|
Plagegeister aller Art und deren Bekämpfung: Avira Free zeig mir Viren an nach einem Steam update!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.05.2014, 13:45 | #1 |
| Avira Free zeig mir Viren an nach einem Steam update! Hallo, Ich hatte ein kleines Problem und zwar, Nach dem neusten Steam update 30.04 hat mein Avira FREE* angezeigt dass Viren auf meinem Pc existieren. Steam wurde immer wieder beendet durch Avira. Ich habe erst Gedacht das könnte auch an Avira liegen hab es Deinstalliert und mir die Vollversion von Kaspersky Security geholt. Jetzt ist angeblich alles wieder ok aber ein bekannter hat mir geraten hier nochmal alles zu schildern er hat immer noch die Vermutung dass da noch was sein könnte. Gruß Sernkrieger. |
01.05.2014, 15:32 | #2 |
/// the machine /// TB-Ausbilder | Avira Free zeig mir Viren an nach einem Steam update! hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
01.05.2014, 16:08 | #3 |
| Avira Free zeig mir Viren an nach einem Steam update! FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-05-2014 Ran by Henry (administrator) on HENRY-PC on 01-05-2014 16:55:34 Running from C:\Users\Henry\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Spotify Ltd) C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Razer USA Ltd) C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12489360 2012-05-18] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM-x32\...\Run: [Razer StarcraftII Driver] => C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify] => C:\Users\Henry\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify Web Helper] => C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\MountPoints2: {fa550837-3bdb-11e3-b18b-50e549ebf6e7} - G:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found ==================== Internet (Whitelisted) ==================== Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-05-2014 Ran by Henry at 2014-05-01 16:55:56 Running from C:\Users\Henry\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated) Arma 2 (HKLM-x32\...\Steam App 33910) (Version: - Bohemia Interactive) Arma 2: DayZ Mod (HKLM-x32\...\Steam App 224580) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead (HKLM-x32\...\Steam App 33930) (Version: - Bohemia Interactive) Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive) Banished (HKLM-x32\...\Steam App 242920) (Version: - Shining Rock Software LLC) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.05 - Piriform) DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Java 7 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle) Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: - ) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla) Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.48.2 - Black Tree Gaming) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-05-2014 Ran by Henry (administrator) on HENRY-PC on 01-05-2014 16:55:34 Running from C:\Users\Henry\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Spotify Ltd) C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Razer USA Ltd) C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12489360 2012-05-18] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM-x32\...\Run: [Razer StarcraftII Driver] => C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify] => C:\Users\Henry\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify Web Helper] => C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\MountPoints2: {fa550837-3bdb-11e3-b18b-50e549ebf6e7} - G:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - DefaultScope {8904F7DE-B09A-4B31-B73A-33F1E8B92A22} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {2B6D4E68-D80D-4A45-80E4-35BA5AF1B91A} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=goughDev3&Lan=de&q={searchTerms}&gu=8d1e47c0f10a4f64adbde576dbb13e95&tu=10G9z00A11B0Ca0&sku=&tstsId=&ver=&&r=546 SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {8904F7DE-B09A-4B31-B73A-33F1E8B92A22} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: WinGuard - {e4bf64e4-237e-48e7-b43b-da6e1b60d81a} - C:\Program Files (x86)\WinGuard\winguard.dll (WinGuard) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\nq1gdbnh.default FF NewTab: chrome://quick_start/content/index.html FF Homepage: hxxp://www.youtube.com/?hl=de&gl=DE FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\nq1gdbnh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-03] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-05-01] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [dieamnlmngcabkakacnbgggaecncjpea] - C:\Program Files (x86)\WinGuard\winguard.crx [2013-08-27] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-11-05] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () S2 AntiVirSchedulerService; "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [X] S2 AntiVirService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [X] S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2014-02-28] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-05-01] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-05-01] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-05-01] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-05-01] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-05-01] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2014-02-28] () R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-01] (Malwarebytes Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R3 RzSynapse; C:\Windows\System32\DRIVERS\RzSynapse.sys [115200 2010-10-15] (Razer USA Ltd) S3 V0700Vid; C:\Windows\System32\DRIVERS\V0700Vid.sys [393920 2011-09-06] (Creative Technology Ltd.) S3 ALSysIO; \??\C:\Users\Henry\AppData\Local\Temp\ALSysIO64.sys [X] S3 cpuz136; \??\C:\Users\Henry\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] S3 GPU-Z; \??\C:\Users\Henry\AppData\Local\Temp\GPU-Z.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-01 16:55 - 2014-05-01 16:55 - 00017630 _____ () C:\Users\Henry\Downloads\FRST.txt 2014-05-01 16:55 - 2014-05-01 16:55 - 00000000 ____D () C:\FRST 2014-05-01 16:54 - 2014-05-01 16:54 - 02061824 _____ (Farbar) C:\Users\Henry\Downloads\FRST64.exe 2014-05-01 16:03 - 2014-05-01 16:03 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-01 15:59 - 2014-05-01 15:59 - 00001342 _____ () C:\Users\Henry\Desktop\DayZ Commander.lnk 2014-05-01 12:06 - 2014-05-01 12:13 - 00002336 _____ () C:\Users\Henry\Desktop\Sicherer Zahlungsverkehr.lnk 2014-05-01 12:05 - 2014-05-01 16:14 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-01 12:05 - 2014-05-01 12:10 - 00625248 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-05-01 12:05 - 2014-05-01 12:10 - 00115296 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-05-01 12:05 - 2014-05-01 12:05 - 00001130 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-05-01 12:05 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2014-05-01 11:53 - 2014-05-01 12:12 - 00004884 _____ () C:\Windows\PFRO.log 2014-05-01 11:51 - 2014-05-01 12:39 - 00003080 _____ () C:\Windows\setupact.log 2014-05-01 11:51 - 2014-05-01 11:51 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-01 02:45 - 2014-05-01 16:51 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-01 02:45 - 2014-05-01 02:45 - 00000969 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 02:45 - 2014-05-01 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 02:44 - 2014-05-01 02:44 - 01141680 _____ () C:\Users\Henry\Downloads\SteamSetup.exe 2014-05-01 02:39 - 2014-05-01 02:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-01 00:57 - 2014-05-01 02:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-30 17:06 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-30 17:06 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-24 12:57 - 2014-04-24 12:57 - 00000000 ____D () C:\Users\Henry\AppData\Local\CrashRpt 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieUserList 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieSiteList 2014-04-20 20:30 - 2014-04-20 20:30 - 00000000 ____D () C:\Users\Henry\Downloads\Smiley icons 2014-04-20 20:29 - 2014-04-20 20:29 - 00000000 ____D () C:\Users\Henry\Downloads\Dark orbit Icon pack 2014-04-20 20:28 - 2014-04-20 20:28 - 00000000 ____D () C:\Users\Henry\Downloads\NeonIcon_Pack_v1 2014-04-20 20:27 - 2014-04-20 20:27 - 00015880 _____ () C:\Users\Henry\Downloads\Icone_Pack_By_Clems.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00105079 _____ () C:\Users\Henry\Downloads\game-icon2.5.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00037810 _____ () C:\Users\Henry\Downloads\Puddel´s_Icon_Pack.rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo(1).rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00000000 ____D () C:\Users\Henry\Downloads\25-TeamSpeak-Rank-Icons-v1.01 2014-04-20 20:23 - 2014-04-20 20:23 - 00000000 ____D () C:\Users\Henry\Neuer Ordner 2014-04-20 20:18 - 2014-04-20 20:18 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo.rar 2014-04-15 20:47 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-15 20:47 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-15 20:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-15 20:47 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-15 20:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-15 20:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-15 20:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-15 20:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-15 20:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-15 20:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-15 20:47 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-15 20:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-15 20:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-15 20:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-15 20:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-15 20:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-15 20:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-15 20:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-15 20:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-15 20:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-15 20:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-15 20:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-15 20:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-15 20:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-15 20:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-15 20:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-15 20:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-15 20:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-15 20:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-15 20:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-15 20:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-15 20:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-15 20:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-15 20:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-15 20:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-15 20:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-15 20:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-15 20:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-15 20:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-15 20:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-15 20:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-15 20:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-15 20:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-15 20:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-15 20:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-15 20:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-15 20:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-15 20:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 13:33 - 2014-03-04 13:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2014-04-09 13:33 - 2014-03-04 13:03 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:39 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 13:33 - 2014-03-04 12:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:33 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 13:33 - 2014-03-04 11:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 13:33 - 2014-03-04 11:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2014-04-09 13:33 - 2014-02-04 04:37 - 00191424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 13:33 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 13:33 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 13:33 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 13:33 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 13:33 - 2014-01-24 04:40 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 15:06 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-08 15:06 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-06 01:16 - 2014-04-06 01:16 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(1).exe 2014-04-06 01:14 - 2014-04-06 01:14 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer.exe 2014-04-03 17:55 - 2014-04-03 17:55 - 00000000 ____D () C:\Users\Henry\AppData\Local\FalloutNV 2014-04-03 13:10 - 2014-05-01 13:03 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-03 13:10 - 2014-04-05 12:58 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-03 13:10 - 2014-04-05 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-03 13:09 - 2014-04-05 12:58 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-03 13:09 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 13:09 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 13:09 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-03 13:01 - 2014-04-03 13:01 - 00907018 _____ () C:\Users\Henry\Downloads\adblockplus-2.5.1.zip 2014-04-03 12:47 - 2014-04-03 12:54 - 00000000 ____D () C:\AdwCleaner ==================== One Month Modified Files and Folders ======= 2014-05-01 16:55 - 2014-05-01 16:55 - 00017630 _____ () C:\Users\Henry\Downloads\FRST.txt 2014-05-01 16:55 - 2014-05-01 16:55 - 00000000 ____D () C:\FRST 2014-05-01 16:54 - 2014-05-01 16:54 - 02061824 _____ (Farbar) C:\Users\Henry\Downloads\FRST64.exe 2014-05-01 16:51 - 2014-05-01 02:45 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-01 16:29 - 2013-09-11 15:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-01 16:14 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-01 16:06 - 2013-09-14 17:55 - 00000000 ____D () C:\Users\Henry\AppData\Local\ArmA 2 OA 2014-05-01 16:03 - 2014-05-01 16:03 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-01 15:59 - 2014-05-01 15:59 - 00001342 _____ () C:\Users\Henry\Desktop\DayZ Commander.lnk 2014-05-01 15:58 - 2013-10-18 22:10 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Spotify 2014-05-01 15:58 - 2013-09-13 16:38 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Skype 2014-05-01 14:02 - 2013-12-20 16:26 - 00000000 ____D () C:\Users\Henry\AppData\Local\DayZ 2014-05-01 13:13 - 2013-09-13 16:36 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\TS3Client 2014-05-01 13:03 - 2014-04-03 13:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-01 12:46 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-01 12:46 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-01 12:45 - 2010-11-21 08:50 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-05-01 12:45 - 2010-11-21 08:50 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-05-01 12:45 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-01 12:42 - 2013-12-01 11:01 - 02029038 _____ () C:\Windows\WindowsUpdate.log 2014-05-01 12:39 - 2014-05-01 11:51 - 00003080 _____ () C:\Windows\setupact.log 2014-05-01 12:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-01 12:13 - 2014-05-01 12:06 - 00002336 _____ () C:\Users\Henry\Desktop\Sicherer Zahlungsverkehr.lnk 2014-05-01 12:12 - 2014-05-01 11:53 - 00004884 _____ () C:\Windows\PFRO.log 2014-05-01 12:10 - 2014-05-01 12:05 - 00625248 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-05-01 12:10 - 2014-05-01 12:05 - 00115296 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-05-01 12:10 - 2013-10-17 15:47 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-05-01 12:10 - 2013-10-17 15:47 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-05-01 12:10 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-05-01 12:05 - 2014-05-01 12:05 - 00001130 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-05-01 11:51 - 2014-05-01 11:51 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-01 11:44 - 2013-09-11 15:06 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-05-01 02:48 - 2014-05-01 00:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-01 02:48 - 2013-09-13 16:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-01 02:45 - 2014-05-01 02:45 - 00000969 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 02:45 - 2014-05-01 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 02:44 - 2014-05-01 02:44 - 01141680 _____ () C:\Users\Henry\Downloads\SteamSetup.exe 2014-05-01 02:39 - 2014-05-01 02:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-29 18:31 - 2013-11-26 14:52 - 00000000 ____D () C:\Users\Henry\AppData\Local\Arma 3 2014-04-29 16:29 - 2013-09-11 15:17 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-29 16:29 - 2013-09-11 15:17 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-29 16:29 - 2013-09-11 15:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-25 13:23 - 2013-10-18 22:13 - 00000000 ____D () C:\Users\Henry\AppData\Local\Spotify 2014-04-24 12:57 - 2014-04-24 12:57 - 00000000 ____D () C:\Users\Henry\AppData\Local\CrashRpt 2014-04-24 12:55 - 2013-09-14 09:54 - 00000000 ____D () C:\Users\Henry\Documents\My Games 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieUserList 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieSiteList 2014-04-20 20:30 - 2014-04-20 20:30 - 00000000 ____D () C:\Users\Henry\Downloads\Smiley icons 2014-04-20 20:29 - 2014-04-20 20:29 - 00000000 ____D () C:\Users\Henry\Downloads\Dark orbit Icon pack 2014-04-20 20:28 - 2014-04-20 20:28 - 00000000 ____D () C:\Users\Henry\Downloads\NeonIcon_Pack_v1 2014-04-20 20:27 - 2014-04-20 20:27 - 00015880 _____ () C:\Users\Henry\Downloads\Icone_Pack_By_Clems.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00105079 _____ () C:\Users\Henry\Downloads\game-icon2.5.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00037810 _____ () C:\Users\Henry\Downloads\Puddel´s_Icon_Pack.rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo(1).rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00000000 ____D () C:\Users\Henry\Downloads\25-TeamSpeak-Rank-Icons-v1.01 2014-04-20 20:23 - 2014-04-20 20:23 - 00000000 ____D () C:\Users\Henry\Neuer Ordner 2014-04-20 20:23 - 2013-09-11 14:56 - 00000000 ____D () C:\Users\Henry 2014-04-20 20:18 - 2014-04-20 20:18 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo.rar 2014-04-16 13:06 - 2013-12-03 14:47 - 00000000 ____D () C:\Windows\rescache 2014-04-16 12:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-14 04:24 - 2014-04-30 17:06 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-04-30 17:06 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-10 10:47 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-10 10:46 - 2013-09-13 19:48 - 00000000 ____D () C:\Users\Henry\AppData\Local\Adobe 2014-04-09 21:13 - 2013-09-13 19:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 21:13 - 2013-09-13 19:13 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-09 21:12 - 2013-09-13 19:48 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 15:07 - 2013-12-15 17:36 - 00000000 ____D () C:\Users\Henry\AppData\Local\NVIDIA Corporation 2014-04-08 15:07 - 2013-09-11 15:53 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-08 15:06 - 2013-09-11 15:53 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-06 01:16 - 2014-04-06 01:16 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(1).exe 2014-04-06 01:14 - 2014-04-06 01:14 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer.exe 2014-04-05 12:58 - 2014-04-03 13:10 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 12:58 - 2014-04-03 13:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-05 12:58 - 2014-04-03 13:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 09:55 - 2014-03-29 11:25 - 00000000 ____D () C:\Users\Henry\Documents\Nexus Mod Manager 2014-04-05 09:55 - 2013-09-14 13:00 - 00000000 ____D () C:\Users\Henry\AppData\Local\Skyrim 2014-04-04 18:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-03 17:55 - 2014-04-03 17:55 - 00000000 ____D () C:\Users\Henry\AppData\Local\FalloutNV 2014-04-03 13:09 - 2013-12-01 10:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-03 13:01 - 2014-04-03 13:01 - 00907018 _____ () C:\Users\Henry\Downloads\adblockplus-2.5.1.zip 2014-04-03 12:54 - 2014-04-03 12:47 - 00000000 ____D () C:\AdwCleaner 2014-04-03 12:48 - 2014-03-16 16:42 - 00001067 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-04-03 12:48 - 2014-03-16 16:42 - 00001055 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-03 09:51 - 2014-04-03 13:09 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-03 13:09 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-03 13:09 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 15:27 - 2013-12-15 17:36 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-02 15:27 - 2013-12-15 17:36 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll Some content of TEMP: ==================== C:\Users\Henry\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe [2013-05-06 12:50] - [2013-05-06 12:50] - 0391680 ____A (Microsoft Corporation) 13CD6BA1F798A61AEE985E78D3644A1E C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2013-05-06 13:16] - [2013-05-06 13:16] - 2871296 ____A (Microsoft Corporation) 70D758D2DBE79757421017EE68143763 C:\Windows\SysWOW64\explorer.exe [2013-05-06 13:16] - [2013-05-06 13:16] - 2616320 ____A (Microsoft Corporation) B0846DB5BDAB92131529A58E627FCEB7 C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll [2013-05-06 12:37] - [2013-05-06 12:37] - 1008128 ____A (Microsoft Corporation) 7FB4D54B502C6CF2E35B8188FA4CC08C C:\Windows\SysWOW64\User32.dll [2013-05-06 12:37] - [2013-05-06 12:37] - 0833024 ____A (Microsoft Corporation) 9B836EE76E3A99052EF6DEA52B41D1BE C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-29 17:29 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-05-2014 Ran by Henry at 2014-05-01 16:55:56 Running from C:\Users\Henry\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated) Arma 2 (HKLM-x32\...\Steam App 33910) (Version: - Bohemia Interactive) Arma 2: DayZ Mod (HKLM-x32\...\Steam App 224580) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead (HKLM-x32\...\Steam App 33930) (Version: - Bohemia Interactive) Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive) Banished (HKLM-x32\...\Steam App 242920) (Version: - Shining Rock Software LLC) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.05 - Piriform) DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Java 7 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417025FF}) (Version: 7.0.250 - Oracle) Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: - ) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla) Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.48.2 - Black Tree Gaming) NVIDIA 3D Vision Controller-Treiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 334.89 - NVIDIA Corporation) NVIDIA GeForce Experience 2.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0 - NVIDIA Corporation) NVIDIA Grafiktreiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 334.89 (Version: 334.89 - NVIDIA Corporation) Hidden NVIDIA Update 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 12.4.55 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.22 (Version: 1.2.22 - NVIDIA Corporation) Hidden SHIELD Streaming (Version: 1.8.323 - NVIDIA Corporation) Hidden Spotify (HKCU\...\Spotify) (Version: 0.9.8.296.g91f68827 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) Total War: ROME II (HKLM-x32\...\Steam App 214950) (Version: - Creative Assembly) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {24A06402-CFBD-4658-BBDE-469FD9FD6E09} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {2E110DFD-5E96-4D97-A7DA-58D3663531E2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd) Task: {3E9109C7-569A-4CED-8DCA-55122948BE86} - \BackgroundContainer Startup Task No Task File <==== ATTENTION Task: {635D02AA-CF10-4A72-BA77-CCC522E48389} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-29] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-11 15:54 - 2014-02-08 19:42 - 00117024 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-10-17 16:27 - 2013-10-17 16:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe 2014-03-16 16:19 - 2014-03-16 16:19 - 00173568 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll 2014-03-16 16:19 - 2014-03-16 16:19 - 01080832 _____ () C:\Program Files\TeamSpeak 3 Client\platforms\qwindows.dll 2014-03-16 16:19 - 2014-03-16 16:19 - 00833024 _____ () C:\Program Files\TeamSpeak 3 Client\sqldrivers\qsqlite.dll 2013-09-09 10:31 - 2014-03-16 16:19 - 00102344 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2013-09-09 10:31 - 2014-03-16 16:19 - 00108488 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2014-03-16 16:19 - 2014-03-16 16:19 - 00030208 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qgif.dll 2014-03-16 16:19 - 2014-03-16 16:19 - 00233984 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg.dll 2013-09-09 10:31 - 2014-03-16 16:19 - 00563656 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2013-09-09 10:31 - 2014-03-16 16:19 - 00577480 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2014-03-16 16:19 - 2014-03-16 16:19 - 00159232 _____ () C:\Program Files\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2014-02-13 15:56 - 2014-02-13 15:56 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\024dc77f90497de2296d41c98380743c\IsdiInterop.ni.dll 2013-09-11 15:40 - 2012-02-01 16:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2013-09-11 15:39 - 2012-05-10 15:03 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2014-03-16 16:42 - 2014-03-29 20:04 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-05-01 02:46 - 2014-04-22 00:55 - 00340480 _____ () C:\Program Files (x86)\Steam\libavresample-1.dll 2014-05-01 02:46 - 2014-04-22 00:55 - 00471552 _____ () C:\Program Files (x86)\Steam\libavutil-53.dll 2014-05-01 02:46 - 2014-04-01 00:09 - 00754688 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2014-05-01 02:46 - 2014-04-24 00:01 - 01092288 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2014-05-01 02:46 - 2014-03-03 21:15 - 20626624 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2014-05-01 02:46 - 2013-06-15 01:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll 2014-05-01 02:46 - 2013-06-15 01:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll 2014-05-01 02:46 - 2013-06-15 01:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll 2014-05-01 00:57 - 2014-05-01 00:57 - 03019888 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2014-05-01 00:57 - 2014-05-01 00:57 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2014-05-01 00:57 - 2014-05-01 00:57 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: V0700Mon.exe => C:\Windows\V0700Mon.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/01/2014 04:09:55 PM) (Source: Application Hang) (User: ) Description: Programm ArmA2OA.exe, Version 1.62.103.718 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 128c Startzeit: 01cf654688c83f51 Endzeit: 29 Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe Berichts-ID: Error: (05/01/2014 00:40:54 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:29:09 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:22:02 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:18:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:14:00 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:03:50 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 11:59:01 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 11:58:33 AM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (05/01/2014 11:58:33 AM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (05/01/2014 00:39:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "atksgt" wurde aufgrund folgenden Fehlers nicht gestartet: %%1275 Error: (05/01/2014 00:39:07 PM) (Source: Application Popup) (User: ) Description: Treiber atksgt.sys konnte nicht geladen werden. Error: (05/01/2014 00:39:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Browser-Schutz" ist vom Dienst "Avira Echtzeit-Scanner" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%2 Error: (05/01/2014 00:39:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/01/2014 00:39:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Planer" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/01/2014 00:37:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (05/01/2014 00:37:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (05/01/2014 00:37:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (05/01/2014 00:37:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (05/01/2014 00:37:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (05/01/2014 04:09:55 PM) (Source: Application Hang)(User: ) Description: ArmA2OA.exe1.62.103.718128c01cf654688c83f5129C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe Error: (05/01/2014 00:40:54 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:29:09 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:22:02 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:18:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:14:00 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 00:03:50 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 11:59:01 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/01/2014 11:58:33 AM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (05/01/2014 11:58:33 AM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) ==================== Memory info =========================== Percentage of memory in use: 16% Total physical RAM: 16344.66 MB Available physical RAM: 13586.48 MB Total Pagefile: 32687.5 MB Available Pagefile: 29414.43 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:200 GB) (Free:30.54 GB) NTFS Drive d: (Daten) (Fixed) (Total:729.46 GB) (Free:107.55 GB) NTFS Drive e: (HI-TECH Treiber) (Fixed) (Total:1.95 GB) (Free:0.8 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 03A9730E) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=729 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=2 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
02.05.2014, 07:43 | #4 |
/// the machine /// TB-Ausbilder | Avira Free zeig mir Viren an nach einem Steam update! Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.05.2014, 13:05 | #5 |
| Avira Free zeig mir Viren an nach einem Steam update!Code:
ATTFilter # AdwCleaner v3.205 - Bericht erstellt am 02/05/2014 um 13:42:55 # Aktualisiert 28/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Henry - HENRY-PC # Gestartet von : C:\Users\Henry\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Henry\.android Ordner Gelöscht : C:\Users\Henry\AppData\Local\Temp\apn ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053} Schlüssel Gelöscht : HKCU\Software\AnyProtect Schlüssel Gelöscht : HKCU\Software\OCS Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\nq1gdbnh.default\prefs.js ] Zeile gelöscht : user_pref("extensions.buenosearch.admin", false); Zeile gelöscht : user_pref("extensions.buenosearch.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}"); Zeile gelöscht : user_pref("extensions.buenosearch.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.buenosearch.dfltLng", "en"); Zeile gelöscht : user_pref("extensions.buenosearch.excTlbr", false); Zeile gelöscht : user_pref("extensions.buenosearch.ffxUnstlRst", true); Zeile gelöscht : user_pref("extensions.buenosearch.id", "687300d700000000000050e549ebf6e7"); Zeile gelöscht : user_pref("extensions.buenosearch.instlDay", "16151"); Zeile gelöscht : user_pref("extensions.buenosearch.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.buenosearch.newTab", false); Zeile gelöscht : user_pref("extensions.buenosearch.prdct", "buenosearch"); Zeile gelöscht : user_pref("extensions.buenosearch.prtnrId", "buenosearch"); Zeile gelöscht : user_pref("extensions.buenosearch.rvrt", "false"); Zeile gelöscht : user_pref("extensions.buenosearch.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=687350E549EBF6E7&affID=127690&tsp=5194"); Zeile gelöscht : user_pref("extensions.buenosearch.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=687350E549EBF6E7&affID=127690&tsp=5194"); Zeile gelöscht : user_pref("extensions.buenosearch.vrsn", "1.8.28.7"); Zeile gelöscht : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.715:05:58"); Zeile gelöscht : user_pref("extensions.buenosearch.vrsni", "1.8.28.7"); -\\ Google Chrome v [ Datei : C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Extension] : majjphhgppkndjjkmhhnbgafooenebhd ************************* AdwCleaner[R0].txt - [27612 octets] - [03/04/2014 12:47:28] AdwCleaner[R1].txt - [1044 octets] - [03/04/2014 12:54:04] AdwCleaner[R2].txt - [4937 octets] - [02/05/2014 13:42:35] AdwCleaner[S0].txt - [25332 octets] - [03/04/2014 12:47:58] AdwCleaner[S1].txt - [4703 octets] - [02/05/2014 13:42:55] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4763 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Henry on 02.05.2014 at 13:48:11,46 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8904F7DE-B09A-4B31-B73A-33F1E8B92A22} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" ~~~ FireFox Emptied folder: C:\Users\Henry\AppData\Roaming\mozilla\firefox\profiles\nq1gdbnh.default\minidumps [77 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02.05.2014 at 13:52:18,30 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 02.05.2014 Suchlauf-Zeit: 13:41:00 Logdatei: MBAM.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.05.02.07 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Henry Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 258672 Verstrichene Zeit: 8 Min, 44 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-05-2014 Ran by Henry (administrator) on HENRY-PC on 02-05-2014 14:04:04 Running from C:\Users\Henry\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Spotify Ltd) C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Razer USA Ltd) C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12489360 2012-05-18] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM-x32\...\Run: [Razer StarcraftII Driver] => C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify] => C:\Users\Henry\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify Web Helper] => C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1825984 2014-04-24] (Valve Corporation) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\MountPoints2: {fa550837-3bdb-11e3-b18b-50e549ebf6e7} - G:\HTC_Sync_Manager_PC.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {2B6D4E68-D80D-4A45-80E4-35BA5AF1B91A} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=goughDev3&Lan=de&q={searchTerms}&gu=8d1e47c0f10a4f64adbde576dbb13e95&tu=10G9z00A11B0Ca0&sku=&tstsId=&ver=&&r=546 SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: WinGuard - {e4bf64e4-237e-48e7-b43b-da6e1b60d81a} - C:\Program Files (x86)\WinGuard\winguard.dll (WinGuard) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\nq1gdbnh.default FF NewTab: chrome://quick_start/content/index.html FF Homepage: hxxp://www.youtube.com/?hl=de&gl=DE FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\nq1gdbnh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-03] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-05-01] Chrome: ======= CHR HomePage: CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [dieamnlmngcabkakacnbgggaecncjpea] - C:\Program Files (x86)\WinGuard\winguard.crx [2013-08-27] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-11-05] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () S2 AntiVirSchedulerService; "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [X] S2 AntiVirService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [X] S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2014-02-28] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-05-01] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-05-01] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-05-01] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-05-01] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-05-01] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2014-02-28] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R3 RzSynapse; C:\Windows\System32\DRIVERS\RzSynapse.sys [115200 2010-10-15] (Razer USA Ltd) S3 V0700Vid; C:\Windows\System32\DRIVERS\V0700Vid.sys [393920 2011-09-06] (Creative Technology Ltd.) S3 ALSysIO; \??\C:\Users\Henry\AppData\Local\Temp\ALSysIO64.sys [X] S3 cpuz136; \??\C:\Users\Henry\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] S3 GPU-Z; \??\C:\Users\Henry\AppData\Local\Temp\GPU-Z.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-02 14:03 - 2014-05-02 14:03 - 00000000 ____D () C:\Users\Henry\Downloads\FRST-OlderVersion 2014-05-02 13:58 - 2014-05-02 13:58 - 00001148 _____ () C:\MBAM.txt 2014-05-02 13:52 - 2014-05-02 13:52 - 00000959 _____ () C:\Users\Henry\Desktop\JRT.txt 2014-05-02 13:48 - 2014-05-02 13:48 - 00000000 ____D () C:\Windows\ERUNT 2014-05-02 13:47 - 2014-05-02 13:48 - 01016261 _____ (Thisisu) C:\Users\Henry\Downloads\JRT.exe 2014-05-02 13:42 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-02 13:41 - 2014-05-02 13:41 - 01310621 _____ () C:\Users\Henry\Downloads\adwcleaner.exe 2014-05-02 13:26 - 2014-05-02 13:26 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Henry\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-01 16:55 - 2014-05-02 14:04 - 00017079 _____ () C:\Users\Henry\Downloads\FRST.txt 2014-05-01 16:55 - 2014-05-02 14:04 - 00000000 ____D () C:\FRST 2014-05-01 16:55 - 2014-05-01 16:56 - 00019407 _____ () C:\Users\Henry\Downloads\Addition.txt 2014-05-01 16:54 - 2014-05-02 14:03 - 02062336 _____ (Farbar) C:\Users\Henry\Downloads\FRST64.exe 2014-05-01 16:03 - 2014-05-01 16:03 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-01 15:59 - 2014-05-01 15:59 - 00001342 _____ () C:\Users\Henry\Desktop\DayZ Commander.lnk 2014-05-01 12:06 - 2014-05-01 12:13 - 00002336 _____ () C:\Users\Henry\Desktop\Sicherer Zahlungsverkehr.lnk 2014-05-01 12:05 - 2014-05-02 13:43 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-01 12:05 - 2014-05-01 12:10 - 00625248 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-05-01 12:05 - 2014-05-01 12:10 - 00115296 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-05-01 12:05 - 2014-05-01 12:05 - 00001130 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-05-01 12:05 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2014-05-01 11:53 - 2014-05-02 13:43 - 00005194 _____ () C:\Windows\PFRO.log 2014-05-01 11:51 - 2014-05-02 13:43 - 00003696 _____ () C:\Windows\setupact.log 2014-05-01 11:51 - 2014-05-01 11:51 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-01 02:45 - 2014-05-02 13:43 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-01 02:45 - 2014-05-01 02:45 - 00000969 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 02:45 - 2014-05-01 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 02:44 - 2014-05-01 02:44 - 01141680 _____ () C:\Users\Henry\Downloads\SteamSetup.exe 2014-05-01 02:39 - 2014-05-01 02:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-01 00:57 - 2014-05-01 02:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-30 17:06 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-30 17:06 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-24 12:57 - 2014-04-24 12:57 - 00000000 ____D () C:\Users\Henry\AppData\Local\CrashRpt 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieUserList 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieSiteList 2014-04-20 20:30 - 2014-04-20 20:30 - 00000000 ____D () C:\Users\Henry\Downloads\Smiley icons 2014-04-20 20:29 - 2014-04-20 20:29 - 00000000 ____D () C:\Users\Henry\Downloads\Dark orbit Icon pack 2014-04-20 20:28 - 2014-04-20 20:28 - 00000000 ____D () C:\Users\Henry\Downloads\NeonIcon_Pack_v1 2014-04-20 20:27 - 2014-04-20 20:27 - 00015880 _____ () C:\Users\Henry\Downloads\Icone_Pack_By_Clems.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00105079 _____ () C:\Users\Henry\Downloads\game-icon2.5.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00037810 _____ () C:\Users\Henry\Downloads\Puddel´s_Icon_Pack.rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo(1).rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00000000 ____D () C:\Users\Henry\Downloads\25-TeamSpeak-Rank-Icons-v1.01 2014-04-20 20:23 - 2014-04-20 20:23 - 00000000 ____D () C:\Users\Henry\Neuer Ordner 2014-04-20 20:18 - 2014-04-20 20:18 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo.rar 2014-04-15 20:47 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-15 20:47 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-15 20:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-15 20:47 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-15 20:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-15 20:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-15 20:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-15 20:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-15 20:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-15 20:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-15 20:47 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-15 20:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-15 20:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-15 20:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-15 20:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-15 20:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-15 20:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-15 20:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-15 20:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-15 20:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-15 20:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-15 20:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-15 20:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-15 20:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-15 20:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-15 20:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-15 20:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-15 20:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-15 20:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-15 20:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-15 20:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-15 20:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-15 20:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-15 20:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-15 20:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-15 20:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-15 20:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-15 20:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-15 20:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-15 20:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-15 20:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-15 20:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-15 20:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-15 20:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-15 20:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-15 20:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-15 20:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-15 20:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 13:33 - 2014-03-04 13:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2014-04-09 13:33 - 2014-03-04 13:03 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:39 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 13:33 - 2014-03-04 12:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:33 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 13:33 - 2014-03-04 11:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 13:33 - 2014-03-04 11:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2014-04-09 13:33 - 2014-02-04 04:37 - 00191424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 13:33 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 13:33 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 13:33 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 13:33 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 13:33 - 2014-01-24 04:40 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 15:06 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-08 15:06 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-06 01:16 - 2014-04-06 01:16 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(1).exe 2014-04-06 01:14 - 2014-04-06 01:14 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer.exe 2014-04-03 17:55 - 2014-04-03 17:55 - 00000000 ____D () C:\Users\Henry\AppData\Local\FalloutNV 2014-04-03 13:10 - 2014-05-02 13:56 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-03 13:10 - 2014-05-02 13:27 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-03 13:10 - 2014-05-02 13:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-03 13:09 - 2014-05-02 13:27 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-03 13:09 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 13:09 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 13:09 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-03 13:01 - 2014-04-03 13:01 - 00907018 _____ () C:\Users\Henry\Downloads\adblockplus-2.5.1.zip 2014-04-03 12:47 - 2014-05-02 13:42 - 00000000 ____D () C:\AdwCleaner ==================== One Month Modified Files and Folders ======= 2014-05-02 14:04 - 2014-05-01 16:55 - 00017079 _____ () C:\Users\Henry\Downloads\FRST.txt 2014-05-02 14:04 - 2014-05-01 16:55 - 00000000 ____D () C:\FRST 2014-05-02 14:03 - 2014-05-02 14:03 - 00000000 ____D () C:\Users\Henry\Downloads\FRST-OlderVersion 2014-05-02 14:03 - 2014-05-01 16:54 - 02062336 _____ (Farbar) C:\Users\Henry\Downloads\FRST64.exe 2014-05-02 13:58 - 2014-05-02 13:58 - 00001148 _____ () C:\MBAM.txt 2014-05-02 13:56 - 2014-04-03 13:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-02 13:52 - 2014-05-02 13:52 - 00000959 _____ () C:\Users\Henry\Desktop\JRT.txt 2014-05-02 13:50 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-02 13:50 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-02 13:49 - 2013-10-18 22:10 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Spotify 2014-05-02 13:49 - 2013-09-13 16:38 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Skype 2014-05-02 13:49 - 2010-11-21 08:50 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-05-02 13:49 - 2010-11-21 08:50 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-05-02 13:49 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-02 13:48 - 2014-05-02 13:48 - 00000000 ____D () C:\Windows\ERUNT 2014-05-02 13:48 - 2014-05-02 13:47 - 01016261 _____ (Thisisu) C:\Users\Henry\Downloads\JRT.exe 2014-05-02 13:44 - 2013-09-13 16:36 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\TS3Client 2014-05-02 13:43 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-02 13:43 - 2014-05-01 11:53 - 00005194 _____ () C:\Windows\PFRO.log 2014-05-02 13:43 - 2014-05-01 11:51 - 00003696 _____ () C:\Windows\setupact.log 2014-05-02 13:43 - 2014-05-01 02:45 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-02 13:43 - 2013-12-01 11:01 - 02067913 _____ () C:\Windows\WindowsUpdate.log 2014-05-02 13:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-02 13:42 - 2014-04-03 12:47 - 00000000 ____D () C:\AdwCleaner 2014-05-02 13:42 - 2013-09-11 14:56 - 00000000 ____D () C:\Users\Henry 2014-05-02 13:41 - 2014-05-02 13:41 - 01310621 _____ () C:\Users\Henry\Downloads\adwcleaner.exe 2014-05-02 13:29 - 2013-09-11 15:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-02 13:27 - 2014-04-03 13:10 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-02 13:27 - 2014-04-03 13:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-02 13:27 - 2014-04-03 13:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-02 13:26 - 2014-05-02 13:26 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Henry\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-01 18:41 - 2013-12-20 16:26 - 00000000 ____D () C:\Users\Henry\AppData\Local\DayZ 2014-05-01 16:56 - 2014-05-01 16:55 - 00019407 _____ () C:\Users\Henry\Downloads\Addition.txt 2014-05-01 16:06 - 2013-09-14 17:55 - 00000000 ____D () C:\Users\Henry\AppData\Local\ArmA 2 OA 2014-05-01 16:03 - 2014-05-01 16:03 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-01 15:59 - 2014-05-01 15:59 - 00001342 _____ () C:\Users\Henry\Desktop\DayZ Commander.lnk 2014-05-01 12:13 - 2014-05-01 12:06 - 00002336 _____ () C:\Users\Henry\Desktop\Sicherer Zahlungsverkehr.lnk 2014-05-01 12:10 - 2014-05-01 12:05 - 00625248 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-05-01 12:10 - 2014-05-01 12:05 - 00115296 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-05-01 12:10 - 2013-10-17 15:47 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-05-01 12:10 - 2013-10-17 15:47 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-05-01 12:10 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-05-01 12:05 - 2014-05-01 12:05 - 00001130 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-05-01 11:51 - 2014-05-01 11:51 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-01 11:44 - 2013-09-11 15:06 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-05-01 02:48 - 2014-05-01 00:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-01 02:48 - 2013-09-13 16:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-01 02:45 - 2014-05-01 02:45 - 00000969 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 02:45 - 2014-05-01 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 02:44 - 2014-05-01 02:44 - 01141680 _____ () C:\Users\Henry\Downloads\SteamSetup.exe 2014-05-01 02:39 - 2014-05-01 02:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-29 18:31 - 2013-11-26 14:52 - 00000000 ____D () C:\Users\Henry\AppData\Local\Arma 3 2014-04-29 16:29 - 2013-09-11 15:17 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-29 16:29 - 2013-09-11 15:17 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-29 16:29 - 2013-09-11 15:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-25 13:23 - 2013-10-18 22:13 - 00000000 ____D () C:\Users\Henry\AppData\Local\Spotify 2014-04-24 12:57 - 2014-04-24 12:57 - 00000000 ____D () C:\Users\Henry\AppData\Local\CrashRpt 2014-04-24 12:55 - 2013-09-14 09:54 - 00000000 ____D () C:\Users\Henry\Documents\My Games 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieUserList 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieSiteList 2014-04-20 20:30 - 2014-04-20 20:30 - 00000000 ____D () C:\Users\Henry\Downloads\Smiley icons 2014-04-20 20:29 - 2014-04-20 20:29 - 00000000 ____D () C:\Users\Henry\Downloads\Dark orbit Icon pack 2014-04-20 20:28 - 2014-04-20 20:28 - 00000000 ____D () C:\Users\Henry\Downloads\NeonIcon_Pack_v1 2014-04-20 20:27 - 2014-04-20 20:27 - 00015880 _____ () C:\Users\Henry\Downloads\Icone_Pack_By_Clems.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00105079 _____ () C:\Users\Henry\Downloads\game-icon2.5.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00037810 _____ () C:\Users\Henry\Downloads\Puddel´s_Icon_Pack.rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo(1).rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00000000 ____D () C:\Users\Henry\Downloads\25-TeamSpeak-Rank-Icons-v1.01 2014-04-20 20:23 - 2014-04-20 20:23 - 00000000 ____D () C:\Users\Henry\Neuer Ordner 2014-04-20 20:18 - 2014-04-20 20:18 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo.rar 2014-04-16 13:06 - 2013-12-03 14:47 - 00000000 ____D () C:\Windows\rescache 2014-04-16 12:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-14 04:24 - 2014-04-30 17:06 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-04-30 17:06 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-10 10:47 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-10 10:46 - 2013-09-13 19:48 - 00000000 ____D () C:\Users\Henry\AppData\Local\Adobe 2014-04-09 21:13 - 2013-09-13 19:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 21:13 - 2013-09-13 19:13 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-09 21:12 - 2013-09-13 19:48 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 15:07 - 2013-12-15 17:36 - 00000000 ____D () C:\Users\Henry\AppData\Local\NVIDIA Corporation 2014-04-08 15:07 - 2013-09-11 15:53 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-08 15:06 - 2013-09-11 15:53 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-06 01:16 - 2014-04-06 01:16 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(1).exe 2014-04-06 01:14 - 2014-04-06 01:14 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer.exe 2014-04-05 09:55 - 2014-03-29 11:25 - 00000000 ____D () C:\Users\Henry\Documents\Nexus Mod Manager 2014-04-05 09:55 - 2013-09-14 13:00 - 00000000 ____D () C:\Users\Henry\AppData\Local\Skyrim 2014-04-04 18:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-03 17:55 - 2014-04-03 17:55 - 00000000 ____D () C:\Users\Henry\AppData\Local\FalloutNV 2014-04-03 13:09 - 2013-12-01 10:47 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-03 13:01 - 2014-04-03 13:01 - 00907018 _____ () C:\Users\Henry\Downloads\adblockplus-2.5.1.zip 2014-04-03 12:48 - 2014-03-16 16:42 - 00001067 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-04-03 12:48 - 2014-03-16 16:42 - 00001055 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-03 09:51 - 2014-04-03 13:09 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-03 13:09 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-03 13:09 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 15:27 - 2013-12-15 17:36 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2014-04-02 15:27 - 2013-12-15 17:36 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll Some content of TEMP: ==================== C:\Users\Henry\AppData\Local\Temp\avgnt.exe C:\Users\Henry\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe [2013-05-06 12:50] - [2013-05-06 12:50] - 0391680 ____A (Microsoft Corporation) 13CD6BA1F798A61AEE985E78D3644A1E C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2013-05-06 13:16] - [2013-05-06 13:16] - 2871296 ____A (Microsoft Corporation) 70D758D2DBE79757421017EE68143763 C:\Windows\SysWOW64\explorer.exe [2013-05-06 13:16] - [2013-05-06 13:16] - 2616320 ____A (Microsoft Corporation) B0846DB5BDAB92131529A58E627FCEB7 C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll [2013-05-06 12:37] - [2013-05-06 12:37] - 1008128 ____A (Microsoft Corporation) 7FB4D54B502C6CF2E35B8188FA4CC08C C:\Windows\SysWOW64\User32.dll [2013-05-06 12:37] - [2013-05-06 12:37] - 0833024 ____A (Microsoft Corporation) 9B836EE76E3A99052EF6DEA52B41D1BE C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-29 17:29 ==================== End Of Log ============================ --- --- --- |
04.05.2014, 06:53 | #6 |
/// the machine /// TB-Ausbilder | Avira Free zeig mir Viren an nach einem Steam update!ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Avira Free zeig mir Viren an nach einem Steam update! |
04.05.2014, 21:37 | #7 |
| Avira Free zeig mir Viren an nach einem Steam update!Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=2baaf3b5c510e445a03eabfd2ff4ab47 # engine=18132 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-04 08:25:11 # local_time=2014-05-04 10:25:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 28886 150864961 0 0 # scanned=203035 # found=0 # cleaned=0 # scan_time=4618 Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.206 Mozilla Thunderbird (24.5.0) ````````Process Check: objlist.exe by Laurent```````` Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-05-2014 Ran by Henry (administrator) on HENRY-PC on 04-05-2014 22:34:49 Running from C:\Users\Henry\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Spotify Ltd) C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Razer USA Ltd) C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Ghisler Software GmbH) C:\totalcmd\TOTALCMD.EXE () C:\Users\Henry\Downloads\SecurityCheck.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12489360 2012-05-18] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM-x32\...\Run: [Razer StarcraftII Driver] => C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify] => C:\Users\Henry\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Spotify Web Helper] => C:\Users\Henry\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-10] (Spotify Ltd) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1825984 2014-04-24] (Valve Corporation) HKU\S-1-5-21-2843971231-471032046-1002746783-1000\...\MountPoints2: {fa550837-3bdb-11e3-b18b-50e549ebf6e7} - G:\HTC_Sync_Manager_PC.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {2B6D4E68-D80D-4A45-80E4-35BA5AF1B91A} URL = hxxp://search.zonealarm.com/search?src=sp&tbid=goughDev3&Lan=de&q={searchTerms}&gu=8d1e47c0f10a4f64adbde576dbb13e95&tu=10G9z00A11B0Ca0&sku=&tstsId=&ver=&&r=546 SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: WinGuard - {e4bf64e4-237e-48e7-b43b-da6e1b60d81a} - C:\Program Files (x86)\WinGuard\winguard.dll (WinGuard) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\nq1gdbnh.default FF NewTab: chrome://quick_start/content/index.html FF Homepage: hxxp://www.youtube.com/?hl=de&gl=DE FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Henry\AppData\Roaming\Mozilla\Firefox\Profiles\nq1gdbnh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-03] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-05-01] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-05-01] Chrome: ======= CHR HomePage: CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [dieamnlmngcabkakacnbgggaecncjpea] - C:\Program Files (x86)\WinGuard\winguard.crx [2013-08-27] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-11-05] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-05-10] (Intel Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () S2 AntiVirSchedulerService; "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [X] S2 AntiVirService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [X] S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2014-02-28] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-05-01] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-05-01] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-05-01] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-05-01] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-05-01] (Kaspersky Lab ZAO) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2014-02-28] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation) R3 RzSynapse; C:\Windows\System32\DRIVERS\RzSynapse.sys [115200 2010-10-15] (Razer USA Ltd) S3 V0700Vid; C:\Windows\System32\DRIVERS\V0700Vid.sys [393920 2011-09-06] (Creative Technology Ltd.) S3 ALSysIO; \??\C:\Users\Henry\AppData\Local\Temp\ALSysIO64.sys [X] S3 cpuz136; \??\C:\Users\Henry\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X] S3 GPU-Z; \??\C:\Users\Henry\AppData\Local\Temp\GPU-Z.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-04 22:31 - 2014-05-04 22:31 - 00855379 _____ () C:\Users\Henry\Downloads\SecurityCheck.exe 2014-05-04 20:53 - 2014-05-04 20:53 - 02347384 _____ (ESET) C:\Users\Henry\Downloads\esetsmartinstaller_deu.exe 2014-05-02 21:51 - 2014-05-02 22:11 - 00001213 _____ () C:\Users\Henry\AppData\Roaming\BreakingPoint_Options.ini 2014-05-02 21:51 - 2014-05-02 21:55 - 00000282 _____ () C:\Users\Henry\AppData\Roaming\BreakingPoint_Login.ini 2014-05-02 21:30 - 2014-05-02 21:30 - 01686528 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(2).exe 2014-05-02 14:03 - 2014-05-02 14:03 - 00000000 ____D () C:\Users\Henry\Downloads\FRST-OlderVersion 2014-05-02 13:58 - 2014-05-02 13:58 - 00001148 _____ () C:\MBAM.txt 2014-05-02 13:48 - 2014-05-02 13:48 - 00000000 ____D () C:\Windows\ERUNT 2014-05-02 13:47 - 2014-05-02 13:48 - 01016261 _____ (Thisisu) C:\Users\Henry\Downloads\JRT.exe 2014-05-02 13:42 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-02 13:41 - 2014-05-02 13:41 - 01310621 _____ () C:\Users\Henry\Downloads\adwcleaner.exe 2014-05-02 13:26 - 2014-05-02 13:26 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Henry\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-01 16:55 - 2014-05-04 22:34 - 00017368 _____ () C:\Users\Henry\Downloads\FRST.txt 2014-05-01 16:55 - 2014-05-04 22:34 - 00000000 ____D () C:\FRST 2014-05-01 16:55 - 2014-05-01 16:56 - 00019407 _____ () C:\Users\Henry\Downloads\Addition.txt 2014-05-01 16:54 - 2014-05-02 14:03 - 02062336 _____ (Farbar) C:\Users\Henry\Downloads\FRST64.exe 2014-05-01 16:03 - 2014-05-01 16:03 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-01 15:59 - 2014-05-01 15:59 - 00001342 _____ () C:\Users\Henry\Desktop\DayZ Commander.lnk 2014-05-01 12:06 - 2014-05-01 12:13 - 00002336 _____ () C:\Users\Henry\Desktop\Sicherer Zahlungsverkehr.lnk 2014-05-01 12:05 - 2014-05-04 21:42 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-01 12:05 - 2014-05-01 12:10 - 00625248 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-05-01 12:05 - 2014-05-01 12:10 - 00115296 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-05-01 12:05 - 2014-05-01 12:05 - 00001130 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-05-01 12:05 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2014-05-01 11:53 - 2014-05-02 13:43 - 00005194 _____ () C:\Windows\PFRO.log 2014-05-01 11:51 - 2014-05-04 20:51 - 00005837 _____ () C:\Windows\setupact.log 2014-05-01 11:51 - 2014-05-01 11:51 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-01 02:45 - 2014-05-04 16:32 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-01 02:45 - 2014-05-01 02:45 - 00000969 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 02:45 - 2014-05-01 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 02:44 - 2014-05-01 02:44 - 01141680 _____ () C:\Users\Henry\Downloads\SteamSetup.exe 2014-05-01 02:39 - 2014-05-01 02:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-01 00:57 - 2014-05-01 02:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-30 17:06 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-30 17:06 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-24 12:57 - 2014-04-24 12:57 - 00000000 ____D () C:\Users\Henry\AppData\Local\CrashRpt 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieUserList 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieSiteList 2014-04-20 20:30 - 2014-04-20 20:30 - 00000000 ____D () C:\Users\Henry\Downloads\Smiley icons 2014-04-20 20:29 - 2014-04-20 20:29 - 00000000 ____D () C:\Users\Henry\Downloads\Dark orbit Icon pack 2014-04-20 20:28 - 2014-04-20 20:28 - 00000000 ____D () C:\Users\Henry\Downloads\NeonIcon_Pack_v1 2014-04-20 20:27 - 2014-04-20 20:27 - 00015880 _____ () C:\Users\Henry\Downloads\Icone_Pack_By_Clems.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00105079 _____ () C:\Users\Henry\Downloads\game-icon2.5.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00037810 _____ () C:\Users\Henry\Downloads\Puddel´s_Icon_Pack.rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo(1).rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00000000 ____D () C:\Users\Henry\Downloads\25-TeamSpeak-Rank-Icons-v1.01 2014-04-20 20:23 - 2014-04-20 20:23 - 00000000 ____D () C:\Users\Henry\Neuer Ordner 2014-04-20 20:18 - 2014-04-20 20:18 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo.rar 2014-04-15 20:47 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-15 20:47 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-15 20:47 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-15 20:47 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-15 20:47 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-15 20:47 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-15 20:47 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-15 20:47 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-15 20:47 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-15 20:47 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-15 20:47 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-15 20:47 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-15 20:47 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-15 20:47 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-15 20:47 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-15 20:47 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-15 20:47 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-15 20:47 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-15 20:47 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-15 20:47 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-15 20:47 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-15 20:47 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-15 20:47 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-15 20:47 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-15 20:47 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-15 20:47 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-15 20:47 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-15 20:47 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-15 20:47 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-15 20:47 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-15 20:47 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-15 20:47 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-15 20:47 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-15 20:47 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-15 20:47 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-15 20:47 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-15 20:47 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-15 20:47 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-15 20:47 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-15 20:47 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-15 20:47 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-15 20:47 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-15 20:47 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-15 20:47 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-15 20:47 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-15 20:47 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-15 20:47 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-15 20:47 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 13:33 - 2014-03-04 13:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 13:33 - 2014-03-04 13:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2014-04-09 13:33 - 2014-03-04 13:03 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 13:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:39 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-04-09 13:33 - 2014-03-04 12:38 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 13:33 - 2014-03-04 12:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 12:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:33 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 13:33 - 2014-03-04 11:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 13:33 - 2014-03-04 11:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2014-04-09 13:33 - 2014-03-04 11:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2014-04-09 13:33 - 2014-02-04 04:37 - 00191424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 13:33 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 13:33 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 13:33 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 13:33 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 13:33 - 2014-01-24 04:40 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-08 15:06 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2014-04-08 15:06 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2014-04-06 01:16 - 2014-04-06 01:16 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(1).exe 2014-04-06 01:14 - 2014-04-06 01:14 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer.exe ==================== One Month Modified Files and Folders ======= 2014-05-04 22:35 - 2014-05-01 16:55 - 00017368 _____ () C:\Users\Henry\Downloads\FRST.txt 2014-05-04 22:34 - 2014-05-01 16:55 - 00000000 ____D () C:\FRST 2014-05-04 22:31 - 2014-05-04 22:31 - 00855379 _____ () C:\Users\Henry\Downloads\SecurityCheck.exe 2014-05-04 22:29 - 2013-09-11 15:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-04 21:59 - 2013-10-18 22:10 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Spotify 2014-05-04 21:59 - 2013-09-13 16:38 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Skype 2014-05-04 21:51 - 2013-09-13 16:36 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\TS3Client 2014-05-04 21:42 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-04 20:54 - 2010-11-21 08:50 - 00699416 _____ () C:\Windows\system32\perfh007.dat 2014-05-04 20:54 - 2010-11-21 08:50 - 00149556 _____ () C:\Windows\system32\perfc007.dat 2014-05-04 20:54 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-04 20:53 - 2014-05-04 20:53 - 02347384 _____ (ESET) C:\Users\Henry\Downloads\esetsmartinstaller_deu.exe 2014-05-04 20:51 - 2014-05-01 11:51 - 00005837 _____ () C:\Windows\setupact.log 2014-05-04 17:04 - 2013-12-01 11:01 - 01065709 _____ () C:\Windows\WindowsUpdate.log 2014-05-04 16:38 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-04 16:38 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-04 16:32 - 2014-05-01 02:45 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-04 16:31 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-03 15:34 - 2013-12-20 16:26 - 00000000 ____D () C:\Users\Henry\AppData\Local\DayZ 2014-05-02 22:12 - 2013-11-26 14:52 - 00000000 ____D () C:\Users\Henry\AppData\Local\Arma 3 2014-05-02 22:11 - 2014-05-02 21:51 - 00001213 _____ () C:\Users\Henry\AppData\Roaming\BreakingPoint_Options.ini 2014-05-02 22:11 - 2014-04-03 13:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-02 21:55 - 2014-05-02 21:51 - 00000282 _____ () C:\Users\Henry\AppData\Roaming\BreakingPoint_Login.ini 2014-05-02 21:30 - 2014-05-02 21:30 - 01686528 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(2).exe 2014-05-02 14:17 - 2013-09-14 17:55 - 00000000 ____D () C:\Users\Henry\AppData\Local\ArmA 2 OA 2014-05-02 14:03 - 2014-05-02 14:03 - 00000000 ____D () C:\Users\Henry\Downloads\FRST-OlderVersion 2014-05-02 14:03 - 2014-05-01 16:54 - 02062336 _____ (Farbar) C:\Users\Henry\Downloads\FRST64.exe 2014-05-02 13:58 - 2014-05-02 13:58 - 00001148 _____ () C:\MBAM.txt 2014-05-02 13:48 - 2014-05-02 13:48 - 00000000 ____D () C:\Windows\ERUNT 2014-05-02 13:48 - 2014-05-02 13:47 - 01016261 _____ (Thisisu) C:\Users\Henry\Downloads\JRT.exe 2014-05-02 13:43 - 2014-05-01 11:53 - 00005194 _____ () C:\Windows\PFRO.log 2014-05-02 13:42 - 2014-04-03 12:47 - 00000000 ____D () C:\AdwCleaner 2014-05-02 13:42 - 2013-09-11 14:56 - 00000000 ____D () C:\Users\Henry 2014-05-02 13:41 - 2014-05-02 13:41 - 01310621 _____ () C:\Users\Henry\Downloads\adwcleaner.exe 2014-05-02 13:27 - 2014-04-03 13:10 - 00001108 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-02 13:27 - 2014-04-03 13:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-02 13:27 - 2014-04-03 13:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-02 13:26 - 2014-05-02 13:26 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Henry\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-01 16:56 - 2014-05-01 16:55 - 00019407 _____ () C:\Users\Henry\Downloads\Addition.txt 2014-05-01 16:03 - 2014-05-01 16:03 - 00000000 ____D () C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive 2014-05-01 15:59 - 2014-05-01 15:59 - 00001342 _____ () C:\Users\Henry\Desktop\DayZ Commander.lnk 2014-05-01 12:13 - 2014-05-01 12:06 - 00002336 _____ () C:\Users\Henry\Desktop\Sicherer Zahlungsverkehr.lnk 2014-05-01 12:10 - 2014-05-01 12:05 - 00625248 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-05-01 12:10 - 2014-05-01 12:05 - 00115296 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-05-01 12:10 - 2013-10-17 15:47 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2014-05-01 12:10 - 2013-10-17 15:47 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2014-05-01 12:10 - 2013-06-06 17:38 - 00178272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2014-05-01 12:05 - 2014-05-01 12:05 - 00001130 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-05-01 12:05 - 2014-05-01 12:05 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-05-01 11:51 - 2014-05-01 11:51 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-01 11:44 - 2013-09-11 15:06 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-05-01 02:48 - 2014-05-01 00:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-05-01 02:48 - 2013-09-13 16:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-01 02:45 - 2014-05-01 02:45 - 00000969 _____ () C:\Users\Public\Desktop\Steam.lnk 2014-05-01 02:45 - 2014-05-01 02:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2014-05-01 02:44 - 2014-05-01 02:44 - 01141680 _____ () C:\Users\Henry\Downloads\SteamSetup.exe 2014-05-01 02:39 - 2014-05-01 02:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-29 16:29 - 2013-09-11 15:17 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-29 16:29 - 2013-09-11 15:17 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-29 16:29 - 2013-09-11 15:17 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-25 13:23 - 2013-10-18 22:13 - 00000000 ____D () C:\Users\Henry\AppData\Local\Spotify 2014-04-24 12:57 - 2014-04-24 12:57 - 00000000 ____D () C:\Users\Henry\AppData\Local\CrashRpt 2014-04-24 12:55 - 2013-09-14 09:54 - 00000000 ____D () C:\Users\Henry\Documents\My Games 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieUserList 2014-04-23 20:45 - 2014-04-23 20:45 - 00000000 __SHD () C:\Users\Henry\AppData\Local\EmieSiteList 2014-04-20 20:30 - 2014-04-20 20:30 - 00000000 ____D () C:\Users\Henry\Downloads\Smiley icons 2014-04-20 20:29 - 2014-04-20 20:29 - 00000000 ____D () C:\Users\Henry\Downloads\Dark orbit Icon pack 2014-04-20 20:28 - 2014-04-20 20:28 - 00000000 ____D () C:\Users\Henry\Downloads\NeonIcon_Pack_v1 2014-04-20 20:27 - 2014-04-20 20:27 - 00015880 _____ () C:\Users\Henry\Downloads\Icone_Pack_By_Clems.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00105079 _____ () C:\Users\Henry\Downloads\game-icon2.5.rar 2014-04-20 20:26 - 2014-04-20 20:26 - 00037810 _____ () C:\Users\Henry\Downloads\Puddel´s_Icon_Pack.rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo(1).rar 2014-04-20 20:25 - 2014-04-20 20:25 - 00000000 ____D () C:\Users\Henry\Downloads\25-TeamSpeak-Rank-Icons-v1.01 2014-04-20 20:23 - 2014-04-20 20:23 - 00000000 ____D () C:\Users\Henry\Neuer Ordner 2014-04-20 20:18 - 2014-04-20 20:18 - 00046867 _____ () C:\Users\Henry\Downloads\ico_by_Waflo.rar 2014-04-16 13:06 - 2013-12-03 14:47 - 00000000 ____D () C:\Windows\rescache 2014-04-16 12:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-14 04:24 - 2014-04-30 17:06 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-04-30 17:06 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-10 10:47 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-04-10 10:46 - 2013-09-13 19:48 - 00000000 ____D () C:\Users\Henry\AppData\Local\Adobe 2014-04-09 21:13 - 2013-09-13 19:48 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 21:13 - 2013-09-13 19:13 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-09 21:12 - 2013-09-13 19:48 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 15:07 - 2013-12-15 17:36 - 00000000 ____D () C:\Users\Henry\AppData\Local\NVIDIA Corporation 2014-04-08 15:07 - 2013-09-11 15:53 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-04-08 15:06 - 2013-09-11 15:53 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-04-06 01:16 - 2014-04-06 01:16 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer(1).exe 2014-04-06 01:14 - 2014-04-06 01:14 - 02103808 _____ (Alderon Games) C:\Users\Henry\Downloads\BP_Installer.exe 2014-04-05 09:55 - 2014-03-29 11:25 - 00000000 ____D () C:\Users\Henry\Documents\Nexus Mod Manager 2014-04-05 09:55 - 2013-09-14 13:00 - 00000000 ____D () C:\Users\Henry\AppData\Local\Skyrim 2014-04-04 18:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports Some content of TEMP: ==================== C:\Users\Henry\AppData\Local\Temp\avgnt.exe C:\Users\Henry\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe [2013-05-06 12:50] - [2013-05-06 12:50] - 0391680 ____A (Microsoft Corporation) 13CD6BA1F798A61AEE985E78D3644A1E C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2013-05-06 13:16] - [2013-05-06 13:16] - 2871296 ____A (Microsoft Corporation) 70D758D2DBE79757421017EE68143763 C:\Windows\SysWOW64\explorer.exe [2013-05-06 13:16] - [2013-05-06 13:16] - 2616320 ____A (Microsoft Corporation) B0846DB5BDAB92131529A58E627FCEB7 C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll [2013-05-06 12:37] - [2013-05-06 12:37] - 1008128 ____A (Microsoft Corporation) 7FB4D54B502C6CF2E35B8188FA4CC08C C:\Windows\SysWOW64\User32.dll [2013-05-06 12:37] - [2013-05-06 12:37] - 0833024 ____A (Microsoft Corporation) 9B836EE76E3A99052EF6DEA52B41D1BE C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-29 17:29 ==================== End Of Log ============================ --- --- --- --- --- --- Nein keine weiteren Probleme ! Hast du in meinen Dateien irgendwas gefunden? Danke für alles! |
05.05.2014, 16:39 | #8 |
/// the machine /// TB-Ausbilder | Avira Free zeig mir Viren an nach einem Steam update! Wir haben ja jede Menge Adware entfernt. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.05.2014, 18:22 | #9 |
| Avira Free zeig mir Viren an nach einem Steam update! Alles erledigt. Danke für alles |
06.05.2014, 11:30 | #10 |
/// the machine /// TB-Ausbilder | Avira Free zeig mir Viren an nach einem Steam update! Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Avira Free zeig mir Viren an nach einem Steam update! |
angeblich, angezeigt, avira, beendet, bekannter, deinstalliert, free, immer wieder, kaspersky, kleines, neuste, problem, security, steam, update, vermutung, viren, vollversion |