|
Plagegeister aller Art und deren Bekämpfung: Malwarebytes Suchlauf 2 infizierte ObjekteWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
30.01.2014, 22:05 | #1 |
| Malwarebytes Suchlauf 2 infizierte Objekte So schnell kanns gehen Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.28.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 *** :: ***-PC [Administrator] 30.01.2014 21:29:00 log 30.01.txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 220316 Laufzeit: 7 Minute(n), 47 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\***\AppData\Local\Temp\FlashPlayersetup__3873_i298670765_il155.exe (PUP.Optional.InstallMonetizer) -> Keine Aktion durchgeführt. C:\Users\***\Downloads\FlashPlayersetup__3873_i298670765_il155.exe (PUP.Optional.InstallMonetizer) -> Keine Aktion durchgeführt. (Ende) Geändert von Jako1712 (30.01.2014 um 22:51 Uhr) |
30.01.2014, 22:35 | #2 |
/// the machine /// TB-Ausbilder | Malwarebytes Suchlauf 2 infizierte Objekte hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
30.01.2014, 22:49 | #3 |
| Malwarebytes Suchlauf 2 infizierte Objekte FRST.txt :
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by *** (administrator) on ***-PC on 30-01-2014 22:46:30 Running from C:\Users\***\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Dropbox, Inc.) C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Spotify Ltd) C:\Users\***\AppData\Roaming\Spotify\spotify.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Users\***\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [Cm108Sound] - C:\Windows\Syswow64\cm108.dll [8757248 2013-01-16] (C-Media Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-19] (AVAST Software) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3813200 2014-01-23] (LogMeIn Inc.) HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1 HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1 HKCU\...\Run: [Facebook Update] - C:\Users\***\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-12-25] (Facebook Inc.) HKCU\...\Run: [KeePass Password Safe 2] - "C:\Users\***\Desktop\KeePass-2.21\KeePass.exe" HKCU\...\Run: [Gyazo] - C:\Program Files (x86)\Gyazo\GyStation.exe [2990304 2013-10-02] (Nota Inc.) Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x69F34B026D6BCE01 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLEP1&pc=SPLH SearchScopes: HKCU - {7BF33919-C77C-4a38-8DE7-BF8C178DD4A4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK SearchScopes: HKCU - {BDC7F2B5-AAC9-4958-AC94-2F3EBD3A8AB0} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A6976579318&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A6976579318&q={searchTerms} SearchScopes: HKCU - {F4402334-0E59-4F29-B5DB-7F81C6F051DD} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=goughDev3&Lan=de&q={searchTerms}&gu=52e57722afdf46bcb06ab11f02dad718&tu=10G9z009V1B0CO0&sku=&tstsId=&ver=&&r=143 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Zonealarm Helper Object - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\bh\zonealarm.dll (Check Point Software Technologies LTD) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - ZoneAlarm Security Toolbar - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmTlbr.dll (Check Point Software Technologies LTD) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\hof1d5rn.default FF SearchEngineOrder.1: Search By ZoneAlarm FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\***\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\***\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\hof1d5rn.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-10-22] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-24] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-10-22] Chrome: ======= CHR Extension: (Google Drive) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-24] CHR Extension: (YouTube) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-24] CHR Extension: (Google-Suche) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-24] CHR Extension: (avast! Online Security) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-12-01] CHR Extension: (Google Wallet) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-24] CHR Extension: (Google Mail) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-24] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-11-24] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-19] (AVAST Software) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-12-13] (LogMeIn, Inc.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-08-28] () R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) S2 SmartViewService; C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [x] ==================== Drivers (Whitelisted) ==================== R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [19600 2012-08-21] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-01-19] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-24] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-24] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2014-01-19] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2014-01-19] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2014-01-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-19] () R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [39768 2013-02-09] (AVG Technologies) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-09-17] (Anchorfree Inc.) S3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [126976 2010-11-26] (VIA Technologies, Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [x] S3 MBfilt; system32\drivers\MBfilt64.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-30 22:46 - 2014-01-30 22:46 - 00018106 _____ C:\Users\***\Downloads\FRST.txt 2014-01-30 22:46 - 2014-01-30 22:46 - 00000000 ____D C:\FRST 2014-01-30 22:45 - 2014-01-30 22:45 - 02079744 _____ (Farbar) C:\Users\***\Downloads\FRST64.exe 2014-01-30 12:27 - 2014-01-30 12:27 - 00000000 ____D C:\Users\***\Documents\Orcs Must Die 2014-01-30 10:28 - 2014-01-30 10:28 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2014-01-30 10:27 - 2014-01-15 23:35 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-01-30 10:23 - 2014-01-30 10:24 - 00000000 ____D C:\Windows\LastGood 2014-01-30 10:21 - 2014-01-16 00:13 - 31421216 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 25255200 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 23672096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 17714760 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 12668192 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-01-30 10:21 - 2014-01-16 00:13 - 11631544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 11583616 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 09723944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 09686304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433467.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433467.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00859936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00483104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00408352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00378656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-01-30 10:21 - 2014-01-16 00:13 - 00024544 _____ C:\Windows\system32\nvinfo.pb 2014-01-30 10:08 - 2014-01-30 10:08 - 00000000 ____D C:\Users\***\Desktop\154 Botschaft aus der Unterwelt 2014-01-28 21:51 - 2014-01-28 21:52 - 00338472 _____ (Amônétízé Ltd) C:\Users\***\Downloads\FlashPlayersetup__3873_i298670765_il155.exe 2014-01-27 14:27 - 2014-01-27 14:27 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2014-01-25 19:22 - 2014-01-25 19:24 - 77064997 _____ (DyVox Studios ) C:\Users\***\Downloads\DVsetup_00012.exe 2014-01-24 15:52 - 2014-01-24 16:13 - 00000000 ____D C:\Users\***\Documents\InfiniteCrisis 2014-01-24 15:52 - 2014-01-24 15:52 - 00000000 ____D C:\Users\***\AppData\Local\InfiniteCrisis 2014-01-24 15:28 - 2014-01-24 15:28 - 00127080 _____ (Spotify Ltd) C:\Users\***\Downloads\SpotifySetup(1).exe 2014-01-24 15:23 - 2014-01-24 15:23 - 00000000 ____D C:\Users\***\AppData\Local\Turbine 2014-01-24 15:20 - 2014-01-24 15:49 - 00000000 ____D C:\Program Files (x86)\InfiniteCrisis 2014-01-24 15:20 - 2014-01-24 15:20 - 00001088 _____ C:\Users\Public\Desktop\InfiniteCrisis.lnk 2014-01-24 15:20 - 2014-01-24 15:20 - 00000000 ____D C:\ProgramData\Turbine 2014-01-24 15:17 - 2014-01-24 15:19 - 138644080 _____ C:\Users\***\Downloads\InfiniteCrisis-GLOBAL_Setup.exe 2014-01-23 19:16 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-01-23 19:16 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-01-22 18:25 - 2014-01-22 18:26 - 03821064 _____ C:\Users\***\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-19 19:42 - 2014-01-28 17:35 - 00000000 ____D C:\Users\***\AppData\Roaming\HpUpdate 2014-01-19 19:41 - 2014-01-19 19:41 - 00000000 ____D C:\Windows\Hewlett-Packard 2014-01-19 19:39 - 2014-01-19 19:41 - 03111104 _____ (Hewlett-Packard ) C:\Users\***\Downloads\hpusetup.exe 2014-01-19 19:32 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-19 19:32 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-19 19:32 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-19 19:32 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-19 19:30 - 2014-01-19 19:32 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-19 19:28 - 2014-01-19 19:29 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-19 19:22 - 2014-01-19 19:22 - 00000907 _____ C:\Users\Public\Desktop\WinSCP.lnk 2014-01-19 19:08 - 2014-01-19 19:08 - 05329480 _____ (Secunia) C:\Users\***\Downloads\PSISetup_3.0.0.9016.exe 2014-01-19 19:08 - 2014-01-19 19:08 - 00000000 ____D C:\Users\***\AppData\Local\Secunia PSI 2014-01-19 19:08 - 2014-01-19 19:08 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-19 19:01 - 2014-01-19 19:03 - 00002418 _____ C:\DelFix.txt 2014-01-19 19:01 - 2014-01-19 19:01 - 00000000 ____D C:\Windows\ERUNT 2014-01-19 15:30 - 2014-01-19 15:30 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-19 14:49 - 2014-01-19 15:01 - 00000000 ____D C:\Users\***\Downloads\FRST-OlderVersion 2014-01-18 22:08 - 2014-01-18 22:08 - 00000000 ____D C:\Users\***\Documents\Pinnacle VideoSpin 2014-01-18 22:01 - 2014-01-18 22:01 - 00000000 ____D C:\Users\***\AppData\Local\Downloaded Installations 2014-01-18 22:01 - 2014-01-18 22:01 - 00000000 ____D C:\ProgramData\Pinnacle 2014-01-18 21:56 - 2014-01-18 21:56 - 00000000 ____D C:\Users\***\Downloads\VideoSpin_2_0_Setup 2014-01-18 16:34 - 2014-01-18 16:34 - 00001195 _____ C:\Users\***\Desktop\Podcast - Verknüpfung.lnk 2014-01-17 17:28 - 2014-01-17 17:28 - 00000000 ____D C:\Users\***\AppData\Roaming\Unity 2014-01-17 17:27 - 2014-01-17 17:27 - 00000000 ____D C:\Users\***\AppData\Local\Unity 2014-01-15 23:15 - 2014-01-15 23:15 - 00000000 ____D C:\projects 2014-01-15 17:52 - 2014-01-15 17:52 - 00000000 ____D C:\ccc3a3a1e955984900e330689a 2014-01-15 17:32 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 17:32 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 17:32 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 17:32 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 17:32 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 17:32 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 17:32 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 17:32 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 17:32 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-13 22:10 - 2014-01-13 22:10 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-13 22:10 - 2014-01-13 22:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-13 22:08 - 2014-01-13 22:08 - 00283096 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup Stub 26.0.exe 2014-01-12 13:29 - 2014-01-12 13:29 - 00000169 _____ C:\Windows\Cm108.ini.cfl 2014-01-12 13:29 - 2013-01-16 17:54 - 08757248 ____N (C-Media Corporation) C:\Windows\SysWOW64\CM108.dll 2014-01-12 13:29 - 2013-01-16 17:54 - 00389120 ____N () C:\Windows\system32\CM108.cpl 2014-01-12 13:29 - 2013-01-16 17:54 - 00200704 ____N (C-Media) C:\Windows\SysWOW64\cmpa108.dll 2014-01-12 13:29 - 2013-01-16 17:54 - 00143360 ____N C:\Windows\Vmix108.dll 2014-01-12 13:28 - 2014-01-12 13:29 - 00000277 _____ C:\Windows\Cm108.ini.imi 2014-01-12 13:28 - 2014-01-12 13:28 - 00000226 _____ C:\Windows\system\Cm108.ini 2014-01-12 13:28 - 2013-01-16 17:56 - 00001459 ____N C:\Windows\Cm108.ini.cfg 2014-01-12 13:28 - 2013-01-16 17:54 - 01310720 _____ (C-Media Electronics Inc) C:\Windows\system32\Drivers\CM10864.sys 2014-01-12 13:28 - 2013-01-16 17:54 - 00315392 _____ (C-Media Electronics Inc.) C:\Windows\system\fltr108.dll 2014-01-12 13:28 - 2013-01-16 17:54 - 00001353 ____N C:\Windows\cm108.ini 2014-01-11 23:31 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll 2014-01-11 23:31 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll 2014-01-11 23:31 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-01-11 23:31 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-01-11 23:31 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-01-06 20:59 - 2014-01-06 20:59 - 00000000 ____D C:\ProgramData\SystemRequirementsLab ==================== One Month Modified Files and Folders ======= 2014-01-30 22:46 - 2014-01-30 22:46 - 00018106 _____ C:\Users\***\Downloads\FRST.txt 2014-01-30 22:46 - 2014-01-30 22:46 - 00000000 ____D C:\FRST 2014-01-30 22:45 - 2014-01-30 22:45 - 02079744 _____ (Farbar) C:\Users\***\Downloads\FRST64.exe 2014-01-30 22:43 - 2013-07-11 11:25 - 00056903 _____ C:\Windows\setupact.log 2014-01-30 22:21 - 2013-11-24 22:09 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-30 22:07 - 2012-12-25 19:02 - 00000932 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3479666674-3888422604-2336058070-1000UA.job 2014-01-30 22:06 - 2013-02-20 18:18 - 00000000 ____D C:\Program Files (x86)\Steam 2014-01-30 22:02 - 2013-03-16 18:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-30 22:00 - 2012-11-10 22:10 - 00000000 ____D C:\Users\***\AppData\Local\PMB Files 2014-01-30 22:00 - 2012-11-10 22:10 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-30 21:54 - 2012-09-17 18:17 - 01749606 _____ C:\Windows\WindowsUpdate.log 2014-01-30 21:36 - 2013-11-16 13:38 - 00000000 ____D C:\Users\***\AppData\Roaming\Spotify 2014-01-30 20:38 - 2013-03-02 13:34 - 00000000 ____D C:\Users\***\AppData\Local\LogMeIn Hamachi 2014-01-30 19:06 - 2012-12-25 19:01 - 00000910 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3479666674-3888422604-2336058070-1000Core.job 2014-01-30 18:21 - 2013-11-24 22:09 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-30 17:13 - 2013-02-18 21:30 - 00000000 ____D C:\Users\***\AppData\Roaming\vlc 2014-01-30 17:13 - 2013-02-09 20:13 - 00000000 ___RD C:\Users\***\Dropbox 2014-01-30 17:13 - 2013-02-09 20:09 - 00000000 ____D C:\Users\***\AppData\Roaming\Dropbox 2014-01-30 12:27 - 2014-01-30 12:27 - 00000000 ____D C:\Users\***\Documents\Orcs Must Die 2014-01-30 12:26 - 2013-07-11 12:56 - 00354618 _____ C:\Windows\DirectX.log 2014-01-30 10:28 - 2014-01-30 10:28 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2014-01-30 10:28 - 2012-10-19 17:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2014-01-30 10:27 - 2013-03-20 15:28 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-30 10:24 - 2014-01-30 10:23 - 00000000 ____D C:\Windows\LastGood 2014-01-30 10:18 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-30 10:18 - 2009-07-14 05:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-30 10:12 - 2012-09-17 20:00 - 00000000 ____D C:\Users\***\AppData\Local\Windows Live 2014-01-30 10:08 - 2014-01-30 10:08 - 00000000 ____D C:\Users\***\Desktop\154 Botschaft aus der Unterwelt 2014-01-30 10:07 - 2013-11-24 22:10 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2014-01-30 10:06 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-28 21:52 - 2014-01-28 21:51 - 00338472 _____ (Amônétízé Ltd) C:\Users\***\Downloads\FlashPlayersetup__3873_i298670765_il155.exe 2014-01-28 17:35 - 2014-01-19 19:42 - 00000000 ____D C:\Users\***\AppData\Roaming\HpUpdate 2014-01-27 18:45 - 2012-10-01 17:41 - 00000000 ____D C:\Users\***\Desktop\Alle Ordner 2014-01-27 14:27 - 2014-01-27 14:27 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2014-01-25 19:26 - 2012-09-18 15:33 - 00000000 ____D C:\Users\***\AppData\Roaming\Skype 2014-01-25 19:24 - 2014-01-25 19:22 - 77064997 _____ (DyVox Studios ) C:\Users\***\Downloads\DVsetup_00012.exe 2014-01-24 16:13 - 2014-01-24 15:52 - 00000000 ____D C:\Users\***\Documents\InfiniteCrisis 2014-01-24 15:52 - 2014-01-24 15:52 - 00000000 ____D C:\Users\***\AppData\Local\InfiniteCrisis 2014-01-24 15:49 - 2014-01-24 15:20 - 00000000 ____D C:\Program Files (x86)\InfiniteCrisis 2014-01-24 15:29 - 2013-11-16 13:40 - 00001811 _____ C:\Users\***\Desktop\Spotify.lnk 2014-01-24 15:29 - 2013-11-16 13:40 - 00001797 _____ C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2014-01-24 15:28 - 2014-01-24 15:28 - 00127080 _____ (Spotify Ltd) C:\Users\***\Downloads\SpotifySetup(1).exe 2014-01-24 15:23 - 2014-01-24 15:23 - 00000000 ____D C:\Users\***\AppData\Local\Turbine 2014-01-24 15:22 - 2012-10-02 22:56 - 00000000 ____D C:\Users\***\AppData\Local\Adobe 2014-01-24 15:20 - 2014-01-24 15:20 - 00001088 _____ C:\Users\Public\Desktop\InfiniteCrisis.lnk 2014-01-24 15:20 - 2014-01-24 15:20 - 00000000 ____D C:\ProgramData\Turbine 2014-01-24 15:19 - 2014-01-24 15:17 - 138644080 _____ C:\Users\***\Downloads\InfiniteCrisis-GLOBAL_Setup.exe 2014-01-23 20:01 - 2012-10-24 12:59 - 00000000 ____D C:\Users\***\AppData\Roaming\.minecraft 2014-01-23 19:33 - 2012-09-21 13:30 - 00000000 ____D C:\Users\***\Desktop\Musik 2014-01-23 17:46 - 2013-03-02 22:27 - 00000000 ____D C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-01-23 16:29 - 2013-08-26 17:16 - 00000000 ____D C:\Program Files (x86)\Origin 2014-01-22 20:33 - 2013-11-16 13:40 - 00000000 ____D C:\Users\***\AppData\Local\Spotify 2014-01-22 18:27 - 2012-09-19 18:56 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2014-01-22 18:27 - 2012-09-19 18:14 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-22 18:26 - 2014-01-22 18:25 - 03821064 _____ C:\Users\***\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-22 18:26 - 2013-08-27 21:08 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2014-01-22 18:26 - 2012-09-19 18:14 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-21 03:53 - 2013-12-21 19:52 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-01-21 03:53 - 2013-12-21 19:52 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-01-20 17:56 - 2013-02-18 21:21 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk 2014-01-20 16:56 - 2013-08-01 10:58 - 00106884 _____ C:\Windows\PFRO.log 2014-01-19 19:42 - 2012-10-22 10:30 - 00000000 ____D C:\Program Files (x86)\HP 2014-01-19 19:41 - 2014-01-19 19:41 - 00000000 ____D C:\Windows\Hewlett-Packard 2014-01-19 19:41 - 2014-01-19 19:39 - 03111104 _____ (Hewlett-Packard ) C:\Users\***\Downloads\hpusetup.exe 2014-01-19 19:33 - 2013-10-25 16:21 - 00000000 ____D C:\ProgramData\Oracle 2014-01-19 19:32 - 2014-01-19 19:30 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-19 19:32 - 2013-07-01 15:07 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-19 19:29 - 2014-01-19 19:28 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-01-19 19:29 - 2013-11-24 22:11 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-01-19 19:27 - 2013-11-24 22:09 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-01-19 19:27 - 2013-11-24 22:09 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-01-19 19:27 - 2013-11-24 22:09 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys 2014-01-19 19:27 - 2013-11-24 22:09 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-01-19 19:27 - 2013-11-24 22:09 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-19 19:27 - 2012-09-17 20:12 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-01-19 19:23 - 2012-11-08 18:24 - 00000000 ____D C:\Program Files (x86)\WinSCP 2014-01-19 19:22 - 2014-01-19 19:22 - 00000907 _____ C:\Users\Public\Desktop\WinSCP.lnk 2014-01-19 19:22 - 2013-05-08 19:58 - 00000000 ____D C:\Program Files\Java 2014-01-19 19:08 - 2014-01-19 19:08 - 05329480 _____ (Secunia) C:\Users\***\Downloads\PSISetup_3.0.0.9016.exe 2014-01-19 19:08 - 2014-01-19 19:08 - 00000000 ____D C:\Users\***\AppData\Local\Secunia PSI 2014-01-19 19:08 - 2014-01-19 19:08 - 00000000 ____D C:\Program Files (x86)\Secunia 2014-01-19 19:03 - 2014-01-19 19:01 - 00002418 _____ C:\DelFix.txt 2014-01-19 19:01 - 2014-01-19 19:01 - 00000000 ____D C:\Windows\ERUNT 2014-01-19 15:30 - 2014-01-19 15:30 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-19 15:29 - 2009-07-14 18:58 - 00696620 _____ C:\Windows\system32\perfh007.dat 2014-01-19 15:29 - 2009-07-14 18:58 - 00147916 _____ C:\Windows\system32\perfc007.dat 2014-01-19 15:29 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-19 15:01 - 2014-01-19 14:49 - 00000000 ____D C:\Users\***\Downloads\FRST-OlderVersion 2014-01-19 10:07 - 2009-07-14 05:45 - 00327664 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-19 01:04 - 2012-09-17 18:50 - 00072336 _____ C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-18 23:10 - 2013-04-29 18:33 - 00317440 ___SH C:\Users\***\Desktop\Thumbs.db 2014-01-18 22:08 - 2014-01-18 22:08 - 00000000 ____D C:\Users\***\Documents\Pinnacle VideoSpin 2014-01-18 22:01 - 2014-01-18 22:01 - 00000000 ____D C:\Users\***\AppData\Local\Downloaded Installations 2014-01-18 22:01 - 2014-01-18 22:01 - 00000000 ____D C:\ProgramData\Pinnacle 2014-01-18 21:56 - 2014-01-18 21:56 - 00000000 ____D C:\Users\***\Downloads\VideoSpin_2_0_Setup 2014-01-18 16:34 - 2014-01-18 16:34 - 00001195 _____ C:\Users\***\Desktop\Podcast - Verknüpfung.lnk 2014-01-17 17:28 - 2014-01-17 17:28 - 00000000 ____D C:\Users\***\AppData\Roaming\Unity 2014-01-17 17:27 - 2014-01-17 17:27 - 00000000 ____D C:\Users\***\AppData\Local\Unity 2014-01-16 18:05 - 2013-02-09 20:11 - 00001021 _____ C:\Users\***\Desktop\Dropbox.lnk 2014-01-16 18:05 - 2013-02-09 20:10 - 00000000 ____D C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 18:05 - 2012-09-17 18:19 - 00000000 ___RD C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-16 13:01 - 2013-03-16 18:17 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-01-16 13:01 - 2013-02-18 21:15 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-16 13:01 - 2013-02-18 21:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-16 00:13 - 2014-01-30 10:21 - 31421216 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 25255200 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 23672096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 17714760 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 12668192 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-01-16 00:13 - 2014-01-30 10:21 - 11631544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 11583616 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 09723944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 09686304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433467.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433467.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00859936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00483104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00408352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00378656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-01-16 00:13 - 2014-01-30 10:21 - 00024544 _____ C:\Windows\system32\nvinfo.pb 2014-01-16 00:13 - 2013-12-21 19:47 - 14668008 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-01-16 00:13 - 2013-03-20 15:55 - 15690744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-01-16 00:13 - 2013-02-26 00:32 - 18184976 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-01-16 00:13 - 2013-02-26 00:32 - 03087112 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-01-16 00:13 - 2013-02-26 00:32 - 02711656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-01-16 00:13 - 2013-02-26 00:32 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-01-16 00:13 - 2012-12-19 15:34 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-01-16 00:13 - 2012-12-19 15:34 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-01-15 23:35 - 2014-01-30 10:27 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-01-15 23:15 - 2014-01-15 23:15 - 00000000 ____D C:\projects 2014-01-15 22:53 - 2013-03-20 15:28 - 06712608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-01-15 22:53 - 2013-03-20 15:28 - 03498272 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-01-15 22:53 - 2013-03-20 15:28 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-01-15 22:53 - 2013-03-20 15:28 - 00923936 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-01-15 22:53 - 2013-03-20 15:28 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-01-15 22:53 - 2013-03-20 15:28 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-01-15 17:52 - 2014-01-15 17:52 - 00000000 ____D C:\ccc3a3a1e955984900e330689a 2014-01-15 17:52 - 2013-08-14 17:23 - 00000000 ____D C:\Windows\system32\MRT 2014-01-15 17:52 - 2009-10-14 06:12 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-13 23:31 - 2013-03-20 15:28 - 03559557 _____ C:\Windows\system32\nvcoproc.bin 2014-01-13 22:10 - 2014-01-13 22:10 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-13 22:10 - 2014-01-13 22:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-13 22:10 - 2013-12-20 13:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-13 22:08 - 2014-01-13 22:08 - 00283096 _____ (Mozilla) C:\Users\***\Downloads\Firefox Setup Stub 26.0.exe 2014-01-13 17:08 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2014-01-12 13:37 - 2013-04-07 20:09 - 00000000 ____D C:\Users\***\AppData\Roaming\Audacity 2014-01-12 13:29 - 2014-01-12 13:29 - 00000169 _____ C:\Windows\Cm108.ini.cfl 2014-01-12 13:29 - 2014-01-12 13:28 - 00000277 _____ C:\Windows\Cm108.ini.imi 2014-01-12 13:29 - 2013-12-21 21:16 - 00000133 _____ C:\Windows\system\Dlap.pfx 2014-01-12 13:29 - 2012-09-17 18:27 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2014-01-12 13:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system 2014-01-12 13:28 - 2014-01-12 13:28 - 00000226 _____ C:\Windows\system\Cm108.ini 2014-01-12 12:53 - 2012-09-17 18:27 - 00000000 ____D C:\Program Files (x86)\Realtek 2014-01-08 18:10 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-06 21:05 - 2013-12-21 14:35 - 00000000 ____D C:\Users\***\AppData\Local\DayZ 2014-01-06 20:59 - 2014-01-06 20:59 - 00000000 ____D C:\ProgramData\SystemRequirementsLab 2014-01-06 20:59 - 2013-01-26 15:30 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab Files to move or delete: ==================== C:\Users\Public\Minecraft Alpha Custom Installer(1).exe Some content of TEMP: ==================== C:\Users\***\AppData\Local\Temp\FlashPlayersetup__3873_i298670765_il155.exe C:\Users\***\AppData\Local\Temp\i4jdel0.exe C:\Users\***\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\***\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\***\AppData\Local\Temp\nvSCPAPI.dll C:\Users\***\AppData\Local\Temp\nvStereoApiI.dll C:\Users\***\AppData\Local\Temp\nvStInst.exe C:\Users\***\AppData\Local\Temp\sonarinst.exe C:\Users\***\AppData\Local\Temp\vlc-2.1.2-win32.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-30 17:49 ==================== End Of Log ============================ Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2014 01 Ran by *** at 2014-01-30 22:47:05 Running from C:\Users\***\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) Acrobat.com (x32 Version: 0.0.0 - Adobe Systems Incorporated) Hidden Acrobat.com (x32 Version: 1.1.377 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.6.0.6090 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.6.0.6090 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.43 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated) AIO_CDA_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden AIO_CDA_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden AIO_Scan (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden Any Video Converter 5.0.5 (x32 Version: - Any-Video-Converter.com) ASRock App Charger v1.0.5 (Version: - ASRock Inc.) ASRock InstantBoot v1.29 (x32 Version: - ) ASRock OC Tuner v2.4.47 (x32 Version: - ) Assassin's Creed(R) III v1.06 (x32 Version: 1.06 - Ubisoft) Audacity 2.0.3 (x32 Version: 2.0.3 - Audacity Team) avast! Free Antivirus (x32 Version: 9.0.2011 - Avast Software) Battle.net (x32 Version: - Blizzard Entertainment) Battlefield 1942™ (x32 Version: 1.6.20.0 - Electronic Arts) Battlefield 3™ (x32 Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (x32 Version: 2.3.2 - EA Digital Illusions CE AB) BattlEye (A2Free) Uninstall (x32 Version: - ) Blobby Volley 2 Version 1.0RC3 (x32 Version: - ) BlueJ (x32 Version: 3.0.8 - BlueJ Team) BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden Burnout Paradise: The Ultimate Box (x32 Version: - Criterion Games) C5100 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden c5100_Help (x32 Version: 82.0.256.000 - Hewlett-Packard) Hidden CCleaner (Version: 3.27 - Piriform) Cities in Motion 2 (x32 Version: - Colossal Order Ltd.) Command and Conquer: Red Alert 3 - Uprising (x32 Version: - EA Los Angeles) Convert AVI to MP4 1.3 (x32 Version: - convertavitomp3.com) Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Hidden Crysis 2 Maximum Edition (x32 Version: - Crytek Studios) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Darksiders (x32 Version: - Vigil Games) DarksidersInstaller (x32 Version: 1.00.1000 - Ihr Firmenname) DayZ (x32 Version: - Bohemia Interactive) Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden Die Sims™ 3 (x32 Version: 1.63.5 - Electronic Arts) DiRT Showdown (x32 Version: - Codemasters) DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.) ESET Online Scanner v3 (x32 Version: - ) ESN Sonar (x32 Version: 0.70.4 - ESN Social Software AB) Express Rip (x32 Version: - NCH Software) Facebook Video Calling 2.0.0.447 (x32 Version: 2.0.447 - Skype Limited) Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden Fraps (remove only) (x32 Version: - ) Free YouTube Download version 3.2.14.1022 (x32 Version: 3.2.14.1022 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.13.925 (x32 Version: 3.12.13.925 - DVDVideoSoft Ltd.) Game Dev Tycoon DEMO Version 1.0.1 (x32 Version: 1.0.1 - Greenheart Games Pty. Ltd.) Garry's Mod (x32 Version: - Garry) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Google Chrome (x32 Version: 32.0.1700.76 - Google Inc.) Google Earth Plug-in (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden Grand Theft Auto IV (x32 Version: - Rockstar North) Grand Theft Auto V - The Manual (x32 Version: 1.0.0 - Rockstar Games) Grand Theft Auto: Episodes from Liberty City (x32 Version: - Rockstar) Gyazo 2.0.1 (x32 Version: - Nota Inc. & Toshiyuki Masui) Hearthstone (x32 Version: - Blizzard Entertainment) HP Customer Participation Program 13.0 (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (Version: 13.0 - HP) HP Photosmart All-In-One Driver Software 13.0 Rel. A (Version: 13.0 - HP) HP Smart Web Printing 4.51 (Version: 4.51 - HP) HP Solution Center 13.0 (Version: 13.0 - HP) HP Update (x32 Version: 5.005.000.001 - Hewlett-Packard) HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden InfiniteCrisis_410193F41CAE (x32 Version: - Turbine, Inc) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java SE Development Kit 7 Update 21 (64-bit) (Version: 1.7.0.210 - Oracle) Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Just Cause 2 (x32 Version: - Avalanche) League of Legends (x32 Version: 1.3 - Riot Games) Left 4 Dead 2 (x32 Version: - Valve) LibreOffice 3.6 (x32 Version: 3.6.1.2 - The Document Foundation) LogMeIn Hamachi (x32 Version: 2.2.0.114 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.114 - LogMeIn, Inc.) Hidden Magicka (x32 Version: - Arrowhead Game Studios) MAGIX Foto & Grafik Designer 7 SE (Version: 7.1.2.26041 - MAGIX AG) Hidden MAGIX Foto & Grafik Designer 7 SE (x32 Version: 7.1.2.26041 - MAGIX AG) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Age of Empires II (x32 Version: - ) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE (x32 Version: 3.1.186.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation) MinecraftAlpha (x32 Version: - ) Mirror's Edge (x32 Version: - DICE) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation) Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden NVIDIA 3D Vision Controller-Treiber 334.67 (Version: 334.67 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 334.67 (Version: 334.67 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2 (Version: 1.8.2 - NVIDIA Corporation) NVIDIA Grafiktreiber 334.67 (Version: 334.67 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.145.1024 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3467 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 334.67 (Version: 334.67 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (Version: 1.2.20 - NVIDIA Corporation) OCR Software by I.R.I.S. 13.0 (Version: 13.0 - HP) OpenAL (x32 Version: - ) OpenOffice 4.0.1 (x32 Version: 4.01.9714 - Apache Software Foundation) Orcs Must Die! (x32 Version: - Robot Entertainment) Origin (x32 Version: 9.3.1.4482 - Electronic Arts, Inc.) Pando Media Booster (x32 Version: 2.6.0.8 - Pando Networks Inc.) Platform (x32 Version: 1.36 - VIA Technologies, Inc.) Hidden Populous (x32 Version: 1.0.0.0 - Electronic Arts) PunkBuster Services (x32 Version: 0.991 - Even Balance, Inc.) Rapture3D 2.4.11 Game (x32 Version: - Blue Ripple Sound) Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011 - Realtek) Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden Secunia PSI (3.0.0.9016) (x32 Version: 3.0.0.9016 - Secunia) SHIELD Streaming (Version: 1.7.306 - NVIDIA Corporation) Hidden Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden Speccy (Version: 1.24 - Piriform) Spotify (HKCU Version: 0.9.7.16.g4b197456 - Spotify AB) Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden Steam (x32 Version: 1.0.0.0 - Valve Corporation) System Requirements Lab CYRI (x32 Version: 6.0.8.0 - Husdawg, LLC) TeamSpeak 3 Client (HKCU Version: 3.0.13.1 - TeamSpeak Systems GmbH) Terraria (x32 Version: - Re-Logic) Time Gentlemen, Please! (x32 Version: - Size Five Games) Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden Torchlight II (x32 Version: - Runic Games) TrackMania² Stadium Open Beta (x32 Version: - ) TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden Unity Web Player (HKCU Version: - Unity Technologies ApS) UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Uplay (x32 Version: 2.1 - Ubisoft) USB PnP Sound Device (x32 Version: - ) Venetica (x32 Version: - dtp) VIA Plattform-Geräte-Manager (x32 Version: 1.36 - VIA Technologies, Inc.) VLC media player 2.1.2 (x32 Version: 2.1.2 - VideoLAN) WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows Driver Package - Texas Instruments Inc. (SilvrLnk) USB (06/11/2009 1.0.0.0) (Version: 06/11/2009 1.0.0.0 - Texas Instruments Inc.) Windows Driver Package - Texas Instruments Inc. (TIEHDUSB) USB (09/02/2009 1.0.0.1) (Version: 09/02/2009 1.0.0.1 - Texas Instruments Inc.) Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WinRAR 4.20 (64-bit) (Version: 4.20.0 - win.rar GmbH) WinSCP 5.1.6 (x32 Version: 5.1.6 - Martin Prikryl) World of Goo (x32 Version: - 2D BOY) ZoneAlarm Security Toolbar (x32 Version: 1.8.22.0 - Check Point Software Technologies LTD) Hidden ==================== Restore Points ========================= 23-01-2014 18:17:50 DirectX wurde installiert 24-01-2014 14:20:38 DirectX wurde installiert 28-01-2014 16:34:22 Windows Update 30-01-2014 09:23:03 Gerätetreiber-Paketinstallation: NVIDIA Grafikkarte 30-01-2014 09:26:31 Gerätetreiber-Paketinstallation: NVIDIA USB-Controller 30-01-2014 11:25:13 DirectX wurde installiert ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-02-18 17:11 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {66127B8E-DA2A-4019-9D12-C3C66163DD03} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3479666674-3888422604-2336058070-1000Core => C:\Users\***\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-12-25] (Facebook Inc.) Task: {6D07DEFD-96A0-4131-9195-71B53A752BF7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-24] (Google Inc.) Task: {7F1A54FA-B9F3-4026-970E-76E054B890EE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-16] (Adobe Systems Incorporated) Task: {84933449-E912-422C-8475-62F8A1C66A66} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3479666674-3888422604-2336058070-1000UA => C:\Users\***\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-12-25] (Facebook Inc.) Task: {C3CF9459-DEB8-4069-B7D7-2227AD06843E} - \DSite No Task File Task: {C9D94D34-8037-475A-9B0B-D8A63F327F1B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: {E557CE1E-ACA2-4435-BB32-55CDC96DEDA5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-24] (Google Inc.) Task: {FEC4792C-368B-433F-BDEA-0F52284D9B0D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-01-19] (AVAST Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3479666674-3888422604-2336058070-1000Core.job => C:\Users\***\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3479666674-3888422604-2336058070-1000UA.job => C:\Users\***\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-28 21:31 - 2014-01-28 17:44 - 02166272 _____ () C:\Program Files\AVAST Software\Avast\defs\14012801\algo.dll 2014-01-30 10:07 - 2014-01-30 08:54 - 02168320 _____ () C:\Program Files\AVAST Software\Avast\defs\14013000\algo.dll 2014-01-30 22:09 - 2014-01-30 17:52 - 02168320 _____ () C:\Program Files\AVAST Software\Avast\defs\14013001\algo.dll 2013-11-24 22:09 - 2013-11-24 22:09 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\***\AppData\Roaming\Dropbox\bin\libcef.dll 2013-11-16 13:40 - 2014-01-24 15:29 - 36967424 _____ () C:\Users\***\AppData\Roaming\Spotify\Data\libcef.dll 2013-11-16 13:40 - 2014-01-24 15:29 - 00887808 _____ () C:\Users\***\AppData\Roaming\Spotify\Data\libglesv2.dll 2013-11-16 13:40 - 2014-01-24 15:29 - 00109568 _____ () C:\Users\***\AppData\Roaming\Spotify\Data\libegl.dll 2014-01-13 22:10 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-01-16 13:01 - 2014-01-16 13:01 - 16287624 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Photosmart C5100 series Description: Photosmart C5100 series Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Photosmart C5100 series Description: Photosmart C5100 series Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: HP Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/30/2014 10:02:35 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (01/30/2014 09:20:39 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: LolClient.exe, Version: 0.0.0.0, Zeitstempel: 0x515663e0 Name des fehlerhaften Moduls: Adobe AIR.dll, Version: 3.7.0.1530, Zeitstempel: 0x5156646c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006dd76 ID des fehlerhaften Prozesses: 0xd28 Startzeit der fehlerhaften Anwendung: 0xLolClient.exe0 Pfad der fehlerhaften Anwendung: LolClient.exe1 Pfad des fehlerhaften Moduls: LolClient.exe2 Berichtskennung: LolClient.exe3 Error: (01/30/2014 08:44:28 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: LolClient.exe, Version: 0.0.0.0, Zeitstempel: 0x515663e0 Name des fehlerhaften Moduls: Adobe AIR.dll, Version: 3.7.0.1530, Zeitstempel: 0x5156646c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006dd76 ID des fehlerhaften Prozesses: 0x21c Startzeit der fehlerhaften Anwendung: 0xLolClient.exe0 Pfad der fehlerhaften Anwendung: LolClient.exe1 Pfad des fehlerhaften Moduls: LolClient.exe2 Berichtskennung: LolClient.exe3 Error: (01/30/2014 08:42:40 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: LolClient.exe, Version: 0.0.0.0, Zeitstempel: 0x515663e0 Name des fehlerhaften Moduls: Adobe AIR.dll, Version: 3.7.0.1530, Zeitstempel: 0x5156646c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006dd76 ID des fehlerhaften Prozesses: 0x1790 Startzeit der fehlerhaften Anwendung: 0xLolClient.exe0 Pfad der fehlerhaften Anwendung: LolClient.exe1 Pfad des fehlerhaften Moduls: LolClient.exe2 Berichtskennung: LolClient.exe3 Error: (01/30/2014 08:23:19 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: LolClient.exe, Version: 0.0.0.0, Zeitstempel: 0x515663e0 Name des fehlerhaften Moduls: Adobe AIR.dll, Version: 3.7.0.1530, Zeitstempel: 0x5156646c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006dd76 ID des fehlerhaften Prozesses: 0x1580 Startzeit der fehlerhaften Anwendung: 0xLolClient.exe0 Pfad der fehlerhaften Anwendung: LolClient.exe1 Pfad des fehlerhaften Moduls: LolClient.exe2 Berichtskennung: LolClient.exe3 Error: (01/30/2014 07:14:05 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (01/30/2014 06:52:58 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (01/30/2014 10:35:41 AM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (01/28/2014 07:24:26 PM) (Source: NVNetworkService) (User: ) Description: NVNetworkServiceྨ*罐Çection write error system:10054 in src\RPC\Connection.cpp:160 Error: (01/28/2014 07:12:03 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall System errors: ============= Error: (01/30/2014 09:39:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (01/30/2014 09:39:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (01/30/2014 09:39:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (01/30/2014 09:39:31 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Error: (01/30/2014 09:39:31 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (01/30/2014 09:39:31 PM) (Source: PNRPSvc) (User: ) Description: 0x80630801 Error: (01/30/2014 07:14:04 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/30/2014 07:14:04 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (01/30/2014 05:23:26 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peernetzwerk-Gruppenzuordnung" ist vom Dienst "Peer Name Resolution-Protokoll" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%-2140993535 Error: (01/30/2014 05:23:26 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Peer Name Resolution-Protokoll" wurde mit folgendem Fehler beendet: %%-2140993535 Microsoft Office Sessions: ========================= Error: (01/30/2014 10:02:35 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (01/30/2014 09:20:39 PM) (Source: Application Error)(User: ) Description: LolClient.exe0.0.0.0515663e0Adobe AIR.dll3.7.0.15305156646cc00000050006dd76d2801cf1df86b141a7eC:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\LolClient.exeC:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\Adobe AIR\Versions\1.0\Adobe AIR.dllfb788a38-89eb-11e3-908c-bc5ff42ad298 Error: (01/30/2014 08:44:28 PM) (Source: Application Error)(User: ) Description: LolClient.exe0.0.0.0515663e0Adobe AIR.dll3.7.0.15305156646cc00000050006dd7621c01cf1df3801d8407C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\LolClient.exeC:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\Adobe AIR\Versions\1.0\Adobe AIR.dlledbc6189-89e6-11e3-908c-bc5ff42ad298 Error: (01/30/2014 08:42:40 PM) (Source: Application Error)(User: ) Description: LolClient.exe0.0.0.0515663e0Adobe AIR.dll3.7.0.15305156646cc00000050006dd76179001cf1df0e0846e74C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\LolClient.exeC:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\Adobe AIR\Versions\1.0\Adobe AIR.dllada1128c-89e6-11e3-908c-bc5ff42ad298 Error: (01/30/2014 08:23:19 PM) (Source: Application Error)(User: ) Description: LolClient.exe0.0.0.0515663e0Adobe AIR.dll3.7.0.15305156646cc00000050006dd76158001cf1dd734e15159C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\LolClient.exeC:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\Adobe AIR\Versions\1.0\Adobe AIR.dllf93861e7-89e3-11e3-908c-bc5ff42ad298 Error: (01/30/2014 07:14:05 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (01/30/2014 06:52:58 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (01/30/2014 10:35:41 AM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (01/28/2014 07:24:26 PM) (Source: NVNetworkService)(User: ) Description: NVNetworkServiceྨ*罐Çection write error system:10054 in src\RPC\Connection.cpp:160 Error: (01/28/2014 07:12:03 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall CodeIntegrity Errors: =================================== Date: 2014-01-30 10:06:28.029 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-30 10:06:27.873 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-28 17:29:25.236 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-28 17:29:25.080 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-27 18:41:59.875 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-27 18:41:59.719 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-27 14:26:12.639 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-27 14:26:12.483 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-26 19:43:10.074 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-01-26 19:43:09.918 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\XHCDRV.SYS" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 35% Total physical RAM: 8191.24 MB Available physical RAM: 5242.79 MB Total Pagefile: 16380.66 MB Available Pagefile: 13247.41 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:649.42 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: DD4DDD4D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
31.01.2014, 16:54 | #4 |
/// the machine /// TB-Ausbilder | Malwarebytes Suchlauf 2 infizierte Objekte Da is nix, Fnde von MBAM einfach mit MBAM löschen und gut
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.01.2014, 19:23 | #5 |
| Malwarebytes Suchlauf 2 infizierte Objekte Ok, Dankeschön |
01.02.2014, 17:19 | #6 |
/// the machine /// TB-Ausbilder | Malwarebytes Suchlauf 2 infizierte Objekte Gern Geschehen
__________________ --> Malwarebytes Suchlauf 2 infizierte Objekte |
Themen zu Malwarebytes Suchlauf 2 infizierte Objekte |
administrator, aktion, anti-malware, appdata, autostart, bösartige, code, dateien, downloads, explorer, gen, infizierte, local, malwarebytes, minute, objekt, registrierung, schnell, schonmal, service, speicher, temp, users, version, verzeichnisse |