Hallo,

mein Virenprogramm G Data InternetSecurity 2014 hat mir letztens einen Virenfund angezeigt und zwar:

Win32.Trojan.Agent.UVDH0J (Engine B)
Objekt: ChromeModule.dll
Ort: C\Users\Dennis\Appdata\Roaming\SearchProtect\bin

Die Datei hab ich in die Quarantäne verlegt.

Daraufhin habe ich mir mal Malwarebytes heruntergeladen und es wurden 13 infizierte Dateien gefunden.

Hier der LOG:

Malwarebytes Anti-Malware (Test) www.malwarebytes.org

Datenbank Version: v2013.11.11.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
Dennis :: DENNIS-PC [Administrator]

Schutz: Aktiviert

11.11.2013 19:49:58
MBAM-log-2013-11-11 (21-37-07).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 429713
Laufzeit: 1 Stunde(n), 24 Minute(n), 42 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 2
HKCU\Software\DC3_FEXEC (Malware.Trace) -> Keine Aktion durchgeführt.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 3
C:\Users\Dennis\AppData\Roaming\dclogs (Stolen.Data) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\OpenCandy\80D0074D768A4C0090696B06A7652C43 (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.

Infizierte Dateien: 8
C:\Users\Dennis\AppData\Local\Temp\nsk9C8F.exe (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Local\Temp\~nsu.tmp\Au_.exe (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\dclogs\2012-06-09-7.dc (Stolen.Data) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\OpenCandy\80D0074D768A4C0090696B06A7652C43\5375.ico (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\OpenCandy\80D0074D768A4C0090696B06A7652C43\conduitinstaller.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\OpenCandy\80D0074D768A4C0090696B06A7652C43\ConduitRBCB_p1v1.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\OpenCandy\80D0074D768A4C0090696B06A7652C43\EBB77268-338F-4C6A-8590-AD88FED26F4A (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.
C:\Users\Dennis\AppData\Roaming\OpenCandy\80D0074D768A4C0090696B06A7652C43\OCBrowserHelper_1.0.5.112.dll (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt.

(Ende)

Weiß nicht was ich jetzt tun soll. Soll ich alle Dateien erstmal löschen oder wie ist weiter vorzugehen?

MfG
hi,
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
G Data hat selbst bei FRST gemeldet das es ein bösartiges Programm ist, solangsam kann man darauf nicht mehr setzen oder ?
FRST:
Unsere Tools müssen mit den gleichen Techniken arbeiten wie malware, um diese zu sehen. Daher kommen die Fehlalarme

Downloade Dir bitte
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
2013-10-25 17:39 - 2013-10-25 17:39 - 00157736 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00142304 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-10-25 17:23 - 2013-10-25 17:23 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-10-25 17:20 - 2013-10-25 17:20 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-10-25 17:13 - 2013-10-25 17:13 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-10-25 16:59 - 2013-10-25 16:59 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-10-25 16:56 - 2013-10-25 16:56 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-10-25 16:52 - 2013-10-25 16:52 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-10-25 16:41 - 2013-10-25 16:41 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-10-25 16:36 - 2013-10-25 16:36 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-10-25 16:35 - 2013-10-25 16:35 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-10-25 16:34 - 2013-10-25 16:34 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-10-25 16:21 - 2013-10-25 16:21 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-10-25 16:10 - 2013-10-25 16:10 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-10-25 16:06 - 2013-10-25 16:06 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-10-25 16:06 - 2013-10-25 16:06 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-10-25 16:05 - 2013-10-25 16:05 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00096256 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-10-25 16:01 - 2013-10-25 16:01 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2013-10-25 16:01 - 2013-10-25 16:01 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2013-10-25 12:33 - 2013-10-25 12:33 - 00051200 _____ C:\Windows\system32\kdbsdk64.dll 2013-10-25 12:28 - 2013-10-25 12:28 - 00038912 _____ C:\Windows\SysWOW64\kdbsdk32.dll 2013-10-22 13:57 - 2013-10-22 13:57 - 00000000 ____D C:\ProgramData\Oracle 2013-10-22 13:57 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-22 13:57 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 13:57 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-22 13:57 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-22 13:56 - 2013-10-22 13:57 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-16 20:53 - 2013-10-16 20:53 - 00000000 ____D C:\Users\Dennis\AppData\Local\CAPCOM 2013-10-16 18:57 - 2013-10-30 14:54 - 00000000 ____D C:\Program Files (x86)\Origin Games ==================== One Month Modified Files and Folders ======= 2013-11-13 15:52 - 2013-11-12 15:02 - 00016937 _____ C:\Users\Dennis\Desktop\FRST.txt 2013-11-13 15:52 - 2013-02-05 16:49 - 00000000 ____D C:\Users\Dennis\AppData\Local\PMB Files 2013-11-13 15:51 - 2013-11-13 15:51 - 01957610 _____ (Farbar) C:\Users\Dennis\Desktop\FRST64.exe 2013-11-13 15:50 - 2011-09-29 00:07 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{1C99BB06-D008-4C8B-967D-53B040103298} 2013-11-13 15:46 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-13 15:46 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-13 15:45 - 2013-11-13 15:45 - 00000930 _____ C:\Users\Dennis\Desktop\JRT.txt 2013-11-13 15:42 - 2013-10-30 17:10 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Raptr 2013-11-13 15:40 - 2011-09-28 20:57 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Skype 2013-11-13 15:39 - 2013-11-10 02:14 - 00001120 _____ C:\Windows\setupact.log 2013-11-13 15:39 - 2013-02-24 12:14 - 00000004 _____ C:\Windows\SysWOW64\GVTunner.ref 2013-11-13 15:39 - 2013-02-22 16:40 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-13 15:39 - 2011-09-28 23:54 - 00030528 _____ C:\Windows\GVTDrv64.sys 2013-11-13 15:39 - 2011-09-28 23:46 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-11-13 15:39 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-13 15:38 - 2011-09-28 23:16 - 01157956 _____ C:\Windows\WindowsUpdate.log 2013-11-13 15:35 - 2013-11-13 15:35 - 01034531 _____ (Thisisu) C:\Users\Dennis\Desktop\JRT.exe 2013-11-13 15:35 - 2013-11-13 15:35 - 00000000 ____D C:\Windows\ERUNT 2013-11-13 15:30 - 2013-11-13 15:26 - 00000000 ____D C:\AdwCleaner 2013-11-13 15:26 - 2013-11-13 15:26 - 01085542 _____ C:\Users\Dennis\Desktop\adwcleaner.exe 2013-11-13 15:08 - 2013-02-22 16:40 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-13 14:57 - 2012-09-15 23:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-12 15:02 - 2013-11-12 15:01 - 00027766 _____ C:\Users\Dennis\Desktop\Addition.txt 2013-11-12 14:59 - 2013-11-12 14:59 - 00000000 ____D C:\FRST 2013-11-11 22:13 - 2011-09-29 14:58 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-11 22:08 - 2013-11-11 22:08 - 00004122 _____ C:\Windows\PFRO.log 2013-11-11 19:48 - 2013-11-11 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Dennis\Downloads\mbam-setup- 2013-11-11 19:48 - 2013-11-11 19:48 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Malwarebytes 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-10 17:27 - 2011-09-28 20:34 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-11-10 13:40 - 2013-11-10 13:40 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Doublefine 2013-11-10 02:16 - 2011-09-28 21:01 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Media Player Classic 2013-11-10 02:14 - 2013-11-10 02:14 - 00000000 _____ C:\Windows\setuperr.log 2013-11-09 23:44 - 2012-01-26 16:08 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-09 23:42 - 2013-11-09 23:42 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Kalypso Media 2013-11-09 23:41 - 2013-11-09 23:41 - 00017551 _____ C:\Windows\DirectX.log 2013-11-09 23:04 - 2013-04-05 14:31 - 00000000 ____D C:\Users\Dennis\Desktop\Games 2013-11-09 21:49 - 2011-09-29 00:08 - 00000000 ____D C:\Windows\Panther 2013-11-09 18:03 - 2013-04-07 18:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-11-09 13:40 - 2012-01-26 16:41 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-11-09 12:18 - 2011-04-12 08:43 - 00699416 _____ C:\Windows\system32\perfh007.dat 2013-11-09 12:18 - 2011-04-12 08:43 - 00149556 _____ C:\Windows\system32\perfc007.dat 2013-11-09 12:18 - 2009-07-14 06:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-08 18:39 - 2011-10-04 18:38 - 00000000 ____D C:\Users\Dennis\Documents\My Games 2013-11-07 14:58 - 2012-09-16 12:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-06 15:53 - 2013-11-06 15:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 19:44 - 2013-04-06 17:34 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-03 17:39 - 2013-11-03 17:39 - 00000000 ____D C:\Users\Dennis\AppData\Local\My Games 2013-11-03 16:33 - 2013-02-09 15:44 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-03 16:33 - 2011-09-28 20:57 - 00000000 ____D C:\ProgramData\Skype 2013-10-30 17:16 - 2013-10-30 17:16 - 00000000 ____D C:\Users\Dennis\AppData\Local\AMD 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\ATI 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\Users\Dennis\AppData\Local\ATI 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\ProgramData\ATI 2013-10-30 17:13 - 2013-10-30 17:13 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\library_dir 2013-10-30 17:11 - 2013-10-30 17:10 - 00000000 ____D C:\Program Files (x86)\Raptr 2013-10-30 17:10 - 2013-10-30 17:10 - 00066451 _____ C:\Windows\SysWOW64\CCCInstall_201310301710334298.log 2013-10-30 17:10 - 2013-10-30 17:10 - 00000000 ____D C:\ProgramData\AMD 2013-10-30 17:10 - 2013-10-30 17:10 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-10-30 17:10 - 2013-10-30 17:06 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-30 17:09 - 2013-10-30 17:05 - 00000000 ____D C:\AMD 2013-10-30 17:08 - 2013-10-30 17:08 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-10-30 17:08 - 2013-10-30 17:08 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-10-30 17:08 - 2012-03-21 20:16 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-30 17:06 - 2013-10-30 17:06 - 00000000 ____D C:\Program Files\ATI 2013-10-30 16:59 - 2013-10-30 16:59 - 00059932 _____ C:\Windows\SysWOW64\CCCInstall_201310301659174544.log 2013-10-30 16:53 - 2013-10-30 16:53 - 02325160 _____ C:\Users\Dennis\Desktop\amd_cleanup_util_1.2.1.0.exe 2013-10-30 15:54 - 2013-04-07 18:34 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-30 15:54 - 2012-01-26 17:15 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-10-30 14:54 - 2013-10-16 18:57 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-10-28 18:35 - 2012-04-23 13:28 - 00000132 _____ C:\Users\Dennis\Desktop\Games.txt 2013-10-27 17:27 - 2013-10-27 16:35 - 00000000 ____D C:\Users\Dennis\Desktop\Lets EAT XD 2013-10-26 16:23 - 2013-01-19 16:03 - 00000000 ____D C:\Users\Dennis\AppData\Local\Windows Live 2013-10-25 17:39 - 2013-10-25 17:39 - 09763576 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 08412168 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 08287008 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 06630232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 01318040 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 01099704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00157736 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00142304 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00115512 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-10-25 17:38 - 2013-10-25 17:38 - 08927704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-10-25 17:38 - 2013-10-25 17:38 - 07751408 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2013-10-25 17:36 - 2013-10-25 17:36 - 13198848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-10-25 17:23 - 2013-10-25 17:23 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-10-25 17:20 - 2013-10-25 17:20 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-10-25 17:13 - 2013-10-25 17:13 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-10-25 16:59 - 2013-10-25 16:59 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-10-25 16:56 - 2013-10-25 16:56 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-10-25 16:52 - 2013-10-25 16:52 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-10-25 16:41 - 2013-10-25 16:41 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-10-25 16:36 - 2013-10-25 16:36 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-10-25 16:35 - 2013-10-25 16:35 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-10-25 16:34 - 2013-10-25 16:34 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-10-25 16:21 - 2013-10-25 16:21 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-10-25 16:10 - 2013-10-25 16:10 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-10-25 16:06 - 2013-10-25 16:06 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-10-25 16:06 - 2013-10-25 16:06 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-10-25 16:05 - 2013-10-25 16:05 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00096256 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00043520 _____ (Advanced Micro Devices, Inc.) #2

/// the machine /// TB-Ausbilder

Malwarebytes 13 Funde (PUP.Optional.OpenCandy etc.)

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
__________________ --> Malwarebytes 13 Funde (PUP.Optional.OpenCandy etc.) |
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=98edad3c981d994b824c6d34fba33031 # engine=15883 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-14 04:06:26 # local_time=2013-11-14 05:06:26 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 97507 136075036 0 0 # scanned=250887 # found=0 # cleaned=0 # scan_time=6600 Code:
ATTFilter Results of screen317's Security Check version 0.99.76 Windows 7 Service Pack 1 x64 Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` G Data InternetSecurity 2014 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version DH Driver Cleaner Professional Edition JavaFX 2.1.1 Java 7 Update 45 Adobe Flash Player 11.9.900.117 Adobe Reader XI Mozilla Firefox (25.0) Google Chrome 30.0.1599.101 Google Chrome 30.0.1599.69 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe G Data InternetSecurity Firewall GDFwSvcx64.exe G Data InternetSecurity Firewall GDFirewallTray.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013 Ran by Dennis (administrator) on DENNIS-PC on 14-11-2013 17:18:38 Running from C:\Users\Dennis\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe (AMD) C:\Windows\system32\atiesrxx.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe (AMD) C:\Windows\system32\atieclxx.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\WMPSideShowGadget.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-8.01.067\Applets\x64\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-8.01.067\Applets\x64\LCDCountdown.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-8.01.067\Applets\x64\LCDRSS.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-8.01.067\Applets\x86\LCDMedia.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-8.01.067\Applets\x64\LCDPop3.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.Exe [134160 2007-09-21] (Logitech, Inc.) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [110360 2011-07-28] (Logitech Inc.) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-06-24] (Logitech, Inc.) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212560 2012-06-13] (Realtek Semiconductor) HKLM-x32\...\RunOnce: [EasyTuneVI] - C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [20480 2007-07-26] () HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) HKCU\...\Run: [Advanced SystemCare 5] - "C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-05] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.) HKCU\...\Run: [Raptr] - C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2013-10-25] (Raptr, Inc) MountPoints2: {f3c20ff7-a5fb-11e2-9a0d-50e549b5df01} - F:\ST_MENU.EXE HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [G Data AntiVirus Tray] - C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe [1444472 2013-08-21] (G Data Software AG) HKLM-x32\...\Run: [GDFirewallTray] - C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1854928 2013-03-22] (G Data Software AG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-10-25] (Advanced Micro Devices, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1B78929DFB93CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.138.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\searchplugins\instagrille-customized-web-search.xml FF SearchPlugin: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: firefox - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\Extensions\firefox@ghostery.com.xpi FF Extension: Adblock Plus - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\eyl47877.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR DefaultSearchURL: (Ask) - hxxp://www.google.com CHR DefaultSuggestURL: (Ask) - hxxp://www.google.com CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U13) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll No File CHR Plugin: (Java Deployment Toolkit - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (Google Docs) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (Chrome In-App Payments service) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR Extension: (Gmail) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-10-25] (Advanced Micro Devices, Inc.) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1970296 2013-08-26] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [635000 2013-08-21] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2562208 2013-10-15] (G Data Software AG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-02-21] () R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2942808 2013-10-17] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [695416 2013-08-22] (G Data Software AG) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-30] () ==================== Drivers (Whitelisted) ==================== R3 AODDriver; C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys [52280 2010-03-12] (Advanced Micro Devices) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2011-10-21] () S3 etdrv; C:\Windows\etdrv.sys [25640 2013-02-22] (Windows (R) Server 2003 DDK provider) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-10-04] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [130392 2013-10-04] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [63320 2013-10-04] (G Data Software AG) R3 gdrv; C:\Windows\gdrv.sys [25640 2013-11-14] (Windows (R) Server 2003 DDK provider) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-10-24] (G Data Software AG) R3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-11-14] () R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65368 2013-10-04] (G Data Software AG) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2011-10-21] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2013-04-15] () U3 AppMgmt; S3 atillk64; \??\C:\Program Files (x86)\GIGABYTE\atBIOS\AtiTool\atillk64.sys [x] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x] U2 CscService; S3 GPCIDrv; \??\C:\Program Files (x86)\GIGABYTE\atBIOS\GPCIDrv64.sys [x] U3 PeerDistSvc; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-14 17:17 - 2013-11-14 17:17 - 01957794 _____ (Farbar) C:\Users\Dennis\Desktop\FRST64.exe 2013-11-14 17:11 - 2013-11-14 17:11 - 00891184 _____ C:\Users\Dennis\Desktop\SecurityCheck.exe 2013-11-14 15:15 - 2013-11-14 15:15 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-14 15:10 - 2013-11-14 15:10 - 02347384 _____ (ESET) C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe 2013-11-13 15:56 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-13 15:56 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-13 15:56 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-13 15:56 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-13 15:56 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-13 15:56 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-13 15:56 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-13 15:56 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-13 15:56 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-13 15:56 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-13 15:56 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-13 15:55 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-13 15:55 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-13 15:55 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-13 15:55 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-13 15:55 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-13 15:45 - 2013-11-13 15:45 - 00000930 _____ C:\Users\Dennis\Desktop\JRT.txt 2013-11-13 15:35 - 2013-11-13 15:35 - 01034531 _____ (Thisisu) C:\Users\Dennis\Desktop\JRT.exe 2013-11-13 15:35 - 2013-11-13 15:35 - 00000000 ____D C:\Windows\ERUNT 2013-11-13 15:26 - 2013-11-13 15:30 - 00000000 ____D C:\AdwCleaner 2013-11-13 15:26 - 2013-11-13 15:26 - 01085542 _____ C:\Users\Dennis\Desktop\adwcleaner.exe 2013-11-13 15:02 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 15:02 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 15:02 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 15:02 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 15:02 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 15:02 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 15:02 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 15:02 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 15:02 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 15:02 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 15:02 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 15:02 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 15:02 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 15:02 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 15:02 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 15:02 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 15:02 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 15:02 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 15:02 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 15:02 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 15:02 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 15:02 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 15:02 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 15:02 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 15:02 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 15:02 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 15:02 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 15:02 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 15:02 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 15:02 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-12 15:02 - 2013-11-14 17:18 - 00017017 _____ C:\Users\Dennis\Desktop\FRST.txt 2013-11-12 15:01 - 2013-11-12 15:02 - 00027766 _____ C:\Users\Dennis\Desktop\Addition.txt 2013-11-12 14:59 - 2013-11-12 14:59 - 00000000 ____D C:\FRST 2013-11-11 22:08 - 2013-11-11 22:08 - 00004122 _____ C:\Windows\PFRO.log 2013-11-11 19:48 - 2013-11-11 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Dennis\Downloads\mbam-setup- 2013-11-11 19:48 - 2013-11-11 19:48 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Malwarebytes 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-11 19:48 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-10 19:54 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-11-10 19:54 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-11-10 19:54 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-11-10 19:54 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-11-10 19:54 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-11-10 19:54 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-11-10 19:54 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-11-10 13:40 - 2013-11-10 13:40 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Doublefine 2013-11-10 02:14 - 2013-11-14 14:55 - 00001176 _____ C:\Windows\setupact.log 2013-11-10 02:14 - 2013-11-10 02:14 - 00000000 _____ C:\Windows\setuperr.log 2013-11-09 23:42 - 2013-11-09 23:42 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Kalypso Media 2013-11-09 23:41 - 2013-11-09 23:41 - 00017551 _____ C:\Windows\DirectX.log 2013-11-06 15:53 - 2013-11-06 15:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-03 17:39 - 2013-11-03 17:39 - 00000000 ____D C:\Users\Dennis\AppData\Local\My Games 2013-10-30 17:16 - 2013-10-30 17:16 - 00000000 ____D C:\Users\Dennis\AppData\Local\AMD 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\ATI 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\Users\Dennis\AppData\Local\ATI 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\ProgramData\ATI 2013-10-30 17:13 - 2013-10-30 17:13 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\library_dir 2013-10-30 17:10 - 2013-11-14 15:01 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Raptr 2013-10-30 17:10 - 2013-10-30 17:11 - 00000000 ____D C:\Program Files (x86)\Raptr 2013-10-30 17:10 - 2013-10-30 17:10 - 00066451 _____ C:\Windows\SysWOW64\CCCInstall_201310301710334298.log 2013-10-30 17:10 - 2013-10-30 17:10 - 00000000 ____D C:\ProgramData\AMD 2013-10-30 17:10 - 2013-10-30 17:10 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-10-30 17:08 - 2013-10-30 17:08 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-10-30 17:08 - 2013-10-30 17:08 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-10-30 17:06 - 2013-10-30 17:10 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-30 17:06 - 2013-10-30 17:06 - 00000000 ____D C:\Program Files\ATI 2013-10-30 17:05 - 2013-10-30 17:09 - 00000000 ____D C:\AMD 2013-10-30 16:59 - 2013-10-30 16:59 - 00059932 _____ C:\Windows\SysWOW64\CCCInstall_201310301659174544.log 2013-10-30 16:53 - 2013-10-30 16:53 - 02325160 _____ C:\Users\Dennis\Desktop\amd_cleanup_util_1.2.1.0.exe 2013-10-27 16:35 - 2013-10-27 17:27 - 00000000 ____D C:\Users\Dennis\Desktop\Lets EAT XD 2013-10-25 17:39 - 2013-10-25 17:39 - 09763576 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 08412168 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 08287008 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 06630232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 01318040 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 01099704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00157736 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00142304 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00115512 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-10-25 17:38 - 2013-10-25 17:38 - 08927704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-10-25 17:38 - 2013-10-25 17:38 - 07751408 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2013-10-25 17:36 - 2013-10-25 17:36 - 13198848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-10-25 17:23 - 2013-10-25 17:23 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-10-25 17:20 - 2013-10-25 17:20 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-10-25 17:13 - 2013-10-25 17:13 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-10-25 16:59 - 2013-10-25 16:59 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-10-25 16:56 - 2013-10-25 16:56 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-10-25 16:52 - 2013-10-25 16:52 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-10-25 16:41 - 2013-10-25 16:41 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-10-25 16:36 - 2013-10-25 16:36 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-10-25 16:35 - 2013-10-25 16:35 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-10-25 16:34 - 2013-10-25 16:34 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-10-25 16:21 - 2013-10-25 16:21 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-10-25 16:10 - 2013-10-25 16:10 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-10-25 16:06 - 2013-10-25 16:06 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-10-25 16:06 - 2013-10-25 16:06 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-10-25 16:05 - 2013-10-25 16:05 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00096256 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-10-25 16:01 - 2013-10-25 16:01 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2013-10-25 16:01 - 2013-10-25 16:01 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2013-10-25 12:33 - 2013-10-25 12:33 - 00051200 _____ C:\Windows\system32\kdbsdk64.dll 2013-10-25 12:28 - 2013-10-25 12:28 - 00038912 _____ C:\Windows\SysWOW64\kdbsdk32.dll 2013-10-22 13:57 - 2013-10-22 13:57 - 00000000 ____D C:\ProgramData\Oracle 2013-10-22 13:57 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-22 13:57 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 13:57 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-22 13:57 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-22 13:56 - 2013-10-22 13:57 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-16 20:53 - 2013-10-16 20:53 - 00000000 ____D C:\Users\Dennis\AppData\Local\CAPCOM 2013-10-16 18:57 - 2013-10-30 14:54 - 00000000 ____D C:\Program Files (x86)\Origin Games ==================== One Month Modified Files and Folders ======= 2013-11-14 17:18 - 2013-11-12 15:02 - 00017017 _____ C:\Users\Dennis\Desktop\FRST.txt 2013-11-14 17:18 - 2013-02-05 16:49 - 00000000 ____D C:\Users\Dennis\AppData\Local\PMB Files 2013-11-14 17:17 - 2013-11-14 17:17 - 01957794 _____ (Farbar) C:\Users\Dennis\Desktop\FRST64.exe 2013-11-14 17:11 - 2013-11-14 17:11 - 00891184 _____ C:\Users\Dennis\Desktop\SecurityCheck.exe 2013-11-14 17:08 - 2013-02-22 16:40 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-14 17:05 - 2011-09-29 00:07 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{1C99BB06-D008-4C8B-967D-53B040103298} 2013-11-14 16:57 - 2012-09-15 23:00 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-14 16:37 - 2011-09-28 23:16 - 01612473 _____ C:\Windows\WindowsUpdate.log 2013-11-14 16:08 - 2013-02-22 16:40 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-14 15:15 - 2013-11-14 15:15 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-14 15:15 - 2011-04-12 08:43 - 00699416 _____ C:\Windows\system32\perfh007.dat 2013-11-14 15:15 - 2011-04-12 08:43 - 00149556 _____ C:\Windows\system32\perfc007.dat 2013-11-14 15:15 - 2009-07-14 06:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-14 15:10 - 2013-11-14 15:10 - 02347384 _____ (ESET) C:\Users\Dennis\Desktop\esetsmartinstaller_enu.exe 2013-11-14 15:04 - 2011-09-28 20:57 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Skype 2013-11-14 15:04 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-14 15:04 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-14 15:01 - 2013-10-30 17:10 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Raptr 2013-11-14 14:57 - 2013-02-24 12:14 - 00000004 _____ C:\Windows\SysWOW64\GVTunner.ref 2013-11-14 14:57 - 2011-09-28 23:54 - 00030528 _____ C:\Windows\GVTDrv64.sys 2013-11-14 14:57 - 2011-09-28 23:46 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-11-14 14:56 - 2011-09-29 00:08 - 00000000 ____D C:\Windows\Panther 2013-11-14 14:56 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-14 14:55 - 2013-11-10 02:14 - 00001176 _____ C:\Windows\setupact.log 2013-11-13 15:54 - 2013-08-16 01:41 - 00000000 ____D C:\Windows\system32\MRT 2013-11-13 15:54 - 2011-09-28 19:45 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-13 15:45 - 2013-11-13 15:45 - 00000930 _____ C:\Users\Dennis\Desktop\JRT.txt 2013-11-13 15:35 - 2013-11-13 15:35 - 01034531 _____ (Thisisu) C:\Users\Dennis\Desktop\JRT.exe 2013-11-13 15:35 - 2013-11-13 15:35 - 00000000 ____D C:\Windows\ERUNT 2013-11-13 15:30 - 2013-11-13 15:26 - 00000000 ____D C:\AdwCleaner 2013-11-13 15:26 - 2013-11-13 15:26 - 01085542 _____ C:\Users\Dennis\Desktop\adwcleaner.exe 2013-11-12 15:02 - 2013-11-12 15:01 - 00027766 _____ C:\Users\Dennis\Desktop\Addition.txt 2013-11-12 14:59 - 2013-11-12 14:59 - 00000000 ____D C:\FRST 2013-11-11 22:13 - 2011-09-29 14:58 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-11 22:08 - 2013-11-11 22:08 - 00004122 _____ C:\Windows\PFRO.log 2013-11-11 19:48 - 2013-11-11 19:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Dennis\Downloads\mbam-setup- 2013-11-11 19:48 - 2013-11-11 19:48 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Malwarebytes 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-11 19:48 - 2013-11-11 19:48 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-10 17:27 - 2011-09-28 20:34 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-11-10 13:40 - 2013-11-10 13:40 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Doublefine 2013-11-10 02:16 - 2011-09-28 21:01 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Media Player Classic 2013-11-10 02:14 - 2013-11-10 02:14 - 00000000 _____ C:\Windows\setuperr.log 2013-11-09 23:44 - 2012-01-26 16:08 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-09 23:42 - 2013-11-09 23:42 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Kalypso Media 2013-11-09 23:41 - 2013-11-09 23:41 - 00017551 _____ C:\Windows\DirectX.log 2013-11-09 23:04 - 2013-04-05 14:31 - 00000000 ____D C:\Users\Dennis\Desktop\Games 2013-11-09 18:03 - 2013-04-07 18:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-11-09 13:40 - 2012-01-26 16:41 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-11-08 18:39 - 2011-10-04 18:38 - 00000000 ____D C:\Users\Dennis\Documents\My Games 2013-11-07 14:58 - 2012-09-16 12:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-06 15:53 - 2013-11-06 15:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 19:44 - 2013-04-06 17:34 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-03 17:39 - 2013-11-03 17:39 - 00000000 ____D C:\Users\Dennis\AppData\Local\My Games 2013-11-03 16:33 - 2013-02-09 15:44 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-03 16:33 - 2011-09-28 20:57 - 00000000 ____D C:\ProgramData\Skype 2013-10-30 17:16 - 2013-10-30 17:16 - 00000000 ____D C:\Users\Dennis\AppData\Local\AMD 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\ATI 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\Users\Dennis\AppData\Local\ATI 2013-10-30 17:15 - 2013-10-30 17:15 - 00000000 ____D C:\ProgramData\ATI 2013-10-30 17:13 - 2013-10-30 17:13 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raptr 2013-10-30 17:11 - 2013-10-30 17:11 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\library_dir 2013-10-30 17:11 - 2013-10-30 17:10 - 00000000 ____D C:\Program Files (x86)\Raptr 2013-10-30 17:10 - 2013-10-30 17:10 - 00066451 _____ C:\Windows\SysWOW64\CCCInstall_201310301710334298.log 2013-10-30 17:10 - 2013-10-30 17:10 - 00000000 ____D C:\ProgramData\AMD 2013-10-30 17:10 - 2013-10-30 17:10 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-10-30 17:10 - 2013-10-30 17:06 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-30 17:09 - 2013-10-30 17:05 - 00000000 ____D C:\AMD 2013-10-30 17:08 - 2013-10-30 17:08 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-10-30 17:08 - 2013-10-30 17:08 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-10-30 17:08 - 2012-03-21 20:16 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-30 17:06 - 2013-10-30 17:06 - 00000000 ____D C:\Program Files\ATI 2013-10-30 16:59 - 2013-10-30 16:59 - 00059932 _____ C:\Windows\SysWOW64\CCCInstall_201310301659174544.log 2013-10-30 16:53 - 2013-10-30 16:53 - 02325160 _____ C:\Users\Dennis\Desktop\amd_cleanup_util_1.2.1.0.exe 2013-10-30 15:54 - 2013-04-07 18:34 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-30 15:54 - 2012-01-26 17:15 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-10-30 14:54 - 2013-10-16 18:57 - 00000000 ____D C:\Program Files (x86)\Origin Games 2013-10-28 18:35 - 2012-04-23 13:28 - 00000132 _____ C:\Users\Dennis\Desktop\Games.txt 2013-10-27 17:27 - 2013-10-27 16:35 - 00000000 ____D C:\Users\Dennis\Desktop\Lets EAT XD 2013-10-26 16:23 - 2013-01-19 16:03 - 00000000 ____D C:\Users\Dennis\AppData\Local\Windows Live 2013-10-25 17:39 - 2013-10-25 17:39 - 09763576 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 08412168 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 08287008 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 06630232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 01318040 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 01099704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00157736 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00142304 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00115512 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00098496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-10-25 17:39 - 2013-10-25 17:39 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-10-25 17:38 - 2013-10-25 17:38 - 08927704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-10-25 17:38 - 2013-10-25 17:38 - 07751408 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll 2013-10-25 17:36 - 2013-10-25 17:36 - 13198848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-10-25 17:23 - 2013-10-25 17:23 - 01187342 _____ C:\Windows\system32\amdocl_as64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 01061902 _____ C:\Windows\system32\amdocl_ld64.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00995342 _____ C:\Windows\SysWOW64\amdocl_as32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00798734 _____ C:\Windows\SysWOW64\amdocl_ld32.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00230912 _____ C:\Windows\system32\clinfo.exe 2013-10-25 17:23 - 2013-10-25 17:23 - 00100352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 29363712 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll 2013-10-25 17:22 - 2013-10-25 17:22 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll 2013-10-25 17:20 - 2013-10-25 17:20 - 24846848 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-10-25 17:17 - 2013-10-25 17:17 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-10-25 17:13 - 2013-10-25 17:13 - 00129536 _____ (AMD) C:\Windows\system32\coinst_13.25.18.dll 2013-10-25 16:59 - 2013-10-25 16:59 - 26350592 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\SysWOW64\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00547152 _____ C:\Windows\system32\atiapfxx.blb 2013-10-25 16:56 - 2013-10-25 16:56 - 00368640 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-10-25 16:56 - 2013-10-25 16:56 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-10-25 16:56 - 2013-10-25 16:56 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-10-25 16:55 - 2013-10-25 16:55 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-10-25 16:52 - 2013-10-25 16:52 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-10-25 16:41 - 2013-10-25 16:41 - 22156288 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00585216 _____ (AMD) C:\Windows\system32\atieclxx.exe 2013-10-25 16:36 - 2013-10-25 16:36 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll 2013-10-25 16:36 - 2013-10-25 16:36 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll 2013-10-25 16:35 - 2013-10-25 16:35 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe 2013-10-25 16:34 - 2013-10-25 16:34 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll 2013-10-25 16:21 - 2013-10-25 16:21 - 03399312 _____ C:\Windows\system32\atiumd6a.cap 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00204952 _____ C:\Windows\system32\ativvsvl.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat 2013-10-25 16:18 - 2013-10-25 16:18 - 00157144 _____ C:\Windows\system32\ativvsva.dat 2013-10-25 16:10 - 2013-10-25 16:10 - 03433360 _____ C:\Windows\SysWOW64\atiumdva.cap 2013-10-25 16:06 - 2013-10-25 16:06 - 01145344 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-10-25 16:06 - 2013-10-25 16:06 - 00825856 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00624128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-10-25 16:05 - 2013-10-25 16:05 - 00100352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00096768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00074752 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-10-25 16:05 - 2013-10-25 16:05 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00096256 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll 2013-10-25 16:02 - 2013-10-25 16:02 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-10-25 16:01 - 2013-10-25 16:01 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll 2013-10-25 16:01 - 2013-10-25 16:01 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll 2013-10-25 12:33 - 2013-10-25 12:33 - 00051200 _____ C:\Windows\system32\kdbsdk64.dll 2013-10-25 12:28 - 2013-10-25 12:28 - 00038912 _____ C:\Windows\SysWOW64\kdbsdk32.dll 2013-10-24 13:57 - 2013-07-24 19:58 - 00001978 _____ C:\Users\Public\Desktop\G Data InternetSecurity 2014.lnk 2013-10-24 13:57 - 2013-07-24 19:57 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2013-10-22 13:57 - 2013-10-22 13:57 - 00000000 ____D C:\ProgramData\Oracle 2013-10-22 13:57 - 2013-10-22 13:56 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-22 13:57 - 2013-06-25 13:26 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-18 17:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-17 17:26 - 2012-09-15 23:00 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-17 17:26 - 2012-08-27 14:02 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-17 17:26 - 2011-11-29 15:31 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-16 20:53 - 2013-10-16 20:53 - 00000000 ____D C:\Users\Dennis\AppData\Local\CAPCOM 2013-10-16 14:13 - 2013-02-22 16:41 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk Some content of TEMP: ==================== C:\Users\Dennis\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-10 15:05 ==================== End Of Log ============================ --- --- --- Naja was heißt probleme, laut den logs ja nich wobei du da ja wohl eher was zu sagen könntest oder ? #8

/// the machine /// TB-Ausbilder

Malwarebytes 13 Funde (PUP.Optional.OpenCandy etc.)

Quarantäne kannste löschen, wenn der Echtzeitschutz in MBAM aus ist sollte das passen.

Fertig

Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
#9

Malwarebytes 13 Funde (PUP.Optional.OpenCandy etc.)

Hi,

also die beiden Programme dort habe ich nicht benutzt. Hab mir Delfix noch heruntergeladen und die Dateien in der Quarantäne anschließend gelöscht.

Vielen dank für deine Hilfe schrauber, deine tipps zu den browsern etc werde ich mir noch angucken.

Brauche dann erstmal keine Hilfe mehr und wenn doch werde ich einfach einen neuen Thread erstellen

Wünsche dir ein schönes Wochenende.
#10

/// the machine /// TB-Ausbilder

Malwarebytes 13 Funde (PUP.Optional.OpenCandy etc.)

Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
