|
Plagegeister aller Art und deren Bekämpfung: PC gekapert?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
17.12.2013, 15:30 | #1 |
| PC gekapert? Hallo! Ich habe die Vermutung das mein PC gekapert worden ist.Ich hatte Malwarebytes durchlaufen lassen und der fand mehrere PUP Optional Viren.Daraufhin formatierte ich meinen Pc und nach der Neuaufspielung meines Win7 home 64 bit ,hatte ich dieselben Probleme wieder.Ich bitte um Hilfe weiss mir langsam keinen Rat mehr.Danke im voraus Gotthard Bienias |
17.12.2013, 15:55 | #2 |
/// the machine /// TB-Ausbilder | PC gekapert? Hi,
__________________haste mal geschaut was PUP ist? What is PUP (potentially unwanted program)? - Definition from WhatIs.com Das ist einfach nur Adware oder ein Tool was Du installierst, wo ne Toolbar dabei ist. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
18.12.2013, 05:47 | #3 |
| PC gekapert? Hallo
__________________Vielen Dank für die schnelle Antwort.Hier sind die Logfiles. |
18.12.2013, 12:08 | #4 |
/// the machine /// TB-Ausbilder | PC gekapert? Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.12.2013, 17:00 | #5 |
| PC gekapert? FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2013 02 Ran by Gotthard Bienias (administrator) on MEINER on 18-12-2013 05:33:21 Running from C:\Users\Gotthard Bienias\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-05] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7883296 2009-06-16] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-06-16] (Realtek Semiconductor Corp.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] () HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-12-16] (Kaspersky Lab ZAO) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default Startup: C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung SSD Magician.lnk ShortcutTarget: Samsung SSD Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung SSD Magician.exe (Samsung Electronics.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Tcpip\Parameters: [DhcpNameServer] 62.117.1.25 89.16.129.25 FireFox: ======== FF ProfilePath: C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default FF user.js: detected! => C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @kaspersky.com/Password Manager - I:\Kaspersky Password Manager\npkpmAutofill.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: Adblock Plus - C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com Chrome: ======= CHR DefaultSearchKeyword: google.de CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding} CHR Extension: (Google Docs) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Kaspersky URL Advisor) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\14.0.0.4651_0 CHR Extension: (Safe Money) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\14.0.0.4651_0 CHR Extension: (Dangerous Websites Blocker) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0 CHR Extension: (Virtual Keyboard) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\14.0.0.4794_0 CHR Extension: (Google Wallet) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR Extension: (Anti-Banner) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\14.0.0.4651_0 CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-12-16] (Kaspersky Lab ZAO) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-12-01] () R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2409272 2013-12-10] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-30] (Intel Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-16] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-12-16] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-16] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-12-16] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-12-16] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-12-16] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-12-16] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2013-03-26] (TuneUp Software) U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-12-16] (Kaspersky Lab ZAO) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-18 05:33 - 2013-12-18 05:33 - 00016576 _____ C:\Users\Gotthard Bienias\Downloads\FRST.txt 2013-12-18 05:32 - 2013-12-18 05:32 - 00000000 ____D C:\FRST 2013-12-18 05:31 - 2013-12-18 05:31 - 01928214 _____ (Farbar) C:\Users\Gotthard Bienias\Downloads\FRST64.exe 2013-12-17 15:44 - 2013-12-17 15:44 - 00001188 _____ C:\Users\Gotthard Bienias\Desktop\OpenOffice 4.0.1.lnk 2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ___SD C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1 2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\OpenOffice 2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-12-17 15:12 - 2013-12-17 15:18 - 163606685 _____ C:\Users\Gotthard Bienias\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2013-12-17 05:43 - 2013-12-18 05:18 - 00000504 _____ C:\Windows\setupact.log 2013-12-17 05:43 - 2013-12-17 05:43 - 00000000 _____ C:\Windows\setuperr.log 2013-12-16 19:55 - 2013-12-16 19:55 - 00002344 _____ C:\Users\Gotthard Bienias\Desktop\Sicherer Zahlungsverkehr.lnk 2013-12-16 19:55 - 2013-12-16 19:54 - 00001150 _____ C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk 2013-12-16 19:54 - 2013-12-18 05:21 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-12-16 19:54 - 2013-12-16 20:01 - 00626272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-12-16 19:54 - 2013-12-16 20:01 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-12-16 19:54 - 2012-07-11 17:09 - 00064856 _____ (Kaspersky Lab) C:\Windows\system32\klfphc.dll 2013-12-16 19:48 - 2013-12-18 05:21 - 00164523 _____ C:\Windows\WindowsUpdate.log 2013-12-16 19:40 - 2013-12-16 19:41 - 165974760 _____ (Kaspersky Lab) C:\Users\Gotthard Bienias\Downloads\kis13.0.1.4190de-de.exe 2013-12-16 19:28 - 2013-12-16 19:28 - 00078776 _____ C:\Users\Gotthard Bienias\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-16 19:27 - 2013-12-18 05:18 - 00366544 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-16 16:04 - 2013-12-16 16:04 - 00000000 _____ C:\Users\Gotthard Bienias\Desktop\Neues Textdokument.txt 2013-12-15 18:11 - 2013-12-15 18:11 - 00000000 ____D C:\Program Files\7-Zip 2013-12-15 17:57 - 2013-12-15 18:05 - 136952609 _____ C:\Users\Gotthard Bienias\Downloads\T-GAP8DEUC-1029.0.exe 2013-12-14 16:01 - 2013-12-14 16:01 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\NVIDIA 2013-12-14 15:31 - 2013-12-14 15:31 - 00000222 _____ C:\Users\Gotthard Bienias\Desktop\Neverwinter.url 2013-12-14 15:31 - 2013-12-14 15:31 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-12-12 17:31 - 2013-12-10 18:43 - 00038200 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2013-12-12 17:31 - 2013-12-10 18:43 - 00030520 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll 2013-12-12 06:39 - 2013-12-12 06:39 - 23867560 _____ (Mozilla) C:\Users\Gotthard Bienias\Downloads\Firefox_Setup_26.0.exe 2013-12-11 05:50 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 05:50 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 05:50 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 05:50 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 05:49 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 05:49 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 05:49 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 05:49 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 05:49 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 05:49 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 05:49 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 05:49 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 05:49 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 05:49 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 05:49 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 05:49 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 05:49 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 05:49 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 05:49 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 05:49 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 05:49 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 05:49 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 05:49 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 05:49 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 05:49 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 05:49 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 05:49 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 05:49 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 05:49 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 05:49 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 05:49 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 05:49 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 05:49 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 05:49 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 05:49 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 05:48 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 05:48 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 05:48 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 05:48 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 05:48 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 05:48 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 05:48 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 05:48 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 05:48 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 05:48 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 05:48 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 05:48 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 05:48 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 05:48 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 05:48 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 05:48 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 05:48 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 05:48 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 05:48 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-10 17:12 - 2013-12-10 17:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-12-10 17:10 - 2013-12-10 17:10 - 00000000 ____D C:\Program Files\SAMSUNG 2013-12-10 17:10 - 2013-08-21 05:31 - 00204568 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2013-12-10 17:10 - 2013-08-21 05:31 - 00103576 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2013-12-10 17:08 - 2013-12-14 09:06 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Downloaded Installations 2013-12-10 17:08 - 2013-12-10 17:08 - 00001973 _____ C:\Users\Public\Desktop\Samsung Kies 3.lnk 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\SelfMV 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\samsung 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Samsung 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-12-10 17:07 - 2013-12-10 17:07 - 38825784 _____ (Samsung Electronics Co., Ltd. ) C:\Users\Gotthard Bienias\Downloads\Kies3Setup.exe 2013-12-10 16:17 - 2013-12-10 16:17 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Kaspersky Lab 2013-12-10 15:27 - 2013-12-10 15:30 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\vlc 2013-12-10 15:27 - 2013-12-10 15:27 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-12-10 15:26 - 2013-12-10 15:26 - 24097311 _____ C:\Users\Gotthard Bienias\Downloads\vlc-2.1.2-win32.exe 2013-12-10 15:26 - 2013-12-10 15:26 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\PunkBuster 2013-12-03 06:46 - 2013-10-30 18:03 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-12-03 06:46 - 2013-10-30 18:02 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-12-02 06:19 - 2013-12-08 18:24 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\CrashDumps 2013-12-01 17:21 - 2013-12-01 17:24 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\Battlefield 4 2013-12-01 17:21 - 2013-12-01 17:21 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\ESN 2013-12-01 17:15 - 2013-12-09 16:00 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-01 17:15 - 2013-12-02 05:36 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-12-01 17:15 - 2013-12-01 17:15 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-12-01 17:14 - 2013-12-01 17:14 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-12-01 17:14 - 2013-12-01 17:14 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-01 14:36 - 2013-12-01 14:36 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-01 13:52 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-01 13:50 - 2013-12-01 13:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-01 13:50 - 2013-12-01 13:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-01 13:50 - 2013-12-01 13:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-01 13:50 - 2013-12-01 13:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-01 13:50 - 2013-12-01 13:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-01 13:29 - 2013-11-23 20:26 - 30361888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 22951200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 18208624 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 15862272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 12613920 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-12-01 13:29 - 2013-11-23 20:26 - 11566648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 11441664 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 09663656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 09619872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433193.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433193.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00707360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00657184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00609568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00562464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-12-01 13:29 - 2013-11-23 20:26 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-12-01 13:27 - 2013-12-03 06:46 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NVIDIA Corporation 2013-12-01 10:14 - 2013-12-17 15:51 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-01 10:14 - 2013-12-01 10:14 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk 2013-12-01 09:55 - 2013-12-01 17:19 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Origin 2013-12-01 09:55 - 2013-12-01 13:36 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Origin 2013-12-01 09:54 - 2013-12-14 15:32 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-12-01 09:54 - 2013-12-09 15:23 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-01 09:54 - 2013-12-01 17:21 - 00000000 ____D C:\ProgramData\Origin 2013-12-01 09:54 - 2013-12-01 09:54 - 00000983 _____ C:\Users\Public\Desktop\Origin.lnk 2013-12-01 09:54 - 2013-12-01 09:54 - 00000074 _____ C:\Windows\wininit.ini 2013-11-29 16:02 - 2013-11-29 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-11-29 15:57 - 2013-11-29 15:57 - 00001440 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk 2013-11-29 15:52 - 2013-11-19 03:33 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-29 15:48 - 2013-11-29 15:57 - 00001243 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-11-29 15:48 - 2013-11-29 15:57 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\DVDVideoSoft 2013-11-29 15:48 - 2013-11-29 15:57 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-11-29 15:48 - 2013-11-29 15:48 - 00001536 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2013-11-29 15:16 - 2013-11-29 15:16 - 00249444 _____ C:\ProgramData\1385734552.bdinstall.bin 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJSolutionMenuEX 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonEPP 2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\ProgramData\CanonIJMSetup 2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\Program Files\Common Files\CANON 2013-11-23 19:06 - 2013-11-23 19:06 - 00002079 _____ C:\Users\Public\Desktop\Canon Solution Menu EX.lnk 2013-11-23 19:06 - 2013-11-23 19:06 - 00000000 ____D C:\ProgramData\CanonIJWSpt 2013-11-23 19:04 - 2013-11-23 19:04 - 00002360 _____ C:\Users\Public\Desktop\Canon MG6100 series Online-Handbuch.lnk 2013-11-23 19:04 - 2013-11-23 19:04 - 00000000 ____D C:\Program Files\Canon 2013-11-23 18:58 - 2013-11-23 18:58 - 00000000 ____D C:\Windows\system32\STRING 2013-11-23 18:58 - 2010-02-05 02:37 - 00327680 _____ (CANON INC.) C:\Windows\system32\CNMN6PPM.DLL 2013-11-23 18:58 - 2010-02-05 02:37 - 00037376 _____ (CANON INC.) C:\Windows\system32\CNMN6UI.DLL 2013-11-23 18:56 - 2013-11-23 19:10 - 00000000 ____D C:\Program Files (x86)\Canon 2013-11-23 12:18 - 2013-11-23 12:18 - 00590112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-11-23 06:59 - 2013-12-12 06:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-23 06:47 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-23 06:47 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-23 06:47 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-23 06:47 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-23 06:47 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-23 06:47 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-23 06:47 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-23 06:47 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-23 06:47 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-23 06:47 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-23 06:47 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-23 06:47 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-23 06:47 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-23 06:47 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-23 06:47 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-23 06:47 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-23 06:47 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-23 06:47 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-23 06:47 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-23 06:47 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-23 06:47 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-23 06:47 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-23 06:47 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-23 06:47 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-23 06:47 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-23 06:47 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-23 06:47 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-23 06:47 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-23 06:47 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-23 06:47 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys ==================== One Month Modified Files and Folders ======= 2013-12-18 05:33 - 2013-12-18 05:33 - 00016576 _____ C:\Users\Gotthard Bienias\Downloads\FRST.txt 2013-12-18 05:32 - 2013-12-18 05:32 - 00000000 ____D C:\FRST 2013-12-18 05:31 - 2013-12-18 05:31 - 01928214 _____ (Farbar) C:\Users\Gotthard Bienias\Downloads\FRST64.exe 2013-12-18 05:30 - 2013-11-02 09:17 - 00001130 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-18 05:25 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-18 05:25 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-18 05:24 - 2013-10-28 23:13 - 00700454 _____ C:\Windows\system32\perfh007.dat 2013-12-18 05:24 - 2013-10-28 23:13 - 00150092 _____ C:\Windows\system32\perfc007.dat 2013-12-18 05:24 - 2009-07-14 06:13 - 01624034 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-18 05:21 - 2013-12-16 19:54 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-12-18 05:21 - 2013-12-16 19:48 - 00164523 _____ C:\Windows\WindowsUpdate.log 2013-12-18 05:20 - 2013-11-02 09:17 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-18 05:18 - 2013-12-17 05:43 - 00000504 _____ C:\Windows\setupact.log 2013-12-18 05:18 - 2013-12-16 19:27 - 00366544 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-18 05:18 - 2013-10-30 14:47 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-18 05:18 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-17 19:57 - 2013-10-30 17:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-17 15:51 - 2013-12-01 10:14 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-17 15:44 - 2013-12-17 15:44 - 00001188 _____ C:\Users\Gotthard Bienias\Desktop\OpenOffice 4.0.1.lnk 2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ___SD C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1 2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\OpenOffice 2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-12-17 15:42 - 2013-10-31 15:16 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\PrivaZer 2013-12-17 15:18 - 2013-12-17 15:12 - 163606685 _____ C:\Users\Gotthard Bienias\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2013-12-17 05:43 - 2013-12-17 05:43 - 00000000 _____ C:\Windows\setuperr.log 2013-12-16 20:01 - 2013-12-16 19:54 - 00626272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2013-12-16 20:01 - 2013-12-16 19:54 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2013-12-16 20:01 - 2012-08-13 16:49 - 00178448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2013-12-16 20:01 - 2012-08-02 15:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2013-12-16 20:01 - 2012-07-25 14:53 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klmouflt.sys 2013-12-16 20:01 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-12-16 20:01 - 2012-06-08 11:38 - 00054368 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kltdi.sys 2013-12-16 20:01 - 2012-05-25 19:38 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2013-12-16 19:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-16 19:55 - 2013-12-16 19:55 - 00002344 _____ C:\Users\Gotthard Bienias\Desktop\Sicherer Zahlungsverkehr.lnk 2013-12-16 19:54 - 2013-12-16 19:55 - 00001150 _____ C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk 2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Windows\ELAMBKUP 2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2013-12-16 19:51 - 2013-10-31 06:54 - 00000000 ____D C:\Users\Gast 2013-12-16 19:41 - 2013-12-16 19:40 - 165974760 _____ (Kaspersky Lab) C:\Users\Gotthard Bienias\Downloads\kis13.0.1.4190de-de.exe 2013-12-16 19:34 - 2009-07-14 06:08 - 00001386 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-16 19:28 - 2013-12-16 19:28 - 00078776 _____ C:\Users\Gotthard Bienias\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-16 16:04 - 2013-12-16 16:04 - 00000000 _____ C:\Users\Gotthard Bienias\Desktop\Neues Textdokument.txt 2013-12-15 18:11 - 2013-12-15 18:11 - 00000000 ____D C:\Program Files\7-Zip 2013-12-15 18:05 - 2013-12-15 17:57 - 136952609 _____ C:\Users\Gotthard Bienias\Downloads\T-GAP8DEUC-1029.0.exe 2013-12-14 16:01 - 2013-12-14 16:01 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\NVIDIA 2013-12-14 15:32 - 2013-12-01 09:54 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-12-14 15:31 - 2013-12-14 15:31 - 00000222 _____ C:\Users\Gotthard Bienias\Desktop\Neverwinter.url 2013-12-14 15:31 - 2013-12-14 15:31 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-12-14 09:06 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Downloaded Installations 2013-12-14 09:06 - 2013-10-31 08:30 - 00000000 ____D C:\ProgramData\DriverGenius 2013-12-12 17:31 - 2013-10-31 10:16 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2013 2013-12-12 15:58 - 2013-10-30 15:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-12 06:57 - 2013-10-30 17:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-12 06:57 - 2013-10-30 17:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-12 06:57 - 2013-10-30 17:20 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-12 06:40 - 2013-11-23 06:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-12 06:40 - 2013-10-30 15:32 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-12-12 06:39 - 2013-12-12 06:39 - 23867560 _____ (Mozilla) C:\Users\Gotthard Bienias\Downloads\Firefox_Setup_26.0.exe 2013-12-11 05:52 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-11 05:49 - 2013-10-30 14:34 - 00000000 ____D C:\Windows\system32\MRT 2013-12-11 05:48 - 2013-10-30 14:34 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-10 18:43 - 2013-12-12 17:31 - 00038200 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll 2013-12-10 18:43 - 2013-12-12 17:31 - 00030520 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll 2013-12-10 18:43 - 2013-10-31 10:17 - 00035640 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2013-12-10 18:43 - 2013-10-31 10:17 - 00026936 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2013-12-10 18:43 - 2013-10-31 10:17 - 00022328 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2013-12-10 17:12 - 2013-12-10 17:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-12-10 17:10 - 2013-12-10 17:10 - 00000000 ____D C:\Program Files\SAMSUNG 2013-12-10 17:10 - 2013-10-30 14:13 - 00000000 ____D C:\ProgramData\Samsung 2013-12-10 17:08 - 2013-12-10 17:08 - 00001973 _____ C:\Users\Public\Desktop\Samsung Kies 3.lnk 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\SelfMV 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\samsung 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Samsung 2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-12-10 17:08 - 2009-09-17 22:04 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-10 17:07 - 2013-12-10 17:07 - 38825784 _____ (Samsung Electronics Co., Ltd. ) C:\Users\Gotthard Bienias\Downloads\Kies3Setup.exe 2013-12-10 16:17 - 2013-12-10 16:17 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Kaspersky Lab 2013-12-10 16:05 - 2013-10-31 08:47 - 00000000 ____D C:\Windows\SysWOW64\sda 2013-12-10 16:01 - 2013-10-28 14:25 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-12-10 15:31 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-12-10 15:30 - 2013-12-10 15:27 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\vlc 2013-12-10 15:27 - 2013-12-10 15:27 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-12-10 15:26 - 2013-12-10 15:26 - 24097311 _____ C:\Users\Gotthard Bienias\Downloads\vlc-2.1.2-win32.exe 2013-12-10 15:26 - 2013-12-10 15:26 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\PunkBuster 2013-12-09 16:00 - 2013-12-01 17:15 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-09 15:23 - 2013-12-01 09:54 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-08 18:24 - 2013-12-02 06:19 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\CrashDumps 2013-12-08 15:25 - 2013-11-02 09:17 - 00004126 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-08 15:25 - 2013-11-02 09:17 - 00003874 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-06 07:32 - 2013-11-02 07:54 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NPE 2013-12-06 07:23 - 2013-11-02 07:54 - 03057128 ____N (Symantec Corporation) C:\Users\Gotthard Bienias\Downloads\NPE.exe 2013-12-06 07:11 - 2013-10-31 14:03 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\Ubisoft 2013-12-06 07:11 - 2013-10-31 10:44 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2013-12-06 06:26 - 2013-11-02 09:18 - 00002179 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-12-04 15:34 - 2013-10-28 14:31 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\VirtualStore 2013-12-03 06:47 - 2013-10-31 08:59 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NVIDIA 2013-12-03 06:46 - 2013-12-01 13:27 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NVIDIA Corporation 2013-12-03 06:46 - 2013-10-30 14:46 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-12-03 06:46 - 2013-10-30 14:46 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-12-03 06:46 - 2013-10-30 14:46 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-12-02 05:36 - 2013-12-01 17:15 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-12-01 17:24 - 2013-12-01 17:21 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\Battlefield 4 2013-12-01 17:21 - 2013-12-01 17:21 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\ESN 2013-12-01 17:21 - 2013-12-01 09:54 - 00000000 ____D C:\ProgramData\Origin 2013-12-01 17:19 - 2013-12-01 09:55 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Origin 2013-12-01 17:15 - 2013-12-01 17:15 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-12-01 17:14 - 2013-12-01 17:14 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-12-01 17:14 - 2013-12-01 17:14 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-01 16:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-01 14:36 - 2013-12-01 14:36 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-01 14:36 - 2013-10-31 10:42 - 00000000 ____D C:\Program Files\CCleaner 2013-12-01 14:36 - 2009-09-17 22:59 - 00000000 ____D C:\Windows\Panther 2013-12-01 14:17 - 2013-10-28 14:31 - 00001425 _____ C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-01 14:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-01 13:50 - 2013-12-01 13:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-01 13:50 - 2013-12-01 13:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-01 13:50 - 2013-12-01 13:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-01 13:50 - 2013-12-01 13:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-01 13:50 - 2013-12-01 13:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-01 13:50 - 2013-12-01 13:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-01 13:50 - 2013-12-01 13:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-01 13:36 - 2013-12-01 09:55 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Origin 2013-12-01 10:14 - 2013-12-01 10:14 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk 2013-12-01 09:54 - 2013-12-01 09:54 - 00000983 _____ C:\Users\Public\Desktop\Origin.lnk 2013-12-01 09:54 - 2013-12-01 09:54 - 00000074 _____ C:\Windows\wininit.ini 2013-12-01 09:49 - 2013-10-31 08:39 - 01597378 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-29 17:56 - 2013-10-31 09:02 - 01096480 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-11-29 17:56 - 2013-10-31 09:02 - 00979744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-11-29 16:02 - 2013-11-29 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-11-29 15:57 - 2013-11-29 15:57 - 00001440 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk 2013-11-29 15:57 - 2013-11-29 15:48 - 00001243 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-11-29 15:57 - 2013-11-29 15:48 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\DVDVideoSoft 2013-11-29 15:57 - 2013-11-29 15:48 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-11-29 15:48 - 2013-11-29 15:48 - 00001536 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2013-11-29 15:17 - 2013-10-30 14:01 - 00000000 ____D C:\Program Files\Bitdefender 2013-11-29 15:16 - 2013-11-29 15:16 - 00249444 _____ C:\ProgramData\1385734552.bdinstall.bin 2013-11-29 15:16 - 2013-10-30 14:01 - 00000000 ____D C:\ProgramData\Bitdefender 2013-11-29 15:16 - 2013-10-30 14:01 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2013-11-26 12:54 - 2013-12-11 05:49 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-26 11:19 - 2013-12-11 05:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-26 11:18 - 2013-12-11 05:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-26 11:11 - 2013-12-11 05:49 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-26 10:48 - 2013-12-11 05:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-26 10:46 - 2013-12-11 05:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-26 10:41 - 2013-12-11 05:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-26 10:29 - 2013-12-11 05:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-26 10:27 - 2013-12-11 05:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-26 10:23 - 2013-12-11 05:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-26 10:21 - 2013-12-11 05:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-26 10:18 - 2013-12-11 05:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-26 10:18 - 2013-12-11 05:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-26 10:16 - 2013-12-11 05:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-26 09:57 - 2013-12-11 05:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-26 09:38 - 2013-12-11 05:49 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-26 09:38 - 2013-12-11 05:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-26 09:35 - 2013-12-11 05:49 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-26 09:32 - 2013-12-11 05:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-26 09:28 - 2013-12-11 05:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-26 09:16 - 2013-12-11 05:49 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-26 09:02 - 2013-12-11 05:49 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-26 08:48 - 2013-12-11 05:49 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-26 08:32 - 2013-12-11 05:49 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-26 08:26 - 2013-12-11 05:49 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-26 08:07 - 2013-12-11 05:49 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-26 07:40 - 2013-12-11 05:49 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-26 07:34 - 2013-12-11 05:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-26 07:34 - 2013-12-11 05:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-26 07:33 - 2013-12-11 05:49 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-26 07:27 - 2013-12-11 05:49 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 30361888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 22951200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 18208624 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 15862272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 12613920 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-11-23 20:26 - 2013-12-01 13:29 - 11566648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 11441664 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 09663656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 09619872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433193.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433193.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00707360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00657184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00609568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00562464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-11-23 20:26 - 2013-12-01 13:29 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-11-23 20:26 - 2013-10-31 09:06 - 18293096 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-11-23 20:26 - 2013-10-31 08:56 - 15218504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-11-23 20:26 - 2013-10-31 08:56 - 02697248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-11-23 20:26 - 2013-10-30 14:46 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-11-23 20:26 - 2013-10-30 14:46 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2013-11-23 20:26 - 2013-09-17 22:22 - 03069608 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-11-23 20:26 - 2013-09-17 22:22 - 01436528 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-11-23 20:26 - 2013-09-17 22:22 - 00023754 _____ C:\Windows\system32\nvinfo.pb 2013-11-23 19:56 - 2013-10-28 14:33 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Google 2013-11-23 19:26 - 2013-12-11 05:48 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-11-23 19:10 - 2013-11-23 18:56 - 00000000 ____D C:\Program Files (x86)\Canon 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJSolutionMenuEX 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2 2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonEPP 2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\ProgramData\CanonIJMSetup 2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\Program Files\Common Files\CANON 2013-11-23 19:06 - 2013-11-23 19:06 - 00002079 _____ C:\Users\Public\Desktop\Canon Solution Menu EX.lnk 2013-11-23 19:06 - 2013-11-23 19:06 - 00000000 ____D C:\ProgramData\CanonIJWSpt 2013-11-23 19:04 - 2013-11-23 19:04 - 00002360 _____ C:\Users\Public\Desktop\Canon MG6100 series Online-Handbuch.lnk 2013-11-23 19:04 - 2013-11-23 19:04 - 00000000 ____D C:\Program Files\Canon 2013-11-23 18:58 - 2013-11-23 18:58 - 00000000 ____D C:\Windows\system32\STRING 2013-11-23 18:47 - 2013-12-11 05:48 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-11-23 18:42 - 2013-10-30 14:47 - 06674208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-11-23 18:42 - 2013-10-30 14:47 - 03490080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-11-23 18:42 - 2013-10-30 14:47 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-11-23 18:42 - 2013-10-30 14:47 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-11-23 18:42 - 2013-10-30 14:47 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-11-23 18:42 - 2013-10-30 14:47 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-11-23 12:18 - 2013-11-23 12:18 - 00590112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-11-23 06:57 - 2013-10-30 13:38 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Adobe 2013-11-22 17:28 - 2013-10-30 14:47 - 03498475 _____ C:\Windows\system32\nvcoproc.bin 2013-11-19 03:33 - 2013-11-29 15:52 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-01 16:14 ==================== End Of Log ============================ --- --- --- aAdditional scan result of Farbar Recovery Scan Tool (x64) Version: 17-12-2013 02 Ran by Gotthard Bienias at 2013-12-18 05:33:46 Running from C:\Users\Gotthard Bienias\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} ==================== Installed Programs ====================== 7-Zip 9.22 (x64 edition) (Version: 9.22.00.0) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Canon Easy-PhotoPrint EX (x32) Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data (x32) Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data (x32) Canon Easy-PhotoPrint Pro (x32) Canon MG6100 series Benutzerregistrierung (x32) Canon MG6100 series MP Drivers Canon MP Navigator EX 4.0 (x32) Canon My Printer (x32) Canon Solution Menu EX (x32) CCleaner (Version: 4.08) CD-LabelPrint (x32) Driver Genius (x32 Version: 12.0) ESN Sonar (x32 Version: 0.70.4) Free YouTube Download version 3.2.17.1125 (x32 Version: 3.2.17.1125) Free YouTube to MP3 Converter version 3.12.17.1125 (x32 Version: 3.12.17.1125) GeForce Experience NvStream Client Components (Version: 1.6.28) Google Chrome (x32 Version: 31.0.1650.63) Google Update Helper (x32 Version: 1.3.22.3) ImagXpress (x32 Version: 7.0.74.0) Intel(R) Network Connections 18.6.110.0 (Version: 18.6.110.0) Intel(R) Rapid Storage Technology (Version: 12.8.2.1000) Intel® Matrix Storage Manager JMicron JMB36X Driver (x32 Version: 1.17.65.11) Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0) Mozilla Maintenance Service (x32 Version: 26.0) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) neroxml (x32 Version: 1.0.0) Neverwinter (x32) NVIDIA 3D Vision Controller-Treiber 331.93 (Version: 331.93) NVIDIA 3D Vision Treiber 331.93 (Version: 331.93) NVIDIA GeForce Experience 1.8 (Version: 1.8) NVIDIA Grafiktreiber 331.93 (Version: 331.93) NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4) NVIDIA Install Application (Version: 2.1002.142.992) NVIDIA LED Visualizer 1.0 (Version: 1.0) NVIDIA Network Service (Version: 1.0) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA ShadowPlay 10.10.5 (Version: 10.10.5) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3193) NVIDIA Systemsteuerung 331.93 (Version: 331.93) NVIDIA Update 10.10.5 (Version: 10.10.5) NVIDIA Update Core (Version: 10.10.5) NVIDIA Virtual Audio 1.2.12 (Version: 1.2.12) OpenOffice 4.0.1 (x32 Version: 4.01.9714) Origin (x32 Version: 9.3.11.2762) PrivaZer (x32 Version: 2.6.3.0) Realtek Card Reader (x32 Version: 6.2.9600.30169) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5874) Samsung Kies3 (x32 Version: 3.2.13114.22) Samsung SSD Magician (x32 Version: 3.1) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0) SHIELD Streaming (Version: 1.6.75) Steam (x32) TuneUp Utilities 2013 (x32 Version: 13.0.4000.179) TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.179) Uplay (x32 Version: 4.0) VC_CRT_x64 (Version: 1.02.0000) VLC media player 2.1.2 (x32 Version: 2.1.2) ==================== Restore Points ========================= 15-12-2013 17:11:18 Installed 7-Zip 9.22 (x64 edition) 17-12-2013 14:43:28 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 17-12-2013 14:43:41 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 17-12-2013 14:44:07 OpenOffice 4.0.1 wird installiert 17-12-2013 14:46:26 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1140B751-F375-4466-B26C-82F43D6F7F63} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {3F3A6EDB-692B-4C45-B110-FF66FF08E864} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-12] (Adobe Systems Incorporated) Task: {57D70009-4839-412A-B025-27CE37CDD900} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated) Task: {8B9D54B2-C6E6-4372-918F-A7CCB5E619E4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.) Task: {9A34391A-49EE-4577-A0E2-39337F74209A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.) Task: {BC040C1D-8889-4397-81EF-94FD582829F2} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe [2013-12-10] (TuneUp Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-10-31 15:18 - 2013-10-31 15:18 - 03525687 _____ () C:\Program Files (x86)\PrivaZer\PrivaMenu3.dll 2012-08-17 21:39 - 2013-12-16 19:59 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll 2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll 2013-12-06 06:26 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-06 06:26 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-06 06:26 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-06 06:26 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-06 06:26 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:0B9176C0 AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F AlternateDataStreams: C:\ProgramData\Temp:93DE1838 AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D AlternateDataStreams: C:\ProgramData\Temp:E3C56885 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (12/02/2013 06:19:04 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.0.0.0, Zeitstempel: 0x527cfab6 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000009c7dced0 ID des fehlerhaften Prozesses: 0x13a4 Startzeit der fehlerhaften Anwendung: 0xbf4.exe0 Pfad der fehlerhaften Anwendung: bf4.exe1 Pfad des fehlerhaften Moduls: bf4.exe2 Berichtskennung: bf4.exe3 Error: (11/29/2013 03:48:24 PM) (Source: MsiInstaller) (User: meiner) Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\GoogleUpdateHelper.msi System errors: ============= Error: (12/16/2013 07:32:58 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147024846. Error: (12/16/2013 07:32:58 PM) (Source: Microsoft-Windows-Bits-Client) (User: NT-AUTORITÄT) Description: Fehler beim Starten des BITS-Dienstes. Fehler: 2147942450. Error: (12/15/2013 03:12:50 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/15/2013 03:12:50 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (12/12/2013 05:31:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TuneUp Designerweiterung" wurde aufgrund folgenden Fehlers nicht gestartet: %%1083 Error: (12/10/2013 04:15:05 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden. Error: (12/10/2013 04:15:04 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden. Error: (12/10/2013 04:15:04 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden. Error: (12/10/2013 04:15:03 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden. Error: (12/08/2013 10:14:00 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (12/02/2013 06:19:04 AM) (Source: Application Error)(User: ) Description: bf4.exe1.0.0.0527cfab6unknown0.0.0.000000000c0000005000000009c7dced013a401ceef1b3a8c7096C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exeunknown421c3a5f-5b11-11e3-8422-90fba62b103b Error: (11/29/2013 03:48:24 PM) (Source: MsiInstaller)(User: meiner) Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL) CodeIntegrity Errors: =================================== Date: 2013-12-08 10:21:47.210 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 10:21:47.210 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 10:21:47.210 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 10:17:42.242 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 10:17:42.242 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 10:17:42.242 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 07:26:31.165 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 07:26:31.164 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 07:26:31.162 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-12-08 07:20:22.741 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 24% Total physical RAM: 8183.11 MB Available physical RAM: 6206.64 MB Total Pagefile: 16364.4 MB Available Pagefile: 14042.31 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:119.24 GB) (Free:72.01 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive j: (Volume) (Fixed) (Total:931.51 GB) (Free:931.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 7596B406) Partition 1: (Active) - (Size=119 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 7596B413) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================[/CODE] Entschuldige meine Blödheit.Schreibe nicht soviel am PC.Ich hoffe ich habe jetzt alles richtig gemacht.DANKE |
19.12.2013, 11:56 | #6 |
/// the machine /// TB-Ausbilder | PC gekapert? Alles sauber. Wie oben schon erklärt, aufpassen wo du was lädst, und aufpasen beim Installieren
__________________ --> PC gekapert? |
19.12.2013, 15:34 | #7 |
| PC gekapert? Danke |
20.12.2013, 09:56 | #8 |
/// the machine /// TB-Ausbilder | PC gekapert? Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.04.2017, 07:25 | #9 |
| Amazon Pishingmail Hallo Ich habe heute die in Umlauf befindliche Amazon DHLmail göffnet weil ich eine Lieferung erwarte.Habe dann mit MWB gescannt keine Bedrohungen gefunden.Dann habe ich mit Adwarecleaner gescannt und folgenden Key gefunden der sich nicht löschen lässt:HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}.Auch der Esetonlinescanner hat eine Datei gefunden und sie gelöscht.Nur weiß ich jetzt nicht ob ich verseucht bin oder nicht,da der Adwarecleaner den Regeintrag nicht löscht.Bitte um Eure professionelle Hilfe,Danke im voraus Gottel |
06.04.2017, 14:43 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | PC gekapert? Bitte keine uralten Threads aufwärmen. Neues Anliegen => neuer Thread.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu PC gekapert? |
64 bit, bitte um hilfe, dieselbe, dieselben, formatierte, gekapert, hilfe, home, langsam, malwarebytes, optional, probleme, pup optional, vermutung, win, win7 |