|
Plagegeister aller Art und deren Bekämpfung: Virus HTML/Drop.Agent.AB HILFEEEEWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.03.2014, 19:31 | #1 |
| Virus HTML/Drop.Agent.AB HILFEEEE Hallo leute, bin neu hier. Meine Avira spuckt seit der letzten lan party immer wieder diese meldung Der Zugriff auf die Datei C:/ blabllablabla mit dem virus oder dem unerwünschten Programm HTML/Drop.Agent.AB wurde blockiert.. was soll ich tun? die meldung kommt immer wieder bloss mit anderen datein und Avira findet nix! |
19.03.2014, 19:52 | #2 |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEEMein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...
Hinweise: Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Dir jemand vom Team sagt, dass Du clean bist. Bitte beachte, dass alle meine Antworten zuerst von einem Ausbilder freigegeben werden müssen, bevor ich diese hier posten darf. Das dauert dann zwar ein paar Stunden länger, garantiert aber, dass Du kompetente Hilfe und geprüfte Antworten bekommst. Siehe hier... Ich bedanke mich für Deine Geduld! Schritt 1 (Scan mit FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
19.03.2014, 20:33 | #3 |
| Virus HTML/Drop.Agent.AB HILFEEEECode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by BaNgMaN at 2014-03-19 20:25:28 Running from C:\Users\BaNgMaN\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) Advanced AI Mod (HKLM-x32\...\Advanced AI Mod0.98b) (Version: 0.98b - Zero Hour Fandom) AIVIA GHOST (HKLM-x32\...\{4E711815-5F4E-47F2-B1E1-C0B43A8D57F3}) (Version: 1.06.0000 - GIGABYTE) Apple Application Support (HKLM-x32\...\{A922C4B7-50E0-4787-A94C-59DBF3C65DBE}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ARMA 2 Army of The Czech Republic - Data cache removal (HKLM-x32\...\A2ACR Data cache removal) (Version: - ) Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.8.0 - Ask.com) <==== ATTENTION Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira) Avira SearchFree Toolbar plus Web Protection Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.4.1.29403 - Ask.com) <==== ATTENTION Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1105.1601 - Micro-Star International Co., Ltd.) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlefield 3™ (HKLM-x32\...\{64BFBE7A-886C-4CA2-A9B4-0C2B5A5942BC}) (Version: 1.4.0.0 - Electronic Arts) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) BEETmobile (HKLM-x32\...\{AC843048-1628-421B-AEEB-F86FFAEBFA91}) (Version: 1.0.21.0 - BEETmobile AG) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bundled software uninstaller (HKLM-x32\...\bi_uninstaller) (Version: - ) <==== ATTENTION BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 3.0.1103.1801 - Micro-Star International Co., Ltd.) Camera Recorder (HKLM-x32\...\{3BDDA587-7CDE-430C-90A4-E2C4E48D3AE9}) (Version: 1.0.909.0801 - Camera Recorder) CloneDVD2 (HKLM-x32\...\CloneDVD2) (Version: 2.9.3.0 - Elaborate Bytes) Command & Conquer Generals (HKLM-x32\...\InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}) (Version: 0.50.0000 - Electronic Arts) Command & Conquer Generals (x32 Version: 0.50.0000 - Electronic Arts) Hidden Command and Conquer(TM) Generäle Die Stunde Null (HKLM-x32\...\InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}) (Version: 1.00.0000 - Electronic Arts) Command and Conquer(TM) Generäle Die Stunde Null (x32 Version: 1.00.0000 - Electronic Arts) Hidden Contagion (HKLM-x32\...\Steam App 238430) (Version: - Monochrome LLC) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4612 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.1.4612 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd) DAEMON Tools Toolbar (HKLM-x32\...\DAEMON Tools Toolbar) (Version: 1.1.9.0016 - DT Soft Ltd) <==== ATTENTION DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) DealPly (remove only) (HKLM-x32\...\DealPly) (Version: 4.8.7.2 - DealPly Technologies Ltd.) <==== ATTENTION Driver Genius (HKLM-x32\...\Driver Genius_is1) (Version: 12.0 - Driver-Soft Inc.) Easy Text To HTML Converter (HKLM-x32\...\Easy Text To HTML Converter) (Version: 3.0.0 - easy HTools) EasyViewer (HKLM-x32\...\InstallShield_{EECD7B96-1416-4D3A-B12D-0D2512120C36}) (Version: 1.3.0.9 - MSI) EasyViewer (x32 Version: 1.3.0.9 - MSI) Hidden ETDWare PS/2-X64 11.13.0.2_WHQL (HKLM\...\Elantech) (Version: 11.13.0.2 - ELAN Microelectronic Corp.) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) FileZilla Client 3.6.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.6.0.2 - FileZilla Project) Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.) Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden GHOST(6980X) (HKLM-x32\...\{CE7DAF08-F073-4499-AA99-FC0143DF55BB}) (Version: 1.00.0000 - Ihr Firmenname) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 28.0.1500.95 - Google Inc.) Google Talk Plugin (HKLM-x32\...\{2A83AD05-56E6-3FBD-8752-B4143162EF59}) (Version: 4.9.1.16010 - Google) Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden HAWKEN (HKLM-x32\...\Steam App 271290) (Version: - Adhesive Games) Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) Infestation: Survivor Stories (HKLM-x32\...\Steam App 226700) (Version: - Hammerpoint Interactive) Intel PROSet Wireless (Version: - ) Hidden Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.0.1428 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3071 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (HKLM\...\{37EC048A-81A2-452A-8D1F-3BE2018E767D}) (Version: 15.1.0.0096 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{A10B1524-63B5-40F2-B272-D841CF671C16}) (Version: 2.2.0.0266 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.5.0.1066 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.5.0.1066 - Intel Corporation) Hidden Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.63463 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.8.251 - Intel Corporation) Intel® PROSet/Wireless WiFi Software (HKLM\...\{E97F409F-9E1C-42A0-B72D-765A78DF3696}) (Version: 15.01.0000.0830 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.27.798.1 - Intel Corporation) Hidden Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation) Internet Updater (HKLM-x32\...\InternetUpdater) (Version: 2.6.52 - Parallel Lines Development, LLC) <==== ATTENTION iTunes (HKLM\...\{0D924CB2-2EA4-4044-BAF7-770202D6BD0D}) (Version: 11.1.4.62 - Apple Inc.) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java 7 Update 7 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417007FF}) (Version: 7.0.70 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java SE Development Kit 7 Update 7 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170070}) (Version: 1.7.0.70 - Oracle) JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LineIn plugin for WinAMP v1.80 (remove only) (HKLM-x32\...\LineIn plugin for WinAMP) (Version: - ) Live Update 5 (HKLM-x32\...\{E8BAA541-D161-4C9B-85BF-01F05A56BD7F}}_is1) (Version: 5.0.113 - MSI) Loadout (HKLM-x32\...\Steam App 208090) (Version: - Edge of Reality) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.130.10 - McAfee, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0 - Microsoft Corporation) Hidden Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{D285FC5F-3021-32E9-9C59-24CA325BDC5C}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Mozilla Firefox 23.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 23.0.1 (x86 de)) (Version: 23.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.0 - Mozilla) MSI HOUSE (HKLM-x32\...\{DA5597C9-9216-44FF-9670-D1E48817B998}) (Version: 10.07.1601 - MSI) MSI Intel Extreme Tuning Utility (HKLM-x32\...\{2301bb34-385a-4a57-877f-c54347957fad}) (Version: 4.0.6.305 - Intel Corporation) MSI Intel Extreme Tuning Utility (x32 Version: 4.0.6.305 - Intel Corporation) Hidden MSI Kombustor 2.5.0 (HKLM-x32\...\{0B7C79A5-5CB2-4ABD-A9C1-92A6213CE8DD}_is1) (Version: - MSI Co., LTD) MSI Software Install (HKLM-x32\...\{332EBFE0-C39E-42D1-99B5-ABBBECAD71B6}) (Version: 4.0.1105.1701 - Micro-Star International Co., Ltd.) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nether (HKLM-x32\...\Steam App 247730) (Version: - Phosphor Games) Nether Launcher (HKLM\...\{BA92D323-2D01-407D-AA36-285413610376}) (Version: 16.22.0.0 - Nether Productions, LLC.) NVIDIA CUDA Documentation 5.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_CUDADocumentation_5.5) (Version: 5.5 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Nsight Visual Studio Edition 3.1.0.13141 (HKLM\...\{46665C63-E5FA-45FE-ACBC-C1B6A78483F3}) (Version: 3.1.0.13141 - NVIDIA Corporation) NVIDIA Optimus Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Performance (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 6.5 - NVIDIA Corporation) NVIDIA Performance (x32 Version: 6.5 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA System Monitor (HKLM-x32\...\InstallShield_{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}) (Version: 6.5 - NVIDIA Corporation) NVIDIA System Monitor (x32 Version: 6.5 - NVIDIA Corporation) Hidden NVIDIA System Update (HKLM-x32\...\InstallShield_{65A92AAA-3D05-4C94-9F70-731C05E60C16}) (Version: 3.00 - NVIDIA Corporation) NVIDIA System Update (x32 Version: 3.00 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 334.89 (Version: 334.89 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) Origin (HKLM-x32\...\Origin) (Version: 9.0.13.2142 - Electronic Arts, Inc.) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.9 - Pando Networks Inc.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 9.2 - Qualcomm Atheros) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6959 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.28124 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4123-B2B9-173F09590E16}) (Version: 1.00.0180 - ) S-Bar (HKLM-x32\...\{39BDC923-826E-4007-8179-50E7C570E545}) (Version: 21.011.11023 - Micro-Star International Co.,Ltd.) SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) State of Decay (HKLM-x32\...\Steam App 241540) (Version: - Undead Labs) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.019 - MSI) TeamingGenie (HKLM-x32\...\{AF9B9CCF-D1B4-44B4-A030-BFCF5686AA5E}_is1) (Version: 1.0.1.3 - MSI) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.24951 - TeamViewer) Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH) The Walking Dead: Season Two (HKLM-x32\...\Steam App 261030) (Version: - Telltale Games) Thief (HKLM-x32\...\VGhpZWY=_is1) (Version: 1 - ) THX TruStudio Pro (HKLM-x32\...\{4FA6CB9A-2972-4AAF-A36E-3C40FCC22395}) (Version: 1.04.01 - Creative Technology Limited) Tt eSPORTS ShockONE gaming headset Driver V1.0 (HKLM-x32\...\{4B4DB54B-A017-4E82-8995-AC752FEBCDD8}_is1) (Version: - Ttesports Inc.) TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.143 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities) (Version: 14.0.1000.143 - TuneUp Software) TuneUp Utilities 2014 (x32 Version: 14.0.1000.143 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 10.0.4600.4 - TuneUp Software) Hidden Überwachungstool für die Intel® Turbo-Boost-Technik 2.5 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.6.2.0 - Intel) Updater (HKLM-x32\...\{D54E3D9F-FEB8-4D2D-A138-B69A5C80080B}) (Version: 2.6.53 - Creative Island Media, LLC) <==== ATTENTION Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Vodafone Mobile Broadband Lite (HKLM-x32\...\{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}) (Version: 10.3.2.34962 - Vodafone) Winamp (HKLM-x32\...\Winamp) (Version: 5.66 - Nullsoft, Inc) Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - ) WMV Converter 3.2 (HKLM-x32\...\{867D3E0B-B774-4BB6-B439-675E62C6386A}_is1) (Version: - WMV Converter) ==================== Restore Points ========================= 12-03-2014 19:52:48 Windows Update 17-03-2014 23:20:07 Windows Update 18-03-2014 12:05:43 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 18-03-2014 12:07:10 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 18-03-2014 12:08:26 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 18-03-2014 20:12:46 DirectX wurde installiert 19-03-2014 09:07:10 DirectX wurde installiert 19-03-2014 09:45:17 DirectX wurde installiert 19-03-2014 12:49:33 DirectX wurde installiert 19-03-2014 16:12:58 Wiederherstellungsvorgang 19-03-2014 16:33:46 Windows Update 19-03-2014 16:42:50 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {04C00BE8-1AE3-41AF-AB32-45F0E2F0254C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001Core => C:\Users\BaNgMaN\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-20] (Google Inc.) Task: {069A68DE-34A0-4DB2-AC5C-3E7C3144E849} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {1253B760-607C-4AEC-8C05-68F962C4ADAC} - System32\Tasks\Dealply => C:\Users\BaNgMaN\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {24438DEB-7886-4357-9899-207EAE8CF077} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {2680AB76-F624-45BE-B23D-46DA5EEF380A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {26947450-062C-453C-B64A-E4A310A16C4C} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {295A4867-45FB-48C7-AF2A-A6D1FC28A919} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {31ADC117-8D5C-4D29-83C9-8D09995ACD92} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {384A27E7-8F62-4997-ADCE-AE85B2904266} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2011 => C:\Program Files (x86)\TuneUp Utilities 2011\OneClick.exe Task: {44852407-A749-4740-A64A-82CFEB9BC043} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION Task: {4B8D9B02-C026-4F4B-919A-CDBCAE1841C8} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001UA => C:\Users\BaNgMaN\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-04] (Facebook Inc.) Task: {563B6C7C-07D1-4B04-8F15-3C0F2DB8F3CB} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-19] (Adobe Systems Incorporated) Task: {56C350E9-90B3-446C-AB19-71DFE97D1F9D} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation) Task: {5FACCD1F-E8AA-48A5-B636-40C1A7538CAF} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-10-16] () <==== ATTENTION Task: {621B583A-982C-409D-A1EC-21C733A59CC1} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {750C9882-3A31-4D7C-AA86-AEBEA02B228C} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2013-10-12] (TuneUp Software) Task: {7B168271-D2A1-4CAB-B985-F4572F17DF5F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001UA => C:\Users\BaNgMaN\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-20] (Google Inc.) Task: {7D7B95A7-B359-4FBD-A0EA-4E9A51029941} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-25] (Google Inc.) Task: {7F139A04-5849-4E1C-8F73-FB65EF375B87} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-10-24] (DealPly Technologies Ltd) <==== ATTENTION Task: {81EA49D2-A1A5-4949-A4BE-B2A208E97A4E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-25] (Google Inc.) Task: {8ACF0CA3-FF22-4975-B88F-CFE7C714FA10} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe Task: {A6522BED-3B97-4954-8586-077D1F7EB68A} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe Task: {A90A3A1D-4BF7-481A-AB21-7884FDF1AFFB} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-10-24] (DealPly Technologies Ltd) <==== ATTENTION Task: {AFF0CB17-D3D9-442C-9D32-E672C244D5A7} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {B8BB68E4-281C-4A49-8EB8-7FF5166EA20A} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.) Task: {BBAC38FA-2AB1-4D40-A379-BCBB915309EE} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {C1D5F4FE-B3D2-41CD-BD83-DC2B3A5997B6} - System32\Tasks\BEETmobile => C:\Program Files (x86)\BEETmobile\BEETmobile.exe [2012-10-30] (BEETmobile) Task: {E0EDFB2F-5B0C-40BA-8609-E3CD9E556AB4} - System32\Tasks\Google Updater and Installer => C:\Users\BaNgMaN\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-20] (Google Inc.) Task: {E23663B4-2DBE-40E3-8710-8D41FDC48B47} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe Task: {FFDBD657-905F-488C-8966-832FE9470AE2} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001Core => C:\Users\BaNgMaN\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-03-04] (Facebook Inc.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe <==== ATTENTION Task: C:\windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe <==== ATTENTION Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001Core.job => C:\Users\BaNgMaN\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001UA.job => C:\Users\BaNgMaN\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001Core.job => C:\Users\BaNgMaN\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001UA.job => C:\Users\BaNgMaN\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-10 20:32 - 2014-02-08 19:34 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2014-02-14 21:21 - 2014-02-08 18:42 - 00117024 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-12-06 02:30 - 2013-12-06 02:30 - 00040448 _____ () C:\ProgramData\InternetUpdater\InternetUpdaterService.exe 2012-10-21 13:35 - 2013-12-05 15:59 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2013-10-12 02:29 - 2013-10-12 02:29 - 00757048 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2012-04-12 18:18 - 2010-05-04 19:00 - 00237056 _____ () C:\windows\SYSTEM32\APOMgr64.DLL 2012-04-12 01:58 - 2012-02-27 17:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-06-28 17:56 - 2013-06-28 17:56 - 00733184 _____ () C:\Users\BaNgMaN\Documents\GIGABYTE\AIVIA GHOST\Tilt.exe 2012-09-18 15:41 - 2012-09-18 15:41 - 00191488 _____ () C:\Users\BaNgMaN\Documents\GIGABYTE\AIVIA GHOST\GHOSTOPEN.exe 2013-05-09 00:08 - 2014-03-08 19:46 - 01116672 _____ () C:\Program Files (x86)\OBS\OBS.exe 2014-02-14 21:20 - 2014-02-14 21:20 - 00409600 _____ () C:\Users\BaNgMaN\Desktop\darkfix.exe 2014-03-19 17:40 - 2014-03-19 17:40 - 00173568 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll 2014-03-19 17:40 - 2014-03-19 17:40 - 01080832 _____ () C:\Program Files\TeamSpeak 3 Client\platforms\qwindows.dll 2014-03-19 17:40 - 2014-03-19 17:40 - 00833024 _____ () C:\Program Files\TeamSpeak 3 Client\sqldrivers\qsqlite.dll 2012-10-24 16:08 - 2014-03-19 17:40 - 00102344 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2012-10-24 16:08 - 2014-03-19 17:40 - 00108488 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2014-03-19 17:40 - 2014-03-19 17:40 - 00030208 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qgif.dll 2014-03-19 17:40 - 2014-03-19 17:40 - 00233984 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg.dll 2012-10-24 16:08 - 2014-03-19 17:40 - 00134088 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\appscanner_plugin.dll 2012-10-24 16:08 - 2014-03-19 17:40 - 00563656 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2013-09-09 12:51 - 2014-03-19 17:40 - 00577480 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2013-10-02 11:45 - 2014-03-13 07:48 - 09706368 _____ () D:\SteamLibrary\SteamApps\common\The War Z\Infestation.exe 2012-10-21 13:35 - 2014-03-19 20:21 - 00291128 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-01-10 20:32 - 2014-02-08 19:34 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2012-04-12 18:18 - 2011-11-04 20:24 - 00159744 _____ () C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\de-DE\THXAudio.resources.dll 2013-05-26 11:36 - 2013-03-20 14:45 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2013-05-09 00:07 - 2014-03-08 19:46 - 01878528 _____ () C:\Program Files (x86)\OBS\OBSApi.dll 2013-05-09 00:07 - 2014-03-08 19:46 - 00162304 _____ () C:\Program Files (x86)\OBS\plugins\DShowPlugin.dll 2013-05-09 00:07 - 2014-03-08 19:46 - 00108544 _____ () C:\Program Files (x86)\OBS\plugins\GraphicsCapture.dll 2013-05-09 00:08 - 2014-03-08 19:46 - 00096256 _____ () C:\Program Files (x86)\OBS\plugins\NoiseGate.dll 2014-02-16 08:04 - 2014-03-08 19:46 - 00055296 _____ () C:\Program Files (x86)\OBS\plugins\PSVPlugin.dll 2012-10-20 18:00 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2012-11-29 22:59 - 2012-11-29 22:59 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2013-08-13 09:33 - 2013-07-25 01:48 - 00601552 _____ () C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\libglesv2.dll 2013-08-13 09:33 - 2013-07-25 01:48 - 00123344 _____ () C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\libegl.dll 2013-08-13 09:33 - 2013-07-25 01:49 - 04052944 _____ () C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll 2013-08-13 09:33 - 2013-07-25 01:49 - 00396240 _____ () C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll 2013-08-13 09:33 - 2013-07-25 01:48 - 01597392 _____ () C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ffmpegsumo.dll 2014-03-19 19:15 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-03-19 19:15 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2014-03-19 19:15 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2014-03-19 19:15 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2014-03-19 19:15 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2013-09-17 10:50 - 2014-03-19 16:54 - 02044928 _____ () D:\SteamLibrary\SteamApps\common\The War Z\ts3client_win32.dll 2013-09-17 10:50 - 2013-09-17 10:50 - 00076800 _____ () D:\SteamLibrary\SteamApps\common\The War Z\CrashRpt1301.dll 2013-09-17 10:50 - 2013-09-17 10:50 - 00230384 _____ () D:\SteamLibrary\SteamApps\common\The War Z\soundbackends\directsound_win32.dll 2013-09-17 10:50 - 2013-09-17 10:50 - 00233456 _____ () D:\SteamLibrary\SteamApps\common\The War Z\soundbackends\windowsaudiosession_win32.dll 2013-09-19 14:43 - 2014-03-19 16:54 - 00479232 _____ () D:\SteamLibrary\SteamApps\common\The War Z\pb\pbsv.dll 2013-09-17 11:07 - 2013-09-19 14:43 - 00964936 _____ () D:\SteamLibrary\SteamApps\common\The War Z\pb\pbcl.dll 2013-08-29 12:21 - 2013-09-19 14:43 - 00063832 _____ () C:\Users\BaNgMaN\AppData\Local\PunkBuster\TWZ\pb\pbag.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: MobileBroadband => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent MSCONFIG\startupreg: S-Bar => C:\Program Files\S-Bar\S-Bar.exe MSCONFIG\startupreg: Ttesports => C:\Program Files (x86)\Ttesports\ShockONE\ShockTray.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/19/2014 07:10:51 PM) (Source: Application Hang) (User: ) Description: Programm avcenter.exe, Version 14.0.3.332 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: d28 Startzeit: 01cf439dbcd0ef2c Endzeit: 60000 Anwendungspfad: C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe Berichts-ID: a2126612-af91-11e3-9349-001e101f859f Error: (03/19/2014 05:47:09 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall Error: (03/19/2014 05:43:44 PM) (Source: Microsoft Security Client Setup) (User: BaNgMaN-MSI) Description: HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation was canceled. You canceled the Security Essentials installation on your computer. Error code:0x8004FF0A. Error: (03/19/2014 05:42:25 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT) Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet! Error: (03/19/2014 05:41:35 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT) Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet! Error: (03/19/2014 05:41:26 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT) Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet! Error: (03/19/2014 05:32:37 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "F:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" Error: (03/19/2014 05:22:24 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/19/2014 05:22:19 PM) (Source: VmbService) (User: ) Description: conflictManagerTypeValue Error: (03/19/2014 05:21:51 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT) Description: Die Lizenzdatei enthält keine gültige Lizenz. Der Dienst wird beendet! System errors: ============= Error: (03/19/2014 05:41:35 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (03/19/2014 05:22:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (03/19/2014 05:13:55 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (03/18/2014 04:45:55 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "J:" den Befehl "chkdsk" aus. Error: (03/18/2014 04:45:54 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Daten" den Befehl "chkdsk" aus. Error: (03/18/2014 04:45:53 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Daten" den Befehl "chkdsk" aus. Error: (03/18/2014 04:45:53 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Daten" den Befehl "chkdsk" aus. Error: (03/18/2014 04:39:11 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Daten" den Befehl "chkdsk" aus. Error: (03/18/2014 04:39:10 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Daten" den Befehl "chkdsk" aus. Error: (03/18/2014 04:39:08 PM) (Source: Ntfs) (User: ) Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar. Führen Sie auf dem Volume "Daten" den Befehl "chkdsk" aus. Microsoft Office Sessions: ========================= Error: (03/19/2014 07:10:51 PM) (Source: Application Hang)(User: ) Description: avcenter.exe14.0.3.332d2801cf439dbcd0ef2c60000C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exea2126612-af91-11e3-9349-001e101f859f Error: (03/19/2014 05:47:09 PM) (Source: Steam Client Service)(User: ) Description: Failed to poke open firewall Error: (03/19/2014 05:43:44 PM) (Source: Microsoft Security Client Setup)(User: BaNgMaN-MSI) Description: HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation was canceled. You canceled the Security Essentials installation on your computer. Error code:0x8004FF0A. Error: (03/19/2014 05:42:25 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT) Description: 0x0 Error: (03/19/2014 05:41:35 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT) Description: 0x0 Error: (03/19/2014 05:41:26 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT) Description: 0x0 Error: (03/19/2014 05:32:37 PM) (Source: Windows Backup)(User: ) Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006) Error: (03/19/2014 05:22:24 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/19/2014 05:22:19 PM) (Source: VmbService)(User: ) Description: conflictManagerTypeValue Error: (03/19/2014 05:21:51 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT) Description: 0x0 CodeIntegrity Errors: =================================== Date: 2013-03-20 04:17:24.372 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-20 04:17:24.357 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-19 18:20:14.076 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-19 18:20:14.045 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-18 08:15:25.060 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-18 08:15:25.029 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-17 18:21:00.499 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-17 18:21:00.468 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-17 08:07:45.154 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-03-17 08:07:45.123 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\ATITool64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 35% Total physical RAM: 16280.95 MB Available physical RAM: 10517.27 MB Total Pagefile: 32560.07 MB Available Pagefile: 25450.04 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS_Install) (Fixed) (Total:271.96 GB) (Free:81.2 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:181.31 GB) (Free:110.63 GB) NTFS Drive f: (10.3.2.34962_RC1) (CDROM) (Total:0.04 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 4A2DAD7E) Partition 1: (Not Active) - (Size=12 GB) - (Type=07 NTFS) Partition 2: (Active) - (Size=100 MB) - (Type=27) Partition 3: (Not Active) - (Size=272 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=181 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by BaNgMaN (administrator) on BANGMAN-MSI on 19-03-2014 20:24:52 Running from C:\Users\BaNgMaN\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe (Microsoft Corporation) C:\windows\system32\WLANExt.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\ProgramData\InternetUpdater\InternetUpdaterService.exe (MSI) C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe () C:\windows\SysWOW64\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\windows\System32\alg.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Updater) C:\ProgramData\Updater\updater.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Users\BaNgMaN\Documents\GIGABYTE\AIVIA GHOST\Tilt.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe () C:\Users\BaNgMaN\Documents\GIGABYTE\AIVIA GHOST\GHOSTOPEN.exe (WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (WatchDog) C:\ProgramData\RHelpers\FireFoxHelper\FireFoxHelper.exe (WatchDog) C:\ProgramData\RHelpers\IEHelper\IeHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\OBS\OBS.exe () C:\Users\BaNgMaN\Desktop\darkfix.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () D:\SteamLibrary\SteamApps\common\The War Z\Infestation.exe () C:\windows\SysWOW64\PnkBstrB.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2859344 2012-07-23] (ELAN Microelectronics Corp.) HKLM\...\Run: [THXCfg64] - C:\windows\system32\THXCfg64.dll [25600 2010-09-14] (Creative Technology Ltd.) HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-03-22] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13631704 2013-06-28] (Realtek Semiconductor) HKLM\...\Run: [BLEServicesCtrl] - C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [184112 2012-05-31] (Intel Corporation) HKLM\...\Run: [BTMTrayAgent] - C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [11586944 2012-06-18] (Motorola Solutions, Inc.) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [IntelTBRunOnce] - wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [ShadowPlay] - C:\windows\system32\nvspcap64.dll [1179576 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1517056 2011-08-30] (Creative Technology Ltd) HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-10-13] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [230696 2011-10-13] (CyberLink Corp.) HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1573584 2012-10-16] (Ask) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.) HKLM-x32\...\Run: [Tilt] - C:\Users\BaNgMaN\Documents\GIGABYTE\AIVIA GHOST\Tilt.exe [733184 2013-06-28] () HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [490480 2013-08-13] (MSI) HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\Updater.exe [486264 2013-12-18] (Updater) HKLM-x32\...\Run: [ghost] - C:\Users\BaNgMaN\Documents\GIGABYTE\AIVIA GHOST\ghostopen.exe [191488 2012-09-18] () HKLM-x32\...\Run: [Live Update 5] - C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe [315392 2012-01-30] () HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\Run: [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\BaNgMaN\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [486264 2013-12-18] (Updater) HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\RunOnce: [Application Restart #0] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [846288 2013-07-25] (Google Inc.) HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\MountPoints2: F - F:\setup_vmb_lite.exe /checkApplicationPresence HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\MountPoints2: {21fb097d-2256-11e2-b0d3-001e101f2b52} - I:\autorun.exe HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\MountPoints2: {5b99bc93-4791-11e2-9919-8c89a5054762} - F:\setup_vmb_lite.exe /checkApplicationPresence HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\MountPoints2: {6540ff58-1ccd-11e2-825b-0cd29204c3ab} - F:\setup_vmb_lite.exe /checkApplicationPresence HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\MountPoints2: {88f0e344-5a59-11e3-9d1b-00e04c0fe37b} - F:\setup_vmb_lite.exe /checkApplicationPresence HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\MountPoints2: {904c3f90-1b36-11e2-ad11-8c89a5054762} - F:\setup_vmb_lite.exe /checkApplicationPresence HKU\S-1-5-21-3037997946-340245006-2111326209-1001\...\MountPoints2: {904c4064-1b36-11e2-ad11-8c89a5054762} - F:\setup_vmb_lite.exe /checkApplicationPresence AppInit_DLLs: c:\progra~2\movies~1\safety~1\x64\safety~2.dll => c:\progra~2\movies~1\safety~1\x64\safety~2.dll File Not Found AppInit_DLLs: ,c:\windows\system32\nvinitx.dll => c:\windows\system32\nvinitx.dll [174296 2014-02-08] (NVIDIA Corporation) AppInit_DLLs: ,C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [174296 2014-02-08] (NVIDIA Corporation) AppInit_DLLs-x32: c:\progra~2\movies~1\safety~1\safety~2.dll => "c:\progra~2\movies~1\safety~1\safety~2.dll" File Not Found AppInit_DLLs-x32: ,c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [148528 2014-02-08] (NVIDIA Corporation) AppInit_DLLs-x32: ,C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [148528 2014-02-08] (NVIDIA Corporation) IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\firefox.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\iCloud.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\icloudweb.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\imfrmwrk.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\itunes.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\s-bar.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\shellstreamsshortcut.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" IFEO\TeamViewer.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2014\TUAutoReactivator64.exe" ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.search.yahoo.com?type=407956&fr=spigot-yhp-ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} SearchScopes: HKCU - DefaultScope {595EC4B6-80BA-456F-9B6C-F350CE2BD89D} URL = SearchScopes: HKCU - {017C807F-02F8-4F93-8182-AD628935E2A2} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=407956&p={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=C4C00CD29204C3AC SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90&q={searchTerms} SearchScopes: HKCU - {595EC4B6-80BA-456F-9B6C-F350CE2BD89D} URL = SearchScopes: HKCU - {620544BC-9640-4642-9057-A5777196E596} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^VK^DE&apn_uid=9a312e9b-52f0-4f7c-9432-2e2a3a668021&apn_sauid=B9264376-1C80-41BE-8A45-F64ED99612DF SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = hxxp://www.daemon-search.com/search?q={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: DealPly Shopping - {ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly) BHO-x32: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: smartdownloader Class - {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - No File Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{3167F3D4-082A-4150-9296-7E2DF1D361FB}: [NameServer]139.7.30.125 139.7.30.126 Tcpip\..\Interfaces\{B1D80E8F-13A5-4F21-AAC1-43A37493151A}: [NameServer]139.7.30.125 139.7.30.126 Tcpip\..\Interfaces\{F253A197-A36D-441F-8EF8-8AE05A605E0A}: [NameServer]193.189.244.225 193.189.244.206 FireFox: ======== FF ProfilePath: C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default FF user.js: detected! => C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default\user.js FF DefaultSearchEngine: nationzoom FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn/esnlaunch,version=1.140.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.20 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\BaNgMaN\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\BaNgMaN\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\BaNgMaN\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File FF Plugin ProgramFiles/Appdata: C:\Users\BaNgMaN\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\BaNgMaN\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin ProgramFiles/Appdata: C:\Users\BaNgMaN\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default\searchplugins\yahoo_ff.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\nationzoom.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default\Extensions\{906000a4-88d9-4d52-b209-7a772970d91f} [2013-10-24] FF Extension: Better Battlelog (BBLog) - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack.xpi [2013-06-20] FF Extension: Adblock Plus - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-03-15] FF Extension: Greasemonkey - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\Profiles\uw74n90q.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-03-11] FF Extension: No Name - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2013-10-24] FF Extension: No Name - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\profiles\extensions\searchplugins [2013-10-24] FF Extension: Movie2kDownloader - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\profiles\extensions\movie2kdownloader@movie2kdownloader.com.xpi [2012-12-13] FF Extension: No Name - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\Firefox\profiles\extensions\putlockerdownloader@putlockerdownloader.com.xpi [2012-11-06] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2014-02-09] FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.nationzoom.com/?type=sc&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 Chrome: ======= CHR HomePage: hxxp://google.com/ CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Talk Plugin) - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\BaNgMaN\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File CHR Plugin: (Battlelog Game Launcher) - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll No File CHR Plugin: (DealPlyLive Update) - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File CHR Plugin: ( "name": "",) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: ( "name": "",) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (McAfee Security Scanner +) - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\BaNgMaN\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll No File CHR Extension: (BetterTTV) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2014-02-02] CHR Extension: (Adblock Plus) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-06] CHR Extension: (TwitchTV Dashboard Plus) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\eghafjficgdffelombnhmkmgjcggkifb [2014-01-06] CHR Extension: (Zombie Pandemic) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjeadljomcehnkijillijhcnblejgfd [2014-03-18] CHR Extension: (AdBlock) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-06] CHR Extension: (Twitch Chat Enhancer) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnhffjchmkbfikdknajefcfggdlpjpcp [2014-01-06] CHR Extension: (Twitch Live) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\iiljidcefnbhbpamageahhblhbbhhopm [2014-01-06] CHR Extension: (Halloween Soundboard) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbapfeeikjglmbineeobmlbnebdglfbn [2014-03-15] CHR Extension: (Dead Zed Zombie) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhiflblofckjcpphgcoajnebhbdpja [2014-03-18] CHR Extension: (Reptoiden Control - User) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhlbbalfcodgamfhcgcjpnmnjccoakjh [2014-01-06] CHR Extension: (The Walking Dead) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\mldegbgicinanjcfknlopehddepkpial [2014-03-18] CHR Extension: (Adblock Pro) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2014-01-06] CHR Extension: (Battlefield 3) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pagmklehiaheilihklokljahmoihkjni [2014-02-10] CHR Extension: (Twitch Giveaways) - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\poohjpljfecljomfhhimjhddddlidhdd [2014-01-06] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-01-06] CHR HKLM-x32\...\Chrome\Extension: [aaaaabfjnbeinlpljodiajipidiompfl] - C:\Users\BaNgMaN\AppData\Local\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.8.0.crx [2012-10-20] CHR HKLM-x32\...\Chrome\Extension: [apfdadfinodckpcehhdhjlgiphgnbfci] - C:\Program Files (x86)\PutLockerDownloader\putlockerdownloader10.crx [2012-10-20] CHR HKLM-x32\...\Chrome\Extension: [blaofbhgbmeikidhlkmjhbkbfohpgekf] - C:\Program Files (x86)\Movie2KDownloader.com\Movie2KDownloader10.crx [2012-10-20] CHR HKLM-x32\...\Chrome\Extension: [hbcennhacfaagdopikcegfcobcadeocj] - C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.1.crx [2013-10-10] CHR HKLM-x32\...\Chrome\Extension: [icdlfehblmklkikfigmjhbmmpmkmpooj] - C:\Program Files (x86)\Common Files\Spigot\GC\errorassistant_1.1.crx [2013-10-10] CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\BaNgMaN\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2014-01-06] CHR HKLM-x32\...\Chrome\Extension: [mhkaekfpcppmmioggniknbnbdbcigpkk] - C:\Program Files (x86)\Common Files\Spigot\GC\coupons_2.4.crx [2013-04-26] CHR HKLM-x32\...\Chrome\Extension: [pfndaklgolladniicklehhancnlgocpp] - C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx [2012-11-22] CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1388998831&from=adks&uid=WDCXWD5000BPVT-22HXZT3_WD-WXB1E62HEV90HEV90 CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-12-15] () S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-10-24] (DealPly Technologies Ltd) S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-10-24] (DealPly Technologies Ltd) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-03-22] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-20] (Intel Corporation) R2 InternetUpdater; C:\ProgramData\InternetUpdater\InternetUpdaterService.exe [40448 2013-12-06] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-20] (Intel Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) S4 Micro Star SCM; C:\Program Files (x86)\S-Bar\MSIService.exe [160768 2011-11-02] (Micro-Star International Co., Ltd.) R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI HOUSE\MSIFoundationService.exe [12800 2010-07-17] (MSI) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161776 2013-08-19] (MSI) S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [276584 2010-03-22] (NVIDIA) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2013-12-05] () R2 PnkBstrB; C:\windows\SysWOW64\PnkBstrB.exe [291128 2014-03-19] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2099512 2013-10-12] (TuneUp Software) R2 UpdateCenterService; C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe [282728 2009-11-06] (NVIDIA) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [15888 2013-04-01] (Intel(R) Corporation) S4 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== S3 ATITool; C:\Windows\System32\DRIVERS\ATITool64.sys [30720 2006-11-10] () R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2014-02-05] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.) S3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-05-19] (DT Soft Ltd) R3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [415232 2011-10-18] (Huawei Technologies Co., Ltd.) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-22] (Intel Corporation) R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [25448 2013-01-07] (Intel Corporation) S3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [19952 2013-02-01] (Windows (R) Win 7 DDK provider) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2014-02-05] () R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-03-20] (Intel Corporation) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [14136 2010-10-22] (MSI) R3 nvoclk64; C:\Windows\System32\DRIVERS\nvoclk64.sys [42088 2009-09-15] (NVIDIA Corp.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R3 SjtWinIo; C:\Windows\System32\DRIVERS\SjtWinIo.sys [9216 2014-01-06] (SpeedJet Technology INC.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software) S3 MGHwCtrl; \??\C:\Program Files\MSI\MSI Software Install\MGHwCtrl.sys [X] S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X] S3 NTIOLib_1_0_C; \??\C:\MSI\MSI SUITE\NTIOLib_X64.sys [X] S3 NTIOLib_1_1_S; \??\C:\MSI\MSI SUITE\Super-Charger\NTIOLib_X64.sys [X] S4 nvkflt; system32\DRIVERS\nvkflt.sys [X] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013a\WNt500x64\Sandra.sys [X] U2 TMAgent; S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X] S3 xhunter1; \??\C:\windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-19 20:22 - 2014-03-19 20:24 - 00050925 _____ () C:\Users\BaNgMaN\Desktop\Addition.txt 2014-03-19 20:20 - 2014-03-19 20:25 - 00041231 _____ () C:\Users\BaNgMaN\Desktop\FRST.txt 2014-03-19 20:19 - 2014-03-19 20:24 - 00000000 ____D () C:\FRST 2014-03-19 20:19 - 2014-03-19 20:19 - 02157056 _____ (Farbar) C:\Users\BaNgMaN\Desktop\FRST64.exe 2014-03-19 19:24 - 2014-03-19 19:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\BaNgMaN\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-19 19:24 - 2014-03-19 19:24 - 00001119 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-19 19:24 - 2014-03-19 19:24 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\Malwarebytes 2014-03-19 19:24 - 2014-03-19 19:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-19 19:24 - 2014-03-19 19:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-19 19:24 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-03-19 19:15 - 2014-03-19 19:20 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-03-19 19:15 - 2014-03-19 19:15 - 00001389 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-03-19 19:15 - 2014-03-19 19:15 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking 2014-03-19 19:15 - 2014-03-19 19:15 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-19 19:15 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe 2014-03-19 19:13 - 2014-03-19 19:13 - 00613200 _____ (Chip Digital GmbH) C:\Users\BaNgMaN\Downloads\SpyBot Search Destroy - CHIP-Downloader.exe 2014-03-19 10:38 - 2014-03-19 10:38 - 00000219 _____ () C:\Users\BaNgMaN\Desktop\Counter-Strike Global Offensive.url 2014-03-19 07:15 - 2014-03-19 07:15 - 08542519 _____ () C:\Users\BaNgMaN\Downloads\dll new z.rar 2014-03-19 07:12 - 2014-03-19 07:12 - 03325968 _____ () C:\Users\BaNgMaN\Downloads\TheNewZ (2).zip 2014-03-19 07:12 - 2014-03-19 07:12 - 03325968 _____ () C:\Users\BaNgMaN\Downloads\TheNewZ (1).zip 2014-03-19 07:09 - 2014-03-19 07:09 - 07688488 _____ () C:\Users\BaNgMaN\Downloads\Launcher + NewZ.dll + NewZ.exe (1).rar 2014-03-19 01:10 - 2014-03-19 17:18 - 00000000 ____D () C:\Program Files (x86)\The New Z 2014-03-18 13:08 - 2014-03-18 13:08 - 00196754 _____ () C:\Users\BaNgMaN\Downloads\msvcp110.zip 2014-03-18 12:54 - 2014-03-18 12:54 - 44221577 _____ () C:\Users\BaNgMaN\Downloads\herro!.rar 2014-03-18 12:53 - 2014-03-18 12:53 - 07688488 _____ () C:\Users\BaNgMaN\Downloads\Launcher + NewZ.dll + NewZ.exe.rar 2014-03-18 12:49 - 2014-03-18 12:49 - 00000000 ____D () C:\Users\BaNgMaN\Documents\The New Z Entertainment 2014-03-17 14:32 - 2014-03-17 14:32 - 03325968 _____ () C:\Users\BaNgMaN\Downloads\TheNewZ.zip 2014-03-15 13:41 - 2014-03-15 13:41 - 00048313 _____ () C:\Users\BaNgMaN\Downloads\Barney-Stinson-LegenWait-for-itDary.m4r 2014-03-10 12:20 - 2014-03-10 12:20 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\{95A13E8E-145C-4FBE-9F9B-762EE654100C} 2014-03-08 19:51 - 2014-03-15 23:26 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\NVIDIA 2014-03-07 07:11 - 2014-03-19 17:43 - 00002052 _____ () C:\windows\epplauncher.mif 2014-03-05 10:13 - 2014-03-05 10:13 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\{51115717-1D34-49CB-A00F-95925D75AA6B} 2014-03-04 17:52 - 2014-03-04 17:52 - 02970992 _____ () C:\Users\BaNgMaN\Downloads\MorphVOXJunior_Install-1.exe 2014-03-04 14:42 - 2013-12-14 06:19 - 00000000 ____D () C:\Users\BaNgMaN\Downloads\CSGOOverlay 2014-03-04 14:41 - 2014-03-04 14:41 - 20804451 _____ () C:\Users\BaNgMaN\Downloads\csgooverlay169.rar 2014-03-02 18:11 - 2014-03-02 18:12 - 00000000 ____D () C:\Users\BaNgMaN\Documents\Thief 2014-03-02 18:07 - 2014-03-02 18:07 - 00000583 _____ () C:\Users\Public\Desktop\Thief.lnk 2014-03-02 02:25 - 2014-03-19 17:19 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games 2014-03-02 02:25 - 2014-03-02 02:25 - 00000000 ____D () C:\windows\Advanced AI Mod 2014-03-02 02:24 - 2014-03-02 02:24 - 00000877 _____ () C:\Users\BaNgMaN\Desktop\CnC Europe.lnk 2014-03-02 02:19 - 2014-03-02 02:23 - 00000000 ____D () C:\Users\BaNgMaN\Desktop\Mods 2014-03-01 23:44 - 2014-03-02 02:34 - 00000000 ____D () C:\Users\BaNgMaN\Documents\Command & Conquer Generäle Stunde Null Data 2014-03-01 23:40 - 2014-03-01 23:44 - 00000993 _____ () C:\windows\eReg.dat 2014-03-01 23:20 - 2014-03-19 17:19 - 00000000 ____D () C:\Users\BaNgMaN\Desktop\Command & Conquer Generals - Stunde Null 2014-03-01 15:31 - 2014-03-01 15:31 - 00000000 ____D () C:\Users\BaNgMaN\Documents\EntityGaming 2014-03-01 15:31 - 2014-03-01 15:31 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\EntityGaming 2014-03-01 15:19 - 2014-03-19 17:18 - 00000000 ____D () C:\DeadZ 2014-03-01 15:17 - 2014-03-01 15:18 - 4232201047 _____ () C:\Users\BaNgMaN\Downloads\DeadZReborn-Feb-28-2014.rar 2014-02-26 12:01 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-02-26 12:01 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-02-25 00:41 - 2014-02-22 22:13 - 19083278 _____ () C:\Users\BaNgMaN\Desktop\evasi0n7.exe 2014-02-21 15:02 - 2014-03-19 17:19 - 00000000 ____D () C:\windows\SysWOW64\NV 2014-02-21 15:02 - 2014-03-19 17:19 - 00000000 ____D () C:\windows\system32\NV 2014-02-21 15:00 - 2014-02-08 19:34 - 31432480 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 25256224 _____ (NVIDIA Corporation) C:\windows\system32\nvcompiler.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 23683360 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 18257576 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 17715784 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 17560352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcompiler.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 15740232 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 14669032 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 12324640 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys 2014-02-21 15:00 - 2014-02-08 19:34 - 11636176 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 11589272 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 09728064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 09690424 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 03142432 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 02956576 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 02782496 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvenc.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 02713728 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 02410784 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvenc.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 01885472 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6433489.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 01515296 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6433489.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00892192 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00875296 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00863520 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00844576 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00483104 _____ (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00408352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00378656 _____ (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00353504 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00333600 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00305600 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll 2014-02-21 15:00 - 2014-02-08 19:34 - 00032544 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvpciflt.sys 2014-02-19 06:33 - 2014-03-02 23:18 - 00330848 _____ () C:\windows\system32\FNTCACHE.DAT 2014-02-18 14:05 - 2014-03-02 14:18 - 00088296 _____ () C:\Users\BaNgMaN\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-18 14:01 - 2014-02-18 14:01 - 00228983 _____ () C:\Users\BaNgMaN\Downloads\soundboard-0.9.8.4b-win32.ts3_plugin ==================== One Month Modified Files and Folders ======= 2014-03-19 20:25 - 2014-03-19 20:20 - 00041231 _____ () C:\Users\BaNgMaN\Desktop\FRST.txt 2014-03-19 20:24 - 2014-03-19 20:22 - 00050925 _____ () C:\Users\BaNgMaN\Desktop\Addition.txt 2014-03-19 20:24 - 2014-03-19 20:19 - 00000000 ____D () C:\FRST 2014-03-19 20:21 - 2013-02-02 05:39 - 00001128 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001UA.job 2014-03-19 20:21 - 2012-10-21 15:47 - 00291128 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-03-19 20:21 - 2012-10-21 13:35 - 00291128 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-03-19 20:19 - 2014-03-19 20:19 - 02157056 _____ (Farbar) C:\Users\BaNgMaN\Desktop\FRST64.exe 2014-03-19 20:09 - 2013-10-24 12:04 - 00000908 _____ () C:\windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job 2014-03-19 20:01 - 2013-07-25 10:46 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-19 19:48 - 2012-10-21 13:35 - 00291128 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-03-19 19:42 - 2012-10-21 08:06 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-19 19:40 - 2013-05-26 10:25 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-03-19 19:38 - 2012-10-20 22:08 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-03-19 19:36 - 2013-03-05 13:58 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-03-19 19:24 - 2014-03-19 19:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\BaNgMaN\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-19 19:24 - 2014-03-19 19:24 - 00001119 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-19 19:24 - 2014-03-19 19:24 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\Malwarebytes 2014-03-19 19:24 - 2014-03-19 19:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-19 19:24 - 2014-03-19 19:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-19 19:20 - 2014-03-19 19:15 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-03-19 19:15 - 2014-03-19 19:15 - 00001389 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-03-19 19:15 - 2014-03-19 19:15 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking 2014-03-19 19:15 - 2014-03-19 19:15 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-19 19:13 - 2014-03-19 19:13 - 00613200 _____ (Chip Digital GmbH) C:\Users\BaNgMaN\Downloads\SpyBot Search Destroy - CHIP-Downloader.exe 2014-03-19 19:01 - 2012-10-29 17:51 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\TS3Client 2014-03-19 18:52 - 2012-10-20 18:48 - 01283191 _____ () C:\windows\WindowsUpdate.log 2014-03-19 18:38 - 2012-10-20 22:08 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-03-19 18:38 - 2012-10-20 22:08 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-03-19 18:38 - 2012-04-12 18:37 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-19 18:27 - 2013-10-09 14:12 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-03-19 17:43 - 2014-03-07 07:11 - 00002052 _____ () C:\windows\epplauncher.mif 2014-03-19 17:40 - 2012-10-29 17:50 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-19 17:36 - 2012-10-21 04:19 - 00000000 ___RD () C:\Users\BaNgMaN\Desktop\Games 2014-03-19 17:30 - 2009-07-14 05:45 - 00024432 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-19 17:30 - 2009-07-14 05:45 - 00024432 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-19 17:26 - 2012-04-12 01:18 - 00712584 _____ () C:\windows\system32\perfh007.dat 2014-03-19 17:26 - 2012-04-12 01:18 - 00154272 _____ () C:\windows\system32\perfc007.dat 2014-03-19 17:26 - 2009-07-14 06:13 - 01656482 _____ () C:\windows\system32\PerfStringBackup.INI 2014-03-19 17:23 - 2014-01-05 16:01 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\newnext.me 2014-03-19 17:22 - 2014-01-11 19:57 - 00016790 _____ () C:\windows\setupact.log 2014-03-19 17:21 - 2013-10-24 12:04 - 00000904 _____ () C:\windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job 2014-03-19 17:21 - 2013-07-25 10:46 - 00001108 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-19 17:21 - 2012-10-20 18:50 - 00000000 ____D () C:\Users\BaNgMaN 2014-03-19 17:21 - 2012-04-12 04:24 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-03-19 17:21 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-03-19 17:19 - 2014-03-02 02:25 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games 2014-03-19 17:19 - 2014-03-01 23:20 - 00000000 ____D () C:\Users\BaNgMaN\Desktop\Command & Conquer Generals - Stunde Null 2014-03-19 17:19 - 2014-02-21 15:02 - 00000000 ____D () C:\windows\SysWOW64\NV 2014-03-19 17:19 - 2014-02-21 15:02 - 00000000 ____D () C:\windows\system32\NV 2014-03-19 17:19 - 2014-02-13 13:37 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2014-03-19 17:19 - 2014-02-13 11:47 - 00000000 ____D () C:\Users\BaNgMaN\Desktop\TwitchAlerts V0.55 2014-03-19 17:19 - 2014-01-05 16:01 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\genienext 2014-03-19 17:19 - 2013-12-16 23:54 - 00000000 ____D () C:\Users\BaNgMaN\Documents\DayZ 2014-03-19 17:19 - 2013-11-30 11:26 - 00000000 ____D () C:\Users\BaNgMaN\Desktop\DJ 2014-03-19 17:19 - 2013-11-28 18:25 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\OBS 2014-03-19 17:19 - 2013-11-25 11:14 - 00000000 ____D () C:\Program Files (x86)\Winamp 2014-03-19 17:19 - 2013-10-24 12:35 - 00000000 ___HD () C:\SuperChargerProfile 2014-03-19 17:19 - 2013-10-24 12:04 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly 2014-03-19 17:19 - 2013-07-25 10:57 - 00000000 ____D () C:\uninstall 2014-03-19 17:19 - 2013-07-25 10:56 - 00000000 ____D () C:\ProgramData\Package Cache 2014-03-19 17:19 - 2013-03-29 10:51 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\Apps\Windows 7 USB DVD Download Tool 2014-03-19 17:19 - 2013-03-13 03:00 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-19 17:19 - 2013-01-02 15:42 - 00000000 ____D () C:\Users\BaNgMaN\Documents\Procon 2014-03-19 17:19 - 2012-10-21 15:47 - 00000000 ____D () C:\Users\BaNgMaN\Documents\Battlefield 3 2014-03-19 17:19 - 2012-10-21 04:17 - 00000000 ____D () C:\Program Files\WinRAR 2014-03-19 17:19 - 2012-04-12 18:37 - 00000000 ____D () C:\windows\system32\Macromed 2014-03-19 17:19 - 2012-04-12 18:37 - 00000000 ____D () C:\Program Files (x86)\WinRAR 3.61 Multi 2014-03-19 17:19 - 2012-04-12 04:40 - 00000000 ____D () C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation 2014-03-19 17:19 - 2012-04-12 04:31 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-03-19 17:18 - 2014-03-19 01:10 - 00000000 ____D () C:\Program Files (x86)\The New Z 2014-03-19 17:18 - 2014-03-01 15:19 - 00000000 ____D () C:\DeadZ 2014-03-19 17:18 - 2014-02-13 13:38 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-03-19 17:18 - 2014-01-10 20:26 - 00000000 ____D () C:\Program Files (x86)\S-Bar 2014-03-19 17:18 - 2013-10-24 12:04 - 00000000 ____D () C:\Program Files (x86)\DealPlyLive 2014-03-19 17:18 - 2013-10-24 12:04 - 00000000 ____D () C:\Program Files (x86)\DealPly 2014-03-19 17:18 - 2013-03-13 03:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-19 17:18 - 2013-02-11 09:44 - 00000000 ____D () C:\Program Files (x86)\MSI Kombustor 2.5 2014-03-19 17:18 - 2013-02-11 09:43 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner 2014-03-19 17:18 - 2013-01-14 07:33 - 00000000 ____D () C:\Program Files (x86)\Easy Text To HTML Converter 2014-03-19 17:18 - 2012-04-12 04:32 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-03-19 17:18 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\registration 2014-03-19 17:17 - 2013-12-16 23:54 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\DayZ 2014-03-19 17:17 - 2013-11-07 15:44 - 00000000 ____D () C:\Users\BaNgMaN\Downloads\ISS 2014-03-19 10:38 - 2014-03-19 10:38 - 00000219 _____ () C:\Users\BaNgMaN\Desktop\Counter-Strike Global Offensive.url 2014-03-19 08:01 - 2013-01-01 18:34 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\CrashDumps 2014-03-19 07:15 - 2014-03-19 07:15 - 08542519 _____ () C:\Users\BaNgMaN\Downloads\dll new z.rar 2014-03-19 07:12 - 2014-03-19 07:12 - 03325968 _____ () C:\Users\BaNgMaN\Downloads\TheNewZ (2).zip 2014-03-19 07:12 - 2014-03-19 07:12 - 03325968 _____ () C:\Users\BaNgMaN\Downloads\TheNewZ (1).zip 2014-03-19 07:09 - 2014-03-19 07:09 - 07688488 _____ () C:\Users\BaNgMaN\Downloads\Launcher + NewZ.dll + NewZ.exe (1).rar 2014-03-19 01:06 - 2013-12-20 10:41 - 00787968 ___SH () C:\Users\BaNgMaN\Downloads\Thumbs.db 2014-03-18 13:08 - 2014-03-18 13:08 - 00196754 _____ () C:\Users\BaNgMaN\Downloads\msvcp110.zip 2014-03-18 12:54 - 2014-03-18 12:54 - 44221577 _____ () C:\Users\BaNgMaN\Downloads\herro!.rar 2014-03-18 12:53 - 2014-03-18 12:53 - 07688488 _____ () C:\Users\BaNgMaN\Downloads\Launcher + NewZ.dll + NewZ.exe.rar 2014-03-18 12:49 - 2014-03-18 12:49 - 00000000 ____D () C:\Users\BaNgMaN\Documents\The New Z Entertainment 2014-03-18 00:22 - 2013-07-29 22:01 - 00000000 ____D () C:\windows\system32\MRT 2014-03-17 14:32 - 2014-03-17 14:32 - 03325968 _____ () C:\Users\BaNgMaN\Downloads\TheNewZ.zip 2014-03-15 23:26 - 2014-03-08 19:51 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\NVIDIA 2014-03-15 13:41 - 2014-03-15 13:41 - 00048313 _____ () C:\Users\BaNgMaN\Downloads\Barney-Stinson-LegenWait-for-itDary.m4r 2014-03-12 20:30 - 2012-04-12 04:32 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-03-10 13:13 - 2012-04-12 04:24 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-03-10 12:20 - 2014-03-10 12:20 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\{95A13E8E-145C-4FBE-9F9B-762EE654100C} 2014-03-10 10:21 - 2013-02-02 05:39 - 00001076 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001Core.job 2014-03-09 08:36 - 2014-02-14 08:15 - 00123844 _____ () C:\windows\PFRO.log 2014-03-07 10:18 - 2014-01-05 15:56 - 00000066 _____ () C:\Users\BaNgMaN\Desktop\share-online.txt 2014-03-07 07:06 - 2013-11-24 11:01 - 00002017 _____ () C:\Users\Public\Desktop\Live Update 5.lnk 2014-03-05 11:35 - 2012-11-25 16:47 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\vlc 2014-03-05 10:13 - 2014-03-05 10:13 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\{51115717-1D34-49CB-A00F-95925D75AA6B} 2014-03-05 10:13 - 2014-02-05 22:13 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\Windows Live 2014-03-04 17:52 - 2014-03-04 17:52 - 02970992 _____ () C:\Users\BaNgMaN\Downloads\MorphVOXJunior_Install-1.exe 2014-03-04 14:41 - 2014-03-04 14:41 - 20804451 _____ () C:\Users\BaNgMaN\Downloads\csgooverlay169.rar 2014-03-02 23:18 - 2014-02-19 06:33 - 00330848 _____ () C:\windows\system32\FNTCACHE.DAT 2014-03-02 18:12 - 2014-03-02 18:11 - 00000000 ____D () C:\Users\BaNgMaN\Documents\Thief 2014-03-02 18:07 - 2014-03-02 18:07 - 00000583 _____ () C:\Users\Public\Desktop\Thief.lnk 2014-03-02 14:18 - 2014-02-18 14:05 - 00088296 _____ () C:\Users\BaNgMaN\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-02 02:38 - 2014-02-13 00:14 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\Battle.net 2014-03-02 02:34 - 2014-03-01 23:44 - 00000000 ____D () C:\Users\BaNgMaN\Documents\Command & Conquer Generäle Stunde Null Data 2014-03-02 02:25 - 2014-03-02 02:25 - 00000000 ____D () C:\windows\Advanced AI Mod 2014-03-02 02:24 - 2014-03-02 02:24 - 00000877 _____ () C:\Users\BaNgMaN\Desktop\CnC Europe.lnk 2014-03-02 02:23 - 2014-03-02 02:19 - 00000000 ____D () C:\Users\BaNgMaN\Desktop\Mods 2014-03-02 02:05 - 2013-09-03 14:59 - 00000000 ____D () C:\Users\BaNgMaN\Desktop\MSI 2014-03-01 23:44 - 2014-03-01 23:40 - 00000993 _____ () C:\windows\eReg.dat 2014-03-01 23:44 - 2012-04-12 04:25 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-03-01 23:13 - 2013-01-22 13:21 - 00000000 ____D () C:\Program Files (x86)\EA Games 2014-03-01 22:23 - 2013-02-26 09:46 - 00456704 ___SH () C:\Users\BaNgMaN\Desktop\Thumbs.db 2014-03-01 15:31 - 2014-03-01 15:31 - 00000000 ____D () C:\Users\BaNgMaN\Documents\EntityGaming 2014-03-01 15:31 - 2014-03-01 15:31 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\EntityGaming 2014-03-01 15:18 - 2014-03-01 15:17 - 4232201047 _____ () C:\Users\BaNgMaN\Downloads\DeadZReborn-Feb-28-2014.rar 2014-03-01 08:38 - 2013-03-04 11:57 - 00000936 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001UA.job 2014-03-01 08:38 - 2013-03-04 11:57 - 00000914 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001Core.job 2014-03-01 00:52 - 2013-01-05 10:36 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\SoftGrid Client 2014-03-01 00:44 - 2012-10-20 18:01 - 00003830 _____ () C:\windows\System32\Tasks\Scheduled Update for Ask Toolbar 2014-03-01 00:43 - 2013-03-04 11:57 - 00003928 _____ () C:\windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001UA 2014-03-01 00:43 - 2013-03-04 11:57 - 00003560 _____ () C:\windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3037997946-340245006-2111326209-1001Core 2014-03-01 00:40 - 2012-10-29 15:58 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Local\Rockstar Games 2014-03-01 00:40 - 2012-04-12 18:11 - 00000000 ____D () C:\Program Files (x86)\MSI 2014-02-28 17:07 - 2012-10-29 15:12 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2014-02-28 17:04 - 2013-06-17 10:00 - 00000000 ____D () C:\Users\BaNgMaN\AppData\Roaming\DesktopIconForAmazon 2014-02-28 17:03 - 2013-06-10 11:34 - 00000000 ____D () C:\Program Files (x86)\CHIP System-Check-Tool 2014-02-28 17:02 - 2013-11-20 16:11 - 00000000 ____D () C:\Program Files (x86)\RivaTuner Statistics Server 2014-02-28 10:09 - 2013-12-19 00:04 - 00000135 _____ () C:\Users\BaNgMaN\AppData\Roaming\WB.CFG 2014-02-24 21:57 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF 2014-02-22 22:13 - 2014-02-25 00:41 - 19083278 _____ () C:\Users\BaNgMaN\Desktop\evasi0n7.exe 2014-02-21 15:14 - 2013-04-10 17:38 - 00001357 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2014-02-19 06:56 - 2013-07-25 10:46 - 00004108 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-19 06:56 - 2013-07-25 10:46 - 00003856 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-19 06:35 - 2009-07-14 06:08 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2014-02-19 06:33 - 2013-01-05 17:47 - 00000000 ____D () C:\Users\BaNgMaN\.thumbnails 2014-02-18 14:01 - 2014-02-18 14:01 - 00228983 _____ () C:\Users\BaNgMaN\Downloads\soundboard-0.9.8.4b-win32.ts3_plugin 2014-02-18 13:57 - 2012-11-13 09:54 - 00000000 ____D () C:\windows\Minidump Some content of TEMP: ==================== C:\Users\BaNgMaN\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 17:04 ==================== End Of Log ============================ |
20.03.2014, 13:58 | #4 |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEE Hallo! Schritt 1 Bitte poste mir ein Logfile mit den Scanergebnissen von Avira.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
21.03.2014, 00:38 | #5 |
| Virus HTML/Drop.Agent.AB HILFEEEE Hallo, hab versucht das Ergebniss einzufügen aber jedes mal macht dan Chrome schlapp oder mein Rechner. ich habe es in ein winrar rein gepackt hoffe das geht auch? Oder soll ich es nocheinmal anderes versuchen? |
21.03.2014, 12:34 | #6 |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEE Hallo, hast Du gut gemacht mit dem Report! Wir machen jetzt so weiter: Bitte beende Dein Antivirusprogramm bzw. schalte den Hintergrundwächter temporär ab. Bitte lasse anschließend die Datei aus der Code-Box bei Virustotal überprüfen.
Code:
ATTFilter D:\SteamLibrary\SteamApps\common\ContagionBeta\bin\bsppack.dll D:\COD4\Docs\help.htm D:\COD4\Docs\Help\credits.htm
__________________ --> Virus HTML/Drop.Agent.AB HILFEEEE |
21.03.2014, 14:48 | #7 |
| Virus HTML/Drop.Agent.AB HILFEEEECode:
ATTFilter https://www.virustotal.com/de/file/4ef9168a3af823419cd15f2a25551ecf299b7dfdc042521609361cbda491df64/analysis/1395409380/ https://www.virustotal.com/de/file/788c6e9e08962f4b01474bc34bb0072e6a92cb07a6ab3a1ee543bd7e0a9b32ea/analysis/1395409841/ https://www.virustotal.com/de/file/7ba1c2e515a6fbb7fe886836acd10e694e3628eb23808e50c707cb2ded81a4b8/analysis/1395409562/ https://www.virustotal.com/de/file/e7b382a7005f40ea1a0f99ac99f89828d52f43c0b16c461c920d9c2e258b447f/analysis/1395409643/ |
22.03.2014, 08:06 | #8 |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEE Hallo Chris, sieht nicht so gut aus...Egal für was Du Dich entscheidest, ich helfe Dir... Warnung: File Infector Dein Rechner wurde mit einem besonderen Schädling infiziert, der andere Dateien infiziert, wodurch er sich unkontrolliert vermehrt. Diese Art der Computerschädlinge ist mit die gefährlichste. Bereinigungsversuche sind möglich, die Erfolgsaussichten dein System wieder sauber zu bekommen liegen dabei allerdings zwischen gering und unmöglich. Wir empfehlen dringend die Formatierung und das Neuaufsetzen deines Systemes in folgenden Schritten:
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
22.03.2014, 09:39 | #9 |
| Virus HTML/Drop.Agent.AB HILFEEEE Oh man Und wie mach ich das alles ? Sind meine Bilder Video ect auch verseucht? Hab ja keine CD zum Laptop bekommen! Und auch keinen Key oder merkt sich das mein rechner?? |
22.03.2014, 12:46 | #10 | |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEEZitat:
Kein Problem... Bezüglich des Keys: KeyFinder | Magical Jelly Bean virustotal check: https://www.virustotal.com/de/file/a...is/1395434739/ Bezüglich der DVD: http://www.trojaner-board.de/100776-...-download.html Der HP 64bit Link scheint nicht mehr zu gehen. Illegale Links werden hier nicht verbreitet. Daher würde ich das Verfahren mit der Prof. Version und dem Entfernen der ei.cfg empfehlen. Bezüglich Deiner Daten: http://www.trojaner-board.de/71715-k...iendungen.html Lies Dir in Ruhe alle Anleitungen durch. Grober Ablaufplan: - Mit einer Linux-Live-CD nur die persönlichen Daten auf externe Festplatte sichern (Bilder, Videos) - Auf einem sauberen Rechner eine Windows 7 Installations DVD erstellen. - Key mit dem Tool auf dem verseuchten PC auslesen und notieren. - Windows Neuinstallation mit der erstellten DVD - PC absichern - Eine Testversion von einem guten AVP installieren (z.B. Emsisoft oder Kaspersky) - Externe Festplatte prüfen - Saubere Dateien zurückkopieren wenn direkt auf dem PC erforderlich
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
22.03.2014, 14:20 | #11 |
| Virus HTML/Drop.Agent.AB HILFEEEE soooooo hab es jetzt soweit wieder alles drauf hoffe die seuche ist jetzt weg |
22.03.2014, 14:31 | #12 |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEE Hast Du schon neuinstalliert? Mach doch bitte einen neuen FRST-Scan... Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
22.03.2014, 14:42 | #13 |
| Virus HTML/Drop.Agent.AB HILFEEEE Bin ja a schneller |
22.03.2014, 14:47 | #14 |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEE kann man wohl sagen.... Melde mich so schnell als möglich wieder mit weiteren Anweisungen
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
22.03.2014, 19:15 | #15 |
/// TB-Ausbilder /// Anleitungs-Guru | Virus HTML/Drop.Agent.AB HILFEEEE Hallo Chris, wir machen so weiter: Schritt 1 ESET Online Scanner
Schritt 2 Downloade Dir bitte SecurityCheck und:
Bitte poste den Inhalt der Logs von ESET und Securitycheck hier in den Thread.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
Themen zu Virus HTML/Drop.Agent.AB HILFEEEE |
andere, anderen, avira, datei, datein, hilfeee, hilfeeee, html/drop.agent.ab, immer wieder, kommt immer wieder, lan, leute, neu, party, spuckt, unerwünschte, unerwünschten, virus, zugriff |