|
Plagegeister aller Art und deren Bekämpfung: Eset erkenntvirus, kann ihn nicht löschenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
04.03.2014, 22:12 | #16 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Eset erkenntvirus, kann ihn nicht löschen Machen wir einfach mal weiter: Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ Logfiles bitte immer in CODE-Tags posten |
05.03.2014, 17:01 | #17 |
| Eset erkenntvirus, kann ihn nicht löschen Es wurde keine Malware gefunden und ich musste den PC nicht neu starten:
__________________Code:
ATTFilter --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.07.0.1009 (c) Malwarebytes Corporation 2011-2012 OS version: 6.2.9200 Windows 8 x64 Account is Administrative Internet Explorer version: 11.0.9600.16518 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 1.696000 GHz Memory total: 8476971008, free: 4692475904 --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.07.0.1009 (c) Malwarebytes Corporation 2011-2012 OS version: 6.2.9200 Windows 8 x64 Account is Administrative Internet Explorer version: 11.0.9600.16518 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 1.696000 GHz Memory total: 8476971008, free: 4732678144 Downloaded database version: v2014.03.05.07 Downloaded database version: v2014.02.20.01 ======================================= Initializing... ------------ Kernel report ------------ 03/05/2014 16:41:09 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\iaStorAV.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\system32\drivers\WdFilter.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\DRIVERS\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\hpdskflt.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\system32\DRIVERS\nvpciflt.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\avkmgr.sys \SystemRoot\system32\DRIVERS\avipbb.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\CmBatt.sys \SystemRoot\System32\drivers\BATTC.SYS \SystemRoot\system32\DRIVERS\nvlddmkm.sys \SystemRoot\system32\DRIVERS\igdkmd64.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\System32\drivers\ucx01000.sys \SystemRoot\System32\drivers\HECIx64.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\athwbx.sys \SystemRoot\System32\drivers\vwifibus.sys \SystemRoot\system32\DRIVERS\Rt630x64.sys \SystemRoot\system32\DRIVERS\RtsP2Stor.sys \SystemRoot\System32\drivers\i8042prt.sys \SystemRoot\system32\DRIVERS\SynTP.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys \SystemRoot\system32\DRIVERS\Accelerometer.sys \SystemRoot\System32\drivers\WirelessButtonDriver64.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\intelppm.sys \SystemRoot\System32\drivers\irstrtdv.sys \SystemRoot\system32\drivers\nvvad64v.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\iwdbus.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\stwrt64.sys \SystemRoot\system32\DRIVERS\IntcDAud.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_iaStorAV.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\Drivers\usbvideo.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\DRIVERS\avgntflt.sys \??\C:\WINDOWS\system32\drivers\mbam.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\DRIVERS\vwifimp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\Drivers\WdNisDrv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\System32\cdd.dll \SystemRoot\System32\drivers\monitor.sys \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys ----------- End ----------- Done! <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xffffe00007cd0060 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\00000030\ Lower Device Object: 0xffffe00001006060 Lower Device Driver Name: \Driver\iaStorAV\ <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffe00007cd21d0 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\0000002f\ Lower Device Object: 0xffffe00001008060 Lower Device Driver Name: \Driver\iaStorAV\ <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffe00007cd21d0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ --------- Disk Stack ------ DevicePointer: 0xffffe00007cd1040, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffe00007cd21d0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ DevicePointer: 0xffffe00007cd3430, DeviceName: Unknown, DriverName: \Driver\hpdskflt\ DevicePointer: 0xffffe00001008060, DeviceName: \Device\0000002f\, DriverName: \Driver\iaStorAV\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Read File: File "C:\Windows\System32\drivers\1394ohci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\1394ohci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpipagr.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpipagr.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpipmi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpipmi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\acpitime.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\acpitime.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\AGP440.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\AGP440.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\amdk8.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\amdk8.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\amdppm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\amdppm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\atapi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\atapi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\ataport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\ataport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BasicDisplay.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BasicDisplay.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\battc.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\battc.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BtaMPM.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BtaMPM.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BthAvrcpTg.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BthAvrcpTg.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\bthhfenum.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\bthhfenum.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BthhfHid.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BthhfHid.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\bthmodem.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\bthmodem.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\cdrom.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\cdrom.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\circlass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\circlass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\CmBatt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\CmBatt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\CompositeBus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\CompositeBus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\disk.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\disk.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\drmk.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\drmk.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\drmkaud.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\drmkaud.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\dumpsd.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\dumpsd.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\EhStorTcgDrv.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\errdev.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\errdev.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\fdc.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\fdc.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\flpydisk.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\flpydisk.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\fxppm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\fxppm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hdaudbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hdaudbus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidbatt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidbatt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidbth.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidbth.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidclass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidclass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidi2c.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidi2c.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidparse.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidparse.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\hidusb.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\hidusb.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\i8042prt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\i8042prt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\intelpep.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\intelpep.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\intelppm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\intelppm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\isapnp.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\isapnp.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\kbdclass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\kbdclass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\kbdhid.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\kbdhid.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\kdnic.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\kdnic.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\monitor.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\monitor.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\mouclass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\mouclass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\mouhid.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\mouhid.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\mssmbios.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\mssmbios.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\MTConfig.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\MTConfig.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\npsvctrig.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\npsvctrig.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\BasicRender.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\BasicRender.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sbp2port.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sbp2port.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbuhci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbuhci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\parport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\parport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pciide.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pciide.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pciidex.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pciidex.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\pcmcia.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\pcmcia.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\portcls.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\portcls.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\processr.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\processr.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sdbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sdbus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sdstor.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sdstor.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\serenum.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\serenum.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\serial.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\serial.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sermouse.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sermouse.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\sfloppy.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\sfloppy.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\spaceport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\spaceport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\stornvme.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\stornvme.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\swenum.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\swenum.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\terminpt.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\terminpt.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\tpm.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\tpm.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\TsUsbGD.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\TsUsbGD.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\uaspstor.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\uaspstor.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\UCX01000.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\UCX01000.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\uefi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\uefi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\umbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\umbus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\umpass.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\umpass.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbccgp.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbccgp.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbcir.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbcir.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbd.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbd.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbehci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbehci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbhub.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbhub.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\USBHUB3.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\USBHUB3.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbohci.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbohci.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbport.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbport.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbprint.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbprint.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\USBSTOR.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\USBSTOR.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\usbvideo.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\usbvideo.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\USBXHCI.SYS" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\USBXHCI.SYS" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\vdrvroot.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\vdrvroot.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\vhdmp.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\vhdmp.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\volmgr.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\volmgr.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\volsnap.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\volsnap.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\vwifibus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\vwifibus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\wacompen.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\wacompen.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\wmiacpi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\wmiacpi.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\WSDPrint.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\WSDPrint.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\rdpbus.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\rdpbus.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\msgpiowin32.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\msgpiowin32.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\msisadrv.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\msisadrv.sys" is compressed (flags = 1) Read File: File "C:\Windows\System32\drivers\msiscsi.sys" is compressed (flags = 1) Read File: File "C:\WINDOWS\SYSTEM32\drivers\msiscsi.sys" is compressed (flags = 1) Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: This drive is a GPT Drive. MBR Signature: 55AA Disk Signature: 466E2C46 GPT Protective MBR Partition information: Partition 0 type is EFI-GPT (0xee) Partition is NOT ACTIVE. Partition starts at LBA: 1 Numsec = 1465143295 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 GPT Partition information: GPT Header Signature 4546492050415254 GPT Header Revision 65536 Size 92 CRC 3567185626 GPT Header CurrentLba = 1 BackupLba 1465143295 GPT Header FirstUsableLba 34 LastUsableLba 1465143262 GPT Header Guid 317345b4-24f6-4503-a37-218221b6849 GPT Header Contains 128 partition entries starting at LBA 2 GPT Header Partition entry size = 128 Backup GPT header Signature 4546492050415254 Backup GPT header Revision 65536 Size 92 CRC 3567185626 Backup GPT header CurrentLba = 1465143295 BackupLba 1 Backup GPT header FirstUsableLba 34 LastUsableLba 1465143262 Backup GPT header Guid 317345b4-24f6-4503-a37-218221b6849 Backup GPT header Contains 128 partition entries starting at LBA 1465143263 Backup GPT header Partition entry size = 128 Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac Partition ID 8d113c7b-f47a-4a1d-9274-be864bc78b4c FirstLBA 2048 Last LBA 821247 Attributes 1 Partition Name Basic data partition Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b Partition ID 1c299df3-d74-4fc3-a07-2ef04e80a6 FirstLBA 821248 Last LBA 1353727 Attributes 0 Partition Name EFI system partition GPT Partition 1 is bootable Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae Partition ID 94216cd5-c051-4948-a4b3-8366e21922e FirstLBA 1353728 Last LBA 1615871 Attributes 0 Partition Name Microsoft reserved partition Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7 Partition ID 90d7f888-ed67-44ff-97e3-c5fa35a241c3 FirstLBA 1615872 Last LBA 1429886975 Attributes 0 Partition Name Basic data partition Partition 4 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac Partition ID 510e416-9a8f-499b-af2-dcc6efe4c5f8 FirstLBA 1429886976 Last LBA 1430603775 Attributes 1 Partition Name Partition 5 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7 Partition ID f0e4a537-f888-4f10-a158-dcf724c77bc1 FirstLBA 1430603776 Last LBA 1465141247 Attributes 1 Partition Name Basic data partition Disk Size: 750153367552 bytes Sector size: 512 bytes Done! Physical Sector Size: 512 Drive: 1, DevicePointer: 0xffffe00007cd0060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ --------- Disk Stack ------ DevicePointer: 0xffffe00007cd0b20, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffe00007cd0060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ DevicePointer: 0xffffe00007cd17a0, DeviceName: Unknown, DriverName: \Driver\hpdskflt\ DevicePointer: 0xffffe00001006060, DeviceName: \Device\00000030\, DriverName: \Driver\iaStorAV\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 1 Scanning MBR on drive 1... Inspecting partition table: This drive is a GPT Drive. MBR Signature: 55AA Disk Signature: 80487483 GPT Protective MBR Partition information: Partition 0 type is EFI-GPT (0xee) Partition is NOT ACTIVE. Partition starts at LBA: 1 Numsec = 4294967295 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 GPT Partition information: GPT Header Signature 4546492050415254 GPT Header Revision 65536 Size 92 CRC 1070483260 GPT Header CurrentLba = 1 BackupLba 16777215 GPT Header FirstUsableLba 34 LastUsableLba 16777182 GPT Header Guid a5a7edc2-3c3d-411d-825f-50c9494918f GPT Header Contains 128 partition entries starting at LBA 2 GPT Header Partition entry size = 128 Backup GPT header Signature 4546492050415254 Backup GPT header Revision 65536 Size 92 CRC 1070483260 Backup GPT header CurrentLba = 16777215 BackupLba 1 Backup GPT header FirstUsableLba 34 LastUsableLba 16777182 Backup GPT header Guid a5a7edc2-3c3d-411d-825f-50c9494918f Backup GPT header Contains 128 partition entries starting at LBA 16777183 Backup GPT header Partition entry size = 128 Partition 0 Type d3bfe2de-3daf-11df-ba40-e3a556d89593 Partition ID 4bc152b-9bfb-40d4-ab1a-288d21abc4b FirstLBA 2048 Last LBA 16775167 Attributes 0 Partition Name Basic data partition Disk Size: 8589934592 bytes Sector size: 512 bytes Done! Scan finished ======================================= Removal queue found; removal started Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam... Removal finished |
05.03.2014, 17:04 | #18 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Eset erkenntvirus, kann ihn nicht löschen Falsches Log, bitte das richtige von MBAR posten
__________________
__________________ |
10.03.2014, 20:26 | #19 |
| Eset erkenntvirus, kann ihn nicht löschen sicher? aber das muss es sein! Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1009 www.malwarebytes.org Database version: v2014.03.05.07 Windows 8 x64 NTFS Internet Explorer 11.0.9600.16518 Maxi :: MAXI-PC [administrator] 05.03.2014 16:41:15 mbar-log-2014-03-05 (16-41-15).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 248488 Time elapsed: 15 minute(s), 47 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
11.03.2014, 11:07 | #20 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Eset erkenntvirus, kann ihn nicht löschen Das war richtig Adware/Junkware/Toolbars entfernen (alle Tools bitte neu runterladen!) 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
21.03.2014, 12:32 | #21 |
| Eset erkenntvirus, kann ihn nicht löschen sry das ich mich erst jetzt melden kann ! AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.022 - Bericht erstellt am 21/03/2014 um 12:21:27 # Aktualisiert 13/03/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Maxi - MAXI-PC # Gestartet von : C:\Users\Maxi\Downloads\adwcleaner(1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Maxi\AppData\Roaming\Mozilla\Firefox\Profiles\luuqw9uu.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [2386 octets] - [19/02/2014 13:31:59] AdwCleaner[R1].txt - [975 octets] - [01/03/2014 21:33:14] AdwCleaner[R2].txt - [1133 octets] - [21/03/2014 12:20:06] AdwCleaner[S0].txt - [2153 octets] - [19/02/2014 13:33:02] AdwCleaner[S1].txt - [1035 octets] - [01/03/2014 21:33:56] AdwCleaner[S2].txt - [1055 octets] - [21/03/2014 12:21:27] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1115 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.2 (02.20.2014:1) OS: Windows 8.1 x64 Ran by Maxi on 21.03.2014 at 12:25:47,56 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Maxi\appdata\local\{04D50E99-A09A-4E50-A23D-7F44830ED676} Successfully deleted: [Empty Folder] C:\Users\Maxi\appdata\local\{22D099F0-8190-4ECB-AFFA-33F3B3A77B12} Successfully deleted: [Empty Folder] C:\Users\Maxi\appdata\local\{2D5611B9-A2C1-4FE7-BEA8-64A805B5E3C1} Successfully deleted: [Empty Folder] C:\Users\Maxi\appdata\local\{41A1A794-804B-4206-9055-7F501E4C96ED} Successfully deleted: [Empty Folder] C:\Users\Maxi\appdata\local\{705338A4-5B28-4AD4-972C-DB8A9156E2EA} Successfully deleted: [Empty Folder] C:\Users\Maxi\appdata\local\{7AABC1AA-46BA-4276-8C25-FDCD61FDE8E3} Successfully deleted: [Empty Folder] C:\Users\Maxi\appdata\local\{F5414834-AB5A-45A9-9CE1-1109BAB41AC2} ~~~ FireFox Emptied folder: C:\Users\Maxi\AppData\Roaming\mozilla\firefox\profiles\luuqw9uu.default\minidumps [15 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.03.2014 at 12:29:41,87 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
21.03.2014, 12:32 | #22 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Eset erkenntvirus, kann ihn nicht löschen Fehlt noch FRST. Denk bitte daran den Haken bei additions zu setzen
__________________ Logfiles bitte immer in CODE-Tags posten |
21.03.2014, 12:36 | #23 |
| Eset erkenntvirus, kann ihn nicht löschen FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Maxi (administrator) on MAXI-PC on 21-03-2014 12:32:51 Running from C:\Users\Maxi\Downloads Windows 8.1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard Company) C:\WINDOWS\system32\Hpservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Microsoft Corporation) C:\WINDOWS\system32\dashost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\WINDOWS\SysWOW64\PnkBstrA.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Spotify Ltd) C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Farbar) C:\Users\Maxi\Downloads\FRST64(2).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2014-01-20] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3030256 2014-01-30] (Synaptics Incorporated) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\WINDOWS\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-03-12] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1804472024-3847440819-3875843136-1002\...\Run: [Spotify Web Helper] - C:\Users\Maxi\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-21] (Spotify Ltd) HKU\S-1-5-21-1804472024-3847440819-3875843136-1002\...\Run: [Akamai NetSession Interface] - "C:\Users\Maxi\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-1804472024-3847440819-3875843136-1002\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1821888 2014-02-25] (Valve Corporation) HKU\S-1-5-21-1804472024-3847440819-3875843136-1002\...\Run: [EPLTarget\P0000000000000000] - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE [283232 2012-10-01] (SEIKO EPSON CORPORATION) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKLM - {A28F0689-CA9E-46FF-ACB3-73BF34D4AC4B} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Maxi\AppData\Roaming\Mozilla\Firefox\Profiles\luuqw9uu.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Maxi\AppData\Roaming\Mozilla\Firefox\Profiles\luuqw9uu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-05] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR Extension: (Google Docs) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-20] CHR Extension: (Google Drive) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-20] CHR Extension: (YouTube) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-20] CHR Extension: (Google-Suche) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-20] CHR Extension: (Google Wallet) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-20] CHR Extension: (Google Mail) - C:\Users\Maxi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-20] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-02-20] () R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2169016 2014-03-01] (Microsoft Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131032 2014-01-20] (Intel Corporation) R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193576 2012-07-20] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2014-01-20] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2014-03-07] () R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2013-11-22] (Razer Inc.) S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-01-30] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3858944 2013-10-17] (Qualcomm Atheros Communications, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) R0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-01-30] (Microsoft Corporation) R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [43800 2012-07-21] (Intel Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-03] (Realtek Semiconductor Corp.) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-01-30] (Microsoft Corporation) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-01-30] (Synaptics Incorporated) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-06-27] (Hewlett-Packard Development Company, L.P.) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2013-08-22] (Microsoft Corporation) S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-21 12:32 - 2014-03-21 12:32 - 02157056 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64(2).exe 2014-03-21 12:29 - 2014-03-21 12:29 - 00001481 _____ () C:\Users\Maxi\Desktop\JRT.txt 2014-03-21 12:25 - 2014-02-20 07:33 - 01037734 _____ (Thisisu) C:\Users\Maxi\Desktop\JRT_NEW.exe 2014-03-21 12:24 - 2014-03-21 12:24 - 01037734 _____ (Thisisu) C:\Users\Maxi\Downloads\JRT(1).exe 2014-03-21 12:19 - 2014-03-21 12:19 - 01950720 _____ () C:\Users\Maxi\Downloads\adwcleaner(1).exe 2014-03-18 20:26 - 2014-03-18 20:27 - 113634215 _____ () C:\Users\Maxi\Documents\Whatdoesthafpxsay.wmv 2014-03-18 16:52 - 2014-01-08 02:46 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2014-03-18 16:52 - 2014-01-08 02:41 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2014-03-18 16:52 - 2014-01-08 02:41 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2014-03-18 16:52 - 2014-01-04 16:54 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll 2014-03-18 16:52 - 2014-01-04 16:08 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll 2014-03-18 16:52 - 2014-01-04 15:08 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll 2014-03-18 16:52 - 2014-01-04 14:53 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll 2014-03-18 16:52 - 2014-01-03 00:54 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll 2014-03-18 16:52 - 2014-01-03 00:48 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll 2014-03-18 16:52 - 2014-01-01 02:55 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2014-03-18 16:52 - 2014-01-01 02:52 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2014-03-18 16:52 - 2014-01-01 01:56 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2014-03-18 16:52 - 2014-01-01 01:55 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2014-03-18 16:52 - 2014-01-01 00:59 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2014-03-18 16:52 - 2014-01-01 00:57 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2014-03-18 16:52 - 2014-01-01 00:56 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2014-03-18 16:52 - 2013-12-31 00:34 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll 2014-03-18 16:52 - 2013-12-31 00:33 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll 2014-03-18 16:52 - 2013-12-31 00:32 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll 2014-03-18 16:52 - 2013-12-31 00:31 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2014-03-18 16:52 - 2013-12-31 00:31 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 2014-03-18 16:52 - 2013-12-27 16:09 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2014-03-18 16:52 - 2013-12-27 09:57 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2014-03-18 16:52 - 2013-12-27 09:57 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2014-03-18 16:52 - 2013-12-27 09:23 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2014-03-18 16:52 - 2013-12-27 08:03 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2014-03-18 16:52 - 2013-12-27 08:03 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2014-03-18 16:52 - 2013-12-27 07:37 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2014-03-18 16:52 - 2013-12-21 08:21 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll 2014-03-18 16:52 - 2013-12-17 08:21 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2014-03-18 16:52 - 2013-12-14 07:31 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-03-18 16:52 - 2013-12-14 07:19 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2014-03-18 16:52 - 2013-12-13 11:54 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe 2014-03-18 16:52 - 2013-12-13 07:36 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll 2014-03-18 16:52 - 2013-12-13 06:32 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll 2014-03-18 16:52 - 2013-12-09 09:05 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2014-03-18 16:52 - 2013-12-09 05:51 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2014-03-17 15:41 - 2014-02-22 13:16 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2014-03-17 15:41 - 2014-02-22 12:24 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2014-03-16 15:32 - 2014-03-16 15:55 - 1513047790 _____ () C:\Users\Maxi\Documents\Rennen 1.wmv 2014-03-16 14:19 - 2014-03-16 14:21 - 182109657 _____ () C:\Users\Maxi\Documents\Kanal Trailer.wmv 2014-03-15 13:10 - 2014-03-20 15:43 - 00000000 ____D () C:\Users\Maxi\Documents\NFS SHIFT 2014-03-15 13:04 - 2014-03-15 13:04 - 00000000 ____D () C:\Users\Public\Documents\SHIFT 2 UNLEASHED 2014-03-15 12:50 - 2014-03-15 12:54 - 00000000 ____D () C:\Users\Maxi\Documents\SHIFT 2 UNLEASHED 2014-03-15 12:50 - 2014-03-15 12:50 - 00000000 ____D () C:\ProgramData\Solidshield 2014-03-14 20:47 - 2014-03-14 20:47 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\2K Sports 2014-03-14 18:34 - 2014-03-14 18:34 - 00000000 ____D () C:\Users\Maxi\Documents\CAPCOM 2014-03-14 12:37 - 2014-03-14 12:37 - 00000000 ____D () C:\ProgramData\Codemasters 2014-03-13 20:46 - 2014-03-13 20:46 - 03821624 _____ () C:\Users\Maxi\Downloads\battlelog-web-plugins_2.3.2_131(2).exe 2014-03-13 20:44 - 2014-03-13 20:44 - 03821624 _____ () C:\Users\Maxi\Downloads\battlelog-web-plugins_2.3.2_131(1).exe 2014-03-13 20:43 - 2014-03-13 20:44 - 03821624 _____ () C:\Users\Maxi\Downloads\battlelog-web-plugins_2.3.2_131.exe 2014-03-13 15:49 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-03-13 15:49 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-03-13 15:49 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-03-13 15:49 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-03-13 15:49 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-03-13 15:49 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-03-13 15:49 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-03-13 15:49 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-03-13 15:49 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-03-13 15:49 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-03-13 15:49 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-03-13 15:49 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-03-13 15:49 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-03-13 15:49 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-03-13 15:49 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-03-13 15:49 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-03-13 15:49 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-03-13 15:49 - 2013-12-20 11:18 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2014-03-13 15:49 - 2013-12-20 11:18 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2014-03-13 15:48 - 2014-02-11 04:04 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-03-13 15:48 - 2014-02-11 03:43 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-03-13 15:48 - 2014-02-11 03:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-03-13 15:48 - 2014-01-31 17:15 - 00311640 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys 2014-03-13 15:48 - 2014-01-31 17:07 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2014-03-13 15:48 - 2014-01-31 17:06 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2014-03-13 15:48 - 2014-01-31 14:47 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2014-03-13 15:48 - 2014-01-31 10:06 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll 2014-03-13 15:48 - 2014-01-29 10:55 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2014-03-13 15:48 - 2014-01-29 09:53 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2014-03-13 15:48 - 2014-01-29 09:53 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2014-03-13 15:48 - 2014-01-29 09:49 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2014-03-13 15:48 - 2014-01-29 09:47 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2014-03-13 15:48 - 2014-01-29 08:44 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2014-03-13 15:48 - 2014-01-29 08:44 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2014-03-13 15:48 - 2014-01-29 08:44 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2014-03-13 15:48 - 2014-01-29 07:41 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll 2014-03-13 15:48 - 2014-01-29 01:36 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 2014-03-13 15:48 - 2014-01-27 20:07 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll Code:
ATTFilter 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2014-03-13 15:48 - 2014-01-27 20:04 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE 2014-03-13 15:48 - 2014-01-27 19:52 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2014-03-13 15:48 - 2014-01-27 19:23 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2014-03-13 15:48 - 2014-01-27 19:21 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2014-03-13 15:48 - 2014-01-27 19:20 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE 2014-03-13 15:48 - 2014-01-27 19:15 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll 2014-03-13 15:48 - 2014-01-27 18:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll 2014-03-13 15:48 - 2014-01-27 18:18 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2014-03-13 15:48 - 2014-01-27 18:00 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2014-03-13 15:48 - 2014-01-27 16:58 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2014-03-13 15:48 - 2014-01-27 16:50 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2014-03-13 15:48 - 2014-01-27 12:45 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2014-03-13 15:48 - 2014-01-18 00:04 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2014-03-13 15:48 - 2014-01-17 22:54 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2014-03-13 15:48 - 2013-12-21 15:51 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2014-03-13 15:48 - 2013-12-21 09:54 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll 2014-03-13 15:48 - 2013-10-31 01:29 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys 2014-03-13 15:48 - 2013-10-31 01:29 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys 2014-03-13 15:48 - 2013-10-31 01:28 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys 2014-03-10 19:19 - 2014-03-10 19:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA 2014-03-09 18:33 - 2014-03-09 18:33 - 00000000 ____D () C:\Users\Maxi\Documents\Criterion Games 2014-03-07 17:10 - 2014-03-07 17:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls 2014-03-06 18:02 - 2014-03-17 18:00 - 00003156 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForMaxi 2014-03-06 18:02 - 2014-03-17 18:00 - 00000344 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForMaxi.job 2014-03-05 17:45 - 2008-07-12 08:18 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll 2014-03-05 17:45 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll 2014-03-05 17:45 - 2008-07-12 08:18 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll 2014-03-05 17:45 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll 2014-03-05 17:44 - 2008-07-12 08:18 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll 2014-03-05 17:44 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll 2014-03-05 16:41 - 2014-03-05 16:59 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-03-05 16:40 - 2014-03-05 16:59 - 00000000 ____D () C:\Users\Maxi\Desktop\mbar 2014-03-05 16:40 - 2014-03-05 16:40 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-03-05 16:21 - 2014-03-05 16:21 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Maxi\Downloads\mbar-1.07.0.1009.exe 2014-03-05 15:49 - 2014-03-05 15:49 - 20157440 _____ () C:\Users\Maxi\Downloads\PhysX-9.12.1031-SystemSoftware-Legacy.msi 2014-03-05 15:44 - 2014-03-05 15:44 - 00000000 ____D () C:\Users\Maxi\Documents\EA Games 2014-03-05 15:33 - 2014-03-05 15:46 - 00794408 _____ () C:\WINDOWS\SysWOW64\Pbsvc.exe 2014-03-04 22:05 - 2014-03-21 12:05 - 00003922 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E600782D-3A41-4E0D-9D1C-133B88519F03} 2014-03-04 21:03 - 2014-03-04 21:03 - 02156544 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64(1).exe 2014-03-03 18:31 - 2014-03-03 18:31 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Skyrim 2014-03-03 16:59 - 2014-03-03 17:18 - 00000000 ____D () C:\Users\Maxi\Documents\COD Compelation 2014-03-02 16:03 - 2014-03-02 16:03 - 00000000 ____D () C:\Users\Maxi\Documents\My WoZ Animals 2014-03-01 21:54 - 2014-03-01 21:54 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Macromedia 2014-03-01 21:52 - 2014-03-01 21:52 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\Mozilla 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Mozilla 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\ProgramData\Mozilla 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-01 21:51 - 2014-03-01 21:51 - 00283256 _____ (Mozilla) C:\Users\Maxi\Downloads\Firefox Setup Stub 27.0.1.exe 2014-03-01 21:38 - 2014-03-01 21:39 - 02155520 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64 (1).exe 2014-03-01 21:32 - 2014-03-01 21:32 - 01244192 _____ () C:\Users\Maxi\Downloads\adwcleaner (1).exe 2014-03-01 09:49 - 2014-03-01 20:30 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Windows Live 2014-02-28 16:40 - 2014-03-05 17:45 - 00000000 ____D () C:\Users\Maxi\Documents\BioWare 2014-02-27 18:15 - 2014-01-19 08:38 - 00270496 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2014-02-27 18:12 - 2014-03-16 13:44 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Arma 3 2014-02-27 18:12 - 2014-02-27 18:13 - 00000000 ____D () C:\Users\Maxi\Documents\Arma 3 2014-02-27 18:12 - 2014-02-27 18:12 - 00000000 ____D () C:\ProgramData\Bohemia Interactive 2014-02-27 15:47 - 2014-02-27 15:47 - 00000000 ____D () C:\ProgramData\EPSON 2014-02-27 15:47 - 2014-02-27 15:47 - 00000000 ____D () C:\Program Files\Common Files\EPSON 2014-02-27 15:47 - 2012-10-01 03:42 - 00120320 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_ILMJCE.DLL 2014-02-27 15:47 - 2012-10-01 03:42 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\WINDOWS\system32\E_ID4BJCE.DLL 2014-02-27 15:47 - 2012-10-01 03:42 - 00010752 _____ (SEIKO EPSON CORP.) C:\WINDOWS\system32\E_GCINST.DLL 2014-02-26 20:14 - 2014-02-26 20:14 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-26 20:14 - 2014-02-26 20:14 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-26 20:14 - 2014-02-26 20:14 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Skype 2014-02-26 16:14 - 2014-02-26 16:14 - 00000000 ____D () C:\WINDOWS\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP 2014-02-26 16:14 - 2014-02-26 16:14 - 00000000 ____D () C:\Users\Maxi\AppData\Local\2K Games 2014-02-22 15:56 - 2014-03-04 21:05 - 00040707 _____ () C:\Users\Maxi\Downloads\Addition.txt 2014-02-22 15:55 - 2014-03-21 12:33 - 00017948 _____ () C:\Users\Maxi\Downloads\FRST.txt 2014-02-22 15:55 - 2014-03-21 12:32 - 00000000 ____D () C:\FRST 2014-02-22 15:54 - 2014-02-22 15:55 - 02154496 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64.exe 2014-02-21 10:18 - 2014-02-21 10:18 - 00000000 ____D () C:\Crash 2014-02-20 18:14 - 2014-02-20 18:14 - 15453904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xlive.dll 2014-02-20 18:14 - 2014-02-20 18:14 - 13642960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xlivefnt.dll 2014-02-20 18:14 - 2014-02-20 18:14 - 00179377 _____ () C:\WINDOWS\SysWOW64\xlive.dll.cat 2014-02-20 15:59 - 2014-02-20 15:59 - 00001228 _____ () C:\Users\Maxi\Desktop\Torino 2006.lnk 2014-02-20 15:58 - 2014-02-20 15:58 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\2K Sports 2014-02-20 15:50 - 2014-02-20 15:50 - 00000000 ____D () C:\Program Files (x86)\2K Sports 2014-02-20 14:18 - 2014-02-20 14:18 - 00000000 ____D () C:\Users\Maxi\AppData\Local\SCE 2014-02-20 13:16 - 2014-02-20 13:42 - 00000000 ____D () C:\Users\Maxi\Documents\DayZ 2014-02-20 13:16 - 2014-02-20 13:22 - 00000000 ____D () C:\Users\Maxi\AppData\Local\DayZ 2014-02-19 19:25 - 2014-02-19 19:25 - 00000124 _____ () C:\Users\Maxi\Documents\Eset Scan.txt 2014-02-19 13:43 - 2014-02-19 13:43 - 02347384 _____ (ESET) C:\Users\Maxi\Downloads\esetsmartinstaller_enu.exe 2014-02-19 13:43 - 2014-02-19 13:43 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-19 13:37 - 2014-02-19 13:37 - 01037530 _____ (Thisisu) C:\Users\Maxi\Downloads\JRT.exe 2014-02-19 13:37 - 2014-02-19 13:37 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-02-19 13:31 - 2014-03-21 12:21 - 00000000 ____D () C:\AdwCleaner 2014-02-19 13:31 - 2014-02-19 13:31 - 01241834 _____ () C:\Users\Maxi\Downloads\adwcleaner.exe ==================== One Month Modified Files and Folders ======= 2014-03-21 12:33 - 2014-02-22 15:55 - 00017948 _____ () C:\Users\Maxi\Downloads\FRST.txt 2014-03-21 12:32 - 2014-03-21 12:32 - 02157056 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64(2).exe 2014-03-21 12:32 - 2014-02-22 15:55 - 00000000 ____D () C:\FRST 2014-03-21 12:29 - 2014-03-21 12:29 - 00001481 _____ () C:\Users\Maxi\Desktop\JRT.txt 2014-03-21 12:29 - 2013-11-14 08:27 - 01980934 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-03-21 12:29 - 2013-11-14 08:11 - 00842568 _____ () C:\WINDOWS\system32\perfh007.dat 2014-03-21 12:29 - 2013-11-14 08:11 - 00191764 _____ () C:\WINDOWS\system32\perfc007.dat 2014-03-21 12:24 - 2014-03-21 12:24 - 01037734 _____ (Thisisu) C:\Users\Maxi\Downloads\JRT(1).exe 2014-03-21 12:23 - 2014-02-07 13:17 - 00005128 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for Maxi-PC-Maxi Maxi-PC 2014-03-21 12:22 - 2014-01-20 15:52 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-03-21 12:22 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-03-21 12:21 - 2014-02-19 13:31 - 00000000 ____D () C:\AdwCleaner 2014-03-21 12:21 - 2014-01-30 15:47 - 00000000 ____D () C:\Users\Maxi 2014-03-21 12:21 - 2014-01-30 15:42 - 01410472 _____ () C:\WINDOWS\WindowsUpdate.log 2014-03-21 12:20 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-03-21 12:19 - 2014-03-21 12:19 - 01950720 _____ () C:\Users\Maxi\Downloads\adwcleaner(1).exe 2014-03-21 12:16 - 2013-11-13 23:18 - 00015192 _____ () C:\WINDOWS\PFRO.log 2014-03-21 12:14 - 2014-01-20 18:54 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\Skype 2014-03-21 12:05 - 2014-03-04 22:05 - 00003922 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E600782D-3A41-4E0D-9D1C-133B88519F03} 2014-03-21 12:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-03-21 11:57 - 2014-01-20 16:09 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-03-20 21:44 - 2014-01-21 21:38 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\Spotify 2014-03-20 20:33 - 2014-01-29 14:58 - 00000000 ____D () C:\Users\Maxi\Documents\Bandicam 2014-03-20 20:22 - 2014-01-20 18:44 - 00000000 ____D () C:\Users\Maxi\Documents\My Games 2014-03-20 18:40 - 2014-01-25 11:18 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\TS3Client 2014-03-20 18:10 - 2014-01-21 21:38 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Spotify 2014-03-20 17:53 - 2014-01-20 18:24 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log 2014-03-20 17:53 - 2014-01-20 18:23 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-03-20 17:22 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-03-20 16:09 - 2014-01-20 15:51 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1804472024-3847440819-3875843136-1002 2014-03-20 15:43 - 2014-03-15 13:10 - 00000000 ____D () C:\Users\Maxi\Documents\NFS SHIFT 2014-03-19 21:03 - 2014-01-24 15:47 - 00000004 _____ () C:\Users\Maxi\Downloads\survey.info 2014-03-19 19:47 - 2014-01-20 15:55 - 00000000 ____D () C:\ProgramData\Origin 2014-03-19 18:57 - 2014-02-05 13:48 - 00000000 ____D () C:\Users\Maxi\Documents\FIFA 14 2014-03-19 16:53 - 2014-01-20 15:55 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-19 16:42 - 2014-02-07 11:18 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-03-19 07:10 - 2014-01-20 15:45 - 00000000 ___RD () C:\Users\Maxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-19 07:10 - 2014-01-20 15:45 - 00000000 ___RD () C:\Users\Maxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-19 07:09 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-03-19 07:08 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-03-18 20:32 - 2012-08-24 17:09 - 00336438 _____ () C:\WINDOWS\DirectX.log 2014-03-18 20:27 - 2014-03-18 20:26 - 113634215 _____ () C:\Users\Maxi\Documents\Whatdoesthafpxsay.wmv 2014-03-18 19:05 - 2014-01-21 16:45 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-03-18 19:04 - 2014-01-21 16:44 - 90015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-03-18 19:04 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-03-17 21:07 - 2014-01-20 18:45 - 00290184 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2014-03-17 21:07 - 2014-01-20 18:39 - 00290184 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2014-03-17 21:07 - 2014-01-20 18:39 - 00280904 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2014-03-17 18:00 - 2014-03-06 18:02 - 00003156 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForMaxi 2014-03-17 18:00 - 2014-03-06 18:02 - 00000344 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForMaxi.job 2014-03-16 15:55 - 2014-03-16 15:32 - 1513047790 _____ () C:\Users\Maxi\Documents\Rennen 1.wmv 2014-03-16 15:00 - 2014-01-21 17:17 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Warframe 2014-03-16 14:21 - 2014-03-16 14:19 - 182109657 _____ () C:\Users\Maxi\Documents\Kanal Trailer.wmv 2014-03-16 13:44 - 2014-02-27 18:12 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Arma 3 2014-03-15 13:16 - 2014-01-20 16:04 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-03-15 13:04 - 2014-03-15 13:04 - 00000000 ____D () C:\Users\Public\Documents\SHIFT 2 UNLEASHED 2014-03-15 12:54 - 2014-03-15 12:50 - 00000000 ____D () C:\Users\Maxi\Documents\SHIFT 2 UNLEASHED 2014-03-15 12:50 - 2014-03-15 12:50 - 00000000 ____D () C:\ProgramData\Solidshield 2014-03-15 12:49 - 2014-02-05 20:15 - 264635744 _____ () C:\Users\Maxi\Downloads\cow_05.bin 2014-03-15 12:49 - 2014-01-24 15:47 - 00527028 _____ () C:\Users\Maxi\Downloads\cow_00.bin 2014-03-15 12:48 - 2014-02-05 18:56 - 1073741811 _____ () C:\Users\Maxi\Downloads\cow_04.bin 2014-03-15 12:48 - 2014-01-29 17:42 - 09169920 _____ () C:\Users\Maxi\Downloads\game.exe 2014-03-15 10:03 - 2013-08-22 15:44 - 00384240 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-03-14 22:57 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-14 22:57 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-14 22:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender 2014-03-14 22:57 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-03-14 20:47 - 2014-03-14 20:47 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\2K Sports 2014-03-14 18:34 - 2014-03-14 18:34 - 00000000 ____D () C:\Users\Maxi\Documents\CAPCOM 2014-03-14 12:37 - 2014-03-14 12:37 - 00000000 ____D () C:\ProgramData\Codemasters 2014-03-13 20:46 - 2014-03-13 20:46 - 03821624 _____ () C:\Users\Maxi\Downloads\battlelog-web-plugins_2.3.2_131(2).exe 2014-03-13 20:45 - 2014-02-05 18:21 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-03-13 20:44 - 2014-03-13 20:44 - 03821624 _____ () C:\Users\Maxi\Downloads\battlelog-web-plugins_2.3.2_131(1).exe 2014-03-13 20:44 - 2014-03-13 20:43 - 03821624 _____ () C:\Users\Maxi\Downloads\battlelog-web-plugins_2.3.2_131.exe 2014-03-13 15:57 - 2014-01-20 16:09 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2014-03-13 15:49 - 2014-01-25 11:17 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-10 19:19 - 2014-03-10 19:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA 2014-03-09 18:33 - 2014-03-09 18:33 - 00000000 ____D () C:\Users\Maxi\Documents\Criterion Games 2014-03-07 17:38 - 2014-01-20 18:39 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2014-03-07 17:13 - 2014-01-20 18:44 - 00000000 ____D () C:\Users\Maxi\AppData\Local\PunkBuster 2014-03-07 17:10 - 2014-03-07 17:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls 2014-03-05 17:45 - 2014-02-28 16:40 - 00000000 ____D () C:\Users\Maxi\Documents\BioWare 2014-03-05 16:59 - 2014-03-05 16:41 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-03-05 16:59 - 2014-03-05 16:40 - 00000000 ____D () C:\Users\Maxi\Desktop\mbar 2014-03-05 16:40 - 2014-03-05 16:40 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-03-05 16:21 - 2014-03-05 16:21 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Maxi\Downloads\mbar-1.07.0.1009.exe 2014-03-05 15:49 - 2014-03-05 15:49 - 20157440 _____ () C:\Users\Maxi\Downloads\PhysX-9.12.1031-SystemSoftware-Legacy.msi 2014-03-05 15:46 - 2014-03-05 15:33 - 00794408 _____ () C:\WINDOWS\SysWOW64\Pbsvc.exe 2014-03-05 15:44 - 2014-03-05 15:44 - 00000000 ____D () C:\Users\Maxi\Documents\EA Games 2014-03-04 23:53 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-03-04 23:53 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-04 21:05 - 2014-02-22 15:56 - 00040707 _____ () C:\Users\Maxi\Downloads\Addition.txt 2014-03-04 21:03 - 2014-03-04 21:03 - 02156544 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64(1).exe 2014-03-04 20:51 - 2014-01-20 15:54 - 00000000 ____D () C:\Fraps 2014-03-03 18:31 - 2014-03-03 18:31 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Skyrim 2014-03-03 17:18 - 2014-03-03 16:59 - 00000000 ____D () C:\Users\Maxi\Documents\COD Compelation 2014-03-03 17:16 - 2014-02-08 13:38 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\avidemux 2014-03-02 16:03 - 2014-03-02 16:03 - 00000000 ____D () C:\Users\Maxi\Documents\My WoZ Animals 2014-03-02 14:10 - 2013-08-22 15:46 - 00336554 _____ () C:\WINDOWS\setupact.log 2014-03-01 21:54 - 2014-03-01 21:54 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Macromedia 2014-03-01 21:53 - 2014-01-20 16:09 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-01 21:52 - 2014-03-01 21:52 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\Mozilla 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Mozilla 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\ProgramData\Mozilla 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-01 21:52 - 2014-03-01 21:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-01 21:51 - 2014-03-01 21:51 - 00283256 _____ (Mozilla) C:\Users\Maxi\Downloads\Firefox Setup Stub 27.0.1.exe 2014-03-01 21:39 - 2014-03-01 21:38 - 02155520 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64 (1).exe 2014-03-01 21:32 - 2014-03-01 21:32 - 01244192 _____ () C:\Users\Maxi\Downloads\adwcleaner (1).exe 2014-03-01 20:30 - 2014-03-01 09:49 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Windows Live 2014-03-01 07:05 - 2014-03-13 15:49 - 23133696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-03-01 05:58 - 2014-03-13 15:49 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-03-01 05:30 - 2014-03-13 15:49 - 17074688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-03-01 05:17 - 2014-03-13 15:49 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-03-01 04:54 - 2014-03-13 15:49 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-03-01 04:47 - 2014-03-13 15:49 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-03-01 04:42 - 2014-03-13 15:49 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-03-01 04:18 - 2014-03-13 15:49 - 13051904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-03-01 04:14 - 2014-03-13 15:49 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-03-01 04:10 - 2014-03-13 15:49 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-03-01 04:03 - 2014-03-13 15:49 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-03-01 03:57 - 2014-03-13 15:49 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-03-01 03:38 - 2014-03-13 15:49 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-03-01 03:32 - 2014-03-13 15:49 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-03-01 03:27 - 2014-03-13 15:49 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-03-01 03:25 - 2014-03-13 15:49 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-03-01 03:25 - 2014-03-13 15:49 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-02-27 18:13 - 2014-02-27 18:12 - 00000000 ____D () C:\Users\Maxi\Documents\Arma 3 2014-02-27 18:12 - 2014-02-27 18:12 - 00000000 ____D () C:\ProgramData\Bohemia Interactive 2014-02-27 15:47 - 2014-02-27 15:47 - 00000000 ____D () C:\ProgramData\EPSON 2014-02-27 15:47 - 2014-02-27 15:47 - 00000000 ____D () C:\Program Files\Common Files\EPSON 2014-02-26 20:14 - 2014-02-26 20:14 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-02-26 20:14 - 2014-02-26 20:14 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-26 20:14 - 2014-02-26 20:14 - 00000000 ____D () C:\Users\Maxi\AppData\Local\Skype 2014-02-26 20:14 - 2014-01-20 18:53 - 00000000 ____D () C:\ProgramData\Skype 2014-02-26 16:14 - 2014-02-26 16:14 - 00000000 ____D () C:\WINDOWS\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP 2014-02-26 16:14 - 2014-02-26 16:14 - 00000000 ____D () C:\Users\Maxi\AppData\Local\2K Games 2014-02-22 15:55 - 2014-02-22 15:54 - 02154496 _____ (Farbar) C:\Users\Maxi\Downloads\FRST64.exe 2014-02-22 13:16 - 2014-03-17 15:41 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2014-02-22 12:24 - 2014-03-17 15:41 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2014-02-21 10:18 - 2014-02-21 10:18 - 00000000 ____D () C:\Crash 2014-02-20 18:14 - 2014-02-20 18:14 - 15453904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xlive.dll 2014-02-20 18:14 - 2014-02-20 18:14 - 13642960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xlivefnt.dll 2014-02-20 18:14 - 2014-02-20 18:14 - 00179377 _____ () C:\WINDOWS\SysWOW64\xlive.dll.cat 2014-02-20 17:14 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\tracing 2014-02-20 16:03 - 2014-01-30 13:34 - 00000000 ____D () C:\Users\Maxi\AppData\Local\VirtualStore 2014-02-20 15:59 - 2014-02-20 15:59 - 00001228 _____ () C:\Users\Maxi\Desktop\Torino 2006.lnk 2014-02-20 15:58 - 2014-02-20 15:58 - 00000000 ____D () C:\Users\Maxi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\2K Sports 2014-02-20 15:50 - 2014-02-20 15:50 - 00000000 ____D () C:\Program Files (x86)\2K Sports 2014-02-20 14:18 - 2014-02-20 14:18 - 00000000 ____D () C:\Users\Maxi\AppData\Local\SCE 2014-02-20 13:42 - 2014-02-20 13:16 - 00000000 ____D () C:\Users\Maxi\Documents\DayZ 2014-02-20 13:22 - 2014-02-20 13:16 - 00000000 ____D () C:\Users\Maxi\AppData\Local\DayZ 2014-02-20 07:33 - 2014-03-21 12:25 - 01037734 _____ (Thisisu) C:\Users\Maxi\Desktop\JRT_NEW.exe 2014-02-19 19:25 - 2014-02-19 19:25 - 00000124 _____ () C:\Users\Maxi\Documents\Eset Scan.txt 2014-02-19 13:43 - 2014-02-19 13:43 - 02347384 _____ (ESET) C:\Users\Maxi\Downloads\esetsmartinstaller_enu.exe 2014-02-19 13:43 - 2014-02-19 13:43 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-19 13:37 - 2014-02-19 13:37 - 01037530 _____ (Thisisu) C:\Users\Maxi\Downloads\JRT.exe 2014-02-19 13:37 - 2014-02-19 13:37 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-02-19 13:31 - 2014-02-19 13:31 - 01241834 _____ () C:\Users\Maxi\Downloads\adwcleaner.exe 2014-02-19 13:11 - 2014-02-05 12:14 - 00000000 ____D () C:\Users\Maxi\Documents\Teichentabelle Files to move or delete: ==================== C:\Users\Maxi\AppData\Roaming\CamLayout.ini C:\Users\Maxi\AppData\Roaming\CamShapes.ini C:\Users\Maxi\AppData\Roaming\CamStudio.Producer.Data.ini C:\ProgramData\hash.dat Some content of TEMP: ==================== C:\Users\Maxi\AppData\Local\Temp\ace79fa197c23090a2d008fba6ef4268.dll C:\Users\Maxi\AppData\Local\Temp\avgnt.exe C:\Users\Maxi\AppData\Local\Temp\bdzshl64.dll C:\Users\Maxi\AppData\Local\Temp\drm_dyndata_7380014.dll C:\Users\Maxi\AppData\Local\Temp\Extract.exe C:\Users\Maxi\AppData\Local\Temp\OfficeSetup.exe C:\Users\Maxi\AppData\Local\Temp\Quarantine.exe C:\Users\Maxi\AppData\Local\Temp\sonarinst.exe C:\Users\Maxi\AppData\Local\Temp\SP61037.exe C:\Users\Maxi\AppData\Local\Temp\SP63297.exe C:\Users\Maxi\AppData\Local\Temp\SP64792.exe C:\Users\Maxi\AppData\Local\Temp\SP65048.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2014-03-13 15:48] - [2014-01-31 17:15] - 0311640 ___AC (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02 LastRegBack: 2014-03-19 16:25 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by Maxi at 2014-03-21 12:33:24 Running from C:\Users\Maxi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.1.0.8 - Absolute Software) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.) Alliance of Valiant Arms (HKLM-x32\...\Steam App 102700) (Version: - RED DUCK Inc.) Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive) Assassin’s Creed® III (HKLM-x32\...\Steam App 208480) (Version: - Ubisoft Montreal) Avidemux 2.6 (32-bit) (HKLM-x32\...\Avidemux 2.6) (Version: 2.6.7.8981 - ) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Bandicam (HKLM-x32\...\Bandicam) (Version: 1.9.3.492 - Bandisoft.com) Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandisoft.com) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.2 - EA Digital Illusions CE AB) BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version: - Irrational Games) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Burnout Paradise: The Ultimate Box (HKLM-x32\...\Steam App 24740) (Version: - Criterion Games) Call of Duty: Ghosts - Multiplayer (HKLM-x32\...\Steam App 209170) (Version: - ) Call of Duty: Ghosts (HKLM-x32\...\Steam App 209160) (Version: - Infinity Ward) Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version: - Infinity Ward) Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward) Chicken Shoot 2 (HKLM-x32\...\Steam App 259360) (Version: - ) Chicken Shoot Gold (HKLM-x32\...\Steam App 259340) (Version: - ToonTRAXX Studios) Connected Music powered by Universal Music Group version 1.0 (HKLM-x32\...\{46037DC7-F927-46DF-935F-D6F122BDD34B}_is1) (Version: 1.0 - Snowite) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.) CyberLink PowerDirector 10 (x32 Version: 10.0.1.1925 - CyberLink Corp.) Hidden CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.) CyberLink PowerDVD (x32 Version: 10.0.6.4319 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.4.5527 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.5.4.5527 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Draw a Stickman: EPIC (HKLM-x32\...\Steam App 248650) (Version: - Hitcents) Dungeon Defenders (HKLM-x32\...\Steam App 65800) (Version: - Trendy Entertainment) Energy Star (HKLM\...\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard) EPSON XP-600 Series Printer Uninstall (HKLM\...\EPSON XP-600 Series) (Version: - SEIKO EPSON Corporation) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) F1 2013 (HKLM-x32\...\Steam App 223670) (Version: - Codemasters Birmingham) Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version: - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai) FIFA 14 (HKLM-x32\...\{AA7A2800-1E75-4240-855B-03AFF8E5171E}) (Version: 1.0.0.4 - Electronic Arts) Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Grand Theft Auto IV (HKLM-x32\...\Steam App 12210) (Version: - Rockstar North) HAWKEN (HKLM-x32\...\Steam App 271290) (Version: - Adhesive Games) Hewlett-Packard ACLM.NET v1.2.0.0 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP 3D DriveGuard (HKLM\...\{AB5BCC55-18E2-46C7-9405-FF61CB888F05}) (Version: 4.2.9.1 - Hewlett-Packard Company) HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd) HP CoolSense (HKLM-x32\...\{0D3A6808-82B8-4BB1-BE5A-AED75B3F6C02}) (Version: 2.20.11 - Hewlett-Packard Company) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{D044EBE7-94E7-4C49-90FC-9069E3F374E1}) (Version: 1.1.0.0 - Hewlett-Packard) HP Postscript Converter (Version: 3.1.3554 - Hewlett-Packard) Hidden HP Quick Launch (HKLM-x32\...\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company) HP Recovery Manager (x32 Version: 7.00 - Hewlett-Packard) Hidden HP Registration Service (HKLM\...\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{D2462056-BA75-4B2C-8267-DFEA2B6AC4AE}) (Version: 4.6.10.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{B8019B54-F9BE-490A-9619-6D06F18F129F}) (Version: 7.0.32.44 - Hewlett-Packard Company) HP Utility Center (HKLM-x32\...\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard) HP Wireless Button Driver (HKLM-x32\...\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT) Infestation: Survivor Stories (HKLM-x32\...\Steam App 226700) (Version: - Hammerpoint Interactive) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3379 - Intel Corporation) Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 2.1.0.1002 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.27.757.1 - Intel Corporation) Hidden Kingdom Rush (HKLM-x32\...\Steam App 246420) (Version: - Ironhide Game Studio) Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Mafia II (HKLM-x32\...\Steam App 50130) (Version: - 2K Czech) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Mass Effect (HKLM-x32\...\Steam App 17460) (Version: - BioWare) Mass Effect 2 (HKLM-x32\...\Steam App 24980) (Version: - BioWare) Max Payne 3 (HKLM-x32\...\Steam App 204100) (Version: - Rockstar Studios) Medal of Honor: Airborne (HKLM-x32\...\Steam App 24840) (Version: - EA Los Angeles) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation) Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4569.1508 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Mozilla Firefox 27.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden NBA 2K14 (HKLM-x32\...\Steam App 255480) (Version: - Visual Concepts) Need for Speed: Hot Pursuit (HKLM-x32\...\Steam App 47870) (Version: - Criterion Games) Need for Speed: SHIFT (HKLM-x32\...\Steam App 24870) (Version: - Slightly Mad Studios) Need for Speed: Undercover (HKLM-x32\...\Steam App 17430) (Version: - EA Black Box) NVIDIA GeForce Experience 1.8.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2 - NVIDIA Corporation) NVIDIA Grafiktreiber 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.21 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Optimus Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA PhysX (Legacy) (HKLM-x32\...\{6F9D5A0B-202C-4161-BC7F-0664EA39E7E7}) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4569.1508 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4569.1508 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4569.1508 - Microsoft Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 9.3.11.2762 - Electronic Arts, Inc.) PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) PlanetSide 2 (HKLM-x32\...\Steam App 218230) (Version: - Sony Online Entertainment) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.) Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros) Razer Game Booster (HKLM-x32\...\Razer Game Booster_is1) (Version: 4.1.59.0 - Razer Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.) Resident Evil 6 / Biohazard 6 (HKLM-x32\...\Steam App 221040) (Version: - Capcom) Rising Storm/Red Orchestra 2 Multiplayer (HKLM-x32\...\Steam App 35450) (Version: - Tripwire Interactive) Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition) SHIELD Streaming (Version: 1.7.306 - NVIDIA Corporation) Hidden Shift 2 Unleashed (HKLM-x32\...\Steam App 47920) (Version: - Slightly Mad Studios) Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - Firaxis Games) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Spec Ops: The Line (HKLM-x32\...\Steam App 50300) (Version: - Yager) Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB) Starbound (HKLM-x32\...\Steam App 211820) (Version: - ) State of Decay (HKLM-x32\...\Steam App 241540) (Version: - Undead Labs) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Superfrog HD (HKLM-x32\...\Steam App 234000) (Version: - Team17 Digital Ltd) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.1.3 - Synaptics Incorporated) System Requirements Lab Detection (HKLM-x32\...\{A407FC22-36BF-4C82-A516-59D94BC505A9}) (Version: 1.0.5.0 - Husdawg, LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) Tom Clancy's Splinter Cell (HKLM-x32\...\Steam App 13560) (Version: - Ubisoft) Tom Clancy's Splinter Cell: Chaos Theory (HKLM-x32\...\Steam App 13570) (Version: - Ubisoft Montreal) Tom Clancy's Splinter Cell: Double Agent (HKLM-x32\...\Steam App 13580) (Version: - Ubisoft Montreal) Torchlight II (HKLM-x32\...\Steam App 200710) (Version: - Runic Games) Torino 2006 (HKLM-x32\...\Torino 2006_0001) (Version: - ) Trine (HKLM-x32\...\Steam App 35700) (Version: - Frozenbyte) Trine 2 (HKLM-x32\...\Steam App 35720) (Version: - Frozenbyte) Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) War Inc. Battlezone (HKLM-x32\...\Steam App 107900) (Version: - Online Warmongers Group Inc.) Warframe (HKLM-x32\...\Steam App 230410) (Version: - Digital Extremes) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden World of Zoo (HKLM-x32\...\Steam App 43100) (Version: - Blue Fang) ==================== Restore Points ========================= 09-03-2014 17:26:55 DirectX wurde installiert 10-03-2014 18:19:45 DirectX wurde installiert 14-03-2014 11:37:02 DirectX wurde installiert 15-03-2014 11:48:47 DirectX wurde installiert 18-03-2014 18:03:05 Windows Update 19-03-2014 19:28:13 Installed Windows Live ID Sign-in Assistant ==================== Hosts content: ========================== 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {14B49A89-07C1-44CC-BF6B-5C2B82A3CDEF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-10] (Hewlett-Packard Company) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {270C18FB-D645-4B6B-B8E5-587B88946B4D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-10] (Hewlett-Packard Company) Task: {2C2BBB17-CC12-4A6E-AA3C-1787AD0ADFB9} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Maxi-PC-Maxi Maxi-PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-03-19] (Microsoft Corporation) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {38E25B05-DD3F-4800-8082-8600CB042FE7} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2013-12-17] (Microsoft Corporation) Task: {3A4FBAB1-8CB5-4EDC-BCF8-45324A52DC5F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2012-07-13] (Hewlett-Packard) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {5AC6012E-8BA0-4DD6-A9A1-40478466EA1D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-03-18] (Microsoft Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {71FE14E1-5572-48D2-B893-40583DEF0BD5} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-07-27] (CyberLink) Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {7671E920-69AB-4E2E-806D-536A1B1D6435} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-07-20] (Intel) Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {9D22CCF4-5B61-4417-938B-ECC2EF35E821} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-13] (Adobe Systems Incorporated) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {AF0A9F35-330C-49A9-A64A-69BE43DE82B7} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-10] (Hewlett-Packard Company) Task: {B2F7844E-FCBF-491D-8A69-1BFB35496599} - System32\Tasks\HPCeeScheduleForMaxi => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard) Task: {BAA4E83B-08FB-4C76-92CB-D3D82CBA1D30} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-10] (Hewlett-Packard Company) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E374A36A-90A4-4AD2-8B4C-B4D6C9A2CD99} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-08-19] (Hewlett-Packard Development Company, L.P.) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {E742C888-B24E-41E5-ADA0-2F01E9A0D086} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\HPCeeScheduleForMaxi.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Loaded Modules (whitelisted) ============= 2013-10-27 09:03 - 2013-12-19 21:33 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2012-10-04 14:09 - 2013-12-19 19:53 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-03-19 07:25 - 2013-10-31 17:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2014-02-07 11:18 - 2014-01-02 18:41 - 00621736 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll 2014-01-20 18:39 - 2014-03-07 17:38 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2013-12-21 00:02 - 2013-12-21 00:02 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-01-20 19:10 - 2013-12-18 09:32 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2014-01-20 15:53 - 2013-12-12 23:19 - 00142848 _____ () C:\Program Files (x86)\Steam\libavresample-1.dll 2014-01-20 15:53 - 2013-11-05 02:12 - 00890592 _____ () C:\Program Files (x86)\Steam\libavutil-52.dll 2014-01-20 15:53 - 2014-02-11 03:34 - 00751616 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2014-01-20 15:53 - 2014-02-25 22:57 - 01135296 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2014-01-20 15:53 - 2014-01-11 00:33 - 20625832 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2014-01-20 15:53 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll 2014-01-20 15:53 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll 2014-01-20 15:53 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll 2014-02-07 11:18 - 2014-02-07 11:18 - 00316584 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll 2012-10-04 14:11 - 2014-01-20 19:23 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2014-03-01 21:52 - 2014-02-13 01:36 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-10-27 09:03 - 2013-12-19 21:33 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-03-01 21:33:26.327 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-03-01 21:33:26.296 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-01-20 19:22:12.446 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. Date: 2014-01-20 19:21:01.306 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. Date: 2014-01-20 19:03:28.020 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. Date: 2014-01-20 18:57:13.085 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. Date: 2014-01-20 18:56:39.182 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. Date: 2014-01-20 18:55:24.681 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. Date: 2014-01-20 18:55:23.371 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. Date: 2014-01-20 18:55:22.477 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\EEL64A.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Percentage of memory in use: 23% Total physical RAM: 8084.27 MB Available physical RAM: 6208.89 MB Total Pagefile: 18836.27 MB Available Pagefile: 16896.53 MB Total Virtual: 131072 MB Available Virtual: 131071.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:681.05 GB) (Free:124.03 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:16.47 GB) (Free:2.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 466E2C46) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 8 GB) (Disk ID: 80487483) Partition: GPT Partition Type. ==================== End Of Log ============================ |
21.03.2014, 14:59 | #24 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Eset erkenntvirus, kann ihn nicht löschen Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
21.03.2014, 20:10 | #25 |
| Eset erkenntvirus, kann ihn nicht löschen Tja jetzt habe ich ein großes Problem. Mein Computer reagiert seit 2std nur noch lückenhaft ! wenn ich zb über Desktop Symbole fahre erscheint nicht der normale Hintergrund ( beim rüberfahren). Ich kann bei Steam keine Spiele mehr durchgängig installieren. Da steht meistens: Festplatte überlastet. Also habe ich meinen Computer ( nachdem ich es endlich geschafft habe das Recovery Tool zu öffnen, da der LapTop einfach nicht reagiert hat), auf Werkszustand zurückgesetzt ! Jedoch gibt es jetzt keine Besserung. Mich hat es auch gewundert wie schnell die Zurücksetung gedauert hat. Ich habe beschlossen zu Media Markt zu gehen und einen Profi, wie dich, mal selbst an den Lap Top zu lassen. Meinst du die finden jeden Virus? Was soll ich tun? Was kann das mit meinem Lap Top sein? Ich habe mich verschrieben! Es waren nicht 2 STD sondern 4 oder 5! |
22.03.2014, 20:50 | #26 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Eset erkenntvirus, kann ihn nicht löschen Du hast das gerät auf Werkseinstellungen zurückgesetzt, da kann im Prinzip kein Schädling mehr sein! Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Eset erkenntvirus, kann ihn nicht löschen |
appdata, applaus, cache, cleaner, code, entferne, entfernen, erkenn, eset, gefunde, junkware, local, löschen, malwarebytes, microsoft, nicht löschen, objekt, removal, schlimm, schlimmer, tipps, users, virus, virus?, wastun, windows |