![]() |
|
Log-Analyse und Auswertung: Windows 8 Trojaner Zbot.gen gefunden in C:\Users\*****\Appdata\Roaming\Cuyfzy\piutfas.exeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 | ||||
| ![]() Windows 8 Trojaner Zbot.gen gefunden in C:\Users\*****\Appdata\Roaming\Cuyfzy\piutfas.exe Ich habe den oben genannten und weitere Viren mithilfe von 'Windows Defender' und 'Malewarebytes Anti-Maleware' auf meinem Pc gefunden. Es öffnen sich mehrere Java Downloads, die aber nicht ausgeführt werden können weil ich Java Downloads deaktiviert habe. Ich habe bereits versucht, die Viren alleinständig zu entfernen aber bisher ohne Erfolg bei dem Trojaner Zbot.gen. Ich habe hier ebenfalls die Logfiles vom Virusscan notiert, da ich nicht weiß wie man die Logfiles der einzelnen Viren mit dem Programm aufschreibt. defogger: Zitat:
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2014 01 Ran by Kilian (administrator) on KILIAN-IPOD on 18-08-2014 10:59:13 Running from C:\Users\Kilian\Desktop Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Emsi Software GmbH) C:\Program Files (x86)\a-squared Free\a2service.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe () C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Emsi Software GmbH) C:\Program Files (x86)\a-squared Free\a2free.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Windows\WinStore\WSHost.exe () C:\League of Legends\RADS\system\rads_user_kernel.exe () C:\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.215\deploy\LoLLauncher.exe () C:\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.104\deploy\LolClient.exe (Opera Software) C:\Program Files (x86)\Opera\23.0.1522.75\opera.exe () C:\Program Files (x86)\Opera\23.0.1522.75\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\23.0.1522.75\opera.exe (Opera Software) C:\Program Files (x86)\Opera\23.0.1522.75\opera.exe (Opera Software) C:\Program Files (x86)\Opera\23.0.1522.75\opera.exe (Opera Software) C:\Program Files (x86)\Opera\23.0.1522.75\opera.exe (Meskisift Corporatien) C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe (Meskisift Corporatien) C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe (Opera Software) C:\Program Files (x86)\Opera\23.0.1522.75\opera.exe (Meskisift Corporatien) C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe (Opera Software) C:\Program Files (x86)\Opera\23.0.1522.75\opera.exe (Meskisift Corporatien) C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe (Farbar) C:\Users\Kilian\Desktop\FRST64 (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s RtHDVCpl C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s kernel32.dll HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor) HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [79376 2013-04-22] (Intel Corporation) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2014-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4243868721-543226389-1580479791-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-4243868721-543226389-1580479791-1002\...\Run: [Lyrabaodciqu] => C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe [306919 2014-05-11] (Meskisift Corporatien) HKU\S-1-5-21-4243868721-543226389-1580479791-1002\...\MountPoints2: {e4b8b083-4ce2-11e3-be6a-806e6f6e6963} - "E:\AutoRunCD.exe" AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-04-14] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-04-14] (NVIDIA Corporation) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: !AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 a2free; C:\Program Files (x86)\a-squared Free\a2service.exe [1858144 2009-10-01] (Emsi Software GmbH) [File not signed] R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-04-29] (ASUS) R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed] R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [83032 2013-04-22] (Intel Corporation) R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [100032 2013-04-22] (Intel Corporation) R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [84568 2013-04-22] (Intel Corporation) R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [92864 2013-04-22] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-31] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-31] (Intel Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-04-26] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-05-28] (ASUS Corporation) R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [68072 2013-04-22] (Intel Corporation) R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [57216 2013-04-22] (Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [120256 2013-04-22] (Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [200808 2013-04-22] (Intel Corporation) S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-07-21] (LogMeIn Inc.) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99800 2013-05-31] (Intel Corporation) R1 MpKsl8d562ac8; C:\Windows\system32\MpEngineStore\MpKsl8d562ac8.sys [45352 2014-08-17] (Microsoft Corporation) R1 MpKsladfc4267; C:\Windows\system32\MpEngineStore\MpKsladfc4267.sys [45352 2014-08-17] (Microsoft Corporation) S1 rrgcbszm; C:\Windows\system32\drivers\rrgcbszm.sys [55104 2014-08-18] (Microsoft Corporation) R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [460872 2013-03-08] (RTS Corporation) S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-18 10:59 - 2014-08-18 10:59 - 00018000 _____ () C:\Users\Kilian\Desktop\FRST.txt 2014-08-18 10:59 - 2014-08-18 10:59 - 00000000 ____D () C:\FRST 2014-08-18 10:57 - 2014-08-18 10:57 - 02101760 _____ (Farbar) C:\Users\Kilian\Downloads\FRST64.exe 2014-08-18 10:57 - 2014-08-18 10:57 - 02101760 _____ (Farbar) C:\Users\Kilian\Desktop\FRST64 (1).exe 2014-08-18 10:56 - 2014-08-18 10:56 - 00000474 _____ () C:\Users\Kilian\Desktop\defogger_disable.log 2014-08-18 10:56 - 2014-08-18 10:56 - 00000000 _____ () C:\Users\Kilian\defogger_reenable 2014-08-18 10:55 - 2014-08-18 10:55 - 00050477 _____ () C:\Users\Kilian\Desktop\Defogger.exe 2014-08-18 00:07 - 2014-08-18 00:07 - 00055104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rrgcbszm.sys 2014-08-17 23:58 - 2014-08-17 23:59 - 00301592 _____ () C:\Windows\Minidump\081714-52890-01.dmp 2014-08-17 23:47 - 2014-08-17 23:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\a-squared Free 2014-08-17 23:46 - 2014-08-17 23:47 - 00000000 ____D () C:\Program Files (x86)\a-squared Free 2014-08-17 23:46 - 2014-08-17 23:46 - 00000000 ____D () C:\Users\Kilian\Documents\a-squared Free 2014-08-17 23:45 - 2014-08-17 23:46 - 83704128 _____ (Emsi Software GmbH ) C:\Users\Kilian\Downloads\a2FreeSetup27.exe 2014-08-17 23:45 - 2014-08-17 23:46 - 19745792 _____ (Emsi Software GmbH ) C:\Users\Kilian\Downloads\a2FreeSetup27 (1).exe.opdownload 2014-08-17 00:37 - 2014-08-17 00:37 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-08-17 00:37 - 2014-08-17 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-08-17 00:37 - 2014-08-17 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-08-17 00:37 - 2014-08-17 00:37 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-08-17 00:37 - 2014-08-17 00:37 - 00000000 ____D () C:\Program Files (x86)\Java 2014-08-17 00:33 - 2014-08-17 23:30 - 00000000 ____D () C:\Windows\system32\MpEngineStore 2014-08-17 00:29 - 2014-07-31 23:41 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-17 00:28 - 2014-08-17 00:28 - 30517960 _____ (Microsoft Corporation) C:\Users\Kilian\Downloads\Windows-KB890830-x64-V5.15.exe 2014-08-16 23:59 - 2014-08-18 10:00 - 00000830 _____ () C:\Windows\Tasks\Security Center Update - 722109875.job 2014-08-16 23:59 - 2014-08-17 23:40 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage 2014-08-16 23:59 - 2014-08-16 23:59 - 00003804 _____ () C:\Windows\System32\Tasks\Security Center Update - 722109875 2014-08-16 23:59 - 2014-08-16 23:59 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\Cuyfzy 2014-08-16 12:13 - 2014-08-17 00:25 - 00000000 ____D () C:\Users\Kilian\AppData\Local\GameSpy 2014-08-16 12:12 - 2014-08-16 12:12 - 00000094 _____ () C:\Users\Kilian\AppData\Local\fusioncache.dat 2014-08-15 18:05 - 2014-08-15 18:19 - 00000000 ____D () C:\Users\Kilian\AppData\Local\Ubisoft Game Launcher 2014-08-15 18:04 - 2014-08-15 18:04 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2014-08-15 18:03 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2014-08-15 18:03 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-08-15 18:03 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-08-15 18:03 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2014-08-15 18:03 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-08-15 18:03 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-08-15 18:03 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-08-15 18:03 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-08-15 18:03 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2014-08-15 18:03 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-08-15 18:03 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2014-08-15 18:03 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2014-08-15 18:03 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-08-15 18:03 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-08-15 18:03 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-08-15 18:03 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2014-08-15 18:03 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-08-15 18:03 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2014-08-15 18:03 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2014-08-15 18:03 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-08-15 18:03 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-08-15 18:03 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2014-08-15 18:03 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-08-15 18:03 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2014-08-15 18:03 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-08-15 18:03 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-08-15 18:03 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2014-08-15 18:03 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-08-15 18:03 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2014-08-15 18:03 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-08-15 18:03 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2014-08-15 18:03 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2014-08-15 18:03 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2014-08-15 18:03 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2014-08-15 18:03 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-08-15 18:03 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-08-15 18:03 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2014-08-15 18:03 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-08-15 18:03 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2014-08-15 18:03 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2014-08-15 18:03 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-08-15 18:03 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-08-15 18:03 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2014-08-15 18:03 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-08-15 18:03 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-08-15 18:03 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2014-08-15 18:03 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2014-08-15 18:03 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-08-15 18:03 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-08-15 18:03 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2014-08-15 18:03 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2014-08-15 18:03 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-08-15 18:03 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-08-15 18:03 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-08-15 18:03 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-08-15 18:03 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2014-08-15 18:03 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-08-15 18:03 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2014-08-15 18:03 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-08-15 18:03 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2014-08-15 18:03 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2014-08-15 18:03 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-08-15 18:03 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-08-15 18:03 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2014-08-15 18:03 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-08-15 18:03 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2014-08-15 18:03 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-08-15 18:03 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2014-08-15 18:03 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-08-15 18:03 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2014-08-15 18:03 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-08-15 18:03 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2014-08-15 18:03 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-08-15 18:03 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2014-08-15 18:03 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-08-15 18:03 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2014-08-15 18:03 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-08-15 18:03 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2014-08-15 18:03 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-08-15 18:03 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2014-08-15 18:03 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-08-15 18:03 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2014-08-15 18:03 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-08-15 18:03 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2014-08-15 18:02 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-08-15 18:02 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2014-08-15 18:02 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-08-15 18:02 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2014-08-15 18:02 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-08-15 18:02 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2014-08-15 18:02 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-08-15 18:02 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2014-08-15 18:02 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-08-15 18:02 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2014-08-15 18:02 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-08-15 18:02 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2014-08-15 18:02 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2014-08-15 18:02 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-08-15 18:02 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-08-15 18:02 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2014-08-15 18:02 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-08-15 18:02 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2014-08-15 18:02 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2014-08-15 18:02 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-08-15 18:02 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-08-15 18:02 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-08-15 18:02 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2014-08-15 18:02 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2014-08-15 18:02 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2014-08-15 18:02 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-08-15 18:02 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-08-15 18:02 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll 2014-08-15 18:02 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-08-15 18:02 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2014-08-15 18:02 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-08-15 18:02 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2014-08-15 18:02 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-08-15 18:02 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2014-08-15 18:02 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-08-15 18:02 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2014-08-15 18:02 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-08-15 18:02 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2014-08-15 18:02 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-08-15 18:02 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2014-08-15 18:02 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-08-15 18:02 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2014-08-15 18:02 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-08-15 18:02 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2014-08-15 18:02 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-08-15 18:02 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-08-15 18:02 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2014-08-15 17:39 - 2014-08-17 00:13 - 00000000 ____D () C:\Program Files (x86)\Ubisoft 2014-08-15 16:17 - 2014-08-15 16:17 - 00005620 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-08-15 16:16 - 2014-08-15 16:16 - 00000000 __RHD () C:\Users\Kilian\AppData\Roaming\SecuROM 2014-08-15 16:16 - 2014-08-15 16:16 - 00000000 ____D () C:\Windows\SysWOW64\URTTEMP 2014-08-15 16:16 - 2014-08-15 16:16 - 00000000 ____D () C:\Users\Kilian\Documents\My Games 2014-08-15 16:15 - 2014-08-15 16:15 - 00669184 _____ () C:\Windows\SysWOW64\pbsvc.exe 2014-08-15 16:14 - 2014-08-15 16:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts 2014-08-15 16:14 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-08-15 16:14 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2014-08-15 16:14 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-08-15 16:14 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2014-08-15 16:14 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-08-15 16:14 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2014-08-15 16:14 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-08-15 16:14 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2014-08-15 16:14 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-08-15 16:14 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2014-08-15 16:14 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-08-15 16:14 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2014-08-15 16:14 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-08-15 16:14 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2014-08-15 15:59 - 2014-08-15 15:59 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-08-07 23:00 - 2014-08-07 23:10 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\Apple Computer 2014-08-07 23:00 - 2014-08-07 23:00 - 00000000 ____D () C:\Users\Kilian\AppData\Local\Apple Computer 2014-08-07 23:00 - 2014-08-07 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-08-07 23:00 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2014-08-07 22:59 - 2014-08-07 23:00 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-08-07 22:59 - 2014-08-07 23:00 - 00000000 ____D () C:\Program Files\iTunes 2014-08-07 22:59 - 2014-08-07 23:00 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-08-07 22:59 - 2014-08-07 22:59 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\Users\Kilian\AppData\Local\Apple 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\Program Files\iPod 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-08-07 22:58 - 2014-08-07 22:59 - 00000000 ____D () C:\ProgramData\Apple 2014-08-07 22:58 - 2014-08-07 22:58 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-08-07 22:58 - 2014-08-07 22:58 - 00000000 ____D () C:\Program Files\Bonjour 2014-08-07 22:58 - 2014-08-07 22:58 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-08-07 22:57 - 2014-08-07 22:58 - 113492816 _____ (Apple Inc.) C:\Users\Kilian\Downloads\iTunes64Setup.exe 2014-08-07 22:56 - 2014-08-07 22:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-08-01 01:38 - 2014-08-17 00:38 - 00000000 ____D () C:\ProgramData\Oracle 2014-08-01 01:38 - 2014-08-01 01:38 - 00000000 ____D () C:\ProgramData\Sun 2014-07-26 15:19 - 2014-07-26 15:19 - 00349440 _____ () C:\Windows\Minidump\072614-40265-01.dmp 2014-07-21 18:08 - 2014-07-21 18:08 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-18 10:59 - 2014-08-18 10:59 - 00018000 _____ () C:\Users\Kilian\Desktop\FRST.txt 2014-08-18 10:59 - 2014-08-18 10:59 - 00000000 ____D () C:\FRST 2014-08-18 10:58 - 2014-03-30 22:44 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\Skype 2014-08-18 10:57 - 2014-08-18 10:57 - 02101760 _____ (Farbar) C:\Users\Kilian\Downloads\FRST64.exe 2014-08-18 10:57 - 2014-08-18 10:57 - 02101760 _____ (Farbar) C:\Users\Kilian\Desktop\FRST64 (1).exe 2014-08-18 10:56 - 2014-08-18 10:56 - 00000474 _____ () C:\Users\Kilian\Desktop\defogger_disable.log 2014-08-18 10:56 - 2014-08-18 10:56 - 00000000 _____ () C:\Users\Kilian\defogger_reenable 2014-08-18 10:56 - 2014-03-31 00:31 - 00000000 ____D () C:\Users\Kilian 2014-08-18 10:55 - 2014-08-18 10:55 - 00050477 _____ () C:\Users\Kilian\Desktop\Defogger.exe 2014-08-18 10:51 - 2013-11-14 06:27 - 01005034 _____ () C:\Windows\WindowsUpdate.log 2014-08-18 10:00 - 2014-08-16 23:59 - 00000830 _____ () C:\Windows\Tasks\Security Center Update - 722109875.job 2014-08-18 10:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-08-18 02:36 - 2014-04-01 14:29 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4243868721-543226389-1580479791-1002 2014-08-18 00:07 - 2014-08-18 00:07 - 00055104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rrgcbszm.sys 2014-08-18 00:06 - 2014-03-31 00:32 - 00000062 _____ () C:\Users\Kilian\AppData\Roaming\sp_data.sys 2014-08-18 00:05 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-18 00:02 - 2012-08-02 15:24 - 01566820 _____ () C:\Windows\PFRO.log 2014-08-17 23:59 - 2014-08-17 23:58 - 00301592 _____ () C:\Windows\Minidump\081714-52890-01.dmp 2014-08-17 23:58 - 2014-04-06 02:50 - 756383071 _____ () C:\Windows\MEMORY.DMP 2014-08-17 23:58 - 2014-04-06 02:50 - 00000000 ____D () C:\Windows\Minidump 2014-08-17 23:58 - 2013-11-14 06:28 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-17 23:47 - 2014-08-17 23:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\a-squared Free 2014-08-17 23:47 - 2014-08-17 23:46 - 00000000 ____D () C:\Program Files (x86)\a-squared Free 2014-08-17 23:46 - 2014-08-17 23:46 - 00000000 ____D () C:\Users\Kilian\Documents\a-squared Free 2014-08-17 23:46 - 2014-08-17 23:45 - 83704128 _____ (Emsi Software GmbH ) C:\Users\Kilian\Downloads\a2FreeSetup27.exe 2014-08-17 23:46 - 2014-08-17 23:45 - 19745792 _____ (Emsi Software GmbH ) C:\Users\Kilian\Downloads\a2FreeSetup27 (1).exe.opdownload 2014-08-17 23:46 - 2013-11-14 06:41 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1 2014-08-17 23:46 - 2013-11-14 06:41 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2 2014-08-17 23:40 - 2014-08-16 23:59 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage 2014-08-17 23:33 - 2012-08-03 01:02 - 01775488 _____ () C:\Windows\system32\perfh007.dat 2014-08-17 23:33 - 2012-08-03 01:02 - 00499794 _____ () C:\Windows\system32\perfc007.dat 2014-08-17 23:33 - 2012-07-26 09:28 - 00005636 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-17 23:30 - 2014-08-17 00:33 - 00000000 ____D () C:\Windows\system32\MpEngineStore 2014-08-17 23:24 - 2013-04-26 01:06 - 00306312 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-17 00:47 - 2014-05-29 14:38 - 00000000 ____D () C:\Program Files (x86)\Overwolf 2014-08-17 00:45 - 2014-03-30 23:44 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\.minecraft 2014-08-17 00:38 - 2014-08-01 01:38 - 00000000 ____D () C:\ProgramData\Oracle 2014-08-17 00:37 - 2014-08-17 00:37 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-08-17 00:37 - 2014-08-17 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-08-17 00:37 - 2014-08-17 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-08-17 00:37 - 2014-08-17 00:37 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-08-17 00:37 - 2014-08-17 00:37 - 00000000 ____D () C:\Program Files (x86)\Java 2014-08-17 00:28 - 2014-08-17 00:28 - 30517960 _____ (Microsoft Corporation) C:\Users\Kilian\Downloads\Windows-KB890830-x64-V5.15.exe 2014-08-17 00:25 - 2014-08-16 12:13 - 00000000 ____D () C:\Users\Kilian\AppData\Local\GameSpy 2014-08-17 00:13 - 2014-08-15 17:39 - 00000000 ____D () C:\Program Files (x86)\Ubisoft 2014-08-17 00:08 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-08-16 23:59 - 2014-08-16 23:59 - 00003804 _____ () C:\Windows\System32\Tasks\Security Center Update - 722109875 2014-08-16 23:59 - 2014-08-16 23:59 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\Cuyfzy 2014-08-16 19:40 - 2014-04-10 20:06 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\TS3Client 2014-08-16 12:13 - 2014-03-31 00:32 - 00000000 ____D () C:\Users\Kilian\AppData\Local\VirtualStore 2014-08-16 12:12 - 2014-08-16 12:12 - 00000094 _____ () C:\Users\Kilian\AppData\Local\fusioncache.dat 2014-08-15 18:43 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-15 18:19 - 2014-08-15 18:05 - 00000000 ____D () C:\Users\Kilian\AppData\Local\Ubisoft Game Launcher 2014-08-15 18:04 - 2014-08-15 18:04 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2014-08-15 18:03 - 2013-04-26 01:16 - 00064261 _____ () C:\Windows\DirectX.log 2014-08-15 17:39 - 2013-11-14 06:19 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-08-15 16:17 - 2014-08-15 16:17 - 00005620 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-08-15 16:17 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\Registration 2014-08-15 16:16 - 2014-08-15 16:16 - 00000000 __RHD () C:\Users\Kilian\AppData\Roaming\SecuROM 2014-08-15 16:16 - 2014-08-15 16:16 - 00000000 ____D () C:\Windows\SysWOW64\URTTEMP 2014-08-15 16:16 - 2014-08-15 16:16 - 00000000 ____D () C:\Users\Kilian\Documents\My Games 2014-08-15 16:15 - 2014-08-15 16:15 - 00669184 _____ () C:\Windows\SysWOW64\pbsvc.exe 2014-08-15 16:14 - 2014-08-15 16:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts 2014-08-15 16:14 - 2012-07-26 10:12 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-08-15 15:59 - 2014-08-15 15:59 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-08-12 17:08 - 2014-06-03 15:58 - 00003856 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1396219179 2014-08-12 17:08 - 2014-03-31 00:39 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-08-09 00:13 - 2014-03-30 22:44 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-08-07 23:10 - 2014-08-07 23:00 - 00000000 ____D () C:\Users\Kilian\AppData\Roaming\Apple Computer 2014-08-07 23:00 - 2014-08-07 23:00 - 00000000 ____D () C:\Users\Kilian\AppData\Local\Apple Computer 2014-08-07 23:00 - 2014-08-07 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-08-07 23:00 - 2014-08-07 22:59 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-08-07 23:00 - 2014-08-07 22:59 - 00000000 ____D () C:\Program Files\iTunes 2014-08-07 23:00 - 2014-08-07 22:59 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-08-07 22:59 - 2014-08-07 22:59 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\Users\Kilian\AppData\Local\Apple 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\Program Files\iPod 2014-08-07 22:59 - 2014-08-07 22:59 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update 2014-08-07 22:59 - 2014-08-07 22:58 - 00000000 ____D () C:\ProgramData\Apple 2014-08-07 22:58 - 2014-08-07 22:58 - 00000000 ____D () C:\Program Files\Common Files\Apple 2014-08-07 22:58 - 2014-08-07 22:58 - 00000000 ____D () C:\Program Files\Bonjour 2014-08-07 22:58 - 2014-08-07 22:58 - 00000000 ____D () C:\Program Files (x86)\Bonjour 2014-08-07 22:58 - 2014-08-07 22:57 - 113492816 _____ (Apple Inc.) C:\Users\Kilian\Downloads\iTunes64Setup.exe 2014-08-07 22:56 - 2014-08-07 22:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-08-07 22:56 - 2012-07-26 09:21 - 00037937 _____ () C:\Windows\setupact.log 2014-08-01 05:18 - 2014-03-30 22:50 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-08-01 01:38 - 2014-08-01 01:38 - 00000000 ____D () C:\ProgramData\Sun 2014-07-31 23:41 - 2014-08-17 00:29 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-26 15:19 - 2014-07-26 15:19 - 00349440 _____ () C:\Windows\Minidump\072614-40265-01.dmp 2014-07-24 18:22 - 2014-07-17 14:42 - 00075776 _____ () C:\Users\Kilian\AppData\Local\file__0.localstorage 2014-07-24 03:53 - 2014-03-30 22:47 - 00000000 ____D () C:\Users\Kilian\Downloads\authlib 2014-07-21 18:08 - 2014-07-21 18:08 - 00046136 ____H (LogMeIn Inc.) C:\Windows\system32\Drivers\Hamdrv.sys Files to move or delete: ==================== C:\ProgramData\SetStretch.exe C:\ProgramData\SetStretch.VBS Some content of TEMP: ==================== C:\Users\Kilian\AppData\Local\Temp\2DHT.dll C:\Users\Kilian\AppData\Local\Temp\5z8S.dll C:\Users\Kilian\AppData\Local\Temp\drm_dialogs.dll C:\Users\Kilian\AppData\Local\Temp\drm_dyndata_7340014.dll C:\Users\Kilian\AppData\Local\Temp\EVpo.dll C:\Users\Kilian\AppData\Local\Temp\FXyp.dll C:\Users\Kilian\AppData\Local\Temp\itutquy9.dll C:\Users\Kilian\AppData\Local\Temp\jline_git-Bukkit-0_0_0-904-g9277096-b953jnks.dll C:\Users\Kilian\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe C:\Users\Kilian\AppData\Local\Temp\On3Y.dll C:\Users\Kilian\AppData\Local\Temp\scka7rp_.dll C:\Users\Kilian\AppData\Local\Temp\tmpE15E.exe C:\Users\Kilian\AppData\Local\Temp\u74M.dll C:\Users\Kilian\AppData\Local\Temp\ubi2C79.tmp.exe C:\Users\Kilian\AppData\Local\Temp\UNFA.dll C:\Users\Kilian\AppData\Local\Temp\UpdateFlashPlayer_0126b25e.exe C:\Users\Kilian\AppData\Local\Temp\xakb-rup.dll C:\Users\Kilian\AppData\Local\Temp\z4Cl.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-17 03:00 ==================== End Of Log ============================ --- --- --- Addition: Zitat:
GMER Logfile: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-08-18 11:13:39 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003d WDC_WD5000LPVX-80V0TT0 rev.01.01A01 465.76GB Running: Gmer-19357.exe; Driver: C:\Users\Kilian\AppData\Local\Temp\uxdcapod.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff9600011e300 7 bytes [C0, 85, 1B, 01, 00, F2, 9B] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff9600011e308 5 bytes [01, A8, E4, FF, 00] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[736] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fdaf511532 4 bytes [51, AF, FD, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[736] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fdaf51153a 4 bytes [51, AF, FD, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[736] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fdaf51165a 4 bytes [51, AF, FD, 07] .text C:\Windows\system32\DptfPolicyLpmService.exe[1256] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fdb530177a 4 bytes [30, B5, FD, 07] .text C:\Windows\system32\DptfPolicyLpmService.exe[1256] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fdb5301782 4 bytes [30, B5, FD, 07] .text C:\Program Files\Windows Defender\MsMpEng.exe[2156] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 306 000007fdb530177a 4 bytes [30, B5, FD, 07] .text C:\Program Files\Windows Defender\MsMpEng.exe[2156] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 314 000007fdb5301782 4 bytes [30, B5, FD, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3132] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fdaf511532 4 bytes [51, AF, FD, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3132] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fdaf51153a 4 bytes [51, AF, FD, 07] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3132] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fdaf51165a 4 bytes [51, AF, FD, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fdaf511532 4 bytes [51, AF, FD, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fdaf51153a 4 bytes [51, AF, FD, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4320] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fdaf51165a 4 bytes [51, AF, FD, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4376] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fdaf511532 4 bytes [51, AF, FD, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4376] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fdaf51153a 4 bytes [51, AF, FD, 07] .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4376] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fdaf51165a 4 bytes [51, AF, FD, 07] ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [588:612] fffff960008765e8 Thread C:\Windows\Explorer.EXE [3192:5040] 0000000004084e50 ---- Processes - GMER 2.1 ---- Process C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe (*** suspicious ***) @ C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe [11928] (Meskisift Visaal Studie 2010/Meskisift Corporatien)(2014-05-11 09:29:34) 0000000000400000 Process C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe (*** suspicious ***) @ C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe [9880] (Meskisift Visaal Studie 2010/Meskisift Corporatien)(2014-05-11 09:29:34) 0000000000400000 Process C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe (*** suspicious ***) @ C:\Users\Kilian\AppData\Roaming\Cuyfzy\piutfas.exe [3500] (Meskisift Visaal Studie 2010/Meskisift Corporatien)(2014-05-11 09:29:34) 0000000000400000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Virusscan Log alt (Virus meistenteils gelöscht): Zitat:
Zitat:
Entschuldigen Sie, wenn ich die Logs falsch eingebracht habe, ich habe so etwas noch nie vorher gemacht. Ich lasse jetzt meinen Pc neustarten um die bereinigung von Malewarebytes zu vervollständigen. Geändert von seeker1997 (18.08.2014 um 11:13 Uhr) Grund: Die letzten beiden Sätze hinzugefügt. |
Themen zu Windows 8 Trojaner Zbot.gen gefunden in C:\Users\*****\Appdata\Roaming\Cuyfzy\piutfas.exe |
bonjour, explorer, flash player, installation, league of legends, msiexec.exe, performance, programm, pup.optional.bandoo, services.exe, spyware.zbot.ed, svchost.exe, trojan.agent.rvgen, trojan.fakems.ed, trojan.ransom.ed, trojan.zbot.gen, trojaner, windows 8 trojaner zbot.gen, windowsapps |