Windows 7: Spam-Mail geöffnet, bin ich infiziert? - Standard

Windows 7: Spam-Mail geöffnet, bin ich infiziert?


ich habe vor einer guten Woche eine Spam-Mail geöffnet in der es darum ging, mein E-Mail-Konto zu schützen. In der Mail befand sich ein Anhang im PDF-Format, den ich öffnete (ich muss dazu sagen, dass es kurz nach dem Aufstehen war und ich bisher nie von Google's Spamfilter enttäuscht wurde).
Als ich realisierte, dass es sich um eine Spam-Mail handelte, schloss ich den kompletten Browser kurzerhand, eine Virenmeldung seitens Kaspersky & Malwarebytes erhielt ich nicht, weswegen ich mir um eine Infizierung keine Gedanken machte.
Da ich aber seit einigen Tagen kleine Fehlerchen bemerkte (Skype's Sprache ändert sich von deutsch zu polnisch, PC wacht aus dem Stand-by-Modus auf), entschloss ich mich dazu das richtige Forum aufzusuchen.

Farbar Recovery Scan Tool (FRST):

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2014
Ran by Steve (administrator) on STEVE-PC on 25-06-2014 07:51:56
Running from C:\Users\Steve\Downloads
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Malwarebytes Corporation) H:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) H:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files (x86)\puush\puush.exe
(Spotify Ltd) C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Malwarebytes Corporation) H:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
() C:\Users\Steve\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Spotify Ltd) C:\Users\Steve\AppData\Roaming\Spotify\spotify.exe
(Dropbox, Inc.) C:\Users\Steve\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
() C:\Users\Steve\Desktop\Core Temp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2688920 2014-05-26] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3499896 2014-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058880 2013-03-28] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM-x32\...\Run: [RunOnStartup] => [X]
HKU\S-1-5-21-1896797916-3991622073-1759237652-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2014-06-15] ()
HKU\S-1-5-21-1896797916-3991622073-1759237652-1000\...\Run: [Spotify Web Helper] => C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-06-02] (Spotify Ltd)
HKU\S-1-5-21-1896797916-3991622073-1759237652-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21415040 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-1896797916-3991622073-1759237652-1000\...\Run: [Amazon Music] => C:\Users\Steve\AppData\Local\Amazon Music\Amazon Music Helper.exe [3162944 2014-06-05] ()
HKU\S-1-5-21-1896797916-3991622073-1759237652-1000\...\Run: [Spotify] => C:\Users\Steve\AppData\Roaming\Spotify\spotify.exe [6170168 2014-06-02] (Spotify Ltd)
Startup: C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Steve\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers:  AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers:  AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers:  AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.de
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-03-30]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址顧問 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-04-01]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: 虛擬鍵盤 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-04-01]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: 惡意網站攔截器 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-04-01]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Chặn quảng cáo - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-04-01]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-04-01]

CHR HomePage: hxxp://vimeo.com/72216778
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2014-06-23]
CHR Extension: (Google Docs) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-23]
CHR Extension: (Google Drive) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-23]
CHR Extension: (TV) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2014-06-23]
CHR Extension: (YouTube) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-23]
CHR Extension: (Adblock Plus) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-23]
CHR Extension: (Google-Suche) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-23]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-23]
CHR Extension: (Avira Browser Safety) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-06-23]
CHR Extension: (ProxMate) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifalmiidchkjjmkkbkoaibpmoeichmki [2014-06-23]
CHR Extension: (Google Wallet) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-23]
CHR Extension: (Deezer) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\npfkoakaabdallkcdbpkkhfilkkngakh [2014-06-23]
CHR Extension: (Google Mail) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-23]
CHR Extension: (Anti-Banner) - C:\Users\Steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-23]
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-06-23]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-05-08]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

==================== Services (Whitelisted) =================

R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 MBAMScheduler; H:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; H:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [621336 2013-12-04] (Wacom Technology, Corp.)

==================== Drivers (Whitelisted) ====================

S3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [29184 2009-08-13] (CSR, plc)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-04-01] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-04-01] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-04-01] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-04-01] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-04-01] (Kaspersky Lab ZAO)
R2 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [91352 2014-05-12] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2013-11-22] (Seiko Epson Corporation)
R3 ALSysIO; \??\C:\Users\Steve\AppData\Local\Temp\ALSysIO64.sys [X]
S3 cpuz135; \??\C:\Users\Steve\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
S3 SANDRA; \??\E:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP1c\WNt500x64\Sandra.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-06-25 07:50 - 2014-06-25 07:52 - 00022655 _____ () C:\Users\Steve\Downloads\FRST.txt
2014-06-25 07:49 - 2014-06-25 07:51 - 00000000 ____D () C:\FRST
2014-06-25 07:49 - 2014-06-25 07:49 - 02082816 _____ (Farbar) C:\Users\Steve\Downloads\FRST64.exe
2014-06-25 07:48 - 2014-06-25 07:48 - 00000472 _____ () C:\Users\Steve\Downloads\defogger_disable.log
2014-06-25 07:48 - 2014-06-25 07:48 - 00000000 _____ () C:\Users\Steve\defogger_reenable
2014-06-25 07:45 - 2014-06-25 07:45 - 00000000 ____D () C:\Users\Steve\AppData\Local\VirtualStore
2014-06-25 07:42 - 2014-06-25 07:42 - 00050477 _____ () C:\Users\Steve\Downloads\Defogger.exe
2014-06-25 07:41 - 2014-06-25 07:41 - 00000000 ____D () C:\Users\Steve\Downloads\Neuer Ordner
2014-06-25 07:19 - 2014-06-25 07:19 - 00010613 _____ () C:\Windows\SysWOW64\collectionCache.bnk
2014-06-23 16:04 - 2014-06-23 16:04 - 00001136 _____ () C:\Users\Steve\Desktop\Amazon Music.lnk
2014-06-23 16:03 - 2014-06-23 16:03 - 00001582 _____ () C:\Windows\System32\Tasks\Amazon Music Helper
2014-06-23 04:49 - 2014-06-23 04:49 - 00002004 _____ () C:\Users\Steve\Desktop\Kindle.lnk
2014-06-23 04:49 - 2014-06-23 04:49 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2014-06-23 02:50 - 2014-06-23 02:50 - 00003098 _____ () C:\Windows\System32\Tasks\{1573198C-E0B0-4005-B2F1-42583FD2B031}
2014-06-23 02:50 - 2014-06-23 02:50 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-23 02:50 - 2014-06-23 02:50 - 00002699 _____ () C:\ProgramData\Desktop\Skype.lnk
2014-06-23 02:50 - 2014-06-23 02:50 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-06-23 02:50 - 2014-06-23 02:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-23 00:05 - 2014-06-23 00:11 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-23 00:05 - 2014-06-23 00:11 - 00002181 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2014-06-23 00:05 - 2014-06-23 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-06-23 00:04 - 2014-06-25 07:45 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-23 00:04 - 2014-06-25 07:15 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-23 00:04 - 2014-06-23 05:10 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-23 00:04 - 2014-06-23 05:10 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-22 15:37 - 2014-06-22 15:37 - 00064552 _____ () C:\Users\Steve\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-22 15:36 - 2014-06-25 07:45 - 00001176 _____ () C:\Windows\setupact.log
2014-06-22 15:36 - 2014-06-24 13:29 - 00004510 _____ () C:\Windows\PFRO.log
2014-06-22 15:36 - 2014-06-22 15:36 - 04957040 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-22 15:36 - 2014-06-22 15:36 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-22 15:26 - 2014-06-22 15:26 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hopkins Programming
2014-06-22 15:26 - 2014-06-22 15:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hopkins Programming
2014-06-22 15:26 - 2014-06-22 15:26 - 00000000 ____D () C:\Program Files (x86)\Hopkins Programming
2014-06-21 10:46 - 2014-06-21 10:59 - 126172886 _____ () C:\Users\Steve\Downloads\480P_538k_28233831.mp4
2014-06-20 15:14 - 2014-06-22 15:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-19 10:43 - 2014-06-22 15:31 - 00000000 ____D () C:\Users\Steve\Documents\PCSX2
2014-06-19 10:43 - 2014-06-19 10:43 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-06-17 21:10 - 2014-06-17 23:15 - 00000109 _____ () C:\Users\Steve\Desktop\Neues Textdokument.txt
2014-06-17 12:17 - 2014-06-17 12:17 - 00000007 _____ () C:\Users\Steve\Desktop\Schlafzimmer.txt
2014-06-16 12:55 - 2014-06-16 12:56 - 00000121 _____ () C:\Users\Steve\Desktop\+.txt
2014-06-15 22:54 - 2014-06-15 22:57 - 00000000 ____D () C:\Program Files (x86)\puush
2014-06-15 22:54 - 2014-06-15 22:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
2014-06-15 16:28 - 2014-06-15 16:28 - 00001789 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-06-15 16:28 - 2014-06-15 16:28 - 00001789 _____ () C:\ProgramData\Desktop\iTunes.lnk
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\Program Files\iTunes
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\Program Files\iPod
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-15 16:28 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-06-14 22:30 - 2014-06-14 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-06-14 22:30 - 2014-06-14 22:30 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-06-14 22:30 - 2014-06-14 22:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-06-14 14:53 - 2014-06-14 14:53 - 00000000 ____D () C:\Users\Steve\Downloads\Songs_Work
2014-06-13 10:56 - 2014-06-13 10:56 - 00000288 _____ () C:\Users\Steve\Desktop\Amazon.de - Rücksendezentrum.url
2014-06-12 08:57 - 2014-06-12 08:57 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\03622F35.sys
2014-06-12 08:25 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 08:25 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-12 08:25 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 08:25 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 08:25 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 08:25 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 08:25 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 08:25 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 08:25 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 08:25 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-12 08:25 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-12 08:25 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-12 08:25 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-12 08:25 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-12 08:25 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-12 08:25 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-12 08:25 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-12 08:25 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 08:25 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-12 08:25 - 2014-05-08 11:32 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-12 08:25 - 2014-04-25 04:27 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 08:25 - 2014-04-25 03:58 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 08:25 - 2014-04-05 04:37 - 01897408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 08:25 - 2014-04-05 04:37 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-06-12 08:25 - 2014-04-05 04:37 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 08:25 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 08:25 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 08:25 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 08:25 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-12 08:25 - 2014-03-26 04:39 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 08:25 - 2014-03-26 04:36 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 08:25 - 2014-03-26 04:13 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 08:25 - 2014-03-26 04:10 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 09:38 - 2014-06-11 09:38 - 00000000 _____ () C:\Windows\SysWOW64\ꧣ鲁뷦꞉뗦ꒅ藦鲭跧낕跧ꮥ냦ꆉ藦뚁郣꺀胣鲑釧ꆱ뷦꒕闦뎽맦뚕釧꾉맢ꒅ
2014-06-11 09:36 - 2014-06-11 09:36 - 00098304 _____ () C:\Windows\SysWOW64\㩣灜潲牧浡慤慴歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯⹹慤
2014-06-10 15:49 - 2014-06-14 14:54 - 00000000 ____D () C:\Windows\Minidump
2014-06-06 18:42 - 2014-06-13 13:31 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\NVIDIA
2014-06-06 18:37 - 2014-06-06 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-06-06 18:37 - 2014-06-06 18:37 - 00000000 ____D () C:\Users\Steve\AppData\Local\NVIDIA
2014-06-06 18:37 - 2014-06-06 18:37 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-06-06 18:37 - 2013-12-10 04:15 - 00982232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-06-06 18:37 - 2013-12-10 04:14 - 01100248 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 18310112 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 15877216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 15230352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-06-06 18:36 - 2013-12-19 22:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 03071656 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 02698272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 01436528 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-06-06 18:36 - 2013-12-19 22:33 - 00023754 _____ () C:\Windows\system32\nvinfo.pb
2014-06-06 18:36 - 2013-12-19 20:53 - 06671648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-06-06 18:36 - 2013-12-19 20:53 - 03490080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-06-06 18:36 - 2013-12-19 20:53 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-06-06 18:36 - 2013-12-19 20:53 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-06-06 18:36 - 2013-12-19 20:53 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-06-06 18:36 - 2013-12-19 20:53 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-06-06 18:36 - 2013-12-19 07:01 - 03539040 _____ () C:\Windows\system32\nvcoproc.bin
2014-06-06 18:36 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-06-06 18:36 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-06-06 18:36 - 2013-11-22 10:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-06-06 18:35 - 2013-12-05 10:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-06-06 18:35 - 2013-12-05 10:42 - 00035104 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2014-06-06 18:35 - 2013-12-05 10:42 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-06-04 11:50 - 2014-06-21 20:53 - 00000000 ____D () C:\Users\Steve\Documents\FIFA 14
2014-06-04 09:13 - 2014-06-04 09:13 - 00001319 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-06-04 09:13 - 2014-06-04 09:13 - 00001307 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-06-04 09:13 - 2014-06-04 09:13 - 00001307 _____ () C:\ProgramData\Desktop\Adobe Creative Cloud.lnk
2014-06-03 05:07 - 2014-06-21 03:00 - 00001275 _____ () C:\Users\Steve\Desktop\CoreTemp.ini
2014-06-02 12:14 - 2014-06-23 00:05 - 00000000 ____D () C:\Users\Steve\AppData\Local\Google
2014-06-02 06:50 - 2014-06-23 19:42 - 00000000 ____D () C:\Users\Steve\AppData\Local\Spotify
2014-06-02 06:50 - 2014-06-02 06:50 - 00001813 _____ () C:\Users\Steve\Desktop\Spotify.lnk
2014-06-02 06:50 - 2014-06-02 06:50 - 00001799 _____ () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-06-01 20:22 - 2014-06-01 20:22 - 00000000 ____D () C:\Windows\system32\Keyboard
2014-06-01 20:18 - 2014-06-01 20:27 - 00000000 ____D () C:\Users\Steve\Documents\Assassin's Creed IV Black Flag
2014-06-01 18:49 - 2014-06-01 18:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2014-06-01 18:19 - 2014-06-14 14:49 - 00000000 ____D () C:\Users\Steve\AppData\Local\Ubisoft Game Launcher
2014-06-01 18:19 - 2014-06-01 18:19 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-05-31 14:25 - 2014-05-31 14:29 - 00000000 ____D () C:\Users\Steve\Downloads\SpongebobInMinecraft3_MayaSetup
2014-05-26 18:13 - 2014-05-26 18:13 - 00002219 _____ () C:\Users\Steve\Desktop\TweetDeck.lnk
2014-05-26 18:13 - 2014-05-26 18:13 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TweetDeck
2014-05-26 18:13 - 2014-05-26 18:13 - 00000000 ____D () C:\Program Files (x86)\Twitter

==================== One Month Modified Files and Folders =======

2014-06-25 07:52 - 2014-06-25 07:50 - 00022655 _____ () C:\Users\Steve\Downloads\FRST.txt
2014-06-25 07:51 - 2014-06-25 07:49 - 00000000 ____D () C:\FRST
2014-06-25 07:50 - 2014-05-24 08:52 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Spotify
2014-06-25 07:50 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-06-25 07:50 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-06-25 07:50 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-25 07:49 - 2014-06-25 07:49 - 02082816 _____ (Farbar) C:\Users\Steve\Downloads\FRST64.exe
2014-06-25 07:48 - 2014-06-25 07:48 - 00000472 _____ () C:\Users\Steve\Downloads\defogger_disable.log
2014-06-25 07:48 - 2014-06-25 07:48 - 00000000 _____ () C:\Users\Steve\defogger_reenable
2014-06-25 07:48 - 2014-03-30 08:48 - 02043939 _____ () C:\Windows\WindowsUpdate.log
2014-06-25 07:48 - 2014-03-30 08:48 - 00000000 ____D () C:\Users\Steve
2014-06-25 07:47 - 2014-03-30 09:21 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Skype
2014-06-25 07:46 - 2014-04-01 21:24 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-25 07:45 - 2014-06-25 07:45 - 00000000 ____D () C:\Users\Steve\AppData\Local\VirtualStore
2014-06-25 07:45 - 2014-06-23 00:04 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-25 07:45 - 2014-06-22 15:36 - 00001176 _____ () C:\Windows\setupact.log
2014-06-25 07:45 - 2014-05-23 19:26 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\DropboxMaster
2014-06-25 07:45 - 2014-05-23 19:25 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Dropbox
2014-06-25 07:45 - 2014-04-01 21:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-25 07:45 - 2014-03-30 08:58 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-25 07:45 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-25 07:44 - 2009-07-14 06:45 - 00022528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-25 07:44 - 2009-07-14 06:45 - 00022528 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-25 07:42 - 2014-06-25 07:42 - 00050477 _____ () C:\Users\Steve\Downloads\Defogger.exe
2014-06-25 07:41 - 2014-06-25 07:41 - 00000000 ____D () C:\Users\Steve\Downloads\Neuer Ordner
2014-06-25 07:26 - 2014-04-18 03:00 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-25 07:19 - 2014-06-25 07:19 - 00010613 _____ () C:\Windows\SysWOW64\collectionCache.bnk
2014-06-25 07:15 - 2014-06-23 00:04 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-25 07:08 - 2014-05-10 21:14 - 00000000 ____D () C:\Users\Steve\Downloads\Puush's
2014-06-25 07:08 - 2014-04-08 11:08 - 00000911 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Update {08DB0874-7CA0-4D07-892C-349954A5B59E}.job
2014-06-25 07:08 - 2014-04-08 11:08 - 00000725 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Invitation {08DB0874-7CA0-4D07-892C-349954A5B59E}.job
2014-06-25 07:08 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-06-25 03:33 - 2014-03-30 09:16 - 00000000 ____D () C:\Users\Steve\AppData\Local\Adobe
2014-06-24 13:29 - 2014-06-22 15:36 - 00004510 _____ () C:\Windows\PFRO.log
2014-06-23 20:16 - 2014-05-16 11:34 - 00000000 ____D () C:\Users\Steve\Documents\My Kindle Content
2014-06-23 19:42 - 2014-06-02 06:50 - 00000000 ____D () C:\Users\Steve\AppData\Local\Spotify
2014-06-23 16:04 - 2014-06-23 16:04 - 00001136 _____ () C:\Users\Steve\Desktop\Amazon Music.lnk
2014-06-23 16:03 - 2014-06-23 16:03 - 00001582 _____ () C:\Windows\System32\Tasks\Amazon Music Helper
2014-06-23 05:10 - 2014-06-23 00:04 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-23 05:10 - 2014-06-23 00:04 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-23 04:49 - 2014-06-23 04:49 - 00002004 _____ () C:\Users\Steve\Desktop\Kindle.lnk
2014-06-23 04:49 - 2014-06-23 04:49 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2014-06-23 04:49 - 2014-05-16 11:34 - 00000000 ____D () C:\Program Files (x86)\Amazon
2014-06-23 02:50 - 2014-06-23 02:50 - 00003098 _____ () C:\Windows\System32\Tasks\{1573198C-E0B0-4005-B2F1-42583FD2B031}
2014-06-23 02:50 - 2014-06-23 02:50 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-06-23 02:50 - 2014-06-23 02:50 - 00002699 _____ () C:\ProgramData\Desktop\Skype.lnk
2014-06-23 02:50 - 2014-06-23 02:50 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-06-23 02:50 - 2014-06-23 02:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-06-23 02:50 - 2014-03-30 09:21 - 00000000 ____D () C:\ProgramData\Skype
2014-06-23 00:11 - 2014-06-23 00:05 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-23 00:11 - 2014-06-23 00:05 - 00002181 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2014-06-23 00:05 - 2014-06-23 00:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-06-23 00:05 - 2014-06-02 12:14 - 00000000 ____D () C:\Users\Steve\AppData\Local\Google
2014-06-23 00:04 - 2014-03-30 08:52 - 00000000 ____D () C:\Program Files (x86)\Google
2014-06-22 15:37 - 2014-06-22 15:37 - 00064552 _____ () C:\Users\Steve\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-22 15:36 - 2014-06-22 15:36 - 04957040 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-22 15:36 - 2014-06-22 15:36 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-22 15:36 - 2014-06-20 15:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-22 15:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors
2014-06-22 15:31 - 2014-06-19 10:43 - 00000000 ____D () C:\Users\Steve\Documents\PCSX2
2014-06-22 15:26 - 2014-06-22 15:26 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hopkins Programming
2014-06-22 15:26 - 2014-06-22 15:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hopkins Programming
2014-06-22 15:26 - 2014-06-22 15:26 - 00000000 ____D () C:\Program Files (x86)\Hopkins Programming
2014-06-22 12:57 - 2014-03-30 11:18 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\vlc
2014-06-22 09:13 - 2014-04-07 19:32 - 00000000 ____D () C:\ProgramData\Origin
2014-06-22 09:13 - 2014-04-07 19:32 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-06-22 09:13 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-21 20:53 - 2014-06-04 11:50 - 00000000 ____D () C:\Users\Steve\Documents\FIFA 14
2014-06-21 10:59 - 2014-06-21 10:46 - 126172886 _____ () C:\Users\Steve\Downloads\480P_538k_28233831.mp4
2014-06-21 03:00 - 2014-06-03 05:07 - 00001275 _____ () C:\Users\Steve\Desktop\CoreTemp.ini
2014-06-19 10:43 - 2014-06-19 10:43 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-06-19 10:42 - 2014-03-30 09:36 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-17 23:15 - 2014-06-17 21:10 - 00000109 _____ () C:\Users\Steve\Desktop\Neues Textdokument.txt
2014-06-17 19:37 - 2014-04-09 16:58 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\.minecraft
2014-06-17 19:08 - 2014-04-04 22:40 - 00002002 ____H () C:\Users\Steve\Documents\Default.rdp
2014-06-17 12:17 - 2014-06-17 12:17 - 00000007 _____ () C:\Users\Steve\Desktop\Schlafzimmer.txt
2014-06-16 12:56 - 2014-06-16 12:55 - 00000121 _____ () C:\Users\Steve\Desktop\+.txt
2014-06-15 22:57 - 2014-06-15 22:54 - 00000000 ____D () C:\Program Files (x86)\puush
2014-06-15 22:54 - 2014-06-15 22:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
2014-06-15 16:28 - 2014-06-15 16:28 - 00001789 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-06-15 16:28 - 2014-06-15 16:28 - 00001789 _____ () C:\ProgramData\Desktop\iTunes.lnk
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\Program Files\iTunes
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\Program Files\iPod
2014-06-15 16:28 - 2014-06-15 16:28 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-14 22:30 - 2014-06-14 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-06-14 22:30 - 2014-06-14 22:30 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-06-14 22:30 - 2014-06-14 22:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-06-14 14:54 - 2014-06-10 15:49 - 00000000 ____D () C:\Windows\Minidump
2014-06-14 14:54 - 2014-03-30 09:42 - 00000000 ____D () C:\Windows\Panther
2014-06-14 14:53 - 2014-06-14 14:53 - 00000000 ____D () C:\Users\Steve\Downloads\Songs_Work
2014-06-14 14:49 - 2014-06-01 18:19 - 00000000 ____D () C:\Users\Steve\AppData\Local\Ubisoft Game Launcher
2014-06-13 13:31 - 2014-06-06 18:42 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\NVIDIA
2014-06-13 10:56 - 2014-06-13 10:56 - 00000288 _____ () C:\Users\Steve\Desktop\Amazon.de - Rücksendezentrum.url
2014-06-13 02:45 - 2014-05-06 11:21 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 20:45 - 2014-03-30 20:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 20:44 - 2014-03-30 20:50 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 08:57 - 2014-06-12 08:57 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\03622F35.sys
2014-06-11 16:04 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-06-11 09:38 - 2014-06-11 09:38 - 00000000 _____ () C:\Windows\SysWOW64\ꧣ鲁뷦꞉뗦ꒅ藦鲭跧낕跧ꮥ냦ꆉ藦뚁郣꺀胣鲑釧ꆱ뷦꒕闦뎽맦뚕釧꾉맢ꒅ
2014-06-11 09:36 - 2014-06-11 09:36 - 00098304 _____ () C:\Windows\SysWOW64\㩣灜潲牧浡慤慴歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯⹹慤
2014-06-11 07:34 - 2014-03-30 10:25 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\WTablet
2014-06-08 11:13 - 2014-06-12 08:25 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 08:25 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-06 18:40 - 2014-06-06 18:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-06-06 18:38 - 2014-03-30 09:17 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-06-06 18:37 - 2014-06-06 18:37 - 00000000 ____D () C:\Users\Steve\AppData\Local\NVIDIA
2014-06-06 18:37 - 2014-06-06 18:37 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-06-06 18:37 - 2014-03-30 09:17 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-06-06 18:37 - 2014-03-30 09:13 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-06-06 18:36 - 2014-04-01 18:08 - 00000000 ____D () C:\temp
2014-06-06 18:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help
2014-06-06 18:31 - 2014-03-30 09:19 - 00000000 ____D () C:\Users\Steve\AppData\Local\NVIDIA Corporation
2014-06-04 09:13 - 2014-06-04 09:13 - 00001319 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-06-04 09:13 - 2014-06-04 09:13 - 00001307 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-06-04 09:13 - 2014-06-04 09:13 - 00001307 _____ () C:\ProgramData\Desktop\Adobe Creative Cloud.lnk
2014-06-04 09:13 - 2014-03-30 09:36 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-06-03 15:37 - 2014-04-07 16:11 - 00000193 _____ () C:\Windows\WORDPAD.INI
2014-06-02 06:50 - 2014-06-02 06:50 - 00001813 _____ () C:\Users\Steve\Desktop\Spotify.lnk
2014-06-02 06:50 - 2014-06-02 06:50 - 00001799 _____ () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-06-02 06:40 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-01 20:27 - 2014-06-01 20:18 - 00000000 ____D () C:\Users\Steve\Documents\Assassin's Creed IV Black Flag
2014-06-01 20:22 - 2014-06-01 20:22 - 00000000 ____D () C:\Windows\system32\Keyboard
2014-06-01 18:49 - 2014-06-01 18:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_xusb21_01009.Wdf
2014-06-01 18:25 - 2014-04-07 19:41 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-06-01 18:19 - 2014-06-01 18:19 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-05-31 14:29 - 2014-05-31 14:25 - 00000000 ____D () C:\Users\Steve\Downloads\SpongebobInMinecraft3_MayaSetup
2014-05-31 13:02 - 2014-04-01 21:24 - 00000791 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-31 13:02 - 2014-04-01 21:24 - 00000791 _____ () C:\ProgramData\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-31 13:02 - 2014-04-01 21:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-30 16:27 - 2014-04-16 20:45 - 00000132 _____ () C:\Users\Steve\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen
2014-05-26 18:13 - 2014-05-26 18:13 - 00002219 _____ () C:\Users\Steve\Desktop\TweetDeck.lnk
2014-05-26 18:13 - 2014-05-26 18:13 - 00000000 ____D () C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TweetDeck
2014-05-26 18:13 - 2014-05-26 18:13 - 00000000 ____D () C:\Program Files (x86)\Twitter

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-06-18 13:48

==================== End Of Log ============================

Farbar Recovery Scan Tool (Addition):

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2014
Ran by Steve at 2014-06-25 07:52:13
Running from C:\Users\Steve\Downloads
Boot Mode: Normal

==================== Security Center ========================

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

Adobe Acrobat XI Pro (HKLM-x32\...\{23D3F585-AE29-4670-8E3E-64A0EFB29240}) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.07 - Adobe Systems)
Adobe After Effects CC (HKLM-x32\...\{317243C1-6580-4F43-AED7-37D4438C3DD5}) (Version: 12.2.1 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: - Adobe Systems Incorporated)
Adobe AIR (x32 Version: - Adobe Systems Incorporated) Hidden
Adobe Audition CC (HKLM-x32\...\{DE1E055B-679C-42F8-B114-7B6ED0B8ED95}) (Version: 6.0 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CC (HKLM-x32\...\{505FF1AC-E7F5-4462-BBA7-08900E7E9EEF}) (Version: 7.2.2 - Adobe Systems Incorporated)
Amazon Kindle (HKLM-x32\...\Amazon Kindle) (Version:  - Amazon)
Amazon Music (HKCU\...\Amazon Amazon Music) (Version: - Amazon Services LLC)
Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.)
Autodesk Backburner 2014 (HKLM-x32\...\{3D347E6D-5A03-4342-B5BA-6A771885F379}) (Version: - Autodesk, Inc.)
Autodesk Composite 2014 (HKLM\...\Autodesk Composite 2014) (Version: - Autodesk)
Autodesk Composite 2014 (Version: - Autodesk) Hidden
Autodesk DirectConnect 2014 64-bit (HKLM\...\Autodesk DirectConnect 2014 64-bit) (Version: - Autodesk)
Autodesk DirectConnect 2014 64-bit (Version: - Autodesk) Hidden
Autodesk MatchMover 2014 (HKLM\...\{B151ECD3-2DBE-45E9-816E-F8AA6238F6A8}) (Version: 14.00.0000 - Autodesk)
Autodesk Maya 2014 (HKLM\...\Autodesk Maya 2014) (Version: - Autodesk)
Autodesk Maya 2014 (Version: - Autodesk) Hidden
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
CrystalDiskInfo 6.1.9a (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.1.9a - Crystal Dew World)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
Dropbox Folder Sync addon (HKLM-x32\...\{E0B7CA7A-98B0-4EF1-87F5-FF6B02DC06A9}_is1) (Version: 2.7 - Sowrabh & Satyadeep)
Epson Event Manager (HKLM-x32\...\{2970697F-2A11-4588-8B7F-97322D1CCF3C}) (Version: 3.10.0017 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON XP-215 217 Series Printer Uninstall (HKLM\...\EPSON XP-215 217 Series) (Version:  - SEIKO EPSON Corporation)
EpsonNet Config V4 (HKLM-x32\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.4.4 - SEIKO EPSON CORPORATION)
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Update Helper (x32 Version: - Google Inc.) Hidden
iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: - Apple Inc.)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: - Oracle, Inc.) Hidden
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: - Kaspersky Lab) Hidden
K-Lite Mega Codec Pack 10.4.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.4.0 - )
Malwarebytes Anti-Malware Version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
mental ray renderer for Autodesk Maya 2014 (HKLM\...\{8057481C-0CFC-43BB-8EEC-C6A0E1C82E19}) (Version: - mental ray)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Expression Encoder 4 (HKLM-x32\...\Encoder_4.0.4276.0) (Version: 4.0.4276.0 - Microsoft Corporation)
Microsoft Expression Encoder 4 (x32 Version: 4.0.4276.0 - Microsoft Corporation) Hidden
Microsoft Expression Encoder 4 Screen Capture Codec (HKLM-x32\...\{E5AB3F65-7FAC-41C6-B176-7599D2404BB2}) (Version: 4.0.4276.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (Version: - Microsoft Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 332.21 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 332.21 - NVIDIA Corporation)
NVIDIA GeForce Experience 1.8.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.1 - NVIDIA Corporation)
NVIDIA Grafiktreiber 332.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.21 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA ShadowPlay 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden
NVIDIA Update 10.11.15 (Version: 10.11.15 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 10.11.15 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.19 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.19 - NVIDIA Corporation)
Offline Player (HKLM-x32\...\com.digitaltutors.OfflinePlayer) (Version: 0.0.18 - Digital-Tutors)
Offline Player (x32 Version: 0.0.18 - Digital-Tutors) Hidden
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: - Dean Herbert)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: - Renesas Electronics Corporation) Hidden
SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) Hidden
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Software Updater (HKLM-x32\...\{C09D747A-BD47-42A9-915E-CEB6B1BB7C11}) (Version: 4.2.7 - SEIKO EPSON CORPORATION)
Spotify (HKCU\...\Spotify) (Version: - Spotify AB)
SquidNet Render Manager (HKLM-x32\...\SquidNet) (Version: 2.39P1 - SqduidNet Software)
TweetDeck (HKLM-x32\...\{C4ADB67B-C908-4D94-B85E-585D2F3F9118}) (Version: 3.3.7 - Twitter)
VB Doodle (Remove Only) (HKLM-x32\...\VB Doodle) (Version:  - )
VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN)
Wacom Tablett (HKLM\...\Wacom Tablet Driver) (Version: 6.3.7-6 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: - Wacom Technology Corp.)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Restore Points  =========================

15-06-2014 14:28:09 Installed iTunes
15-06-2014 20:53:52 Installed puush
17-06-2014 06:53:46 Windows Update
19-06-2014 08:42:40 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
20-06-2014 08:35:56 Windows Update
22-06-2014 13:13:09 Removed Skype™ 6.16
24-06-2014 09:32:06 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {14B98623-B9A3-4DCB-8E41-8DC5EF2B5EFB} - System32\Tasks\EPSON XP-215 217 Series Update {08DB0874-7CA0-4D07-892C-349954A5B59E} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLGE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {1F10AD6A-52A4-45D8-8C9B-D2A1FA50410D} - System32\Tasks\Core Temp Autostart Steve => C:\Users\Steve\Desktop\Core Temp.exe [2013-10-08] ()
Task: {27BA3907-4CCA-43EB-B0B1-E435C2FE8BE9} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {2A092E16-0564-4E63-8A78-7963EBC57746} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {31C57B49-5BC2-4032-A3E3-6B10A2DC4FB6} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {49740F09-D466-4CDE-8725-2F9D1196B642} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {52CF6C7E-7988-4A4B-BFF8-6FD87126F384} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-23] (Google Inc.)
Task: {593686A6-0DBE-4AC1-8BDD-2BB996962D30} - System32\Tasks\Amazon Music Helper => C:\Users\Steve\AppData\Local\Amazon Music\Amazon Music Helper.exe [2014-06-05] ()
Task: {7931962A-75B3-4FDB-90E1-F33B34B42350} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {816A73D2-E59E-4262-834B-B3CAA545D7D5} - System32\Tasks\EPSON XP-215 217 Series Invitation {08DB0874-7CA0-4D07-892C-349954A5B59E} => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLGE.EXE [2013-02-28] (SEIKO EPSON CORPORATION)
Task: {9A5B752F-A54C-46CF-B1A5-80F94750354A} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {A67C51EE-6B6B-4E5B-B78A-E26EBBE0A7A8} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {B5AB0908-E614-410E-9990-3AC900EA9EE6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-23] (Google Inc.)
Task: {BC762670-C753-476A-A9F6-071C83B1597C} - System32\Tasks\{1573198C-E0B0-4005-B2F1-42583FD2B031} => Chrome.exe hxxp://ui.skype.com/ui/0/
Task: {C4CEE9FE-0C05-4221-97A7-48248258927A} - System32\Tasks\AdobeAAMUpdater-1.0-Steve-PC-Steve => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated)
Task: {F3D9FE47-C280-4BBB-AAF9-F684DE1E953D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {FD312ECF-E521-4EF7-9860-2C078893CC22} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-29] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\EPSON XP-215 217 Series Invitation {08DB0874-7CA0-4D07-892C-349954A5B59E}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLGE.EXE
Task: C:\Windows\Tasks\EPSON XP-215 217 Series Update {08DB0874-7CA0-4D07-892C-349954A5B59E}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_ITSLGE.EXE
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-06-06 18:36 - 2013-12-19 20:53 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-05-23 02:10 - 2014-05-23 02:10 - 00671904 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
2014-04-14 08:34 - 2014-04-14 08:34 - 00012520 _____ () C:\Users\Steve\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\CoreTempReader.dll
2014-04-14 08:34 - 2014-04-14 08:34 - 00015080 _____ () C:\Users\Steve\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\GetCoreTempInfoNET.dll
2014-04-14 08:34 - 2014-04-14 08:34 - 00014056 _____ () C:\Users\Steve\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V4.7.3.gadget\SystemInfo.dll
2012-01-10 14:41 - 2014-06-15 22:57 - 00567880 _____ () C:\Program Files (x86)\puush\puush.exe
2014-03-30 09:27 - 2013-12-04 18:35 - 01185048 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2014-06-23 16:03 - 2014-06-05 00:18 - 03162944 _____ () C:\Users\Steve\AppData\Local\Amazon Music\Amazon Music Helper.exe
2014-06-02 06:50 - 2014-06-02 06:50 - 00598072 _____ () C:\Users\Steve\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
2014-05-23 02:10 - 2014-05-23 02:10 - 05341856 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2014-04-14 08:33 - 2013-10-08 13:23 - 00890016 _____ () C:\Users\Steve\Desktop\Core Temp.exe
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll
2014-06-02 06:50 - 2014-06-02 06:50 - 36966968 _____ () C:\Users\Steve\AppData\Roaming\Spotify\Data\libcef.dll
2014-06-25 07:45 - 2014-06-25 07:45 - 00043008 _____ () c:\users\steve\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmphxqqlr.dll
2014-05-23 19:25 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Steve\AppData\Roaming\Dropbox\bin\libcef.dll
2014-05-26 05:52 - 2014-05-26 05:52 - 32733088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
2012-09-23 20:43 - 2012-09-23 20:43 - 00010240 _____ () C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\locale\de_de\acrotray.deu
2014-06-02 06:50 - 2014-06-02 06:50 - 00886840 _____ () C:\Users\Steve\AppData\Roaming\Spotify\Data\libglesv2.dll
2014-06-02 06:50 - 2014-06-02 06:50 - 00108600 _____ () C:\Users\Steve\AppData\Roaming\Spotify\Data\libegl.dll
2014-05-12 22:22 - 2014-05-12 22:22 - 02217128 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\plugins\ExchangePlugin\ExManCoreLib\ExManZxpSign.dll
2014-06-23 00:11 - 2014-06-05 15:58 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libglesv2.dll
2014-06-23 00:11 - 2014-06-05 15:58 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libegl.dll
2014-06-23 00:11 - 2014-06-05 15:58 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll
2014-06-23 00:11 - 2014-06-05 15:58 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll
2014-06-23 00:11 - 2014-06-05 15:58 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

==================== Safe Mode (whitelisted) ===================

==================== EXE Association (whitelisted) =============

==================== MSCONFIG/TASK MANAGER disabled items =========

MSCONFIG\startupreg: EADM => "E:\Program Files (x86)\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: EPLTarget => 
MSCONFIG\startupreg: iTunesHelper => "E:\Program Files (x86)\iTunes\iTunesHelper.exe"

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (06/25/2014 07:45:43 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/24/2014 10:04:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8002

Error: (06/24/2014 10:04:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8002

Error: (06/24/2014 10:04:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/24/2014 10:04:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7004

Error: (06/24/2014 10:04:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7004

Error: (06/24/2014 10:04:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/24/2014 10:04:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6006

Error: (06/24/2014 10:04:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6006

Error: (06/24/2014 10:04:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

System errors:
Error: (06/24/2014 04:10:04 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk3\DR3 gefunden.

Error: (06/24/2014 01:28:18 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (06/24/2014 10:47:30 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.

Error: (06/22/2014 03:37:37 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: 

Error: (06/22/2014 03:37:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (06/22/2014 03:37:07 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535.

Microsoft Office Sessions:
Error: (06/25/2014 07:45:43 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/24/2014 10:04:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8002

Error: (06/24/2014 10:04:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8002

Error: (06/24/2014 10:04:20 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/24/2014 10:04:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7004

Error: (06/24/2014 10:04:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7004

Error: (06/24/2014 10:04:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/24/2014 10:04:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6006

Error: (06/24/2014 10:04:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6006

Error: (06/24/2014 10:04:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

CodeIntegrity Errors:
  Date: 2014-06-24 11:36:39.604
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.602
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.601
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.591
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.590
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.589
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.583
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.582
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-24 11:36:39.580
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-23 06:16:11.282
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

==================== Memory info =========================== 

Percentage of memory in use: 20%
Total physical RAM: 16367.3 MB
Available physical RAM: 12984.06 MB
Total Pagefile: 32732.8 MB
Available Pagefile: 28619.56 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (System) (Fixed) (Total:111.69 GB) (Free:12.88 GB) NTFS
Drive d: () (Removable) (Total:7.27 GB) (Free:1.1 GB) NTFS
Drive e: (Projects) (Fixed) (Total:465.66 GB) (Free:352.68 GB) NTFS
Drive g: (BackUp) (Fixed) (Total:931.51 GB) (Free:300.09 GB) NTFS
Drive h: (Multimedia) (Fixed) (Total:931.51 GB) (Free:756.93 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 1A7DE13C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: CEBA4D16)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

Disk: 2 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 4E6CF811)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)

Disk: 3 (Size: 932 GB) (Disk ID: 31061F2C)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)

Disk: 4 (MBR Code: Windows 7 or 8) (Size: 7 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End Of Log ============================


GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-06-25 07:59:33
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T1L0-9 Samsung_SSD_840_EVO_120GB rev.EXT0BB6Q 111,79GB
Running: Gmer-19357.exe; Driver: C:\Users\Steve\AppData\Local\Temp\uwtoypob.sys

---- User code sections - GMER 2.1 ----

.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5                                   00000000778210c5 8 bytes {JMP 0xd}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 380                                 000000007782123c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159                        00000000778212ef 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492                        000000007782143c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126                                00000000778217ce 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636                                00000000778219cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204                               0000000077821aa0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373                  0000000077821c25 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691                  0000000077821d63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31                                      0000000077821d8f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84                                     0000000077821e14 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81                                    0000000077821e6d 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7                            0000000077821e87 8 bytes {JMP 0xb}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 672                        0000000077822130 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 523             000000007782254b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16                    0000000077822570 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18                  0000000077822592 8 bytes {JMP 0x10}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79   00000000778225ef 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176  0000000077822650 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  ...                                                                                                                           * 2
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299          0000000077822a7b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367          0000000077822abf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  ...                                                                                                                           * 3
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483                  0000000077822d83 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523                      0000000077822f9b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912                      0000000077823120 16 bytes {JMP 0x4e}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318                                     00000000778237be 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403                                     0000000077823813 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197         00000000778238e5 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611         0000000077823a83 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80                  0000000077823e90 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread                            0000000077870680 8 bytes {JMP QWORD [RIP-0x4ca6f]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread                          0000000077870800 8 bytes {JMP QWORD [RIP-0x4ca99]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection                                0000000077870830 8 bytes {JMP QWORD [RIP-0x4cf51]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                              0000000077870950 8 bytes {JMP QWORD [RIP-0x4cd47]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread                                  0000000077870a00 8 bytes {JMP QWORD [RIP-0x4cf83]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                  0000000077871030 8 bytes {JMP QWORD [RIP-0x4d1a6]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread                                0000000077871280 8 bytes {JMP QWORD [RIP-0x4d455]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                0000000077871ae0 8 bytes {JMP QWORD [RIP-0x4dd71]}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312              00000000753513cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471              000000007535146b 8 bytes {JMP 0xffffffffffffffb0}
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611                           00000000753516d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3                             00000000753516e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23                        00000000753519db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23                        00000000753519fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23                  0000000075351a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3                    0000000075351a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23                  0000000075351a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Steve\Downloads\Gmer-19357.exe[4712] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3                       0000000075351a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001a7dda710f                                                   
Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001a7dda710f@445ef3a3131d                                      0x66 0xB5 0xCC 0x15 ...
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001a7dda710f (not active ControlSet)                               
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001a7dda710f@445ef3a3131d                                          0x66 0xB5 0xCC 0x15 ...

---- EOF - GMER 2.1 ----

Bin ich infiziert? Wenn ja wie sehr? Was kann ich gegebenenfalls tun?

Danke für Ihre Hilfe!
- Steve

 Malwarebytes Anti-Malware 

Update, 25.06.2014 03:23:13, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.24.12, 2014.6.24.14, 
Protection, 25.06.2014 03:23:14, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 25.06.2014 03:23:14, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 25.06.2014 03:23:14, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 25.06.2014 03:23:17, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 25.06.2014 03:23:17, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 25.06.2014 03:23:17, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Update, 25.06.2014 04:26:10, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.24.14, 2014.6.25.1, 
Protection, 25.06.2014 04:26:10, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 25.06.2014 04:26:10, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 25.06.2014 04:26:10, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 25.06.2014 04:26:13, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 25.06.2014 04:26:13, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 25.06.2014 04:26:13, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Update, 25.06.2014 06:30:32, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.25.1, 2014.6.25.2, 
Protection, 25.06.2014 06:30:32, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 25.06.2014 06:30:32, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 25.06.2014 06:30:32, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 25.06.2014 06:30:35, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 25.06.2014 06:30:36, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 25.06.2014 06:30:36, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Protection, 25.06.2014 07:45:42, SYSTEM, STEVE-PC, Protection, Malware Protection, Starting, 
Protection, 25.06.2014 07:45:42, SYSTEM, STEVE-PC, Protection, Malware Protection, Started, 
Protection, 25.06.2014 07:45:42, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 25.06.2014 07:45:42, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Update, 25.06.2014 07:46:04, SYSTEM, STEVE-PC, Manual, Malware Database, 2014.6.25.2, 2014.6.25.3, 
Protection, 25.06.2014 07:46:04, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 25.06.2014 07:46:04, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 25.06.2014 07:46:04, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 25.06.2014 07:46:07, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 25.06.2014 07:46:07, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 25.06.2014 07:46:07, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Protection, 25.06.2014 07:54:22, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 25.06.2014 07:54:22, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 25.06.2014 07:54:22, SYSTEM, STEVE-PC, Protection, Malware Protection, Stopping, 
Protection, 25.06.2014 07:54:23, SYSTEM, STEVE-PC, Protection, Malware Protection, Stopped, 
Protection, 25.06.2014 08:00:51, SYSTEM, STEVE-PC, Protection, Malware Protection, Starting, 
Protection, 25.06.2014 08:00:51, SYSTEM, STEVE-PC, Protection, Malware Protection, Started, 
Protection, 25.06.2014 08:00:51, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 25.06.2014 08:00:52, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Protection, 25.06.2014 08:03:18, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 25.06.2014 08:03:18, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 25.06.2014 08:03:18, SYSTEM, STEVE-PC, Protection, Malware Protection, Stopping, 
Protection, 25.06.2014 08:03:18, SYSTEM, STEVE-PC, Protection, Malware Protection, Stopped, 
Protection, 25.06.2014 08:03:41, SYSTEM, STEVE-PC, Protection, Malware Protection, Starting, 
Protection, 25.06.2014 08:03:41, SYSTEM, STEVE-PC, Protection, Malware Protection, Started, 
Protection, 25.06.2014 08:03:42, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 25.06.2014 08:03:42, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 


 Malwarebytes Anti-Malware 

Suchlauf Datum: 25.06.2014
Suchlauf-Zeit: 07:46:05
Administrator: Ja

Malware Datenbank: v2014.06.25.03
Rootkit Datenbank: v2014.06.23.02
Lizenz: Premium
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Aktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Steve

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgebrochen
Durchsuchte Objekte: 89796
Verstrichene Zeit: 1 Min, 49 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 0
(No malicious items detected)

Physische Sektoren: 0
(No malicious items detected)


 Malwarebytes Anti-Malware 

Update, 24.06.2014 11:54:25, SYSTEM, STEVE-PC, Scheduler, Rootkit Database, 2014.6.20.1, 2014.6.23.2, 
Update, 24.06.2014 11:54:29, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.23.12, 2014.6.24.3, 
Protection, 24.06.2014 11:54:29, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 24.06.2014 11:54:29, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 24.06.2014 11:54:29, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 24.06.2014 11:54:32, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 24.06.2014 11:54:32, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 24.06.2014 11:54:32, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Update, 24.06.2014 12:40:22, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.24.3, 2014.6.24.4, 
Protection, 24.06.2014 12:40:22, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 24.06.2014 12:40:22, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 24.06.2014 12:40:22, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 24.06.2014 12:40:25, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 24.06.2014 12:40:25, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 24.06.2014 12:40:25, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Protection, 24.06.2014 13:30:00, SYSTEM, STEVE-PC, Protection, Malware Protection, Starting, 
Protection, 24.06.2014 13:30:00, SYSTEM, STEVE-PC, Protection, Malware Protection, Started, 
Protection, 24.06.2014 13:30:00, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 24.06.2014 13:30:10, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Update, 24.06.2014 13:38:55, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.24.4, 2014.6.24.7, 
Protection, 24.06.2014 13:38:55, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 24.06.2014 13:38:55, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 24.06.2014 13:38:55, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 24.06.2014 13:38:58, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 24.06.2014 13:38:58, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 24.06.2014 13:38:58, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Update, 24.06.2014 15:46:30, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.24.7, 2014.6.24.8, 
Protection, 24.06.2014 15:46:30, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 24.06.2014 15:46:30, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 24.06.2014 15:46:30, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 24.06.2014 15:46:33, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 24.06.2014 15:46:33, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Protection, 24.06.2014 15:46:33, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Started, 
Update, 24.06.2014 16:57:26, SYSTEM, STEVE-PC, Scheduler, Malware Database, 2014.6.24.8, 2014.6.24.10, 
Protection, 24.06.2014 16:57:26, SYSTEM, STEVE-PC, Protection, Refresh, Starting, 
Protection, 24.06.2014 16:57:26, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopping, 
Protection, 24.06.2014 16:57:26, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Stopped, 
Protection, 24.06.2014 16:57:29, SYSTEM, STEVE-PC, Protection, Refresh, Success, 
Protection, 24.06.2014 16:57:29, SYSTEM, STEVE-PC, Protection, Malicious Website Protection, Starting, 
Ich bitte die schlüpfrigen Internetseiten zu entschuldigen, das muss mein Neffe gewesen sein!

Windows 7: Spam-Mail geöffnet, bin ich infiziert?

Ist das ein gewerblich genutztes System? Ich seh da neben dem Windows 7 Ultimate nämlich auch teure Software von Adobe und Autodesk.
Windows 7: Spam-Mail geöffnet, bin ich infiziert? - Standard

Windows 7: Spam-Mail geöffnet, bin ich infiziert?

Nein, das ist ein privater Computer.

Windows 7: Spam-Mail geöffnet, bin ich infiziert?

Dann bitte kurz erklären woher die "Profisoftware" stammt...
Windows 7: Spam-Mail geöffnet, bin ich infiziert? - Standard

Windows 7: Spam-Mail geöffnet, bin ich infiziert?

Ich bin selbständig und arbeite tagsüber im Büro. Der oben aufgezeigte Computer dient lediglich der Freizeit (zeichnen, Musik etc.).
Ich habe Programme wie After Effects & Photoshop nur installiert, um in erster Linie zu zeichnen und um im Notfall (Erkrankung, Unwetter) eine Alternative zur Verfügung zu haben, ohne mich völlig ausgelaugt zum Büro schleppen zu müssen oder gegebenenfalls einen Tornado überwinden zu müssen.

Windows 7: Spam-Mail geöffnet, bin ich infiziert?

Ok, das erklärt es. Software im Wert von Tausenden von Euros rein privat zur Spieleri kauft sich nämlich niemand.

Die Spam-Mail um die es geht, war das tatsächlich eine PDF als Anhang, oder eine als PDF getarnt ausführbare Datei, also sowas wie zB rechnung.pdf.exe? Dein Windows zeigt dir auch alle Dateiendungen an und unterdrückt sie nicht?
Windows 7: Spam-Mail geöffnet, bin ich infiziert? - Standard

Windows 7: Spam-Mail geöffnet, bin ich infiziert?

Es war eine reine PDF, sie wurde auch direkt im Browser geöffnet und nicht heruntergeladen. Die Option, Dateiendungen auszublenden, habe ich deaktiviert.

Windows 7: Spam-Mail geöffnet, bin ich infiziert?

Es war eine reine PDF, sie wurde auch direkt im Browser geöffnet und nicht heruntergeladen.
Bei einer reinen PDF sollte eigentlich nichts passieren.

Adware/Junkware/Toolbars entfernen

1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

