|
Plagegeister aller Art und deren Bekämpfung: Chrome Browser Deaktiviert Sich immer WiederWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.04.2014, 10:29 | #1 |
| Chrome Browser Deaktiviert Sich immer Wieder Hallo liebes Tb Support Team. Ich habe seit ca 1,5 Wochen das Problem,das mein Chrome Browser sich immer wieder (oft 10-30 Sekunde) von allein deaktiviert. Das wirkt sich so aus,dass wenn ich ganz normal surfe der Browser mich einfach raus kickt und ich wieder auf den Browser rauf klicken muss,damit ich scrollen oder was eingeben kann.Das gleiche passiert auch bei Spielen.Bin momentan ratlos und habe einiges probiert,auch was hier im Forum steht. Laufen habe ich: Anti Virus: Avast und nebenher scanne ich Regelmäßig mit: Spybot S&D PS:Habe mir paar Ähnliche Sachen durchgelesen,und Malwarebytes runtergeladen und gescanned aber da war alles in Ordnung+dazu mit OTL gescanned. Vielleicht könnt ihr mir ja Helfen Mfg OTL Extras logfile created on: 18.04.2014 11:09:31 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\shaboitz\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17041) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 15,98 Gb Total Physical Memory | 13,82 Gb Available Physical Memory | 86,49% Memory free 31,97 Gb Paging File | 29,64 Gb Available in Paging File | 92,71% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 238,37 Gb Total Space | 109,61 Gb Free Space | 45,98% Space Free | Partition Type: NTFS Drive E: | 596,17 Gb Total Space | 592,83 Gb Free Space | 99,44% Space Free | Partition Type: NTFS Computer Name: SHABOITZ-PC | User Name: shaboitz | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.) "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.) ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0373BC36-72E9-4A8E-A5F0-F6F49EBBFB4A}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{0B8D466B-166D-419B-9D45-7AA739F8056A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{134CEDB9-BBD3-44A5-B6E8-516227716CA3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{1C18B696-40C3-4C61-BB43-23D3A59B391A}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{2C85FE75-75AC-4BEB-89EC-3F2448A2A586}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{2CF47485-C062-4AE4-A17F-444D2BB26813}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{3228C9A8-E560-421E-836B-193011A694A4}" = lport=2869 | protocol=6 | dir=in | app=system | "{3541D1BE-CEBC-4AA1-940D-B6AC2107FE34}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{3C2501A9-0D9A-4AC5-AFAD-4E06B6D57FF7}" = lport=139 | protocol=6 | dir=in | app=system | "{3CBC7A04-596B-4F42-B447-9F4D35B0C684}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{3E0CD366-3157-4195-8054-C0BE596A9380}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{42F551DF-9162-464D-93F4-FC4B7E1371F4}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{46B00EFF-ABB1-4A7A-ACD3-A69E0BAC9A5D}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{4D34F673-AF30-410A-AF76-223CE37798D3}" = lport=47987 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{5307FFEB-87E8-40DF-8DFF-F08E9531A2B9}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{5829DC1B-526C-4034-9C44-6111A8C9C784}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{5D3D8CD5-92EA-40C0-AF50-9FBD79DC9AD2}" = lport=445 | protocol=6 | dir=in | app=system | "{65401977-370C-495E-9227-3CF06A59654C}" = rport=445 | protocol=6 | dir=out | app=system | "{6BFEF00F-38FC-4BB0-926B-369B3EC2CC3B}" = lport=138 | protocol=17 | dir=in | app=system | "{6C949C21-3C48-4F67-A22C-B739E63109FB}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{6D021E50-0314-4B65-B8A9-1A5E1A29968A}" = rport=138 | protocol=17 | dir=out | app=system | "{758694EA-D10F-4681-9798-3551D38E0E80}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{82B39782-2B6B-4EB9-8A3F-95EF9277E1FB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{83987C59-2B89-43B3-9577-C7604C37EA6A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{8514FB67-7E64-4879-AAE4-EA7BEC1ACEA4}" = rport=10243 | protocol=6 | dir=out | app=system | "{909565AF-BC80-476B-9068-F8FF3674EF80}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{987EE71A-D3FB-4E6C-8647-B7C39224AA19}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | "{9F349945-9C0F-4629-B94C-2A208B7668F5}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | "{A61CCB03-EF26-41AF-B047-F99284889D75}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{A6EB4C8A-AED3-4372-A9D3-663D464EFEDB}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{A9EDD2DC-EFC8-4539-8F3E-534221501E45}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{B0FFA1FE-EC92-48BD-8A2A-79455001B362}" = lport=137 | protocol=17 | dir=in | app=system | "{B2C99DC3-3E5C-4146-9A02-C30B0EB4AD69}" = rport=137 | protocol=17 | dir=out | app=system | "{BB9C3E3E-3C44-47B0-B62E-67682D48CECF}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{C4A40886-0AF2-40BA-9404-3EFD08B7E454}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E25D6C51-B941-47A2-884D-0CE9C4117348}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E32543C2-6703-4BE2-A3FD-644A8A8ED6A3}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{E52E6A48-B1DE-4507-914C-8E86473ADA64}" = lport=10243 | protocol=6 | dir=in | app=system | "{EB45563C-3785-4F49-80BC-EEC0B62AA1EF}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | "{EF9F3767-4773-4E31-A1CE-770C2B029A3B}" = rport=139 | protocol=6 | dir=out | app=system | "{F81A2440-3225-41B3-B813-4035E0C5FC26}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01007A9A-2330-47B3-939D-45042D898F86}" = protocol=6 | dir=out | app=system | "{0E4D78CC-B228-4501-92BC-13C8252F2654}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{1AB8AD11-EE18-4255-8FFD-5B4550568A84}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | "{1ABB1FE4-E970-4487-B29A-A302334F9000}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "{1B89C89E-5002-4FF0-8F2B-39FA0A1BB4CA}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "{1F5DD083-9127-4D63-B1BA-B1E03B0A5745}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | "{21B46073-9E19-47ED-A4AF-F7A2E4AA814A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | "{3FCBC050-E440-4D89-AB13-5956EB501BA6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{50904C3A-DB51-4F73-8D7D-5A0FD67D6285}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{52AF76F6-E094-4695-9A0F-97A040419DAF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{56DB1978-8DEB-48A3-8A5D-C4908AA77A75}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | "{5F034E60-FF53-44B3-99FF-68E3E1B62314}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | "{63C0653F-4DAB-4A69-ACEA-263F8F143325}" = dir=in | app=e:\skype\phone\skype.exe | "{7232F1E8-60B6-4432-B6DF-3FC7565CCF42}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{7241FC26-819B-464C-9485-84184838AFE2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{81BFB9AF-76B7-42FC-8DE6-F4173EA7B78E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{84F4AA57-B9E9-4FD2-A422-0B9E351D2A3D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{857FD0DF-A23B-4815-B026-55FC096CD7C3}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | "{9138A8AE-E68C-4985-BB2B-B2D6A1EC3567}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{917D1432-9011-4004-8241-B0959C7274A0}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | "{95D392C3-C5A8-46A9-A701-FFE030783DA6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{98BEDFD7-4E02-4F41-A469-5E343F34A0BF}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | "{999B12D5-2BBD-4316-856D-C13C50E5372D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{9A895C8B-C3F5-4168-9813-98E70E4B3369}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{9BBB44C7-6A37-449C-AA02-757F94538E71}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | "{9C070DD5-612B-4D4B-9669-BA34C80B1475}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{A284C1D5-9A52-4502-B08A-BC3F3EAC9CCD}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{A658E3D1-09B0-46C2-8D98-24C0E82E165D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{A808ECF2-6CD7-4149-B2A5-37533B4E2D5F}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{AA71906C-3F51-4852-9350-70F7E48CFD93}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | "{B0F6E044-CAE2-48E2-9288-AB92C8131611}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{BBE87D39-4C2C-4100-AEAD-3A6021AA0FF6}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | "{C3B78ABB-BA81-47E4-B27C-6AEBB8D47527}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | "{C935316B-F23D-4F8B-8912-70239B9689D8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{D4145C60-C471-493C-946E-EF747CC07472}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | "{DA670740-1538-4069-ADE0-8B1EF5E8C6C7}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | "{E7DE08FD-E4FE-483D-8717-4267D1B23C1C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FF72BF3A-0FC4-4E00-B554-3D6093BB61F4}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "TCP Query User{1EA51562-9DFC-4453-9B22-88B1A9FB2853}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe | "TCP Query User{2BFF5D8C-6CCC-467F-9096-2C6ED31ACC77}C:\users\public\sony online entertainment\installed games\everquest\eqvoiceservice.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\everquest\eqvoiceservice.exe | "TCP Query User{7DD0BB31-6A9B-4CFD-8979-ACD655C36075}E:\norm\warcraft iii\war3.exe" = protocol=6 | dir=in | app=e:\norm\warcraft iii\war3.exe | "TCP Query User{D126EB7E-24A9-474A-9CD7-699FE5838CFE}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base26490\sc2.exe | "TCP Query User{D7C05702-5E6E-495E-ADDD-551407B4D6BA}C:\program files (x86)\casino\casinoclub\casino.exe" = protocol=6 | dir=in | app=c:\program files (x86)\casino\casinoclub\casino.exe | "TCP Query User{D8002142-4B55-4F99-8A81-22F703697306}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | "TCP Query User{E74AE750-4760-4470-ACE2-6B18F4DA3021}C:\users\public\sony online entertainment\installed games\everquest ii\eq2voiceservice.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\everquest ii\eq2voiceservice.exe | "UDP Query User{323B7287-7EF5-4D01-ABC6-B49740059854}C:\program files (x86)\starcraft ii\versions\base26490\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base26490\sc2.exe | "UDP Query User{4A94F65F-B462-4E4D-89F2-9BC4ECE4CBF0}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | "UDP Query User{57AC27ED-E9C3-4F7B-86A6-2E1BED772FF3}C:\program files (x86)\casino\casinoclub\casino.exe" = protocol=17 | dir=in | app=c:\program files (x86)\casino\casinoclub\casino.exe | "UDP Query User{784D245F-C695-4E58-B031-695021F341DD}E:\norm\warcraft iii\war3.exe" = protocol=17 | dir=in | app=e:\norm\warcraft iii\war3.exe | "UDP Query User{B2AF4EF3-9EB4-4B2C-A9C6-D0E185430615}C:\program files (x86)\starcraft ii\versions\base28667\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base28667\sc2.exe | "UDP Query User{E0A578A9-2F95-4F97-A098-296219BD469F}C:\users\public\sony online entertainment\installed games\everquest ii\eq2voiceservice.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\everquest ii\eq2voiceservice.exe | "UDP Query User{FB1DF3A3-B77B-4ACF-B8E2-B775CCF9505B}C:\users\public\sony online entertainment\installed games\everquest\eqvoiceservice.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\everquest\eqvoiceservice.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1 "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5.1 (Deutsch) "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 335.23 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 335.23 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 335.23 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.8.2.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 335.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.13.1220 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 11.10.13 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamC" = GeForce Experience NvStream Client Components "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber 1.3.30.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 11.10.13 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.20 "{C513739C-5F16-37B5-9ACF-99925FF1C1F3}" = Microsoft .NET Framework 4.5.1 (DEU) "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 "CCleaner" = CCleaner [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}" = OpenOffice 4.0.1 "{0EE56463-49B2-45E1-B74F-3E0139DBC986}_is1" = SleepTimer Ultimate 1.2 "{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 55 "{319D91C6-3D44-436C-9F79-36C0D22372DC}" = TP-LINK Wireless Configuration Utility "{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4BAE4C76-44C3-418F-B715-6BBF5A65323E}" = TL-WN851ND Driver "{517CC397-B22F-4593-8DCB-DE72CC541E9A}" = League of Legends "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{675F86A8-E093-4002-87D5-915CC2C45571}" = DES 2.0 "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14 "{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Deutsch "{B26438B4-BF51-49C3-9567-7F14A5E40CB9}" = Dolby Home Theater v4 "{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS "{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 "{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin "Advanced Combat Tracker" = Advanced Combat Tracker (remove only) "avast" = avast! Free Antivirus "Battle.net" = Battle.net "Diablo III" = Diablo III "EQ2MAP Updater" = EQ2MAP Updater 1.2.10 "Google Chrome" = Google Chrome "Hearthstone" = Hearthstone "League of Legends 3.0.1" = League of Legends "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware Version 2.0.1.1004 "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "StarCraft II" = StarCraft II "Warcraft III" = Warcraft III ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Flux" = f.lux "PhotoFiltre 7" = PhotoFiltre 7 "soe-EverQuest" = EverQuest "SOE-EverQuest II" = EverQuest II "SOE-LegendsOfNorrath" = Legends of Norrath "TeamSpeak 3 Client" = TeamSpeak 3 Client ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 16.04.2014 11:30:03 | Computer Name = shaboitz-PC | Source = MouseKeyboardCenter | ID = 0 Description = Unknown Node:#text --> Error - 17.04.2014 02:56:19 | Computer Name = shaboitz-PC | Source = WinMgmt | ID = 10 Description = Error - 17.04.2014 03:46:02 | Computer Name = shaboitz-PC | Source = WinMgmt | ID = 10 Description = Error - 17.04.2014 03:48:43 | Computer Name = shaboitz-PC | Source = WinMgmt | ID = 10 Description = Error - 17.04.2014 03:57:43 | Computer Name = shaboitz-PC | Source = WinMgmt | ID = 10 Description = Error - 17.04.2014 04:05:16 | Computer Name = shaboitz-PC | Source = WinMgmt | ID = 10 Description = Error - 18.04.2014 04:29:47 | Computer Name = shaboitz-PC | Source = WinMgmt | ID = 10 Description = [ Spybot - Search and Destroy Events ] Error - 11.04.2014 02:42:22 | Computer Name = shaboitz-PC | Source = SDCleaner | ID = 100 Description = LoadCleaningInstructions [ System Events ] Error - 16.04.2014 11:53:59 | Computer Name = shaboitz-PC | Source = DCOM | ID = 10010 Description = Error - 16.04.2014 18:11:44 | Computer Name = shaboitz-PC | Source = DCOM | ID = 10010 Description = < End of report > |
18.04.2014, 14:17 | #2 |
/// the machine /// TB-Ausbilder | Chrome Browser Deaktiviert Sich immer Wieder hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
18.04.2014, 15:03 | #3 |
| Chrome Browser Deaktiviert Sich immer WiederCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 01 Ran by shaboitz at 2014-04-18 15:59:13 Running from C:\Users\shaboitz\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== @BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.12 - GIGABYTE) Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Advanced Combat Tracker (remove only) (HKLM-x32\...\Advanced Combat Tracker) (Version: - ) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2016 - Avast Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform) DES 2.0 (HKLM-x32\...\{675F86A8-E093-4002-87D5-915CC2C45571}) (Version: 1.00.0000 - Gigabyte) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.7 - Dolby Laboratories Inc) EQ2MAP Updater 1.2.10 (HKLM-x32\...\EQ2MAP Updater) (Version: 1.2.10 - Johan Nilsson) Etron USB3.0 Host Controller (x32 Version: 0.104 - Etron Technology) Hidden EverQuest (HKCU\...\soe-EverQuest) (Version: 1.0.3.183 - Sony Online Entertainment) EverQuest II (HKCU\...\SOE-EverQuest II) (Version: 1.0.3.183 - Sony Online Entertainment) f.lux (HKCU\...\Flux) (Version: - ) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation) Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Legends of Norrath (HKCU\...\SOE-LegendsOfNorrath) (Version: - Sony Online Entertainment) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) ON_OFF Charge B11.0110.1 (HKLM-x32\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) PhotoFiltre 7 (HKCU\...\PhotoFiltre 7) (Version: - ) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.46.531.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6602 - Realtek Semiconductor Corp.) SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) SleepTimer Ultimate 1.2 (HKLM-x32\...\{0EE56463-49B2-45E1-B74F-3E0139DBC986}_is1) (Version: - Christian Handorf) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.1.21 - Safer-Networking Ltd.) StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TL-WN851ND Driver (HKLM-x32\...\{4BAE4C76-44C3-418F-B715-6BBF5A65323E}) (Version: 1.00.0000 - TP-LINK) TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 2.01.0012 - TP-LINK) Warcraft III (HKLM-x32\...\Warcraft III) (Version: - Blizzard Entertainment) ==================== Restore Points ========================= 10-04-2014 21:34:22 Windows Update 15-04-2014 06:46:20 Windows Update 15-04-2014 09:18:20 Windows Update 15-04-2014 14:29:49 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 16-04-2014 07:37:14 Windows Update 16-04-2014 07:50:44 Installed Java 7 Update 55 17-04-2014 08:01:26 DirectX wurde installiert ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-04-15 15:58 - 00450709 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {04982BC0-D7F8-400B-ADA1-A3A033356B1F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-16] (Google Inc.) Task: {15A0CE4D-49E8-4F45-B6F5-CEB89EC0B156} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {27A6FD33-B00B-4C97-8555-FEFE69A30CE9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd) Task: {3F5B3708-D754-4584-9827-3335DD3CB82E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {3FE76E0D-AB38-41A1-BF71-5B625DC5A0AD} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe Task: {800152D9-1BC7-476D-A154-20EAB37F6897} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-08] (AVAST Software) Task: {9F1301AA-8642-4935-9159-708221FAF7CD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {C5E9ED7B-8F7B-4D28-A5EE-C8000DFD3CC5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-16] (Google Inc.) Task: {CA3CB795-3344-4EDC-B9A0-659BF8DC18BC} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe Task: {D9D584C8-DED4-412D-A474-3359BEEDC41D} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-17 09:49 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-10-02 11:27 - 2011-08-22 15:26 - 00057344 _____ () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe 2014-04-04 10:50 - 2011-04-11 17:32 - 00788992 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe 2014-03-14 16:31 - 2014-03-14 16:31 - 00173568 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\quazip.dll 2014-03-14 16:31 - 2014-03-14 16:31 - 01080832 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\platforms\qwindows.dll 2014-03-14 16:31 - 2014-03-14 16:31 - 00833024 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\sqldrivers\qsqlite.dll 2013-09-27 14:15 - 2014-03-14 16:31 - 00102344 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2013-09-27 14:15 - 2014-03-14 16:31 - 00108488 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2014-03-14 16:31 - 2014-03-14 16:31 - 00030208 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\imageformats\qgif.dll 2014-03-14 16:31 - 2014-03-14 16:31 - 00233984 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\imageformats\qjpeg.dll 2013-09-27 14:15 - 2014-03-14 16:31 - 00563656 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2013-09-27 14:15 - 2014-03-14 16:31 - 00577480 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2014-03-14 16:31 - 2014-03-14 16:31 - 00159232 _____ () C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll 2014-04-06 12:38 - 2014-04-04 01:38 - 10693632 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\eqgame.exe 2014-04-18 11:11 - 2014-04-18 11:11 - 02215424 _____ () C:\Program Files\AVAST Software\Avast\defs\14041800\algo.dll 2013-10-02 11:27 - 2009-05-04 17:56 - 00102400 _____ () C:\Program Files (x86)\GIGABYTE\EnergySaver2\ycc.dll 2013-10-14 11:34 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-10-14 11:34 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-10-14 11:34 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-10-14 11:34 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-10-14 11:34 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2014-04-04 10:50 - 2011-05-23 14:32 - 01410048 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\nicLan.dll 2014-04-04 10:50 - 2011-04-11 17:32 - 00167424 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\DC_WFF.dll 2014-04-04 10:50 - 2011-04-11 17:32 - 00128000 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\WJWF\WJWF.dll 2014-04-04 10:50 - 2011-04-11 17:32 - 00111616 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\WJWF\WJWF_WPS_WIN7.DLL 2013-12-04 11:31 - 2013-12-04 11:31 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-04-16 17:27 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2014-04-16 17:27 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-16 17:27 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll 2014-04-16 17:27 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll 2014-04-16 19:06 - 2014-02-10 13:44 - 04592128 _____ () C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll 2014-04-16 19:06 - 2014-02-10 13:44 - 00112128 _____ () C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll 2014-04-06 13:04 - 2010-10-11 23:30 - 00349696 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mss32.dll 2014-04-06 13:39 - 2010-10-11 23:30 - 06459392 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\xul.dll 2014-04-06 12:38 - 2014-04-04 01:39 - 01612288 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\EQGraphicsDX9.DLL 2014-04-06 12:32 - 2010-10-11 23:30 - 00160256 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\dpvs.dll 2014-04-06 13:04 - 2002-09-04 12:35 - 00125952 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mssmp3.asi 2014-04-06 13:04 - 2002-09-04 12:35 - 00197120 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mssvoice.asi 2014-04-06 13:04 - 2002-09-04 12:35 - 00083456 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mssa3d.m3d 2014-04-06 13:04 - 2002-09-04 12:35 - 00070656 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mssds3d.m3d 2014-04-06 13:04 - 2002-09-04 12:35 - 00080896 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mssdx7.m3d 2014-04-06 13:04 - 2002-09-04 12:35 - 00103424 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\msseax.m3d 2014-04-06 13:04 - 2002-09-04 12:35 - 00354816 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mssrsx.m3d 2014-04-06 13:04 - 2002-09-04 12:35 - 00067072 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\msssoft.m3d 2014-04-06 13:04 - 2002-09-04 12:35 - 00093696 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\mssdsp.flt 2014-04-06 13:10 - 2010-12-08 00:02 - 00280552 _____ () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\ortp.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/18/2014 00:00:44 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (04/18/2014 00:00:44 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (04/18/2014 00:00:44 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (04/18/2014 00:00:44 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 11:59:59 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (04/18/2014 10:29:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 10:05:16 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 09:57:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 09:48:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 09:46:02 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/18/2014 11:59:56 AM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (04/17/2014 00:11:44 AM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (04/16/2014 05:53:59 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= Error: (04/18/2014 00:00:44 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD initialization failed [6] Error: (04/18/2014 00:00:44 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0] Error: (04/18/2014 00:00:44 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registration failed [0] Error: (04/18/2014 00:00:44 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 11:59:59 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe)(User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (04/18/2014 10:29:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 10:05:16 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 09:57:43 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 09:48:43 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 09:46:02 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 16367.12 MB Available physical RAM: 9806.27 MB Total Pagefile: 32732.41 MB Available Pagefile: 25331.07 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:238.37 GB) (Free:109.16 GB) NTFS Drive e: () (Fixed) (Total:596.17 GB) (Free:592.83 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 4BC50702) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=238 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 8BACD2F8) Partition 1: (Not Active) - (Size=596 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by shaboitz (administrator) on SHABOITZ-PC on 18-04-2014 15:58:58 Running from C:\Users\shaboitz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Flux Software LLC) C:\Users\shaboitz\AppData\Local\FluxSoftware\Flux\flux.exe () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (TeamSpeak Systems GmbH) C:\Users\shaboitz\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\eqgame.exe (Vivox Inc.) C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\EQVoiceService.exe () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\eqgame.exe () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\eqgame.exe () C:\Users\Public\Sony Online Entertainment\Installed Games\EverQuest\eqgame.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-27] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1179576 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-17] (InstallShield Software Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-08] (AVAST Software) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-86147730-3345030318-3555282241-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation) HKU\S-1-5-21-86147730-3345030318-3555282241-1000\...\Run: [f.lux] => C:\Users\shaboitz\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC) HKU\S-1-5-21-86147730-3345030318-3555282241-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x91899E6052BFCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-02] Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java Deployment Toolkit 7.0.550.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U55) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () CHR Extension: (Google Docs) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-16] CHR Extension: (Google Drive) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-16] CHR Extension: (YouTube) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-16] CHR Extension: (Google-Suche) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-16] CHR Extension: (AdBlock) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-16] CHR Extension: (Google Wallet) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-16] CHR Extension: (Google Mail) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-16] ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-08] (AVAST Software) R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [57344 2011-08-22] () R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) S2 SkypeUpdate; E:\skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-08] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-08] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-08] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-08] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-08] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-04-08] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-04-08] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-10-02] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 15:58 - 2014-04-18 15:59 - 00013797 _____ () C:\Users\shaboitz\Downloads\FRST.txt 2014-04-18 15:58 - 2014-04-18 15:58 - 00000000 ____D () C:\FRST 2014-04-18 15:57 - 2014-04-18 15:58 - 02158592 _____ (Farbar) C:\Users\shaboitz\Downloads\FRST64.exe 2014-04-18 12:00 - 2014-04-18 14:51 - 00000336 _____ () C:\Windows\setupact.log 2014-04-18 12:00 - 2014-04-18 12:00 - 00000734 _____ () C:\Windows\PFRO.log 2014-04-18 12:00 - 2014-04-18 12:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-18 11:12 - 2014-04-18 11:12 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 11:12 - 2014-04-18 11:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-18 11:12 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-18 11:12 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-18 11:12 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-18 11:11 - 2014-04-18 11:11 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\shaboitz\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-17 10:01 - 2014-04-17 10:02 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA 2014-04-17 10:01 - 2014-04-17 10:01 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-04-17 10:01 - 2014-02-05 11:31 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-17 10:01 - 2014-02-05 11:30 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-17 10:00 - 2014-04-18 12:00 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-17 10:00 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-04-17 10:00 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-04-17 10:00 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-04-17 09:59 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-04-17 09:59 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-04-17 09:59 - 2013-12-27 20:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-17 09:59 - 2013-12-27 20:42 - 00035104 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-04-17 09:59 - 2013-12-27 20:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-17 09:59 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-04-17 09:59 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-04-17 09:51 - 2014-04-17 09:51 - 02817354 _____ () C:\Users\shaboitz\Downloads\DCProSetup_15.zip 2014-04-17 09:49 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-04-17 09:49 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-04-17 09:49 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-04-17 09:49 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-04-17 09:41 - 2014-04-17 09:44 - 276762432 _____ (NVIDIA Corporation) C:\Users\shaboitz\Downloads\335.23-desktop-win8-win7-winvista-64bit-international-whql.exe 2014-04-16 17:27 - 2014-04-18 15:39 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-16 17:27 - 2014-04-18 12:00 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-16 17:27 - 2014-04-16 17:34 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-16 17:27 - 2014-04-16 17:34 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-16 17:27 - 2014-04-16 17:27 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieUserList 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieSiteList 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\Windows\ERUNT 2014-04-16 16:47 - 2014-04-16 16:48 - 00000000 ____D () C:\AdwCleaner 2014-04-16 16:46 - 2014-04-16 16:46 - 01426178 _____ () C:\Users\shaboitz\Downloads\adwcleaner.exe 2014-04-16 16:43 - 2014-04-18 11:12 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-16 16:43 - 2014-04-16 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 09:50 - 2014-04-16 09:51 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log 2014-04-16 09:11 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-04-16 09:11 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logitech 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logishrd 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\ProgramData\Package Cache 2014-04-15 16:15 - 2014-04-15 16:15 - 00002464 _____ () C:\Windows\wininit.ini 2014-04-15 15:58 - 2009-06-10 23:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20140415-155823.backup 2014-04-15 11:20 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-04-15 11:20 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-04-15 11:20 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-04-15 11:20 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-04-15 11:20 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-04-15 11:20 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-04-15 11:20 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-04-15 11:20 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-04-15 11:20 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-04-15 11:20 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-04-15 11:20 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-04-15 11:20 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-04-15 11:20 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-04-15 11:20 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-04-15 11:20 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-04-15 11:20 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003118 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003092 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003090 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-04-15 11:19 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-15 11:19 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-15 11:19 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-15 11:19 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-15 11:19 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-15 11:19 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-15 11:19 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-15 11:19 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-15 11:19 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-15 11:19 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-15 11:19 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-15 11:19 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-15 11:19 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-15 11:19 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-15 11:19 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-15 11:19 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-15 11:19 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-15 11:19 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-15 11:19 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-15 11:19 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-15 11:19 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-15 11:19 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-15 11:19 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-15 11:19 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-15 11:19 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-15 11:19 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-15 11:19 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-15 11:19 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-15 11:19 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-15 11:19 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-15 11:19 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-15 11:19 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-15 11:19 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-15 11:19 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-15 11:19 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-15 11:19 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-15 11:19 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-15 11:19 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-15 11:19 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-15 11:19 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-15 11:19 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-15 11:19 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-15 11:19 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-15 11:19 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-15 11:19 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-15 11:19 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-15 11:19 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-15 11:19 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-15 11:19 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-04-15 11:19 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-04-15 11:19 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-04-15 11:19 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-04-15 11:19 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-04-15 11:19 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-04-15 11:19 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-04-15 11:18 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-04-15 11:18 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-04-15 11:18 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-04-15 11:18 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-04-11 17:22 - 2014-04-11 17:22 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-04-11 17:22 - 2014-04-11 17:22 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-11 17:22 - 2014-04-11 17:22 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-10 12:00 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 12:00 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 12:00 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 12:00 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 12:00 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 12:00 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 12:00 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 12:00 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 12:00 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 12:00 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 12:00 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 12:00 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 12:00 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 17:21 - 2014-04-08 17:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-06 18:25 - 2014-04-06 18:25 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Mozilla 2014-04-06 12:11 - 2014-04-06 12:11 - 00002461 _____ () C:\Users\shaboitz\Desktop\EverQuest.lnk 2014-04-04 11:09 - 2014-04-04 11:10 - 00000000 ____D () C:\Users\shaboitz\Desktop\schrift 2014-04-04 10:51 - 2014-04-04 10:55 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00002261 _____ () C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-04-04 10:50 - 2011-04-19 21:55 - 00007634 _____ () C:\Windows\system32\athrextx.cat 2014-04-04 10:50 - 2011-04-11 17:33 - 01579520 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2014-04-04 10:50 - 2011-04-11 17:33 - 01579520 _____ (Atheros Communications, Inc.) C:\Windows\system32\athrx.sys 2014-03-24 03:34 - 2014-03-25 03:28 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\SleepTimerUltimate 2014-03-24 03:34 - 2014-03-24 03:34 - 00001134 _____ () C:\Users\Public\Desktop\SleepTimer Ultimate.lnk 2014-03-24 03:34 - 2014-03-24 03:34 - 00000000 ____D () C:\Program Files (x86)\SleepTimer Ultimate 2014-03-19 22:57 - 2014-03-19 22:57 - 00002554 _____ () C:\Users\shaboitz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II PSG.lnk ==================== One Month Modified Files and Folders ======= 2014-04-18 15:59 - 2014-04-18 15:58 - 00013797 _____ () C:\Users\shaboitz\Downloads\FRST.txt 2014-04-18 15:58 - 2014-04-18 15:58 - 00000000 ____D () C:\FRST 2014-04-18 15:58 - 2014-04-18 15:57 - 02158592 _____ (Farbar) C:\Users\shaboitz\Downloads\FRST64.exe 2014-04-18 15:39 - 2014-04-16 17:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-18 14:51 - 2014-04-18 12:00 - 00000336 _____ () C:\Windows\setupact.log 2014-04-18 12:07 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-18 12:07 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-18 12:06 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-18 12:06 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-18 12:06 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-18 12:03 - 2013-10-02 11:18 - 01690648 _____ () C:\Windows\WindowsUpdate.log 2014-04-18 12:01 - 2013-10-02 13:34 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TS3Client 2014-04-18 12:00 - 2014-04-18 12:00 - 00000734 _____ () C:\Windows\PFRO.log 2014-04-18 12:00 - 2014-04-18 12:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-18 12:00 - 2014-04-17 10:00 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-18 12:00 - 2014-04-16 17:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-18 12:00 - 2013-10-23 18:00 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs 2014-04-18 12:00 - 2013-10-02 11:30 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2014-04-18 12:00 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-18 11:12 - 2014-04-18 11:12 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 11:12 - 2014-04-18 11:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-18 11:12 - 2014-04-16 16:43 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-18 11:11 - 2014-04-18 11:11 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\shaboitz\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-17 20:32 - 2013-10-03 11:41 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Skype 2014-04-17 10:02 - 2014-04-17 10:01 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA 2014-04-17 10:01 - 2014-04-17 10:01 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-04-17 10:01 - 2013-10-17 20:27 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-17 10:01 - 2013-10-02 11:39 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-04-17 10:01 - 2013-10-02 11:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-17 09:51 - 2014-04-17 09:51 - 02817354 _____ () C:\Users\shaboitz\Downloads\DCProSetup_15.zip 2014-04-17 09:49 - 2013-12-27 04:24 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA Corporation 2014-04-17 09:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-04-17 09:44 - 2014-04-17 09:41 - 276762432 _____ (NVIDIA Corporation) C:\Users\shaboitz\Downloads\335.23-desktop-win8-win7-winvista-64bit-international-whql.exe 2014-04-16 17:34 - 2014-04-16 17:27 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-16 17:34 - 2014-04-16 17:27 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-16 17:27 - 2014-04-16 17:27 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Google 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Deployment 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Program Files (x86)\Google 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieUserList 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieSiteList 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\Windows\ERUNT 2014-04-16 16:50 - 2013-10-02 12:01 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-16 16:48 - 2014-04-16 16:47 - 00000000 ____D () C:\AdwCleaner 2014-04-16 16:46 - 2014-04-16 16:46 - 01426178 _____ () C:\Users\shaboitz\Downloads\adwcleaner.exe 2014-04-16 16:43 - 2014-04-16 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 12:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-16 09:51 - 2014-04-16 09:50 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log 2014-04-16 09:51 - 2013-10-09 10:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-16 09:51 - 2013-10-09 10:54 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-16 09:07 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-16 00:57 - 2013-10-02 11:18 - 00000000 ____D () C:\Users\shaboitz 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logitech 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logishrd 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\ProgramData\Package Cache 2014-04-15 16:25 - 2013-10-02 11:45 - 00064416 _____ () C:\Users\shaboitz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-15 16:16 - 2014-02-06 21:57 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-15 16:16 - 2014-02-06 21:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-15 16:15 - 2014-04-15 16:15 - 00002464 _____ () C:\Windows\wininit.ini 2014-04-15 15:49 - 2014-01-22 13:06 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Battle.net 2014-04-15 13:26 - 2009-07-14 06:45 - 00294736 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-15 13:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-15 11:19 - 2014-04-15 11:19 - 00003118 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003092 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003090 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-04-12 17:30 - 2014-01-22 13:06 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-12 14:53 - 2014-03-05 16:46 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Advanced Combat Tracker 2014-04-12 09:40 - 2014-02-06 22:06 - 00000000 ____D () C:\Users\shaboitz\Desktop\scrren 2014-04-12 09:40 - 2013-10-25 11:08 - 00000000 ____D () C:\Users\shaboitz\Desktop\Musi 2014-04-11 17:23 - 2013-10-31 20:26 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft 2014-04-11 17:22 - 2014-04-11 17:22 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-04-11 17:22 - 2014-04-11 17:22 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-11 17:22 - 2014-04-11 17:22 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-11 17:22 - 2013-10-02 12:00 - 00000000 ____D () C:\Windows\Panther 2014-04-11 13:43 - 2014-01-22 13:07 - 00000000 ____D () C:\Program Files (x86)\Hearthstone 2014-04-11 08:40 - 2013-10-12 14:22 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Adobe 2014-04-10 23:35 - 2013-10-02 12:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 23:34 - 2013-10-02 12:34 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 17:22 - 2014-01-03 22:41 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-04-08 17:21 - 2014-04-08 17:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-08 17:21 - 2014-01-03 22:40 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-08 17:21 - 2013-10-02 12:01 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-06 18:25 - 2014-04-06 18:25 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Mozilla 2014-04-06 12:11 - 2014-04-06 12:11 - 00002461 _____ () C:\Users\shaboitz\Desktop\EverQuest.lnk 2014-04-06 12:11 - 2014-02-12 17:32 - 00002491 _____ () C:\Users\shaboitz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest.lnk 2014-04-06 12:11 - 2014-02-12 17:32 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-04 11:11 - 2013-12-09 14:12 - 00000000 ____D () C:\Users\shaboitz\Desktop\Games 2014-04-04 11:10 - 2014-04-04 11:09 - 00000000 ____D () C:\Users\shaboitz\Desktop\schrift 2014-04-04 10:55 - 2014-04-04 10:51 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00002261 _____ () C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-04-04 10:50 - 2013-10-02 11:21 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-03 09:51 - 2014-04-18 11:12 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-18 11:12 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-18 11:12 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-26 22:06 - 2013-10-02 11:18 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\VirtualStore 2014-03-25 03:28 - 2014-03-24 03:34 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\SleepTimerUltimate 2014-03-24 03:34 - 2014-03-24 03:34 - 00001134 _____ () C:\Users\Public\Desktop\SleepTimer Ultimate.lnk 2014-03-24 03:34 - 2014-03-24 03:34 - 00000000 ____D () C:\Program Files (x86)\SleepTimer Ultimate 2014-03-19 22:57 - 2014-03-19 22:57 - 00002554 _____ () C:\Users\shaboitz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II PSG.lnk ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 10:26 ==================== End Of Log ============================ --- --- --- --- --- --- Hier ist beides hoffe passt so. mfg |
19.04.2014, 10:13 | #4 |
/// the machine /// TB-Ausbilder | Chrome Browser Deaktiviert Sich immer Wieder hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.04.2014, 11:39 | #5 |
| Chrome Browser Deaktiviert Sich immer WiederCode:
ATTFilter ComboFix 14-04-17.01 - shaboitz 19.04.2014 12:33:26.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.16367.13606 [GMT 2:00] ausgeführt von:: c:\users\shaboitz\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-19 bis 2014-04-19 )))))))))))))))))))))))))))))) . . 2014-04-19 10:36 . 2014-04-19 10:36 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-04-19 10:35 . 2014-04-19 10:35 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{99DCFE34-C6AE-4BAA-9964-8AF502B754AC}\offreg.dll 2014-04-18 13:58 . 2014-04-18 13:59 -------- d-----w- C:\FRST 2014-04-18 09:12 . 2014-04-18 09:12 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2014-04-18 09:12 . 2014-04-03 07:51 63192 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-04-18 09:12 . 2014-04-03 07:51 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-04-18 09:12 . 2014-04-03 07:50 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-04-18 08:33 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{99DCFE34-C6AE-4BAA-9964-8AF502B754AC}\mpengine.dll 2014-04-17 08:01 . 2014-04-17 08:02 -------- d-----w- c:\users\shaboitz\AppData\Local\NVIDIA 2014-04-17 08:01 . 2014-02-05 09:31 1048152 ----a-w- c:\windows\SysWow64\nvspcap.dll 2014-04-17 08:01 . 2014-02-05 09:30 1179576 ----a-w- c:\windows\system32\nvspcap64.dll 2014-04-17 08:01 . 2014-04-17 08:01 -------- d-----w- c:\program files (x86)\AGEIA Technologies 2014-04-17 08:00 . 2014-03-04 11:32 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2014-04-17 08:00 . 2014-04-19 07:37 -------- d-----w- c:\programdata\NVIDIA 2014-04-17 08:00 . 2014-03-04 14:35 62408 ----a-w- c:\windows\system32\OpenCL.dll 2014-04-17 08:00 . 2014-03-04 14:35 54216 ----a-w- c:\windows\SysWow64\OpenCL.dll 2014-04-17 07:49 . 2014-03-04 13:06 6714312 ----a-w- c:\windows\system32\nvcpl.dll 2014-04-17 07:49 . 2014-03-04 13:06 3497816 ----a-w- c:\windows\system32\nvsvc64.dll 2014-04-17 07:49 . 2014-03-04 13:05 922968 ----a-w- c:\windows\system32\nvvsvc.exe 2014-04-17 07:49 . 2014-03-04 13:05 64968 ----a-w- c:\windows\system32\nvshext.dll 2014-04-17 07:49 . 2014-03-04 13:05 2558808 ----a-w- c:\windows\system32\nvsvcr.dll 2014-04-17 07:49 . 2014-03-04 13:05 386336 ----a-w- c:\windows\system32\nvmctray.dll 2014-04-17 07:49 . 2014-03-04 13:05 3649185 ----a-w- c:\windows\system32\nvcoproc.bin 2014-04-16 15:26 . 2014-04-16 15:26 -------- d-sh--w- c:\users\shaboitz\AppData\Local\EmieUserList 2014-04-16 15:26 . 2014-04-16 15:26 -------- d-sh--w- c:\users\shaboitz\AppData\Local\EmieSiteList 2014-04-16 14:52 . 2014-04-16 14:52 -------- d-----w- c:\windows\ERUNT 2014-04-16 14:47 . 2014-04-16 14:48 -------- d-----w- C:\AdwCleaner 2014-04-16 14:43 . 2014-04-18 09:12 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-04-16 14:43 . 2014-04-16 14:43 -------- d-----w- c:\programdata\Malwarebytes 2014-04-16 07:11 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\SysWow64\mstscax.dll 2014-04-16 07:11 . 2014-01-03 22:44 6574592 ----a-w- c:\windows\system32\mstscax.dll 2014-04-15 14:29 . 2014-04-15 14:29 -------- d-----w- c:\programdata\Package Cache 2014-04-15 14:29 . 2014-04-15 14:29 -------- d-----w- c:\users\shaboitz\AppData\Roaming\Logitech 2014-04-15 14:29 . 2014-04-15 14:29 -------- d-----w- c:\users\shaboitz\AppData\Roaming\Logishrd 2014-04-15 09:19 . 2014-03-06 06:00 359936 ----a-w- c:\program files\Internet Explorer\IEShims.dll 2014-04-15 09:18 . 2013-09-25 02:23 1030144 ----a-w- c:\windows\system32\TSWorkspace.dll 2014-04-15 09:18 . 2013-09-25 01:57 792576 ----a-w- c:\windows\SysWow64\TSWorkspace.dll 2014-04-15 09:18 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll 2014-04-15 09:18 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll 2014-04-11 15:22 . 2014-04-11 15:22 -------- d-----w- c:\program files\CCleaner 2014-04-08 15:21 . 2014-04-08 15:21 43152 ----a-w- c:\windows\avastSS.scr 2014-04-04 08:51 . 2014-04-04 08:55 -------- d-----w- c:\users\shaboitz\AppData\Roaming\TP-LINK 2014-04-04 08:50 . 2014-04-04 08:50 -------- d-----w- c:\program files (x86)\TP-LINK 2014-04-04 08:50 . 2011-04-11 15:33 1579520 ----a-w- c:\windows\system32\drivers\athrx.sys 2014-04-04 08:50 . 2011-04-11 15:33 1579520 ----a-w- c:\windows\system32\athrx.sys 2014-04-04 08:50 . 2014-04-04 08:50 -------- d-----w- c:\programdata\TP-LINK 2014-03-24 01:34 . 2014-03-25 01:28 -------- d-----w- c:\users\shaboitz\AppData\Roaming\SleepTimerUltimate 2014-03-24 01:34 . 2014-03-24 01:34 -------- d-----w- c:\program files (x86)\SleepTimer Ultimate . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-19 07:37 . 2013-10-02 09:30 25640 ----a-w- c:\windows\gdrv.sys 2014-04-15 14:16 . 2014-02-06 19:57 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-04-15 14:16 . 2014-02-06 19:57 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-04-10 21:34 . 2013-10-02 10:34 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-04-08 15:21 . 2014-01-03 20:40 84816 ----a-w- c:\windows\system32\drivers\aswstm.sys 2014-04-08 15:21 . 2013-10-02 10:01 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2014-04-08 15:21 . 2013-10-02 10:01 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2014-04-08 15:21 . 2013-10-02 10:01 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2014-04-08 15:21 . 2013-10-02 10:01 423240 ----a-w- c:\windows\system32\drivers\aswSP.sys 2014-04-08 15:21 . 2013-10-02 10:01 334648 ----a-w- c:\windows\system32\aswBoot.exe 2014-04-08 15:21 . 2013-10-02 10:01 208928 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2014-04-08 15:21 . 2013-10-02 10:01 1039096 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2014-03-31 07:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-03-17 20:11 . 2013-10-09 08:54 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-03-04 14:35 . 2013-10-17 18:09 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll 2014-03-04 14:35 . 2013-10-17 18:09 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2014-03-04 09:17 . 2014-04-10 10:00 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-02-07 01:23 . 2014-03-12 08:38 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-12 08:37 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:32 . 2014-03-12 08:37 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-12 08:37 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-12 08:37 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-01-29 02:32 . 2014-03-12 08:38 484864 ----a-w- c:\windows\system32\wer.dll 2014-01-29 02:06 . 2014-03-12 08:38 381440 ----a-w- c:\windows\SysWow64\wer.dll 2014-01-28 02:32 . 2014-03-12 08:38 228864 ----a-w- c:\windows\system32\wwansvc.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184] "f.lux"="c:\users\shaboitz\AppData\Local\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Dolby Home Theater v4"="c:\program files (x86)\Dolby Home Theater v4\pcee4.exe" [2011-06-01 506712] "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-08 3854640] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ TP-LINK Wireless Configuration Utility.lnk - c:\program files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe -nogui [2014-4-4 788992] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [x] R2 SkypeUpdate;Skype Updater;e:\skype\Updater\Updater.exe;e:\skype\Updater\Updater.exe [x] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x] R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x] S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x] S3 LVUVC64;Logitech Webcam 250(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-16 15:27 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-04-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-04-16 15:27] . 2014-04-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-04-16 15:27] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-04-08 15:21 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-03-27 12459112] "RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2012-03-09 1158248] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-02-05 1179576] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 192.168.1.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_182_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_182_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_182.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-04-19 12:37:52 ComboFix-quarantined-files.txt 2014-04-19 10:37 . Vor Suchlauf: 11 Verzeichnis(se), 120.605.741.056 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 120.431.665.152 Bytes frei . - - End Of File - - 68CF5861CB801FD8DCDF079C11AA27DB A36C5E4F47E84449FF07ED3517B43A31 |
19.04.2014, 19:42 | #6 |
/// the machine /// TB-Ausbilder | Chrome Browser Deaktiviert Sich immer Wieder Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Chrome Browser Deaktiviert Sich immer Wieder |
19.04.2014, 23:40 | #7 |
| Chrome Browser Deaktiviert Sich immer WiederCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 20.04.2014 Suchlauf-Zeit: 00:22:01 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.19.11 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: shaboitz Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 254965 Verstrichene Zeit: 4 Min, 20 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by shaboitz on 20.04.2014 at 0:31:46,89 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.04.2014 at 0:36:34,32 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter # AdwCleaner v3.100 - Bericht erstellt am 20/04/2014 um 00:28:23 # Aktualisiert 20/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : shaboitz - SHABOITZ-PC # Gestartet von : C:\Users\shaboitz\Downloads\adwcleaner (1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Package Cache ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}] Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Google Chrome v34.0.1847.116 [ Datei : C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [947 octets] - [16/04/2014 16:47:54] AdwCleaner[R1].txt - [1301 octets] - [20/04/2014 00:24:57] AdwCleaner[S0].txt - [963 octets] - [16/04/2014 16:48:48] AdwCleaner[S1].txt - [1174 octets] - [20/04/2014 00:28:23] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1234 octets] ########## FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-04-2014 Ran by shaboitz (administrator) on SHABOITZ-PC on 20-04-2014 00:38:41 Running from C:\Users\shaboitz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Flux Software LLC) C:\Users\shaboitz\AppData\Local\FluxSoftware\Flux\flux.exe () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-27] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1179576 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-17] (InstallShield Software Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-08] (AVAST Software) HKU\S-1-5-21-86147730-3345030318-3555282241-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation) HKU\S-1-5-21-86147730-3345030318-3555282241-1000\...\Run: [f.lux] => C:\Users\shaboitz\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x91899E6052BFCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-02] Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java Deployment Toolkit 7.0.550.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U55) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () CHR Extension: (Google Docs) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-16] CHR Extension: (Google Drive) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-16] CHR Extension: (YouTube) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-16] CHR Extension: (Google-Suche) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-16] CHR Extension: (AdBlock) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-16] CHR Extension: (Google Wallet) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-16] CHR Extension: (Google Mail) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-16] ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-08] (AVAST Software) R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [57344 2011-08-22] () R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) S2 SkypeUpdate; E:\skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-08] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-08] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-08] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-08] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-08] (AVAST Software) S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-04-08] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-04-08] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-10-02] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-20 00:38 - 2014-04-20 00:38 - 00012258 _____ () C:\Users\shaboitz\Downloads\FRST.txt 2014-04-20 00:37 - 2014-04-20 00:38 - 02055680 _____ (Farbar) C:\Users\shaboitz\Downloads\FRST64.exe 2014-04-20 00:36 - 2014-04-20 00:36 - 00000628 _____ () C:\Users\shaboitz\Desktop\JRT.txt 2014-04-20 00:31 - 2014-04-20 00:31 - 01016261 _____ (Thisisu) C:\Users\shaboitz\Downloads\JRT.exe 2014-04-20 00:30 - 2014-04-20 00:30 - 00001318 _____ () C:\Users\shaboitz\Desktop\AdwCleaner[S1].txt 2014-04-20 00:23 - 2014-04-20 00:23 - 00001151 _____ () C:\Users\shaboitz\Desktop\mbam.txt 2014-04-19 12:37 - 2014-04-19 12:37 - 00019575 _____ () C:\ComboFix.txt 2014-04-19 12:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-19 12:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-19 12:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-19 12:31 - 2014-04-19 12:37 - 00000000 ____D () C:\Qoobox 2014-04-19 12:30 - 2014-04-19 12:36 - 00000000 ____D () C:\Windows\erdnt 2014-04-19 12:28 - 2014-04-19 12:29 - 05195154 ____R (Swearware) C:\Users\shaboitz\Desktop\ComboFix.exe 2014-04-19 10:16 - 2014-04-19 10:16 - 00007599 _____ () C:\Users\shaboitz\AppData\Local\Resmon.ResmonCfg 2014-04-18 15:58 - 2014-04-20 00:38 - 00000000 ____D () C:\FRST 2014-04-18 12:00 - 2014-04-20 00:29 - 00003960 _____ () C:\Windows\PFRO.log 2014-04-18 12:00 - 2014-04-20 00:29 - 00000728 _____ () C:\Windows\setupact.log 2014-04-18 12:00 - 2014-04-18 12:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-18 11:12 - 2014-04-18 11:12 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 11:12 - 2014-04-18 11:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-18 11:12 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-18 11:12 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-18 11:12 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-17 10:01 - 2014-04-17 10:02 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA 2014-04-17 10:01 - 2014-04-17 10:01 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-04-17 10:01 - 2014-02-05 11:31 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-17 10:01 - 2014-02-05 11:30 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-17 10:00 - 2014-04-20 00:29 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-17 10:00 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-04-17 10:00 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-04-17 10:00 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-04-17 09:59 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-04-17 09:59 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-04-17 09:59 - 2013-12-27 20:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-17 09:59 - 2013-12-27 20:42 - 00035104 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-04-17 09:59 - 2013-12-27 20:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-17 09:59 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-04-17 09:59 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-04-17 09:51 - 2014-04-17 09:51 - 02817354 _____ () C:\Users\shaboitz\Downloads\DCProSetup_15.zip 2014-04-17 09:49 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-04-17 09:49 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-04-17 09:49 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-04-17 09:49 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-04-16 17:27 - 2014-04-20 00:29 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-16 17:27 - 2014-04-19 23:39 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-16 17:27 - 2014-04-16 17:34 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-16 17:27 - 2014-04-16 17:34 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-16 17:27 - 2014-04-16 17:27 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieUserList 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieSiteList 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\Windows\ERUNT 2014-04-16 16:47 - 2014-04-20 00:28 - 00000000 ____D () C:\AdwCleaner 2014-04-16 16:43 - 2014-04-20 00:17 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-16 16:43 - 2014-04-16 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 09:50 - 2014-04-16 09:51 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log 2014-04-16 09:11 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-04-16 09:11 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logitech 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logishrd 2014-04-15 16:15 - 2014-04-19 12:32 - 00002514 _____ () C:\Windows\wininit.ini 2014-04-15 15:58 - 2009-06-10 23:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20140415-155823.backup 2014-04-15 11:20 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-04-15 11:20 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-04-15 11:20 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-04-15 11:20 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-04-15 11:20 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-04-15 11:20 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-04-15 11:20 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-04-15 11:20 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-04-15 11:20 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-04-15 11:20 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-04-15 11:20 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-04-15 11:20 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-04-15 11:20 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-04-15 11:20 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-04-15 11:20 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-04-15 11:20 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003118 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003092 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003090 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-04-15 11:19 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-15 11:19 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-15 11:19 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-15 11:19 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-15 11:19 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-15 11:19 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-15 11:19 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-15 11:19 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-15 11:19 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-15 11:19 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-15 11:19 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-15 11:19 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-15 11:19 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-15 11:19 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-15 11:19 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-15 11:19 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-15 11:19 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-15 11:19 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-15 11:19 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-15 11:19 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-15 11:19 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-15 11:19 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-15 11:19 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-15 11:19 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-15 11:19 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-15 11:19 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-15 11:19 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-15 11:19 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-15 11:19 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-15 11:19 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-15 11:19 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-15 11:19 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-15 11:19 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-15 11:19 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-15 11:19 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-15 11:19 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-15 11:19 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-15 11:19 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-15 11:19 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-15 11:19 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-15 11:19 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-15 11:19 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-15 11:19 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-15 11:19 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-15 11:19 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-15 11:19 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-15 11:19 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-15 11:19 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-15 11:19 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-04-15 11:19 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-04-15 11:19 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-04-15 11:19 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-04-15 11:19 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-04-15 11:19 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-04-15 11:19 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-04-15 11:18 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-04-15 11:18 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-04-15 11:18 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-04-15 11:18 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-04-11 17:22 - 2014-04-11 17:22 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-04-11 17:22 - 2014-04-11 17:22 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-11 17:22 - 2014-04-11 17:22 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-10 12:00 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 12:00 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 12:00 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 12:00 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 12:00 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 12:00 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 12:00 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 12:00 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 12:00 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 12:00 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 12:00 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 12:00 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 12:00 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 17:21 - 2014-04-08 17:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-06 18:25 - 2014-04-06 18:25 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Mozilla 2014-04-06 12:11 - 2014-04-06 12:11 - 00002461 _____ () C:\Users\shaboitz\Desktop\EverQuest.lnk 2014-04-04 11:09 - 2014-04-04 11:10 - 00000000 ____D () C:\Users\shaboitz\Desktop\schrift 2014-04-04 10:51 - 2014-04-04 10:55 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00002261 _____ () C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-04-04 10:50 - 2011-04-19 21:55 - 00007634 _____ () C:\Windows\system32\athrextx.cat 2014-04-04 10:50 - 2011-04-11 17:33 - 01579520 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2014-04-04 10:50 - 2011-04-11 17:33 - 01579520 _____ (Atheros Communications, Inc.) C:\Windows\system32\athrx.sys 2014-03-24 03:34 - 2014-03-25 03:28 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\SleepTimerUltimate 2014-03-24 03:34 - 2014-03-24 03:34 - 00001134 _____ () C:\Users\Public\Desktop\SleepTimer Ultimate.lnk 2014-03-24 03:34 - 2014-03-24 03:34 - 00000000 ____D () C:\Program Files (x86)\SleepTimer Ultimate ==================== One Month Modified Files and Folders ======= 2014-04-20 00:38 - 2014-04-20 00:38 - 00012258 _____ () C:\Users\shaboitz\Downloads\FRST.txt 2014-04-20 00:38 - 2014-04-20 00:37 - 02055680 _____ (Farbar) C:\Users\shaboitz\Downloads\FRST64.exe 2014-04-20 00:38 - 2014-04-18 15:58 - 00000000 ____D () C:\FRST 2014-04-20 00:36 - 2014-04-20 00:36 - 00000628 _____ () C:\Users\shaboitz\Desktop\JRT.txt 2014-04-20 00:36 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-20 00:36 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-20 00:36 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-20 00:36 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-20 00:36 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-20 00:31 - 2014-04-20 00:31 - 01016261 _____ (Thisisu) C:\Users\shaboitz\Downloads\JRT.exe 2014-04-20 00:30 - 2014-04-20 00:30 - 00001318 _____ () C:\Users\shaboitz\Desktop\AdwCleaner[S1].txt 2014-04-20 00:29 - 2014-04-18 12:00 - 00003960 _____ () C:\Windows\PFRO.log 2014-04-20 00:29 - 2014-04-18 12:00 - 00000728 _____ () C:\Windows\setupact.log 2014-04-20 00:29 - 2014-04-17 10:00 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-20 00:29 - 2014-04-16 17:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-20 00:29 - 2013-10-23 18:00 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs 2014-04-20 00:29 - 2013-10-14 11:34 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-04-20 00:29 - 2013-10-02 11:30 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2014-04-20 00:29 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-20 00:28 - 2014-04-16 16:47 - 00000000 ____D () C:\AdwCleaner 2014-04-20 00:28 - 2013-10-02 11:18 - 01713912 _____ () C:\Windows\WindowsUpdate.log 2014-04-20 00:23 - 2014-04-20 00:23 - 00001151 _____ () C:\Users\shaboitz\Desktop\mbam.txt 2014-04-20 00:17 - 2014-04-16 16:43 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 23:39 - 2014-04-16 17:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-19 20:12 - 2013-10-02 13:34 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TS3Client 2014-04-19 12:37 - 2014-04-19 12:37 - 00019575 _____ () C:\ComboFix.txt 2014-04-19 12:37 - 2014-04-19 12:31 - 00000000 ____D () C:\Qoobox 2014-04-19 12:37 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-19 12:36 - 2014-04-19 12:30 - 00000000 ____D () C:\Windows\erdnt 2014-04-19 12:36 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-19 12:32 - 2014-04-15 16:15 - 00002514 _____ () C:\Windows\wininit.ini 2014-04-19 12:29 - 2014-04-19 12:28 - 05195154 ____R (Swearware) C:\Users\shaboitz\Desktop\ComboFix.exe 2014-04-19 10:16 - 2014-04-19 10:16 - 00007599 _____ () C:\Users\shaboitz\AppData\Local\Resmon.ResmonCfg 2014-04-18 23:43 - 2013-10-03 11:41 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Skype 2014-04-18 12:00 - 2014-04-18 12:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-18 11:12 - 2014-04-18 11:12 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 11:12 - 2014-04-18 11:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-17 10:02 - 2014-04-17 10:01 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA 2014-04-17 10:01 - 2014-04-17 10:01 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-04-17 10:01 - 2013-10-17 20:27 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-17 10:01 - 2013-10-02 11:39 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-04-17 10:01 - 2013-10-02 11:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-17 09:51 - 2014-04-17 09:51 - 02817354 _____ () C:\Users\shaboitz\Downloads\DCProSetup_15.zip 2014-04-17 09:49 - 2013-12-27 04:24 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA Corporation 2014-04-17 09:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-04-16 17:34 - 2014-04-16 17:27 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-16 17:34 - 2014-04-16 17:27 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-16 17:27 - 2014-04-16 17:27 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Google 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Deployment 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Program Files (x86)\Google 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieUserList 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieSiteList 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\Windows\ERUNT 2014-04-16 16:50 - 2013-10-02 12:01 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-16 16:43 - 2014-04-16 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 12:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-16 09:51 - 2014-04-16 09:50 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log 2014-04-16 09:51 - 2013-10-09 10:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-16 09:51 - 2013-10-09 10:54 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-16 09:07 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-16 00:57 - 2013-10-02 11:18 - 00000000 ____D () C:\Users\shaboitz 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logitech 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logishrd 2014-04-15 16:25 - 2013-10-02 11:45 - 00064416 _____ () C:\Users\shaboitz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-15 16:16 - 2014-02-06 21:57 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-15 16:16 - 2014-02-06 21:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-15 15:49 - 2014-01-22 13:06 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Battle.net 2014-04-15 13:26 - 2009-07-14 06:45 - 00294736 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-15 13:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-15 11:19 - 2014-04-15 11:19 - 00003118 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003092 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003090 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-04-12 17:30 - 2014-01-22 13:06 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-12 14:53 - 2014-03-05 16:46 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Advanced Combat Tracker 2014-04-12 09:40 - 2014-02-06 22:06 - 00000000 ____D () C:\Users\shaboitz\Desktop\scrren 2014-04-12 09:40 - 2013-10-25 11:08 - 00000000 ____D () C:\Users\shaboitz\Desktop\Musi 2014-04-11 17:23 - 2013-10-31 20:26 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft 2014-04-11 17:22 - 2014-04-11 17:22 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-04-11 17:22 - 2014-04-11 17:22 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-11 17:22 - 2014-04-11 17:22 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-11 17:22 - 2013-10-02 12:00 - 00000000 ____D () C:\Windows\Panther 2014-04-11 13:43 - 2014-01-22 13:07 - 00000000 ____D () C:\Program Files (x86)\Hearthstone 2014-04-11 08:40 - 2013-10-12 14:22 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Adobe 2014-04-10 23:35 - 2013-10-02 12:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 23:34 - 2013-10-02 12:34 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 17:22 - 2014-01-03 22:41 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-04-08 17:21 - 2014-04-08 17:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-08 17:21 - 2014-01-03 22:40 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-08 17:21 - 2013-10-02 12:01 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-06 18:25 - 2014-04-06 18:25 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Mozilla 2014-04-06 12:11 - 2014-04-06 12:11 - 00002461 _____ () C:\Users\shaboitz\Desktop\EverQuest.lnk 2014-04-06 12:11 - 2014-02-12 17:32 - 00002491 _____ () C:\Users\shaboitz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest.lnk 2014-04-06 12:11 - 2014-02-12 17:32 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-04 11:11 - 2013-12-09 14:12 - 00000000 ____D () C:\Users\shaboitz\Desktop\Games 2014-04-04 11:10 - 2014-04-04 11:09 - 00000000 ____D () C:\Users\shaboitz\Desktop\schrift 2014-04-04 10:55 - 2014-04-04 10:51 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00002261 _____ () C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-04-04 10:50 - 2013-10-02 11:21 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-03 09:51 - 2014-04-18 11:12 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-18 11:12 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-18 11:12 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-26 22:06 - 2013-10-02 11:18 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\VirtualStore 2014-03-25 03:28 - 2014-03-24 03:34 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\SleepTimerUltimate 2014-03-24 03:34 - 2014-03-24 03:34 - 00001134 _____ () C:\Users\Public\Desktop\SleepTimer Ultimate.lnk 2014-03-24 03:34 - 2014-03-24 03:34 - 00000000 ____D () C:\Program Files (x86)\SleepTimer Ultimate Some content of TEMP: ==================== C:\Users\shaboitz\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 00:44 ==================== End Of Log ============================ --- --- --- |
20.04.2014, 18:15 | #8 |
/// the machine /// TB-Ausbilder | Chrome Browser Deaktiviert Sich immer WiederESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.04.2014, 21:06 | #9 |
| Chrome Browser Deaktiviert Sich immer WiederCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3c593981078e93478f26228eefbcbb1e # engine=17961 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-20 07:49:17 # local_time=2014-04-20 09:49:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 72 1052785 1052848 0 0 # compatibility_mode=5893 16776573 100 94 33632 149653207 0 0 # scanned=142889 # found=0 # cleaned=0 # scan_time=1286 Code:
ATTFilter Results of screen317's Security Check version 0.99.81 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` MVPS Hosts File Java 7 Update 55 Java version out of Date! Adobe Flash Player 13.0.0.182 Adobe Reader XI Google Chrome 34.0.1847.116 ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2014 02 Ran by shaboitz (administrator) on SHABOITZ-PC on 20-04-2014 22:05:38 Running from C:\Users\shaboitz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (InstallShield Software Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-27] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-17] (InstallShield Software Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-08] (AVAST Software) HKU\S-1-5-21-86147730-3345030318-3555282241-1000\...\Run: [ISUSPM Startup] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation) HKU\S-1-5-21-86147730-3345030318-3555282241-1000\...\Run: [f.lux] => C:\Users\shaboitz\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC) AppInit_DLLs-x32: => "" File Not Found ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x91899E6052BFCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-02] Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java Deployment Toolkit 7.0.550.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U55) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () CHR Extension: (Google Docs) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-16] CHR Extension: (Google Drive) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-16] CHR Extension: (YouTube) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-16] CHR Extension: (Google-Suche) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-16] CHR Extension: (AdBlock) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-16] CHR Extension: (Google Wallet) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-16] CHR Extension: (Google Mail) - C:\Users\shaboitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-16] ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-08] (AVAST Software) R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [57344 2011-08-22] () R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) S2 SkypeUpdate; E:\skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-08] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-08] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-08] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-08] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-08] (AVAST Software) R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-04-08] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-04-08] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-10-02] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-20 22:05 - 2014-04-20 22:05 - 00000000 ____D () C:\Users\shaboitz\Downloads\FRST-OlderVersion 2014-04-20 21:32 - 2014-04-20 21:32 - 00987448 _____ () C:\Users\shaboitz\Downloads\SecurityCheck.exe 2014-04-20 12:18 - 2014-04-20 12:18 - 00001346 _____ () C:\Windows\PFRO.log 2014-04-20 12:18 - 2014-04-20 12:18 - 00000224 _____ () C:\Windows\setupact.log 2014-04-20 12:18 - 2014-04-20 12:18 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-20 12:16 - 2014-04-20 12:16 - 00000000 ___SD () C:\ComboFix 2014-04-20 11:11 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-20 11:11 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-20 00:38 - 2014-04-20 22:05 - 00011998 _____ () C:\Users\shaboitz\Downloads\FRST.txt 2014-04-20 00:37 - 2014-04-20 22:05 - 02056704 _____ (Farbar) C:\Users\shaboitz\Downloads\FRST64.exe 2014-04-19 12:37 - 2014-04-19 12:37 - 00019575 _____ () C:\ComboFix.txt 2014-04-19 12:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-19 12:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-19 12:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-19 12:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-19 12:31 - 2014-04-20 12:16 - 00000000 ____D () C:\Qoobox 2014-04-19 12:30 - 2014-04-19 12:36 - 00000000 ____D () C:\Windows\erdnt 2014-04-19 12:28 - 2014-04-19 12:29 - 05195154 ____R (Swearware) C:\Users\shaboitz\Desktop\ComboFix.exe 2014-04-19 10:16 - 2014-04-19 10:16 - 00007599 _____ () C:\Users\shaboitz\AppData\Local\Resmon.ResmonCfg 2014-04-18 15:58 - 2014-04-20 22:05 - 00000000 ____D () C:\FRST 2014-04-18 11:12 - 2014-04-18 11:12 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 11:12 - 2014-04-18 11:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-18 11:12 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-18 11:12 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-18 11:12 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-17 10:01 - 2014-04-17 10:02 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA 2014-04-17 10:01 - 2014-04-17 10:01 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-04-17 10:01 - 2014-04-02 15:27 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-17 10:01 - 2014-04-02 15:27 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-04-17 10:00 - 2014-04-20 12:18 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-17 10:00 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-04-17 10:00 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-04-17 10:00 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-04-17 09:59 - 2014-03-21 21:43 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-04-17 09:59 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-04-17 09:59 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-04-17 09:59 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-04-17 09:59 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-04-17 09:51 - 2014-04-17 09:51 - 02817354 _____ () C:\Users\shaboitz\Downloads\DCProSetup_15.zip 2014-04-17 09:49 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-04-17 09:49 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-04-17 09:49 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-04-17 09:49 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-04-17 09:49 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-04-16 17:27 - 2014-04-20 21:39 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-16 17:27 - 2014-04-20 17:39 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-16 17:27 - 2014-04-16 17:34 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-16 17:27 - 2014-04-16 17:34 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-16 17:27 - 2014-04-16 17:27 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieUserList 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieSiteList 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\Windows\ERUNT 2014-04-16 16:47 - 2014-04-20 00:28 - 00000000 ____D () C:\AdwCleaner 2014-04-16 16:43 - 2014-04-20 11:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-16 16:43 - 2014-04-16 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 09:50 - 2014-04-16 09:51 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log 2014-04-16 09:11 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-04-16 09:11 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logitech 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logishrd 2014-04-15 16:15 - 2014-04-19 12:32 - 00002514 _____ () C:\Windows\wininit.ini 2014-04-15 15:58 - 2009-06-10 23:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20140415-155823.backup 2014-04-15 11:20 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-04-15 11:20 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-04-15 11:20 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-04-15 11:20 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-04-15 11:20 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-04-15 11:20 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-04-15 11:20 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-04-15 11:20 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-04-15 11:20 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-04-15 11:20 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-04-15 11:20 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-04-15 11:20 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-04-15 11:20 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-04-15 11:20 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-04-15 11:20 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-04-15 11:20 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003118 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003092 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003090 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-04-15 11:19 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-15 11:19 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-15 11:19 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-15 11:19 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-15 11:19 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-15 11:19 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-15 11:19 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-15 11:19 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-15 11:19 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-15 11:19 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-15 11:19 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-15 11:19 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-15 11:19 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-15 11:19 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-15 11:19 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-15 11:19 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-15 11:19 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-15 11:19 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-15 11:19 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-15 11:19 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-15 11:19 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-15 11:19 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-15 11:19 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-15 11:19 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-15 11:19 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-15 11:19 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-15 11:19 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-15 11:19 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-15 11:19 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-15 11:19 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-15 11:19 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-15 11:19 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-15 11:19 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-15 11:19 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-15 11:19 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-15 11:19 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-15 11:19 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-15 11:19 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-15 11:19 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-15 11:19 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-15 11:19 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-15 11:19 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-15 11:19 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-15 11:19 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-15 11:19 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-15 11:19 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-15 11:19 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-15 11:19 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-15 11:19 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-04-15 11:19 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-04-15 11:19 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-04-15 11:19 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-04-15 11:19 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-04-15 11:19 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-04-15 11:19 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-04-15 11:18 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-04-15 11:18 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-04-15 11:18 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-04-15 11:18 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-04-11 17:22 - 2014-04-11 17:22 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-04-11 17:22 - 2014-04-11 17:22 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-11 17:22 - 2014-04-11 17:22 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-10 12:00 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 12:00 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 12:00 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 12:00 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 12:00 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 12:00 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 12:00 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 12:00 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 12:00 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 12:00 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 12:00 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 12:00 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 12:00 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 12:00 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 17:21 - 2014-04-08 17:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-06 18:25 - 2014-04-06 18:25 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Mozilla 2014-04-06 12:11 - 2014-04-06 12:11 - 00002461 _____ () C:\Users\shaboitz\Desktop\EverQuest.lnk 2014-04-04 10:51 - 2014-04-04 10:55 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00002261 _____ () C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-04-04 10:50 - 2011-04-19 21:55 - 00007634 _____ () C:\Windows\system32\athrextx.cat 2014-04-04 10:50 - 2011-04-11 17:33 - 01579520 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2014-04-04 10:50 - 2011-04-11 17:33 - 01579520 _____ (Atheros Communications, Inc.) C:\Windows\system32\athrx.sys 2014-03-24 03:34 - 2014-03-25 03:28 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\SleepTimerUltimate 2014-03-24 03:34 - 2014-03-24 03:34 - 00001134 _____ () C:\Users\Public\Desktop\SleepTimer Ultimate.lnk 2014-03-24 03:34 - 2014-03-24 03:34 - 00000000 ____D () C:\Program Files (x86)\SleepTimer Ultimate ==================== One Month Modified Files and Folders ======= 2014-04-20 22:05 - 2014-04-20 22:05 - 00000000 ____D () C:\Users\shaboitz\Downloads\FRST-OlderVersion 2014-04-20 22:05 - 2014-04-20 00:38 - 00011998 _____ () C:\Users\shaboitz\Downloads\FRST.txt 2014-04-20 22:05 - 2014-04-20 00:37 - 02056704 _____ (Farbar) C:\Users\shaboitz\Downloads\FRST64.exe 2014-04-20 22:05 - 2014-04-18 15:58 - 00000000 ____D () C:\FRST 2014-04-20 21:39 - 2014-04-16 17:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-20 21:32 - 2014-04-20 21:32 - 00987448 _____ () C:\Users\shaboitz\Downloads\SecurityCheck.exe 2014-04-20 21:24 - 2013-12-09 14:13 - 00000000 ____D () C:\Users\shaboitz\Desktop\Programme 2014-04-20 17:39 - 2014-04-16 17:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-20 12:25 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-04-20 12:25 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-04-20 12:25 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-20 12:25 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-20 12:25 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-20 12:24 - 2013-10-02 11:18 - 01739947 _____ () C:\Windows\WindowsUpdate.log 2014-04-20 12:18 - 2014-04-20 12:18 - 00001346 _____ () C:\Windows\PFRO.log 2014-04-20 12:18 - 2014-04-20 12:18 - 00000224 _____ () C:\Windows\setupact.log 2014-04-20 12:18 - 2014-04-20 12:18 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-20 12:18 - 2014-04-17 10:00 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-20 12:18 - 2013-10-23 18:00 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs 2014-04-20 12:18 - 2013-10-02 11:30 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2014-04-20 12:18 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-20 12:16 - 2014-04-20 12:16 - 00000000 ___SD () C:\ComboFix 2014-04-20 12:16 - 2014-04-19 12:31 - 00000000 ____D () C:\Qoobox 2014-04-20 11:44 - 2014-04-16 16:43 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-20 11:11 - 2013-12-27 04:24 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA Corporation 2014-04-20 11:11 - 2013-10-17 20:27 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-20 11:11 - 2013-10-02 11:39 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-20 00:29 - 2013-10-14 11:34 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-04-20 00:28 - 2014-04-16 16:47 - 00000000 ____D () C:\AdwCleaner 2014-04-19 20:12 - 2013-10-02 13:34 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TS3Client 2014-04-19 12:37 - 2014-04-19 12:37 - 00019575 _____ () C:\ComboFix.txt 2014-04-19 12:37 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-19 12:36 - 2014-04-19 12:30 - 00000000 ____D () C:\Windows\erdnt 2014-04-19 12:36 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-19 12:32 - 2014-04-15 16:15 - 00002514 _____ () C:\Windows\wininit.ini 2014-04-19 12:29 - 2014-04-19 12:28 - 05195154 ____R (Swearware) C:\Users\shaboitz\Desktop\ComboFix.exe 2014-04-19 10:16 - 2014-04-19 10:16 - 00007599 _____ () C:\Users\shaboitz\AppData\Local\Resmon.ResmonCfg 2014-04-18 23:43 - 2013-10-03 11:41 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Skype 2014-04-18 11:12 - 2014-04-18 11:12 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 11:12 - 2014-04-18 11:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-17 10:02 - 2014-04-17 10:01 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\NVIDIA 2014-04-17 10:01 - 2014-04-17 10:01 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-04-17 10:01 - 2013-10-02 11:39 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-04-17 09:51 - 2014-04-17 09:51 - 02817354 _____ () C:\Users\shaboitz\Downloads\DCProSetup_15.zip 2014-04-17 09:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-04-16 17:34 - 2014-04-16 17:27 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-16 17:34 - 2014-04-16 17:27 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-16 17:27 - 2014-04-16 17:27 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Google 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Deployment 2014-04-16 17:27 - 2013-10-02 11:45 - 00000000 ____D () C:\Program Files (x86)\Google 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieUserList 2014-04-16 17:26 - 2014-04-16 17:26 - 00000000 __SHD () C:\Users\shaboitz\AppData\Local\EmieSiteList 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\Windows\ERUNT 2014-04-16 16:50 - 2013-10-02 12:01 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-16 16:43 - 2014-04-16 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 12:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-16 09:51 - 2014-04-16 09:50 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log 2014-04-16 09:51 - 2013-10-09 10:55 - 00000000 ____D () C:\ProgramData\Oracle 2014-04-16 09:51 - 2013-10-09 10:54 - 00000000 ____D () C:\Program Files (x86)\Java 2014-04-16 09:07 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-16 00:57 - 2013-10-02 11:18 - 00000000 ____D () C:\Users\shaboitz 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logitech 2014-04-15 16:29 - 2014-04-15 16:29 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Logishrd 2014-04-15 16:25 - 2013-10-02 11:45 - 00064416 _____ () C:\Users\shaboitz\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-15 16:16 - 2014-02-06 21:57 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-15 16:16 - 2014-02-06 21:57 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-15 15:49 - 2014-01-22 13:06 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Battle.net 2014-04-15 13:26 - 2009-07-14 06:45 - 00294736 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-15 13:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-15 11:19 - 2014-04-15 11:19 - 00003118 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003092 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe 2014-04-15 11:19 - 2014-04-15 11:19 - 00003090 _____ () C:\Windows\System32\Tasks\Microsoft_Hardware_Launch_itype_exe 2014-04-12 17:30 - 2014-01-22 13:06 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-04-12 14:53 - 2014-03-05 16:46 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Advanced Combat Tracker 2014-04-12 09:40 - 2013-10-25 11:08 - 00000000 ____D () C:\Users\shaboitz\Desktop\Musi 2014-04-11 17:23 - 2013-10-31 20:26 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft 2014-04-11 17:22 - 2014-04-11 17:22 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-04-11 17:22 - 2014-04-11 17:22 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-11 17:22 - 2014-04-11 17:22 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-11 17:22 - 2013-10-02 12:00 - 00000000 ____D () C:\Windows\Panther 2014-04-11 13:43 - 2014-01-22 13:07 - 00000000 ____D () C:\Program Files (x86)\Hearthstone 2014-04-11 08:40 - 2013-10-12 14:22 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\Adobe 2014-04-10 23:35 - 2013-10-02 12:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 23:34 - 2013-10-02 12:34 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 17:22 - 2014-01-03 22:41 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-04-08 17:21 - 2014-04-08 17:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-08 17:21 - 2014-01-03 22:40 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-08 17:21 - 2013-10-02 12:01 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-08 17:21 - 2013-10-02 12:01 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-06 18:25 - 2014-04-06 18:25 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\Mozilla 2014-04-06 12:11 - 2014-04-06 12:11 - 00002461 _____ () C:\Users\shaboitz\Desktop\EverQuest.lnk 2014-04-06 12:11 - 2014-02-12 17:32 - 00002491 _____ () C:\Users\shaboitz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest.lnk 2014-04-06 12:11 - 2014-02-12 17:32 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-04-04 11:11 - 2013-12-09 14:12 - 00000000 ____D () C:\Users\shaboitz\Desktop\Games 2014-04-04 10:55 - 2014-04-04 10:51 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00002261 _____ () C:\Users\Public\Desktop\TP-LINK Wireless Configuration Utility.lnk 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-04-04 10:50 - 2014-04-04 10:50 - 00000000 ____D () C:\Program Files (x86)\TP-LINK 2014-04-04 10:50 - 2013-10-02 11:21 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-03 09:51 - 2014-04-18 11:12 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-18 11:12 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-18 11:12 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 15:27 - 2014-04-17 10:01 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-02 15:27 - 2014-04-17 10:01 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-26 22:06 - 2013-10-02 11:18 - 00000000 ____D () C:\Users\shaboitz\AppData\Local\VirtualStore 2014-03-25 03:28 - 2014-03-24 03:34 - 00000000 ____D () C:\Users\shaboitz\AppData\Roaming\SleepTimerUltimate 2014-03-24 03:34 - 2014-03-24 03:34 - 00001134 _____ () C:\Users\Public\Desktop\SleepTimer Ultimate.lnk 2014-03-24 03:34 - 2014-03-24 03:34 - 00000000 ____D () C:\Program Files (x86)\SleepTimer Ultimate 2014-03-21 21:43 - 2014-04-20 11:11 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-03-21 21:43 - 2014-04-20 11:11 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-03-21 21:43 - 2014-04-17 09:59 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll Some content of TEMP: ==================== C:\Users\shaboitz\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-19 00:44 ==================== End Of Log ============================ --- --- --- Und leider besteht das Problem immer noch Geändert von Madawac (20.04.2014 um 21:17 Uhr) |
21.04.2014, 20:28 | #10 |
/// the machine /// TB-Ausbilder | Chrome Browser Deaktiviert Sich immer Wieder Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.04.2014, 07:31 | #11 |
| Chrome Browser Deaktiviert Sich immer Wieder Hallo, habe das Problem nun lösen können.Es handelt sich um Tp-Link Problem.Die Firewall konnte nicht mit der Tp-Link Software Kommunizieren,und machte mich dann dauerhaft drauf aufmerksam. Bin selber nochmal paar Files durchgegangen und da ist es mir aufgefallen. Danke für die Tolle Hilfe. lg Kann geschlossen werden |
23.04.2014, 14:21 | #12 |
/// the machine /// TB-Ausbilder | Chrome Browser Deaktiviert Sich immer Wieder Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Chrome Browser Deaktiviert Sich immer Wieder |
adobe, adobe reader xi, battle.net, browser, error, explorer, flash player, format, google, home, homepage, iexplore.exe, install.exe, logfile, nvidia, problem, realtek, registry, rundll, scan, security, software, svchost.exe, tcp, teamspeak, tracker, udp, virus, windows |