Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: _GETWINDOWINFO-Trojaner

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 24.11.2013, 12:49   #1
LikeASiR
 
_GETWINDOWINFO-Trojaner - Ausrufezeichen

_GETWINDOWINFO-Trojaner



Hallo Leute,

Heute Früh, nachdem ich den PC angeschaltet habe, hat sich interessanterweise der Internet Explorer mit dem Link: hxxp://www_getwindowinfo/ geöffnet, welcher nicht geschlossen werden kann.
Interessante Anmerkung: Ich hatte am Vortag keine Downloads durchgeführt und einen Internet Explorer hatte ich auch nie.

Mittlerweile hab ich gesehen, dass viele Leute dieses Problem haben, aber bei jedem die Anleitungen von den Admins anders waren. Was aber gleich blieb ist der Scan mit Farbar Recovery Scan Tool. Also hab ich mir erlaubt, das herunterzuladen und zu scanen, damit meine und eure Zeit nicht umsonst verschwendet wird. :-D

Wenn wir schon dabei sind:
Seit kurzem taucht immer snap.do als Startseite bei meinen Browsern auf. Daraufhin hab ich mir einen Malwarefighter geholt, und der sagt mir jedes mal, wenn ich meinen Browser schließe: Der IOBit HomePage Schutz hat verhindert, dass ihre Startseite verändert wird. Seitdem taucht es nicht mehr auf, aber blockieren ist sicherlich nicht die endgültige Lösung.
Betriebssystem ist Win 7.

Hier sind die Ergebnisse:



FRST.txt:

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2013 03
Ran by Admin (administrator) on PC on 24-11-2013 11:57:20
Running from C:\Users\Admin\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\Tor\tor.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Smartbar) C:\Users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BitTorrent, Inc.) C:\Program Files (x86)\BitTorrent\BitTorrent.exe
(Windows Net) C:\Users\Admin\AppData\Roaming\Windows Net Data\net.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-13] (Adobe Systems Incorporated)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20549280 2013-10-21] (Skype Technologies S.A.)
HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\Admin\AppData\Local\Smartbar\Application\SnapDo.exe [21024 2013-08-04] (Smartbar)
HKCU\...\Run: [BitTorrent] - C:\Program Files (x86)\BitTorrent\BitTorrent.exe [1279384 2012-11-24] (BitTorrent, Inc.)
HKCU\...\Run: [Win Update] - C:\Users\Admin\AppData\Roaming\Win Update.exe
HKCU\...\Run: [DarkComet RAT] - C:\Users\Admin\Documents\DCSCMIN\IMDCSC.exe
HKCU\...\Policies\Explorer: [] 
HKCU\...\Policies\Explorer: [DisallowRun] 1
MountPoints2: {039796ea-03da-11e2-acc2-806e6f6e6963} - D:\start.exe
MountPoints2: {853f4d50-4465-11e2-9c82-001bfcfb8327} - H:\Fairlight\Installer.exe
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1549120 2013-08-16] (IObit)
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk
ShortcutTarget: net.lnk -> C:\Users\Admin\AppData\Roaming\Windows Net Data\net.exe (Windows Net)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2B8F4B822CAECD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/software/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.protectedsearch.com?si=41570&home=true&tid=3026&q=
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKCU - F4FA9A3599F049448F02069E95A87F8C URL = hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_ss_Btisdt4&mntrId=1A054C60DE739903&affID=119357&tsp=4985
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
SearchScopes: HKCU - {26681076-2DF8-44B1-900B-06D059B96AA0} URL = hxxp://search.toggle.com/?lang=en&cid=adfaa7a7&q={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Speed Test Analysis - {310D38FE-EB4C-467C-8781-B7C2AEB7847D} - C:\Program Files (x86)\Speed Test Analysis\ScriptHost64.dll No File
BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Speed Test Analysis - {310D38FE-EB4C-467C-8781-B7C2AEB7847D} - C:\Program Files (x86)\Speed Test Analysis\ScriptHost.dll No File
BHO-x32: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: AccelerateTab - {48A789BF-F6D6-4930-9C8B-77855A63EDE1} - C:\Program Files (x86)\Secure Speed Dial\IE\SpeedDial.dll (Secure Speed Dial)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Utility Chest - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files (x86)\UtilityChest_49\bar\1.bin\49bar.dll No File
Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {CF67755F-9265-449C-87CF-B945519E073B} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default
FF DefaultSearchEngine: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013|hxxp://www.giga.de/software/
FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&installDate=27/10/2013&q=
FF NewTab: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=nt&installDate=27/10/2013
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\toggle.xml
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\searchplugins\Web Search.xml
FF Extension: Amazon-Icon - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\amazon-icon@giga.de
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\ascsurfingprotection@iobit.com
FF Extension: HDvid Codec - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\hdvc@hdvc.com
FF Extension: AD Block - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\searchads@instair.net
FF Extension: AccelerateTab - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speeddial@instair.net
FF Extension: Speed Test Analysis - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\speedtestanalysis@SpeedAnalysis.com
FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\staged
FF Extension: WebSite Recommendation - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\WebSiteRecommendation@weliketheweb.com
FF Extension: Snap.Do  - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\{96e1573f-e7e4-9f36-0509-dd0e99161bc7}
FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\jgb2a5vb.default\Extensions\WTB_GLOBAL.sqlite

Chrome: 
=======
CHR HomePage: chrome://newtab
CHR RestoreOnStartup: "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=hp&installDate=27/10/2013"
CHR DefaultSearchURL: (Web) - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=96e1573f-e7e4-9f36-0509-dd0e99161bc7&searchtype=ds&q={searchTerms}&installDate=27/10/2013
CHR DefaultSuggestURL: (Web) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR Extension: () - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab\background.html
CHR Extension: (Speed Test Analysis) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb\1.0.0.5_1
CHR Extension: (Amazon-Icon) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg\1.0_0
CHR Extension: (	"name":"Advanced SystemCare Surfing Protection",) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_1
CHR HKLM-x32\...\Chrome\Extension: [kckgnnipheglejoddfhekdjpbdbinhmb] - C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis\SpeedTestAnalysis.crx
CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Admin\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx

==================== Services (Whitelisted) =================

R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [878368 2013-10-25] (IObit)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [335168 2013-04-25] (IObit)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-10-25] (IObit)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-01-26] ()
S2 SecureUpdateSvc; C:\Program Files (x86)\Secure Speed Dial\IE\SecureUpdate.exe [2472272 2013-10-23] ()
R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-31] ()
S4 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [x]
S2 Update WebConnect; "C:\Program Files (x86)\WebConnect\updateWebConnect.exe" [x]
S2 UtilityChest_49Service; C:\PROGRA~2\UTILIT~2\bar\1.bin\49barsvc.exe [x]
S2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [x]
S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x]

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-12] (DT Soft Ltd)
S4 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34336 2013-03-26] (IObit.com)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [67024 2013-03-12] (Fuzhou Rockchip Electronics Co,Ltd.)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] ()
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-03-26] (IObit.com)
S3 WinRing0_1_2_0; C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [14544 2012-08-01] (OpenLibSys.org)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-24 11:57 - 2013-11-24 11:57 - 00020033 _____ C:\Users\Admin\Downloads\FRST.txt
2013-11-24 11:56 - 2013-11-24 11:56 - 00000000 ____D C:\FRST
2013-11-24 11:14 - 2013-11-24 11:15 - 01958396 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2013-11-23 14:50 - 2013-11-23 14:50 - 00006310 _____ C:\Users\Admin\Downloads\Universal Unbanner v1.0_mpgh.net.rar
2013-11-23 14:47 - 2013-11-23 14:47 - 05718872 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe
2013-11-23 13:43 - 2013-11-24 10:52 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Windows Net Data
2013-11-23 13:43 - 2013-11-23 13:43 - 00000187 _____ C:\Users\Admin\Desktop\Amazon.de.url
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\Downloads\Fast-IP-Changer
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\ChromeExtensions
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773
2013-11-23 13:42 - 2013-11-23 13:43 - 00669952 _____ C:\Users\Admin\Downloads\Fast-IP-Changer-Setup.exe
2013-11-22 16:25 - 2013-11-22 16:25 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-22 16:24 - 2013-11-22 16:24 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-11-22 16:20 - 2013-11-22 16:20 - 00002850 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Admin
2013-11-22 16:20 - 2013-11-22 16:20 - 00001141 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2013-11-22 16:19 - 2013-11-24 10:51 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job
2013-11-22 16:19 - 2013-11-22 16:20 - 00002133 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2013-11-22 16:19 - 2013-11-22 16:19 - 00003220 _____ C:\Windows\System32\Tasks\Driver Booster Scan
2013-11-22 16:19 - 2013-11-22 16:19 - 00002582 _____ C:\Windows\System32\Tasks\Driver Booster Update
2013-11-22 16:19 - 2013-11-22 16:19 - 00001108 _____ C:\Users\Public\Desktop\Driver Booster.lnk
2013-11-21 20:35 - 2013-11-21 20:35 - 00278869 _____ C:\Users\Admin\Documents\Unbenannt.wma
2013-11-20 18:05 - 2013-11-20 18:05 - 00004644 _____ C:\Users\Admin\Downloads\invite.ics
2013-11-19 16:56 - 2013-11-19 16:56 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2013-11-17 23:49 - 2013-11-17 23:49 - 00000000 ____D C:\Users\Admin\Documents\FIFA 12
2013-11-17 23:43 - 2013-11-17 23:43 - 01699550 _____ C:\Users\Admin\Downloads\fifapadconfig.exe
2013-11-17 21:57 - 2013-11-19 20:29 - 00000000 ____D C:\Users\Admin\Documents\FIFA 13
2013-11-17 21:53 - 2013-11-17 21:53 - 00002324 _____ C:\Users\Admin\Desktop\Play FIFA 13 nosTEAM.lnk
2013-11-17 15:18 - 2013-11-17 21:53 - 00000000 ____D C:\Users\Admin\Downloads\FIFA 13 =FIFA Soccer 13= PC full game ^^nosTEAM^^
2013-11-17 01:12 - 2013-11-17 01:12 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen
2013-11-15 16:41 - 2013-11-15 16:42 - 58575443 _____ C:\Users\Admin\Downloads\TGN Branding Kit 2.4.zip
2013-11-14 18:51 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 18:51 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 18:51 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-14 18:51 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 18:51 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-14 18:51 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-14 18:51 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-14 18:51 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-14 18:51 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 18:51 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-14 18:51 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-14 18:51 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-14 18:07 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 18:07 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 18:07 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 18:06 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 18:06 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 18:06 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 18:06 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 18:06 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-14 18:06 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 18:06 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 18:06 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 18:06 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 18:06 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 18:06 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 18:06 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 18:06 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 18:06 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 18:06 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 18:06 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 18:06 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 18:06 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 18:06 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 18:06 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 18:06 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-12 18:20 - 2013-11-12 18:20 - 00003166 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2013-11-12 18:20 - 2013-11-12 18:20 - 00003164 _____ C:\Windows\System32\Tasks\SmartDefragUpdate
2013-11-12 18:20 - 2013-05-22 18:49 - 00032600 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
2013-11-12 18:16 - 2013-11-12 18:16 - 00883928 _____ (Realtek                                            ) C:\Windows\system32\Drivers\Rt64win7.sys
2013-11-12 18:16 - 2013-11-12 18:16 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2013-11-12 18:16 - 2013-11-12 18:16 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2013-11-12 18:11 - 2013-11-12 18:11 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll
2013-11-12 18:11 - 2013-11-12 18:11 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll
2013-11-12 18:07 - 2013-11-12 18:07 - 00001177 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2013-11-12 18:07 - 2013-11-12 18:07 - 00001174 _____ C:\Users\Public\Desktop\Smart Defrag 2.lnk
2013-11-12 18:07 - 2013-05-22 18:49 - 00017720 _____ C:\Windows\system32\Drivers\SmartDefragDriver.sys
2013-11-12 18:00 - 2013-11-22 16:20 - 00001165 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2013-11-12 18:00 - 2013-11-22 16:18 - 00000000 ____D C:\Program Files (x86)\IObit
2013-11-12 18:00 - 2013-11-19 16:57 - 00000000 ____D C:\ProgramData\ProductData
2013-11-12 18:00 - 2013-11-19 16:57 - 00000000 ____D C:\ProgramData\IObit
2013-11-12 18:00 - 2013-11-12 18:07 - 00000000 ____D C:\Users\Admin\AppData\Roaming\IObit
2013-11-12 18:00 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-08 22:42 - 2013-11-23 14:43 - 00000000 ____D C:\Users\Admin\Desktop\TGN
2013-11-05 16:37 - 2013-11-05 16:38 - 00000000 ____D C:\Users\Admin\Documents\RZDB
2013-11-05 16:37 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mursoft
2013-11-04 21:41 - 2013-11-04 21:42 - 00000000 ____D C:\Program Files (x86)\Audio Recorder Pro
2013-11-03 21:52 - 2013-11-03 21:52 - 00000000 ____D C:\Users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu
2013-11-02 12:35 - 2013-11-02 12:47 - 23244493 _____ C:\Users\Admin\Documents\Media_Intro.mp4
2013-11-01 15:46 - 2013-11-01 15:57 - 03249771 _____ C:\Users\Admin\Documents\GAY.mp4
2013-11-01 12:05 - 2013-11-01 12:17 - 23113631 _____ C:\Users\Admin\Documents\Media Sergio Aktuell.mp4
2013-10-28 20:03 - 2013-10-28 20:06 - 00000600 _____ C:\Users\Admin\PUTTY.RND
2013-10-27 21:31 - 2013-10-27 21:31 - 00000000 ____D C:\Program Files (x86)\SimilarSites
2013-10-27 21:30 - 2013-10-27 21:30 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SimilarSites
2013-10-27 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Apple Computer
2013-10-27 12:47 - 2013-10-27 12:48 - 00000000 ____D C:\Users\Admin\AppData\Local\Smartbar
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\ProgramData\IBUpdaterService
2013-10-27 12:01 - 2013-10-27 12:01 - 00000000 ____D C:\ProgramData\Apple Computer
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\Users\Admin\AppData\Local\Apple
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\ProgramData\Apple
2013-10-27 11:43 - 2008-01-30 18:36 - 00090112 _____ (MindVision Software) C:\Windows\unvise32.exe
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\REVisionEffects
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Program Files (x86)\REVisionEffects
2013-10-26 13:44 - 2013-10-26 15:03 - 00000000 ____D C:\Users\Admin\AppData\Local\LooksBuilder
2013-10-26 12:28 - 2013-10-26 12:32 - 00000000 ____D C:\ProgramData\RedGiant
2013-10-26 12:28 - 2013-10-26 12:28 - 00003642 _____ C:\Windows\System32\Tasks\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\LooksBuilder
2013-10-26 12:28 - 2013-10-08 14:33 - 04890624 _____ C:\Windows\system32\LS3Renderer_x64.dll

==================== One Month Modified Files and Folders =======

2013-11-24 11:57 - 2013-11-24 11:57 - 00020033 _____ C:\Users\Admin\Downloads\FRST.txt
2013-11-24 11:56 - 2013-11-24 11:56 - 00000000 ____D C:\FRST
2013-11-24 11:53 - 2012-11-24 21:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\BitTorrent
2013-11-24 11:52 - 2013-09-13 23:51 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2013-11-24 11:15 - 2013-11-24 11:14 - 01958396 _____ (Farbar) C:\Users\Admin\Downloads\FRST64.exe
2013-11-24 11:01 - 2012-11-03 18:19 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe
2013-11-24 10:59 - 2013-07-27 17:49 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-24 10:59 - 2009-07-14 05:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-24 10:59 - 2009-07-14 05:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-24 10:56 - 2012-09-21 11:52 - 01049363 _____ C:\Windows\WindowsUpdate.log
2013-11-24 10:52 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Windows Net Data
2013-11-24 10:51 - 2013-11-22 16:19 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job
2013-11-24 10:51 - 2013-10-18 14:30 - 00010932 _____ C:\autoupdate.log
2013-11-24 10:51 - 2013-07-27 17:49 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-24 10:51 - 2012-10-19 22:41 - 00096332 _____ C:\Windows\PFRO.log
2013-11-24 10:51 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-24 10:51 - 2009-07-14 05:51 - 00093444 _____ C:\Windows\setupact.log
2013-11-23 14:50 - 2013-11-23 14:50 - 00006310 _____ C:\Users\Admin\Downloads\Universal Unbanner v1.0_mpgh.net.rar
2013-11-23 14:47 - 2013-11-23 14:47 - 05718872 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\vcredist_x64.exe
2013-11-23 14:43 - 2013-11-08 22:42 - 00000000 ____D C:\Users\Admin\Desktop\TGN
2013-11-23 13:43 - 2013-11-23 13:43 - 00000187 _____ C:\Users\Admin\Desktop\Amazon.de.url
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\Downloads\Fast-IP-Changer
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\ChromeExtensions
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Tempf72101802004da32e7f86b1d7a0eeae3
2013-11-23 13:43 - 2013-11-23 13:43 - 00000000 ____D C:\Users\Admin\AppData\Local\Temp8bed7913ae785723085e8a147597e773
2013-11-23 13:43 - 2013-11-23 13:42 - 00669952 _____ C:\Users\Admin\Downloads\Fast-IP-Changer-Setup.exe
2013-11-23 13:43 - 2012-09-21 11:56 - 00000000 ___RD C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-23 13:43 - 2012-09-21 11:56 - 00000000 ____D C:\Users\Admin
2013-11-22 16:30 - 2013-07-08 10:23 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-22 16:25 - 2013-11-22 16:25 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-22 16:25 - 2013-11-22 16:25 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-22 16:25 - 2009-07-13 22:59 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-22 16:24 - 2013-11-22 16:24 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-22 16:24 - 2013-11-22 16:24 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-11-22 16:24 - 2013-07-08 10:22 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-11-22 16:24 - 2013-07-08 10:22 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-11-22 16:24 - 2009-06-10 21:37 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-11-22 16:20 - 2013-11-22 16:20 - 00002850 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Admin
2013-11-22 16:20 - 2013-11-22 16:20 - 00001141 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2013-11-22 16:20 - 2013-11-22 16:19 - 00002133 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2013-11-22 16:20 - 2013-11-12 18:00 - 00001165 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2013-11-22 16:19 - 2013-11-22 16:19 - 00003220 _____ C:\Windows\System32\Tasks\Driver Booster Scan
2013-11-22 16:19 - 2013-11-22 16:19 - 00002582 _____ C:\Windows\System32\Tasks\Driver Booster Update
2013-11-22 16:19 - 2013-11-22 16:19 - 00001108 _____ C:\Users\Public\Desktop\Driver Booster.lnk
2013-11-22 16:18 - 2013-11-12 18:00 - 00000000 ____D C:\Program Files (x86)\IObit
2013-11-21 20:35 - 2013-11-21 20:35 - 00278869 _____ C:\Users\Admin\Documents\Unbenannt.wma
2013-11-21 20:34 - 2012-09-21 11:56 - 00000000 ____D C:\Users\Admin\AppData\Local\VirtualStore
2013-11-20 22:08 - 2013-09-15 19:07 - 00000000 ____D C:\Users\Admin\AppData\Local\Windows Live
2013-11-20 18:29 - 2013-09-21 22:27 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TS3Client
2013-11-20 18:05 - 2013-11-20 18:05 - 00004644 _____ C:\Users\Admin\Downloads\invite.ics
2013-11-19 20:52 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-19 20:29 - 2013-11-17 21:57 - 00000000 ____D C:\Users\Admin\Documents\FIFA 13
2013-11-19 16:59 - 2013-10-22 15:26 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-19 16:58 - 2012-10-19 20:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Adobe
2013-11-19 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\ProductData
2013-11-19 16:57 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\IObit
2013-11-19 16:56 - 2013-11-19 16:56 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2013-11-17 23:49 - 2013-11-17 23:49 - 00000000 ____D C:\Users\Admin\Documents\FIFA 12
2013-11-17 23:43 - 2013-11-17 23:43 - 01699550 _____ C:\Users\Admin\Downloads\fifapadconfig.exe
2013-11-17 21:53 - 2013-11-17 21:53 - 00002324 _____ C:\Users\Admin\Desktop\Play FIFA 13 nosTEAM.lnk
2013-11-17 21:53 - 2013-11-17 15:18 - 00000000 ____D C:\Users\Admin\Downloads\FIFA 13 =FIFA Soccer 13= PC full game ^^nosTEAM^^
2013-11-17 20:07 - 2013-09-03 22:23 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-17 13:33 - 2009-07-14 18:58 - 00696620 _____ C:\Windows\system32\perfh007.dat
2013-11-17 13:33 - 2009-07-14 18:58 - 00147916 _____ C:\Windows\system32\perfc007.dat
2013-11-17 13:33 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-17 02:00 - 2013-10-22 17:40 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen
2013-11-17 01:12 - 2013-11-17 01:12 - 00000132 _____ C:\Users\Admin\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen
2013-11-15 16:42 - 2013-11-15 16:41 - 58575443 _____ C:\Users\Admin\Downloads\TGN Branding Kit 2.4.zip
2013-11-15 16:40 - 2013-10-21 15:41 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 18:51 - 2012-12-20 23:52 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-14 18:48 - 2013-10-21 15:41 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-12 18:20 - 2013-11-12 18:20 - 00003166 _____ C:\Windows\System32\Tasks\SmartDefrag_Startup
2013-11-12 18:20 - 2013-11-12 18:20 - 00003164 _____ C:\Windows\System32\Tasks\SmartDefragUpdate
2013-11-12 18:16 - 2013-11-12 18:16 - 00883928 _____ (Realtek                                            ) C:\Windows\system32\Drivers\Rt64win7.sys
2013-11-12 18:16 - 2013-11-12 18:16 - 00108760 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2013-11-12 18:16 - 2013-11-12 18:16 - 00074456 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2013-11-12 18:13 - 2012-12-06 20:48 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-11-12 18:11 - 2013-11-12 18:11 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll
2013-11-12 18:11 - 2013-11-12 18:11 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll
2013-11-12 18:07 - 2013-11-12 18:07 - 00001177 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2013-11-12 18:07 - 2013-11-12 18:07 - 00001174 _____ C:\Users\Public\Desktop\Smart Defrag 2.lnk
2013-11-12 18:07 - 2013-11-12 18:00 - 00000000 ____D C:\Users\Admin\AppData\Roaming\IObit
2013-11-12 18:00 - 2013-11-12 18:00 - 00000000 ____D C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2013-11-12 18:00 - 2013-10-27 16:57 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Apple Computer
2013-11-11 05:50 - 2012-10-19 20:14 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-06 22:11 - 2013-03-10 11:57 - 00000000 ____D C:\Users\Admin\Downloads\cod mw3
2013-11-05 21:00 - 2013-10-06 18:47 - 00000000 ____D C:\Users\Admin\Documents\Bandicam
2013-11-05 16:38 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\Documents\RZDB
2013-11-05 16:37 - 2013-11-05 16:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mursoft
2013-11-05 16:07 - 2013-09-13 23:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-11-05 16:07 - 2013-09-13 23:51 - 00000000 ____D C:\ProgramData\Skype
2013-11-04 21:42 - 2013-11-04 21:41 - 00000000 ____D C:\Program Files (x86)\Audio Recorder Pro
2013-11-04 00:33 - 2013-09-27 19:08 - 00000000 ____D C:\Users\Admin\AppData\Local\fabi.me
2013-11-03 21:52 - 2013-11-03 21:52 - 00000000 ____D C:\Users\Admin\AppData\Local\TeknoGods_TotalKillaz.eu
2013-11-02 12:47 - 2013-11-02 12:35 - 23244493 _____ C:\Users\Admin\Documents\Media_Intro.mp4
2013-11-01 15:57 - 2013-11-01 15:46 - 03249771 _____ C:\Users\Admin\Documents\GAY.mp4
2013-11-01 12:17 - 2013-11-01 12:05 - 23113631 _____ C:\Users\Admin\Documents\Media Sergio Aktuell.mp4
2013-10-28 20:06 - 2013-10-28 20:03 - 00000600 _____ C:\Users\Admin\PUTTY.RND
2013-10-28 16:15 - 2013-10-17 19:18 - 00000000 ____D C:\Program Files (x86)\Secure Speed Dial
2013-10-27 21:31 - 2013-10-27 21:31 - 00000000 ____D C:\Program Files (x86)\SimilarSites
2013-10-27 21:30 - 2013-10-27 21:30 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SimilarSites
2013-10-27 12:48 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Local\Smartbar
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\Users\Admin\AppData\Roaming\SpeedTestAnalysis
2013-10-27 12:47 - 2013-10-27 12:47 - 00000000 ____D C:\ProgramData\IBUpdaterService
2013-10-27 12:45 - 2013-10-22 17:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\OpenCandy
2013-10-27 12:45 - 2013-10-22 17:20 - 00000000 ____D C:\Users\Admin\AppData\Roaming\DVDVideoSoft
2013-10-27 12:01 - 2013-10-27 12:01 - 00000000 ____D C:\ProgramData\Apple Computer
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\Users\Admin\AppData\Local\Apple
2013-10-27 11:59 - 2013-10-27 11:59 - 00000000 ____D C:\ProgramData\Apple
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\REVisionEffects
2013-10-27 11:40 - 2013-10-27 11:40 - 00000000 ____D C:\Program Files (x86)\REVisionEffects
2013-10-26 15:03 - 2013-10-26 13:44 - 00000000 ____D C:\Users\Admin\AppData\Local\LooksBuilder
2013-10-26 12:32 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\RedGiant
2013-10-26 12:32 - 2012-11-17 19:11 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-26 12:30 - 2013-02-03 10:27 - 00000000 ____D C:\Users\Admin\AppData\Local\Downloaded Installations
2013-10-26 12:28 - 2013-10-26 12:28 - 00003642 _____ C:\Windows\System32\Tasks\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\ProgramData\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant Link
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\Red Giant
2013-10-26 12:28 - 2013-10-26 12:28 - 00000000 ____D C:\Program Files (x86)\LooksBuilder

Files to move or delete:
====================
C:\Users\Admin\jagex_cl_loginapplet_LIVE.dat
C:\Users\Admin\jagex_cl_oldschool_LIVE.dat
C:\Users\Admin\jagex_cl_runescape_LIVE.dat
C:\Users\Admin\jagex_cl_runescape_LIVE1.dat
C:\Users\Admin\jagex_cl_runescape_LIVE2.dat
C:\Users\Admin\jagex_cl_runescape_LIVE3.dat
C:\Users\Admin\random.dat


Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\2qywsnv1.dll
C:\Users\Admin\AppData\Local\Temp\amazonicon_v3.exe
C:\Users\Admin\AppData\Local\Temp\amazoninstallernircmdc.exe
C:\Users\Admin\AppData\Local\Temp\bdfilters.dll
C:\Users\Admin\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Admin\AppData\Local\Temp\install_helper.exe
C:\Users\Admin\AppData\Local\Temp\jna1421531977279418979.dll
C:\Users\Admin\AppData\Local\Temp\jna2667399310951771970.dll
C:\Users\Admin\AppData\Local\Temp\jna51258232191993720.dll
C:\Users\Admin\AppData\Local\Temp\NGMDll.dll
C:\Users\Admin\AppData\Local\Temp\NGMResource.dll
C:\Users\Admin\AppData\Local\Temp\NGMSetup.exe
C:\Users\Admin\AppData\Local\Temp\ose00000.exe
C:\Users\Admin\AppData\Local\Temp\Quarantine.exe
C:\Users\Admin\AppData\Local\Temp\S63GJTpcBQ.exe
C:\Users\Admin\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Admin\AppData\Local\Temp\sdapskill.exe
C:\Users\Admin\AppData\Local\Temp\setup_fsu_cid.exe
C:\Users\Admin\AppData\Local\Temp\SimilarBundleGenericDl.exe
C:\Users\Admin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Admin\AppData\Local\Temp\SmartbarExeInstaller.exe
C:\Users\Admin\AppData\Local\Temp\SpeedTestSetup.exe
C:\Users\Admin\AppData\Local\Temp\unicows.dll
C:\Users\Admin\AppData\Local\Temp\uninst1.exe
C:\Users\Admin\AppData\Local\Temp\Uninstaller-3788.exe
C:\Users\Admin\AppData\Local\Temp\w0chwtqt.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-21 07:19

==================== End Of Log ============================
         

Und Addition.txt:

Code:
ATTFilter
Ran by Admin at 2013-11-24 12:12:12
Running from C:\Users\Admin\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}

==================== Installed Programs ======================

AccelerateTab (x32 Version: 1.4)
Adobe Creative Cloud (x32 Version: 2.1.2.232)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Photoshop CC (x32 Version: 14.0)
Adobe Premiere Pro CC (x32 Version: 7.0.0)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133)
Advanced SystemCare 7 (x32 Version: 7.0.6)
Akamai NetSession Interface (HKCU)
Apple Application Support (x32 Version: 2.1.5)
Apple Software Update (x32 Version: 2.1.3.127)
Audio Recorder Pro 3.70 (x32)
AutoCAD 2013 - Deutsch (German) (Version: 19.0.55.0)
AutoCAD 2013 Language Pack - Deutsch (German) (Version: 19.0.55.0)
Autodesk Content Service (x32 Version: 3.0.84.0)
Autodesk Content Service Language Pack (x32 Version: 3.0.84.0)
Autodesk Material Library 2013 (x32 Version: 3.0.13)
Autodesk Material Library Base Resolution Image Library 2013 (x32 Version: 3.0.13)
Autodesk Sync (Version: 3.5.24.0)
Bandicam (x32)
Bandisoft MPEG-1 Decoder (x32)
BitTorrent (x32 Version: 7.7.2.28499)
Color Suite v11.0.1 (x32 Version: 11.0.1)
D3DX10 (x32 Version: 15.4.2368.0902)
DAEMON Tools Lite (x32 Version: 4.46.1.0327)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Driver Booster (x32 Version: 1.0)
Effects Suite 64-bit (Version: 11.1.0)
Effects Suite 64-bit (x32 Version: 11.1.0)
FARO LS 1.1.406.58 (x32 Version: 4.6.58.2)
Fotogalerie (x32 Version: 16.4.3508.0205)
Free YouTube Download version 3.2.14.1022 (x32 Version: 3.2.14.1022)
Free YouTube to MP3 Converter version 3.12.13.925 (x32 Version: 3.12.13.925)
Google Chrome (x32 Version: 31.0.1650.57)
Google Earth Plug-in (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
HP Deskjet 3050A J611 series - Grundlegende Software für das Gerät (Version: 25.0.571.0)
HP Deskjet 3050A J611 series Hilfe (x32 Version: 140.0.2.2)
HP Update (x32 Version: 5.003.000.004)
IObit Malware Fighter (x32 Version: 2.1)
IObit Uninstaller (x32 Version: 3.0.4.1082)
Java 7 Update 9 (x32 Version: 7.0.90)
Java Auto Updater (x32 Version: 2.1.9.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Excel 2010 (Version: 14.0.6029.1000)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Excel 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 32-bit MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft PowerPoint 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Word 2010 (Version: 14.0.6029.1000)
Movie Maker (x32 Version: 16.4.3508.0205)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MyFreeCodec (HKCU)
Nexon Game Manager (x32)
NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49)
NVIDIA GeForce Experience 1.5.1 (Version: 1.5.1)
NVIDIA Install Application (Version: 2.1002.133.889)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Systemsteuerung 331.65 (Version: 331.65)
NVIDIA Update 6.4.23 (Version: 6.4.23)
NVIDIA Update Components (Version: 6.4.23)
PDF Settings CC (x32 Version: 12.0)
Photo Common (x32 Version: 16.4.3508.0205)
Photo Gallery (x32 Version: 16.4.3508.0205)
PunkBuster Services (x32 Version: 0.993)
QuickTime (x32 Version: 7.71.80.42)
Razer Game Booster (x32 Version: 3.7)
Red Giant Link (x32 Version: 1.7.19.0)
ReelSmart Motion Blur 4, After Effects-compatible plugin set (x32)
RuckZuck (x32 Version: 6.0.10)
Samsung Kies (x32 Version: 2.6.0.13091_9)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
Skype™ 6.10 (x32 Version: 6.10.104)
Smart Defrag 2 (x32 Version: 2.9)
Snap.Do (x32 Version: 1.102.1.11691)
Speed Test Analysis (x32 Version: 1.0.0.5)
Surfing Protection (x32 Version: 1.0)
Sweet Home 3D version 3.7 (x32)
swMSM (x32 Version: 12.0.0.1)
System Requirements Lab CYRI (x32 Version: 5.0.6.0)
TeamSpeak 3 Client (Version: 3.0.12)
Twixtor 5, After Effects-compatible plugin set (x32)
Twixtor 6, After Effects-compatible plugin set (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 64-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 64-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition
Utility Chest Internet Explorer Toolbar (x32)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205)
Windows Live Essentials (x32 Version: 16.4.3508.0205)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (x32 Version: 16.4.3508.0205)
Windows Live Photo Common (x32 Version: 16.4.3508.0205)
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205)
Windows Live SOXE (x32 Version: 16.4.3508.0205)
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205)
Windows Live UX Platform (x32 Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205)
Windows Utils (x32)
WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0)
WinZipper (x32 Version: 1.4.8)

==================== Restore Points  =========================

14-11-2013 17:47:26 Windows Update
19-11-2013 15:52:51 Windows Update
22-11-2013 15:23:43 Driver Booster : NVIDIA GeForce 8800 GTS

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {135AE771-2D3B-462E-8F30-CE5D99E1CCC4} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {1ECDF9E5-1736-47FA-9F68-D17777C66F26} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Red Giant Link.exe [2013-10-10] ()
Task: {32E25F8E-1749-45A9-9721-9794EB156E14} - System32\Tasks\SmartDefragUpdate => C:\Program Files (x86)\IObit\Smart Defrag 2\AutoUpdate.exe [2013-05-22] (IObit)
Task: {4AA883C5-A4D9-4094-937C-E3D07281461C} - System32\Tasks\ASC7_SkipUac_Admin => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2013-11-14] (IObit)
Task: {5C452C96-E65D-4030-B3C1-A20719FA7A7D} - System32\Tasks\Driver Booster Scan => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2013-09-08] (IObit)
Task: {6D939925-0559-4FFF-983F-100C4B9510E2} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe [2013-06-05] ()
Task: {71D4CCA7-7AE8-4EAB-B078-AC718607E749} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.)
Task: {89659F6B-903E-4AE9-8638-3F6299D0CCB4} - \CPU Grid Computing No Task File
Task: {8D5768D7-0BF7-4B7E-B4EF-2B533AF729A3} - System32\Tasks\SmartDefrag_Startup => C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe [2013-09-13] (IObit)
Task: {8DE526A6-E0DE-4613-B213-435FFB35B8F7} - \The Bluetooth service discovery No Task File
Task: {A327627E-50BC-4181-AFB4-661E3EB00912} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [2011-03-24] (Hewlett-Packard)
Task: {A72FE025-AA38-40EE-BCF7-ABC9A84C4852} - \AdobeFlashPlayerUpdate 2 No Task File
Task: {A7B37A96-087C-4BC9-BCE0-469A9FAABD66} - System32\Tasks\Driver Booster Update => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe [2013-09-08] (IObit)
Task: {AC6C9BFE-6D97-4EC4-8BCA-482E1FF41A1C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27] (Google Inc.)
Task: {AE193498-0C1E-4429-9017-6CC81CA63ACA} - System32\Tasks\AdobeAAMUpdater-1.0-PC-Admin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-06-13] (Adobe Systems Incorporated)
Task: {C37565D0-014E-47D4-83EA-4411ED708EF9} - System32\Tasks\hpUrlLauncher.exe_{F897C458-ADC9-403E-BBD9-FF9E01A0A29F} => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\utils\hpUrlLauncher.exe [2011-06-08] (Hewlett-Packard Co.)
Task: {DB0FF65C-8F09-4C52-BAEC-0FAD6A5A706C} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe
Task: {E35029B4-73DE-4341-8C43-FFAADAF0D4FB} - \AdobeFlashPlayerUpdate No Task File
Task: {E389FFAE-9FD5-4610-BB82-17FA20CF858E} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {E4D749A2-89E1-4257-81F6-3F4FBE02D0D5} - System32\Tasks\{901D29C3-49F3-49F5-9378-C1DCB736EDE9} => C:\Users\Admin\Downloads\Xpadder.exe
Task: {F1E0DC7B-D17A-4019-B6D8-0AB183F8E8E0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-27] (Google Inc.)
Task: C:\Windows\Tasks\Driver Booster Update.job => C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-08-30 09:01 - 2013-08-30 09:01 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll
2013-11-22 16:19 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\sqlite3.dll
2013-11-12 18:07 - 2013-09-11 19:06 - 00048960 _____ () C:\Program Files (x86)\IObit\Smart Defrag 2\NtfsData.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00032800 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00056352 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00150560 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00112672 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 01767456 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00078880 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00013344 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00726048 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00081952 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00014368 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00016928 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
2013-08-04 19:51 - 2013-08-04 19:51 - 00020512 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll
2013-08-04 19:51 - 2013-08-04 19:51 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00057888 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00014368 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll
2013-07-16 13:20 - 2013-07-16 13:20 - 00911128 _____ () C:\Windows\assembly\GAC_32\System.Data.SQLite\1.0.66.0__db937bc2d44ff139\System.Data.SQLite.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00014880 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00052256 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00048160 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll
2013-08-04 19:51 - 2013-08-04 19:51 - 00026144 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
2013-08-04 19:41 - 2013-08-04 19:41 - 00194080 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.dll
2013-08-04 19:40 - 2013-08-04 19:40 - 00068640 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll
2013-08-04 19:50 - 2013-08-04 19:50 - 00246304 _____ () C:\Users\Admin\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll
2013-09-03 14:25 - 2013-09-03 14:25 - 32726528 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
2013-03-13 12:42 - 2013-06-05 13:21 - 00071560 _____ () C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\zlib1.dll
2013-08-30 09:00 - 2013-08-30 09:00 - 00381808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll
2013-11-17 20:07 - 2013-11-14 12:28 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-17 20:07 - 2013-11-14 12:28 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libegl.dll
2013-11-17 20:07 - 2013-11-14 12:29 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-17 20:07 - 2013-11-14 12:29 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-17 20:07 - 2013-11-14 12:28 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2013-11-17 20:07 - 2013-11-14 12:29 - 13582800 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:373E1720

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/18/2013 01:10:17 AM) (Source: IMFservice) (User: )
Description: Das Handle ist ungültig

Error: (11/18/2013 01:10:17 AM) (Source: IMFservice) (User: )
Description: Das Handle ist ungültig

Error: (11/10/2013 11:52:02 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0xffff3fa4
ID des fehlerhaften Prozesses: 0x330
Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0
Pfad der fehlerhaften Anwendung: iw5mp.exe1
Pfad des fehlerhaften Moduls: iw5mp.exe2
Berichtskennung: iw5mp.exe3

Error: (11/10/2013 11:47:10 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f
Name des fehlerhaften Moduls: nvd3dum.dll, Version: 9.18.13.2049, Zeitstempel: 0x51c40fa2
Ausnahmecode: 0xc0000005
Fehleroffset: 0x004af57a
ID des fehlerhaften Prozesses: 0x10c0
Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0
Pfad der fehlerhaften Anwendung: iw5mp.exe1
Pfad des fehlerhaften Moduls: iw5mp.exe2
Berichtskennung: iw5mp.exe3

Error: (11/10/2013 07:02:25 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iw5mp.exe, Version: 0.0.0.0, Zeitstempel: 0x4f186c8f
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0xffff3f80
ID des fehlerhaften Prozesses: 0x880
Startzeit der fehlerhaften Anwendung: 0xiw5mp.exe0
Pfad der fehlerhaften Anwendung: iw5mp.exe1
Pfad des fehlerhaften Moduls: iw5mp.exe2
Berichtskennung: iw5mp.exe3

Error: (11/10/2013 00:58:58 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WoulClass.vshost.exe, Version: 11.0.50727.1, Zeitstempel: 0x5011d446
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe0434f4d
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xWoulClass.vshost.exe0
Pfad der fehlerhaften Anwendung: WoulClass.vshost.exe1
Pfad des fehlerhaften Moduls: WoulClass.vshost.exe2
Berichtskennung: WoulClass.vshost.exe3

Error: (11/10/2013 00:58:47 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WoulClass.vshost.exe, Version: 11.0.50727.1, Zeitstempel: 0x5011d446
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe0434f4d
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xWoulClass.vshost.exe0
Pfad der fehlerhaften Anwendung: WoulClass.vshost.exe1
Pfad des fehlerhaften Moduls: WoulClass.vshost.exe2
Berichtskennung: WoulClass.vshost.exe3

Error: (11/03/2013 09:52:42 PM) (Source: Application Hang) (User: )
Description: Programm iw5mp.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 560

Startzeit: 01ced8d68fca516b

Endzeit: 38

Anwendungspfad: C:\Users\Admin\Downloads\Teknogods 2.7.1.2\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exe

Berichts-ID: df0dbe24-44c9-11e3-95d6-001bfcfb8327

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.


System errors:
=============
Error: (11/24/2013 10:53:42 AM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005

Error: (11/24/2013 10:52:26 AM) (Source: Service Control Manager) (User: )
Description: Dienst "SecureUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/24/2013 10:51:26 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Utility ChestService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/24/2013 10:51:26 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Update WebConnect" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/24/2013 10:51:17 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Wsys Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/24/2013 10:51:17 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinZiper service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/23/2013 10:27:08 AM) (Source: Service Control Manager) (User: )
Description: Dienst "SecureUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (11/23/2013 10:26:08 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Utility ChestService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/23/2013 10:26:08 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Update WebConnect" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (11/23/2013 10:25:59 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Wsys Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2


Microsoft Office Sessions:
=========================
Error: (11/18/2013 01:10:17 AM) (Source: IMFservice)(User: )
Description: Das Handle ist ungültig

Error: (11/18/2013 01:10:17 AM) (Source: IMFservice)(User: )
Description: Das Handle ist ungültig

Error: (11/10/2013 11:52:02 PM) (Source: Application Error)(User: )
Description: iw5mp.exe0.0.0.04f186c8funknown0.0.0.000000000c0000005ffff3fa433001cede66d2662730C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeunknownb6270760-4a5a-11e3-9172-001bfcfb8327

Error: (11/10/2013 11:47:10 PM) (Source: Application Error)(User: )
Description: iw5mp.exe0.0.0.04f186c8fnvd3dum.dll9.18.13.204951c40fa2c0000005004af57a10c001cede6570685656C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeC:\Windows\system32\nvd3dum.dll081bb54f-4a5a-11e3-9172-001bfcfb8327

Error: (11/10/2013 07:02:25 PM) (Source: Application Error)(User: )
Description: iw5mp.exe0.0.0.04f186c8funknown0.0.0.000000000c0000005ffff3f8088001cede3ef2a128a2C:\Users\Admin\Downloads\cod mw3\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exeunknown40a9e580-4a32-11e3-9172-001bfcfb8327

Error: (11/10/2013 00:58:58 AM) (Source: Application Error)(User: )
Description: WoulClass.vshost.exe11.0.50727.15011d446KERNELBASE.dll6.1.7601.1822951fb1677e0434f4d000000000000940d

Error: (11/10/2013 00:58:47 AM) (Source: Application Error)(User: )
Description: WoulClass.vshost.exe11.0.50727.15011d446KERNELBASE.dll6.1.7601.1822951fb1677e0434f4d000000000000940d

Error: (11/03/2013 09:52:42 PM) (Source: Application Hang)(User: )
Description: iw5mp.exe0.0.0.056001ced8d68fca516b38C:\Users\Admin\Downloads\Teknogods 2.7.1.2\Call Of Duty Modern Warfare 3 Full Multiplayer\iw5mp.exedf0dbe24-44c9-11e3-95d6-001bfcfb8327

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Admin\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe

Error: (10/28/2013 11:52:29 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Users\Admin\Downloads\SoftonicDownloader_fuer_winrar.exe


==================== Memory info =========================== 

Percentage of memory in use: 56%
Total physical RAM: 4095.18 MB
Available physical RAM: 1770.45 MB
Total Pagefile: 8188.54 MB
Available Pagefile: 5518.29 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:297.99 GB) (Free:153.12 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D13C098D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

 

Themen zu _GETWINDOWINFO-Trojaner
amazon-icon, branding, browser, darkcomet, darkcomet rat, defender, driver booster, excel, flash player, getwindowinfo, google, internet, internet exlorer, internet explorer, mozilla, newtab, plug-in, pup.optional.elex.a, pup.optional.smartbar.a, pup.optional.snapdo, pup.optional.sweetim, realtek, richtlinie, schutz, services.exe, smartbar, svchost.exe, trojaner, vcredist





Zum Thema _GETWINDOWINFO-Trojaner - Hallo Leute, Heute Früh, nachdem ich den PC angeschaltet habe, hat sich interessanterweise der Internet Explorer mit dem Link: hxxp://www_getwindowinfo/ geöffnet, welcher nicht geschlossen werden kann. Interessante Anmerkung : Ich - _GETWINDOWINFO-Trojaner...
Archiv
Du betrachtest: _GETWINDOWINFO-Trojaner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.