Logitech.exe 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-11 23:13 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 23:13 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 23:13 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 23:13 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 23:13 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 23:13 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 23:13 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 23:13 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 23:13 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 23:13 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 23:13 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 23:13 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 21:31 - 2013-09-11 22:22 - 653056624 _____ C:\Users\Jorrit\Downloads\Duden_Home.exe 2013-09-11 15:47 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 15:47 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 15:47 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 15:47 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 15:47 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 15:47 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 15:47 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 15:47 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 15:47 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 15:47 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 15:47 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 15:46 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 15:46 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 15:46 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 15:46 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 15:46 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 15:46 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 15:46 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 15:46 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 15:46 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 15:46 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-10 17:44 - 2013-09-10 17:44 - 00075264 _____ C:\Users\Jorrit\Downloads\2013-08-07_Klausurplanung_BG_Aug_2013_bis_Jan_2014_.xls 2013-09-09 16:19 - 2013-09-09 16:19 - 00015630 _____ C:\Users\Jorrit\Downloads\Umrechnen_08.09.2013.odt 2013-09-08 18:48 - 2013-09-26 18:06 - 00000000 ____D C:\Users\Jorrit\Documents\!Schule! 2013-09-08 14:48 - 2013-09-08 14:48 - 00000000 ____D C:\Users\Jorrit\AppData\Local\NVIDIA 2013-09-08 14:48 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-09-08 14:48 - 2013-08-20 15:32 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-09-08 14:48 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-09-08 14:04 - 2013-09-08 14:04 - 00001347 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-09-08 13:58 - 2013-09-12 10:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-08 13:58 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll 2013-09-08 13:58 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll 2013-09-08 13:09 - 2013-09-08 13:26 - 229594432 _____ (NVIDIA Corporation) C:\Users\Jorrit\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-09-08 12:59 - 2013-09-08 13:00 - 14660349 _____ C:\Users\Jorrit\Downloads\DirectX_11_Vista(1).zip 2013-09-03 19:00 - 2013-09-03 19:00 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-09-03 19:00 - 2013-09-03 19:00 - 00000000 ____D C:\Program Files\CPUID 2013-09-03 18:59 - 2013-09-03 18:59 - 01458872 _____ ( ) C:\Users\Jorrit\Downloads\cpu-z_1.66.1-setup-en.exe 2013-09-03 16:33 - 2013-09-03 16:33 - 02326976 _____ (Beepa Pty Ltd) C:\Users\Jorrit\Downloads\setup3599.exe 2013-09-03 15:51 - 2013-09-03 15:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_ZuneDriver_01_09_00.Wdf 2013-09-03 15:51 - 2013-09-03 15:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2013-09-03 14:20 - 2013-09-03 14:20 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\FLEXnet 2013-09-03 14:14 - 2013-09-03 14:14 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Vodafone 2013-09-03 14:14 - 2009-06-29 18:00 - 00132608 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbnet.sys 2013-09-03 14:14 - 2009-04-09 13:38 - 00116864 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2013-09-03 14:13 - 2013-09-03 14:13 - 13369276 _____ C:\Vodafone Mobile Connect.msi 2013-09-03 14:13 - 2013-09-03 14:13 - 00008464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SpOrder.dll 2013-09-03 14:13 - 2013-09-03 14:13 - 00000000 ____D C:\ProgramData\Vodafone 2013-09-03 14:13 - 2013-09-03 14:13 - 00000000 ____D C:\ProgramData\FLEXnet 2013-09-03 14:13 - 2013-09-03 14:12 - 00047616 _____ C:\1031.MST 2013-09-03 14:12 - 2013-09-03 14:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\{86DD38A2-C8BD-404A-A1BD-907F6B69C913} ==================== One Month Modified Files and Folders ======= 2013-10-02 22:38 - 2013-10-02 22:38 - 00000000 ____D C:\FRST 2013-10-02 22:37 - 2013-10-02 22:36 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe 2013-10-02 22:36 - 2013-10-02 22:36 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe.part 2013-10-02 22:36 - 2013-02-04 14:11 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-02 22:25 - 2013-03-04 11:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-02 22:18 - 2009-07-14 06:45 - 00015776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-02 22:18 - 2009-07-14 06:45 - 00015776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-02 22:15 - 2013-10-02 22:01 - 00000000 ____D C:\AdwCleaner 2013-10-02 22:15 - 2013-02-04 15:19 - 01398925 _____ C:\Windows\WindowsUpdate.log 2013-10-02 22:14 - 2013-10-02 22:14 - 00006856 _____ C:\Users\Jorrit\Documents\AdwCleaner[S0].txt 2013-10-02 22:12 - 2013-02-04 16:34 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Skype 2013-10-02 22:10 - 2013-10-02 22:10 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-10-02 22:10 - 2013-02-17 18:08 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-02 22:10 - 2013-02-04 14:11 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-02 22:10 - 2013-02-04 13:22 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-10-02 22:10 - 2013-02-04 13:07 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2013-10-02 22:10 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-02 22:10 - 2009-07-14 06:51 - 11859992 _____ C:\Windows\setupact.log 2013-10-02 22:09 - 2013-05-06 13:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-02 22:09 - 2013-02-04 13:08 - 00302732 _____ C:\Windows\PFRO.log 2013-10-02 22:00 - 2013-10-02 22:01 - 01045226 _____ C:\Users\Jorrit\Downloads\adwcleaner_3.0.0.6.exe 2013-10-02 21:39 - 2013-10-02 21:39 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Avira 2013-10-02 21:38 - 2013-10-02 21:38 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-10-02 21:37 - 2013-10-02 21:37 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-10-02 21:37 - 2013-10-02 21:37 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork 2013-10-02 21:36 - 2013-10-02 21:36 - 00000000 ____D C:\ProgramData\APN 2013-10-02 21:35 - 2013-10-02 21:35 - 00002066 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-10-02 21:35 - 2013-10-02 21:35 - 00000000 ____D C:\ProgramData\Avira 2013-10-02 21:35 - 2013-10-02 21:35 - 00000000 ____D C:\Program Files (x86)\Avira 2013-10-02 21:33 - 2013-10-02 21:35 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-10-02 21:33 - 2013-10-02 21:35 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-10-02 21:33 - 2013-10-02 21:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-10-02 21:23 - 2013-10-02 21:23 - 02296952 _____ C:\Users\Jorrit\Downloads\avira_free_antivirus.exe 2013-10-02 21:20 - 2013-10-02 21:20 - 00000000 ___HD C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi 2013-10-02 19:59 - 2013-02-04 13:22 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2013-10-02 18:21 - 2013-10-02 21:19 - 00083929 _____ C:\Users\Jorrit\Downloads\Forderung Inga Biernatzki 02.10.2013 der abgewiesenen Zahlung Ihrer Bestellung.zip 2013-10-02 16:15 - 2013-02-04 17:05 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-02 16:12 - 2013-02-04 17:05 - 00215416 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-02 16:07 - 2013-02-04 17:14 - 00000000 ____D C:\Users\Jorrit\AppData\Local\PunkBuster 2013-10-02 15:58 - 2013-05-06 14:06 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Mozilla 2013-10-01 17:43 - 2013-10-01 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-01 16:51 - 2013-10-01 16:51 - 00000000 ____D C:\Users\Jorrit\Documents\Battlefield 4 2013-10-01 16:50 - 2013-02-04 16:56 - 00000000 ____D C:\ProgramData\Origin 2013-10-01 03:37 - 2013-06-16 14:34 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-01 03:37 - 2013-02-04 17:05 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-01 03:37 - 2013-02-04 17:04 - 00319613 _____ C:\Windows\DirectX.log 2013-09-30 22:31 - 2009-07-14 19:58 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-09-30 22:31 - 2009-07-14 19:58 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-09-30 22:31 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-30 19:27 - 2013-04-14 00:03 - 00000765 _____ C:\Users\Public\Desktop\Gameforge Live.lnk 2013-09-30 16:53 - 2013-02-04 17:14 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-09-30 16:30 - 2013-02-04 17:10 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-09-30 16:28 - 2013-09-30 16:27 - 03820328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-09-27 18:41 - 2013-09-27 18:40 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118(1).exe 2013-09-26 22:36 - 2013-05-12 14:54 - 00000000 ___RD C:\Users\Jorrit\SkyDrive 2013-09-26 21:06 - 2013-09-26 21:06 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118.exe 2013-09-26 18:06 - 2013-09-08 18:48 - 00000000 ____D C:\Users\Jorrit\Documents\!Schule! 2013-09-26 17:53 - 2013-05-12 14:54 - 00002180 _____ C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk 2013-09-26 17:29 - 2013-09-26 17:53 - 06040688 _____ (Microsoft Corporation) C:\Users\Jorrit\Downloads\SkyDriveSetup(1).exe 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SaiK0728_01009.Wdf 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____D C:\Program Files\Saitek 2013-09-21 21:25 - 2013-09-21 21:25 - 00000000 ____D C:\Users\Jorrit\Documents\Logitech Gaming Software 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Logitech 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\ProgramData\LogiShrd 2013-09-21 21:19 - 2013-09-21 21:19 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-21 21:19 - 2013-09-21 21:19 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Leadertech 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logitech 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logishrd 2013-09-21 21:16 - 2013-09-21 20:44 - 00000000 ____D C:\Program Files\SmartTechnology 2013-09-21 21:12 - 2013-09-21 21:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\SmartTechnology 2013-09-21 19:56 - 2013-09-21 19:39 - 129201056 _____ (Mad catz ) C:\Users\Jorrit\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-09-21 19:49 - 2013-09-21 19:34 - 56514904 _____ (Logitech Inc.) C:\Users\Jorrit\Downloads\LGS_8.50.281_x64_Logitech.exe 2013-09-21 19:41 - 2013-09-21 19:41 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-21 19:41 - 2013-09-21 19:40 - 04502536 _____ (Mad catz ) C:\Users\Jorrit\Downloads\V7_Keyboard_SD7_0_23_0_x64_Drivers.exe 2013-09-21 19:41 - 2013-02-04 15:18 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\system32\NV 2013-09-20 19:25 - 2013-03-04 11:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-20 19:25 - 2013-03-04 11:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-20 19:25 - 2013-03-04 11:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-18 22:13 - 2013-07-24 20:13 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\.minecraft 2013-09-14 09:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-12 15:46 - 2013-02-03 23:57 - 00000000 ___RD C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 15:46 - 2013-02-03 23:57 - 00000000 ___RD C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 15:45 - 2009-07-14 06:45 - 00371200 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 10:58 - 2013-09-21 19:35 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-12 10:58 - 2013-09-21 19:35 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-09-12 10:58 - 2013-02-17 18:05 - 00022814 _____ C:\Windows\system32\nvinfo.pb 2013-09-12 09:25 - 2013-02-17 18:07 - 06599968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 03452192 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-09-12 09:25 - 2013-02-17 18:07 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-12 00:06 - 2013-02-17 18:07 - 03361114 _____ C:\Windows\system32\nvcoproc.bin 2013-09-11 23:13 - 2013-08-15 15:37 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:11 - 2013-03-03 20:16 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-11 23:11 - 2013-02-13 18:27 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 22:22 - 2013-09-11 21:31 - 653056624 _____ C:\Users\Jorrit\Downloads\Duden_Home.exe 2013-09-10 17:44 - 2013-09-10 17:44 - 00075264 _____ C:\Users\Jorrit\Downloads\2013-08-07_Klausurplanung_BG_Aug_2013_bis_Jan_2014_.xls 2013-09-09 16:19 - 2013-09-09 16:19 - 00015630 _____ C:\Users\Jorrit\Downloads\Umrechnen_08.09.2013.odt 2013-09-08 14:49 - 2013-02-17 18:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-09-08 14:48 - 2013-09-08 14:48 - 00000000 ____D C:\Users\Jorrit\AppData\Local\NVIDIA 2013-09-08 14:44 - 2013-02-17 18:06 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-09-08 14:04 - 2013-09-08 14:04 - 00001347 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-09-08 13:26 - 2013-09-08 13:09 - 229594432 _____ (NVIDIA Corporation) C:\Users\Jorrit\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-09-08 13:00 - 2013-09-08 12:59 - 14660349 _____ C:\Users\Jorrit\Downloads\DirectX_11_Vista(1).zip 2013-09-03 19:00 - 2013-09-03 19:00 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-09-03 19:00 - 2013-09-03 19:00 - 00000000 ____D C:\Program Files\CPUID 2013-09-03 18:59 - 2013-09-03 18:59 - 01458872 _____ ( ) C:\Users\Jorrit\Downloads\cpu-z_1.66.1-setup-en.exe 2013-09-03 16:33 - 2013-09-03 16:33 - 02326976 _____ (Beepa Pty Ltd) C:\Users\Jorrit\Downloads\setup3599.exe 2013-09-03 15:51 - 2013-09-03 15:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_ZuneDriver_01_09_00.Wdf 2013-09-03 15:51 - 2013-09-03 15:51 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2013-09-03 14:20 - 2013-09-03 14:20 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\FLEXnet 2013-09-03 14:14 - 2013-09-03 14:14 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Vodafone 2013-09-03 14:13 - 2013-09-03 14:13 - 13369276 _____ C:\Vodafone Mobile Connect.msi 2013-09-03 14:13 - 2013-09-03 14:13 - 00008464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SpOrder.dll 2013-09-03 14:13 - 2013-09-03 14:13 - 00000000 ____D C:\ProgramData\Vodafone 2013-09-03 14:13 - 2013-09-03 14:13 - 00000000 ____D C:\ProgramData\FLEXnet 2013-09-03 14:12 - 2013-09-03 14:13 - 00047616 _____ C:\1031.MST 2013-09-03 14:12 - 2013-09-03 14:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\{86DD38A2-C8BD-404A-A1BD-907F6B69C913} Some content of TEMP: ==================== C:\Users\Jorrit\AppData\Local\Temp\APNStub.exe C:\Users\Jorrit\AppData\Local\Temp\AutoRun.exe C:\Users\Jorrit\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Jorrit\AppData\Local\Temp\drm_dyndata_7330017.dll C:\Users\Jorrit\AppData\Local\Temp\drm_dyndata_7370014.dll C:\Users\Jorrit\AppData\Local\Temp\EAInstall.dll C:\Users\Jorrit\AppData\Local\Temp\eauninstall.exe C:\Users\Jorrit\AppData\Local\Temp\FreemakeVideoConverter_4.0.1.1.exe C:\Users\Jorrit\AppData\Local\Temp\IXP000.TMPwrar420d.exe C:\Users\Jorrit\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Jorrit\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Jorrit\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Jorrit\AppData\Local\Temp\nvSCPAPISvr.exe C:\Users\Jorrit\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Jorrit\AppData\Local\Temp\nvStInst.exe C:\Users\Jorrit\AppData\Local\Temp\ose00000.exe C:\Users\Jorrit\AppData\Local\Temp\SkypeSetup.exe C:\Users\Jorrit\AppData\Local\Temp\sonarinst.exe C:\Users\Jorrit\AppData\Local\Temp\SpOrder.dll C:\Users\Jorrit\AppData\Local\Temp\SpotifyUninstall.exe C:\Users\Jorrit\AppData\Local\Temp\ubi1404.tmp.exe C:\Users\Jorrit\AppData\Local\Temp\uninst1.exe C:\Users\Jorrit\AppData\Local\Temp\war3_Install.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-01 18:33 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013 Ran by Jorrit at 2013-10-02 22:42:21 Running from C:\Users\Jorrit\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.1.377) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.175) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168) Adobe Reader XI (11.0.04) - Deutsch (x32 Version: 11.0.04) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) Arma 2: DayZ Mod (x32) Asmedia ASM106x SATA Host Controller Driver (x32) ASRock App Charger v1.0.5 ASRock eXtreme Tuner v0.1.251 (x32) ASRock XFast RAM v2.0.9 Assassin's Creed Revelations 1.02 (x32 Version: 1.02) Aufstieg des Hexenkönigs™ (x32) Avira Free Antivirus (x32 Version: 13.0.0.4052) Avira SearchFree Toolbar (x32 Version: 12.5.1.1249) AVM FRITZ!WLAN (x32) Battlefield 3™ (x32 Version: 1.5.0.0) Battlefield 4™ Beta (x32 Version: 1.0.0.0) Battlelog Web Plugins (x32 Version: 2.3.0) BattlEye for OA Uninstall (x32) BattlEye Uninstall (x32) Bing Bar (x32 Version: 7.3.107.0) Bonjour (Version: 3.0.0.10) Call of Duty: Modern Warfare 3 - Multiplayer (x32) CPUID CPU-Z 1.66.1 D3DX10 (x32 Version: 15.4.2368.0902) DayZ Commander (x32 Version: 0.92.83) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Die Schlacht um Mittelerde™ II (x32) DiRT 3 (x32) Dota 2 (x32) Dota 2 Test (x32) ESN Sonar (x32 Version: 0.70.4) Far Cry 3 (x32 Version: 1.05) Fotogalerie (x32 Version: 16.4.3505.0912) Freemake Video Converter Version 4.0.1 (x32 Version: 4.0.1) FreeMind (x32 Version: 0.9.0) Gameforge Live 1.8.1 "Legend" (x32 Version: 1.8.1) GeForce Experience NvStream Client Components (Version: 0.1.87) GIMP 2.8.4 (Version: 2.8.4) Google Chrome (x32 Version: 29.0.1547.76) Gothic II - Die Nacht des Raben (x32) Gothic II (x32) Intel(R) Control Center (x32 Version: 1.2.1.1008) Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342) Intel(R) Management Engine Components (x32 Version: 8.0.3.1427) Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: 8.15.10.2761) Intel(R) Rapid Storage Technology (x32 Version: 11.2.0.1006) Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.4.220) Intel® Trusted Connect Service Client (Version: 1.23.605.1) IPTInstaller (x32 Version: 4.0.4) iTunes (Version: 11.0.4.4) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Logitech Gaming Software (Version: 8.45.88) Logitech Gaming Software 8.50 (Version: 8.50.281) Metin2 (x32) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft SkyDrive (HKCU Version: 17.0.2015.0811) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106) Minecraft1.5.2 (x32) Movie Maker (x32 Version: 16.4.3505.0912) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) Mozilla Maintenance Service (x32 Version: 24.0) Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) Need For Speed™ World (x32 Version: 1.0.0.0) NVIDIA 3D Vision Controller-Treiber 326.01 (Version: 326.01) NVIDIA 3D Vision Treiber 327.23 (Version: 327.23) NVIDIA GeForce Experience 1.6.1 (Version: 1.6.1) NVIDIA Grafiktreiber 327.23 (Version: 327.23) NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4) NVIDIA Install Application (Version: 2.1002.133.902) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2723) NVIDIA Systemsteuerung 327.23 (Version: 327.23) NVIDIA Update 8.3.14 (Version: 8.3.14) NVIDIA Update Components (Version: 8.3.14) NVIDIA Virtual Audio 1.2.5 (Version: 1.2.5) OpenAL (x32) OpenOffice 4.0.0 (x32 Version: 4.00.9702) Opera 12.15 (x32 Version: 12.15.1748) Origin (x32 Version: 9.2.1.4399) Photo Gallery (x32 Version: 16.4.3505.0912) PunkBuster Services (x32 Version: 0.993) Rapture3D 2.4.8 Game (x32) Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6482) Rome - Total War - Gold Edition (x32 Version: 1.6) Safrosoft RoX 1.4 (x32) SHIELD Streaming (Version: 1.05.28) Skype™ 6.6 (x32 Version: 6.6.106) Smart Technology Volume Tracker 7.0.23.0 (Version: 7.0.23.0) TeamSpeak 3 Client (Version: 3.0.10) TeamViewer 8 (x32 Version: 8.0.17292) THX TruStudio (x32 Version: 1.00.01) Tom Clancy's Ghost Recon Future Soldier (x32 Version: 1.8) Total War: ROME II (x32) Unity Web Player (HKCU Version: ) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32) Uplay (x32 Version: 3.0) Windows Live Communications Platform (x32 Version: 16.4.3505.0912) Windows Live Essentials (x32 Version: 16.4.3505.0912) Windows Live ID Sign-in Assistant (Version: 7.250.4311.0) Windows Live Installer (x32 Version: 16.4.3505.0912) Windows Live Photo Common (x32 Version: 16.4.3505.0912) Windows Live PIMT Platform (x32 Version: 16.4.3505.0912) Windows Live SOXE (x32 Version: 16.4.3505.0912) Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912) Windows Live UX Platform (x32 Version: 16.4.3505.0912) Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912) Windows Phone app for desktop (x32 Version: 1.0.1720.1) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) World of Tanks (x32) XFast LAN v6.61 (Version: 6.61) XFastUSB (x32 Version: 3.02.30) ==================== Restore Points ========================= 21-09-2013 18:45:05 Gerätetreiber-Paketinstallation: Mad Catz 21-09-2013 19:15:18 Smart Technology Programming Software 7.0.27.13 wird entfernt 21-09-2013 19:27:26 Gerätetreiber-Paketinstallation: Mad Catz Eingabegeräte (Human Interface Devices) 24-09-2013 10:40:16 Windows Update 27-09-2013 13:15:37 Windows Update 01-10-2013 01:36:00 DirectX wurde installiert 01-10-2013 01:37:25 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 01-10-2013 14:47:25 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0A42B753-3E5A-48EA-940C-DE64816EB9B1} - System32\Tasks\{63554E4F-3033-4CD4-ACB8-7D13746B7F06} => C:\Program Files (x86)\Warcraft III\Frozen Throne.exe Task: {3DEDB022-26FA-4195-9D9E-D8E4BD9C625F} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {522B9A88-5B75-419E-B27D-96D70FEB59F9} - System32\Tasks\{228EA3C0-38A9-4082-9D19-7F1B1E76D192} => C:\Program Files (x86)\Warcraft III\Frozen Throne.exe Task: {6ED486DC-2DE9-484F-B933-194E43234DA9} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {80003EC8-8052-498E-B755-292EEA49F982} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-04] (Google Inc.) Task: {A43318F8-5FC1-4D36-9223-E0C80F367BC4} - System32\Tasks\{86ED4CE8-AE3E-4051-9F35-029A615C87C8} => C:\Program Files (x86)\Warcraft III\Frozen Throne.exe Task: {B00916F0-F00A-4CDE-9C56-64E3D28B0CA8} - System32\Tasks\{97BCD7D9-D7DE-4600-A88D-D8BAA2701ECE} => C:\Program Files (x86)\Warcraft III\Frozen Throne.exe Task: {B1D1EF39-50C2-4D63-8470-5EE17D23F194} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-02-04] (Google Inc.) Task: {D15CC417-D99D-4658-ABEC-ACFF762C94F2} - System32\Tasks\{77C55A94-0336-490B-ADE0-60F6E06093BB} => C:\Program Files (x86)\Warcraft III\Frozen Throne.exe Task: {E2ED4AC8-4023-44D2-B3B8-2F3896D72218} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-20] (Adobe Systems Incorporated) Task: {E45ED850-2BEE-496F-AB01-E3C2DB1B1F3A} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {FFC4AC54-24FD-400D-886C-A468E7B21849} - System32\Tasks\{7E422216-A264-4E16-8177-9298643D50F2} => C:\Program Files (x86)\Warcraft III\Frozen Throne.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2013-02-17 18:05 - 2013-09-12 10:58 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-02-04 12:51 - 2012-05-21 04:38 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-02-04 13:48 - 2011-05-19 10:58 - 00246784 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2013-10-02 21:35 - 2013-10-02 21:32 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-04-21 21:44 - 2013-04-21 21:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 21:44 - 2013-04-21 21:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-02-04 13:48 - 2011-05-04 17:32 - 00094208 _____ () C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\de-DE\THXAudNB.resources.dll 2013-08-15 16:02 - 2013-08-15 16:02 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\d5fbd408c39e0de3296b93ac03a5c147\IsdiInterop.ni.dll 2013-02-04 12:55 - 2012-05-30 14:55 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-02-04 13:21 - 2012-02-21 13:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-10-01 17:43 - 2013-10-01 17:43 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-08-07 20:38 - 2013-08-07 20:38 - 02244504 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2013-08-07 20:38 - 2013-08-07 20:38 - 00158104 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2013-08-07 20:38 - 2013-08-07 20:38 - 00022424 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll 2013-09-25 16:44 - 2013-09-25 16:44 - 00283032 _____ () C:\Program Files (x86)\Battlelog Web Plugins\launcher-119.dll 2013-09-11 15:25 - 2013-09-11 15:25 - 16177544 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Jorrit\Downloads\GPU-Z.0.7.2.exe:BDU AlternateDataStreams: C:\Users\Jorrit\Downloads\Minecraft(1).exe:BDU AlternateDataStreams: C:\Users\Jorrit\Downloads\Minecraft.exe:BDU AlternateDataStreams: C:\Users\Jorrit\Downloads\minecraft_server.1.6.2.exe:BDU AlternateDataStreams: C:\Users\Jorrit\Downloads\WoT_internet_install_eu.exe:BDU ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Programmable Root Enumerator Description: Programming Support Class Guid: {678dcf40-e2e6-11d5-8cd5-e960089ea00a} Manufacturer: Mad Catz Service: SaiNtBus Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: cFosSpeed for faster Internet connections (NDIS 6) Description: cFosSpeed for faster Internet connections (NDIS 6) Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: cFosSpeed Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/02/2013 10:10:26 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (10/02/2013 08:31:37 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11014 Error: (10/02/2013 08:31:37 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11014 Error: (10/02/2013 08:31:37 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/02/2013 08:31:36 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10016 Error: (10/02/2013 08:31:36 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10016 Error: (10/02/2013 08:31:36 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/02/2013 08:31:35 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9017 Error: (10/02/2013 08:31:35 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9017 Error: (10/02/2013 08:31:35 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (10/02/2013 10:10:51 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (10/02/2013 03:57:53 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (10/01/2013 04:42:04 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (10/01/2013 07:14:36 AM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (09/30/2013 05:24:13 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (09/30/2013 05:21:32 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (09/30/2013 05:15:24 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (09/30/2013 04:47:47 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (09/30/2013 03:31:29 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cFosSpeed Error: (09/29/2013 08:26:37 PM) (Source: DCOM) (User: Jorrit-PC) Description: AnwendungsspezifischLokalAktivierung{D3DCB472-7261-43CE-924B-0704BD730D5F}{D3DCB472-7261-43CE-924B-0704BD730D5F}Jorrit-PCJorritS-1-5-21-4055101477-3450429827-836436164-1000LocalHost (unter Verwendung von LRPC) Microsoft Office Sessions: ========================= Error: (10/02/2013 10:10:26 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (10/02/2013 08:31:37 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11014 Error: (10/02/2013 08:31:37 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11014 Error: (10/02/2013 08:31:37 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/02/2013 08:31:36 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10016 Error: (10/02/2013 08:31:36 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10016 Error: (10/02/2013 08:31:36 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (10/02/2013 08:31:35 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9017 Error: (10/02/2013 08:31:35 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9017 Error: (10/02/2013 08:31:35 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second ==================== Memory info =========================== Percentage of memory in use: 65% Total physical RAM: 3978.42 MB Available physical RAM: 1381.26 MB Total Pagefile: 7955.02 MB Available Pagefile: 4789.57 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:259.76 GB) (Free:146 GB) NTFS Drive d: () (Fixed) (Total:19.68 GB) (Free:0.15 GB) FAT32 Drive e: () (Fixed) (Total:931.41 GB) (Free:649.06 GB) NTFS Drive g: (Expansion Drive) (Fixed) (Total:931.51 GB) (Free:176.88 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 279 GB) (Disk ID: A7A7A7A7) Partition 1: (Active) - (Size=260 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 1465FF97) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 932 GB) (Disk ID: 02009C84) Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ hoffe ich habe es richtig gemacht und du kannst etwas damit anfangen --- --- --- |
03.10.2013, 07:54 | #4 | |
/// the machine /// TB-Ausbilder | MS-DOS Datei runtergeladen! ;(Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.10.2013, 09:04 | #5 |
| MS-DOS Datei runtergeladen! ;(Code:
ATTFilter ComboFix 13-10-01.03 - Jorrit 03.10.2013 9:50.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3978.2073 [GMT 2:00] ausgeführt von:: c:\users\Jorrit\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\1376729507.bdinstall.bin c:\programdata\1376729509.bdinstall.bin c:\users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\preferences c:\windows\isRS-000.tmp c:\windows\SysWow64\frapsvid.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-09-03 bis 2013-10-03 )))))))))))))))))))))))))))))) . . 2013-10-03 07:56 . 2013-10-03 07:56 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-10-03 07:56 . 2013-10-03 07:56 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-10-03 07:53 . 2013-10-03 07:53 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8A96B620-126F-4314-ABC9-9C91D092CFB1}\offreg.dll 2013-10-03 07:41 . 2013-10-03 07:41 94656 ----a-w- c:\windows\system32\WPRO_41_2001woem.tmp 2013-10-02 20:38 . 2013-10-02 20:38 -------- d-----w- C:\FRST 2013-10-02 20:01 . 2013-10-02 20:15 -------- d-----w- C:\AdwCleaner 2013-10-02 19:36 . 2013-10-02 19:36 -------- d-----w- c:\programdata\APN 2013-10-02 19:35 . 2013-10-03 07:19 -------- d-----w- c:\programdata\Avira 2013-10-02 19:20 . 2013-10-02 19:20 -------- d--h--w- c:\users\Jorrit\AppData\Roaming\Ucybwxrjpi 2013-10-01 14:47 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8A96B620-126F-4314-ABC9-9C91D092CFB1}\mpengine.dll 2013-09-21 19:27 . 2013-09-21 19:27 -------- d-----w- c:\program files\Saitek 2013-09-21 19:20 . 2013-09-21 19:20 -------- d-----w- c:\programdata\LogiShrd 2013-09-21 19:20 . 2013-09-21 19:20 -------- d-----w- c:\users\Jorrit\AppData\Local\Logitech 2013-09-21 19:19 . 2013-09-21 19:19 -------- d-----w- c:\users\Jorrit\AppData\Roaming\Leadertech 2013-09-21 19:19 . 2013-09-21 19:19 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2013-09-21 19:19 . 2013-09-21 19:19 -------- d-----w- c:\program files\Logitech Gaming Software 2013-09-21 19:18 . 2013-09-21 19:18 -------- d-----w- c:\users\Jorrit\AppData\Roaming\Logitech 2013-09-21 19:18 . 2013-09-21 19:18 -------- d-----w- c:\users\Jorrit\AppData\Roaming\Logishrd 2013-09-21 19:12 . 2013-09-21 19:12 -------- d-----w- c:\users\Jorrit\AppData\Local\SmartTechnology 2013-09-21 18:44 . 2013-09-21 19:16 -------- d-----w- c:\program files\SmartTechnology 2013-09-21 17:41 . 2013-09-21 17:41 -------- d-----w- c:\program files (x86)\AGEIA Technologies 2013-09-21 17:40 . 2013-09-21 17:40 -------- d-----w- c:\windows\SysWow64\NV 2013-09-21 17:40 . 2013-09-21 17:40 -------- d-----w- c:\windows\system32\NV 2013-09-11 23:17 . 2013-09-11 23:17 571168 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2013-09-11 13:47 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys 2013-09-11 13:46 . 2013-08-02 02:12 6656 ----a-w- c:\windows\system32\apisetschema.dll 2013-09-08 12:48 . 2013-08-20 13:33 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2013-09-08 12:48 . 2013-08-20 13:32 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll 2013-09-08 12:48 . 2013-08-20 13:32 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2013-09-08 12:48 . 2013-09-08 12:48 -------- d-----w- c:\users\Jorrit\AppData\Local\NVIDIA 2013-09-08 11:58 . 2013-09-12 08:58 168616 ----a-w- c:\windows\system32\nvinitx.dll 2013-09-08 11:58 . 2013-09-12 08:58 15901448 ----a-w- c:\windows\system32\nvwgf2umx.dll 2013-09-08 11:58 . 2013-09-12 08:58 15703688 ----a-w- c:\windows\system32\nvd3dumx.dll 2013-09-08 11:58 . 2013-09-12 08:58 141336 ----a-w- c:\windows\SysWow64\nvinit.dll 2013-09-08 11:58 . 2013-09-12 08:58 13628208 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2013-09-08 11:58 . 2013-09-12 08:58 12947360 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2013-09-08 11:58 . 2013-09-12 08:58 1222824 ----a-w- c:\windows\SysWow64\nvumdshim.dll 2013-09-08 11:58 . 2013-06-21 12:06 1832224 ----a-w- c:\windows\system32\nvdispco6432049.dll 2013-09-08 11:58 . 2013-06-21 12:06 1511712 ----a-w- c:\windows\system32\nvdispgenco6432049.dll 2013-09-03 17:00 . 2013-09-03 17:00 -------- d-----w- c:\program files\CPUID 2013-09-03 14:16 . 2013-09-03 14:16 -------- d-----w- c:\users\Jorrit\AppData\Roaming\The Creative Assembly 2013-09-03 12:20 . 2013-09-03 12:20 -------- d-----w- c:\users\Jorrit\AppData\Roaming\FLEXnet 2013-09-03 12:14 . 2013-09-03 12:14 -------- d-----w- c:\users\Jorrit\AppData\Roaming\Vodafone 2013-09-03 12:14 . 2009-06-29 16:00 132608 ----a-w- c:\windows\system32\drivers\ewusbnet.sys 2013-09-03 12:14 . 2009-04-09 11:38 116864 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys 2013-09-03 12:13 . 2013-09-03 12:13 -------- d-----w- c:\programdata\Vodafone 2013-09-03 12:13 . 2013-09-03 12:13 -------- d-----w- c:\programdata\FLEXnet 2013-09-03 12:13 . 2013-09-03 12:13 13369276 ----a-w- C:\Vodafone Mobile Connect.msi 2013-09-03 12:13 . 2013-09-03 12:13 8464 ----a-w- c:\windows\SysWow64\SpOrder.dll 2013-09-03 12:12 . 2013-09-03 12:12 -------- d-----w- c:\users\Jorrit\AppData\Local\{86DD38A2-C8BD-404A-A1BD-907F6B69C913} . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-10-03 07:41 . 2013-02-04 11:07 34752 ----a-w- c:\windows\system32\drivers\WPRO_41_2001.sys 2013-10-02 21:09 . 2013-02-04 15:05 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-10-02 21:09 . 2013-02-04 15:05 215416 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-10-01 01:37 . 2013-02-04 15:05 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe 2013-09-30 14:53 . 2013-02-04 15:14 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-09-20 17:25 . 2013-03-04 09:05 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-09-20 17:25 . 2013-03-04 09:05 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-09-12 08:58 . 2013-02-25 22:32 2630304 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-09-12 08:58 . 2013-02-25 22:32 2986672 ----a-w- c:\windows\system32\nvapi64.dll 2013-09-12 08:58 . 2013-02-25 22:32 1412832 ----a-w- c:\windows\system32\nvumdshimx.dll 2013-09-12 07:25 . 2013-02-17 16:07 6599968 ----a-w- c:\windows\system32\nvcpl.dll 2013-09-12 07:25 . 2013-02-17 16:07 3452192 ----a-w- c:\windows\system32\nvsvc64.dll 2013-09-12 07:25 . 2013-02-17 16:07 920864 ----a-w- c:\windows\system32\nvvsvc.exe 2013-09-12 07:25 . 2013-02-17 16:07 63776 ----a-w- c:\windows\system32\nvshext.dll 2013-09-12 07:25 . 2013-02-17 16:07 2559776 ----a-w- c:\windows\system32\nvsvcr.dll 2013-09-12 07:25 . 2013-02-17 16:07 219424 ----a-w- c:\windows\system32\nvmctray.dll 2013-09-11 22:06 . 2013-02-17 16:07 3361114 ----a-w- c:\windows\system32\nvcoproc.bin 2013-09-11 21:11 . 2013-02-13 16:27 79143768 ----a-w- c:\windows\system32\MRT.exe 2013-08-07 02:22 . 2013-02-04 11:52 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-08-02 01:48 . 2013-09-11 13:47 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-07-25 09:25 . 2013-08-14 14:22 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-25 08:57 . 2013-08-14 14:22 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-24 18:13 . 2013-07-24 18:13 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-07-24 18:13 . 2013-02-12 16:04 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-07-24 18:13 . 2013-02-12 16:04 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-07-24 18:07 . 2013-07-24 18:07 212360 ----a-w- c:\programdata\1374688690.bdinstall.bin 2013-07-19 01:58 . 2013-08-14 14:22 2048 ----a-w- c:\windows\system32\tzres.dll 2013-07-19 01:41 . 2013-08-14 14:22 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2013-07-15 21:13 . 2013-07-15 21:13 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2013-07-15 21:13 . 2013-07-15 21:13 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2013-07-15 21:13 . 2013-07-15 21:13 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2013-07-15 21:13 . 2013-07-15 21:13 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll 2013-07-09 05:52 . 2013-08-14 14:27 224256 ----a-w- c:\windows\system32\wintrust.dll 2013-07-09 05:51 . 2013-08-14 14:22 1217024 ----a-w- c:\windows\system32\rpcrt4.dll 2013-07-09 05:46 . 2013-08-14 14:27 1472512 ----a-w- c:\windows\system32\crypt32.dll 2013-07-09 05:46 . 2013-08-14 14:27 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2013-07-09 05:46 . 2013-08-14 14:27 139776 ----a-w- c:\windows\system32\cryptnet.dll 2013-07-09 04:52 . 2013-08-14 14:22 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll 2013-07-09 04:52 . 2013-08-14 14:27 175104 ----a-w- c:\windows\SysWow64\wintrust.dll 2013-07-09 04:46 . 2013-08-14 14:27 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-07-09 04:46 . 2013-08-14 14:27 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-07-09 04:46 . 2013-08-14 14:27 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-07-06 06:03 . 2013-08-14 14:22 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-09-26 15:53 222832 ----a-w- c:\users\Jorrit\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-09-26 15:53 222832 ----a-w- c:\users\Jorrit\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-09-26 15:53 222832 ----a-w- c:\users\Jorrit\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432] "bobviyxb"="c:\users\Jorrit\AppData\Roaming\Ucybwxrjpi\nrgqafiyxb.exe" [2013-10-02 83669] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-06-07 56128] "THX TruStudio NB Settings"="c:\program files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe" [2011-05-19 909824] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-26 291608] "XFastUSB"="c:\program files (x86)\XFastUSB\XFastUsb.exe" [2013-02-04 5019360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392] "AVMWlanClient"="c:\program files (x86)\avmwlanstick\wlangui.exe" [2010-10-22 2105344] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys;c:\windows\SYSNATIVE\drivers\avmeject.sys [x] R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x] R3 cpuz136;cpuz136;c:\users\Jorrit\AppData\Local\Temp\cpuz136\cpuz136_x64.sys;c:\users\Jorrit\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbnet.sys [x] R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x] R3 fwlanusb4;FRITZ!WLAN N/G;c:\windows\system32\DRIVERS\fwlanusb4.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusb4.sys [x] R3 GPU-Z;GPU-Z;c:\users\Jorrit\AppData\Local\Temp\GPU-Z.sys;c:\users\Jorrit\AppData\Local\Temp\GPU-Z.sys [x] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x] R3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] R3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] R3 RZMAELSTROMVADService;Razer Surround Audio Enhancer Service;c:\windows\system32\drivers\RzMaelstromVAD.sys;c:\windows\SYSNATIVE\drivers\RzMaelstromVAD.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.3.107.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.3.107.0\BBSvc.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] S2 ISCTAgent;ISCT Always Updated Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.3.107.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.3.107.0\SeaPort.exe [x] S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x] S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 SaiK0728;SaiK0728;c:\windows\system32\DRIVERS\SaiK0728.sys;c:\windows\SYSNATIVE\DRIVERS\SaiK0728.sys [x] S3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys;c:\windows\SYSNATIVE\drivers\WPRO_41_2001.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-09-21 13:49 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-10-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-04 17:25] . 2013-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-04 12:11] . 2013-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-04 12:11] . 2013-10-03 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 12:41] . 2013-10-02 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 12:41] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-09-26 15:53 261744 ----a-w- c:\users\Jorrit\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-09-26 15:53 261744 ----a-w- c:\users\Jorrit\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-09-26 15:53 261744 ----a-w- c:\users\Jorrit\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-05-24 170304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-05-24 398656] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-05-24 440128] "THXCfg64"="c:\windows\system32\THXCfg64.dll" [2011-05-13 26624] "XFast LAN"="c:\program files (x86)\ASRock Utility\XFast Lan\cFosSpeed.exe" [2011-10-19 1441152] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496] "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-08-27 1028896] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2013-08-01 8290584] "SaiVolume"="c:\program files\Saitek\VolumeTracker\SaiVolume.exe" [2012-10-15 152064] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = https://www.google.de/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = fritz.box;*.local IE: An OneNote s&enden - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - ExtSQL: 2013-09-13 15:43; ich@maltegoetz.de; c:\users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\extensions\ich@maltegoetz.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-BattlEye for A2 - e:\steam\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe AddRemove-com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 - c:\program files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe AddRemove-Gothic II - c:\progra~1\JoWooD\GOTHIC~1\UNWISE.EXE AddRemove-Gothic II - Die Nacht des Raben - c:\progra~1\JoWooD\GOTHIC~1\UNWISE.EXE AddRemove-Metin2_is1 - e:\metin2\unins000.exe AddRemove-Safrosoft RoX_is1 - e:\rox\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-4055101477-3450429827-836436164-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (S-1-5-21-4055101477-3450429827-836436164-1000) @Denied: (2) (LocalSystem) "Progid"="ThunderbirdEML" . [HKEY_USERS\S-1-5-21-4055101477-3450429827-836436164-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-4055101477-3450429827-836436164-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:c9,48,1e,97,b7,f4,da,91,83,4c,a4,a7,0e,5d,ac,17,1b,a9,03,a6,e1,05,a3, d7,8b,8d,1f,89,c9,ae,75,3c,54,1f,c5,1e,17,ee,04,59,c6,d1,fa,5c,91,36,4e,50,\ "??"=hex:fd,a8,5e,85,e5,3a,14,6c,5d,88,3d,ef,18,d3,30,dd . [HKEY_USERS\S-1-5-21-4055101477-3450429827-836436164-1000\Software\SecuROM\License information*] "datasecu"=hex:d8,17,d4,d2,9a,52,44,ac,63,86,16,25,68,8d,bb,fd,1c,f0,f4,74,57, 85,32,92,fb,d0,99,58,97,72,41,18,b7,22,32,98,53,69,64,b8,d6,db,c1,f5,3c,5d,\ "rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-10-03 09:59:24 ComboFix-quarantined-files.txt 2013-10-03 07:59 . Vor Suchlauf: 11 Verzeichnis(se), 157.414.350.848 Bytes frei Nach Suchlauf: 20 Verzeichnis(se), 160.142.843.904 Bytes frei . - - End Of File - - 27F545A357ABB95951BCA8C232E4D761 bin jetzt aber 2 tage im urlaub kan erst samstag wieder antworten :/ dann mache ich alles weiter wie ihr es mir sagt danke auch schonmal obwohl ich überhaupt nciht weiß was ich mache |
04.10.2013, 01:32 | #6 |
/// the machine /// TB-Ausbilder | MS-DOS Datei runtergeladen! ;( Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> MS-DOS Datei runtergeladen! ;( |
04.10.2013, 22:59 | #7 |
| MS-DOS Datei runtergeladen! ;( so habe die letzten stunden mein Rechner mal Arbeiten gelassen und nun ist er fertig Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.04.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16686 Jorrit :: JORRIT-PC [Administrator] 04.10.2013 20:25:27 mbam-log-2013-10-04 (20-25-27).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|G:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: Registrierung | P2P Durchsuchte Objekte: 985422 Laufzeit: 1 Stunde(n), 53 Minute(n), 29 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 7 C:\AdwCleaner\Quarantine\C\Users\Jorrit\AppData\Local\Conduit\CT2832595\InnoGames_InternationalAutoUpdateHelper.exe.vir (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Users\Jorrit\AppData\Roaming\OpenCandy\248A31CDDFA04AE397DB524C850F3094\DeltaTB.exe.vir (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Jorrit\Downloads\FreemakeVideoConverterSetup_4.0.1.1.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. D:\Dokumente und Einstellungen\janes\Lokale Einstellungen\Temp\comver.dll (Adware.GameSpyArcade) -> Erfolgreich gelöscht und in Quarantäne gestellt. G:\Janes Festplatte\Dokumente und Einstellungen\Janes\Eigene Dateien\ACDSEE\ACDSEE241GERCRK.EXE (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. G:\Janes Festplatte\LAN\Daemon Tool v. 4.06.exe (Adware.WhenU) -> Erfolgreich gelöscht und in Quarantäne gestellt. G:\Janes Festplatte\Programme\ACDSee32\ACDSEE241GERCRK.EXE (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.3 (09.27.2013:1) OS: Windows 7 Home Premium x64 Ran by Jorrit on 04.10.2013 at 23:51:06.03 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4055101477-3450429827-836436164-1000\Software\SweetIM Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5DF4CD1D-12DB-4EE9-A31B-B346F6E2399D} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Jorrit\AppData\Roaming\mozilla\firefox\profiles\7ocspq43.default\minidumps [61 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.10.2013 at 23:52:41.06 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter # AdwCleaner v3.006 - Bericht erstellt am 04/10/2013 um 23:43:05 # Updated 01/10/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Jorrit - JORRIT-PC # Gestartet von : C:\Users\Jorrit\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Datei Gelöscht : C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\\invalidprefs.js Datei Gelöscht : C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\foxydeal.sqlite ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16686 -\\ Mozilla Firefox v24.0 (de) [ Datei : C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\prefs.js ] ************************* AdwCleaner[R0].txt - [7250 octets] - [02/10/2013 22:04:42] AdwCleaner[R1].txt - [1254 octets] - [02/10/2013 22:14:46] AdwCleaner[R2].txt - [1237 octets] - [04/10/2013 23:41:12] AdwCleaner[S0].txt - [6856 octets] - [02/10/2013 22:07:36] AdwCleaner[S1].txt - [1160 octets] - [04/10/2013 23:43:05] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1220 octets] ########## FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Jorrit (administrator) on JORRIT-PC on 04-10-2013 23:54:38 Running from C:\Users\Jorrit\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BBSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (cFos Software GmbH) C:\Program Files (x86)\ASRock Utility\XFast Lan\spd.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (cFos Software GmbH) C:\Program Files (x86)\ASRock Utility\XFast Lan\cfosspeed.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Saitek) C:\Program Files\Saitek\VolumeTracker\SaiVolume.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Farbar) C:\Users\Jorrit\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 HKLM\...\Run: [XFast LAN] - C:\Program Files (x86)\ASRock Utility\XFast Lan\cFosSpeed.exe [1441152 2011-10-19] (cFos Software GmbH) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.) HKLM\...\Run: [SaiVolume] - C:\Program Files\Saitek\VolumeTracker\SaiVolume.exe [152064 2012-10-15] (Saitek) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [bobviyxb] - C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi\nrgqafiyxb.exe [243712 2013-10-04] () HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation) HKLM-x32\...\Run: [THX TruStudio NB Settings] - C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation) HKLM-x32\...\Run: [XFastUSB] - C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-02-04] (FNet Co., Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-12] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x397BA609B66ACE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jorrit\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File FF SearchPlugin: C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\searchplugins\bingp.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\ich@maltegoetz.de FF Extension: savedpasswordeditor - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\savedpasswordeditor@daniel.dawson.xpi FF Extension: No Name - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Angry Birds) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0 CHR Extension: (Google Docs) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (Turn Off the Lights) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.2.0.22_0 CHR Extension: (YouTube) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Apple Shooter) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbcjjgkapdombcilbfbjapkbpnocbkcf\2.0.0_0 CHR Extension: (The QR Code Generator) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcmhlmapohffdglflokbgknlknnmogbb\0.2.4_0 CHR Extension: (AdBlock) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.7_0 CHR Extension: (Dropbox) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.8_0 CHR Extension: (Freemake Video Converter) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0 CHR Extension: (Google Mail Checker) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Chrome to Phone) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.2_0 CHR Extension: (Battlefield 3) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pagmklehiaheilihklokljahmoihkjni\1_0 CHR Extension: (Gmail) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-06-20] () R2 cFosSpeedS; C:\Program Files (x86)\ASRock Utility\XFast Lan\spd.exe [395136 2011-10-19] (cFos Software GmbH) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] () R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-01] () ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [132608 2009-06-29] (Huawei Technologies Co., Ltd.) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2013-05-11] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-02-04] (FNet Co., Ltd.) S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation) S3 RZMAELSTROMVADService; C:\Windows\System32\drivers\RzMaelstromVAD.sys [40696 2013-05-17] (Windows (R) Win 7 DDK provider) R3 SaiK0728; C:\Windows\System32\DRIVERS\SaiK0728.sys [180584 2012-12-05] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-10-04] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 cpuz136; \??\C:\Users\Jorrit\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 GPU-Z; \??\C:\Users\Jorrit\AppData\Local\Temp\GPU-Z.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-04 23:53 - 2013-10-04 23:54 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64(1).exe 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Documents\JRT.txt 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Desktop\JRT.txt 2013-10-04 23:50 - 2013-10-04 23:50 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-10-04 23:47 - 2013-10-04 23:47 - 01030305 _____ (Thisisu) C:\Users\Jorrit\Downloads\JRT.exe 2013-10-04 23:47 - 2013-10-04 23:47 - 00000000 ____D C:\Windows\ERUNT 2013-10-04 23:45 - 2013-10-04 23:45 - 00001300 _____ C:\Users\Jorrit\Documents\AdwCleaner[S1].txt 2013-10-04 23:40 - 2013-10-04 23:40 - 01045226 _____ C:\Users\Jorrit\Desktop\adwcleaner.exe 2013-10-04 20:15 - 2013-10-04 20:15 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Malwarebytes 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-04 20:15 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-04 20:12 - 2013-10-04 20:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jorrit\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-03 09:59 - 2013-10-03 09:59 - 00030528 _____ C:\ComboFix.txt 2013-10-03 09:48 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-10-03 09:48 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-10-03 09:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-10-03 09:47 - 2013-10-03 09:59 - 00000000 ____D C:\Qoobox 2013-10-03 09:47 - 2013-10-03 09:58 - 00000000 ____D C:\Windows\erdnt 2013-10-03 09:44 - 2013-10-03 09:46 - 05132885 ____R (Swearware) C:\Users\Jorrit\Desktop\ComboFix.exe 2013-10-02 22:42 - 2013-10-02 22:43 - 00025177 _____ C:\Users\Jorrit\Downloads\Addition.txt 2013-10-02 22:38 - 2013-10-02 22:38 - 00000000 ____D C:\FRST 2013-10-02 22:36 - 2013-10-02 22:37 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe 2013-10-02 22:36 - 2013-10-02 22:36 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe.part 2013-10-02 22:14 - 2013-10-02 22:14 - 00006856 _____ C:\Users\Jorrit\Documents\AdwCleaner[S0].txt 2013-10-02 22:01 - 2013-10-04 23:43 - 00000000 ____D C:\AdwCleaner 2013-10-02 22:01 - 2013-10-02 22:00 - 01045226 _____ C:\Users\Jorrit\Downloads\adwcleaner_3.0.0.6.exe 2013-10-02 21:35 - 2013-10-03 09:19 - 00000000 ____D C:\ProgramData\Avira 2013-10-02 21:23 - 2013-10-02 21:23 - 02296952 _____ C:\Users\Jorrit\Downloads\avira_free_antivirus.exe 2013-10-02 21:20 - 2013-10-02 21:20 - 00000000 ___HD C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi 2013-10-02 21:19 - 2013-10-02 18:21 - 00083929 _____ C:\Users\Jorrit\Downloads\Forderung Inga Biernatzki 02.10.2013 der abgewiesenen Zahlung Ihrer Bestellung.zip 2013-10-01 17:43 - 2013-10-01 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-01 16:51 - 2013-10-01 16:51 - 00000000 ____D C:\Users\Jorrit\Documents\Battlefield 4 2013-09-30 16:27 - 2013-09-30 16:28 - 03820328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-09-27 18:40 - 2013-09-27 18:41 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118(1).exe 2013-09-26 21:06 - 2013-09-26 21:06 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118.exe 2013-09-26 17:53 - 2013-09-26 17:29 - 06040688 _____ (Microsoft Corporation) C:\Users\Jorrit\Downloads\SkyDriveSetup(1).exe 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SaiK0728_01009.Wdf 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____D C:\Program Files\Saitek 2013-09-21 21:25 - 2013-09-21 21:25 - 00000000 ____D C:\Users\Jorrit\Documents\Logitech Gaming Software 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Logitech 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\ProgramData\LogiShrd 2013-09-21 21:19 - 2013-09-21 21:19 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-21 21:19 - 2013-09-21 21:19 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Leadertech 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logitech 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logishrd 2013-09-21 21:12 - 2013-09-21 21:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\SmartTechnology 2013-09-21 20:44 - 2013-09-21 21:16 - 00000000 ____D C:\Program Files\SmartTechnology 2013-09-21 19:41 - 2013-09-21 19:41 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-21 19:40 - 2013-09-21 19:41 - 04502536 _____ (Mad catz ) C:\Users\Jorrit\Downloads\V7_Keyboard_SD7_0_23_0_x64_Drivers.exe 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\system32\NV 2013-09-21 19:39 - 2013-09-21 19:56 - 129201056 _____ (Mad catz ) C:\Users\Jorrit\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-09-21 19:35 - 2013-09-12 10:58 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-21 19:35 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-21 19:35 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-09-21 19:35 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-09-21 19:34 - 2013-09-21 19:49 - 56514904 _____ (Logitech Inc.) C:\Users\Jorrit\Downloads\LGS_8.50.281_x64_Logitech.exe 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-11 23:13 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 23:13 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 23:13 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 23:13 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 23:13 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 23:13 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 23:13 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 23:13 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 23:13 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 23:13 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 23:13 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 23:13 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 21:31 - 2013-09-11 22:22 - 653056624 _____ C:\Users\Jorrit\Downloads\Duden_Home.exe 2013-09-11 15:47 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 15:47 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 15:47 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 15:47 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 15:47 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 15:47 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 15:47 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 15:47 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 15:47 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 15:47 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 15:47 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 15:46 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 15:46 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 15:46 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 15:46 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 15:46 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 15:46 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 15:46 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 15:46 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 15:46 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 15:46 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-10 17:44 - 2013-09-10 17:44 - 00075264 _____ C:\Users\Jorrit\Downloads\2013-08-07_Klausurplanung_BG_Aug_2013_bis_Jan_2014_.xls 2013-09-09 16:19 - 2013-09-09 16:19 - 00015630 _____ C:\Users\Jorrit\Downloads\Umrechnen_08.09.2013.odt 2013-09-08 18:48 - 2013-09-26 18:06 - 00000000 ____D C:\Users\Jorrit\Documents\!Schule! 2013-09-08 14:48 - 2013-09-08 14:48 - 00000000 ____D C:\Users\Jorrit\AppData\Local\NVIDIA 2013-09-08 14:48 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-09-08 14:48 - 2013-08-20 15:32 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-09-08 14:48 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-09-08 14:04 - 2013-09-08 14:04 - 00001347 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-09-08 13:58 - 2013-09-12 10:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-08 13:58 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll 2013-09-08 13:58 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll 2013-09-08 13:09 - 2013-09-08 13:26 - 229594432 _____ (NVIDIA Corporation) C:\Users\Jorrit\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-09-08 12:59 - 2013-09-08 13:00 - 14660349 _____ C:\Users\Jorrit\Downloads\DirectX_11_Vista(1).zip ==================== One Month Modified Files and Folders ======= 2013-10-04 23:54 - 2013-10-04 23:53 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64(1).exe 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Documents\JRT.txt 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Desktop\JRT.txt 2013-10-04 23:51 - 2013-02-04 16:34 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Skype 2013-10-04 23:50 - 2013-10-04 23:50 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-10-04 23:50 - 2013-02-17 18:08 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-04 23:50 - 2013-02-04 14:11 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-04 23:50 - 2013-02-04 13:22 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-10-04 23:50 - 2013-02-04 13:08 - 00307534 _____ C:\Windows\PFRO.log 2013-10-04 23:50 - 2013-02-04 13:07 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2013-10-04 23:50 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-04 23:50 - 2009-07-14 06:51 - 11979584 _____ C:\Windows\setupact.log 2013-10-04 23:49 - 2013-02-04 15:19 - 01724671 _____ C:\Windows\WindowsUpdate.log 2013-10-04 23:49 - 2009-07-14 06:45 - 00015776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-04 23:49 - 2009-07-14 06:45 - 00015776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-04 23:47 - 2013-10-04 23:47 - 01030305 _____ (Thisisu) C:\Users\Jorrit\Downloads\JRT.exe 2013-10-04 23:47 - 2013-10-04 23:47 - 00000000 ____D C:\Windows\ERUNT 2013-10-04 23:45 - 2013-10-04 23:45 - 00001300 _____ C:\Users\Jorrit\Documents\AdwCleaner[S1].txt 2013-10-04 23:43 - 2013-10-02 22:01 - 00000000 ____D C:\AdwCleaner 2013-10-04 23:40 - 2013-10-04 23:40 - 01045226 _____ C:\Users\Jorrit\Desktop\adwcleaner.exe 2013-10-04 23:36 - 2013-02-04 14:11 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-04 23:25 - 2013-03-04 11:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-04 21:13 - 2013-02-04 17:05 - 00215416 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-04 21:13 - 2013-02-04 17:05 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-04 20:15 - 2013-10-04 20:15 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Malwarebytes 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-04 20:13 - 2013-10-04 20:12 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jorrit\Downloads\mbam-setup-1.75.0.1300.exe 2013-10-04 19:59 - 2013-02-04 13:22 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2013-10-03 09:59 - 2013-10-03 09:59 - 00030528 _____ C:\ComboFix.txt 2013-10-03 09:59 - 2013-10-03 09:47 - 00000000 ____D C:\Qoobox 2013-10-03 09:58 - 2013-10-03 09:47 - 00000000 ____D C:\Windows\erdnt 2013-10-03 09:57 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-10-03 09:46 - 2013-10-03 09:44 - 05132885 ____R (Swearware) C:\Users\Jorrit\Desktop\ComboFix.exe 2013-10-03 09:19 - 2013-10-02 21:35 - 00000000 ____D C:\ProgramData\Avira 2013-10-02 22:43 - 2013-10-02 22:42 - 00025177 _____ C:\Users\Jorrit\Downloads\Addition.txt 2013-10-02 22:38 - 2013-10-02 22:38 - 00000000 ____D C:\FRST 2013-10-02 22:37 - 2013-10-02 22:36 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe 2013-10-02 22:36 - 2013-10-02 22:36 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe.part 2013-10-02 22:14 - 2013-10-02 22:14 - 00006856 _____ C:\Users\Jorrit\Documents\AdwCleaner[S0].txt 2013-10-02 22:09 - 2013-05-06 13:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-02 22:00 - 2013-10-02 22:01 - 01045226 _____ C:\Users\Jorrit\Downloads\adwcleaner_3.0.0.6.exe 2013-10-02 21:23 - 2013-10-02 21:23 - 02296952 _____ C:\Users\Jorrit\Downloads\avira_free_antivirus.exe 2013-10-02 21:20 - 2013-10-02 21:20 - 00000000 ___HD C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi 2013-10-02 18:21 - 2013-10-02 21:19 - 00083929 _____ C:\Users\Jorrit\Downloads\Forderung Inga Biernatzki 02.10.2013 der abgewiesenen Zahlung Ihrer Bestellung.zip 2013-10-02 16:07 - 2013-02-04 17:14 - 00000000 ____D C:\Users\Jorrit\AppData\Local\PunkBuster 2013-10-02 15:58 - 2013-05-06 14:06 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Mozilla 2013-10-01 17:43 - 2013-10-01 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-01 16:51 - 2013-10-01 16:51 - 00000000 ____D C:\Users\Jorrit\Documents\Battlefield 4 2013-10-01 16:50 - 2013-02-04 16:56 - 00000000 ____D C:\ProgramData\Origin 2013-10-01 03:37 - 2013-06-16 14:34 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-01 03:37 - 2013-02-04 17:05 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-01 03:37 - 2013-02-04 17:04 - 00319613 _____ C:\Windows\DirectX.log 2013-09-30 22:31 - 2009-07-14 19:58 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-09-30 22:31 - 2009-07-14 19:58 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-09-30 22:31 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-30 19:27 - 2013-04-14 00:03 - 00000765 _____ C:\Users\Public\Desktop\Gameforge Live.lnk 2013-09-30 16:53 - 2013-02-04 17:14 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-09-30 16:30 - 2013-02-04 17:10 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-09-30 16:28 - 2013-09-30 16:27 - 03820328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-09-27 18:41 - 2013-09-27 18:40 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118(1).exe 2013-09-26 22:36 - 2013-05-12 14:54 - 00000000 ___RD C:\Users\Jorrit\SkyDrive 2013-09-26 21:06 - 2013-09-26 21:06 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118.exe 2013-09-26 18:06 - 2013-09-08 18:48 - 00000000 ____D C:\Users\Jorrit\Documents\!Schule! 2013-09-26 17:53 - 2013-05-12 14:54 - 00002180 _____ C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk 2013-09-26 17:29 - 2013-09-26 17:53 - 06040688 _____ (Microsoft Corporation) C:\Users\Jorrit\Downloads\SkyDriveSetup(1).exe 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SaiK0728_01009.Wdf 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____D C:\Program Files\Saitek 2013-09-21 21:25 - 2013-09-21 21:25 - 00000000 ____D C:\Users\Jorrit\Documents\Logitech Gaming Software 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Logitech 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\ProgramData\LogiShrd 2013-09-21 21:19 - 2013-09-21 21:19 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-21 21:19 - 2013-09-21 21:19 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Leadertech 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logitech 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logishrd 2013-09-21 21:16 - 2013-09-21 20:44 - 00000000 ____D C:\Program Files\SmartTechnology 2013-09-21 21:12 - 2013-09-21 21:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\SmartTechnology 2013-09-21 19:56 - 2013-09-21 19:39 - 129201056 _____ (Mad catz ) C:\Users\Jorrit\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-09-21 19:49 - 2013-09-21 19:34 - 56514904 _____ (Logitech Inc.) C:\Users\Jorrit\Downloads\LGS_8.50.281_x64_Logitech.exe 2013-09-21 19:41 - 2013-09-21 19:41 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-21 19:41 - 2013-09-21 19:40 - 04502536 _____ (Mad catz ) C:\Users\Jorrit\Downloads\V7_Keyboard_SD7_0_23_0_x64_Drivers.exe 2013-09-21 19:41 - 2013-02-04 15:18 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\system32\NV 2013-09-20 19:25 - 2013-03-04 11:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-20 19:25 - 2013-03-04 11:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-20 19:25 - 2013-03-04 11:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-18 22:13 - 2013-07-24 20:13 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\.minecraft 2013-09-14 09:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-12 15:46 - 2013-02-03 23:57 - 00000000 ___RD C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 15:46 - 2013-02-03 23:57 - 00000000 ___RD C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 15:45 - 2009-07-14 06:45 - 00371200 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 10:58 - 2013-09-21 19:35 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-12 10:58 - 2013-09-21 19:35 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-09-12 10:58 - 2013-02-17 18:05 - 00022814 _____ C:\Windows\system32\nvinfo.pb 2013-09-12 09:25 - 2013-02-17 18:07 - 06599968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 03452192 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-09-12 09:25 - 2013-02-17 18:07 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-12 00:06 - 2013-02-17 18:07 - 03361114 _____ C:\Windows\system32\nvcoproc.bin 2013-09-11 23:13 - 2013-08-15 15:37 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:11 - 2013-03-03 20:16 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-11 23:11 - 2013-02-13 18:27 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 22:22 - 2013-09-11 21:31 - 653056624 _____ C:\Users\Jorrit\Downloads\Duden_Home.exe 2013-09-10 17:44 - 2013-09-10 17:44 - 00075264 _____ C:\Users\Jorrit\Downloads\2013-08-07_Klausurplanung_BG_Aug_2013_bis_Jan_2014_.xls 2013-09-09 16:19 - 2013-09-09 16:19 - 00015630 _____ C:\Users\Jorrit\Downloads\Umrechnen_08.09.2013.odt 2013-09-08 14:49 - 2013-02-17 18:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-09-08 14:48 - 2013-09-08 14:48 - 00000000 ____D C:\Users\Jorrit\AppData\Local\NVIDIA 2013-09-08 14:44 - 2013-02-17 18:06 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-09-08 14:04 - 2013-09-08 14:04 - 00001347 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-09-08 13:26 - 2013-09-08 13:09 - 229594432 _____ (NVIDIA Corporation) C:\Users\Jorrit\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-09-08 13:00 - 2013-09-08 12:59 - 14660349 _____ C:\Users\Jorrit\Downloads\DirectX_11_Vista(1).zip Some content of TEMP: ==================== C:\Users\Jorrit\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-01 18:33 ==================== End Of Log ============================ So und nun? mfg. |
05.10.2013, 11:21 | #8 |
/// the machine /// TB-Ausbilder | MS-DOS Datei runtergeladen! ;(ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.10.2013, 22:51 | #9 |
| MS-DOS Datei runtergeladen! ;(Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a3beb303f1eb6144be5429f741b28034 # engine=15365 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-05 05:17:20 # local_time=2013-10-05 07:17:20 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 69383 132623290 0 0 # scanned=789293 # found=4 # cleaned=0 # scan_time=13115 sh=D42E2A667553C0891A3DA0D634C064967F3657EF ft=1 fh=c0f64c44b64a0e08 vn="multiple threats" ac=I fn="C:\Users\Jorrit\Desktop\Maps\Download1337\daemon4124-lite.exe" sh=EABF9CC794CE93E6EB4575D1E70F5AC3DE58716E ft=0 fh=0000000000000000 vn="probably a variant of Win32/TrojanDownloader.Banload.GDOQIAO trojan" ac=I fn="C:\Users\Jorrit\Desktop\Maps\Download1337\Novos_Easy_Mangos_WotLK_v5.rar" sh=17A0044B5B38BAF9C71C1AA87E00220E2CF81DFB ft=0 fh=0000000000000000 vn="probably a variant of Win32/TrojanDropper.Agent.KIOAZOT trojan" ac=I fn="C:\Users\Jorrit\Desktop\Maps\Download1337\WoWMe_2_4_1.rar" sh=639601FF48D69CF7F27CBF3B82ACDB4CA3EE8FC8 ft=0 fh=0000000000000000 vn="Win32/Trustezeb.E trojan" ac=I fn="C:\Users\Jorrit\Downloads\Forderung Inga Biernatzki 02.10.2013 der abgewiesenen Zahlung Ihrer Bestellung.zip" Code:
ATTFilter Results of screen317's Security Check version 0.99.74 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 25 Java version out of Date! Adobe Flash Player 11.8.800.168 Adobe Reader XI Mozilla Firefox (24.0) Mozilla Thunderbird (17.0.8) Google Chrome 29.0.1547.66 Google Chrome 29.0.1547.76 ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Jorrit (administrator) on JORRIT-PC on 05-10-2013 23:48:32 Running from C:\Users\Jorrit\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WlanNetService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (cFos Software GmbH) C:\Program Files (x86)\ASRock Utility\XFast Lan\spd.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (cFos Software GmbH) C:\Program Files (x86)\ASRock Utility\XFast Lan\cfosspeed.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Saitek) C:\Program Files\Saitek\VolumeTracker\SaiVolume.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\SeaPort.exe (Electronic Arts) E:\Origin\Origin\Origin.exe (Logitech, Inc.) C:\Program Files\Logitech Gaming Software\LU_1\LULnchr.exe (Logitech, Inc.) C:\Program Files\Logitech Gaming Software\LU_1\LogitechUpdate.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Microsoft Corporation) C:\Windows\system32\calc.exe () C:\Users\Jorrit\Desktop\SecurityCheck.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 HKLM\...\Run: [XFast LAN] - C:\Program Files (x86)\ASRock Utility\XFast Lan\cFosSpeed.exe [1441152 2011-10-19] (cFos Software GmbH) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.) HKLM\...\Run: [SaiVolume] - C:\Program Files\Saitek\VolumeTracker\SaiVolume.exe [152064 2012-10-15] (Saitek) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [bobviyxb] - C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi\nrgqafiyxb.exe [243712 2013-10-04] () HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation) HKLM-x32\...\Run: [THX TruStudio NB Settings] - C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation) HKLM-x32\...\Run: [XFastUSB] - C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-02-04] (FNet Co., Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-12] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x397BA609B66ACE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jorrit\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File FF SearchPlugin: C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\searchplugins\bingp.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\ich@maltegoetz.de FF Extension: savedpasswordeditor - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\savedpasswordeditor@daniel.dawson.xpi FF Extension: No Name - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Jorrit\AppData\Roaming\Mozilla\Firefox\Profiles\7ocspq43.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ FF Extension: Freemake Video Converter Plugin - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Angry Birds) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0 CHR Extension: (Google Docs) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (Turn Off the Lights) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.2.0.22_0 CHR Extension: (YouTube) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Apple Shooter) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbcjjgkapdombcilbfbjapkbpnocbkcf\2.0.0_0 CHR Extension: (The QR Code Generator) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcmhlmapohffdglflokbgknlknnmogbb\0.2.4_0 CHR Extension: (AdBlock) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.7_0 CHR Extension: (Dropbox) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.8_0 CHR Extension: (Freemake Video Converter) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0 CHR Extension: (Google Mail Checker) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Chrome to Phone) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.2_0 CHR Extension: (Battlefield 3) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pagmklehiaheilihklokljahmoihkjni\1_0 CHR Extension: (Gmail) - C:\Users\Jorrit\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-06-20] () R2 cFosSpeedS; C:\Program Files (x86)\ASRock Utility\XFast Lan\spd.exe [395136 2011-10-19] (cFos Software GmbH) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] () R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-01] () ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [132608 2009-06-29] (Huawei Technologies Co., Ltd.) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2013-05-11] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-02-04] (FNet Co., Ltd.) S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation) S3 RZMAELSTROMVADService; C:\Windows\System32\drivers\RzMaelstromVAD.sys [40696 2013-05-17] (Windows (R) Win 7 DDK provider) R3 SaiK0728; C:\Windows\System32\DRIVERS\SaiK0728.sys [180584 2012-12-05] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-10-05] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 cpuz136; \??\C:\Users\Jorrit\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 GPU-Z; \??\C:\Users\Jorrit\AppData\Local\Temp\GPU-Z.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-05 23:48 - 2013-10-05 23:48 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe 2013-10-05 23:41 - 2013-10-05 23:41 - 00891167 _____ C:\Users\Jorrit\Desktop\SecurityCheck.exe 2013-10-05 15:34 - 2013-10-05 15:34 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-10-05 13:14 - 2013-10-05 13:14 - 02347384 _____ (ESET) C:\Users\Jorrit\Downloads\esetsmartinstaller_enu.exe 2013-10-05 13:14 - 2013-10-05 13:14 - 00000000 ____D C:\Program Files (x86)\ESET 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Documents\JRT.txt 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Desktop\JRT.txt 2013-10-04 23:47 - 2013-10-04 23:47 - 00000000 ____D C:\Windows\ERUNT 2013-10-04 23:45 - 2013-10-04 23:45 - 00001300 _____ C:\Users\Jorrit\Documents\AdwCleaner[S1].txt 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Malwarebytes 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-03 09:59 - 2013-10-03 09:59 - 00030528 _____ C:\ComboFix.txt 2013-10-03 09:48 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-10-03 09:48 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-10-03 09:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-10-03 09:48 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-10-03 09:47 - 2013-10-03 09:59 - 00000000 ____D C:\Qoobox 2013-10-03 09:47 - 2013-10-03 09:58 - 00000000 ____D C:\Windows\erdnt 2013-10-02 22:42 - 2013-10-02 22:43 - 00025177 _____ C:\Users\Jorrit\Downloads\Addition.txt 2013-10-02 22:38 - 2013-10-02 22:38 - 00000000 ____D C:\FRST 2013-10-02 22:14 - 2013-10-02 22:14 - 00006856 _____ C:\Users\Jorrit\Documents\AdwCleaner[S0].txt 2013-10-02 22:01 - 2013-10-04 23:43 - 00000000 ____D C:\AdwCleaner 2013-10-02 22:01 - 2013-10-02 22:00 - 01045226 _____ C:\Users\Jorrit\Downloads\adwcleaner_3.0.0.6.exe 2013-10-02 21:35 - 2013-10-03 09:19 - 00000000 ____D C:\ProgramData\Avira 2013-10-02 21:23 - 2013-10-02 21:23 - 02296952 _____ C:\Users\Jorrit\Downloads\avira_free_antivirus.exe 2013-10-02 21:20 - 2013-10-02 21:20 - 00000000 ___HD C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi 2013-10-02 21:19 - 2013-10-02 18:21 - 00083929 _____ C:\Users\Jorrit\Downloads\Forderung Inga Biernatzki 02.10.2013 der abgewiesenen Zahlung Ihrer Bestellung.zip 2013-10-01 17:43 - 2013-10-01 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-01 16:51 - 2013-10-01 16:51 - 00000000 ____D C:\Users\Jorrit\Documents\Battlefield 4 2013-09-30 16:27 - 2013-09-30 16:28 - 03820328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-09-27 18:40 - 2013-09-27 18:41 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118(1).exe 2013-09-26 21:06 - 2013-09-26 21:06 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118.exe 2013-09-26 17:53 - 2013-09-26 17:29 - 06040688 _____ (Microsoft Corporation) C:\Users\Jorrit\Downloads\SkyDriveSetup(1).exe 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SaiK0728_01009.Wdf 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____D C:\Program Files\Saitek 2013-09-21 21:25 - 2013-09-21 21:25 - 00000000 ____D C:\Users\Jorrit\Documents\Logitech Gaming Software 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Logitech 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\ProgramData\LogiShrd 2013-09-21 21:19 - 2013-09-21 21:19 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-21 21:19 - 2013-09-21 21:19 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Leadertech 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logitech 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logishrd 2013-09-21 21:12 - 2013-09-21 21:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\SmartTechnology 2013-09-21 20:44 - 2013-09-21 21:16 - 00000000 ____D C:\Program Files\SmartTechnology 2013-09-21 19:41 - 2013-09-21 19:41 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-21 19:40 - 2013-09-21 19:41 - 04502536 _____ (Mad catz ) C:\Users\Jorrit\Downloads\V7_Keyboard_SD7_0_23_0_x64_Drivers.exe 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\system32\NV 2013-09-21 19:39 - 2013-09-21 19:56 - 129201056 _____ (Mad catz ) C:\Users\Jorrit\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-09-21 19:35 - 2013-09-12 10:58 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-21 19:35 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-21 19:35 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-21 19:35 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-09-21 19:35 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-09-21 19:34 - 2013-09-21 19:49 - 56514904 _____ (Logitech Inc.) C:\Users\Jorrit\Downloads\LGS_8.50.281_x64_Logitech.exe 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-11 23:13 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-11 23:13 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-11 23:13 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-11 23:13 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-11 23:13 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-11 23:13 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-11 23:13 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-11 23:13 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-11 23:13 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-11 23:13 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-11 23:13 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-11 23:13 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-11 23:13 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-11 23:13 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-11 21:31 - 2013-09-11 22:22 - 653056624 _____ C:\Users\Jorrit\Downloads\Duden_Home.exe 2013-09-11 15:47 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-11 15:47 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-11 15:47 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-11 15:47 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-11 15:47 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-11 15:47 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-11 15:47 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-11 15:47 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-11 15:47 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-11 15:47 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-11 15:47 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-11 15:47 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-11 15:47 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-11 15:47 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-11 15:46 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-11 15:46 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-11 15:46 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-11 15:46 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-11 15:46 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-11 15:46 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-11 15:46 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-11 15:46 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-11 15:46 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-11 15:46 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-11 15:46 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-10 17:44 - 2013-09-10 17:44 - 00075264 _____ C:\Users\Jorrit\Downloads\2013-08-07_Klausurplanung_BG_Aug_2013_bis_Jan_2014_.xls 2013-09-09 16:19 - 2013-09-09 16:19 - 00015630 _____ C:\Users\Jorrit\Downloads\Umrechnen_08.09.2013.odt 2013-09-08 18:48 - 2013-09-26 18:06 - 00000000 ____D C:\Users\Jorrit\Documents\!Schule! 2013-09-08 14:48 - 2013-09-08 14:48 - 00000000 ____D C:\Users\Jorrit\AppData\Local\NVIDIA 2013-09-08 14:48 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-09-08 14:48 - 2013-08-20 15:32 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-09-08 14:48 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-09-08 14:04 - 2013-09-08 14:04 - 00001347 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-09-08 13:58 - 2013-09-12 10:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-08 13:58 - 2013-09-12 10:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-08 13:58 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll 2013-09-08 13:58 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll 2013-09-08 13:09 - 2013-09-08 13:26 - 229594432 _____ (NVIDIA Corporation) C:\Users\Jorrit\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-09-08 12:59 - 2013-09-08 13:00 - 14660349 _____ C:\Users\Jorrit\Downloads\DirectX_11_Vista(1).zip ==================== One Month Modified Files and Folders ======= 2013-10-05 23:48 - 2013-10-05 23:48 - 01954124 _____ (Farbar) C:\Users\Jorrit\Downloads\FRST64.exe 2013-10-05 23:41 - 2013-10-05 23:41 - 00891167 _____ C:\Users\Jorrit\Desktop\SecurityCheck.exe 2013-10-05 23:36 - 2013-02-04 14:11 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-05 23:35 - 2013-02-04 16:34 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Skype 2013-10-05 23:25 - 2013-03-04 11:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-05 22:38 - 2013-02-04 15:19 - 01863928 _____ C:\Windows\WindowsUpdate.log 2013-10-05 20:36 - 2013-02-04 14:11 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-05 19:59 - 2013-02-04 13:22 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2013-10-05 18:41 - 2009-07-14 06:51 - 12065956 _____ C:\Windows\setupact.log 2013-10-05 16:32 - 2013-02-04 17:05 - 00215416 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-05 16:32 - 2013-02-04 17:05 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-05 15:42 - 2009-07-14 06:45 - 00015776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-05 15:42 - 2009-07-14 06:45 - 00015776 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-05 15:34 - 2013-10-05 15:34 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-10-05 15:34 - 2013-02-17 18:08 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-05 15:34 - 2013-02-04 13:22 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-10-05 15:34 - 2013-02-04 13:08 - 00308536 _____ C:\Windows\PFRO.log 2013-10-05 15:34 - 2013-02-04 13:07 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2013-10-05 15:34 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-05 13:14 - 2013-10-05 13:14 - 02347384 _____ (ESET) C:\Users\Jorrit\Downloads\esetsmartinstaller_enu.exe 2013-10-05 13:14 - 2013-10-05 13:14 - 00000000 ____D C:\Program Files (x86)\ESET 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Documents\JRT.txt 2013-10-04 23:52 - 2013-10-04 23:52 - 00001116 _____ C:\Users\Jorrit\Desktop\JRT.txt 2013-10-04 23:47 - 2013-10-04 23:47 - 00000000 ____D C:\Windows\ERUNT 2013-10-04 23:45 - 2013-10-04 23:45 - 00001300 _____ C:\Users\Jorrit\Documents\AdwCleaner[S1].txt 2013-10-04 23:43 - 2013-10-02 22:01 - 00000000 ____D C:\AdwCleaner 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Malwarebytes 2013-10-04 20:15 - 2013-10-04 20:15 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-03 09:59 - 2013-10-03 09:59 - 00030528 _____ C:\ComboFix.txt 2013-10-03 09:59 - 2013-10-03 09:47 - 00000000 ____D C:\Qoobox 2013-10-03 09:58 - 2013-10-03 09:47 - 00000000 ____D C:\Windows\erdnt 2013-10-03 09:57 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-10-03 09:19 - 2013-10-02 21:35 - 00000000 ____D C:\ProgramData\Avira 2013-10-02 22:43 - 2013-10-02 22:42 - 00025177 _____ C:\Users\Jorrit\Downloads\Addition.txt 2013-10-02 22:38 - 2013-10-02 22:38 - 00000000 ____D C:\FRST 2013-10-02 22:14 - 2013-10-02 22:14 - 00006856 _____ C:\Users\Jorrit\Documents\AdwCleaner[S0].txt 2013-10-02 22:09 - 2013-05-06 13:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-02 22:00 - 2013-10-02 22:01 - 01045226 _____ C:\Users\Jorrit\Downloads\adwcleaner_3.0.0.6.exe 2013-10-02 21:23 - 2013-10-02 21:23 - 02296952 _____ C:\Users\Jorrit\Downloads\avira_free_antivirus.exe 2013-10-02 21:20 - 2013-10-02 21:20 - 00000000 ___HD C:\Users\Jorrit\AppData\Roaming\Ucybwxrjpi 2013-10-02 18:21 - 2013-10-02 21:19 - 00083929 _____ C:\Users\Jorrit\Downloads\Forderung Inga Biernatzki 02.10.2013 der abgewiesenen Zahlung Ihrer Bestellung.zip 2013-10-02 16:07 - 2013-02-04 17:14 - 00000000 ____D C:\Users\Jorrit\AppData\Local\PunkBuster 2013-10-02 15:58 - 2013-05-06 14:06 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Mozilla 2013-10-01 17:43 - 2013-10-01 17:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-01 16:51 - 2013-10-01 16:51 - 00000000 ____D C:\Users\Jorrit\Documents\Battlefield 4 2013-10-01 16:50 - 2013-02-04 16:56 - 00000000 ____D C:\ProgramData\Origin 2013-10-01 03:37 - 2013-06-16 14:34 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-01 03:37 - 2013-02-04 17:05 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-01 03:37 - 2013-02-04 17:04 - 00319613 _____ C:\Windows\DirectX.log 2013-09-30 22:31 - 2009-07-14 19:58 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-09-30 22:31 - 2009-07-14 19:58 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-09-30 22:31 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-30 19:27 - 2013-04-14 00:03 - 00000765 _____ C:\Users\Public\Desktop\Gameforge Live.lnk 2013-09-30 16:53 - 2013-02-04 17:14 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-09-30 16:30 - 2013-02-04 17:10 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-09-30 16:28 - 2013-09-30 16:27 - 03820328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-09-27 18:41 - 2013-09-27 18:40 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118(1).exe 2013-09-26 22:36 - 2013-05-12 14:54 - 00000000 ___RD C:\Users\Jorrit\SkyDrive 2013-09-26 21:06 - 2013-09-26 21:06 - 03819328 _____ C:\Users\Jorrit\Downloads\battlelog-web-plugins_2.3.0_118.exe 2013-09-26 18:06 - 2013-09-08 18:48 - 00000000 ____D C:\Users\Jorrit\Documents\!Schule! 2013-09-26 17:53 - 2013-05-12 14:54 - 00002180 _____ C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk 2013-09-26 17:29 - 2013-09-26 17:53 - 06040688 _____ (Microsoft Corporation) C:\Users\Jorrit\Downloads\SkyDriveSetup(1).exe 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SaiK0728_01009.Wdf 2013-09-21 21:27 - 2013-09-21 21:27 - 00000000 ____D C:\Program Files\Saitek 2013-09-21 21:25 - 2013-09-21 21:25 - 00000000 ____D C:\Users\Jorrit\Documents\Logitech Gaming Software 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\Users\Jorrit\AppData\Local\Logitech 2013-09-21 21:20 - 2013-09-21 21:20 - 00000000 ____D C:\ProgramData\LogiShrd 2013-09-21 21:19 - 2013-09-21 21:19 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2013-09-21 21:19 - 2013-09-21 21:19 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Leadertech 2013-09-21 21:19 - 2013-09-21 21:19 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logitech 2013-09-21 21:18 - 2013-09-21 21:18 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\Logishrd 2013-09-21 21:16 - 2013-09-21 20:44 - 00000000 ____D C:\Program Files\SmartTechnology 2013-09-21 21:12 - 2013-09-21 21:12 - 00000000 ____D C:\Users\Jorrit\AppData\Local\SmartTechnology 2013-09-21 19:56 - 2013-09-21 19:39 - 129201056 _____ (Mad catz ) C:\Users\Jorrit\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-09-21 19:49 - 2013-09-21 19:34 - 56514904 _____ (Logitech Inc.) C:\Users\Jorrit\Downloads\LGS_8.50.281_x64_Logitech.exe 2013-09-21 19:41 - 2013-09-21 19:41 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-09-21 19:41 - 2013-09-21 19:40 - 04502536 _____ (Mad catz ) C:\Users\Jorrit\Downloads\V7_Keyboard_SD7_0_23_0_x64_Drivers.exe 2013-09-21 19:41 - 2013-02-04 15:18 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-09-21 19:40 - 2013-09-21 19:40 - 00000000 ____D C:\Windows\system32\NV 2013-09-20 19:25 - 2013-03-04 11:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-20 19:25 - 2013-03-04 11:05 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-20 19:25 - 2013-03-04 11:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-09-18 22:13 - 2013-07-24 20:13 - 00000000 ____D C:\Users\Jorrit\AppData\Roaming\.minecraft 2013-09-14 09:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-09-12 15:46 - 2013-02-03 23:57 - 00000000 ___RD C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-12 15:46 - 2013-02-03 23:57 - 00000000 ___RD C:\Users\Jorrit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-12 15:45 - 2009-07-14 06:45 - 00371200 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 10:58 - 2013-09-21 19:35 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-12 10:58 - 2013-09-21 19:35 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-09-12 10:58 - 2013-09-21 19:35 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 01222824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-09-12 10:58 - 2013-09-08 13:58 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-09-12 10:58 - 2013-02-26 00:32 - 01412832 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-09-12 10:58 - 2013-02-17 18:05 - 00022814 _____ C:\Windows\system32\nvinfo.pb 2013-09-12 09:25 - 2013-02-17 18:07 - 06599968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 03452192 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 00920864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-09-12 09:25 - 2013-02-17 18:07 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-09-12 09:25 - 2013-02-17 18:07 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-09-12 01:17 - 2013-09-12 01:17 - 00571168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-09-12 00:06 - 2013-02-17 18:07 - 03361114 _____ C:\Windows\system32\nvcoproc.bin 2013-09-11 23:13 - 2013-08-15 15:37 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:11 - 2013-03-03 20:16 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-11 23:11 - 2013-02-13 18:27 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-11 22:22 - 2013-09-11 21:31 - 653056624 _____ C:\Users\Jorrit\Downloads\Duden_Home.exe 2013-09-10 17:44 - 2013-09-10 17:44 - 00075264 _____ C:\Users\Jorrit\Downloads\2013-08-07_Klausurplanung_BG_Aug_2013_bis_Jan_2014_.xls 2013-09-09 16:19 - 2013-09-09 16:19 - 00015630 _____ C:\Users\Jorrit\Downloads\Umrechnen_08.09.2013.odt 2013-09-08 14:49 - 2013-02-17 18:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-09-08 14:48 - 2013-09-08 14:48 - 00000000 ____D C:\Users\Jorrit\AppData\Local\NVIDIA 2013-09-08 14:44 - 2013-02-17 18:06 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-09-08 14:04 - 2013-09-08 14:04 - 00001347 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-09-08 13:26 - 2013-09-08 13:09 - 229594432 _____ (NVIDIA Corporation) C:\Users\Jorrit\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-09-08 13:00 - 2013-09-08 12:59 - 14660349 _____ C:\Users\Jorrit\Downloads\DirectX_11_Vista(1).zip Some content of TEMP: ==================== C:\Users\Jorrit\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-01 18:33 ==================== End Of Log ============================ so mein rechner mal wieder ein paar stunden arbeiten gelassen würdest du mir auch erklären was das alles überhaupt ist ? vielleicht kann man ja dann ncoh etwas lernen aber die programme scheinen ja immer etwas zu finden :/ mfg. F41L |
06.10.2013, 16:25 | #10 |
/// the machine /// TB-Ausbilder | MS-DOS Datei runtergeladen! ;( Überwiegend Adware. Die von ESET angemeckerten Funde in den Downloads bitte händisch löschen. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.10.2013, 18:09 | #11 |
| MS-DOS Datei runtergeladen! ;( Alles wunderbar danke |
10.10.2013, 08:45 | #12 |
/// the machine /// TB-Ausbilder | MS-DOS Datei runtergeladen! ;( Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.10.2013, 09:18 | #13 |
| MS-DOS Datei runtergeladen! ;( Alles Gute DANKE! |
10.10.2013, 09:27 | #14 |
/// the machine /// TB-Ausbilder | MS-DOS Datei runtergeladen! ;( Büdde
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu MS-DOS Datei runtergeladen! ;( |
.zip datei, adware.gamespyarcade, adware.whenu, anhang, datei, e-mail, festplatte, forum, frage, gestartet, heute, insterliert, inter, interne, internet, ms-dos, neues, platte, pup.optional.conduit.a, pup.optional.delta.a, pup.optional.opencandy, rechnung, runtergeladen, trojan.agent, verdacht |