|
Plagegeister aller Art und deren Bekämpfung: Win7 Computer geht seit ein paar Tagen massiv "in die Knie"Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.02.2014, 15:42 | #1 |
| Win7 Computer geht seit ein paar Tagen massiv "in die Knie" Seit ein paar Tagen kommt es immer mal wieder vor, das quasi nichts mehr geht, bzw nur quälend langsam. Das passierte immer dann, wenn ich world of warplanes minimiert hatte und nebenher emailprogramme und browser bediente. Das man das nicht machen sollte ist mir klar, jedoch war das bis vor ein paar Tagen mit akzeptablen performanceeinbußen möglich. Icch bin nicht sicher, aber mir kommts so vor, dass das seit d3em einbau einer neuen grafikkarte und damit dem umstieg von amd radeon auf nvidia geforce der fall ist. Der SPeicher ist in solchen Momenten zu ~87% ausgelastet die CPU mit ~47% auch ist mir aufgefallen das "atieclxx.exe" im taskmanager läuft, trotz drivercleaner. virenscan mit avast und malwarescan mit MBAM ohne befund |
21.02.2014, 06:48 | #2 |
/// the machine /// TB-Ausbilder | Win7 Computer geht seit ein paar Tagen massiv "in die Knie" Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
21.02.2014, 07:47 | #3 |
| Win7 Computer geht seit ein paar Tagen massiv "in die Knie" addition.txt
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2014 Ran by Jan at 2014-02-20 14:56:40 Running from C:\Users\Jan\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== µTorrent (HKCU Version: 3.3.2.30303 - BitTorrent Inc.) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) 7-Zip 9.22beta (x32 Version: - ) Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) ASRock IES v2.1.28 (x32 Version: - ) ASUS GPU Tweak (x32 Version: 2.5.2.3 - ASUSTek COMPUTER INC.) ASUS GPU Tweak (x32 Version: 2.5.2.3 - ASUSTek COMPUTER INC.) Hidden avast! Free Antivirus (x32 Version: 9.0.2013 - Avast Software) Bonjour (Version: 1.0.106 - Apple Inc.) calibre 64bit (Version: 1.21.0 - Kovid Goyal) CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden Captcha Brotherhood (x32 Version: 1.1.8 - Brotherhood Software) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden CloudReading (x32 Version: 1.1.47.1220 - Foxit Corporation) Curse Client (HKCU Version: 5.1.1.792 - Curse) DAEMON Tools Lite (x32 Version: 4.46.1.0328 - DT Soft Ltd) DC Universe Online Live (HKCU Version: - Sony Online Entertainment) DC Universe Online PSG (HKCU Version: 1.0.3.183 - Sony Online Entertainment) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version: - Microsoft) DH Driver Cleaner Professional Edition (x32 Version: Version 1.5 - Ruud Ketelaars) Dokan Library 0.6.0 (x32 Version: - ) Dropbox (HKCU Version: 2.6.2 - Dropbox, Inc.) Duplicate Cleaner Free 3.2.1 (x32 Version: 3.2.1 - DigitalVolcano Software Ltd) erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden EVEREST Ultimate Edition v5.50 (x32 Version: 5.50 - Lavalys, Inc.) Exact Audio Copy 1.0beta3 (x32 Version: 1.0beta3 - Andre Wiethoff) Faster Than Light (x32 Version: - GOG.com) foobar2000 v1.2.5 (x32 Version: 1.2.5 - Peter Pawlowski) Foxit Reader (x32 Version: 6.1.2.1224 - Foxit Corporation) Free Video Flip and Rotate version 2.1.9.827 (x32 Version: 2.1.9.827 - DVDVideoSoft Ltd.) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Golden Videos (x32 Version: 3.01 - NCH Software) Google Chrome (x32 Version: 32.0.1700.107 - Google Inc.) Google Earth (x32 Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden Hi-Rez Studios Authenticate and Update Service (x32 Version: 3.0.0.0 - Hi-Rez Studios) IrfanView (remove only) (x32 Version: 4.37 - Irfan Skiljan) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (x32 Version: 0.9 - AppWork GmbH) League of Legends (x32 Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden LG Bluetooth Drivers (x32 Version: 1.1 - LG Electronics) LG PC Suite IV (x32 Version: 4.3.46.20111117 - LG Electronics) LG United Mobile Driver (x32 Version: 3.10.1.0 - LG Electronics) Logitech Touch Mouse Server 1.0 (x32 Version: 1.0 - Logitech Inc.) Logitech Webcam-Software (x32 Version: 2.51 - Logitech Inc.) LWS Facebook (x32 Version: 13.50.854.0 - Logitech) Hidden LWS Gallery (x32 Version: 13.51.827.0 - Logitech) Hidden LWS Help_main (x32 Version: 13.51.828.0 - Logitech) Hidden LWS Launcher (x32 Version: 13.51.828.0 - Logitech) Hidden LWS Motion Detection (x32 Version: 13.51.815.0 - Logitech) Hidden LWS Pictures And Video (x32 Version: 13.51.815.0 - Logitech) Hidden LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Webcam Software (x32 Version: 13.51.815.0 - Logitech) Hidden LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (x32 Version: 13.31.1038.0 - Logitech) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) MechWarrior Online (x32 Version: 1.4.1.0 - Piranha Games Inc.) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.88.0 - Microsoft Corporation) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 27.0.1 (x86 de) (x32 Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (x32 Version: 27.0.1 - Mozilla) Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8 - Mozilla) MSRedists64 (Version: 2.00.0000 - Ingres Corporation) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (x32 Version: 4.20.9818.0 - Microsoft Corporation) No23 Recorder (x32 Version: 2.1.0.3 - No23) NVIDIA 3D Vision Controller-Treiber 334.89 (Version: 334.89 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 334.89 (Version: 334.89 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 334.89 (Version: 334.89 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3489 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 334.89 (Version: 334.89 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (Version: 1.2.20 - NVIDIA Corporation) OpenAL (x32 Version: - ) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593 - Apache Software Foundation) Pando Media Booster (x32 Version: 2.6.0.8 - Pando Networks Inc.) PDF to Word (x32 Version: - Quick PDF) Pirate101 (x32 Version: 1.0.0 - KingsIsle Entertainment, Inc.) Prism Videodatei-Konverter (x32 Version: 2.02 - NCH Software) Rapture3D 2.4.11 Game (x32 Version: - Blue Ripple Sound) Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6433 - Realtek Semiconductor Corp.) REFLEXW Program version 4.2 (x32 Version: - ) Remove Empty Directories version 2.2 (x32 Version: 2.2 - Jonas John) ScummVM 1.5.0 (x32 Version: - The ScummVM Team) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Smite (x32 Version: 0.1.1970.1 - Hi-Rez Studios) Steam (x32 Version: 1.0.0.0 - Valve Corporation) Summit Acquisition Tool .Net (x32 Version: 1.7.2 - DMT) TeamSpeak 3 Client (Version: 3.0.11.1 - TeamSpeak Systems GmbH) TechPowerUp GPU-Z (x32 Version: - TechPowerUp) teXXas (x32 Version: 1 - metaspinner net GmbH) TIPP10 Version 2.1.0 (x32 Version: - (c) 2006-2011, Tom Thielicke IT Solutions) TL-WN751ND Driver (x32 Version: 1.00.0000 - TP-LINK) TP-LINK Wireless Configuration Utility (x32 Version: 2.01.0012 - TP-LINK) TuneUp Utilities 2013 (x32 Version: 13.0.2020.4 - TuneUp Software) TuneUp Utilities 2013 (x32 Version: 13.0.2020.4 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.2020.4 - TuneUp Software) Hidden Unity Web Player (HKCU Version: - Unity Technologies ApS) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2837583) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version: - Microsoft) VideoPad Video-Editor (x32 Version: 3.25 - NCH Software) VLC media player 2.1.2 (x32 Version: 2.1.2 - VideoLAN) War Thunder Launcher 1.0.1.252 (x32 Version: - 2013 Gaijin Entertainment Corporation) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0 - Microsoft Corporation) WinRAR 5.01 (64-bit) (Version: 5.01.0 - win.rar GmbH) WinSism V.14 (x32 Version: 14.6 - ) World of Tanks (x32 Version: - Wargaming.net) World of Warplanes (x32 Version: - Wargaming.net) XFast USB (x32 Version: - ) XFastUSB (x32 Version: 3.02.38 - ASRock Inc.) xp-AntiSpy 3.98-2 (x32 Version: - Christian Taubenheim) Zero Assumption Disk Space Visualizer 1.2 (x32 Version: - Zero Assumption Software) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {3A8ED586-8107-4798-9835-F69EA747D6B6} - System32\Tasks\ASRockIES => C:\Program Files (x86)\ASRock Utility\IES\AsrIes.exe [2011-09-16] (ASRock Incorporation) Task: {44771463-D3F4-4B5A-8620-1563BB543D16} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~2\AD-AWA~1\AdAwareLauncher.exe Task: {4D93D8BF-702B-431F-9253-3B5566C14F63} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-19] (Google Inc.) Task: {5225D6DC-8715-4822-B408-A61DF6BE8BE2} - \Software Updater Ui No Task File Task: {5C2D9067-ADEC-42E8-ADC1-AF028EAA503B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe [2012-09-19] (TuneUp Software) Task: {95D13DFA-E65C-4E72-A957-1701A88A663A} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-19] (AVAST Software) Task: {9F365516-0BA6-40CC-A092-6D545E939640} - System32\Tasks\{283C42D8-4A23-4110-8A58-8EE78D629D53} => Firefox.exe hxxp://ui.skype.com/ui/0/6.11.0.102/de/abandoninstall?source=lightinstaller&page=tsBing Task: {AB81FDB4-9A6A-43A9-9E4C-CBCC148DFF6A} - \Software Updater No Task File Task: {D56D61D6-E97F-429B-BCAF-DCAEC5DBBA40} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-19] (Google Inc.) Task: {E9F13F4A-2542-4E8D-AAA5-985D5C24CDC1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-05] (Adobe Systems Incorporated) Task: {EB9E5175-7DEE-46A1-9BC8-038B57FE403D} - System32\Tasks\Google Updater and Installer => C:\Users\Jan\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-02-12 14:49 - 2014-02-08 18:42 - 00117024 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2012-01-17 11:24 - 2012-01-17 11:24 - 00055296 _____ () C:\Windows\SysWOW64\ASGT.exe 2012-09-13 00:38 - 2012-09-13 00:38 - 00264040 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe 2014-02-19 10:48 - 2014-02-19 09:01 - 02181120 _____ () C:\Program Files\AVAST Software\Avast\defs\14021900\algo.dll 2014-02-20 14:32 - 2014-02-20 12:34 - 02181120 _____ () C:\Program Files\AVAST Software\Avast\defs\14022000\algo.dll 2013-12-13 09:39 - 2013-12-13 09:39 - 00278528 _____ () C:\Program Files (x86)\ASUS\GPU Tweak\Vender.dll 2013-11-18 09:32 - 2013-11-18 09:32 - 00053248 _____ () C:\Program Files (x86)\ASUS\GPU Tweak\Exeio.dll 2012-09-01 09:46 - 2010-06-24 14:50 - 00094208 _____ () C:\Program Files (x86)\ASRock Utility\IES\IccLibDll.DLL 2014-02-20 14:32 - 2014-02-20 14:32 - 00041984 _____ () c:\users\jan\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptzt6qy.dll 2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Jan\AppData\Roaming\Dropbox\bin\libcef.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 02144104 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 07955304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 00341352 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 00028008 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 00127336 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2013-12-28 15:00 - 2013-12-28 15:00 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2012-09-13 00:39 - 2012-09-13 00:39 - 00336232 _____ () C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll 2014-02-06 11:07 - 2014-02-17 09:45 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:48A9EADC ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: SBRE Description: SBRE Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: SBRE Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (02/20/2014 02:31:49 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (02/20/2014 02:31:49 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (02/20/2014 02:31:49 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (02/20/2014 00:57:39 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x800706b5, Die Schnittstelle ist unbekannt. . Error: (02/20/2014 00:57:39 PM) (Source: VSS) (User: ) Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} und dem Namen "CEventSystem" kann nicht gestartet werden. [0x800706b5, Die Schnittstelle ist unbekannt. ] Error: (02/20/2014 00:45:39 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: NvBackend.exe, Version: 11.10.13.1, Zeitstempel: 0x52f202d0 Name des fehlerhaften Moduls: OLEAUT32.dll, Version: 6.1.7601.17676, Zeitstempel: 0x4e58702a Ausnahmecode: 0xc0000005 Fehleroffset: 0x00021750 ID des fehlerhaften Prozesses: 0x9c8 Startzeit der fehlerhaften Anwendung: 0xNvBackend.exe0 Pfad der fehlerhaften Anwendung: NvBackend.exe1 Pfad des fehlerhaften Moduls: NvBackend.exe2 Berichtskennung: NvBackend.exe3 Error: (02/20/2014 00:45:21 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: NvBackend.exe, Version: 11.10.13.1, Zeitstempel: 0x52f202d0 Name des fehlerhaften Moduls: nvspcap.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52f20257 Ausnahmecode: 0xc0000005 Fehleroffset: 0x100c9860 ID des fehlerhaften Prozesses: 0x9c8 Startzeit der fehlerhaften Anwendung: 0xNvBackend.exe0 Pfad der fehlerhaften Anwendung: NvBackend.exe1 Pfad des fehlerhaften Moduls: NvBackend.exe2 Berichtskennung: NvBackend.exe3 Error: (02/19/2014 10:15:49 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Monitor.exe, Version: 1.3.2.7, Zeitstempel: 0x52b00780 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00720075 ID des fehlerhaften Prozesses: 0xe64 Startzeit der fehlerhaften Anwendung: 0xMonitor.exe0 Pfad der fehlerhaften Anwendung: Monitor.exe1 Pfad des fehlerhaften Moduls: Monitor.exe2 Berichtskennung: Monitor.exe3 Error: (02/19/2014 00:26:31 PM) (Source: NVNetworkService) (User: ) Description: NVNetworkServiceonnection write error system:10054 in src\RPC\Connection.cpp:160 Error: (02/17/2014 09:45:29 AM) (Source: Application Hang) (User: ) Description: Programm firefox.exe, Version 27.0.0.5140 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 3f0 Startzeit: 01cf2b58da2a2a9c Endzeit: 12 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: d6f5af15-97af-11e3-aa74-bc5ff41e006f System errors: ============= Error: (02/20/2014 02:32:03 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: SBRE Error: (02/20/2014 02:01:19 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (02/20/2014 00:59:56 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: SBRE Error: (02/20/2014 00:52:00 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Remoteprozeduraufruf (RPC)" Korrekturmaßnahmen (Neustart des Computers) durchzuführen, ist fehlgeschlagen. Fehler: %%1190 Error: (02/20/2014 00:52:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Remoteprozeduraufruf (RPC)" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Computers. Error: (02/20/2014 00:52:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "RPC-Endpunktzuordnung" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (02/20/2014 00:51:55 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Stromversorgung" Korrekturmaßnahmen (Neustart des Computers) durchzuführen, ist fehlgeschlagen. Fehler: %%1190 Error: (02/20/2014 00:51:55 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Plug & Play" Korrekturmaßnahmen (Neustart des Computers) durchzuführen, ist fehlgeschlagen. Fehler: %%1190 Error: (02/20/2014 00:51:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Stromversorgung" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Computers. Error: (02/20/2014 00:51:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Plug & Play" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Computers. Microsoft Office Sessions: ========================= Error: (02/20/2014 02:31:49 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (02/20/2014 02:31:49 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (02/20/2014 02:31:49 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (02/20/2014 00:57:39 PM) (Source: VSS)(User: ) Description: CoCreateInstance0x800706b5, Die Schnittstelle ist unbekannt. Error: (02/20/2014 00:57:39 PM) (Source: VSS)(User: ) Description: {4e14fba2-2e22-11d1-9964-00c04fbbb345}CEventSystem0x800706b5, Die Schnittstelle ist unbekannt. Error: (02/20/2014 00:45:39 PM) (Source: Application Error)(User: ) Description: NvBackend.exe11.10.13.152f202d0OLEAUT32.dll6.1.7601.176764e58702ac0000005000217509c801cf2e1ad0113106C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exeC:\Windows\syswow64\OLEAUT32.dll84771b88-9a24-11e3-b10f-bc5ff41e006f Error: (02/20/2014 00:45:21 PM) (Source: Application Error)(User: ) Description: NvBackend.exe11.10.13.152f202d0nvspcap.dll_unloaded0.0.0.052f20257c0000005100c98609c801cf2e1ad0113106C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exenvspcap.dll79f94124-9a24-11e3-b10f-bc5ff41e006f Error: (02/19/2014 10:15:49 PM) (Source: Application Error)(User: ) Description: Monitor.exe1.3.2.752b00780unknown0.0.0.000000000c000000500720075e6401cf2db7bcd14fefC:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exeunknown011cae91-99ab-11e3-98d7-bc5ff41e006f Error: (02/19/2014 00:26:31 PM) (Source: NVNetworkService)(User: ) Description: NVNetworkServiceonnection write error system:10054 in src\RPC\Connection.cpp:160 Error: (02/17/2014 09:45:29 AM) (Source: Application Hang)(User: ) Description: firefox.exe27.0.0.51403f001cf2b58da2a2a9c12C:\Program Files (x86)\Mozilla Firefox\firefox.exed6f5af15-97af-11e3-aa74-bc5ff41e006f CodeIntegrity Errors: =================================== Date: 2013-02-20 16:44:37.831 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Jan\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-02-20 16:44:37.773 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Jan\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-02-20 16:44:37.445 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-02-20 16:44:37.386 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 4095.24 MB Available physical RAM: 2253.05 MB Total Pagefile: 10093.42 MB Available Pagefile: 7953.05 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (System WD) (Fixed) (Total:75.13 GB) (Free:25.94 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Workplace WD) (Fixed) (Total:390.63 GB) (Free:57.46 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 876CD8D1) Partition 1: (Active) - (Size=75 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=391 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2014 Ran by Jan (administrator) on HOMOFÜRST on 20-02-2014 14:56:10 Running from C:\Users\Jan\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AMD) C:\Windows\system32\atiesrxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) C:\Windows\system32\atieclxx.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Windows\SysWOW64\ASGT.exe (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Hi-Rez Studios) d:\gamezone\Hi-Rez Studios\HiPatchService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe (ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\IES\AsrIes.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Dropbox, Inc.) C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Logitech, Inc.) C:\Program Files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\splwow64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12666984 2011-08-09] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-28] (AVAST Software) HKLM-x32\...\Run: [XFastUSB] - C:\Program Files (x86)\XFastUSB\XFastUsb.exe [6311104 2014-01-24] (FNet Co., Ltd.) HKLM Group Policy restriction on software: C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Avira\AntiVir Desktop\ipmgui.exe <====== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION HKU\S-1-5-21-185422420-646135407-2176989575-1000\...\Policies\Explorer: [NoDriveTypeAutoRun] 0xDD000000 HKU\S-1-5-21-185422420-646135407-2176989575-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-185422420-646135407-2176989575-1000\...\MountPoints2: J - J:\LaunchU3.exe -a HKU\S-1-5-21-185422420-646135407-2176989575-1000\...\MountPoints2: {501196bf-f412-11e1-b745-bc5ff41e006f} - H:\LaunchU3.exe -a HKU\S-1-5-21-185422420-646135407-2176989575-1000\...\MountPoints2: {57144ee5-cc4e-11e2-ae2d-0015833fb07e} - H:\LGAutoRun.exe AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => File Not Found IFEO\taskmgr.exe: [Debugger] C:\Program Files (x86)\TuneUp Utilities 2013\PMLauncher.exe Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Touch Mouse Server.lnk ShortcutTarget: Logitech Touch Mouse Server.lnk -> C:\Program Files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe (Logitech, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5777D5D7178ACD01 SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317741&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPA9713B57-2CEB-43C6-B7CE-77843CED26B4&q={searchTerms}&SSPV= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317741&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPA9713B57-2CEB-43C6-B7CE-77843CED26B4&q={searchTerms}&SSPV= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.5&ts=1372136646390&tguid=46364-3869-1372136646390-CE06C5498458038F4CF1B9A31AFE1AC3&q={searchTerms} SearchScopes: HKCU - {98C9AE5B-3C2B-45a5-AEF5-47B585F0B5DD} URL = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: HistoryTriggerBHO Class - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 82.212.62.62 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default FF user.js: detected! => C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\user.js FF SelectedSearchEngine: Google FF Homepage: about:home FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com')%20%7B%20return%20'PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxMate - Proxy on steroids! - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-06-28] FF Extension: Adblock Plus - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-28] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-12-28] Chrome: ======= CHR HomePage: hxxp://search.conduit.com/?ctid=CT3317741&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPA9713B57-2CEB-43C6-B7CE-77843CED26B4&SSPV= CHR Extension: (Google Docs) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-01] CHR Extension: (Google Drive) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-01] CHR Extension: (YouTube) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-01] CHR Extension: (Adblock Plus) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-17] CHR Extension: (Google-Suche) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-01] CHR Extension: (avast! Online Security) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-11] CHR Extension: (Google Wallet) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-01] CHR Extension: (Lavasoft NewTab) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole [2014-01-01] CHR Extension: (Google Mail) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-01] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-12-28] CHR HKLM-x32\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx [2013-08-08] ==================== Services (Whitelisted) ================= R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-28] (AVAST Software) S4 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () R2 HiPatchService; d:\gamezone\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-03] (Hi-Rez Studios) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2365792 2012-09-19] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.) S3 AndNetDiag2; C:\Windows\System32\DRIVERS\lgandnetdiag264.sys [29696 2013-04-18] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.) S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93696 2013-04-23] (LG Electronics Inc.) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-19] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-28] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-28] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-19] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-19] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-28] () R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-02-19] (DT Soft Ltd) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-01-24] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-01-24] (FNet Co., Ltd.) S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-08-31] (GFI Software) R3 IOMap; C:\Windows\system32\drivers\IOMap64.sys [24824 2013-07-02] (ASUSTeK Computer Inc.) R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.) R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.) R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-02-19] (Duplex Secure Ltd.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-09-19] (TuneUp Software) S3 Andbus; system32\DRIVERS\lgandbus64.sys [X] S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X] S3 AndGps; system32\DRIVERS\lgandgps64.sys [X] S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X] S3 EverestDriver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X] S3 GPU-Z; \??\C:\Users\Jan\AppData\Local\Temp\GPU-Z.sys [X] R3 IesDrv; \??\C:\Windows\SysWOW64\Drivers\IesDrv.sys [X] S3 RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [X] S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-20 14:56 - 2014-02-20 14:56 - 00022445 _____ () C:\Users\Jan\Downloads\FRST.txt 2014-02-20 14:56 - 2014-02-20 14:56 - 00000000 ____D () C:\FRST 2014-02-20 14:30 - 2014-02-20 14:30 - 00000578 _____ () C:\Users\Jan\Downloads\defogger_disable.log 2014-02-20 14:30 - 2014-02-20 14:30 - 00000020 _____ () C:\Users\Jan\defogger_reenable 2014-02-20 14:26 - 2014-02-20 14:26 - 02153472 _____ (Farbar) C:\Users\Jan\Downloads\FRST64.exe 2014-02-20 14:26 - 2014-02-20 14:26 - 00380416 _____ () C:\Users\Jan\Downloads\Gmer-19357.exe 2014-02-20 14:25 - 2014-02-20 14:25 - 00050477 _____ () C:\Users\Jan\Downloads\Defogger.exe 2014-02-20 13:12 - 2014-02-20 13:12 - 02817354 _____ () C:\Users\Jan\Downloads\DCProSetup_15.zip 2014-02-20 13:12 - 2014-02-20 13:12 - 00001984 _____ () C:\Users\Jan\Desktop\Driver Cleaner Pro.lnk 2014-02-20 13:12 - 2014-02-20 13:12 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Cleaner Pro 2014-02-20 13:12 - 2014-02-20 13:12 - 00000000 ____D () C:\Program Files (x86)\Driver Cleaner Pro 2014-02-19 17:23 - 2014-02-19 17:23 - 00423981 _____ () C:\Users\Jan\Downloads\myspace-music-downloader_21456.zip 2014-02-19 15:03 - 2014-02-19 15:03 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Iggels 2014-02-19 15:02 - 2014-02-19 15:02 - 00423981 _____ () C:\Users\Jan\Downloads\MyMusicDownloader.zip 2014-02-19 15:02 - 2014-02-19 15:02 - 00000000 ____D () C:\MyMusic Downloader 2014-02-19 12:40 - 2014-02-19 12:40 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-02-19 12:40 - 2014-02-08 17:18 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-02-19 12:37 - 2014-02-08 19:34 - 31432480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 23683360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 15740232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 14669032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 12324640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-19 12:37 - 2014-02-08 19:34 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433489.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433489.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00875296 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00844576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00483104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00408352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00378656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00148528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-02-19 12:31 - 2013-07-02 16:29 - 00024824 _____ (ASUSTeK Computer Inc.) C:\Windows\system32\Drivers\IOMap64.sys 2014-02-19 12:27 - 2014-02-19 12:29 - 00002252 _____ () C:\Windows\logboot_19.02.2014.tureg.log 2014-02-19 11:27 - 2014-02-19 11:27 - 01031147 _____ (Zero Assumption Software ) C:\Users\Jan\Downloads\vis12setup.exe 2014-02-19 11:27 - 2014-02-19 11:27 - 00000000 ____D () C:\Program Files (x86)\Disk Space Visualizer 2014-02-19 11:18 - 2014-02-19 11:23 - 276927952 _____ (NVIDIA Corporation) C:\Users\Jan\Downloads\334.89-desktop-win8-win7-winvista-64bit-international-whql.exe 2014-02-19 11:13 - 2014-02-19 11:13 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-19 11:12 - 2014-02-19 11:12 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-19 11:12 - 2014-02-19 11:12 - 00000000 ____D () C:\ProgramData\Sun 2014-02-19 11:11 - 2014-02-19 11:11 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-19 11:09 - 2014-02-19 11:09 - 00921000 _____ (Oracle Corporation) C:\Users\Jan\Downloads\jxpiinstall.exe 2014-02-18 10:42 - 2013-12-18 19:30 - 00005552 _____ () C:\Users\Jan\Desktop\engine_config.xml 2014-02-18 10:23 - 2013-12-17 18:56 - 00001443 _____ () C:\Users\Jan\Desktop\paths.xml 2014-02-18 10:19 - 2014-02-18 10:19 - 00719500 _____ () C:\Users\Jan\Downloads\Carnival1.1.0.zip 2014-02-17 16:54 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-02-17 16:54 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-02-17 16:34 - 2014-02-17 16:34 - 00000022 _____ () C:\Windows\GPU-Z.INI 2014-02-12 15:02 - 2014-02-17 16:55 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA Corporation 2014-02-12 14:58 - 2014-02-19 12:43 - 00001356 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2014-02-12 14:51 - 2014-02-12 20:37 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA 2014-02-12 14:51 - 2014-02-05 10:31 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-02-12 14:51 - 2014-02-05 10:30 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-02-12 14:50 - 2014-02-20 14:31 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-12 14:49 - 2014-02-08 18:42 - 06712608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 03498272 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 00923936 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-12 14:49 - 2014-02-08 18:42 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-12 14:49 - 2014-02-05 18:52 - 03573739 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-12 14:47 - 2013-12-27 19:42 - 00035104 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-02-12 14:47 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-02-12 14:47 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-02-12 14:47 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 18257576 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 17715784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 03090184 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 02713728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\OLDE361.tmp 2014-02-12 14:37 - 2014-02-08 19:34 - 02713728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 00947296 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-02-12 14:37 - 2013-12-19 21:33 - 18310112 _____ (NVIDIA Corporation) C:\Windows\system32\SETB7AF.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\SET888B.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 15230352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\SETCFAE.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 03071656 _____ (NVIDIA Corporation) C:\Windows\system32\SET7CA3.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 02698272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\SETBDFC.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll 2014-02-12 14:37 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll 2014-02-12 14:37 - 2013-12-19 21:33 - 01436528 _____ (NVIDIA Corporation) C:\Windows\system32\SETAEE7.tmp 2014-02-12 14:26 - 2014-02-19 12:40 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-12 14:26 - 2014-02-12 20:37 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-12 14:26 - 2014-02-12 14:51 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-12 03:02 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 03:02 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 03:01 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 03:01 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 03:01 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 03:01 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 03:01 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 03:01 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-12 03:01 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 03:01 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 03:01 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 03:01 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 03:01 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-12 03:01 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-12 03:01 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-12 03:01 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 03:01 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-12 03:01 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 03:01 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 03:01 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-12 03:01 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-12 03:01 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-12 03:01 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 03:01 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-12 03:01 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-12 03:01 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 03:01 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-12 03:01 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-12 03:01 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-12 03:01 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-12 03:01 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-12 03:01 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 03:01 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 03:01 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-12 03:01 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-12 03:01 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-12 03:01 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 03:01 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-12 03:01 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-12 03:01 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-12 03:01 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 01:05 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 01:05 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 01:05 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 01:05 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 01:05 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 01:05 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 01:05 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 01:05 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 01:05 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 01:05 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 01:05 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 01:05 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 01:05 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 01:05 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 01:05 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 01:05 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 01:05 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 01:05 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 01:05 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 01:05 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 01:05 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 01:05 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 01:05 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 01:05 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 22:15 - 2014-02-11 22:00 - 179891296 _____ () C:\auftritt.avi 2014-02-11 09:48 - 2014-02-11 21:27 - 00004001 _____ () C:\Users\Jan\Desktop\Unbenannt.vpj 2014-02-10 22:55 - 2014-02-10 22:55 - 00001052 _____ () C:\Users\Public\Desktop\ASUS GPU Tweak.lnk 2014-02-10 22:55 - 2014-02-10 22:55 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS 2014-02-10 22:55 - 2014-02-10 22:55 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-02-10 22:53 - 2014-02-10 22:53 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-02-10 22:52 - 2014-01-07 14:16 - 00000000 ____D () C:\GPUTweak_2_5_2 2014-02-07 22:37 - 2014-02-07 22:37 - 00000000 _____ () C:\Users\Jan\Desktop\Neues Textdokument (2).txt 2014-02-06 11:07 - 2014-02-17 09:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-01 18:05 - 2014-02-01 18:05 - 00262144 ____N () C:\Windows\Minidump\020114-16645-01.dmp 2014-01-30 22:57 - 2014-02-10 21:52 - 00000003 _____ () C:\Windows\system32\HRUPPROG.TXT 2014-01-30 22:57 - 2014-01-30 22:57 - 00000003 _____ () C:\Windows\system32\HRUPPROG.DIE.NOW 2014-01-27 16:53 - 2014-01-27 16:53 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\AVAST Software 2014-01-27 11:49 - 2014-02-18 17:09 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\DropboxMaster 2014-01-27 11:49 - 2014-01-27 11:49 - 00001046 _____ () C:\Users\Jan\Desktop\Dropbox.lnk 2014-01-27 11:48 - 2014-01-27 11:48 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-27 11:47 - 2014-02-20 14:33 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Dropbox 2014-01-25 19:24 - 2014-01-26 12:00 - 00000897 _____ () C:\Users\Jan\Desktop\texteimer.txt 2014-01-25 13:39 - 2014-01-25 13:39 - 00000000 ____D () C:\Users\Jan\MediaFire 2014-01-25 13:17 - 2013-12-06 17:42 - 00020696 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\mfmonitor_x64.sys 2014-01-25 13:12 - 2014-01-25 13:12 - 00000000 _____ () C:\Windows\winstart.INI 2014-01-25 13:06 - 2014-01-25 13:31 - 00000237 _____ () C:\Windows\ODBCINST.INI 2014-01-25 13:06 - 2014-01-25 13:31 - 00000000 ____D () C:\ProgramData\Actian 2014-01-25 08:39 - 2014-01-25 08:39 - 00000000 ____D () C:\Users\Jan\Documents\VideoPad Projekte 2014-01-24 15:03 - 2014-01-24 15:03 - 00005417 _____ () C:\Users\Jan\Documents\pehpel.xps 2014-01-24 14:16 - 2014-01-24 14:16 - 00069344 _____ (FNet Co., Ltd.) C:\Windows\system32\TurboShell_105.dll 2014-01-24 14:16 - 2014-01-24 14:16 - 00001894 _____ () C:\Users\Public\Desktop\XFast USB.LNK 2014-01-24 14:16 - 2014-01-24 14:16 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\FNET 2014-01-24 14:16 - 2014-01-24 14:16 - 00000000 ____D () C:\Program Files (x86)\XFastUSB 2014-01-24 14:03 - 2014-01-24 14:03 - 00001167 _____ () C:\Users\Public\Desktop\Golden Videos.lnk 2014-01-24 14:02 - 2014-01-24 14:02 - 00001165 _____ () C:\Users\Public\Desktop\VideoPad Video-Editor.lnk 2014-01-24 13:58 - 2014-01-24 13:59 - 00000000 ____D () C:\Users\Jan\Desktop\ebay 2014-01-24 10:08 - 2014-01-24 10:08 - 00001371 _____ () C:\Users\Public\Desktop\Free Video Flip and Rotate.lnk 2014-01-24 10:08 - 2014-01-24 10:08 - 00001248 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2014-01-24 10:08 - 2014-01-24 10:08 - 00000000 ____D () C:\Users\Jan\Documents\DVDVideoSoft 2014-01-24 10:08 - 2014-01-24 10:08 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\DVDVideoSoft 2014-01-24 10:08 - 2014-01-24 10:08 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-01-24 08:51 - 2014-01-31 14:03 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2014-01-24 08:51 - 2014-01-31 14:03 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\NCH Software 2014-01-24 08:51 - 2014-01-31 14:03 - 00000000 ____D () C:\ProgramData\NCH Software 2014-01-24 08:51 - 2014-01-24 14:03 - 00000000 ____D () C:\Program Files (x86)\NCH Software 2014-01-24 08:51 - 2014-01-24 08:51 - 00001137 _____ () C:\Users\Public\Desktop\Prism Videodatei-Konverter.lnk 2014-01-23 22:39 - 2014-02-11 22:11 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\vlc 2014-01-23 22:33 - 2014-01-23 22:33 - 00001899 _____ () C:\Users\Jan\Desktop\IrfanView Thumbnails.lnk ==================== One Month Modified Files and Folders ======= 2014-02-20 14:56 - 2014-02-20 14:56 - 00022445 _____ () C:\Users\Jan\Downloads\FRST.txt 2014-02-20 14:56 - 2014-02-20 14:56 - 00000000 ____D () C:\FRST 2014-02-20 14:52 - 2013-12-21 13:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-20 14:39 - 2009-07-14 05:45 - 00016896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-20 14:39 - 2009-07-14 05:45 - 00016896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-20 14:35 - 2012-09-02 10:25 - 01509367 _____ () C:\Windows\WindowsUpdate.log 2014-02-20 14:33 - 2014-01-27 11:47 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Dropbox 2014-02-20 14:33 - 2013-12-28 15:00 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-20 14:31 - 2014-02-12 14:50 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-20 14:31 - 2013-09-22 16:03 - 00043495 _____ () C:\Windows\setupact.log 2014-02-20 14:31 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-20 14:30 - 2014-02-20 14:30 - 00000578 _____ () C:\Users\Jan\Downloads\defogger_disable.log 2014-02-20 14:30 - 2014-02-20 14:30 - 00000020 _____ () C:\Users\Jan\defogger_reenable 2014-02-20 14:30 - 2013-09-20 20:19 - 00000000 ____D () C:\mehl 2014-02-20 14:30 - 2012-09-01 09:03 - 00000000 ____D () C:\Users\Jan 2014-02-20 14:26 - 2014-02-20 14:26 - 02153472 _____ (Farbar) C:\Users\Jan\Downloads\FRST64.exe 2014-02-20 14:26 - 2014-02-20 14:26 - 00380416 _____ () C:\Users\Jan\Downloads\Gmer-19357.exe 2014-02-20 14:25 - 2014-02-20 14:25 - 00050477 _____ () C:\Users\Jan\Downloads\Defogger.exe 2014-02-20 13:12 - 2014-02-20 13:12 - 02817354 _____ () C:\Users\Jan\Downloads\DCProSetup_15.zip 2014-02-20 13:12 - 2014-02-20 13:12 - 00001984 _____ () C:\Users\Jan\Desktop\Driver Cleaner Pro.lnk 2014-02-20 13:12 - 2014-02-20 13:12 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Driver Cleaner Pro 2014-02-20 13:12 - 2014-02-20 13:12 - 00000000 ____D () C:\Program Files (x86)\Driver Cleaner Pro 2014-02-20 12:45 - 2012-09-07 06:00 - 00000000 ____D () C:\Users\Jan\AppData\Local\CrashDumps 2014-02-20 10:29 - 2013-02-23 14:05 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2014-02-20 00:28 - 2012-09-02 15:50 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\foobar2000 2014-02-19 22:14 - 2013-09-22 16:03 - 00049342 _____ () C:\Windows\PFRO.log 2014-02-19 17:23 - 2014-02-19 17:23 - 00423981 _____ () C:\Users\Jan\Downloads\myspace-music-downloader_21456.zip 2014-02-19 15:03 - 2014-02-19 15:03 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Iggels 2014-02-19 15:02 - 2014-02-19 15:02 - 00423981 _____ () C:\Users\Jan\Downloads\MyMusicDownloader.zip 2014-02-19 15:02 - 2014-02-19 15:02 - 00000000 ____D () C:\MyMusic Downloader 2014-02-19 12:43 - 2014-02-12 14:58 - 00001356 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2014-02-19 12:40 - 2014-02-19 12:40 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-02-19 12:40 - 2014-02-12 14:26 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-19 12:29 - 2014-02-19 12:27 - 00002252 _____ () C:\Windows\logboot_19.02.2014.tureg.log 2014-02-19 12:29 - 2009-07-14 03:34 - 77332480 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old 2014-02-19 12:29 - 2009-07-14 03:34 - 25427968 _____ () C:\Windows\system32\config\SYSTEM_tureg_old 2014-02-19 12:29 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY_tureg_old 2014-02-19 12:27 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT_tureg_old 2014-02-19 12:27 - 2009-07-14 03:34 - 00032768 _____ () C:\Windows\system32\config\SAM_tureg_old 2014-02-19 12:05 - 2013-12-28 15:00 - 00001975 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-19 12:04 - 2013-12-28 15:00 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-19 12:04 - 2013-12-28 15:00 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-19 11:27 - 2014-02-19 11:27 - 01031147 _____ (Zero Assumption Software ) C:\Users\Jan\Downloads\vis12setup.exe 2014-02-19 11:27 - 2014-02-19 11:27 - 00000000 ____D () C:\Program Files (x86)\Disk Space Visualizer 2014-02-19 11:23 - 2014-02-19 11:18 - 276927952 _____ (NVIDIA Corporation) C:\Users\Jan\Downloads\334.89-desktop-win8-win7-winvista-64bit-international-whql.exe 2014-02-19 11:13 - 2014-02-19 11:13 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-19 11:12 - 2014-02-19 11:12 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-19 11:12 - 2014-02-19 11:12 - 00000000 ____D () C:\ProgramData\Sun 2014-02-19 11:11 - 2014-02-19 11:11 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-19 11:09 - 2014-02-19 11:09 - 00921000 _____ (Oracle Corporation) C:\Users\Jan\Downloads\jxpiinstall.exe 2014-02-18 17:09 - 2014-01-27 11:49 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\DropboxMaster 2014-02-18 10:19 - 2014-02-18 10:19 - 00719500 _____ () C:\Users\Jan\Downloads\Carnival1.1.0.zip 2014-02-17 19:24 - 2012-09-07 09:57 - 00000000 ____D () C:\Program Files (x86)\AMD APP 2014-02-17 19:23 - 2012-09-07 09:48 - 00000000 ____D () C:\ProgramData\AMD 2014-02-17 19:05 - 2013-03-19 16:40 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-17 19:05 - 2013-03-19 16:40 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-17 19:05 - 2012-10-13 03:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-17 16:55 - 2014-02-12 15:02 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA Corporation 2014-02-17 16:34 - 2014-02-17 16:34 - 00000022 _____ () C:\Windows\GPU-Z.INI 2014-02-17 09:45 - 2014-02-06 11:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-17 01:42 - 2013-03-19 16:40 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-17 01:42 - 2013-03-19 16:40 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-16 03:00 - 2012-09-04 07:46 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-12 20:37 - 2014-02-12 14:51 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA 2014-02-12 20:37 - 2014-02-12 14:26 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-12 14:51 - 2014-02-12 14:26 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-12 14:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help 2014-02-12 14:27 - 2013-02-23 23:07 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-02-12 14:27 - 2012-09-01 09:44 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\ATI 2014-02-12 14:27 - 2012-09-01 09:44 - 00000000 ____D () C:\Users\Jan\AppData\Local\ATI 2014-02-12 09:35 - 2009-07-14 18:58 - 00696832 _____ () C:\Windows\system32\perfh007.dat 2014-02-12 09:35 - 2009-07-14 18:58 - 00148128 _____ () C:\Windows\system32\perfc007.dat 2014-02-12 09:35 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-12 03:15 - 2013-09-19 17:41 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-12 03:14 - 2013-06-26 08:17 - 01590298 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-12 03:02 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini 2014-02-11 22:11 - 2014-01-23 22:39 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\vlc 2014-02-11 22:00 - 2014-02-11 22:15 - 179891296 _____ () C:\auftritt.avi 2014-02-11 21:27 - 2014-02-11 09:48 - 00004001 _____ () C:\Users\Jan\Desktop\Unbenannt.vpj 2014-02-10 22:55 - 2014-02-10 22:55 - 00001052 _____ () C:\Users\Public\Desktop\ASUS GPU Tweak.lnk 2014-02-10 22:55 - 2014-02-10 22:55 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASUS 2014-02-10 22:55 - 2014-02-10 22:55 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-02-10 22:55 - 2012-09-01 09:40 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-02-10 22:53 - 2014-02-10 22:53 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-02-10 22:46 - 2013-02-01 15:50 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\dvdcss 2014-02-10 21:52 - 2014-01-30 22:57 - 00000003 _____ () C:\Windows\system32\HRUPPROG.TXT 2014-02-08 19:34 - 2014-02-19 12:37 - 31432480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 23683360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 15740232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 14669032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 12324640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-08 19:34 - 2014-02-19 12:37 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433489.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433489.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00875296 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00844576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00483104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00408352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00378656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00148528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 18257576 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 17715784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 03090184 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 02713728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\OLDE361.tmp 2014-02-08 19:34 - 2014-02-12 14:37 - 02713728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 00947296 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-02-08 19:34 - 2013-10-27 09:12 - 00024544 _____ () C:\Windows\system32\nvinfo.pb 2014-02-08 19:34 - 2012-12-19 15:34 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-02-08 19:34 - 2012-12-19 15:34 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 06712608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 03498272 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 00923936 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-08 18:42 - 2014-02-12 14:49 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-08 17:18 - 2014-02-19 12:40 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-02-07 22:37 - 2014-02-07 22:37 - 00000000 _____ () C:\Users\Jan\Desktop\Neues Textdokument (2).txt 2014-02-07 09:29 - 2013-12-20 19:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak 2014-02-06 13:16 - 2014-02-12 03:01 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-12 03:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-12 03:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-12 03:01 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-12 03:01 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-12 03:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-12 03:01 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-12 03:01 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-12 03:01 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-12 03:01 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-12 03:01 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-12 03:01 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-12 03:01 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-12 03:01 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-12 03:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-12 03:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-12 03:01 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-12 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-12 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-12 03:01 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-12 03:01 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-12 03:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-12 03:01 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-12 03:01 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-12 03:01 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-12 03:01 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-12 03:01 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-12 03:01 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-12 03:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-12 03:01 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-12 03:01 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-12 03:01 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-12 03:01 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-12 03:01 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-12 03:01 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-12 03:01 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-12 03:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-12 03:01 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-12 03:01 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-05 19:52 - 2013-12-21 13:10 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-05 19:52 - 2012-09-05 08:53 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-05 19:52 - 2012-09-05 08:53 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-05 18:52 - 2014-02-12 14:49 - 03573739 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-05 10:31 - 2014-02-12 14:51 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-02-05 10:30 - 2014-02-12 14:51 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-02-04 09:11 - 2014-01-01 21:41 - 00002184 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-01 18:05 - 2014-02-01 18:05 - 00262144 ____N () C:\Windows\Minidump\020114-16645-01.dmp 2014-02-01 18:05 - 2012-11-22 16:05 - 00000000 ____D () C:\Windows\Minidump 2014-01-31 14:03 - 2014-01-24 08:51 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2014-01-31 14:03 - 2014-01-24 08:51 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\NCH Software 2014-01-31 14:03 - 2014-01-24 08:51 - 00000000 ____D () C:\ProgramData\NCH Software 2014-01-30 22:57 - 2014-01-30 22:57 - 00000003 _____ () C:\Windows\system32\HRUPPROG.DIE.NOW 2014-01-27 16:53 - 2014-01-27 16:53 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\AVAST Software 2014-01-27 11:49 - 2014-01-27 11:49 - 00001046 _____ () C:\Users\Jan\Desktop\Dropbox.lnk 2014-01-27 11:49 - 2012-09-01 09:03 - 00000000 ___RD () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-27 11:48 - 2014-01-27 11:48 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-26 13:41 - 2012-09-02 02:45 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\uTorrent 2014-01-26 12:00 - 2014-01-25 19:24 - 00000897 _____ () C:\Users\Jan\Desktop\texteimer.txt 2014-01-26 11:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-01-25 23:53 - 2013-03-08 14:46 - 00000000 ____D () C:\Users\Jan\AppData\Local\PMB Files 2014-01-25 23:53 - 2012-11-10 15:01 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Skype 2014-01-25 13:39 - 2014-01-25 13:39 - 00000000 ____D () C:\Users\Jan\MediaFire 2014-01-25 13:36 - 2013-09-22 16:03 - 00441136 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-25 13:31 - 2014-01-25 13:06 - 00000237 _____ () C:\Windows\ODBCINST.INI 2014-01-25 13:31 - 2014-01-25 13:06 - 00000000 ____D () C:\ProgramData\Actian 2014-01-25 13:31 - 2013-09-22 08:44 - 00117776 _____ () C:\Users\Jan\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-25 13:12 - 2014-01-25 13:12 - 00000000 _____ () C:\Windows\winstart.INI 2014-01-25 08:57 - 2014-01-11 15:13 - 00000939 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk 2014-01-25 08:57 - 2014-01-11 15:13 - 00000000 ____D () C:\Program Files\Calibre2 2014-01-25 08:39 - 2014-01-25 08:39 - 00000000 ____D () C:\Users\Jan\Documents\VideoPad Projekte 2014-01-24 15:03 - 2014-01-24 15:03 - 00005417 _____ () C:\Users\Jan\Documents\pehpel.xps 2014-01-24 14:16 - 2014-01-24 14:16 - 00069344 _____ (FNet Co., Ltd.) C:\Windows\system32\TurboShell_105.dll 2014-01-24 14:16 - 2014-01-24 14:16 - 00001894 _____ () C:\Users\Public\Desktop\XFast USB.LNK 2014-01-24 14:16 - 2014-01-24 14:16 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\FNET 2014-01-24 14:16 - 2014-01-24 14:16 - 00000000 ____D () C:\Program Files (x86)\XFastUSB 2014-01-24 14:16 - 2012-09-01 10:44 - 00032320 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETTBOH_305.SYS 2014-01-24 14:16 - 2012-09-01 09:46 - 00016648 _____ (FNet Co., Ltd.) C:\Windows\system32\Drivers\FNETURPX.SYS 2014-01-24 14:16 - 2012-09-01 09:46 - 00000000 ____D () C:\ProgramData\FNET 2014-01-24 14:03 - 2014-01-24 14:03 - 00001167 _____ () C:\Users\Public\Desktop\Golden Videos.lnk 2014-01-24 14:03 - 2014-01-24 08:51 - 00000000 ____D () C:\Program Files (x86)\NCH Software 2014-01-24 14:02 - 2014-01-24 14:02 - 00001165 _____ () C:\Users\Public\Desktop\VideoPad Video-Editor.lnk 2014-01-24 13:59 - 2014-01-24 13:58 - 00000000 ____D () C:\Users\Jan\Desktop\ebay 2014-01-24 10:08 - 2014-01-24 10:08 - 00001371 _____ () C:\Users\Public\Desktop\Free Video Flip and Rotate.lnk 2014-01-24 10:08 - 2014-01-24 10:08 - 00001248 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2014-01-24 10:08 - 2014-01-24 10:08 - 00000000 ____D () C:\Users\Jan\Documents\DVDVideoSoft 2014-01-24 10:08 - 2014-01-24 10:08 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\DVDVideoSoft 2014-01-24 10:08 - 2014-01-24 10:08 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-01-24 08:51 - 2014-01-24 08:51 - 00001137 _____ () C:\Users\Public\Desktop\Prism Videodatei-Konverter.lnk 2014-01-23 22:36 - 2013-06-28 18:43 - 00000000 ____D () C:\Users\Jan\AppData\Local\Adobe 2014-01-23 22:35 - 2013-09-21 15:20 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-01-23 22:35 - 2013-09-21 15:20 - 00000000 ____D () C:\Program Files\WinRAR 2014-01-23 22:33 - 2014-01-23 22:33 - 00001899 _____ () C:\Users\Jan\Desktop\IrfanView Thumbnails.lnk 2014-01-23 22:33 - 2013-10-11 22:48 - 00001075 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-01-23 22:33 - 2012-09-04 09:10 - 00001007 _____ () C:\Users\Jan\Desktop\IrfanView.lnk 2014-01-23 22:33 - 2012-09-04 09:10 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView Some content of TEMP: ==================== C:\Users\Jan\AppData\Local\Temp\devcon.exe C:\Users\Jan\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptzt6qy.dll C:\Users\Jan\AppData\Local\Temp\nvStInst.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 11:32 ==================== End Of Log ============================ |
21.02.2014, 07:47 | #4 |
| Win7 Computer geht seit ein paar Tagen massiv "in die Knie" GMER.txt Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-02-20 15:15:34 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 WDC_WD5000AAKX-001CA0 rev.15.01H15 465.76GB Running: Gmer-19357.exe; Driver: C:\Users\Jan\AppData\Local\Temp\pfrdipod.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\System32\win32k.sys!EngSetLastError + 608 fffff96000174b94 8 bytes [2C, B6, A9, 03, 80, F8, FF, ...] .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff960001a3e00 7 bytes [00, 96, F3, FF, 01, A1, F0] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff960001a3e08 3 bytes [C0, 06, 02] .text ... * 107 .text C:\Windows\System32\win32k.sys!EngGetProcessHandle + 404 fffff96000262b28 6 bytes {JMP QWORD [RIP-0xba4d6]} ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\wininit.exe[496] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\services.exe[560] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\winlogon.exe[648] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[732] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\nvvsvc.exe[808] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[832] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Windows\system32\atiesrxx.exe[956] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[1004] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[228] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[296] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[320] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1172] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1428] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\nvvsvc.exe[1436] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\Explorer.EXE[1680] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\System32\spoolsv.exe[1740] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1840] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\taskhost.exe[1884] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\SysWOW64\ASGT.exe[860] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files (x86)\Bonjour\mDNSResponder.exe[1536] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text d:\gamezone\Hi-Rez Studios\HiPatchService.exe[1860] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[1416] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2080] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2128] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[2168] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2232] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\conhost.exe[2240] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2376] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2376] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074f81465 2 bytes [F8, 74] .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2376] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074f814bb 2 bytes [F8, 74] .text ... * 2 .text C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe[2400] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe[2400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074f81465 2 bytes [F8, 74] .text C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe[2400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074f814bb 2 bytes [F8, 74] .text ... * 2 .text C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2516] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2820] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[3260] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe[3428] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe[3428] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000074f81465 2 bytes [F8, 74] .text C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe[3428] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 0000000074f814bb 2 bytes [F8, 74] .text ... * 2 .text C:\Windows\system32\SearchIndexer.exe[3460] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[3780] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe[3968] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3352] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1128] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe[4192] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe[4816] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe[4816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074f81465 2 bytes [F8, 74] .text C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe[4816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074f814bb 2 bytes [F8, 74] .text ... * 2 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[4824] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe[4900] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe[4900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074f81465 2 bytes [F8, 74] .text C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe[4900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074f814bb 2 bytes [F8, 74] .text ... * 2 .text C:\Program Files (x86)\XFastUSB\XFastUsb.exe[4908] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] .text C:\Windows\system32\AUDIODG.EXE[4296] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189 0000000076d5eecd 1 byte [62] .text C:\Users\Jan\Downloads\Gmer-19357.exe[1824] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000750fa2ba 1 byte [62] ---- Threads - GMER 2.1 ---- Thread C:\Windows\System32\svchost.exe [3928:4020] 000007feea479688 ---- Processes - GMER 2.1 ---- Library C:\Users\Jan\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe [3428](2013-12-18 02:25:54) 00000000039b0000 Library c:\users\jan\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptzt6qy.dll (*** suspicious ***) @ C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe [3428](2014-02-20 13:32:31) 0000000002db0000 Library C:\Users\Jan\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe [3428](2013-10-18 23:55:02) 000000006c640000 Library C:\Users\Jan\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe [3428] (ICU Data DLL/The ICU Project)(2013-10-18 23:55:00) 000000006bcb0000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0015833fb07e Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0015833fb07e@70051454fa08 0xD4 0x8E 0xAA 0xE8 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x52 0xA5 0x37 0x5B ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x69 0x65 0xBA 0xF9 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x94 0xA9 0x3A 0x8D ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0015833fb07e (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0015833fb07e@70051454fa08 0xD4 0x8E 0xAA 0xE8 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x52 0xA5 0x37 0x5B ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x69 0x65 0xBA 0xF9 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x94 0xA9 0x3A 0x8D ... Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Jan\AppData\Local\Logitech\xae Webcam-Software\Logishrd\LU2.0\LogitechUpdate.exe 1 ---- EOF - GMER 2.1 ---- |
22.02.2014, 12:57 | #5 |
/// the machine /// TB-Ausbilder | Win7 Computer geht seit ein paar Tagen massiv "in die Knie" hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.02.2014, 08:42 | #6 |
| Win7 Computer geht seit ein paar Tagen massiv "in die Knie"Code:
ATTFilter ComboFix 14-02-24.02 - Jan 25.02.2014 8:30.2.2 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.4095.2124 [GMT 1:00] ausgeführt von:: c:\users\Jan\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-25 bis 2014-02-25 )))))))))))))))))))))))))))))) . . 2014-02-25 07:34 . 2014-02-25 07:34 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-25 07:20 . 2014-02-25 07:20 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1E610591-81B5-40DB-AE10-F6CDDCE636DE}\offreg.dll 2014-02-25 06:38 . 2014-02-25 06:38 -------- d-----w- c:\users\Jan\AppData\Roaming\Apple Computer 2014-02-25 06:38 . 2014-02-25 06:38 -------- d-----w- c:\users\Jan\AppData\Local\Apple Computer 2014-02-25 06:36 . 2014-02-25 06:37 -------- d-----w- c:\program files (x86)\Common Files\Apple 2014-02-25 06:13 . 2014-02-06 09:01 10536864 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1E610591-81B5-40DB-AE10-F6CDDCE636DE}\mpengine.dll 2014-02-24 20:37 . 2014-02-25 07:10 -------- d-----w- c:\users\Jan\AppData\Local\Audible 2014-02-24 20:37 . 2014-02-24 20:37 255352 ----a-w- c:\windows\SysWow64\awrdscdc.ax 2014-02-24 20:37 . 2003-03-18 20:20 1060864 ------w- c:\windows\SysWow64\mfc71.dll 2014-02-24 20:37 . 2003-03-18 19:14 499712 ------w- c:\windows\SysWow64\msvcp71.dll 2014-02-24 20:37 . 2003-02-21 03:42 348160 ------w- c:\windows\SysWow64\msvcr71.dll 2014-02-24 20:37 . 2001-08-17 21:43 24576 ------w- c:\windows\SysWow64\msxml3a.dll 2014-02-24 20:37 . 2014-02-24 20:37 -------- d-----w- c:\program files (x86)\Audible 2014-02-23 19:40 . 2014-02-23 19:40 -------- dc-h--w- c:\programdata\{1F992D7B-8BF0-4A62-9EA8-1CA890E8464D} 2014-02-23 15:24 . 2014-02-23 19:40 -------- d-----w- c:\program files\Golden Software 2014-02-23 15:24 . 2014-02-23 15:25 -------- dc-h--w- c:\programdata\{0E9B3B8F-4F9F-4852-B1F7-6ED22BEFCBAC} 2014-02-23 14:37 . 2014-02-23 14:37 -------- d-----w- c:\users\Jan\AppData\Roaming\Polar Engineering 2014-02-23 14:37 . 2014-02-23 19:40 -------- d-----w- c:\users\Jan\AppData\Roaming\Golden Software 2014-02-23 14:36 . 2014-02-23 14:36 -------- d-----w- c:\users\Jan\AppData\Local\PackageAware 2014-02-21 10:42 . 2014-02-21 10:43 -------- d-----w- c:\users\Jan\AppData\Local\Sony Online Entertainment 2014-02-21 09:22 . 2014-02-21 09:44 -------- d-----w- c:\users\Jan\AppData\Roaming\NVIDIA 2014-02-21 09:13 . 2014-02-24 11:49 -------- d-----w- c:\program files (x86)\MSI Afterburner 2014-02-21 09:13 . 2014-02-21 09:13 -------- d-----w- c:\program files (x86)\MSI Kombustor 2.5 2014-02-21 07:05 . 2014-02-21 11:22 -------- d-----w- c:\program files (x86)\GO2Bot 2014-02-20 13:56 . 2014-02-20 13:57 -------- d-----w- C:\FRST 2014-02-20 12:12 . 2014-02-20 12:12 -------- d-----w- c:\program files (x86)\Driver Cleaner Pro 2014-02-19 14:03 . 2014-02-19 14:03 -------- d-----w- c:\users\Jan\AppData\Roaming\Iggels 2014-02-19 14:02 . 2014-02-19 14:02 -------- d-----w- C:\MyMusic Downloader 2014-02-19 11:40 . 2014-02-19 11:40 -------- d-----w- c:\program files (x86)\AGEIA Technologies 2014-02-19 11:40 . 2014-02-08 16:18 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2014-02-19 10:27 . 2014-02-19 10:27 -------- d-----w- c:\program files (x86)\Disk Space Visualizer 2014-02-19 10:13 . 2014-02-19 10:13 -------- d-----w- c:\programdata\Oracle 2014-02-19 10:12 . 2014-02-19 10:12 -------- d-----w- c:\program files (x86)\Common Files\Java 2014-02-19 10:12 . 2014-02-19 10:12 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-02-19 10:11 . 2014-02-19 10:11 -------- d-----w- c:\program files (x86)\Java 2014-02-17 15:54 . 2013-12-27 18:42 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys 2014-02-17 15:54 . 2013-12-27 18:42 33056 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll 2014-02-12 14:02 . 2014-02-17 15:55 -------- d-----w- c:\users\Jan\AppData\Local\NVIDIA Corporation 2014-02-12 13:51 . 2014-02-05 09:31 1048152 ----a-w- c:\windows\SysWow64\nvspcap.dll 2014-02-12 13:51 . 2014-02-05 09:30 1179576 ----a-w- c:\windows\system32\nvspcap64.dll 2014-02-12 13:51 . 2014-02-12 19:37 -------- d-----w- c:\users\Jan\AppData\Local\NVIDIA 2014-02-12 13:50 . 2014-02-25 06:08 -------- d-----w- c:\programdata\NVIDIA 2014-02-12 13:49 . 2014-02-08 17:42 6712608 ----a-w- c:\windows\system32\nvcpl.dll 2014-02-12 13:49 . 2014-02-08 17:42 3498272 ----a-w- c:\windows\system32\nvsvc64.dll 2014-02-12 13:49 . 2014-02-08 17:42 923936 ----a-w- c:\windows\system32\nvvsvc.exe 2014-02-12 13:49 . 2014-02-08 17:42 63776 ----a-w- c:\windows\system32\nvshext.dll 2014-02-12 13:49 . 2014-02-08 17:42 386336 ----a-w- c:\windows\system32\nvmctray.dll 2014-02-12 13:49 . 2014-02-08 17:42 2559776 ----a-w- c:\windows\system32\nvsvcr.dll 2014-02-12 13:49 . 2014-02-05 17:52 3573739 ----a-w- c:\windows\system32\nvcoproc.bin 2014-02-12 13:47 . 2013-12-27 18:42 35104 ----a-w- c:\windows\system32\nvaudcap64v.dll 2014-02-12 13:47 . 2013-11-28 13:38 31520 ----a-w- c:\windows\system32\nvhdap64.dll 2014-02-12 13:47 . 2013-11-22 08:36 1515296 ----a-w- c:\windows\system32\nvhdagenco6420103.dll 2014-02-12 13:47 . 2013-11-28 13:38 197408 ----a-w- c:\windows\system32\drivers\nvhda64v.sys 2014-02-12 13:37 . 2014-02-08 18:34 947296 ----a-w- c:\windows\system32\nvumdshimx.dll 2014-02-12 13:37 . 2014-02-08 18:34 18257576 ----a-w- c:\windows\system32\nvwgf2umx.dll 2014-02-12 13:37 . 2013-12-19 20:33 18310112 ----a-w- c:\windows\system32\SETB7AF.tmp 2014-02-12 13:37 . 2013-12-19 20:33 1436528 ----a-w- c:\windows\system32\SETAEE7.tmp 2014-02-12 13:37 . 2014-02-08 18:34 3090184 ----a-w- c:\windows\system32\nvapi64.dll 2014-02-12 13:37 . 2014-02-08 18:34 2713728 ----a-w- c:\windows\SysWow64\nvapi.dll 2014-02-12 13:37 . 2014-02-08 18:34 17715784 ----a-w- c:\windows\system32\nvd3dumx.dll 2014-02-12 13:37 . 2013-12-19 20:33 3071656 ----a-w- c:\windows\system32\SET7CA3.tmp 2014-02-12 13:37 . 2013-12-19 20:33 1884448 ----a-w- c:\windows\system32\nvdispco6433221.dll 2014-02-12 13:37 . 2013-12-19 20:33 18222008 ----a-w- c:\windows\system32\SET888B.tmp 2014-02-12 13:37 . 2013-12-19 20:33 1511712 ----a-w- c:\windows\system32\nvdispgenco6433221.dll 2014-02-12 13:26 . 2014-02-12 19:37 -------- d-----w- c:\programdata\NVIDIA Corporation 2014-02-12 13:26 . 2014-02-19 11:40 -------- d-----w- c:\program files (x86)\NVIDIA Corporation 2014-02-12 13:26 . 2014-02-12 13:51 -------- d-----w- c:\program files\NVIDIA Corporation 2014-02-12 02:02 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll 2014-02-12 02:02 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-02-12 00:05 . 2013-12-06 02:30 1882112 ----a-w- c:\windows\system32\msxml3.dll 2014-02-10 21:55 . 2014-02-10 21:55 -------- d-----w- c:\program files (x86)\ASUS 2014-02-10 21:53 . 2014-02-10 21:53 -------- d-----w- c:\windows\Downloaded Installations 2014-02-10 21:52 . 2014-01-07 13:16 -------- d-----w- C:\GPUTweak_2_5_2 2014-01-27 15:53 . 2014-01-27 15:53 -------- d-----w- c:\users\Jan\AppData\Roaming\AVAST Software 2014-01-27 10:47 . 2014-02-25 06:10 -------- d-----w- c:\users\Jan\AppData\Roaming\Dropbox . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-02-21 14:53 . 2012-09-05 07:53 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-02-21 14:53 . 2012-09-05 07:53 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-02-19 11:04 . 2013-12-28 14:00 80184 ----a-w- c:\windows\system32\drivers\aswstm.sys 2014-02-19 11:04 . 2013-12-28 14:00 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2014-02-19 11:04 . 2013-12-28 14:00 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys 2014-02-19 11:04 . 2013-12-28 14:00 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2014-02-19 11:04 . 2013-12-28 14:00 334136 ----a-w- c:\windows\system32\aswBoot.exe 2014-02-19 11:04 . 2013-12-28 14:00 43152 ----a-w- c:\windows\avastSS.scr 2014-02-16 02:00 . 2012-09-04 06:46 88567024 ----a-w- c:\windows\system32\MRT.exe 2014-02-08 18:34 . 2012-12-19 14:34 61216 ----a-w- c:\windows\system32\OpenCL.dll 2014-02-08 18:34 . 2012-12-19 14:34 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll 2014-01-25 12:17 . 2014-01-25 12:17 1409 ----a-w- c:\windows\Fonts\OpenSans-Regular.fot 2014-01-25 12:17 . 2014-01-25 12:17 1409 ----a-w- c:\windows\Fonts\OpenSans-Light.fot 2014-01-25 12:17 . 2014-01-25 12:17 1409 ----a-w- c:\windows\Fonts\OpenSans-Bold.fot 2014-01-24 13:16 . 2014-01-24 13:16 69344 ----a-w- c:\windows\system32\TurboShell_105.dll 2014-01-24 13:16 . 2012-09-01 09:44 32320 ----a-w- c:\windows\system32\drivers\FNETTBOH_305.SYS 2014-01-24 13:16 . 2012-09-01 08:46 16648 ----a-w- c:\windows\system32\drivers\FNETURPX.SYS 2013-12-28 14:00 . 2013-12-28 14:00 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-12-28 14:00 . 2013-12-28 14:00 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-12-28 14:00 . 2013-12-28 14:00 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-12-18 05:13 . 2012-09-01 10:58 270496 ------w- c:\windows\system32\MpSigStub.exe 2013-12-06 16:42 . 2014-01-25 12:17 20696 ----a-w- c:\windows\system32\drivers\mfmonitor_x64.sys 2013-11-30 18:15 . 2013-11-30 18:15 53248 ----a-r- c:\users\Jan\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Jan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Jan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Jan\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 89184] "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2012-09-12 204136] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-28 3764024] "XFastUSB"="c:\program files (x86)\XFastUSB\XFastUsb.exe" [2014-01-24 6311104] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-02-06 152392] . c:\users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ CurseClientStartup.ccip [2013-10-18 0] Dropbox.lnk - c:\users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-1-3 33508336] Logitech Touch Mouse Server.lnk - c:\program files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe [2009-10-23 178688] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "XFast USB"=c:\program files (x86)\XFast USB\XFastUsb.exe . R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys;c:\windows\SYSNATIVE\drivers\SBREdrv.sys [x] R2 ASGT;ASGT;c:\windows\SysWOW64\ASGT.exe;c:\windows\SysWOW64\ASGT.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x] R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandbus64.sys [x] R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lganddiag64.sys [x] R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandgps64.sys [x] R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandmodem64.sys [x] R3 andnetadb;ADB Interface DriverNet;c:\windows\system32\Drivers\lgandnetadb.sys;c:\windows\SYSNATIVE\Drivers\lgandnetadb.sys [x] R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x] R3 AndNetDiag2;LGE AndroidNet For Diagnostics Port;c:\windows\system32\DRIVERS\lgandnetdiag264.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag264.sys [x] R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x] R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetndis64.sys [x] R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] R3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64;c:\program files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [x] R3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys;c:\windows\SYSNATIVE\drivers\gfiark.sys [x] R3 GPU-Z;GPU-Z;c:\users\Jan\AppData\Local\Temp\GPU-Z.sys;c:\users\Jan\AppData\Local\Temp\GPU-Z.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x] R3 LVUVC64;Logitech HD Webcam C270(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] R4 DokanMounter;DokanMounter;c:\program files (x86)\Dokan\DokanLibrary\mounter.exe;c:\program files (x86)\Dokan\DokanLibrary\mounter.exe [x] R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Dokan;Dokan;c:\windows\system32\drivers\dokan.sys;c:\windows\SYSNATIVE\drivers\dokan.sys [x] S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;d:\gamezone\Hi-Rez Studios\HiPatchService.exe;d:\gamezone\Hi-Rez Studios\HiPatchService.exe [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x] S3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x] S3 IesDrv;IesDrv;c:\windows\SysWOW64\Drivers\IesDrv.sys;c:\windows\SysWOW64\Drivers\IesDrv.sys [x] S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x] S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x] S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys;c:\program files (x86)\MSI Afterburner\RTCore64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-02-22 07:41 1150280 ----a-w- c:\program files (x86)\Google\Chrome\Application\33.0.1750.117\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-02-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-05 14:53] . 2014-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-19 15:40] . 2014-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-19 15:40] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-12-28 14:00 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Jan\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Jan\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Jan\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Jan\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-09 12666984] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com uDefault_Search_URL = hxxp://www.google.com mDefault_Search_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com mSearch Bar = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 82.212.62.62 192.168.0.1 FF - ProfilePath - c:\users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: network.proxy.type - 2 FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-xp-AntiSpy - c:\program files (x86)\xp-AntiSpy\Uninstall.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\EverestDriver] "ImagePath"="\??\c:\program files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-185422420-646135407-2176989575-1000\Software\SecuROM\License information*] "datasecu"=hex:a2,39,13,ee,2a,23,7f,8a,00,2a,5e,3b,91,6b,e8,ae,6c,3f,78,9e,5c, 06,48,cc,99,6e,c8,49,c1,13,e3,88,20,e3,f4,92,98,77,6f,47,d7,81,00,84,a4,e9,\ "rkeysecu"=hex:63,74,65,17,9e,a1,7f,23,ad,1e,4f,1e,bc,32,8e,2c . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_70_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_70_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.12" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_70.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-02-25 08:36:08 ComboFix-quarantined-files.txt 2014-02-25 07:36 ComboFix2.txt 2014-02-25 07:25 . Vor Suchlauf: 19 Verzeichnis(se), 30.342.328.320 Bytes frei Nach Suchlauf: 20 Verzeichnis(se), 30.266.212.352 Bytes frei . - - End Of File - - 2BEC1E0D94A158BCF721219B551D79FE A36C5E4F47E84449FF07ED3517B43A31 |
26.02.2014, 10:09 | #7 |
/// the machine /// TB-Ausbilder | Win7 Computer geht seit ein paar Tagen massiv "in die Knie" Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.02.2014, 10:59 | #8 |
| Win7 Computer geht seit ein paar Tagen massiv "in die Knie" FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-02-2014 02 Ran by Jan (administrator) on HOMOFÜRST on 27-02-2014 10:55:43 Running from C:\Users\Jan\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASRock Incorporation) C:\Program Files (x86)\ASRock Utility\IES\AsrIes.exe () C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe (Hi-Rez Studios) d:\gamezone\Hi-Rez Studios\HiPatchService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe (H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe (Dropbox, Inc.) C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Logitech, Inc.) C:\Program Files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (H+H Software GmbH) C:\Program Files (x86)\Virtual CD v10\System\VC10Tray.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12666984 2011-08-09] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-28] (AVAST Software) HKLM-x32\...\Run: [XFastUSB] - C:\Program Files (x86)\XFastUSB\XFastUsb.exe [6311104 2014-01-24] (FNet Co., Ltd.) HKLM-x32\...\Run: [VC10Player] - C:\Program Files (x86)\Virtual CD v10\System\VC10Play.exe [409456 2013-11-19] (H+H Software GmbH) HKLM Group Policy restriction on software: C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Avira\AntiVir Desktop\ipmgui.exe <====== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <====== ATTENTION HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <====== ATTENTION HKU\S-1-5-21-185422420-646135407-2176989575-1000\...\Policies\Explorer: [NoDriveTypeAutoRun] 0xDD000000 HKU\S-1-5-21-185422420-646135407-2176989575-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Jan\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Touch Mouse Server.lnk ShortcutTarget: Logitech Touch Mouse Server.lnk -> C:\Program Files (x86)\Logitech Touch Mouse Server\iTouch-Server-Win.exe (Logitech, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5777D5D7178ACD01 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {98C9AE5B-3C2B-45a5-AEF5-47B585F0B5DD} URL = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: HistoryTriggerBHO Class - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 82.212.62.62 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default FF SelectedSearchEngine: Google FF Homepage: about:home FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20((url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D" FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Jan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxMate - Proxy on steroids! - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-06-28] FF Extension: Adblock Plus - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-28] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-12-28] Chrome: ======= CHR HomePage: hxxp://search.conduit.com/?ctid=CT3317741&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPA9713B57-2CEB-43C6-B7CE-77843CED26B4&SSPV= CHR Extension: (Google Docs) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-01] CHR Extension: (Google Drive) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-01] CHR Extension: (YouTube) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-01] CHR Extension: (Adblock Plus) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-17] CHR Extension: (Google-Suche) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-01] CHR Extension: (avast! Online Security) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-11] CHR Extension: (Google Wallet) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-01] CHR Extension: (Lavasoft NewTab) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole [2014-01-01] CHR Extension: (Google Mail) - C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-01] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-12-28] CHR HKLM-x32\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx [2013-08-08] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-28] (AVAST Software) S4 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] () R2 HiPatchService; d:\gamezone\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-03] (Hi-Rez Studios) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2365792 2012-09-19] (TuneUp Software) R2 VC10SecS; C:\Program Files (x86)\Virtual CD v10\System\VC10SecS.exe [147464 2013-01-08] (H+H Software GmbH) ==================== Drivers (Whitelisted) ==================== S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.) S3 AndNetDiag2; C:\Windows\System32\DRIVERS\lgandnetdiag264.sys [29696 2013-04-18] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.) S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93696 2013-04-23] (LG Electronics Inc.) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-19] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-28] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-28] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-19] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-19] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-19] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-28] () R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-02-19] (DT Soft Ltd) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [32320 2014-01-24] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2014-01-24] (FNet Co., Ltd.) S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-08-31] (GFI Software) R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.) R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.) R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-02-19] (Duplex Secure Ltd.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-09-19] (TuneUp Software) U3 aq0uar8r; C:\Windows\System32\Drivers\aq0uar8r.sys [0 ] (H+H Software GmbH) S3 Andbus; system32\DRIVERS\lgandbus64.sys [X] S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X] S3 AndGps; system32\DRIVERS\lgandgps64.sys [X] S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EverestDriver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X] S3 GPU-Z; \??\C:\Users\Jan\AppData\Local\Temp\GPU-Z.sys [X] S3 HH10Help.sys; \??\C:\Windows\system32\drivers\HH10Help.sys [X] R3 IesDrv; \??\C:\Windows\SysWOW64\Drivers\IesDrv.sys [X] S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X] R5 vdrv1000; C:\Windows\System32\Drivers\vdrv1000.sys [226080 2012-12-06] (H+H Software GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-27 10:55 - 2014-02-27 10:55 - 00000000 ____D () C:\Users\Jan\Downloads\FRST-OlderVersion 2014-02-27 10:47 - 2014-02-27 10:47 - 00001353 _____ () C:\Users\Jan\Desktop\JRT.txt 2014-02-27 10:39 - 2014-02-27 10:39 - 00000000 ____D () C:\Windows\ERUNT 2014-02-27 10:38 - 2014-02-27 10:38 - 01037734 _____ (Thisisu) C:\Users\Jan\Downloads\JRT.exe 2014-02-27 10:36 - 2014-02-27 10:36 - 00012044 _____ () C:\Users\Jan\Desktop\AdwCleaner[S1].txt 2014-02-27 10:27 - 2014-02-27 10:38 - 59904000 _____ () C:\Users\Jan\Downloads\calibre-64bit-1.25.0.msi 2014-02-27 10:26 - 2014-02-27 10:26 - 01241834 _____ () C:\Users\Jan\Downloads\adwcleaner.exe 2014-02-27 10:19 - 2014-02-27 10:19 - 00000000 ____D () C:\andReceiver-1.1.3-eng 2014-02-27 09:30 - 2014-02-27 09:30 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\vlc 2014-02-27 08:44 - 2014-02-27 10:35 - 00001117 _____ () C:\Users\Jan\Desktop\CD-R (E) 702 MB.lnk 2014-02-26 11:53 - 2014-02-26 11:54 - 00000000 ____D () C:\Program Files (x86)\MusicBrainz Picard 2014-02-26 11:52 - 2014-02-26 11:53 - 08790287 _____ (MusicBrainz) C:\Users\Jan\Downloads\picard-setup-1.2.exe 2014-02-26 11:49 - 2014-02-26 11:50 - 00281768 _____ () C:\Users\Jan\Downloads\magic-mp3-tagger-serial.exe_2239228_64_letF.exe 2014-02-26 11:44 - 2014-02-26 11:44 - 00001690 _____ () C:\Users\Jan\Downloads\Magic Mp3 Tagger 2.2.1 Cd Key Serial Registration Number And Activation Cod download.txt 2014-02-26 10:27 - 2014-02-26 10:28 - 04645440 _____ (Mathias Kunter ) C:\Users\Jan\Downloads\magic_tagger_db_2011-05-16 (1).exe 2014-02-26 10:27 - 2014-02-26 10:27 - 04645440 _____ (Mathias Kunter ) C:\Users\Jan\Downloads\magic_tagger_db_2011-05-16.exe 2014-02-26 10:27 - 2014-02-26 10:27 - 00051241 _____ () C:\Users\Jan\Downloads\id3_module.zip 2014-02-26 10:24 - 2014-02-26 10:28 - 00000000 ____D () C:\Program Files (x86)\Magic MP3 Tagger 2014-02-26 10:24 - 2014-02-26 10:24 - 00001032 _____ () C:\Users\Jan\Desktop\Magic MP3 Tagger.lnk 2014-02-26 10:23 - 2014-02-26 10:23 - 05579472 _____ (Mathias Kunter ) C:\Users\Jan\Downloads\magic_tagger.exe 2014-02-26 10:02 - 2014-02-26 10:02 - 00000282 _____ () C:\Users\Jan\Downloads\defogger_enable.log 2014-02-26 10:01 - 2014-02-26 10:46 - 00000000 ____D () C:\Users\Public\Virtual CDs 2014-02-26 10:01 - 2014-02-26 10:30 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Virtual CD v10 2014-02-26 10:01 - 2014-02-26 10:01 - 00002086 _____ () C:\Users\Public\Desktop\Virtual CD v10.lnk 2014-02-26 10:01 - 2014-02-26 10:01 - 00000000 ____D () C:\Users\Public\Virtual CD v10 2014-02-26 10:01 - 2012-12-06 11:09 - 00226080 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\vdrv1000.sys 2014-02-26 10:01 - 2009-07-09 10:24 - 00024088 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\HH10Help.dat 2014-02-26 10:00 - 2014-02-26 10:01 - 00000000 ____D () C:\Program Files (x86)\Virtual CD v10 2014-02-26 09:59 - 2014-02-26 10:01 - 00002963 _____ () C:\Windows\hhdrvi.log 2014-02-26 09:59 - 2008-06-17 08:22 - 00040464 _____ (H+H Software GmbH) C:\Windows\system32\Drivers\vcd10bus.sys 2014-02-26 09:58 - 2014-02-26 09:58 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\InstallShield 2014-02-26 09:50 - 2014-02-26 09:57 - 112570776 _____ (Macrovision Corporation) C:\Users\Jan\Downloads\VirtualCD10502Demo.exe 2014-02-25 15:52 - 2014-02-25 15:52 - 00394347 _____ (Ray Siegl ) C:\Users\Jan\Downloads\ram_clean_tool_setup.exe 2014-02-25 15:52 - 2014-02-25 15:52 - 00000000 ____D () C:\Program Files (x86)\RAM Clean Tool 2014-02-25 08:36 - 2014-02-25 08:36 - 00030222 _____ () C:\ComboFix.txt 2014-02-25 08:15 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-25 08:15 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-25 08:15 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-25 08:15 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-25 08:15 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-25 08:15 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-25 08:15 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-25 08:15 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-25 08:09 - 2014-02-25 08:36 - 00000000 ____D () C:\Qoobox 2014-02-25 08:09 - 2014-02-25 08:24 - 00000000 ____D () C:\Windows\erdnt 2014-02-25 08:08 - 2014-02-25 08:08 - 05185084 ____R (Swearware) C:\Users\Jan\Desktop\ComboFix.exe 2014-02-25 07:38 - 2014-02-25 07:38 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Apple Computer 2014-02-25 07:38 - 2014-02-25 07:38 - 00000000 ____D () C:\Users\Jan\AppData\Local\Apple Computer 2014-02-25 07:38 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-02-25 07:37 - 2014-02-25 07:38 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-02-25 07:37 - 2014-02-25 07:38 - 00000000 ____D () C:\Program Files\iTunes 2014-02-25 07:37 - 2014-02-25 07:38 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Users\Jan\AppData\Local\Apple 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files\iPod 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-02-25 07:36 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files\Bonjour 2014-02-25 07:36 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-02-25 07:32 - 2014-02-25 07:33 - 148896080 _____ (Apple Inc.) C:\Users\Jan\Downloads\iTunes64Setup.exe 2014-02-24 21:37 - 2014-02-26 09:48 - 00000000 ____D () C:\Users\Jan\AppData\Local\Audible 2014-02-24 21:37 - 2014-02-24 21:37 - 00255352 _____ (Audible, Inc.) C:\Windows\SysWOW64\awrdscdc.ax 2014-02-24 21:37 - 2014-02-24 21:37 - 00001974 _____ () C:\Users\Jan\Desktop\Audible Manager.lnk 2014-02-24 21:37 - 2014-02-24 21:37 - 00000000 ____D () C:\Users\Jan\Documents\Audible 2014-02-24 21:37 - 2014-02-24 21:37 - 00000000 ____D () C:\Program Files (x86)\Audible 2014-02-24 21:37 - 2003-03-18 21:20 - 01060864 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2014-02-24 21:37 - 2003-03-18 20:14 - 00499712 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2014-02-24 21:37 - 2003-02-21 04:42 - 00348160 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2014-02-24 21:37 - 2001-08-17 22:43 - 00024576 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2014-02-24 21:36 - 2014-02-24 21:36 - 01730272 _____ (Audible Inc.) C:\Users\Jan\Downloads\ActiveSetupN.exe 2014-02-24 10:41 - 2014-02-26 07:54 - 00003020 _____ () C:\Windows\System32\Tasks\MSIAfterburner 2014-02-23 20:40 - 2014-02-26 15:01 - 00000000 __HDC () C:\ProgramData\{1F992D7B-8BF0-4A62-9EA8-1CA890E8464D} 2014-02-23 20:40 - 2014-02-23 20:40 - 00002085 _____ () C:\Users\Public\Desktop\Surfer 11.lnk 2014-02-23 16:25 - 2014-02-23 16:25 - 00002099 _____ () C:\Users\Public\Desktop\Grapher 10.lnk 2014-02-23 16:24 - 2014-02-26 15:01 - 00000000 __HDC () C:\ProgramData\{0E9B3B8F-4F9F-4852-B1F7-6ED22BEFCBAC} 2014-02-23 16:24 - 2014-02-23 20:40 - 00000000 ____D () C:\Program Files\Golden Software 2014-02-23 15:37 - 2014-02-23 20:40 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Golden Software 2014-02-23 15:37 - 2014-02-23 15:37 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Polar Engineering 2014-02-23 13:01 - 2014-02-23 13:13 - 76383302 _____ () C:\Users\Jan\Downloads\Heart_Of_A_Coward-HaH-2012.rar 2014-02-21 11:42 - 2014-02-21 11:43 - 00000000 ____D () C:\Users\Jan\AppData\Local\Sony Online Entertainment 2014-02-21 10:22 - 2014-02-21 10:44 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\NVIDIA 2014-02-21 10:13 - 2014-02-25 19:17 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner 2014-02-21 10:13 - 2014-02-21 10:13 - 00001101 _____ () C:\Users\Jan\Desktop\MSI Kombustor 2.5.lnk 2014-02-21 10:13 - 2014-02-21 10:13 - 00001095 _____ () C:\Users\Jan\Desktop\MSI Afterburner.lnk 2014-02-21 10:13 - 2014-02-21 10:13 - 00000000 ____D () C:\Program Files (x86)\MSI Kombustor 2.5 2014-02-21 10:10 - 2014-02-21 10:11 - 22990573 _____ () C:\Users\Jan\Downloads\MSIAfterburnerSetup231.zip 2014-02-21 08:05 - 2014-02-21 12:22 - 00000000 ____D () C:\Program Files (x86)\GO2Bot 2014-02-21 08:04 - 2014-02-21 08:04 - 04950682 _____ (methejuggler ) C:\Users\Jan\Downloads\SetupGO2Bot.exe 2014-02-20 14:56 - 2014-02-27 10:55 - 00021938 _____ () C:\Users\Jan\Downloads\FRST.txt 2014-02-20 14:56 - 2014-02-27 10:55 - 00000000 ____D () C:\FRST 2014-02-20 14:56 - 2014-02-20 14:57 - 00032889 _____ () C:\Users\Jan\Downloads\Addition.txt 2014-02-20 14:30 - 2014-02-20 14:30 - 00000578 _____ () C:\Users\Jan\Downloads\defogger_disable.log 2014-02-20 14:26 - 2014-02-27 10:55 - 02155520 _____ (Farbar) C:\Users\Jan\Downloads\FRST64.exe 2014-02-20 14:26 - 2014-02-20 14:26 - 00380416 _____ () C:\Users\Jan\Downloads\Gmer-19357.exe 2014-02-20 14:25 - 2014-02-20 14:25 - 00050477 _____ () C:\Users\Jan\Downloads\Defogger.exe 2014-02-20 13:12 - 2014-02-20 13:12 - 02817354 _____ () C:\Users\Jan\Downloads\DCProSetup_15.zip 2014-02-19 17:23 - 2014-02-19 17:23 - 00423981 _____ () C:\Users\Jan\Downloads\myspace-music-downloader_21456.zip 2014-02-19 15:03 - 2014-02-19 15:03 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Iggels 2014-02-19 15:02 - 2014-02-19 15:02 - 00423981 _____ () C:\Users\Jan\Downloads\MyMusicDownloader.zip 2014-02-19 15:02 - 2014-02-19 15:02 - 00000000 ____D () C:\MyMusic Downloader 2014-02-19 12:40 - 2014-02-19 12:40 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-02-19 12:40 - 2014-02-08 17:18 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-02-19 12:37 - 2014-02-08 19:34 - 31432480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 23683360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 15740232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 14669032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 12324640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-19 12:37 - 2014-02-08 19:34 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433489.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433489.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00875296 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00844576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00483104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00408352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00378656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-02-19 12:37 - 2014-02-08 19:34 - 00148528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-02-19 11:27 - 2014-02-19 11:27 - 01031147 _____ (Zero Assumption Software ) C:\Users\Jan\Downloads\vis12setup.exe 2014-02-19 11:27 - 2014-02-19 11:27 - 00000000 ____D () C:\Program Files (x86)\Disk Space Visualizer 2014-02-19 11:18 - 2014-02-19 11:23 - 276927952 _____ (NVIDIA Corporation) C:\Users\Jan\Downloads\334.89-desktop-win8-win7-winvista-64bit-international-whql.exe 2014-02-19 11:13 - 2014-02-19 11:13 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-19 11:12 - 2014-02-19 11:12 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-19 11:12 - 2014-02-19 11:12 - 00000000 ____D () C:\ProgramData\Sun 2014-02-19 11:11 - 2014-02-19 11:11 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-19 11:09 - 2014-02-19 11:09 - 00921000 _____ (Oracle Corporation) C:\Users\Jan\Downloads\jxpiinstall.exe 2014-02-18 10:19 - 2014-02-18 10:19 - 00719500 _____ () C:\Users\Jan\Downloads\Carnival1.1.0.zip 2014-02-17 16:54 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-02-17 16:54 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-02-17 16:34 - 2014-02-17 16:34 - 00000022 _____ () C:\Windows\GPU-Z.INI 2014-02-12 15:02 - 2014-02-17 16:55 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA Corporation 2014-02-12 14:51 - 2014-02-12 20:37 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA 2014-02-12 14:51 - 2014-02-05 10:31 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-02-12 14:51 - 2014-02-05 10:30 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-02-12 14:50 - 2014-02-27 10:34 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-12 14:49 - 2014-02-08 18:42 - 06712608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 03498272 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 00923936 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-12 14:49 - 2014-02-08 18:42 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-12 14:49 - 2014-02-08 18:42 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-12 14:49 - 2014-02-05 18:52 - 03573739 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-12 14:47 - 2013-12-27 19:42 - 00035104 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-02-12 14:47 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-02-12 14:47 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-02-12 14:47 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 18257576 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 17715784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 03090184 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 02713728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-02-12 14:37 - 2014-02-08 19:34 - 00947296 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-02-12 14:37 - 2013-12-19 21:33 - 18310112 _____ (NVIDIA Corporation) C:\Windows\system32\SETB7AF.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\SET888B.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 03071656 _____ (NVIDIA Corporation) C:\Windows\system32\SET7CA3.tmp 2014-02-12 14:37 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll 2014-02-12 14:37 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll 2014-02-12 14:37 - 2013-12-19 21:33 - 01436528 _____ (NVIDIA Corporation) C:\Windows\system32\SETAEE7.tmp 2014-02-12 14:26 - 2014-02-19 12:40 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-12 14:26 - 2014-02-12 20:37 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-12 14:26 - 2014-02-12 14:51 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-12 03:02 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 03:02 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 03:01 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 03:01 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 03:01 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 03:01 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 03:01 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 03:01 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-12 03:01 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 03:01 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 03:01 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 03:01 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 03:01 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-12 03:01 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-12 03:01 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-12 03:01 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 03:01 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-12 03:01 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 03:01 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 03:01 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-12 03:01 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-12 03:01 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-12 03:01 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 03:01 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-12 03:01 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-12 03:01 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 03:01 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-12 03:01 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-12 03:01 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-12 03:01 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-12 03:01 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-12 03:01 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 03:01 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 03:01 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-12 03:01 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-12 03:01 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-12 03:01 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 03:01 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-12 03:01 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-12 03:01 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-12 03:01 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 01:05 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 01:05 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 01:05 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 01:05 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 01:05 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 01:05 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 01:05 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 01:05 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 01:05 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 01:05 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 01:05 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 01:05 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 01:05 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 01:05 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 01:05 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 01:05 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 01:05 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 01:05 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 01:05 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 01:05 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 01:05 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 01:05 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 01:05 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 01:05 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 01:05 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 22:15 - 2014-02-11 22:00 - 179891296 _____ () C:\auftritt.avi 2014-02-10 22:53 - 2014-02-10 22:53 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-02-10 22:52 - 2014-01-07 14:16 - 00000000 ____D () C:\GPUTweak_2_5_2 2014-02-06 11:07 - 2014-02-17 09:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-01 18:05 - 2014-02-01 18:05 - 00262144 ____N () C:\Windows\Minidump\020114-16645-01.dmp 2014-01-30 22:57 - 2014-02-10 21:52 - 00000003 _____ () C:\Windows\system32\HRUPPROG.TXT 2014-01-30 22:57 - 2014-01-30 22:57 - 00000003 _____ () C:\Windows\system32\HRUPPROG.DIE.NOW ==================== One Month Modified Files and Folders ======= 2014-02-27 10:55 - 2014-02-27 10:55 - 00000000 ____D () C:\Users\Jan\Downloads\FRST-OlderVersion 2014-02-27 10:55 - 2014-02-20 14:56 - 00021938 _____ () C:\Users\Jan\Downloads\FRST.txt 2014-02-27 10:55 - 2014-02-20 14:56 - 00000000 ____D () C:\FRST 2014-02-27 10:55 - 2014-02-20 14:26 - 02155520 _____ (Farbar) C:\Users\Jan\Downloads\FRST64.exe 2014-02-27 10:52 - 2013-12-21 13:10 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-27 10:47 - 2014-02-27 10:47 - 00001353 _____ () C:\Users\Jan\Desktop\JRT.txt 2014-02-27 10:42 - 2009-07-14 05:45 - 00016896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-27 10:42 - 2009-07-14 05:45 - 00016896 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-27 10:39 - 2014-02-27 10:39 - 00000000 ____D () C:\Windows\ERUNT 2014-02-27 10:38 - 2014-02-27 10:38 - 01037734 _____ (Thisisu) C:\Users\Jan\Downloads\JRT.exe 2014-02-27 10:38 - 2014-02-27 10:27 - 59904000 _____ () C:\Users\Jan\Downloads\calibre-64bit-1.25.0.msi 2014-02-27 10:38 - 2012-09-02 10:25 - 01939705 _____ () C:\Windows\WindowsUpdate.log 2014-02-27 10:36 - 2014-02-27 10:36 - 00012044 _____ () C:\Users\Jan\Desktop\AdwCleaner[S1].txt 2014-02-27 10:36 - 2014-01-27 11:47 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Dropbox 2014-02-27 10:35 - 2014-02-27 08:44 - 00001117 _____ () C:\Users\Jan\Desktop\CD-R (E) 702 MB.lnk 2014-02-27 10:35 - 2013-12-28 15:00 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-02-27 10:35 - 2013-09-22 16:03 - 00050025 _____ () C:\Windows\setupact.log 2014-02-27 10:34 - 2014-02-12 14:50 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-27 10:34 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-27 10:30 - 2013-09-18 07:24 - 00000000 ____D () C:\AdwCleaner 2014-02-27 10:28 - 2013-09-20 20:19 - 00000000 ____D () C:\mehl 2014-02-27 10:26 - 2014-02-27 10:26 - 01241834 _____ () C:\Users\Jan\Downloads\adwcleaner.exe 2014-02-27 10:19 - 2014-02-27 10:19 - 00000000 ____D () C:\andReceiver-1.1.3-eng 2014-02-27 09:30 - 2014-02-27 09:30 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\vlc 2014-02-26 23:30 - 2013-06-26 08:17 - 01593956 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-26 23:30 - 2009-07-14 18:58 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-02-26 23:30 - 2009-07-14 18:58 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-02-26 23:29 - 2009-07-14 06:13 - 01593956 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-26 22:59 - 2012-09-07 06:00 - 00000000 ____D () C:\Users\Jan\AppData\Local\CrashDumps 2014-02-26 20:22 - 2012-09-02 15:50 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\foobar2000 2014-02-26 15:01 - 2014-02-23 20:40 - 00000000 __HDC () C:\ProgramData\{1F992D7B-8BF0-4A62-9EA8-1CA890E8464D} 2014-02-26 15:01 - 2014-02-23 16:24 - 00000000 __HDC () C:\ProgramData\{0E9B3B8F-4F9F-4852-B1F7-6ED22BEFCBAC} 2014-02-26 11:59 - 2012-09-01 11:53 - 00000000 ____D () C:\Users\Jan\AppData\Local\Deployment 2014-02-26 11:54 - 2014-02-26 11:53 - 00000000 ____D () C:\Program Files (x86)\MusicBrainz Picard 2014-02-26 11:53 - 2014-02-26 11:52 - 08790287 _____ (MusicBrainz) C:\Users\Jan\Downloads\picard-setup-1.2.exe 2014-02-26 11:50 - 2014-02-26 11:49 - 00281768 _____ () C:\Users\Jan\Downloads\magic-mp3-tagger-serial.exe_2239228_64_letF.exe 2014-02-26 11:44 - 2014-02-26 11:44 - 00001690 _____ () C:\Users\Jan\Downloads\Magic Mp3 Tagger 2.2.1 Cd Key Serial Registration Number And Activation Cod download.txt 2014-02-26 10:46 - 2014-02-26 10:01 - 00000000 ____D () C:\Users\Public\Virtual CDs 2014-02-26 10:30 - 2014-02-26 10:01 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Virtual CD v10 2014-02-26 10:28 - 2014-02-26 10:27 - 04645440 _____ (Mathias Kunter ) C:\Users\Jan\Downloads\magic_tagger_db_2011-05-16 (1).exe 2014-02-26 10:28 - 2014-02-26 10:24 - 00000000 ____D () C:\Program Files (x86)\Magic MP3 Tagger 2014-02-26 10:27 - 2014-02-26 10:27 - 04645440 _____ (Mathias Kunter ) C:\Users\Jan\Downloads\magic_tagger_db_2011-05-16.exe 2014-02-26 10:27 - 2014-02-26 10:27 - 00051241 _____ () C:\Users\Jan\Downloads\id3_module.zip 2014-02-26 10:24 - 2014-02-26 10:24 - 00001032 _____ () C:\Users\Jan\Desktop\Magic MP3 Tagger.lnk 2014-02-26 10:23 - 2014-02-26 10:23 - 05579472 _____ (Mathias Kunter ) C:\Users\Jan\Downloads\magic_tagger.exe 2014-02-26 10:02 - 2014-02-26 10:02 - 00000282 _____ () C:\Users\Jan\Downloads\defogger_enable.log 2014-02-26 10:02 - 2012-09-01 09:03 - 00000000 ____D () C:\Users\Jan 2014-02-26 10:01 - 2014-02-26 10:01 - 00002086 _____ () C:\Users\Public\Desktop\Virtual CD v10.lnk 2014-02-26 10:01 - 2014-02-26 10:01 - 00000000 ____D () C:\Users\Public\Virtual CD v10 2014-02-26 10:01 - 2014-02-26 10:00 - 00000000 ____D () C:\Program Files (x86)\Virtual CD v10 2014-02-26 10:01 - 2014-02-26 09:59 - 00002963 _____ () C:\Windows\hhdrvi.log 2014-02-26 10:00 - 2012-09-01 09:40 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-02-26 09:58 - 2014-02-26 09:58 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\InstallShield 2014-02-26 09:57 - 2014-02-26 09:50 - 112570776 _____ (Macrovision Corporation) C:\Users\Jan\Downloads\VirtualCD10502Demo.exe 2014-02-26 09:48 - 2014-02-24 21:37 - 00000000 ____D () C:\Users\Jan\AppData\Local\Audible 2014-02-26 07:55 - 2013-09-22 16:03 - 00220040 _____ () C:\Windows\PFRO.log 2014-02-26 07:55 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-02-26 07:54 - 2014-02-24 10:41 - 00003020 _____ () C:\Windows\System32\Tasks\MSIAfterburner 2014-02-25 20:36 - 2013-10-11 22:48 - 00001075 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-02-25 19:17 - 2014-02-21 10:13 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner 2014-02-25 17:33 - 2012-09-01 11:53 - 00000000 ____D () C:\Users\Jan\AppData\Local\Apps\2.0 2014-02-25 15:52 - 2014-02-25 15:52 - 00394347 _____ (Ray Siegl ) C:\Users\Jan\Downloads\ram_clean_tool_setup.exe 2014-02-25 15:52 - 2014-02-25 15:52 - 00000000 ____D () C:\Program Files (x86)\RAM Clean Tool 2014-02-25 08:36 - 2014-02-25 08:36 - 00030222 _____ () C:\ComboFix.txt 2014-02-25 08:36 - 2014-02-25 08:09 - 00000000 ____D () C:\Qoobox 2014-02-25 08:34 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-25 08:25 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-25 08:24 - 2014-02-25 08:09 - 00000000 ____D () C:\Windows\erdnt 2014-02-25 08:08 - 2014-02-25 08:08 - 05185084 ____R (Swearware) C:\Users\Jan\Desktop\ComboFix.exe 2014-02-25 07:38 - 2014-02-25 07:38 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Apple Computer 2014-02-25 07:38 - 2014-02-25 07:38 - 00000000 ____D () C:\Users\Jan\AppData\Local\Apple Computer 2014-02-25 07:38 - 2014-02-25 07:37 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-02-25 07:38 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files\iTunes 2014-02-25 07:38 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Users\Jan\AppData\Local\Apple 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files\iPod 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-02-25 07:37 - 2014-02-25 07:37 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-02-25 07:37 - 2014-02-25 07:36 - 00000000 ____D () C:\Program Files\Bonjour 2014-02-25 07:37 - 2014-02-25 07:36 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-02-25 07:37 - 2013-11-02 02:57 - 00000000 ____D () C:\ProgramData\Apple 2014-02-25 07:33 - 2014-02-25 07:32 - 148896080 _____ (Apple Inc.) C:\Users\Jan\Downloads\iTunes64Setup.exe 2014-02-24 21:37 - 2014-02-24 21:37 - 00255352 _____ (Audible, Inc.) C:\Windows\SysWOW64\awrdscdc.ax 2014-02-24 21:37 - 2014-02-24 21:37 - 00001974 _____ () C:\Users\Jan\Desktop\Audible Manager.lnk 2014-02-24 21:37 - 2014-02-24 21:37 - 00000000 ____D () C:\Users\Jan\Documents\Audible 2014-02-24 21:37 - 2014-02-24 21:37 - 00000000 ____D () C:\Program Files (x86)\Audible 2014-02-24 21:36 - 2014-02-24 21:36 - 01730272 _____ (Audible Inc.) C:\Users\Jan\Downloads\ActiveSetupN.exe 2014-02-23 20:40 - 2014-02-23 20:40 - 00002085 _____ () C:\Users\Public\Desktop\Surfer 11.lnk 2014-02-23 20:40 - 2014-02-23 16:24 - 00000000 ____D () C:\Program Files\Golden Software 2014-02-23 20:40 - 2014-02-23 15:37 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Golden Software 2014-02-23 17:05 - 2013-09-22 16:03 - 00447536 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-23 16:25 - 2014-02-23 16:25 - 00002099 _____ () C:\Users\Public\Desktop\Grapher 10.lnk 2014-02-23 15:37 - 2014-02-23 15:37 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Polar Engineering 2014-02-23 15:37 - 2013-09-22 08:44 - 00120904 _____ () C:\Users\Jan\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-23 13:13 - 2014-02-23 13:01 - 76383302 _____ () C:\Users\Jan\Downloads\Heart_Of_A_Coward-HaH-2012.rar 2014-02-21 15:53 - 2013-12-21 13:10 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-21 15:53 - 2012-09-05 08:53 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-21 15:53 - 2012-09-05 08:53 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-21 13:39 - 2013-12-31 10:47 - 00000000 ____D () C:\Users\Jan\Desktop\KWATSCH 2014-02-21 12:24 - 2014-01-02 13:59 - 00001461 _____ () C:\Users\Jan\AppData\Local\RecConfig.xml 2014-02-21 12:22 - 2014-02-21 08:05 - 00000000 ____D () C:\Program Files (x86)\GO2Bot 2014-02-21 11:43 - 2014-02-21 11:42 - 00000000 ____D () C:\Users\Jan\AppData\Local\Sony Online Entertainment 2014-02-21 11:20 - 2013-03-14 11:36 - 00000000 ____D () C:\Users\Jan\AppData\Local\SKIDROW 2014-02-21 10:44 - 2014-02-21 10:22 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\NVIDIA 2014-02-21 10:14 - 2012-10-10 21:17 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-02-21 10:13 - 2014-02-21 10:13 - 00001101 _____ () C:\Users\Jan\Desktop\MSI Kombustor 2.5.lnk 2014-02-21 10:13 - 2014-02-21 10:13 - 00001095 _____ () C:\Users\Jan\Desktop\MSI Afterburner.lnk 2014-02-21 10:13 - 2014-02-21 10:13 - 00000000 ____D () C:\Program Files (x86)\MSI Kombustor 2.5 2014-02-21 10:13 - 2013-02-23 14:05 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2014-02-21 10:11 - 2014-02-21 10:10 - 22990573 _____ () C:\Users\Jan\Downloads\MSIAfterburnerSetup231.zip 2014-02-21 08:04 - 2014-02-21 08:04 - 04950682 _____ (methejuggler ) C:\Users\Jan\Downloads\SetupGO2Bot.exe 2014-02-20 14:57 - 2014-02-20 14:56 - 00032889 _____ () C:\Users\Jan\Downloads\Addition.txt 2014-02-20 14:30 - 2014-02-20 14:30 - 00000578 _____ () C:\Users\Jan\Downloads\defogger_disable.log 2014-02-20 14:26 - 2014-02-20 14:26 - 00380416 _____ () C:\Users\Jan\Downloads\Gmer-19357.exe 2014-02-20 14:25 - 2014-02-20 14:25 - 00050477 _____ () C:\Users\Jan\Downloads\Defogger.exe 2014-02-20 13:12 - 2014-02-20 13:12 - 02817354 _____ () C:\Users\Jan\Downloads\DCProSetup_15.zip 2014-02-19 17:23 - 2014-02-19 17:23 - 00423981 _____ () C:\Users\Jan\Downloads\myspace-music-downloader_21456.zip 2014-02-19 15:03 - 2014-02-19 15:03 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\Iggels 2014-02-19 15:02 - 2014-02-19 15:02 - 00423981 _____ () C:\Users\Jan\Downloads\MyMusicDownloader.zip 2014-02-19 15:02 - 2014-02-19 15:02 - 00000000 ____D () C:\MyMusic Downloader 2014-02-19 12:40 - 2014-02-19 12:40 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-02-19 12:40 - 2014-02-12 14:26 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-19 12:29 - 2009-07-14 03:34 - 77332480 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old 2014-02-19 12:29 - 2009-07-14 03:34 - 25427968 _____ () C:\Windows\system32\config\SYSTEM_tureg_old 2014-02-19 12:29 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY_tureg_old 2014-02-19 12:27 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT_tureg_old 2014-02-19 12:27 - 2009-07-14 03:34 - 00032768 _____ () C:\Windows\system32\config\SAM_tureg_old 2014-02-19 12:05 - 2013-12-28 15:00 - 00001975 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-02-19 12:04 - 2013-12-28 15:00 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-02-19 12:04 - 2013-12-28 15:00 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-02-19 12:04 - 2013-12-28 15:00 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-02-19 11:27 - 2014-02-19 11:27 - 01031147 _____ (Zero Assumption Software ) C:\Users\Jan\Downloads\vis12setup.exe 2014-02-19 11:27 - 2014-02-19 11:27 - 00000000 ____D () C:\Program Files (x86)\Disk Space Visualizer 2014-02-19 11:23 - 2014-02-19 11:18 - 276927952 _____ (NVIDIA Corporation) C:\Users\Jan\Downloads\334.89-desktop-win8-win7-winvista-64bit-international-whql.exe 2014-02-19 11:13 - 2014-02-19 11:13 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-19 11:12 - 2014-02-19 11:12 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-02-19 11:12 - 2014-02-19 11:12 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-19 11:12 - 2014-02-19 11:12 - 00000000 ____D () C:\ProgramData\Sun 2014-02-19 11:11 - 2014-02-19 11:11 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-19 11:09 - 2014-02-19 11:09 - 00921000 _____ (Oracle Corporation) C:\Users\Jan\Downloads\jxpiinstall.exe 2014-02-18 17:09 - 2014-01-27 11:49 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\DropboxMaster 2014-02-18 10:19 - 2014-02-18 10:19 - 00719500 _____ () C:\Users\Jan\Downloads\Carnival1.1.0.zip 2014-02-17 19:24 - 2012-09-07 09:57 - 00000000 ____D () C:\Program Files (x86)\AMD APP 2014-02-17 19:23 - 2012-09-07 09:48 - 00000000 ____D () C:\ProgramData\AMD 2014-02-17 19:05 - 2013-03-19 16:40 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-17 19:05 - 2013-03-19 16:40 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-17 19:05 - 2012-10-13 03:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-17 16:55 - 2014-02-12 15:02 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA Corporation 2014-02-17 16:34 - 2014-02-17 16:34 - 00000022 _____ () C:\Windows\GPU-Z.INI 2014-02-17 09:45 - 2014-02-06 11:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-17 01:42 - 2013-03-19 16:40 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-17 01:42 - 2013-03-19 16:40 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-16 03:00 - 2012-09-04 07:46 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-12 20:37 - 2014-02-12 14:51 - 00000000 ____D () C:\Users\Jan\AppData\Local\NVIDIA 2014-02-12 20:37 - 2014-02-12 14:26 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-12 14:51 - 2014-02-12 14:26 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-12 14:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help 2014-02-12 14:27 - 2013-02-23 23:07 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies 2014-02-12 14:27 - 2012-09-01 09:44 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\ATI 2014-02-12 14:27 - 2012-09-01 09:44 - 00000000 ____D () C:\Users\Jan\AppData\Local\ATI 2014-02-12 03:15 - 2013-09-19 17:41 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-12 03:02 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini 2014-02-11 22:00 - 2014-02-11 22:15 - 179891296 _____ () C:\auftritt.avi 2014-02-10 22:53 - 2014-02-10 22:53 - 00000000 ____D () C:\Windows\Downloaded Installations 2014-02-10 22:46 - 2013-02-01 15:50 - 00000000 ____D () C:\Users\Jan\AppData\Roaming\dvdcss 2014-02-10 21:52 - 2014-01-30 22:57 - 00000003 _____ () C:\Windows\system32\HRUPPROG.TXT 2014-02-08 19:34 - 2014-02-19 12:37 - 31432480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 23683360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 15740232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 14669032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 12324640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-08 19:34 - 2014-02-19 12:37 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433489.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433489.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00875296 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00844576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00483104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00408352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00378656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00333600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-02-08 19:34 - 2014-02-19 12:37 - 00148528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 18257576 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 17715784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 03090184 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 02713728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-02-08 19:34 - 2014-02-12 14:37 - 00947296 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-02-08 19:34 - 2013-10-27 09:12 - 00024544 _____ () C:\Windows\system32\nvinfo.pb 2014-02-08 19:34 - 2012-12-19 15:34 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-02-08 19:34 - 2012-12-19 15:34 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 06712608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 03498272 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 00923936 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-08 18:42 - 2014-02-12 14:49 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-08 18:42 - 2014-02-12 14:49 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-08 17:18 - 2014-02-19 12:40 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-02-07 09:29 - 2013-12-20 19:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak 2014-02-06 13:16 - 2014-02-12 03:01 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-12 03:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-12 03:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-12 03:01 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-12 03:01 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-12 03:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-12 03:01 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-12 03:01 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-12 03:01 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-12 03:01 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-12 03:01 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-12 03:01 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-12 03:01 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-12 03:01 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-12 03:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-12 03:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-12 03:01 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-12 03:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-12 03:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-12 03:01 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-12 03:01 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-12 03:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-12 03:01 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-12 03:01 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-12 03:01 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-12 03:01 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-12 03:01 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-12 03:01 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-12 03:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-12 03:01 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-12 03:01 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-12 03:01 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-12 03:01 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-12 03:01 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-12 03:01 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-12 03:01 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-12 03:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-12 03:01 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-12 03:01 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-05 18:52 - 2014-02-12 14:49 - 03573739 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-05 10:31 - 2014-02-12 14:51 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-02-05 10:30 - 2014-02-12 14:51 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-02-01 18:05 - 2014-02-01 18:05 - 00262144 ____N () C:\Windows\Minidump\020114-16645-01.dmp 2014-02-01 18:05 - 2012-11-22 16:05 - 00000000 ____D () C:\Windows\Minidump 2014-01-31 14:03 - 2014-01-24 08:51 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software 2014-01-30 22:57 - 2014-01-30 22:57 - 00000003 _____ () C:\Windows\system32\HRUPPROG.DIE.NOW Some content of TEMP: ==================== C:\Users\Jan\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgxzupt.dll C:\Users\Jan\AppData\Local\Temp\Quarantine.exe C:\Users\Jan\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 11:32 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.2 (02.20.2014:1) OS: Windows 7 Professional x64 Ran by Jan on 27.02.2014 at 10:39:29.30 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-185422420-646135407-2176989575-1000\Software\sweetim ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Jan\AppData\Roaming\mozilla\firefox\profiles\9c5mpvj5.default\minidumps [264 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.02.2014 at 10:47:20.35 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter # AdwCleaner v3.019 - Bericht erstellt am 27/02/2014 um 10:30:13 # Aktualisiert 17/02/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Jan - HOMOFÜRST # Gestartet von : C:\Users\Jan\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\NCH Software Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup Ordner Gelöscht : C:\Program Files (x86)\NCH Software Ordner Gelöscht : C:\Program Files (x86)\Toolbar Cleaner Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin Ordner Gelöscht : C:\Users\Jan\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\Jan\AppData\Local\Searchprotect Ordner Gelöscht : C:\Users\Jan\AppData\Roaming\NCH Software Ordner Gelöscht : C:\Users\Jan\AppData\Roaming\Systweak Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\searchplugins\conduit-search.xml Datei Gelöscht : C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\user.js Datei Gelöscht : C:\Windows\System32\Tasks\NCH Software ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Classes\pokki Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKCU\Software\caphyon Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\NCH Software Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKLM\Software\caphyon Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\NCH Software Schlüssel Gelöscht : HKLM\Software\SearchProtect Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\9c5mpvj5.default\prefs.js ] Zeile gelöscht : user_pref("iminent.LayoutId", "1"); Zeile gelöscht : user_pref("iminent.adapters", "{\"iminent\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":1,\"expireTime\":\"1385662702253245692\"},\"downloadinfo\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Stat[...] Zeile gelöscht : user_pref("iminent.version", "7.48.1.1"); Zeile gelöscht : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.48.1.1\",\"InstallEventCTime\":1385662700376,\"InstallEvent\":\"True\"}"); -\\ Google Chrome v33.0.1750.117 [ Datei : C:\Users\Jan\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage ************************* AdwCleaner[R0].txt - [9465 octets] - [18/09/2013 07:24:46] AdwCleaner[R1].txt - [12380 octets] - [27/02/2014 10:27:52] AdwCleaner[S0].txt - [6778 octets] - [18/09/2013 07:29:57] AdwCleaner[S1].txt - [11726 octets] - [27/02/2014 10:30:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [11787 octets] ########## Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.27.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16518 Jan :: HOMOFÜRST [Administrator] 27.02.2014 10:49:13 mbam-log-2014-02-27 (10-49-13).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 222469 Laufzeit: 4 Minute(n), 30 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
27.02.2014, 18:47 | #9 |
/// the machine /// TB-Ausbilder | Win7 Computer geht seit ein paar Tagen massiv "in die Knie"ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win7 Computer geht seit ein paar Tagen massiv "in die Knie" |
amd, amd radeon, ausgelastet, avast, befund, browser, computer, cpu, einbau, geforce, grafikkarte, kommts, mbam, momente, neue, neuen, nichts, nvidia, ohne befund, radeon, scan, speicher, taskmanager, trotz, win, win7, world |