| ![]() Systweak Software gedownloadet, lies sich nach Neustart Deinstallieren - Würde es gerne kontrollieren lassen Guten Abend! Mir ist es gelungen Zusatzsoftware, auf der Suche nach einem Treiber für meine On-Board Soundkarte, zu downloaden (Allmyapps, Systweak Support Dock, Jump Flip, PC Cleaner; Allmyapps und Jump Flip stammen von einem Anwender mit jeweils dem gleichen Namen, wie die Anwendung. Support Dock sowie Pc Cleaner wurden laut der Systemsteuerung von Sytweak veröffentlicht) Diese Programme ließen sich zu Beginn nicht deinstallieren (Die Systemsteuerung meldete: "Warten Sie, bis die Deinstallation bzw. Änderung des aktuellen Programms abgeschlossen ist") Ich hatte allerdings alle zugehörigen Anwendungen und (so gut wie möglich) Prozesse per Task Manager beendet. Ich habe den PC neu gestartet und die Programme ließen sich (scheinbar) deinstallieren. Weil ich dachte, diese so nicht entfernen zu können, habe ich mich über die Software von Systweak informiert und bin unter anderem auf diesen Post in eurem Forum gestoßen: http://www.trojaner-board.de/138386-...-systweak.html Antivir meldete vor der anscheinend erfolgreichen Deinstallation beim Starten des Browsers (Google Chrome Version 31.0.1650.63 m) jeweils einen Virus, diesen per "Entfernen" zu entfernen, hinderte diesen aber nicht am erneuten Auftauchen beim Browserstart. Letztenendes wäre es natürlich super, falls ich diese Programme tatsächlich einfach deinstallieren konnte, möchte aber lieber auf Nummer sicher gehen und erbitte deshalb eure Hilfe. schonmal vorab vielen Dank, Gruß Chris PS: Ich habe Windows 7 Professional x64 Version 6.1.7601 Service Pack 1 Build 7601 |
hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
| ![]() Systweak Software gedownloadet, lies sich nach Neustart Deinstallieren - Würde es gerne kontrollieren lassen Habe die beiden Dokumente als Anhänge hinzugefügt, verstehe Variante mit "#" nicht...
__________________Hoffe, das geht so auch. |
Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| ![]() Systweak Software gedownloadet, lies sich nach Neustart Deinstallieren - Würde es gerne kontrollieren lassen Hier die FRST.txt Datei FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-01-2014 Ran by Christian (administrator) on CHRIS on 10-01-2014 23:20:25 Running from C:\Users\Christian\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Akamai Technologies, Inc.) C:\Users\Christian\AppData\Local\Akamai\netsession_win.exe (Gainward Co. Ltd.) C:\Program Files (x86)\EXPERTool\TBPanel.exe (Electronic Arts) S:\Spiele\Origin\Origin.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Akamai Technologies, Inc.) C:\Users\Christian\AppData\Local\Akamai\netsession_win.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IntelliType Pro] - C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation) HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-10-18] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Christian\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKCU\...\Run: [GoogleChromeAutoLaunch_F95133299531DA24C7CB703BC8432DCE] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [863184 2013-12-04] (Google Inc.) HKCU\...\Run: [TBPanel] - C:\Program Files (x86)\EXPERTool\TBPanel.exe [2048368 2012-07-13] (Gainward Co. Ltd.) HKCU\...\Run: [EADM] - S:\Spiele\Origin\Origin.exe [3551576 2013-11-21] (Electronic Arts) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1815464 2014-01-07] (Valve Corporation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [Allmyapps] - "C:\Users\Christian\AppData\Roaming\Allmyapps\Allmyapps.exe" startup HKCU\...\Run: [Allmyapps Update] - "C:\Users\Christian\AppData\Roaming\Allmyapps\AllmyappsUpdater.exe" check startup MountPoints2: E - E:\CDSETUP.EXE MountPoints2: F - F:\LGAutoRun.exe MountPoints2: {404a7c4a-1031-11e0-a38b-a4badb0360b5} - K:\setup.exe -a MountPoints2: {5093092f-3840-11df-928b-806e6f6e6963} - E:\autorun.exe MountPoints2: {d29ae55c-c87a-11df-bfdb-a4badb0360b5} - K:\LGAutoRun.exe MountPoints2: {d485d1fa-6c09-11e3-91b7-a4badb0360b5} - K:\HTC_Sync_Manager_PC.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USSMB/8 URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll No File URLSearchHook: HKCU - (No Name) - {6d8d66f3-14fc-4736-a096-fac0ea66289c} - No File SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6EA08A8D-A144-46B1-A06A-363DC2CF4A3A} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=0960938B-4D96-4EE1-8D57-8328C27108D6&apn_sauid=A0C89EDE-5542-4BB9-9796-CA0E8B8432BB SearchScopes: HKCU - {7C034EE8-F2AC-430E-B656-56325F806F33} URL = SearchScopes: HKCU - {F495FA74-9D34-4774-8B6D-4C4DFE528C60} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File Toolbar: HKCU - No Name - {6D8D66F3-14FC-4736-A096-FAC0EA66289C} - No File DPF: HKLM {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\10csbgas.default FF user.js: detected! => C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\10csbgas.default\user.js FF DefaultSearchEngine: foxsearch FF SearchEngineOrder.1: foxsearch FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.116.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.116.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.122.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.140.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @real.com/nppl3260;version= - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll No File FF Plugin-x32: @real.com/nprjplug;version= - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll No File FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version= - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version= - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpjplug;version= - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Christian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF SearchPlugin: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\10csbgas.default\searchplugins\searchplugins-backup FF Extension: ProxTube - Unblock YouTube - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\10csbgas.default\Extensions\ich@maltegoetz.de FF Extension: ProxMate - unblock the Internet! - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\10csbgas.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext Chrome: ======= CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0 CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\ CHR Extension: (Google Wallet) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Christian\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx ==================== Services (Whitelisted) ================= R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-05-30] () R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) S3 npggsvc; C:\Windows\SysWow64\GameMon.des [3819912 2010-06-06] (INCA Internet Co., Ltd.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-11-09] () S2 Update Jump Flip; "C:\Program Files (x86)\Jump Flip\updateJumpFlip.exe" [x] S2 vToolbarUpdater17.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2010-06-29] () R2 atksgt; C:\Windows\SysWow64\DRIVERS\atksgt.sys [165376 2010-06-02] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2014-01-10] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2010-06-29] () R2 lirsgt; C:\Windows\SysWow64\DRIVERS\lirsgt.sys [18048 2010-06-02] () S3 NPPTNT2; C:\Windows\SysWow64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation) S3 TKCtrl; C:\Windows\system32\TKCtrl2k64.sys [87872 2012-07-03] (INCA Internet Co., Ltd.) S3 TKFsAvM; C:\Windows\system32\TKFsAv64.sys [139136 2012-12-26] (INCA Internet Co., Ltd.) S3 TKFsFtM; C:\Windows\system32\TKFsFt64.sys [23392 2012-11-06] (INCA Internet Co., Ltd.) S1 TKFWFV; C:\Windows\System32\TKFWFV64.sys [34400 2011-03-29] (INCA Internet Co., Ltd.) S3 TKFWVT; C:\Windows\system32\TKFWVT64.sys [183112 2012-10-23] (INCA Internet Co.,Ltd.) S3 TkIdsVt; C:\Windows\system32\TkIdsVt64.sys [99168 2012-07-31] (INCA Internet Co.,Ltd.) S3 TKPcFt; C:\Windows\system32\TKPcFtCb64.sys [29024 2012-11-06] (INCA Internet Co., Ltd.) S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2008-11-19] (LG Electronics Inc.) S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27136 2008-11-19] (LG Electronics Inc.) S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33792 2008-11-19] (LG Electronics Inc.) S3 wolf; S:\Spiele\Wolfteam\Wolfteam-DE\avital\wolf64.sys [82472 2013-04-09] () S3 BTCFilterService; system32\DRIVERS\motfilt.sys [x] S3 dump_wmimmc; \??\S:\Spiele\Wolfteam\Wolfteam-DE\GameGuard\dump_wmimmc.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [x] S3 motccgp; system32\DRIVERS\motccgp.sys [x] S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [x] S3 motmodem; system32\DRIVERS\motmodem.sys [x] S3 MotoSwitchService; system32\DRIVERS\motswch.sys [x] S3 Motousbnet; system32\DRIVERS\Motousbnet.sys [x] S3 motusbdevice; system32\DRIVERS\motusbdevice.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-10 23:20 - 2014-01-10 23:21 - 00020891 _____ C:\Users\Christian\Downloads\FRST.txt 2014-01-10 23:20 - 2014-01-10 23:20 - 00000000 ____D C:\FRST 2014-01-10 23:19 - 2014-01-10 23:19 - 01932166 _____ (Farbar) C:\Users\Christian\Downloads\FRST64.exe 2014-01-10 22:28 - 2014-01-10 22:28 - 00020821 _____ C:\Users\Christian\Desktop\dds.txt 2014-01-10 22:27 - 2014-01-10 22:27 - 00688992 ____R (Swearware) C:\Users\Christian\Downloads\dds.exe 2014-01-10 22:19 - 2014-01-10 22:50 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Systweak 2014-01-10 22:14 - 2014-01-10 22:16 - 00000000 ____D C:\AdwCleaner 2014-01-10 22:14 - 2014-01-10 22:14 - 01233962 _____ C:\Users\Christian\Downloads\adwcleaner.exe 2014-01-10 22:05 - 2014-01-10 22:05 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Christian\Downloads\SpyHunter-Installer.exe 2014-01-10 21:56 - 2014-01-10 21:56 - 00000956 _____ C:\Users\Christian\Desktop\Allmyapps.lnk 2014-01-10 21:56 - 2014-01-10 21:56 - 00000000 ____D C:\Users\Christian\AppData\Local\CrashRpt 2014-01-10 21:55 - 2014-01-10 22:50 - 00000000 ____D C:\Program Files (x86)\Systweak Support Dock 2014-01-10 21:53 - 2014-01-10 21:53 - 175311560 _____ (NVIDIA Corporation) C:\Users\Christian\Downloads\314.07-notebook-win8-win7-winvista-32bit-international-whql.exe 2014-01-10 21:52 - 2014-01-10 22:09 - 00000000 ____D C:\Users\Christian\AppData\Local\cache 2014-01-10 21:52 - 2014-01-10 21:53 - 00000000 ____D C:\Users\Christian\AppData\Roaming\newnext.me 2014-01-10 21:52 - 2014-01-10 21:53 - 00000000 ____D C:\Users\Christian\AppData\Local\genienext 2014-01-10 21:52 - 2014-01-10 21:52 - 00000000 ____D C:\Users\Christian\.android 2014-01-10 21:52 - 2014-01-10 21:52 - 00000000 _____ C:\Users\Christian\daemonprocess.txt 2014-01-10 21:51 - 2014-01-10 21:51 - 00685704 _____ C:\Users\Christian\Downloads\nvidia-hd-audio-driver.exe 2014-01-10 21:46 - 2014-01-10 21:46 - 05511528 _____ (Copyright © 2013 eSupport.com, Inc • All Rights Reserved ) C:\Users\Christian\Downloads\driveragent-setup-avg-1213 (1).exe 2014-01-10 21:46 - 2014-01-10 21:46 - 01466296 _____ ( ) C:\Users\Christian\Downloads\cpu-z_1.68-setup-en (1).exe 2014-01-10 21:46 - 2014-01-10 21:45 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-01-10 21:45 - 2014-01-10 21:45 - 05511528 _____ (Copyright © 2013 eSupport.com, Inc • All Rights Reserved ) C:\Users\Christian\Downloads\driveragent-setup-avg-1213.exe 2014-01-10 21:45 - 2014-01-10 21:45 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS 2014-01-10 21:45 - 2014-01-10 21:45 - 00001220 _____ C:\Users\Public\Desktop\Find Drivers with DriverAgent.lnk 2014-01-10 21:45 - 2014-01-10 21:45 - 00001200 _____ C:\Users\Christian\Desktop\Find Drivers with DriverAgent.lnk 2014-01-10 21:41 - 2014-01-10 21:41 - 01466296 _____ ( ) C:\Users\Christian\Downloads\cpu-z_1.68-setup-en.exe 2014-01-10 21:41 - 2014-01-10 21:41 - 00000871 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2014-01-10 21:41 - 2014-01-10 21:41 - 00000000 ____D C:\Program Files\CPUID 2014-01-10 21:24 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 15877216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-01-10 21:24 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-01-10 21:24 - 2013-12-19 21:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-01-10 21:24 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-01-10 21:24 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-01-10 21:24 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-01-10 19:38 - 2014-01-10 19:42 - 00000000 ____D C:\Users\Christian\Downloads\Neuer Ordner 2014-01-04 14:05 - 2014-01-04 14:05 - 00000000 ____D C:\Crash 2013-12-25 11:13 - 2014-01-05 22:09 - 00000000 ____D C:\Users\Christian\AppData\Local\DayZ 2013-12-25 11:13 - 2013-12-25 11:13 - 00000000 ____D C:\Users\Christian\Documents\DayZ 2013-12-24 15:24 - 2013-12-24 15:24 - 00000222 _____ C:\Users\Christian\Desktop\DayZ.url 2013-12-23 22:04 - 2013-12-23 22:04 - 00008332 _____ C:\Windows\DPINST.LOG 2013-12-23 22:04 - 2013-12-23 22:04 - 00000000 ____D C:\Program Files (x86)\HTC 2013-12-23 22:03 - 2013-12-23 22:03 - 00000000 ____D C:\ProgramData\HTC 2013-12-23 11:23 - 2013-12-23 11:23 - 00000000 ____D C:\Users\Christian\Desktop\7dtd - Server 2013-12-19 12:20 - 2013-12-19 12:20 - 00590112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-12-18 16:57 - 2013-12-18 16:57 - 04954736 _____ (Microsoft Corporation) C:\Users\Christian\Downloads\WindowsUpgradeAssistant (1).exe 2013-12-17 21:58 - 2013-12-17 21:59 - 04954736 _____ (Microsoft Corporation) C:\Users\Christian\Downloads\WindowsUpgradeAssistant.exe 2013-12-17 21:37 - 2013-12-05 09:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-12-17 21:37 - 2013-12-05 09:42 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-12-16 18:59 - 2013-11-14 12:56 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433182.dll 2013-12-16 18:59 - 2013-11-14 12:56 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433182.dll 2013-12-13 17:54 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-13 17:54 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-13 17:53 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-13 17:53 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-13 17:53 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-13 17:53 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-13 17:53 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-13 17:53 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-13 17:53 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-13 17:53 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-13 17:53 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-13 17:53 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-13 17:53 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-13 17:53 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-13 17:53 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-13 17:53 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-13 17:53 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-13 17:53 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-13 17:53 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-13 17:53 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-13 17:53 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-13 17:53 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-13 17:53 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-13 17:53 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-13 17:53 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-13 17:53 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-13 17:53 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-13 17:53 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-13 17:53 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-13 17:53 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-13 17:53 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-12 10:47 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-12 10:47 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-12 10:47 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-12 10:47 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 16:37 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 16:37 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 16:37 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 16:37 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 16:37 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 16:37 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 16:37 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 16:37 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-11 16:36 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 16:36 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 16:36 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 16:36 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 16:36 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 16:36 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 16:36 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 16:36 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 16:36 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 16:36 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 16:36 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 16:36 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 16:31 - 2013-12-11 16:31 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 16:31 - 2013-12-11 16:31 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 16:31 - 2013-12-11 16:31 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 16:31 - 2013-12-11 16:31 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 16:31 - 2013-12-11 16:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 16:31 - 2013-12-11 16:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 16:31 - 2013-12-11 16:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-11 16:25 - 2013-12-11 16:37 - 00011300 _____ C:\Windows\IE11_main.log ==================== One Month Modified Files and Folders ======= 2014-01-10 23:21 - 2014-01-10 23:20 - 00020891 _____ C:\Users\Christian\Downloads\FRST.txt 2014-01-10 23:20 - 2014-01-10 23:20 - 00000000 ____D C:\FRST 2014-01-10 23:19 - 2014-01-10 23:19 - 01932166 _____ (Farbar) C:\Users\Christian\Downloads\FRST64.exe 2014-01-10 23:19 - 2012-06-29 17:26 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin 2014-01-10 23:18 - 2011-02-26 10:59 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Skype 2014-01-10 23:07 - 2013-01-06 11:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-10 22:50 - 2014-01-10 22:19 - 00000000 ____D C:\Users\Christian\AppData\Roaming\Systweak 2014-01-10 22:50 - 2014-01-10 21:55 - 00000000 ____D C:\Program Files (x86)\Systweak Support Dock 2014-01-10 22:38 - 2010-06-29 18:15 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-10 22:38 - 2010-06-29 18:15 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-10 22:28 - 2014-01-10 22:28 - 00020821 _____ C:\Users\Christian\Desktop\dds.txt 2014-01-10 22:27 - 2014-01-10 22:27 - 00688992 ____R (Swearware) C:\Users\Christian\Downloads\dds.exe 2014-01-10 22:27 - 2009-07-14 05:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-10 22:27 - 2009-07-14 05:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-10 22:23 - 2009-07-14 06:10 - 01586714 _____ C:\Windows\WindowsUpdate.log 2014-01-10 22:19 - 2013-03-09 22:33 - 00000000 ____D C:\Program Files (x86)\Steam 2014-01-10 22:18 - 2013-02-11 20:33 - 00000000 ____D C:\Users\Christian\AppData\Local\LogMeIn Hamachi 2014-01-10 22:18 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2014-01-10 22:17 - 2013-08-06 19:54 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2014-01-10 22:17 - 2013-06-22 10:43 - 00052678 _____ C:\Windows\setupact.log 2014-01-10 22:17 - 2010-03-25 20:03 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-10 22:17 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-10 22:16 - 2014-01-10 22:14 - 00000000 ____D C:\AdwCleaner 2014-01-10 22:16 - 2010-05-08 17:02 - 00000000 ___RD C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-10 22:15 - 2010-06-03 17:43 - 00000000 ____D C:\ProgramData\ICQ 2014-01-10 22:14 - 2014-01-10 22:14 - 01233962 _____ C:\Users\Christian\Downloads\adwcleaner.exe 2014-01-10 22:09 - 2014-01-10 21:52 - 00000000 ____D C:\Users\Christian\AppData\Local\cache 2014-01-10 22:05 - 2014-01-10 22:05 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Christian\Downloads\SpyHunter-Installer.exe 2014-01-10 21:56 - 2014-01-10 21:56 - 00000956 _____ C:\Users\Christian\Desktop\Allmyapps.lnk 2014-01-10 21:56 - 2014-01-10 21:56 - 00000000 ____D C:\Users\Christian\AppData\Local\CrashRpt 2014-01-10 21:53 - 2014-01-10 21:53 - 175311560 _____ (NVIDIA Corporation) C:\Users\Christian\Downloads\314.07-notebook-win8-win7-winvista-32bit-international-whql.exe 2014-01-10 21:53 - 2014-01-10 21:52 - 00000000 ____D C:\Users\Christian\AppData\Roaming\newnext.me 2014-01-10 21:53 - 2014-01-10 21:52 - 00000000 ____D C:\Users\Christian\AppData\Local\genienext 2014-01-10 21:52 - 2014-01-10 21:52 - 00000000 ____D C:\Users\Christian\.android 2014-01-10 21:52 - 2014-01-10 21:52 - 00000000 _____ C:\Users\Christian\daemonprocess.txt 2014-01-10 21:52 - 2010-05-08 17:01 - 00000000 ____D C:\Users\Christian 2014-01-10 21:51 - 2014-01-10 21:51 - 00685704 _____ C:\Users\Christian\Downloads\nvidia-hd-audio-driver.exe 2014-01-10 21:46 - 2014-01-10 21:46 - 05511528 _____ (Copyright © 2013 eSupport.com, Inc • All Rights Reserved ) C:\Users\Christian\Downloads\driveragent-setup-avg-1213 (1).exe 2014-01-10 21:46 - 2014-01-10 21:46 - 01466296 _____ ( ) C:\Users\Christian\Downloads\cpu-z_1.68-setup-en (1).exe 2014-01-10 21:45 - 2014-01-10 21:46 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-01-10 21:45 - 2014-01-10 21:45 - 05511528 _____ (Copyright © 2013 eSupport.com, Inc • All Rights Reserved ) C:\Users\Christian\Downloads\driveragent-setup-avg-1213.exe 2014-01-10 21:45 - 2014-01-10 21:45 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS 2014-01-10 21:45 - 2014-01-10 21:45 - 00001220 _____ C:\Users\Public\Desktop\Find Drivers with DriverAgent.lnk 2014-01-10 21:45 - 2014-01-10 21:45 - 00001200 _____ C:\Users\Christian\Desktop\Find Drivers with DriverAgent.lnk 2014-01-10 21:45 - 2013-09-11 19:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-10 21:41 - 2014-01-10 21:41 - 01466296 _____ ( ) C:\Users\Christian\Downloads\cpu-z_1.68-setup-en.exe 2014-01-10 21:41 - 2014-01-10 21:41 - 00000871 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2014-01-10 21:41 - 2014-01-10 21:41 - 00000000 ____D C:\Program Files\CPUID 2014-01-10 21:28 - 2012-02-23 20:20 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-10 19:42 - 2014-01-10 19:38 - 00000000 ____D C:\Users\Christian\Downloads\Neuer Ordner 2014-01-10 19:42 - 2013-07-02 16:34 - 00000000 ____D C:\Users\Christian\Desktop\Minecraft 2014-01-09 16:16 - 2013-07-23 15:00 - 00000000 ____D C:\Users\Christian\AppData\Local\Warframe 2014-01-08 18:47 - 2013-03-10 23:56 - 00000000 ____D C:\Users\Christian\Desktop\2013 B-LK1 Gönner Christian 2014-01-07 21:42 - 2010-08-11 22:02 - 00000000 ____D C:\Program Files (x86)\DivX 2014-01-07 21:42 - 2010-08-11 22:01 - 00000000 ____D C:\ProgramData\DivX 2014-01-06 17:37 - 2011-04-20 22:20 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-06 17:22 - 2011-04-20 22:20 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-05 22:09 - 2013-12-25 11:13 - 00000000 ____D C:\Users\Christian\AppData\Local\DayZ 2014-01-04 14:05 - 2014-01-04 14:05 - 00000000 ____D C:\Crash 2013-12-26 10:02 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-25 11:13 - 2013-12-25 11:13 - 00000000 ____D C:\Users\Christian\Documents\DayZ 2013-12-24 15:24 - 2013-12-24 15:24 - 00000222 _____ C:\Users\Christian\Desktop\DayZ.url 2013-12-23 22:04 - 2013-12-23 22:04 - 00008332 _____ C:\Windows\DPINST.LOG 2013-12-23 22:04 - 2013-12-23 22:04 - 00000000 ____D C:\Program Files (x86)\HTC 2013-12-23 22:03 - 2013-12-23 22:03 - 00000000 ____D C:\ProgramData\HTC 2013-12-23 18:17 - 2011-05-27 22:59 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-12-23 11:23 - 2013-12-23 11:23 - 00000000 ____D C:\Users\Christian\Desktop\7dtd - Server 2013-12-19 21:33 - 2014-01-10 21:24 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 15877216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-12-19 21:33 - 2014-01-10 21:24 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-12-19 21:33 - 2014-01-10 21:24 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-12-19 21:33 - 2013-11-09 13:34 - 00023754 _____ C:\Windows\system32\nvinfo.pb 2013-12-19 21:33 - 2012-11-18 23:28 - 01436528 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-12-19 21:33 - 2012-10-10 21:23 - 18310112 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-12-19 21:33 - 2012-10-10 21:22 - 15230352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-12-19 21:33 - 2012-10-10 21:22 - 02698272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-12-19 21:33 - 2010-03-26 04:48 - 03071656 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-12-19 20:28 - 2009-07-14 18:58 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-12-19 20:28 - 2009-07-14 18:58 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-12-19 20:28 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-19 19:53 - 2009-06-26 17:00 - 06671648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-12-19 19:53 - 2009-06-26 17:00 - 03490080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-12-19 19:53 - 2009-06-26 17:00 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-12-19 19:53 - 2009-06-26 17:00 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-12-19 19:53 - 2009-06-26 17:00 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-12-19 19:53 - 2009-06-26 17:00 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-12-19 12:20 - 2013-12-19 12:20 - 00590112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-12-19 06:01 - 2012-12-21 00:12 - 03539040 _____ C:\Windows\system32\nvcoproc.bin 2013-12-18 16:57 - 2013-12-18 16:57 - 04954736 _____ (Microsoft Corporation) C:\Users\Christian\Downloads\WindowsUpgradeAssistant (1).exe 2013-12-17 21:59 - 2013-12-17 21:58 - 04954736 _____ (Microsoft Corporation) C:\Users\Christian\Downloads\WindowsUpgradeAssistant.exe 2013-12-17 21:26 - 2013-02-01 19:03 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-12-17 21:26 - 2011-02-26 10:59 - 00000000 ____D C:\ProgramData\Skype 2013-12-15 15:32 - 2013-08-19 11:11 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 15:30 - 2010-06-03 10:28 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-14 10:55 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-13 20:12 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-12 15:46 - 2009-07-14 05:45 - 00433864 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-12 10:47 - 2009-07-14 03:34 - 00000499 _____ C:\Windows\win.ini 2013-12-12 10:43 - 2013-08-05 21:20 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-12-12 10:43 - 2013-08-05 21:19 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-12 10:43 - 2013-08-05 21:19 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-11 20:56 - 2013-06-22 20:16 - 00001427 _____ C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-11 20:53 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-11 20:10 - 2013-01-06 11:52 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 20:10 - 2012-05-19 09:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 20:10 - 2011-05-19 13:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 16:37 - 2013-12-11 16:25 - 00011300 _____ C:\Windows\IE11_main.log 2013-12-11 16:31 - 2013-12-11 16:31 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 16:31 - 2013-12-11 16:31 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 16:31 - 2013-12-11 16:31 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 16:31 - 2013-12-11 16:31 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 16:31 - 2013-12-11 16:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 16:31 - 2013-12-11 16:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 16:31 - 2013-12-11 16:31 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 16:31 - 2013-12-11 16:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 16:31 - 2013-12-11 16:31 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe Files to move or delete: ==================== C:\Users\.minecraft\Minecraft.exe C:\Users\.minecraft\MinecraftSP.exe Some content of TEMP: ==================== C:\Users\Christian\AppData\Local\Temp\avgnt.exe C:\Users\Christian\AppData\Local\Temp\BackupSetup.exe C:\Users\Christian\AppData\Local\Temp\DivXSetup.exe C:\Users\Christian\AppData\Local\Temp\jansi-32-git-Bukkit-1.5.2-R1.0-b2788jnks.dll C:\Users\Christian\AppData\Local\Temp\jansi-64-git-Bukkit-1.5.2-R1.0-b2788jnks.dll C:\Users\Christian\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Christian\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Christian\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Christian\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Christian\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Christian\AppData\Local\Temp\nvStInst.exe C:\Users\Christian\AppData\Local\Temp\oi_{DCCFA149-7444-427C-8322-596FB201CB20}.exe C:\Users\Christian\AppData\Local\Temp\Quarantine.exe C:\Users\Christian\AppData\Local\Temp\RSPUpgradeInstaller.exe C:\Users\Christian\AppData\Local\Temp\SkypeSetup.exe C:\Users\Christian\AppData\Local\Temp\sonarinst.exe C:\Users\Christian\AppData\Local\Temp\UNINSTALL.EXE C:\Users\Christian\AppData\Local\Temp\Uninstaller-5076.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 22:33 ==================== End Of Log ============================ Und hier die Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-01-2014 Ran by Christian at 2014-01-10 23:21:30 Running from C:\Users\Christian\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: - Igor Pavlov) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.02) - Deutsch (x32 Version: 11.0.02 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (x32 Version: - Adobe Systems, Inc.) AirRivals (x32 Version: - Gameforge 4D GmbH) Akamai NetSession Interface (HKCU Version: - Akamai Technologies, Inc) Akamai NetSession Interface (x32 Version: - ) Anno 1701 (x32 Version: 1.00 - Sunflowers) ANNO 2070 (x32 Version: - Ubisoft) applicationupdater (HKCU Version: - Sony Online Entertainment) ARMA 2 Operation Arrowhead Uninstall (x32 Version: - ) ArmA 2 Uninstall (x32 Version: - ) Arma 3 Beta (x32 Version: - Bohemia Interactive) Avira Free Antivirus (x32 Version: - Avira) Battlefield 3™ (x32 Version: - Electronic Arts) Battlefield 4™ (x32 Version: - Electronic Arts) Battlelog Web Plugins (x32 Version: 2.3.2 - EA Digital Illusions CE AB) BattlEye for OA Uninstall (x32 Version: - ) BattlEye Uninstall (x32 Version: - ) Blacklight Retribution (x32 Version: - Perfect World Entertainment) CCleaner (Version: 3.20 - Piriform) Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000 - Microsoft Corporation) CPUID CPU-Z 1.68 (Version: - ) DayZ (x32 Version: - Bohemia Interactive) DayZ Commander (x32 Version: 0.91.4 - Dotjosh Studios) Dell Backup and Recovery Manager (Version: 1.2.1 - Dell Inc.) Dell Edoc Viewer (Version: 1.0.0 - Dell Inc) DivX-Setup (x32 Version: - DivX, LLC) ESN Sonar (x32 Version: 0.70.4 - ESN Social Software AB) EXPERTool v8.4 (x32 Version: - Gainward Co. Ltd.) Fraps (remove only) (x32 Version: - ) gamelauncher-ps2-psg (HKCU Version: - Sony Online Entertainment) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.) Google Update Helper (x32 Version: - Google Inc.) Hidden Hawken (HKCU Version: - Meteor Entertainment) Internet-TV für Windows Media Center (x32 Version: - Microsoft Corporation) IPTInstaller (x32 Version: 4.0.8 - HTC) Java 7 Update 17 (64-bit) (Version: 7.0.170 - Oracle) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: - Sun Microsystems, Inc.) Hidden KFTools_AutoInstaller_V1.1 (x32 Version: - ) Left 4 Dead 2 (x32 Version: - Valve) LG USB Modem Drivers (x32 Version: 4.9.4 - LG Electronics) LogMeIn Hamachi (x32 Version: - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: - LogMeIn, Inc.) Hidden Mass Effect 2 (x32 Version: 1.00 - Electronic Arts, Inc.) Mass Effect™ 3 (x32 Version: - Electronic Arts) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (x32 Version: - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Works (x32 Version: 9.7.0621 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (Version: - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (Version: - Microsoft Corporation) Hidden MotoHelper MergeModules (x32 Version: 1.0.0 - Motorola) Hidden MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden Mozilla Firefox 20.0.1 (x86 de) (x32 Version: 20.0.1 - Mozilla) Mozilla Maintenance Service (x32 Version: 20.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (x32 Version: 4.20.9818.0 - Microsoft Corporation) Natural Selection 2 (x32 Version: - Unknown Worlds Entertainment) nProtect Security Platform (x32 Version: 3.00.0000 - INCAInternet) Hidden NVIDIA 3D Vision Controller-Treiber 332.21 (Version: 332.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 332.21 (Version: 332.21 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.1 (Version: 1.8.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 332.21 (Version: 332.21 - NVIDIA Corporation) NVIDIA HD-Audiotreiber (Version: - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA ShadowPlay 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden NVIDIA Update 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.19 (Version: 1.2.19 - NVIDIA Corporation) Origin (x32 Version: - Electronic Arts, Inc.) PlanetSide 2 (HKCU Version: - Sony Online Entertainment) Portal 2 (x32 Version: - Valve) Portal 2 Publishing Tool (x32 Version: - ) PunkBuster Services (x32 Version: 0.993 - Even Balance, Inc.) RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) Hidden Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Steam (x32 Version: - Valve Corporation) Supreme Commander 2 (x32 Version: - Gas Powered Games) swMSM (x32 Version: - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (Version: 3.0.12 - TeamSpeak Systems GmbH) Ubisoft Game Launcher (x32 Version: - UBISOFT) Unity Web Player (HKCU Version: - Unity Technologies ApS) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.0.6 (Version: 2.0.6 - VideoLAN) War Thunder Launcher (x32 Version: - 2012 Gaijin Entertainment Corporation) Warframe (x32 Version: - Digital Extremes) Windows Media Center Add-in for Silverlight (x32 Version: - Microsoft Corporation) WolfTeam-DE (x32 Version: - ) World of Tanks (x32 Version: - Wargaming.net) X3 Terran Conflict v3.2 (x32 Version: - EGOSOFT) X3: Albion Prelude (x32 Version: - ) X3: Terran Conflict (x32 Version: - Egosoft) Yahoo! Detect (x32 Version: - ) YTD Video Downloader 4.0 (x32 Version: 4.0 - GreenTree Applications SRL) ==================== Restore Points ========================= 27-12-2013 16:49:24 Windows Update 29-12-2013 18:00:28 Windows-Sicherung 31-12-2013 16:01:08 Windows Update 05-01-2014 18:00:27 Windows-Sicherung 07-01-2014 10:42:28 Windows Update 10-01-2014 18:14:34 Windows Update 10-01-2014 22:02:00 Removed Aeria Ignite ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {039EC66A-C131-47B5-AA5D-8F82BC8FF75F} - System32\Tasks\{C953FC9D-4DD8-486A-9EC4-39A9CD45D5E5} => C:\Program Files (x86)\Electronic Arts\Aufstieg des Hexenkönigs\lotrbfme2ep1.exe Task: {07ADFB65-3EEC-4923-BBAB-8CF571804915} - System32\Tasks\{3045EC2C-9A05-4D8F-AF1F-7AECCCD8A763} => C:\Program Files (x86)\Electronic Arts\Aufstieg des Hexenkönigs\lotrbfme2ep1.exe Task: {08238CA9-53A3-4274-81DF-08A77734B496} - System32\Tasks\{E93D0681-1C84-4A83-ABBA-08E940C0CAA2} => C:\Program Files (x86)\EGOSOFT\X3 Terran Conflict\X3TC.exe Task: {088F6434-CA06-40E0-A320-602E35D74FDC} - System32\Tasks\{0602D15F-9464-4733-BFA2-554024C02B72} => C:\Program Files (x86)\Gameforge4D\AirRivals_DE\airrivals.exe Task: {0D0BF488-C45E-441E-A3FF-13660B69E64C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-29] (Google Inc.) Task: {14924B78-54FB-4854-8803-A3A31722DB9D} - System32\Tasks\{315D9BB1-C238-4CFD-A6EF-1EF4D723F814} => C:\Program Files (x86)\EGOSOFT\X3 Terran Conflict\X3TC.exe Task: {1B4BA442-A01D-4B74-9EDB-A0FD5E4FD3A5} - System32\Tasks\{DA5B4A13-D550-4D3C-A113-C400A18B1009} => C:\Program Files (x86)\EGOSOFT\X3 Terran Conflict\X3TC.exe Task: {1BE3F742-54E1-4C76-AE0F-CF2A76F2A95A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2012-11-02] (Microsoft) Task: {1E2E9CC4-69F6-4E28-9FE5-C98327A8B459} - System32\Tasks\JavaUpdateChristian => C:\Windows\System32\jusched.exe Task: {22501128-9012-4368-9D78-A66910606E2D} - System32\Tasks\JavaUpdateSched => C:\Windows\System32\jusched.exe Task: {23AD3435-6D73-4F39-8E0C-EEA884DC50F7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {3729C398-1EC1-4A23-BBE8-8EAE7AB5ABEA} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2012-11-02] (Microsoft Corporation) Task: {40666742-D36C-4BD2-9844-CAF61D74FF9C} - System32\Tasks\{3F8A5AB5-5CC9-4C6B-9C6B-7942A68A0177} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {42FF5B90-9201-4EF0-BCED-A292BB95C5BA} - System32\Tasks\{21A3E80F-91BF-42A0-9A8A-DB0BF20EFF12} => C:\Program Files (x86)\EGOSOFT\X3 Terran Conflict\X3TC.exe Task: {47243793-3A03-4121-AAE0-64AEAEACBC39} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-06-22] (Piriform Ltd) Task: {47FE14A2-E52D-4086-AC79-A32A1B4B4071} - System32\Tasks\{C38A153D-EA42-4744-A9CF-643D45022586} => C:\Program Files (x86)\Gameforge4D\AirRivals_DE\airrivals.exe Task: {522262AE-01A9-4B5F-BAAC-F6840AF55E56} - System32\Tasks\{3C7D4E5C-1CA8-4C94-9C60-0D54837C8DEE} => C:\Program Files (x86)\Electronic Arts\Aufstieg des Hexenkönigs\lotrbfme2ep1.exe Task: {58CEE766-C376-4354-88A4-B59574F5F131} - System32\Tasks\{F2F5ED48-FA03-4868-921B-A3A1E5367C78} => C:\Program Files (x86)\Minecraft\.minecraft\MinecraftSP.exe Task: {5E9E4993-998C-46A7-82E7-3A1F7D6E191E} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2012-11-02] (Microsoft Corporation) Task: {6731FED5-7C63-4B5B-9869-E674B1D3ED37} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-29] (Google Inc.) Task: {67EFA74E-4510-49B0-9D41-FEF0AB67C795} - System32\Tasks\{649F3AD1-D76D-468C-9FB9-DEF99DA50B59} => C:\Program Files (x86)\Gameforge4D\AirRivals_DE\airrivals.exe Task: {6B8ECC27-9025-4E3E-A73B-BF6090A5BDC2} - \RegClean Pro_DEFAULT No Task File Task: {724AE155-60CC-4944-8064-4C3DAA305E11} - System32\Tasks\{7EF8F1B7-0924-4157-891E-94A6544FE2D4} => C:\Program Files (x86)\EGOSOFT\X3 Terran Conflict\X3TC.exe Task: {7EDD3744-F12F-4C0F-B8E2-227060E2E756} - System32\Tasks\{95446217-32CD-45C5-9A62-EFDA5AC53E18} => C:\Program Files (x86)\Gameforge4D\AirRivals_DE\airrivals.exe Task: {8F16111D-BDEA-4D3D-B6F1-E3B8D552ADB3} - \RegClean Pro_UPDATES No Task File Task: {A99C897F-A1B5-4AAB-8B13-3402AE43DE3B} - System32\Tasks\{9802989F-6067-464B-BB61-830F8CC8EE27} => C:\Program Files (x86)\Gameforge4D\AirRivals_DE\airrivals.exe Task: {AC630CAF-B036-4671-9730-B3C33D8A63FB} - System32\Tasks\{26B480AA-74C8-4855-AAA6-423042DA7984} => C:\Program Files (x86)\Electronic Arts\Aufstieg des Hexenkönigs\lotrbfme2ep1.exe Task: {AD9D9002-0C28-4CB8-A1DA-65FBC49A30CC} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2334490465-2500225930-2497035786-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {B9E3B1DD-30C9-454D-98C0-9269D7C5BB99} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2334490465-2500225930-2497035786-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {C511623F-0CEB-4C25-9F7A-CC1D82EEC0A5} - System32\Tasks\{520E2329-42FD-4A15-82F7-357126BD3CA2} => C:\Program Files (x86)\EGOSOFT\X3 Terran Conflict\X3TC.exe Task: {E0C3CF8F-8ECB-4CA6-B35A-1C4032E22C38} - System32\Tasks\{DE45C353-DD57-49FE-A1C5-5836D3C0EF6F} => C:\Program Files (x86)\EGOSOFT\X3 Terran Conflict\X3TC.exe Task: {E73640DF-1AA4-4E52-B964-EB5813EC7E30} - \RegClean Pro No Task File Task: {FF4133DA-9DAE-455C-BD8F-F8240E7D0E42} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-05 21:19 - 2013-08-05 21:10 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-01-16 19:42 - 2013-11-21 13:32 - 00064000 _____ () S:\Spiele\Origin\tufao.dll 2014-01-08 18:29 - 2013-12-12 23:19 - 00142848 _____ () C:\Program Files (x86)\Steam\libavresample-1.dll 2014-01-08 18:29 - 2013-11-05 02:12 - 00890592 _____ () C:\Program Files (x86)\Steam\libavutil-52.dll 2013-03-25 13:23 - 2013-12-12 23:04 - 00716800 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2013-02-25 07:39 - 2014-01-07 22:00 - 01138088 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2013-02-19 11:48 - 2013-12-12 23:04 - 20625832 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2012-12-11 09:51 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll 2012-12-11 09:51 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll 2012-12-11 09:51 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll 2013-08-29 01:25 - 2013-08-29 01:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2013-12-05 18:41 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-05 18:41 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-05 18:41 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-05 18:41 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-05 18:41 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-05 18:41 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Faulty Device Manager Devices ============= Name: nProtect Firewall Core Driver Description: nProtect Firewall Core Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: TKFWFV Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (01/10/2014 09:26:03 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: TBPanel.exe, Version:, Zeitstempel: 0x4fffce71 Name des fehlerhaften Moduls: TBPanel.exe, Version:, Zeitstempel: 0x4fffce71 Ausnahmecode: 0xc0000094 Fehleroffset: 0x0002bb6e ID des fehlerhaften Prozesses: 0xcc8 Startzeit der fehlerhaften Anwendung: 0xTBPanel.exe0 Pfad der fehlerhaften Anwendung: TBPanel.exe1 Pfad des fehlerhaften Moduls: TBPanel.exe2 Berichtskennung: TBPanel.exe3 Error: (01/08/2014 10:47:01 PM) (Source: Application Hang) (User: ) Description: Programm PlanetSide2.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 11bc Startzeit: 01cf0ca84f411600 Endzeit: 87 Anwendungspfad: S:\Spiele\Sony Online Entertainment\Installed Games\PlanetSide 2 PSG\PlanetSide2.exe Berichts-ID: Error: (01/06/2014 04:03:29 PM) (Source: Application Hang) (User: ) Description: Programm bf4.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 6e0 Startzeit: 01cf0aebf27a7719 Endzeit: 59 Anwendungspfad: S:\Spiele\Origin Games\Battlefield 4\bf4.exe Berichts-ID: Error: (01/06/2014 02:20:34 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (01/06/2014 02:20:34 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (01/02/2014 07:52:01 PM) (Source: Application Hang) (User: ) Description: Programm bf4.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 10f0 Startzeit: 01cf07eb5ee1bb7f Endzeit: 208 Anwendungspfad: S:\Spiele\Origin Games\Battlefield 4\bf4.exe Berichts-ID: Error: (12/30/2013 09:17:48 PM) (Source: Application Hang) (User: ) Description: Programm DayZ.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: ccc Startzeit: 01cf059c04d94726 Endzeit: 44 Anwendungspfad: S:\SteamLibrary\steamapps\common\DayZ\DayZ.exe Berichts-ID: Error: (12/30/2013 09:17:23 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: nvtray.exe, Version:, Zeitstempel: 0x5280e916 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000004e4e4 ID des fehlerhaften Prozesses: 0xf54 Startzeit der fehlerhaften Anwendung: 0xnvtray.exe0 Pfad der fehlerhaften Anwendung: nvtray.exe1 Pfad des fehlerhaften Moduls: nvtray.exe2 Berichtskennung: nvtray.exe3 Error: (12/21/2013 10:42:52 PM) (Source: Application Hang) (User: ) Description: Programm Skype.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: abc Startzeit: 01cefe7e4489ab97 Endzeit: 20 Anwendungspfad: C:\Program Files (x86)\Skype\Phone\Skype.exe Berichts-ID: Error: (12/20/2013 06:48:42 PM) (Source: Application Hang) (User: ) Description: Programm Launcher.exe, Version 2013.12.18.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 13bc Startzeit: 01cefdabaaa7b944 Endzeit: 0 Anwendungspfad: S:\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exe Berichts-ID: f58804c1-699e-11e3-9d42-a4badb0360b5 System errors: ============= Error: (01/10/2014 10:50:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Update Jump Flip" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/10/2014 10:50:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Update Jump Flip" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (01/10/2014 10:20:43 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (01/10/2014 10:19:52 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: TKFWFV Error: (01/10/2014 10:18:04 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "vToolbarUpdater17.3.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/10/2014 09:45:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DrvAgent64" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/10/2014 09:45:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DrvAgent64" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/10/2014 09:45:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DrvAgent64" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/10/2014 09:45:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DrvAgent64" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/10/2014 09:45:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DrvAgent64" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (01/10/2014 09:26:03 PM) (Source: Application Error)(User: ) Description: TBPanel.exe8.4.0.04fffce71TBPanel.exe8.4.0.04fffce71c00000940002bb6ecc801cf0e2f0ca8866bC:\Program Files (x86)\EXPERTool\TBPanel.exeC:\Program Files (x86)\EXPERTool\TBPanel.exe6c608e00-7a35-11e3-aa1d-a4badb0360b5 Error: (01/08/2014 10:47:01 PM) (Source: Application Hang)(User: ) Description: PlanetSide2.exe0.0.0.011bc01cf0ca84f41160087S:\Spiele\Sony Online Entertainment\Installed Games\PlanetSide 2 PSG\PlanetSide2.exe Error: (01/06/2014 04:03:29 PM) (Source: Application Hang)(User: ) Description: bf4.exe1.0.0.16e001cf0aebf27a771959S:\Spiele\Origin Games\Battlefield 4\bf4.exe Error: (01/06/2014 02:20:34 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (01/06/2014 02:20:34 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (01/02/2014 07:52:01 PM) (Source: Application Hang)(User: ) Description: bf4.exe1.0.0.110f001cf07eb5ee1bb7f208S:\Spiele\Origin Games\Battlefield 4\bf4.exe Error: (12/30/2013 09:17:48 PM) (Source: Application Hang)(User: ) Description: DayZ.exe0.30.113.860ccc01cf059c04d9472644S:\SteamLibrary\steamapps\common\DayZ\DayZ.exe Error: (12/30/2013 09:17:23 PM) (Source: Application Error)(User: ) Description: nvtray.exe7.17.13.31825280e916ntdll.dll6.1.7601.18247521eaf24c0000005000000000004e4e4f5401cf059bb537be3cC:\Program Files\NVIDIA Corporation\Display\nvtray.exeC:\Windows\SYSTEM32\ntdll.dll63e8d175-718f-11e3-84f6-a4badb0360b5 Error: (12/21/2013 10:42:52 PM) (Source: Application Hang)(User: ) Description: Skype.exe6.11.0.102abc01cefe7e4489ab9720C:\Program Files (x86)\Skype\Phone\Skype.exe Error: (12/20/2013 06:48:42 PM) (Source: Application Hang)(User: ) Description: Launcher.exe2013.12.18.113bc01cefdabaaa7b9440S:\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exef58804c1-699e-11e3-9d42-a4badb0360b5 ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 12247.11 MB Available physical RAM: 8602.89 MB Total Pagefile: 24492.41 MB Available Pagefile: 20304.33 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:224.01 GB) (Free:84.36 GB) NTFS Drive d: (DATAPART1) (Fixed) (Total:232.83 GB) (Free:110.72 GB) NTFS Drive s: (Volume) (Fixed) (Total:1862.89 GB) (Free:1569.48 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: E8000000) Partition 1: (Not Active) - (Size=110 MB) - (Type=DE) Partition 2: (Active) - (Size=9 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=224 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 7B945512) Partition 1: (Not Active) - (Size=233 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT Partition Type ==================== End Of Log ============================ |
Downloade Dir bitte
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Systweak Software gedownloadet, lies sich nach Neustart Deinstallieren - Würde es gerne kontrollieren lassen |
| ![]() Systweak Software gedownloadet, lies sich nach Neustart Deinstallieren - Würde es gerne kontrollieren lassen Das mbam-log: Code:
ATTFilter Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2014.01.12.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Christian :: CHRIS [Administrator] Schutz: Aktiviert 12.01.2014 12:53:00 mbam-log-2014-01-12 (12-53-00).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 254980 Laufzeit: 7 Minute(n), 35 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKLM\SYSTEM\CurrentControlSet\Services\Update Jump Flip (PUP.Optional.JumpFlip.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 5 C:\Users\Christian\AppData\Local\Temp\ct3288691 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Local\Temp\ct3297265 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Local\Temp\ct3297861 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 11 C:\ProgramData\YTD Video Downloader\ytd_installer.exe (PUP.Optional.Spigot.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-21-2334490465-2500225930-2497035786-1000\$R000ZIT.zip (Malware.Packer.KISS) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-21-2334490465-2500225930-2497035786-1000\$RZ76ZAA.zip (Trojan.Agent.rfz) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Local\Temp\ct3297265\ism.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Local\Temp\ct3288691\chromeid.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Local\Temp\ct3288691\setup.ini.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Local\Temp\ct3297861\chromeid.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Local\Temp\ct3297861\setup.ini.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Christian\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) AdwCleaner: Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 12/01/2014 um 13:11:38 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Christian - CHRIS # Gestartet von : C:\Users\Christian\Downloads\adwcleaner (1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Christian\AppData\Roaming\Systweak Datei Gelöscht : C:\Users\CHRIST~1\AppData\Local\Temp\Uninstall.exe Datei Gelöscht : C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\10csbgas.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v20.0.1 (de) [ Datei : C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\10csbgas.default\prefs.js ] -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [45234 octets] - [10/01/2014 22:14:25] AdwCleaner[R1].txt - [1610 octets] - [12/01/2014 13:10:51] AdwCleaner[S0].txt - [41782 octets] - [10/01/2014 22:15:44] AdwCleaner[S1].txt - [1395 octets] - [12/01/2014 13:11:38] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1455 octets] ########## Code:
![]() | #8 |
Downloade Dir bitte
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #9 |
Hallo!
![]() | #10 |
/// the machine /// TB-Ausbilder

Firefox updaten Fertig
gruß, schrauber

Proud Member of UNITE and ASAP since 2009
![]() | #11 |
Dann bedanke ich mich kurz schon einmal hier!

Soweit wäre dann alles geklärt, du kannst das Abo löschen. Und danke für TFC für die Performance, kann ich sehr gut gebrauchen

Ich wünsche dir desweiteren ganz viel Erfolg im Studium, sowie mit ASAP und UNITE und verabschiede mich an dieser Stelle

Gruß, Chris
![]() | #12 |
/// the machine /// TB-Ausbilder

Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
