|
Log-Analyse und Auswertung: Systemcheck meines pc´sWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.11.2013, 13:14 | #1 |
| Systemcheck meines pc´s Hallo ich würde gern mal jemandem über meinen pc schauen lassen um mögliche probleme etc. festzustellen und zu lösen danke schonmal im voraus |
11.11.2013, 13:36 | #2 |
/// the machine /// TB-Ausbilder | Systemcheck meines pc´s hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
11.11.2013, 14:24 | #3 |
| Systemcheck meines pc´s hier sind die die logs
__________________FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01 Ran by Andrč (administrator) on PÄRMERSENSER on 11-11-2013 12:16:35 Running from C:\Users\Andrč\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe ==================== Registry (Whitelisted) ================== MountPoints2: {929d72b7-8a59-11e1-9064-806e6f6e6963} - D:\Setup.exe MountPoints2: {d0312305-eaca-11e1-a829-60eb6968405e} - E:\Startme.exe HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-10] (AVAST Software) AppInit_DLLs: [97280 2009-07-14] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x33AE1D9EE91ECD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default FF NewTab: about:blank FF Homepage: about:home FF NetworkProxy: "http", "www-proxy.t-online.de" FF NetworkProxy: "http_port", 80 FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @TelevisionFanatic.com/Plugin - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll No File FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\ich@maltegoetz.de FF Extension: No Name - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\trash FF Extension: YouTube Unblocker - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\youtubeunblocker@unblocker.yt FF Extension: client - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\client@anonymox.net.xpi FF Extension: info - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\info@maltegoetz.de.xpi FF Extension: adblocker - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR Extension: () - C:\Users\ANDR~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html CHR HKLM-x32\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files (x86)\Movie2KDownloader.com\m2kDownloader10.crx ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-10] (AVAST Software) S4 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-01-29] (Nero AG) S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-08-12] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-08-12] (Microsoft Corporation) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [5038448 2013-01-03] (INCA Internet Co., Ltd.) S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-11-10] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-11-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-10] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-10] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-11-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-10] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-11-10] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-11-10] () S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2012-06-29] (Mobile Connector) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-05-03] (DT Soft Ltd) R1 HBtnKey; C:\Windows\System32\DRIVERS\wstbtndb.sys [9856 2007-09-14] (Lenovo) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP6\WNt500x64\Sandra.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va008; \??\C:\Windows\SysWOW64\Drivers\X6va008 [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-11 12:16 - 2013-11-11 12:16 - 00000000 ____D C:\FRST 2013-11-11 12:15 - 2013-11-11 12:15 - 01957590 _____ (Farbar) C:\Users\Andrč\Desktop\FRST64.exe 2013-11-11 00:15 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-11-11 00:15 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-11-11 00:15 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-11-11 00:15 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-11-11 00:15 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-11-11 00:15 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-11-11 00:15 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-11-11 00:15 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2013-11-11 00:15 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-11-11 00:15 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-11-11 00:15 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-11-11 00:15 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-11-11 00:15 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-11-11 00:15 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-11-11 00:15 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-11-11 00:15 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-11-11 00:15 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-11-11 00:15 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-11-11 00:15 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2013-11-11 00:15 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-11-11 00:15 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-11-11 00:15 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-11-11 00:15 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-11-11 00:15 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-11-11 00:12 - 2013-11-11 00:12 - 00347304 _____ (Microsoft Corporation) C:\Users\Andrč\Desktop\MicrosoftFixit.wu.RNP.33307551741428977.5.1.Run.exe 2013-11-10 20:20 - 2013-11-10 20:20 - 00000000 ____D C:\Windows\pss 2013-11-10 12:17 - 2013-11-10 12:17 - 00000000 ____D C:\Users\Andrč\AppData\Local\Apps\2.0 2013-11-10 12:16 - 2013-11-10 12:16 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-10 12:16 - 2013-11-10 12:16 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-11-10 12:14 - 2013-11-10 12:14 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\AVAST Software 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-11-10 11:53 - 2013-11-10 11:54 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-10 11:52 - 2012-08-24 19:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-10 11:52 - 2012-08-24 19:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-10 11:52 - 2012-08-24 19:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-10 11:52 - 2012-08-24 19:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-10 11:52 - 2012-08-24 17:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-10 11:52 - 2012-08-24 17:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-10 11:52 - 2012-08-24 17:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-10 11:52 - 2012-05-04 12:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-11-10 11:52 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-11-10 11:41 - 2013-11-10 11:41 - 00004122 _____ C:\Windows\System32\Tasks\FreeDriverScout 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-11-10 11:07 - 2013-11-10 12:16 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-10 09:46 - 2013-11-10 09:54 - 00007597 _____ C:\Users\Andrč\AppData\Local\resmon.resmoncfg 2013-11-10 08:40 - 2013-11-10 08:40 - 00000000 ____D C:\Windows\ERUNT 2013-11-10 08:24 - 2013-11-10 08:27 - 00000000 ____D C:\AdwCleaner 2013-11-10 08:11 - 2013-11-10 11:53 - 00000000 ____D C:\Users\Andrč\Desktop\Games 2013-11-10 07:34 - 2013-11-10 07:34 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Malwarebytes 2013-11-10 07:33 - 2013-11-10 07:33 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-10 04:59 - 2013-11-10 04:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 15:07 - 2013-11-05 15:07 - 00000000 ____D C:\Users\Andrč\AppData\Local\BigHugeEngine 2013-11-04 07:07 - 2013-11-04 07:07 - 00000000 ____D C:\Users\Andrč\Documents\FUSSBALL MANAGER 13 Demo 2013-11-01 01:48 - 2013-11-01 01:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Electronic_Arts_Inc 2013-11-01 01:23 - 2013-11-01 01:36 - 00000000 ____D C:\Users\Andrč\Downloads\games 2013-10-29 00:18 - 2013-10-29 00:18 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-10-28 23:47 - 2013-10-28 23:47 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-26 12:43 - 2013-10-26 12:43 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\vlc 2013-10-26 11:45 - 2013-10-26 11:45 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Program Files\Realtek 2013-10-26 11:03 - 2013-10-26 11:03 - 00000000 ____D C:\Program Files (x86)\Lenovo 2013-10-26 11:03 - 2013-05-24 10:59 - 03948544 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2013-10-26 11:00 - 2013-10-26 11:00 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\InstallShield 2013-10-26 10:53 - 2013-10-26 10:53 - 00000000 ____D C:\Program Files\ATI 2013-10-26 10:52 - 2013-10-26 10:52 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-26 10:51 - 2013-07-05 03:40 - 00110080 _____ (TODO: <Company name>) C:\Windows\system32\DelayAPO.dll 2013-10-26 10:51 - 2013-07-05 03:40 - 00096256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2013-10-26 10:50 - 2007-09-14 22:12 - 01459712 _____ C:\Windows\system32\wstbtnrb.dll 2013-10-26 10:50 - 2007-09-14 22:12 - 00009856 _____ (Lenovo) C:\Windows\system32\Drivers\wstbtndb.sys 2013-10-26 10:38 - 2013-10-26 10:38 - 00000000 ____D C:\Intel 2013-10-26 01:03 - 2013-10-26 01:04 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-10-26 01:03 - 2013-10-26 01:03 - 00000000 ____D C:\Users\Andrč\Documents\Freemium Driver Utilities 2013-10-26 01:02 - 2013-10-26 07:03 - 00004320 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-updater 2013-10-26 01:02 - 2013-10-26 01:02 - 00004226 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-codedownloader 2013-10-26 01:02 - 2013-10-26 01:02 - 00004124 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-enabler 2013-10-26 01:01 - 2013-10-26 01:01 - 00000000 ____D C:\Program Files\Covus Freemium 2013-10-24 19:38 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-24 19:32 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-24 19:32 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-24 19:32 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-24 19:32 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-24 19:32 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-24 19:32 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-24 19:32 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-24 19:32 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-24 19:32 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-24 19:32 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-24 19:32 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-24 19:32 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-24 19:32 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-24 19:32 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-24 19:32 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-24 19:14 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-10-24 19:14 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-10-24 19:14 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-10-24 19:14 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-10-24 19:14 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-10-24 19:14 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-10-24 19:14 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-10-24 19:14 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-10-24 19:13 - 2013-10-24 19:13 - 00000000 ____D C:\Users\Andrč\AppData\Local\DriverTuner 2013-10-24 19:10 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-10-24 19:10 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-10-24 19:10 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-10-24 19:10 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-10-24 19:10 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-10-24 19:10 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-10-24 19:10 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-10-24 19:10 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-10-24 19:10 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-10-24 19:10 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-10-24 19:10 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-10-24 19:10 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-10-24 19:10 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-10-24 19:10 - 2012-04-07 13:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2013-10-24 19:10 - 2012-04-07 12:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2013-10-24 19:09 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-24 19:09 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-24 19:09 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-24 19:09 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-24 19:09 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-24 19:09 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-10-24 19:09 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-24 19:09 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-24 19:09 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-24 19:09 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-24 19:09 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-24 19:09 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-10-24 19:09 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-10-24 19:09 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2013-10-24 19:09 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2013-10-24 19:09 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2013-10-24 19:09 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2013-10-24 19:09 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-10-24 19:09 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-10-24 19:09 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-10-24 19:09 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2013-10-24 19:09 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-10-24 19:09 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2013-10-24 19:09 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2013-10-24 19:09 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2013-10-24 19:09 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2013-10-24 19:09 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2013-10-24 19:09 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2013-10-24 19:09 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-10-24 19:09 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-10-24 19:09 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-10-24 19:09 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-10-24 19:09 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-10-24 19:09 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-10-24 19:09 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-10-24 19:09 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-10-24 19:09 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-10-24 19:08 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-10-24 19:08 - 2012-07-06 21:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2013-10-24 19:08 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-10-24 19:08 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2013-10-24 19:04 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-10-24 19:04 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2013-10-24 18:59 - 2013-10-24 18:59 - 00000000 ____D C:\Users\Andrč\AppData\Local\WindowsUpdate 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\Program Files (x86)\Covus Freemium 2013-10-24 16:48 - 2013-10-24 16:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Software Updater 2013-10-24 16:20 - 2013-10-24 16:20 - 00000000 ____D C:\Riot Games 2013-10-24 15:34 - 2013-11-04 08:54 - 00054692 _____ C:\Windows\DirectX.log 2013-10-24 15:11 - 2013-11-04 06:16 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-10-24 15:09 - 2013-11-05 15:06 - 00000000 ____D C:\Users\Andrč\AppData\Local\Origin 2013-10-24 15:06 - 2013-11-08 14:54 - 00000000 ____D C:\Program Files (x86)\Origin 2013-10-24 15:06 - 2013-11-05 15:07 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-10-24 15:05 - 2013-10-24 15:05 - 16957136 _____ (Electronic Arts, Inc.) C:\Users\Andrč\Downloads\OriginThinSetup.exe 2013-10-24 13:12 - 2013-10-24 13:16 - 181594458 _____ C:\Users\Andrč\Downloads\kofuma.exe 2013-10-24 13:12 - 2013-10-24 13:13 - 03896653 _____ C:\Users\Andrč\Downloads\kofuma.exe.part 2013-10-17 09:29 - 2013-10-17 09:29 - 29040552 _____ (Oracle Corporation) C:\Users\Andrč\Downloads\jre-7u45-windows-i586.exe 2013-10-17 00:24 - 2013-10-17 00:24 - 30363050 _____ (SRWare ) C:\Users\Andrč\Downloads\srware_iron.exe ==================== One Month Modified Files and Folders ======= 2013-11-11 12:16 - 2013-11-11 12:16 - 00000000 ____D C:\FRST 2013-11-11 12:15 - 2013-11-11 12:15 - 01957590 _____ (Farbar) C:\Users\Andrč\Desktop\FRST64.exe 2013-11-11 12:10 - 2012-04-19 21:02 - 01839854 _____ C:\Windows\WindowsUpdate.log 2013-11-11 12:08 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-11 12:08 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-11 12:03 - 2013-05-16 09:19 - 00034405 _____ C:\Windows\setupact.log 2013-11-11 12:03 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-11 11:51 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-11 11:00 - 2013-05-24 14:12 - 00004478 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-11-11 10:56 - 2012-10-12 12:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-11 00:12 - 2013-11-11 00:12 - 00347304 _____ (Microsoft Corporation) C:\Users\Andrč\Desktop\MicrosoftFixit.wu.RNP.33307551741428977.5.1.Run.exe 2013-11-10 20:20 - 2013-11-10 20:20 - 00000000 ____D C:\Windows\pss 2013-11-10 12:17 - 2013-11-10 12:17 - 00000000 ____D C:\Users\Andrč\AppData\Local\Apps\2.0 2013-11-10 12:16 - 2013-11-10 12:16 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-10 12:16 - 2013-11-10 12:16 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-11-10 12:16 - 2013-11-10 11:07 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-10 12:14 - 2013-11-10 12:14 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\AVAST Software 2013-11-10 12:13 - 2013-07-02 12:15 - 00000000 ____D C:\Users\Andrč\AppData\Local\HTC MediaHub 2013-11-10 12:11 - 2013-05-25 11:23 - 00115310 _____ C:\Windows\PFRO.log 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-11-10 11:54 - 2013-11-10 11:53 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-10 11:53 - 2013-11-10 08:11 - 00000000 ____D C:\Users\Andrč\Desktop\Games 2013-11-10 11:41 - 2013-11-10 11:41 - 00004122 _____ C:\Windows\System32\Tasks\FreeDriverScout 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-11-10 11:14 - 2012-05-15 20:46 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-11-10 11:07 - 2012-04-24 17:49 - 00000000 ____D C:\Windows\Minidump 2013-11-10 11:05 - 2013-03-20 14:50 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-11-10 11:05 - 2013-03-20 14:50 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-11-10 11:05 - 2012-04-20 12:40 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-11-10 11:05 - 2012-04-20 12:40 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-11-10 11:05 - 2012-04-20 12:39 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-11-10 11:05 - 2012-04-20 12:39 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-11-10 11:05 - 2012-04-20 12:39 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-11-10 11:05 - 2012-04-20 12:39 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-11-10 11:05 - 2012-04-20 12:37 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-11-10 11:03 - 2012-04-20 12:39 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-11-10 11:03 - 2012-04-20 12:37 - 00000000 ____D C:\ProgramData\AVAST Software 2013-11-10 10:48 - 2012-04-19 21:04 - 00000000 ___RD C:\Users\Andrč\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-10 10:10 - 2013-08-04 16:21 - 00000000 ____D C:\Users\Andrč\AppData\Local\PMB Files 2013-11-10 09:54 - 2013-11-10 09:46 - 00007597 _____ C:\Users\Andrč\AppData\Local\resmon.resmoncfg 2013-11-10 08:40 - 2013-11-10 08:40 - 00000000 ____D C:\Windows\ERUNT 2013-11-10 08:33 - 2013-02-23 04:47 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Spotify 2013-11-10 08:28 - 2013-09-29 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-10 08:27 - 2013-11-10 08:24 - 00000000 ____D C:\AdwCleaner 2013-11-10 08:27 - 2012-04-19 21:04 - 00000995 _____ C:\Users\Andrč\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-10 08:10 - 2013-08-04 16:21 - 00000000 ____D C:\ProgramData\PMB Files 2013-11-10 07:34 - 2013-11-10 07:34 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Malwarebytes 2013-11-10 07:33 - 2013-11-10 07:33 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-10 04:59 - 2013-11-10 04:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-09 18:07 - 2013-02-23 04:47 - 00000000 ____D C:\Users\Andrč\AppData\Local\Spotify 2013-11-08 14:54 - 2013-10-24 15:06 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-05 15:07 - 2013-11-05 15:07 - 00000000 ____D C:\Users\Andrč\AppData\Local\BigHugeEngine 2013-11-05 15:07 - 2013-10-24 15:06 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-11-05 15:07 - 2012-06-23 16:02 - 00000000 ____D C:\Users\Andrč\Documents\My Games 2013-11-05 15:06 - 2013-10-24 15:09 - 00000000 ____D C:\Users\Andrč\AppData\Local\Origin 2013-11-04 08:54 - 2013-10-24 15:34 - 00054692 _____ C:\Windows\DirectX.log 2013-11-04 07:07 - 2013-11-04 07:07 - 00000000 ____D C:\Users\Andrč\Documents\FUSSBALL MANAGER 13 Demo 2013-11-04 06:16 - 2013-10-24 15:11 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-11-01 01:48 - 2013-11-01 01:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Electronic_Arts_Inc 2013-11-01 01:36 - 2013-11-01 01:23 - 00000000 ____D C:\Users\Andrč\Downloads\games 2013-10-29 21:17 - 2009-07-14 18:58 - 00697098 _____ C:\Windows\system32\perfh007.dat 2013-10-29 21:17 - 2009-07-14 18:58 - 00148362 _____ C:\Windows\system32\perfc007.dat 2013-10-29 21:17 - 2009-07-14 06:13 - 01613412 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-29 06:12 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-29 00:18 - 2013-10-29 00:18 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-10-28 23:47 - 2013-10-28 23:47 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-28 23:47 - 2012-10-12 12:43 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-28 23:47 - 2012-05-15 20:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Adobe 2013-10-28 23:47 - 2012-04-20 13:03 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-28 23:47 - 2012-04-20 13:03 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-26 20:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-26 12:43 - 2013-10-26 12:43 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\vlc 2013-10-26 11:46 - 2012-04-19 22:16 - 00000000 ____D C:\Program Files (x86)\Intel 2013-10-26 11:45 - 2013-10-26 11:45 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Program Files\Realtek 2013-10-26 11:25 - 2013-05-24 14:11 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-26 11:03 - 2013-10-26 11:03 - 00000000 ____D C:\Program Files (x86)\Lenovo 2013-10-26 11:03 - 2012-04-20 13:21 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-26 11:00 - 2013-10-26 11:00 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\InstallShield 2013-10-26 10:53 - 2013-10-26 10:53 - 00000000 ____D C:\Program Files\ATI 2013-10-26 10:52 - 2013-10-26 10:52 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-26 10:38 - 2013-10-26 10:38 - 00000000 ____D C:\Intel 2013-10-26 07:03 - 2013-10-26 01:02 - 00004320 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-updater 2013-10-26 01:04 - 2013-10-26 01:03 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-10-26 01:03 - 2013-10-26 01:03 - 00000000 ____D C:\Users\Andrč\Documents\Freemium Driver Utilities 2013-10-26 01:02 - 2013-10-26 01:02 - 00004226 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-codedownloader 2013-10-26 01:02 - 2013-10-26 01:02 - 00004124 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-enabler 2013-10-26 01:01 - 2013-10-26 01:01 - 00000000 ____D C:\Program Files\Covus Freemium 2013-10-24 20:23 - 2013-04-23 12:28 - 01591306 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-24 19:58 - 2012-04-19 21:04 - 00000000 ____D C:\Users\Andrč 2013-10-24 19:46 - 2012-04-20 12:45 - 00000000 ____D C:\Users\Andrč\AppData\Local\Mozilla 2013-10-24 19:32 - 2013-05-16 09:22 - 00064408 _____ C:\Users\Andrč\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-24 19:23 - 2013-06-06 20:22 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-24 19:23 - 2013-06-06 20:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-24 19:23 - 2009-07-14 05:45 - 00295424 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-24 19:13 - 2013-10-24 19:13 - 00000000 ____D C:\Users\Andrč\AppData\Local\DriverTuner 2013-10-24 18:59 - 2013-10-24 18:59 - 00000000 ____D C:\Users\Andrč\AppData\Local\WindowsUpdate 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\Program Files (x86)\Covus Freemium 2013-10-24 16:48 - 2013-10-24 16:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Software Updater 2013-10-24 16:20 - 2013-10-24 16:20 - 00000000 ____D C:\Riot Games 2013-10-24 15:39 - 2013-07-27 14:56 - 00000000 ____D C:\ProgramData\Origin 2013-10-24 15:39 - 2012-06-23 16:02 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-10-24 15:05 - 2013-10-24 15:05 - 16957136 _____ (Electronic Arts, Inc.) C:\Users\Andrč\Downloads\OriginThinSetup.exe 2013-10-24 13:16 - 2013-10-24 13:12 - 181594458 _____ C:\Users\Andrč\Downloads\kofuma.exe 2013-10-24 13:13 - 2013-10-24 13:12 - 03896653 _____ C:\Users\Andrč\Downloads\kofuma.exe.part 2013-10-17 09:29 - 2013-10-17 09:29 - 29040552 _____ (Oracle Corporation) C:\Users\Andrč\Downloads\jre-7u45-windows-i586.exe 2013-10-17 00:25 - 2013-06-18 15:42 - 00000000 ____D C:\Program Files (x86)\SRWare Iron 2013-10-17 00:24 - 2013-10-17 00:24 - 30363050 _____ (SRWare ) C:\Users\Andrč\Downloads\srware_iron.exe Some content of TEMP: ==================== C:\Users\Andrč\AppData\Local\Temp\rootsupd.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 02:44 ==================== End Of Log ============================ Addiotion: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-11-2013 01 Ran by Andrč at 2013-11-11 12:17:38 Running from C:\Users\Andrč\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe AIR (x32 Version: 3.9.0.1030) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Adobe Shockwave Player 12.0 (x32 Version: 12.0.4.144) avast! Free Antivirus (x32 Version: 9.0.2007) DAEMON Tools Lite (x32 Version: 4.47.1.0333) DriverTuner 3.1.0.1 (x32 Version: 3.1.0.1) Extended Update (HKCU) Free Driver Scout (Version: 1.0.0.0) Free Driver Scout (x32 Version: 1.0.0.0) Free System Utilities (x32 Version: 1.1.3.0) Free SystemUtilities (x32 Version: 1.1.3.0) Free YouTube to MP3 Converter version 3.12.8.717 (x32 Version: 3.12.8.717) FUSSBALL MANAGER 13 Demo (x32 Version: 1.0.0.0) Google Update Helper (x32 Version: 1.3.23.0) HTC Driver Installer (x32 Version: 4.2.0.001) HTC Sync Manager (x32 Version: 2.0.61.0) Intel(R) Control Center (x32 Version: 1.2.1.1011) Intel(R) Management Engine Components (x32 Version: 6.2.50.1050) IPTInstaller (x32 Version: 4.0.8) Kingdoms of Amalur: Reckoning (x32 Version: 1.0.0.0) League of Legends (x32 Version: 3.0.1) McAfee Security Scan Plus (Version: 3.8.130.8) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000) Microsoft Security Client (Version: 4.3.0219.0) Microsoft Security Essentials (Version: 4.3.219.0) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft XML Parser (x32 Version: 8.70.1104.04) Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0) Mozilla Maintenance Service (x32 Version: 25.0) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Need for Speed Underground 2 (x32) Need For Speed™ World (x32 Version: 1.0.0.0) Nero Backup Drivers (Version: 1.0.11100.8.0) neroxml (x32 Version: 1.0.0) NVIDIA PhysX (x32 Version: 9.10.0513) OpenOffice.org 3.4 (x32 Version: 3.4.9590) Origin (x32 Version: 9.3.10.4710) Pando Media Booster (x32 Version: 2.6.0.7) PlanetSide 2 (HKCU) Prince of Persia T2T (x32) Realtek High Definition Audio Driver (x32 Version: 6.0.1.7037) SleepTimer Ultimate 1.2 (x32) Snap.Do (x32 Version: 1.149.1.12678) Spotify (HKCU Version: 0.9.4.185.g7545a404) SRWare Iron Version SRWare Iron 29.0.1600.1 (x32 Version: SRWare Iron 29.0.1600.1) swMSM (x32 Version: 12.0.0.1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) VCRedistSetup (x32 Version: 1.0.0) VLC media player 2.1.0 (x32 Version: 2.1.0) WebEnhance (x32) WhiteCap (x32 Version: 5.2.2) WinRAR 4.11 (32-Bit) (x32 Version: 4.11.0) ==================== Restore Points ========================= 04-11-2013 05:50:45 DirectX wurde installiert 04-11-2013 07:52:44 DirectX wurde installiert 05-11-2013 06:58:11 Windows Update 08-11-2013 16:44:30 Windows Update 10-11-2013 10:03:41 avast! antivirus system restore point 10-11-2013 10:05:46 Free System Utilities 10.11.2013 11:05:46 10-11-2013 10:19:09 avast! antivirus system restore point 10-11-2013 11:12:06 avast! antivirus system restore point 10-11-2013 23:14:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {042D69FB-5A96-4226-90C2-3475E9DB858C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-28] (Adobe Systems Incorporated) Task: {0C388C26-0167-4BCA-8184-CF9751BC7964} - \DealPly No Task File Task: {0F570F0E-AA15-4975-AF26-77C6842CA540} - System32\Tasks\{F8A6D428-5169-42A8-AC9D-C4AD03D3D5CA} => C:\Program Files (x86)\EA GAMES\Need for Speed Underground 2\speed2.exe [2004-10-23] () Task: {11B3D2EC-22BD-4DD6-B825-C26EAAAEB7E5} - System32\Tasks\{2D57564F-7578-42AF-B378-61D0BECD4A8A} => C:\Users\Andrč\Desktop\CrossFire_NA.exe Task: {1ABCC00B-FC07-4AB4-852D-C5E9A0A86A55} - System32\Tasks\{BA00EC27-BA1A-4CB5-84D4-96688667CF3C} => C:\Users\Andrč\Desktop\CrossFire_NA.exe Task: {3E98F8A8-0AC5-4608-A7A5-B9CB3607CA23} - System32\Tasks\{455AE924-AB14-4DBF-973B-ACF83CCBFC1A} => C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE Task: {4B44661F-2FAB-49A9-94F0-12DCE8D5A2C7} - System32\Tasks\{6EA5365A-F660-4A9E-A74B-B9266B045522} => C:\Program Files (x86)\EA GAMES\Need for Speed Underground 2\speed2.exe [2004-10-23] () Task: {53387CB4-B23A-4BFE-8811-BABE39396E65} - System32\Tasks\{333EBECF-CA8B-43A7-9BEE-9253F8880974} => C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE Task: {53B3688E-8406-405E-BE6C-11DEE4C8DF55} - System32\Tasks\{E76A156C-D802-48C2-87E2-8400D87F36B5} => C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE Task: {5C948FA7-EA90-40FC-9860-27CDD7641594} - System32\Tasks\FreeDriverScout => C:\Program Files\Covus Freemium\Free Driver Scout\1Click.exe [2013-10-24] () Task: {63692BB0-556F-4E17-A167-08629E1BDF5C} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated) Task: {6418E86E-7A19-4171-A66A-7EB89F7D2450} - System32\Tasks\{C2F9979E-CC08-431D-B74C-E2C0D23775C0} => C:\Users\Andrč\Desktop\CrossFire_NA.exe Task: {734D8351-7A0B-4529-AE09-44D489BC3788} - System32\Tasks\{563CE4B1-1AAC-4B42-A6C2-166BCDE4E20E} => C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE Task: {93EDB8FB-3C86-4498-AF87-6AE935D65CE5} - \Software Updater Ui No Task File Task: {93FE9DC0-5B85-4CD1-A3AB-CBA8C65723F8} - System32\Tasks\{550DC7FB-A217-48F5-917D-F7914DCB676D} => C:\Program Files (x86)\EA GAMES\Need for Speed Underground 2\speed2.exe [2004-10-23] () Task: {95D367F6-B463-44C9-A959-F0B67E2879BF} - System32\Tasks\Freemium1ClickMaint => C:\Program Files (x86)\Covus Freemium\Free System Utilities\1Click.exe [2013-09-23] (Covus Freemium GmbH) Task: {AF1B4980-CF61-49AB-957D-758B1939765E} - System32\Tasks\{A640CA30-69F6-477D-B1F8-BDACBB7780AC} => C:\Users\Andrč\Desktop\CrossFire_NA.exe Task: {B15C1346-73CE-4E40-A8BF-E4B66051F26B} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {B3C0EFA1-8B68-4340-B13A-1E0D86A58D16} - System32\Tasks\{C02CB30A-BD72-47B6-A7EB-F8BFF579DC9F} => F:\Games\Bioshock Infinite - Pre - Cracked\Binaries\Win32\STARTGAME.exe Task: {C78B69A1-4FC2-46AD-8EC9-E674C1051498} - \UpdaterEX No Task File Task: {C9FE9369-8145-49FC-8EC5-5B9138EA62A8} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-11-10] (AVAST Software) Task: {CAAB65E8-82FA-4C03-8A8D-1D6F3AC95BB6} - System32\Tasks\{990BFF90-1AB5-4540-B649-D8E9D00E36F0} => C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE Task: {CE012A64-5345-412E-919B-3BDC1C72C372} - \DSite No Task File Task: {E8EF3D2D-EEB3-409F-BF30-89CBCEF27DE8} - System32\Tasks\{9D77F20C-2EB1-4057-A40C-580BB9AA5DE1} => F:\Games\Bioshock Infinite - Pre - Cracked\Binaries\Win32\BioShockInfinite.exe Task: {EF05E0D3-1B50-4B9A-8CF1-488DC7674575} - System32\Tasks\{723F5847-E97B-4DC7-844B-D27BDC9CB4DA} => C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE Task: {F39D9FED-A522-46D3-A0AB-002D97CF7D79} - \Software Updater No Task File Task: {FA8AA181-F3B5-4ED0-98A1-401F964FC7D7} - \Funmoods No Task File Task: {FC05C63F-7752-49F7-B982-8265A2B05556} - System32\Tasks\{0C35478F-4F7A-4779-8CA5-E62C69BDED81} => C:\Program Files (x86)\EA SPORTS\FUSSBALL MANAGER 2005\FM2005.EXE Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-11-11 00:55 - 2013-11-10 23:41 - 02140672 _____ () C:\Program Files\AVAST Software\Avast\defs\13111002\algo.dll 2013-11-10 11:05 - 2013-11-10 11:05 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-06-18 15:43 - 2013-09-08 17:23 - 00881152 _____ () C:\Program Files (x86)\SRWare Iron\libglesv2.dll 2013-06-18 15:43 - 2013-09-08 17:33 - 00102912 _____ () C:\Program Files (x86)\SRWare Iron\libegl.dll 2013-06-18 15:42 - 2013-09-08 17:03 - 00861696 _____ () C:\Program Files (x86)\SRWare Iron\ffmpegsumo.dll 2013-10-09 10:56 - 2013-10-28 23:47 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/10/2013 00:43:58 PM) (Source: Application Hang) (User: ) Description: Programm iron.exe, Version 29.0.1600.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 928 Startzeit: 01cede06da7e9e69 Endzeit: 20 Anwendungspfad: C:\Program Files (x86)\SRWare Iron\iron.exe Berichts-ID: 5d1ee3bc-49fd-11e3-a959-60eb6968405e Error: (11/10/2013 11:53:20 AM) (Source: Microsoft Security Client Setup) (User: PÄRMERSENSER) Description: HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation was canceled. You canceled the Security Essentials installation on your computer. Error code:0x8004FF0A. Error: (11/10/2013 11:49:04 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000053290 ID des fehlerhaften Prozesses: 0xe88 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/10/2013 11:39:55 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000028389 ID des fehlerhaften Prozesses: 0xe08 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/10/2013 11:32:00 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000374 Fehleroffset: 0x00000000000c4102 ID des fehlerhaften Prozesses: 0xfcc Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/10/2013 11:08:21 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000374 Fehleroffset: 0x00000000000c4102 ID des fehlerhaften Prozesses: 0x40c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/10/2013 10:36:20 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (11/10/2013 09:14:19 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (11/10/2013 09:14:15 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (11/10/2013 09:14:15 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (11/11/2013 11:53:41 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet: %%13 Error: (11/10/2013 08:48:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (11/10/2013 08:48:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (11/10/2013 08:48:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (11/10/2013 08:48:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (11/10/2013 08:48:08 PM) (Source: DCOM) (User: ) Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (11/10/2013 08:48:08 PM) (Source: DCOM) (User: ) Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (11/10/2013 08:48:04 PM) (Source: DCOM) (User: ) Description: 1084EventSystem{1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (11/10/2013 08:47:56 PM) (Source: DCOM) (User: ) Description: 1084ShellHWDetection{DD522ACC-F821-461A-A407-50B198B896DC} Error: (11/10/2013 08:47:41 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: aswRvrt aswSnx aswSP aswTdi aswVmm discache MpFilter spldr Wanarpv6 Microsoft Office Sessions: ========================= Error: (11/10/2013 00:43:58 PM) (Source: Application Hang)(User: ) Description: iron.exe29.0.1600.192801cede06da7e9e6920C:\Program Files (x86)\SRWare Iron\iron.exe5d1ee3bc-49fd-11e3-a959-60eb6968405e Error: (11/10/2013 11:53:20 AM) (Source: Microsoft Security Client Setup)(User: PÄRMERSENSER) Description: HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation was canceled. You canceled the Security Essentials installation on your computer. Error code:0x8004FF0A. Error: (11/10/2013 11:49:04 AM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c00000050000000000053290e8801cede0136978c57C:\Windows\explorer.exeC:\Windows\SYSTEM32\ntdll.dllb6a178ae-49f5-11e3-a022-60eb6968405e Error: (11/10/2013 11:39:55 AM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c00000050000000000028389e0801cede001b7e39c9C:\Windows\explorer.exeC:\Windows\SYSTEM32\ntdll.dll6f6e49c0-49f4-11e3-a022-60eb6968405e Error: (11/10/2013 11:32:00 AM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c000037400000000000c4102fcc01ceddfccbfedf9eC:\Windows\explorer.exeC:\Windows\SYSTEM32\ntdll.dll54628bf5-49f3-11e3-a022-60eb6968405e Error: (11/10/2013 11:08:21 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c000037400000000000c410240c01ceddf92160ae51C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dll06a10884-49f0-11e3-a022-60eb6968405e Error: (11/10/2013 10:36:20 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Andrč\Desktop\esetsmartinstaller_enu.exe Error: (11/10/2013 09:14:19 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Andrč\Desktop\esetsmartinstaller_enu.exe Error: (11/10/2013 09:14:15 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Andrč\Desktop\esetsmartinstaller_enu.exe Error: (11/10/2013 09:14:15 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Andrč\Desktop\esetsmartinstaller_enu.exe ==================== Memory info =========================== Percentage of memory in use: 37% Total physical RAM: 3958.81 MB Available physical RAM: 2455.75 MB Total Pagefile: 7915.8 MB Available Pagefile: 6161.56 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:303.87 GB) NTFS Drive d: (FM2005CD1) (CDROM) (Total:0.65 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 2577A2D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
12.11.2013, 10:01 | #4 |
/// the machine /// TB-Ausbilder | Systemcheck meines pc´s Adware-Schleuder Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.11.2013, 19:00 | #5 |
| Systemcheck meines pc´s warum adware-schleuder hier die logs mbam: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.13.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 Andrč :: PÄRMERSENSER [Administrator] Schutz: Deaktiviert 13.11.2013 12:44:42 mbam-log-2013-11-13 (12-44-42).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 407379 Laufzeit: 1 Stunde(n), 19 Minute(n), 58 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\AdwCleaner\Quarantine\C\Windows\System32\roboot64.exe.vir (PUP.Optional.PCPerformer.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) AdwCleaner: Code:
ATTFilter # AdwCleaner v3.012 - Bericht erstellt am 13/11/2013 um 17:19:18 # Updated 11/11/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : Andrč - PÄRMERSENSER # Gestartet von : C:\Users\Andrč\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\ehitxwa2.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} Ordner Gelöscht : C:\Users\Andrč\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjgnhihlklpobkaloamkankaaoclfjh Datei Gelöscht : C:\Windows\System32\Tasks\FreeDriverScout ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\Software\hdcode ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v25.0 (de) [ Datei : C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\prefs.js ] [ Datei : C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\ehitxwa2.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Andrč\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [28599 octets] - [10/11/2013 08:26:30] AdwCleaner[R1].txt - [1503 octets] - [13/11/2013 14:06:58] AdwCleaner[S0].txt - [27177 octets] - [10/11/2013 08:27:23] AdwCleaner[S1].txt - [1424 octets] - [13/11/2013 17:19:18] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1484 octets] ########## jrt: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Ultimate x64 Ran by AndrŠ on 13.11.2013 at 17:26:07,82 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\covus freemium gmbh ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\AndrŠ\AppData\Roaming\mozilla\firefox\profiles\826sg4tl.default\minidumps [4 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.11.2013 at 17:37:28,25 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-11-2013 Ran by Andrč (administrator) on PÄRMERSENSER on 13-11-2013 18:58:47 Running from C:\Users\Andrč\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe (SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe ==================== Registry (Whitelisted) ================== MountPoints2: {929d72b7-8a59-11e1-9064-806e6f6e6963} - D:\Setup.exe MountPoints2: {d0312305-eaca-11e1-a829-60eb6968405e} - E:\Startme.exe HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-10] (AVAST Software) AppInit_DLLs: [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x33AE1D9EE91ECD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default FF NewTab: about:blank FF Homepage: about:home FF NetworkProxy: "http", "www-proxy.t-online.de" FF NetworkProxy: "http_port", 80 FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @TelevisionFanatic.com/Plugin - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll No File FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\ich@maltegoetz.de FF Extension: No Name - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\trash FF Extension: YouTube Unblocker - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\youtubeunblocker@unblocker.yt FF Extension: client - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\client@anonymox.net.xpi FF Extension: info - C:\Users\Andrč\AppData\Roaming\Mozilla\Firefox\Profiles\826sg4tl.default\Extensions\info@maltegoetz.de.xpi FF Extension: adblocker - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR Extension: () - C:\Users\ANDR~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html CHR HKLM-x32\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files (x86)\Movie2KDownloader.com\m2kDownloader10.crx ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-10] (AVAST Software) S4 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-01-29] (Nero AG) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-08-12] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-08-12] (Microsoft Corporation) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [5038448 2013-01-03] (INCA Internet Co., Ltd.) S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-11-10] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-11-10] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-10] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-10] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-11-10] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-11-10] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-11-10] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-11-10] () S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2012-06-29] (Mobile Connector) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-05-03] (DT Soft Ltd) R1 HBtnKey; C:\Windows\System32\DRIVERS\wstbtndb.sys [9856 2007-09-14] (Lenovo) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP6\WNt500x64\Sandra.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va008; \??\C:\Windows\SysWOW64\Drivers\X6va008 [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-13 18:58 - 2013-11-13 18:58 - 01957610 _____ (Farbar) C:\Users\Andrč\Desktop\FRST64.exe 2013-11-13 18:58 - 2013-11-13 18:58 - 00009320 _____ C:\Users\Andrč\Desktop\FRST.txt 2013-11-13 12:49 - 2013-11-13 12:49 - 01034531 _____ (Thisisu) C:\Users\Andrč\Desktop\JRT.exe 2013-11-13 12:47 - 2013-11-13 12:47 - 01085542 _____ C:\Users\Andrč\Desktop\adwcleaner.exe 2013-11-13 12:42 - 2013-11-13 12:42 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-13 12:42 - 2013-11-13 12:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-13 12:42 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-11 12:16 - 2013-11-11 12:16 - 00000000 ____D C:\FRST 2013-11-11 00:15 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-11-11 00:15 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-11-11 00:15 - 2012-08-23 15:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-11-11 00:15 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-11-11 00:15 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-11-11 00:15 - 2012-08-23 14:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-11-11 00:15 - 2012-08-23 14:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-11-11 00:15 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2013-11-11 00:15 - 2012-08-23 14:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-11-11 00:15 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-11-11 00:15 - 2012-08-23 14:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-11-11 00:15 - 2012-08-23 14:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-11-11 00:15 - 2012-08-23 13:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-11-11 00:15 - 2012-08-23 12:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-11-11 00:15 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-11-11 00:15 - 2012-08-23 12:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-11-11 00:15 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-11-11 00:15 - 2012-08-23 11:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-11-11 00:15 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2013-11-11 00:15 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-11-11 00:15 - 2012-08-23 11:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-11-11 00:15 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-11-11 00:15 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-11-11 00:15 - 2012-08-23 09:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-11-10 20:20 - 2013-11-10 20:20 - 00000000 ____D C:\Windows\pss 2013-11-10 12:17 - 2013-11-10 12:17 - 00000000 ____D C:\Users\Andrč\AppData\Local\Apps\2.0 2013-11-10 12:16 - 2013-11-10 12:16 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-10 12:14 - 2013-11-10 12:14 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\AVAST Software 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-11-10 11:53 - 2013-11-10 11:54 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-10 11:52 - 2012-08-24 19:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-10 11:52 - 2012-08-24 19:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-10 11:52 - 2012-08-24 19:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-10 11:52 - 2012-08-24 19:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-10 11:52 - 2012-08-24 17:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-10 11:52 - 2012-08-24 17:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-10 11:52 - 2012-08-24 17:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-10 11:52 - 2012-05-04 12:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-11-10 11:52 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-11-10 11:07 - 2013-11-13 12:10 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-10 09:46 - 2013-11-10 09:54 - 00007597 _____ C:\Users\Andrč\AppData\Local\resmon.resmoncfg 2013-11-10 08:40 - 2013-11-10 08:40 - 00000000 ____D C:\Windows\ERUNT 2013-11-10 08:24 - 2013-11-13 17:19 - 00000000 ____D C:\AdwCleaner 2013-11-10 08:11 - 2013-11-12 07:15 - 00000000 ____D C:\Users\Andrč\Desktop\Games 2013-11-10 07:34 - 2013-11-10 07:34 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Malwarebytes 2013-11-10 07:33 - 2013-11-10 07:33 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-10 04:59 - 2013-11-10 04:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 15:07 - 2013-11-05 15:07 - 00000000 ____D C:\Users\Andrč\AppData\Local\BigHugeEngine 2013-11-04 07:07 - 2013-11-04 07:07 - 00000000 ____D C:\Users\Andrč\Documents\FUSSBALL MANAGER 13 Demo 2013-11-01 01:48 - 2013-11-01 01:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Electronic_Arts_Inc 2013-11-01 01:23 - 2013-11-01 01:36 - 00000000 ____D C:\Users\Andrč\Downloads\games 2013-10-29 00:18 - 2013-10-29 00:18 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-10-28 23:47 - 2013-10-28 23:47 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-26 12:43 - 2013-10-26 12:43 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\vlc 2013-10-26 11:45 - 2013-10-26 11:45 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Program Files\Realtek 2013-10-26 11:03 - 2013-10-26 11:03 - 00000000 ____D C:\Program Files (x86)\Lenovo 2013-10-26 11:03 - 2013-05-24 10:59 - 03948544 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2013-10-26 11:00 - 2013-10-26 11:00 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\InstallShield 2013-10-26 10:53 - 2013-10-26 10:53 - 00000000 ____D C:\Program Files\ATI 2013-10-26 10:52 - 2013-10-26 10:52 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-26 10:51 - 2013-07-05 03:40 - 00110080 _____ (TODO: <Company name>) C:\Windows\system32\DelayAPO.dll 2013-10-26 10:51 - 2013-07-05 03:40 - 00096256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW76.sys 2013-10-26 10:50 - 2007-09-14 22:12 - 01459712 _____ C:\Windows\system32\wstbtnrb.dll 2013-10-26 10:50 - 2007-09-14 22:12 - 00009856 _____ (Lenovo) C:\Windows\system32\Drivers\wstbtndb.sys 2013-10-26 10:38 - 2013-10-26 10:38 - 00000000 ____D C:\Intel 2013-10-26 01:03 - 2013-10-26 01:04 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-10-26 01:03 - 2013-10-26 01:03 - 00000000 ____D C:\Users\Andrč\Documents\Freemium Driver Utilities 2013-10-26 01:02 - 2013-10-26 07:03 - 00004320 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-updater 2013-10-26 01:02 - 2013-10-26 01:02 - 00004226 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-codedownloader 2013-10-26 01:02 - 2013-10-26 01:02 - 00004124 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-enabler 2013-10-26 01:01 - 2013-10-26 01:01 - 00000000 ____D C:\Program Files\Covus Freemium 2013-10-24 19:38 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-24 19:38 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-24 19:32 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-24 19:32 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-24 19:32 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-24 19:32 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-24 19:32 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-24 19:32 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-24 19:32 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-24 19:32 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-24 19:32 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-24 19:32 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-24 19:32 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-24 19:32 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-24 19:32 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-24 19:32 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-24 19:32 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-24 19:14 - 2012-07-26 04:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-10-24 19:14 - 2012-07-26 04:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-10-24 19:14 - 2012-07-26 04:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-10-24 19:14 - 2012-07-26 04:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-10-24 19:14 - 2012-07-26 04:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-10-24 19:14 - 2012-07-26 03:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-10-24 19:14 - 2012-07-26 03:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-10-24 19:14 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-10-24 19:13 - 2013-10-24 19:13 - 00000000 ____D C:\Users\Andrč\AppData\Local\DriverTuner 2013-10-24 19:10 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-10-24 19:10 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-10-24 19:10 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-10-24 19:10 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-10-24 19:10 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-10-24 19:10 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-10-24 19:10 - 2012-12-07 14:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-10-24 19:10 - 2012-12-07 14:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-10-24 19:10 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-10-24 19:10 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-10-24 19:10 - 2012-12-07 12:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-10-24 19:10 - 2012-12-07 12:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-10-24 19:10 - 2012-12-07 12:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-10-24 19:10 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-10-24 19:10 - 2012-08-22 19:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-10-24 19:10 - 2012-07-04 21:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-10-24 19:10 - 2012-04-07 13:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2013-10-24 19:10 - 2012-04-07 12:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2013-10-24 19:09 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-24 19:09 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-24 19:09 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-24 19:09 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-24 19:09 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-24 19:09 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-10-24 19:09 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-24 19:09 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-24 19:09 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-24 19:09 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-24 19:09 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-24 19:09 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-10-24 19:09 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-10-24 19:09 - 2012-11-30 00:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2013-10-24 19:09 - 2012-11-30 00:15 - 00420064 _____ C:\Windows\system32\locale.nls 2013-10-24 19:09 - 2012-11-22 06:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2013-10-24 19:09 - 2012-11-22 05:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2013-10-24 19:09 - 2012-10-09 19:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-10-24 19:09 - 2012-10-09 19:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-10-24 19:09 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-10-24 19:09 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2013-10-24 19:09 - 2012-10-03 18:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2013-10-24 19:09 - 2012-10-03 18:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-10-24 19:09 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2013-10-24 19:09 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2013-10-24 19:09 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2013-10-24 19:09 - 2012-10-03 17:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2013-10-24 19:09 - 2012-08-21 22:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2013-10-24 19:09 - 2012-05-01 06:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2013-10-24 19:09 - 2012-01-13 08:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-10-24 19:09 - 2011-05-04 06:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-10-24 19:09 - 2011-05-04 06:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-10-24 19:09 - 2011-05-04 06:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-10-24 19:09 - 2011-05-04 06:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-10-24 19:09 - 2011-05-04 06:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-10-24 19:09 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-10-24 19:09 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-10-24 19:09 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-10-24 19:09 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-10-24 19:09 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-10-24 19:08 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-10-24 19:08 - 2012-07-06 21:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2013-10-24 19:08 - 2012-05-05 09:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-10-24 19:08 - 2012-05-05 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2013-10-24 19:04 - 2012-02-11 07:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-10-24 19:04 - 2012-02-11 07:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2013-10-24 18:59 - 2013-10-24 18:59 - 00000000 ____D C:\Users\Andrč\AppData\Local\WindowsUpdate 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\Program Files (x86)\Covus Freemium 2013-10-24 16:48 - 2013-10-24 16:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Software Updater 2013-10-24 16:20 - 2013-10-24 16:20 - 00000000 ____D C:\Riot Games 2013-10-24 15:34 - 2013-11-04 08:54 - 00054692 _____ C:\Windows\DirectX.log 2013-10-24 15:11 - 2013-11-12 07:15 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-10-24 15:09 - 2013-11-05 15:06 - 00000000 ____D C:\Users\Andrč\AppData\Local\Origin 2013-10-24 15:06 - 2013-11-12 11:45 - 00000000 ____D C:\Program Files (x86)\Origin 2013-10-24 15:06 - 2013-11-05 15:07 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-10-24 15:05 - 2013-10-24 15:05 - 16957136 _____ (Electronic Arts, Inc.) C:\Users\Andrč\Downloads\OriginThinSetup.exe 2013-10-24 13:12 - 2013-10-24 13:16 - 181594458 _____ C:\Users\Andrč\Downloads\kofuma.exe 2013-10-24 13:12 - 2013-10-24 13:13 - 03896653 _____ C:\Users\Andrč\Downloads\kofuma.exe.part 2013-10-17 09:29 - 2013-10-17 09:29 - 29040552 _____ (Oracle Corporation) C:\Users\Andrč\Downloads\jre-7u45-windows-i586.exe 2013-10-17 00:24 - 2013-10-17 00:24 - 30363050 _____ (SRWare ) C:\Users\Andrč\Downloads\srware_iron.exe ==================== One Month Modified Files and Folders ======= 2013-11-13 18:58 - 2013-11-13 18:58 - 01957610 _____ (Farbar) C:\Users\Andrč\Desktop\FRST64.exe 2013-11-13 18:58 - 2013-11-13 18:58 - 00009320 _____ C:\Users\Andrč\Desktop\FRST.txt 2013-11-13 18:56 - 2012-10-12 12:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-13 17:25 - 2012-04-19 21:02 - 01202598 _____ C:\Windows\WindowsUpdate.log 2013-11-13 17:25 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-13 17:25 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-13 17:20 - 2013-05-25 11:23 - 00115682 _____ C:\Windows\PFRO.log 2013-11-13 17:20 - 2013-05-16 09:19 - 00034685 _____ C:\Windows\setupact.log 2013-11-13 17:20 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-13 17:19 - 2013-11-10 08:24 - 00000000 ____D C:\AdwCleaner 2013-11-13 12:49 - 2013-11-13 12:49 - 01034531 _____ (Thisisu) C:\Users\Andrč\Desktop\JRT.exe 2013-11-13 12:47 - 2013-11-13 12:47 - 01085542 _____ C:\Users\Andrč\Desktop\adwcleaner.exe 2013-11-13 12:42 - 2013-11-13 12:42 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-13 12:42 - 2013-11-13 12:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-13 12:10 - 2013-11-10 11:07 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-12 11:45 - 2013-10-24 15:06 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-12 07:15 - 2013-11-10 08:11 - 00000000 ____D C:\Users\Andrč\Desktop\Games 2013-11-12 07:15 - 2013-10-24 15:11 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-11-11 16:08 - 2012-04-20 13:19 - 00000000 ____D C:\Program Files (x86)\WinRAR 2013-11-11 14:57 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-11 12:16 - 2013-11-11 12:16 - 00000000 ____D C:\FRST 2013-11-11 11:51 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-11 11:00 - 2013-05-24 14:12 - 00004478 _____ C:\Windows\System32\Tasks\Freemium1ClickMaint 2013-11-10 20:20 - 2013-11-10 20:20 - 00000000 ____D C:\Windows\pss 2013-11-10 12:17 - 2013-11-10 12:17 - 00000000 ____D C:\Users\Andrč\AppData\Local\Apps\2.0 2013-11-10 12:16 - 2013-11-10 12:16 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2013-11-10 12:14 - 2013-11-10 12:14 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\AVAST Software 2013-11-10 12:13 - 2013-07-02 12:15 - 00000000 ____D C:\Users\Andrč\AppData\Local\HTC MediaHub 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-11-10 11:54 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-11-10 11:54 - 2013-11-10 11:53 - 00001912 _____ C:\Windows\epplauncher.mif 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2013-11-10 11:15 - 2013-11-10 11:15 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2013-11-10 11:14 - 2012-05-15 20:46 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-11-10 11:07 - 2012-04-24 17:49 - 00000000 ____D C:\Windows\Minidump 2013-11-10 11:05 - 2013-03-20 14:50 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-11-10 11:05 - 2013-03-20 14:50 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-11-10 11:05 - 2012-04-20 12:40 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-11-10 11:05 - 2012-04-20 12:40 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-11-10 11:05 - 2012-04-20 12:39 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-11-10 11:05 - 2012-04-20 12:39 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-11-10 11:05 - 2012-04-20 12:39 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-11-10 11:05 - 2012-04-20 12:39 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-11-10 11:05 - 2012-04-20 12:37 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-11-10 11:03 - 2012-04-20 12:39 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-11-10 11:03 - 2012-04-20 12:37 - 00000000 ____D C:\ProgramData\AVAST Software 2013-11-10 10:48 - 2012-04-19 21:04 - 00000000 ___RD C:\Users\Andrč\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-10 10:10 - 2013-08-04 16:21 - 00000000 ____D C:\Users\Andrč\AppData\Local\PMB Files 2013-11-10 09:54 - 2013-11-10 09:46 - 00007597 _____ C:\Users\Andrč\AppData\Local\resmon.resmoncfg 2013-11-10 08:40 - 2013-11-10 08:40 - 00000000 ____D C:\Windows\ERUNT 2013-11-10 08:33 - 2013-02-23 04:47 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Spotify 2013-11-10 08:28 - 2013-09-29 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-10 08:27 - 2012-04-19 21:04 - 00000995 _____ C:\Users\Andrč\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-10 08:10 - 2013-08-04 16:21 - 00000000 ____D C:\ProgramData\PMB Files 2013-11-10 07:34 - 2013-11-10 07:34 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Malwarebytes 2013-11-10 07:33 - 2013-11-10 07:33 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-10 04:59 - 2013-11-10 04:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-09 18:07 - 2013-02-23 04:47 - 00000000 ____D C:\Users\Andrč\AppData\Local\Spotify 2013-11-05 15:07 - 2013-11-05 15:07 - 00000000 ____D C:\Users\Andrč\AppData\Local\BigHugeEngine 2013-11-05 15:07 - 2013-10-24 15:06 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-11-05 15:07 - 2012-06-23 16:02 - 00000000 ____D C:\Users\Andrč\Documents\My Games 2013-11-05 15:06 - 2013-10-24 15:09 - 00000000 ____D C:\Users\Andrč\AppData\Local\Origin 2013-11-04 08:54 - 2013-10-24 15:34 - 00054692 _____ C:\Windows\DirectX.log 2013-11-04 07:07 - 2013-11-04 07:07 - 00000000 ____D C:\Users\Andrč\Documents\FUSSBALL MANAGER 13 Demo 2013-11-01 01:48 - 2013-11-01 01:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Electronic_Arts_Inc 2013-11-01 01:36 - 2013-11-01 01:23 - 00000000 ____D C:\Users\Andrč\Downloads\games 2013-10-29 21:17 - 2009-07-14 18:58 - 00697098 _____ C:\Windows\system32\perfh007.dat 2013-10-29 21:17 - 2009-07-14 18:58 - 00148362 _____ C:\Windows\system32\perfc007.dat 2013-10-29 21:17 - 2009-07-14 06:13 - 01613412 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-29 06:12 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-29 00:18 - 2013-10-29 00:18 - 00000000 ____D C:\Program Files\McAfee Security Scan 2013-10-28 23:47 - 2013-10-28 23:47 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-28 23:47 - 2012-10-12 12:43 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-28 23:47 - 2012-05-15 20:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Adobe 2013-10-28 23:47 - 2012-04-20 13:03 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-28 23:47 - 2012-04-20 13:03 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-26 12:43 - 2013-10-26 12:43 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\vlc 2013-10-26 11:46 - 2012-04-19 22:16 - 00000000 ____D C:\Program Files (x86)\Intel 2013-10-26 11:45 - 2013-10-26 11:45 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-10-26 11:44 - 2013-10-26 11:44 - 00000000 ____D C:\Program Files\Realtek 2013-10-26 11:25 - 2013-05-24 14:11 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-26 11:03 - 2013-10-26 11:03 - 00000000 ____D C:\Program Files (x86)\Lenovo 2013-10-26 11:03 - 2012-04-20 13:21 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-26 11:00 - 2013-10-26 11:00 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\InstallShield 2013-10-26 10:53 - 2013-10-26 10:53 - 00000000 ____D C:\Program Files\ATI 2013-10-26 10:52 - 2013-10-26 10:52 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-26 10:38 - 2013-10-26 10:38 - 00000000 ____D C:\Intel 2013-10-26 07:03 - 2013-10-26 01:02 - 00004320 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-updater 2013-10-26 01:04 - 2013-10-26 01:03 - 00000000 ____D C:\ProgramData\FreeDriverScout 2013-10-26 01:03 - 2013-10-26 01:03 - 00000000 ____D C:\Users\Andrč\Documents\Freemium Driver Utilities 2013-10-26 01:02 - 2013-10-26 01:02 - 00004226 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-codedownloader 2013-10-26 01:02 - 2013-10-26 01:02 - 00004124 _____ C:\Windows\System32\Tasks\Plus-HD-3.8-enabler 2013-10-26 01:01 - 2013-10-26 01:01 - 00000000 ____D C:\Program Files\Covus Freemium 2013-10-24 20:23 - 2013-04-23 12:28 - 01591306 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-24 19:58 - 2012-04-19 21:04 - 00000000 ____D C:\Users\Andrč 2013-10-24 19:46 - 2012-04-20 12:45 - 00000000 ____D C:\Users\Andrč\AppData\Local\Mozilla 2013-10-24 19:32 - 2013-05-16 09:22 - 00064408 _____ C:\Users\Andrč\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-24 19:23 - 2013-06-06 20:22 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-24 19:23 - 2013-06-06 20:22 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-24 19:23 - 2009-07-14 05:45 - 00295424 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-24 19:13 - 2013-10-24 19:13 - 00000000 ____D C:\Users\Andrč\AppData\Local\DriverTuner 2013-10-24 18:59 - 2013-10-24 18:59 - 00000000 ____D C:\Users\Andrč\AppData\Local\WindowsUpdate 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-10-24 16:51 - 2013-10-24 16:51 - 00000000 ____D C:\Program Files (x86)\Covus Freemium 2013-10-24 16:48 - 2013-10-24 16:48 - 00000000 ____D C:\Users\Andrč\AppData\Local\Software Updater 2013-10-24 16:20 - 2013-10-24 16:20 - 00000000 ____D C:\Riot Games 2013-10-24 15:39 - 2013-07-27 14:56 - 00000000 ____D C:\ProgramData\Origin 2013-10-24 15:39 - 2012-06-23 16:02 - 00000000 ____D C:\Users\Andrč\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-10-24 15:05 - 2013-10-24 15:05 - 16957136 _____ (Electronic Arts, Inc.) C:\Users\Andrč\Downloads\OriginThinSetup.exe 2013-10-24 13:16 - 2013-10-24 13:12 - 181594458 _____ C:\Users\Andrč\Downloads\kofuma.exe 2013-10-24 13:13 - 2013-10-24 13:12 - 03896653 _____ C:\Users\Andrč\Downloads\kofuma.exe.part 2013-10-17 09:29 - 2013-10-17 09:29 - 29040552 _____ (Oracle Corporation) C:\Users\Andrč\Downloads\jre-7u45-windows-i586.exe 2013-10-17 00:25 - 2013-06-18 15:42 - 00000000 ____D C:\Program Files (x86)\SRWare Iron 2013-10-17 00:24 - 2013-10-17 00:24 - 30363050 _____ (SRWare ) C:\Users\Andrč\Downloads\srware_iron.exe Some content of TEMP: ==================== C:\Users\Andrč\AppData\Local\Temp\Quarantine.exe C:\Users\Andrč\AppData\Local\Temp\rootsupd.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 02:44 ==================== End Of Log ============================ --- --- --- |
14.11.2013, 09:57 | #6 |
/// the machine /// TB-Ausbilder | Systemcheck meines pc´sESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Systemcheck meines pc´s |
Themen zu Systemcheck meines pc´s |
jemandem, mögliche, probleme, schonmal, systemcheck, würde |