|
Plagegeister aller Art und deren Bekämpfung: TR/dldr.bagle.ay von Avira gefunden, was ist das?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.02.2015, 18:53 | #1 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? guten Abend, ich hab letztens mit dem TestDisk Photorec Programm Bilder von einem kaputten USB Stick wiederhergestellt. Die hab ich dann heute auf einen neuen Stick getan und den Testdisk Ordner löschen wollen (mit Secure Eraser). Ging dann auch, bis auf eine Datei, die Secure Eraser nicht löschen wollte, als ich die aufgemacht hab hat Avira Antivirus Pro TR/dldr.bagle.ay gemeldet, worauf ich auf in Quarantäne verschieben gegangen bin. Was ist das für ein Virus? Und muss ich noch andere Schritte unternehmen um den unschädlich zu machen oder hat Avira den schon entfernt? mfg |
03.02.2015, 19:24 | #2 |
/// the machine /// TB-Ausbilder | TR/dldr.bagle.ay von Avira gefunden, was ist das? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
03.02.2015, 19:36 | #3 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? Hier ist die FRST.txt
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015 Ran by Johannes (administrator) on JOH on 03-02-2015 19:31:17 Running from E:\Daten\Download Loaded Profiles: Johannes (Available profiles: Johannes) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SUPERAntiSpyware.com) G:\SASCORE64.EXE (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Nero AG) G:\Program Files (x86)\HSMServiceEntry.exe () C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () G:\Program Files (x86)\HTC Sync\adb.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Valve Corporation) G:\Program Files (x86)\Steam\Steam.exe (SUPERAntiSpyware) G:\SUPERANTISPYWARE.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Autodesk Inc.) C:\Users\Johannes\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Valve Corporation) G:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Farbar) E:\Daten\Download\FRST64(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-27] (Realtek Semiconductor) HKLM\...\Run: [MBCfg64] => C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\MBCfg64.dll,RunDLLEntry MBCfg64 HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation) HKLM-x32\...\Run: [CommandCenter] => C:\Program Files (x86)\MSI\CommandCenter\StartCommandCenter.exe [797680 2013-06-19] () HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1935824 2014-05-19] (APN) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [488328 2014-09-04] (Autodesk Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [EADM] => G:\Origin\Origin.exe [3619160 2015-01-27] (Electronic Arts) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Steam] => G:\Program Files (x86)\Steam\Steam.exe [1942720 2015-01-23] (Valve Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [SUPERAntiSpyware] => G:\SUPERAntiSpyware.exe [7777560 2014-11-28] (SUPERAntiSpyware) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {8f88013a-7b8c-11e3-bf31-fbc38769574a} - "M:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {e4fd87da-0abb-11e4-8053-e47334489d3d} - "H:\LGAutoRun.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKLM-x32 -> DefaultScope value is missing. BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-00A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Avira SearchFree Toolbar -> {41564952-412D-5637-00A7-7A786E7484D7} -> C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default FF DefaultSearchEngine: eBay FF SelectedSearchEngine: Bing FF Homepage: google.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: ubisoft.com/uplaypc -> G:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-maps.xml FF Extension: Better Battlelog (BBLog) - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack [2015-01-27] FF Extension: WOT - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: ProxTube - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11] FF Extension: Restartless Restart - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\restartless.restart@erikvold.com.xpi [2013-10-22] FF Extension: Google Translator for Firefox - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\translator@zoli.bod.xpi [2014-07-26] FF Extension: NoScript - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-28] FF Extension: Adblock Plus - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-22] FF Extension: BetterPrivacy - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-10-22] FF HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> hxxp://freebitco.in/ CHR Profile: C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-14] CHR Extension: (Google Drive) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-14] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-25] CHR Extension: (YouTube) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-14] CHR Extension: (Google-Suche) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-14] CHR Extension: (ThemeBeta.com) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnomoddmmgfhcejjblojoaandlmkfmla [2015-01-27] CHR Extension: (Google Wallet) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-14] CHR Extension: (Google Mail) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-14] CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [Not Found] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; G:\SASCORE64.EXE [172344 2014-08-13] (SUPERAntiSpyware.com) R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [597896 2014-09-04] (Autodesk Inc.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-12-16] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [610688 2014-10-29] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation) R2 HTCMonitorService; G:\Program Files (x86)\HSMServiceEntry.exe [87368 2014-04-02] (Nero AG) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S3 mi-raysat_3dsmax2015_64; G:\Program Files (x86)\3dMax\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [86016 2011-09-15] () [File not signed] S2 MSIBIOSData_CC; C:\Program Files (x86)\MSI\CommandCenter\BIOSData\MSIBIOSDataService.exe [2055680 2013-06-06] (MSI) [File not signed] S2 MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\MSIClockService.exe [305152 2013-06-19] () [File not signed] S2 MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\MSICommService.exe [2104832 2013-06-24] () [File not signed] S2 MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\MSICPUService.exe [4101120 2013-06-19] () [File not signed] R2 MSICTL_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe [1982976 2013-06-24] () [File not signed] S2 MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\MSIDDRService.exe [2237440 2013-06-19] () [File not signed] S2 MSISaveLoad_CC; C:\Program Files (x86)\MSI\CommandCenter\MSISaveLoadService.exe [3957248 2013-04-18] () [File not signed] S2 MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\MSISMBService.exe [175616 2013-05-28] () [File not signed] S2 MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\MSISuperIOService.exe [481280 2013-06-19] () [File not signed] S2 MSIWMI_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIWMIService.exe [181760 2013-04-18] () [File not signed] R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833544 2015-01-16] (NVIDIA Corporation) S3 Origin Client Service; G:\Origin\OriginClientService.exe [1910128 2015-01-27] (Electronic Arts) S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] S2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2014-10-01] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2013-04-30] () [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [15888 2013-04-01] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AcpiCtlDrv; C:\Windows\System32\drivers\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43064 2014-10-14] (Avira Operations GmbH & Co. KG) S1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2013-04-30] (Qualcomm Atheros, Inc.) S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.) S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [25448 2013-01-07] (Intel Corporation) R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [174448 2013-04-30] (Qualcomm Atheros, Inc.) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2014-10-20] (Malwarebytes Corporation) S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MSI) S3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MSI) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3068120 2014-01-10] (Realtek Semiconductor Corporation ) R1 SASDIFSV; G:\\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; G:\\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-31 21:58 - 2015-01-31 21:58 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2015-01-31 21:58 - 2015-01-13 05:15 - 01540240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 32102544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 25459856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 24765584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 20465296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13295552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13210248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10774544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10714488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10274448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2015-01-31 21:58 - 2015-01-10 09:07 - 03607184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 03245712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01895240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01556808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00994712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00969360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00942736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00929424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00906384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00877488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00833864 _____ () C:\WINDOWS\system32\nvmcumd.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00496456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00399688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00390472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00353040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00345744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00305320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00177624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00164568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2015-01-31 21:58 - 2015-01-09 23:27 - 00621200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2015-01-27 23:19 - 2015-01-27 23:19 - 00000049 _____ () C:\WINDOWS\SysWOW64\ScrRecX.log 2015-01-27 23:19 - 2008-08-18 18:18 - 00077824 _____ (Fox Magic Software) C:\WINDOWS\SysWOW64\fmcodec.DLL 2015-01-27 13:36 - 2015-01-27 13:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-01-14 22:05 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2015-01-14 22:05 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2015-01-14 22:05 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-01-14 22:05 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2015-01-14 22:05 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2015-01-14 22:05 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-01-14 22:05 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2015-01-14 22:05 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2015-01-14 22:05 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-01-14 22:05 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-03 19:31 - 2014-09-09 13:59 - 00000000 ____D () C:\FRST 2015-02-03 19:08 - 2014-07-09 12:51 - 01497665 _____ () C:\WINDOWS\WindowsUpdate.log 2015-02-03 19:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-02-03 18:57 - 2014-05-14 15:30 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-03 18:56 - 2014-09-08 20:48 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Akamai 2015-02-03 18:51 - 2013-10-30 14:52 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-02-03 17:59 - 2013-12-08 19:01 - 00000072 _____ () C:\Users\Public\LMDebug.log 2015-02-03 17:56 - 2013-10-21 21:01 - 00000000 ____D () C:\ProgramData\Origin 2015-02-03 17:53 - 2013-10-22 15:11 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\TS3Client 2015-02-03 16:47 - 2014-12-21 00:04 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Arma 3 2015-02-03 15:54 - 2013-10-18 21:55 - 00000000 ____D () C:\ProgramData\Bigfoot Networks 2015-02-03 14:57 - 2014-05-14 15:30 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-03 14:06 - 2013-09-30 05:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-02-03 14:06 - 2013-09-30 04:56 - 00750632 _____ () C:\WINDOWS\system32\perfh007.dat 2015-02-03 14:06 - 2013-09-30 04:56 - 00155144 _____ () C:\WINDOWS\system32\perfc007.dat 2015-02-03 14:03 - 2014-08-02 12:47 - 00039629 _____ () C:\WINDOWS\setupact.log 2015-02-03 14:02 - 2013-10-20 22:37 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-02-03 14:02 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-02-01 15:41 - 2013-10-16 21:57 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-597342630-187561070-3433799475-1001 2015-01-31 21:59 - 2014-10-08 14:12 - 00000000 ____D () C:\TEMP 2015-01-31 21:59 - 2013-10-18 22:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-01-31 16:55 - 2013-12-09 18:43 - 00348928 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2015-01-31 16:55 - 2013-10-21 21:44 - 00348928 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2015-01-31 16:55 - 2013-10-21 21:39 - 00290184 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2015-01-31 16:46 - 2014-05-24 14:42 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\vlc 2015-01-28 22:56 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-01-28 14:49 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-01-28 13:33 - 2013-10-30 15:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 23:19 - 2014-06-14 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher 2015-01-27 23:19 - 2013-11-05 17:40 - 00000919 _____ () C:\Users\Public\Desktop\aTube Catcher.lnk 2015-01-24 21:20 - 2014-04-29 22:34 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-01-24 21:20 - 2014-04-29 22:34 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-24 20:51 - 2013-10-30 14:52 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-01-21 13:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-01-16 20:41 - 2014-12-22 19:23 - 00000000 ____D () C:\Users\Johannes\AppData\Local\ftblauncher 2015-01-16 07:41 - 2014-06-03 13:15 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2015-01-16 07:41 - 2014-06-03 13:15 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01514528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01278920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2015-01-16 00:44 - 2013-12-08 22:40 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Skype 2015-01-15 20:43 - 2014-03-14 19:53 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-01-15 20:43 - 2013-12-08 22:40 - 00000000 ____D () C:\ProgramData\Skype 2015-01-15 17:49 - 2013-10-20 11:35 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-01-15 17:48 - 2013-10-20 11:35 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-01-15 17:48 - 2013-08-22 14:25 - 00008192 ___SH () C:\WINDOWS\system32\config\ELAM 2015-01-14 00:35 - 2014-11-09 23:29 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Mp3tag 2015-01-11 15:29 - 2013-10-20 11:04 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork 2015-01-10 09:07 - 2014-12-16 19:59 - 17250776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2015-01-10 09:07 - 2014-12-16 19:59 - 16009120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 18566296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 14115944 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 03298816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 02902456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 00027441 _____ () C:\WINDOWS\system32\nvinfo.pb 2015-01-10 00:30 - 2013-10-20 22:37 - 06860432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2015-01-10 00:30 - 2013-10-20 22:37 - 03517256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00935056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2015-01-10 00:29 - 2013-10-20 22:37 - 00385352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2015-01-09 20:47 - 2013-10-20 22:37 - 04173527 _____ () C:\WINDOWS\system32\nvcoproc.bin ==================== Files in the root of some directories ======= 2014-07-16 14:30 - 2014-07-16 14:30 - 0001456 _____ () C:\Users\Johannes\AppData\Local\Adobe Für Web speichern 11.0 Prefs 2013-10-18 17:13 - 2013-10-18 22:01 - 0001008 _____ () C:\Users\Johannes\AppData\Local\killertool.log 2013-10-18 23:18 - 2014-09-09 15:57 - 0007651 _____ () C:\Users\Johannes\AppData\Local\Resmon.ResmonCfg 2013-10-18 17:21 - 2013-10-21 10:12 - 0062352 _____ () C:\ProgramData\dxdiag.txt Some content of TEMP: ==================== C:\Users\Johannes\AppData\Local\Temp\avgnt.exe C:\Users\Johannes\AppData\Local\Temp\camtasiade.exe C:\Users\Johannes\AppData\Local\Temp\drm_dyndata_7380014.dll C:\Users\Johannes\AppData\Local\Temp\exe2pin.exe C:\Users\Johannes\AppData\Local\Temp\jansi-32-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Johannes\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Johannes\AppData\Local\Temp\nvStInst.exe C:\Users\Johannes\AppData\Local\Temp\procexp0364.exe C:\Users\Johannes\AppData\Local\Temp\sdanircmdc.exe C:\Users\Johannes\AppData\Local\Temp\sdapskill.exe C:\Users\Johannes\AppData\Local\Temp\sdaspwn.exe C:\Users\Johannes\AppData\Local\Temp\sHID.dll C:\Users\Johannes\AppData\Local\Temp\sonarinst.exe C:\Users\Johannes\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-29 15:53 ==================== End Of Log ============================ Addition.txt hats irgentwie keine erstellt |
04.02.2015, 17:58 | #4 |
/// the machine /// TB-Ausbilder | TR/dldr.bagle.ay von Avira gefunden, was ist das? FRST öffnen, Haken setzen bei Addition und scannen, poste bitte die Addition.txt.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.02.2015, 22:11 | #5 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? ok dann hier die Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-02-2015 01 Ran by Johannes at 2015-02-04 22:03:04 Running from E:\Daten\Download Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 123D Design R1.5 (HKLM\...\123D Design) (Version: 1.5.23 - Autodesk, Inc.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Akamai NetSession Interface (HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Akamai) (Version: - Akamai Technologies, Inc) Antivirus Pro (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Arma 2 (HKLM-x32\...\Steam App 33910) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead (HKLM-x32\...\Steam App 33930) (Version: - Bohemia Interactive) Arma 2: Operation Arrowhead Beta (Obsolete) (HKLM-x32\...\Steam App 219540) (Version: - ) Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive) ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach) ASUS PCE-N15 WLAN Card Utilities & Driver (HKLM-x32\...\{556BEFE2-30FF-4113-98F4-01234396DF2B}) (Version: 1.0.1.0 - ASUS) aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 3.8.7971 - DsNET Corp) aTube Catcher Version 3.8 (HKLM-x32\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp) Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team) Autodesk 3ds Max 2015 (HKLM\...\Autodesk 3ds Max 2015) (Version: 17.1.149.0 - Autodesk) Autodesk 3ds Max 2015 (Version: 17.1.149.0 - Autodesk) Hidden Autodesk 3ds Max 2015 Populate Data (HKLM\...\{57E92DED-DC6C-41E5-B9E1-76D83BD2EABE}) (Version: 17.0.0.0 - Autodesk) Autodesk 3ds Max 2015 SP1 (HKLM\...\Autodesk 3ds Max 2015 SP1) (Version: 17.1.149.0 - Autodesk) Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 3.0.159.0 - Autodesk) Autodesk Backburner 2015 (HKLM-x32\...\{8C5F38D2-8EFE-49A4-B3F5-BF3210FED168}) (Version: 15.0.0.0 - Autodesk) Autodesk DirectConnect 2015 64-bit (HKLM\...\Autodesk DirectConnect 2015 64-bit) (Version: 9.0.56.4 - Autodesk) Autodesk DirectConnect 2015 64-bit (Version: 9.0.56.4 - Autodesk) Hidden Autodesk DirectConnect 2015 64-bit Hotfix1 (HKLM\...\Autodesk DirectConnect 2015 64-bit_9001) (Version: 9.0.56.4 - Autodesk) Autodesk Inventor Server Engine for 3ds Max 2015 (HKLM\...\{9167CA34-4E48-49E3-8892-3C439739D2D3}) (Version: 17.0.2 - Autodesk) Autodesk Material Library 2015 (HKLM-x32\...\{427F733F-4D6C-45BC-9324-EB743104C321}) (Version: 5.2.9.100 - Autodesk) Autodesk Material Library Base Resolution Image Library 2015 (HKLM-x32\...\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}) (Version: 5.2.9.100 - Autodesk) Autodesk Material Library Medium Resolution Image Library 2015 (HKLM-x32\...\{9F6466D9-6EFC-4A10-B931-C72D1A3F1763}) (Version: 5.2.9.100 - Autodesk) Autodesk Revit Interoperability for 3ds Max 2015 (HKLM\...\Autodesk Revit Interoperability for 3ds Max 2015) (Version: 15.0.166.0 - Autodesk) Autodesk Revit Interoperability for 3ds Max 2015 (Version: 15.0.166.0 - Autodesk) Hidden Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4487 - APN, LLC) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts) Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.4.2.23831 - Electronic Arts) Battlefield: Bad Company™ 2 (HKLM-x32\...\{3AC8457C-0385-4BEA-A959-E095F05D6D67}) (Version: 1.0.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) BitMinter Client (HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\BitMinter Client) (Version: - BitMinter.com) BlueJ (HKLM-x32\...\{7D66971C-652B-4065-A6B1-B3EE313C254B}) (Version: 3.1.0 - BlueJ Team) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.22 - Cliqz.com) CommandCenter (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 1.0.0.15 - MSI) DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) DayZ Commander (HKLM-x32\...\{B3653588-3AC0-4A1D-950F-D96531E84374}) (Version: 0.92.91 - Dotjosh Studios) Dead Space (HKLM-x32\...\{025A585C-0C66-413D-80D2-4C05CB699771}) (Version: 1.0.0.222 - Electronic Arts) DriverToolkit version 8.3.5.0 (HKLM-x32\...\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1) (Version: 8.3.5.0 - Megaify Software) Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft) FL Studio 11 (HKLM-x32\...\FL Studio 11) (Version: - Image-Line) FlowStone FL 3.0 (HKLM-x32\...\FlowStone) (Version: - ) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.94 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Grand Theft Auto IV (HKLM-x32\...\Steam App 12210) (Version: - Rockstar North) Heroes & Generals (HKLM-x32\...\Steam App 227940) (Version: - Reto-Moto) HI-TECH C Compiler for the PIC10/12/16 MCUs V9.80PL0 (HKLM-x32\...\PICC 9.80) (Version: 9.80 - HI-TECH Software) HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.11.0.001 - HTC Corporation) HTC Sync Manager (HKLM-x32\...\{231D0C79-98A6-4693-A366-36DE7D7346EC}) (Version: 3.1.13.0 - HTC) IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line) IL Shared Libraries (HKLM-x32\...\IL Shared Libraries) (Version: - Image-Line) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation) Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\3FD0C489-0F02-481a-A3E1-9754CD396761) (Version: - Intel Corporation) IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan) Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java 7 Update 71 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417071FF}) (Version: 7.0.710 - Oracle) Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Java SE Development Kit 7 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170450}) (Version: 1.7.0.450 - Oracle) Java SE Development Kit 7 Update 71 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170710}) (Version: 1.7.0.710 - Oracle) LG United Mobile Drivers (HKLM-x32\...\{5DB849D6-9392-4FB7-9ABB-87ED433152E5}) (Version: 3.8.1 - LG Electronics) Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Meshmixer (HKLM\...\Meshmixer_x64) (Version: - ) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mp3tag v2.58 (HKLM-x32\...\Mp3tag) (Version: v2.58 - Florian Heidenreich) MPLAB Tools v8.60 (HKLM-x32\...\InstallShield_{2AD34BE6-9D8D-4EC8-AA73-5AAF407217ED}) (Version: 8.60 - Microchip Technology Inc.) MPLAB Tools v8.60 (x32 Version: 8.60 - Microchip Technology Inc.) Hidden MPLAB X IDE v2.00 (HKLM-x32\...\MPLAB X IDE v2.00 v2.00) (Version: v2.00 - Microchip) MPLAB XC8 C Compiler (HKLM-x32\...\MPLAB XC8 C Compiler v1.30) (Version: v1.30 - Microchip) MPLAB XC8 C Compiler (HKLM-x32\...\MPLAB XC8 C Compiler v1.33) (Version: v1.33 - Microchip) MSI Intel Extreme Tuning Utility (HKLM-x32\...\{2301bb34-385a-4a57-877f-c54347957fad}) (Version: 4.0.6.305 - Intel Corporation) MSI Intel Extreme Tuning Utility (x32 Version: 4.0.6.305 - Intel Corporation) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 347.25 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.25 - NVIDIA Corporation) NVIDIA GeForce Experience 2.2.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation) NVIDIA Grafiktreiber 347.25 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.25 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation) NVIDIA Miracast Virtueller Ton 347.25 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 347.25 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Origin (HKLM-x32\...\Origin) (Version: 9.3.10.4710 - Electronic Arts, Inc.) PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version: - OVERKILL Software) PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.205.0 - Tracker Software Products Ltd) PicPick (HKLM-x32\...\PicPick) (Version: 4.0.0 - NTeWORKS) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Qualcomm Atheros Killer Network Manager (HKLM-x32\...\InstallShield_{DF446558-ADF7-4884-9B2D-281979CCE71F}) (Version: 6.1.0.583 - Qualcomm Atheros) Qualcomm Atheros Killer Network Manager (Version: 6.1.0.583 - Qualcomm Atheros) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6923 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0239 - REALTEK Semiconductor Corp.) Secure Eraser (HKLM-x32\...\Secure Eraser_is1) (Version: 4.2.0.1 - ASCOMP Software GmbH) SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.02 - Creative Technology Limited) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Star Wars Battlefront II (HKLM-x32\...\{3D374523-CFDE-461A-827E-2A102E2AB365}) (Version: 1.0 - LucasArts) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.7.1018 - SUPERAntiSpyware.com) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) TmNationsForever (HKLM-x32\...\TmNationsForever_is1) (Version: - Nadeo) Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) Vegas Pro 12.0 (64-bit) (HKLM\...\{6592B670-2680-11E3-B0E0-F04DA23A5C58}) (Version: 12.0.726 - Sony) VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.5 - MSI) Visual Pinball (HKLM-x32\...\{B36C4994-A563-4339-8754-CCCE51314A4C}) (Version: 0.0.4.1226 - Randy Davis) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WinRAR 5.00 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 01-02-2015 15:43:38 Geplanter Prüfpunkt 04-02-2015 17:27:35 Installed LG United Mobile Drivers. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {152D993E-E159-4E75-B5D5-C1B843493780} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-01-15] (Microsoft Corporation) Task: {2763972F-D8D9-4A7A-B2C0-EF9193EFD636} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {280BCCA3-89AE-467E-B363-85E3B66332F5} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated) Task: {4D3ED548-8897-4549-BB4A-E8DADEC13D49} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-14] (Google Inc.) Task: {6AE1597F-4856-4D5D-836A-47B1DF05EF55} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxp://www.roboform.com/uninstall.html?aaa=KICMIMKMPMGMLMLMKMOMCNOJJMJJJMCNLMGMOJPMCNOJHMNMHMCNMMJMOMNJPMOJJMMMKMNMPMNJJNJICMIMCNGMCNIMFMOMOMCNPMCNGMJMPMPMFMJMCNMMCNGMJMPMPMCNNMJNPICMPMFMFMOMNMJNHICMEKMICNJJCKJNBJCMFLAJHJOJBJBJKJMIJNKJCMJNNICMJNDJCMLJKJJNMJCMPMFMPMFMPMJNFICMNIJJIIGJPIKJAJKILIBNKJHIKJ" Task: {C9AF1713-2B96-4703-94D6-797B50E5EDCA} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe Task: {CDAA4D87-43DD-407D-A91D-935C93DBCDDD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-14] (Google Inc.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2013-10-20 22:37 - 2015-01-10 00:29 - 00117392 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2008-06-04 06:53 - 2008-06-04 06:53 - 00027648 _____ () C:\WINDOWS\System32\ssd2cl6.dll 2009-08-28 05:38 - 2009-08-28 05:38 - 00740864 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\ssd2cdu.dll 2013-10-18 22:09 - 2013-06-24 10:54 - 01982976 _____ () C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe 2013-12-09 18:43 - 2014-10-01 20:16 - 00076152 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2013-11-05 16:14 - 2012-09-07 16:57 - 00559424 _____ () G:\Program Files (x86)\Secure Eraser\SecEraser64.dll 2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () G:\Program Files (x86)\Notepad++\NppShell_05.dll 2014-05-27 11:43 - 2014-05-27 11:43 - 00821600 _____ () G:\Program Files (x86)\HTC Sync\adb.exe 2013-10-21 00:12 - 2012-11-01 10:21 - 00325120 _____ () C:\WINDOWS\SYSTEM32\APOMgr64.DLL 2014-03-13 19:17 - 2014-03-13 19:17 - 00173568 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll 2014-03-13 19:17 - 2014-03-13 19:17 - 01080832 _____ () C:\Program Files\TeamSpeak 3 Client\platforms\qwindows.dll 2014-03-13 19:17 - 2014-03-13 19:17 - 00833024 _____ () C:\Program Files\TeamSpeak 3 Client\sqldrivers\qsqlite.dll 2013-09-27 13:15 - 2014-08-07 13:15 - 00102344 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2013-09-27 13:15 - 2014-08-07 13:15 - 00108488 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2014-03-13 19:17 - 2014-03-13 19:17 - 00030208 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qgif.dll 2014-03-13 19:17 - 2014-03-13 19:17 - 00233984 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg.dll 2013-09-27 13:15 - 2014-08-07 13:15 - 00563656 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2013-09-27 13:15 - 2014-08-07 13:15 - 00579016 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2014-03-13 19:17 - 2014-03-13 19:17 - 00159232 _____ () C:\Program Files\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll 2014-09-08 21:07 - 2014-09-04 04:41 - 00047496 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\QtSolutions_Service-head.dll 2014-09-08 21:07 - 2014-09-04 04:41 - 00104328 _____ () C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\qjson0.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-05-27 11:42 - 2014-05-27 11:42 - 00031080 _____ () G:\Program Files (x86)\DbAccess.dll 2014-05-27 11:42 - 2014-05-27 11:42 - 00607376 _____ () G:\Program Files (x86)\sqlite3.dll 2014-05-27 11:43 - 2014-05-27 11:43 - 00059752 _____ () G:\Program Files (x86)\NAdvLog.dll 2014-05-27 11:42 - 2014-05-27 11:42 - 00036216 _____ () G:\Program Files (x86)\NFileCacheDBAccess.dll 2014-05-27 11:43 - 2014-05-27 11:43 - 00080248 _____ () G:\Program Files (x86)\ninstallerhelper.dll 2014-05-27 11:44 - 2014-05-27 11:44 - 00129376 _____ () G:\Program Files (x86)\zlib1.dll 2014-05-27 11:45 - 2014-05-27 11:45 - 00223592 _____ () G:\Program Files (x86)\DevConnMon.dll 2014-08-31 00:48 - 2014-12-01 22:31 - 02396672 _____ () G:\Program Files (x86)\Steam\libavcodec-56.dll 2014-08-31 00:48 - 2014-12-01 22:31 - 00479744 _____ () G:\Program Files (x86)\Steam\libavformat-56.dll 2014-08-31 00:48 - 2014-12-01 22:31 - 00332800 _____ () G:\Program Files (x86)\Steam\libavresample-2.dll 2014-08-31 00:48 - 2014-12-01 22:31 - 00442880 _____ () G:\Program Files (x86)\Steam\libavutil-54.dll 2013-08-21 13:18 - 2014-11-11 19:47 - 00774656 _____ () G:\Program Files (x86)\Steam\SDL2.dll 2015-01-20 14:43 - 2014-12-02 01:29 - 05002752 _____ () G:\Program Files (x86)\Steam\v8.dll 2014-05-22 12:12 - 2015-01-23 23:34 - 02227904 _____ () G:\Program Files (x86)\Steam\video.dll 2015-01-20 14:43 - 2014-12-02 01:29 - 01612800 _____ () G:\Program Files (x86)\Steam\icui18n.dll 2015-01-20 14:43 - 2014-12-02 01:29 - 01210368 _____ () G:\Program Files (x86)\Steam\icuuc.dll 2014-08-31 00:48 - 2014-12-01 22:31 - 00485888 _____ () G:\Program Files (x86)\Steam\libswscale-3.dll 2013-10-08 17:19 - 2015-01-23 23:33 - 00696512 _____ () G:\Program Files (x86)\Steam\bin\chromehtml.DLL 2015-02-04 13:03 - 2014-09-04 04:41 - 00104328 _____ () C:\Users\Johannes\AppData\Local\Autodesk\.AdskAppManager\R1\qjson0.dll 2013-09-10 13:20 - 2015-01-16 00:42 - 34641288 _____ () G:\Program Files (x86)\Steam\bin\libcef.dll 2014-08-14 20:12 - 2015-01-16 00:42 - 01709960 _____ () G:\Program Files (x86)\Steam\bin\ffmpegsumo.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 01007104 _____ () G:\Origin\platforms\qwindows.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 00023552 _____ () G:\Origin\imageformats\qgif.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 00024576 _____ () G:\Origin\imageformats\qico.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 00216576 _____ () G:\Origin\imageformats\qjpeg.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 00261120 _____ () G:\Origin\imageformats\qmng.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 00019456 _____ () G:\Origin\imageformats\qtga.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 00337408 _____ () G:\Origin\imageformats\qtiff.dll 2014-01-29 14:01 - 2015-01-27 14:52 - 00018944 _____ () G:\Origin\imageformats\qwbmp.dll 2015-01-27 13:36 - 2015-01-27 13:36 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Registry Areas ===================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-597342630-187561070-3433799475-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\MSI\MSI innovation with style.jpg ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "Qualcomm Atheros Killer Network Manager.lnk" HKLM\...\StartupApproved\Run32: => "ApnTBMon" ==================== Accounts: ============================= Administrator (S-1-5-21-597342630-187561070-3433799475-500 - Administrator - Disabled) Gast (S-1-5-21-597342630-187561070-3433799475-501 - Limited - Disabled) Johannes (S-1-5-21-597342630-187561070-3433799475-1001 - Administrator - Enabled) => C:\Users\Johannes ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/04/2015 09:35:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: arma3.exe, Version: 1.38.128.937, Zeitstempel: 0x54bd4194 Name des fehlerhaften Moduls: PhysX3_x86.dll, Version: 3.3.2.0, Zeitstempel: 0x54233834 Ausnahmecode: 0xc0000005 Fehleroffset: 0x001a484c ID des fehlerhaften Prozesses: 0x10e8 Startzeit der fehlerhaften Anwendung: 0xarma3.exe0 Pfad der fehlerhaften Anwendung: arma3.exe1 Pfad des fehlerhaften Moduls: arma3.exe2 Berichtskennung: arma3.exe3 Vollständiger Name des fehlerhaften Pakets: arma3.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: arma3.exe5 Error: (02/04/2015 05:58:10 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (02/04/2015 05:57:52 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (02/04/2015 01:03:43 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (02/04/2015 01:03:26 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (02/04/2015 00:57:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: MSIDDRService.exe, Version: 0.0.0.0, Zeitstempel: 0x51c1a704 Name des fehlerhaften Moduls: MSIDDRService.exe, Version: 0.0.0.0, Zeitstempel: 0x51c1a704 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000893a ID des fehlerhaften Prozesses: 0x478 Startzeit der fehlerhaften Anwendung: 0xMSIDDRService.exe0 Pfad der fehlerhaften Anwendung: MSIDDRService.exe1 Pfad des fehlerhaften Moduls: MSIDDRService.exe2 Berichtskennung: MSIDDRService.exe3 Vollständiger Name des fehlerhaften Pakets: MSIDDRService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MSIDDRService.exe5 Error: (02/04/2015 00:57:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: MSICPUService.exe, Version: 0.0.0.0, Zeitstempel: 0x51c10c88 Name des fehlerhaften Moduls: MSICPUService.exe, Version: 0.0.0.0, Zeitstempel: 0x51c10c88 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00013ba6 ID des fehlerhaften Prozesses: 0x7dc Startzeit der fehlerhaften Anwendung: 0xMSICPUService.exe0 Pfad der fehlerhaften Anwendung: MSICPUService.exe1 Pfad des fehlerhaften Moduls: MSICPUService.exe2 Berichtskennung: MSICPUService.exe3 Vollständiger Name des fehlerhaften Pakets: MSICPUService.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: MSICPUService.exe5 Error: (02/03/2015 11:04:58 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (02/03/2015 11:04:41 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. Error: (02/03/2015 06:56:05 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können. System errors: ============= Error: (02/04/2015 05:45:48 PM) (Source: DCOM) (EventID: 10010) (User: Joh) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (02/04/2015 05:45:18 PM) (Source: DCOM) (EventID: 10010) (User: Joh) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (02/04/2015 02:58:07 PM) (Source: DCOM) (EventID: 10010) (User: Joh) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (02/04/2015 02:57:37 PM) (Source: DCOM) (EventID: 10010) (User: Joh) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (02/04/2015 01:18:16 PM) (Source: DCOM) (EventID: 10010) (User: Joh) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (02/04/2015 01:17:46 PM) (Source: DCOM) (EventID: 10010) (User: Joh) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (02/04/2015 00:57:48 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde mit folgendem Fehler beendet: %%1008 Error: (02/04/2015 00:57:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Qualcomm Atheros Killer Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (02/04/2015 00:57:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Internet Pass-Through Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%109 Error: (02/03/2015 06:36:38 PM) (Source: DCOM) (EventID: 10010) (User: Joh) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Microsoft Office Sessions: ========================= Error: (02/04/2015 09:35:14 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: arma3.exe1.38.128.93754bd4194PhysX3_x86.dll3.3.2.054233834c0000005001a484c10e801d040ac703fbe4eG:\Program Files (x86)\Steam\steamapps\common\Arma 3\arma3.exeG:\Program Files (x86)\Steam\steamapps\common\Arma 3\PhysX3_x86.dll524bdef7-acad-11e4-8176-d43d7ee34be9 Error: (02/04/2015 05:58:10 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/04/2015 05:57:52 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/04/2015 01:03:43 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/04/2015 01:03:26 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/04/2015 00:57:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: MSIDDRService.exe0.0.0.051c1a704MSIDDRService.exe0.0.0.051c1a704c00000050000893a47801d04071c67f065fC:\Program Files (x86)\MSI\CommandCenter\DDR\MSIDDRService.exeC:\Program Files (x86)\MSI\CommandCenter\DDR\MSIDDRService.exe09030209-ac65-11e4-8176-ac220b91a1ed Error: (02/04/2015 00:57:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: MSICPUService.exe0.0.0.051c10c88MSICPUService.exe0.0.0.051c10c88c000000500013ba67dc01d04071c66006ceC:\Program Files (x86)\MSI\CommandCenter\CPU\MSICPUService.exeC:\Program Files (x86)\MSI\CommandCenter\CPU\MSICPUService.exe0902daf9-ac65-11e4-8176-ac220b91a1ed Error: (02/03/2015 11:04:58 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/03/2015 11:04:41 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (02/03/2015 06:56:05 PM) (Source: MsiInstaller) (EventID: 11310) (User: Joh) Description: Produkt: Akamai NetSession Interface -- Fehler 1310. Fehler beim Schreiben in die Datei: C:\Users\Johannes\AppData\Local\Akamai\admintool.exe. Systemfehler 0. Stellen Sie sicher, dass Sie auf das Verzeichnis zugreifen können.(NULL)(NULL)(NULL)(NULL)(NULL) ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4670 CPU @ 3.40GHz Percentage of memory in use: 14% Total physical RAM: 16328.55 MB Available physical RAM: 13898.09 MB Total Pagefile: 17328.55 MB Available Pagefile: 14287.77 MB Total Virtual: 131072 MB Available Virtual: 131071.83 MB ==================== Drives ================================ Drive c: (SSD) (Fixed) (Total:118.9 GB) (Free:17.08 GB) NTFS Drive e: (DATA) (Fixed) (Total:200 GB) (Free:78.68 GB) NTFS Drive f: (SIK) (Fixed) (Total:200 GB) (Free:139.36 GB) NTFS Drive g: (SONST) (Fixed) (Total:531.51 GB) (Free:381.77 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 3A8E3A8D) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: C0901677) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=118.9 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
05.02.2015, 08:33 | #6 |
/// the machine /// TB-Ausbilder | TR/dldr.bagle.ay von Avira gefunden, was ist das? Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> TR/dldr.bagle.ay von Avira gefunden, was ist das? |
05.02.2015, 18:18 | #7 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? mbam.txt: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 05.02.2015 Suchlauf-Zeit: 17:53:53 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.02.05.08 Rootkit Datenbank: v2015.02.03.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Johannes Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 424365 Verstrichene Zeit: 5 Min, 15 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 0 (Keine schädliche Elemente erkannt) Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) AdwCleaner[S0].txt: Code:
ATTFilter # AdwCleaner v4.109 - Bericht erstellt am 05/02/2015 um 18:05:47 # Aktualisiert 24/01/2015 von Xplode # Database : 2015-02-04.1 [Live] # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Johannes - JOH # Gestartet von : E:\Daten\Download\AdwCleaner_4.109.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\AskPartnerNetwork Ordner Gelöscht : C:\Program Files (x86)\AskPartnerNetwork Ordner Gelöscht : C:\Users\Johannes\AppData\Local\Temp\apn Datei Gelöscht : C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\foxydeal.sqlite ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41564952-412D-5637-00A7-7A786E7484D7} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41564952-412D-5637-00A7-7A786E7484D7} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{41564952-412D-5637-00A7-7A786E7484D7}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D} Schlüssel Gelöscht : HKCU\Software\AskPartnerNetwork Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\SOFTWARE\AskPartnerNetwork Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local> ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17416 -\\ Mozilla Firefox v35.0.1 (x86 de) -\\ Google Chrome v40.0.2214.94 ************************* AdwCleaner[R0].txt - [3598 octets] - [05/02/2015 18:03:14] AdwCleaner[S0].txt - [3393 octets] - [05/02/2015 18:05:47] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3453 octets] ########## JRT.txt: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.2 (02.02.2015:1) OS: Windows 8.1 x64 Ran by Johannes on 05.02.2015 at 18:10:38,09 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\WINDOWS\Tasks\DriverToolkit Autorun.job ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Johannes\AppData\Roaming\mozilla\firefox\profiles\1o4elyyo.default\minidumps [68 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.02.2015 at 18:11:51,78 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2015 01 Ran by Johannes (administrator) on JOH on 05-02-2015 18:16:31 Running from E:\Daten\Download Loaded Profiles: Johannes (Available profiles: Johannes) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SUPERAntiSpyware.com) G:\SASCORE64.EXE (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Nero AG) G:\Program Files (x86)\HSMServiceEntry.exe () C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () G:\Program Files (x86)\HTC Sync\adb.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Electronic Arts) G:\Origin\Origin.exe (Valve Corporation) G:\Program Files (x86)\Steam\Steam.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Autodesk Inc.) C:\Users\Johannes\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Valve Corporation) G:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-27] (Realtek Semiconductor) HKLM\...\Run: [MBCfg64] => C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\MBCfg64.dll,RunDLLEntry MBCfg64 HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation) HKLM-x32\...\Run: [CommandCenter] => C:\Program Files (x86)\MSI\CommandCenter\StartCommandCenter.exe [797680 2013-06-19] () HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [488328 2014-09-04] (Autodesk Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [EADM] => G:\Origin\Origin.exe [3619160 2015-01-27] (Electronic Arts) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Steam] => G:\Program Files (x86)\Steam\Steam.exe [1942720 2015-01-23] (Valve Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [SUPERAntiSpyware] => G:\SUPERAntiSpyware.exe [7780120 2015-02-04] (SUPERAntiSpyware) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {0182337f-ac65-11e4-8176-d43d7ee34be9} - "H:\LGAutoRun.exe" HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {8f88013a-7b8c-11e3-bf31-fbc38769574a} - "M:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {e4fd87da-0abb-11e4-8053-e47334489d3d} - "H:\LGAutoRun.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default FF DefaultSearchEngine: LEO Eng-Deu FF SelectedSearchEngine: Bing FF Homepage: google.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: ubisoft.com/uplaypc -> G:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-maps.xml FF Extension: Better Battlelog (BBLog) - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack [2015-01-27] FF Extension: WOT - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: ProxTube - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11] FF Extension: Restartless Restart - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\restartless.restart@erikvold.com.xpi [2013-10-22] FF Extension: Google Translator for Firefox - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\translator@zoli.bod.xpi [2014-07-26] FF Extension: NoScript - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-28] FF Extension: Adblock Plus - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-22] FF Extension: BetterPrivacy - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-10-22] FF HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> hxxp://freebitco.in/ CHR Profile: C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-14] CHR Extension: (Google Drive) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-14] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-25] CHR Extension: (YouTube) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-14] CHR Extension: (Google-Suche) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-14] CHR Extension: (ThemeBeta.com) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnomoddmmgfhcejjblojoaandlmkfmla [2015-01-27] CHR Extension: (Google Wallet) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-14] CHR Extension: (Google Mail) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-14] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; G:\SASCORE64.EXE [172344 2014-08-13] (SUPERAntiSpyware.com) R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [597896 2014-09-04] (Autodesk Inc.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-12-16] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [610688 2014-10-29] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation) R2 HTCMonitorService; G:\Program Files (x86)\HSMServiceEntry.exe [87368 2014-04-02] (Nero AG) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S3 mi-raysat_3dsmax2015_64; G:\Program Files (x86)\3dMax\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [86016 2011-09-15] () [File not signed] S2 MSIBIOSData_CC; C:\Program Files (x86)\MSI\CommandCenter\BIOSData\MSIBIOSDataService.exe [2055680 2013-06-06] (MSI) [File not signed] S2 MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\MSIClockService.exe [305152 2013-06-19] () [File not signed] S2 MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\MSICommService.exe [2104832 2013-06-24] () [File not signed] S2 MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\MSICPUService.exe [4101120 2013-06-19] () [File not signed] R2 MSICTL_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe [1982976 2013-06-24] () [File not signed] S2 MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\MSIDDRService.exe [2237440 2013-06-19] () [File not signed] S2 MSISaveLoad_CC; C:\Program Files (x86)\MSI\CommandCenter\MSISaveLoadService.exe [3957248 2013-04-18] () [File not signed] S2 MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\MSISMBService.exe [175616 2013-05-28] () [File not signed] S2 MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\MSISuperIOService.exe [481280 2013-06-19] () [File not signed] S2 MSIWMI_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIWMIService.exe [181760 2013-04-18] () [File not signed] R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833544 2015-01-16] (NVIDIA Corporation) S3 Origin Client Service; G:\Origin\OriginClientService.exe [1910128 2015-01-27] (Electronic Arts) S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2015-02-04] () S2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [291496 2015-02-04] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2013-04-30] () [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [15888 2013-04-01] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AcpiCtlDrv; C:\Windows\System32\drivers\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43064 2014-10-14] (Avira Operations GmbH & Co. KG) S1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2013-04-30] (Qualcomm Atheros, Inc.) S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.) S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [25448 2013-01-07] (Intel Corporation) R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [174448 2013-04-30] (Qualcomm Atheros, Inc.) R3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI) R3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\NTIOLib_X64.sys [13368 2012-11-19] (MSI) R3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI) R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI) S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MSI) S3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MSI) S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI) S3 NTIOLib_MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\NTIOLib_X64.sys [13368 2012-11-19] (MSI) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3068120 2014-01-10] (Realtek Semiconductor Corporation ) R1 SASDIFSV; G:\\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; G:\\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-05 18:11 - 2015-02-05 18:11 - 00000827 _____ () C:\Users\Johannes\Desktop\JRT.txt 2015-02-05 18:02 - 2015-02-05 18:05 - 00000000 ____D () C:\AdwCleaner 2015-02-05 17:52 - 2015-02-05 17:52 - 00001117 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-04 23:57 - 2015-02-04 23:57 - 00000651 _____ () C:\Users\Public\Desktop\Battlefield Hardline Beta.lnk 2015-02-04 23:57 - 2015-02-04 23:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield Hardline Beta 2015-02-04 21:55 - 2015-02-04 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-02-04 18:14 - 2015-02-04 18:14 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Microsoft_Corporation 2015-02-04 17:27 - 2015-02-04 17:27 - 00000000 ____D () C:\Program Files (x86)\LG Electronics 2015-01-31 21:58 - 2015-01-31 21:58 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp 2015-01-31 21:58 - 2015-01-13 05:15 - 01540240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 32102544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 25459856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 24765584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 20465296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13295552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13210248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10774544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10714488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10274448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2015-01-31 21:58 - 2015-01-10 09:07 - 03607184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 03245712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01895240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01556808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00994712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00969360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00942736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00929424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00906384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00877488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00833864 _____ () C:\WINDOWS\system32\nvmcumd.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00496456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00399688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00390472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00353040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00345744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00305320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00177624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00164568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2015-01-31 21:58 - 2015-01-09 23:27 - 00621200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2015-01-27 23:19 - 2015-01-27 23:19 - 00000049 _____ () C:\WINDOWS\SysWOW64\ScrRecX.log 2015-01-27 23:19 - 2008-08-18 18:18 - 00077824 _____ (Fox Magic Software) C:\WINDOWS\SysWOW64\fmcodec.DLL 2015-01-27 13:36 - 2015-01-27 13:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-01-14 22:05 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2015-01-14 22:05 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2015-01-14 22:05 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-01-14 22:05 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2015-01-14 22:05 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2015-01-14 22:05 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-01-14 22:05 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2015-01-14 22:05 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2015-01-14 22:05 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-01-14 22:05 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-05 18:16 - 2014-09-09 13:59 - 00000000 ____D () C:\FRST 2015-02-05 18:16 - 2013-10-16 21:57 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-597342630-187561070-3433799475-1001 2015-02-05 18:10 - 2013-09-30 05:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-02-05 18:10 - 2013-09-30 04:56 - 00750632 _____ () C:\WINDOWS\system32\perfh007.dat 2015-02-05 18:10 - 2013-09-30 04:56 - 00155144 _____ () C:\WINDOWS\system32\perfc007.dat 2015-02-05 18:08 - 2014-05-14 15:30 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-05 18:08 - 2013-10-21 21:01 - 00000000 ____D () C:\ProgramData\Origin 2015-02-05 18:06 - 2014-08-14 13:03 - 00024814 _____ () C:\WINDOWS\PFRO.log 2015-02-05 18:06 - 2014-08-02 12:47 - 00043366 _____ () C:\WINDOWS\setupact.log 2015-02-05 18:06 - 2013-10-20 22:37 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-02-05 18:06 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-02-05 18:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-02-05 17:57 - 2014-05-14 15:30 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-05 17:53 - 2014-09-09 13:21 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-02-05 17:52 - 2014-09-09 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-02-05 17:52 - 2014-09-09 13:21 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-05 17:51 - 2013-10-30 14:52 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-02-05 17:47 - 2014-07-09 12:51 - 01743081 _____ () C:\WINDOWS\WindowsUpdate.log 2015-02-05 17:27 - 2014-09-08 20:48 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Akamai 2015-02-05 00:18 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-02-04 23:57 - 2014-09-06 18:01 - 00178191 _____ () C:\WINDOWS\DirectX.log 2015-02-04 23:57 - 2013-12-09 18:43 - 00291496 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2015-02-04 23:57 - 2013-12-09 18:43 - 00076152 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2015-02-04 23:57 - 2013-10-21 21:39 - 00291496 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2015-02-04 23:16 - 2013-10-22 15:11 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\TS3Client 2015-02-04 21:35 - 2014-12-21 00:04 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Arma 3 2015-02-04 19:51 - 2013-10-30 14:52 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-02-03 17:59 - 2013-12-08 19:01 - 00000072 _____ () C:\Users\Public\LMDebug.log 2015-02-03 15:54 - 2013-10-18 21:55 - 00000000 ____D () C:\ProgramData\Bigfoot Networks 2015-01-31 21:59 - 2014-10-08 14:12 - 00000000 ____D () C:\TEMP 2015-01-31 21:59 - 2013-10-18 22:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-01-31 16:55 - 2013-10-21 21:44 - 00348928 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2015-01-31 16:46 - 2014-05-24 14:42 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\vlc 2015-01-28 14:49 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-01-28 13:33 - 2013-10-30 15:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 23:19 - 2014-06-14 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher 2015-01-27 23:19 - 2013-11-05 17:40 - 00000919 _____ () C:\Users\Public\Desktop\aTube Catcher.lnk 2015-01-24 21:20 - 2014-04-29 22:34 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-01-24 21:20 - 2014-04-29 22:34 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-21 13:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-01-16 20:41 - 2014-12-22 19:23 - 00000000 ____D () C:\Users\Johannes\AppData\Local\ftblauncher 2015-01-16 07:41 - 2014-06-03 13:15 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2015-01-16 07:41 - 2014-06-03 13:15 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01514528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01278920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2015-01-16 00:44 - 2013-12-08 22:40 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Skype 2015-01-15 20:43 - 2014-03-14 19:53 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-01-15 20:43 - 2013-12-08 22:40 - 00000000 ____D () C:\ProgramData\Skype 2015-01-15 17:49 - 2013-10-20 11:35 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-01-15 17:48 - 2013-10-20 11:35 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-01-15 17:48 - 2013-08-22 14:25 - 00008192 ___SH () C:\WINDOWS\system32\config\ELAM 2015-01-14 00:35 - 2014-11-09 23:29 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Mp3tag 2015-01-10 09:07 - 2014-12-16 19:59 - 17250776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2015-01-10 09:07 - 2014-12-16 19:59 - 16009120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 18566296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 14115944 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 03298816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 02902456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 00027441 _____ () C:\WINDOWS\system32\nvinfo.pb 2015-01-10 00:30 - 2013-10-20 22:37 - 06860432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2015-01-10 00:30 - 2013-10-20 22:37 - 03517256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00935056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2015-01-10 00:29 - 2013-10-20 22:37 - 00385352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2015-01-09 20:47 - 2013-10-20 22:37 - 04173527 _____ () C:\WINDOWS\system32\nvcoproc.bin ==================== Files in the root of some directories ======= 2014-07-16 14:30 - 2014-07-16 14:30 - 0001456 _____ () C:\Users\Johannes\AppData\Local\Adobe Für Web speichern 11.0 Prefs 2013-10-18 17:13 - 2013-10-18 22:01 - 0001008 _____ () C:\Users\Johannes\AppData\Local\killertool.log 2013-10-18 23:18 - 2014-09-09 15:57 - 0007651 _____ () C:\Users\Johannes\AppData\Local\Resmon.ResmonCfg 2013-10-18 17:21 - 2013-10-21 10:12 - 0062352 _____ () C:\ProgramData\dxdiag.txt Some content of TEMP: ==================== C:\Users\Johannes\AppData\Local\Temp\avgnt.exe C:\Users\Johannes\AppData\Local\Temp\camtasiade.exe C:\Users\Johannes\AppData\Local\Temp\drm_dyndata_7380014.dll C:\Users\Johannes\AppData\Local\Temp\exe2pin.exe C:\Users\Johannes\AppData\Local\Temp\jansi-32-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Johannes\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Johannes\AppData\Local\Temp\nvStInst.exe C:\Users\Johannes\AppData\Local\Temp\procexp0364.exe C:\Users\Johannes\AppData\Local\Temp\Quarantine.exe C:\Users\Johannes\AppData\Local\Temp\sdanircmdc.exe C:\Users\Johannes\AppData\Local\Temp\sdapskill.exe C:\Users\Johannes\AppData\Local\Temp\sdaspwn.exe C:\Users\Johannes\AppData\Local\Temp\sHID.dll C:\Users\Johannes\AppData\Local\Temp\sonarinst.exe C:\Users\Johannes\AppData\Local\Temp\sqlite3.dll C:\Users\Johannes\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-04 13:17 ==================== End Of Log ============================ --- --- --- |
06.02.2015, 07:26 | #8 |
/// the machine /// TB-Ausbilder | TR/dldr.bagle.ay von Avira gefunden, was ist das?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.02.2015, 16:34 | #9 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? log.txt Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=5b4daa3b6f59fa4480a76d2f503648cf # engine=22341 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-06 03:12:12 # local_time=2015-02-06 04:12:12 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 7405013 82741643 0 0 # scanned=453798 # found=13 # cleaned=0 # scan_time=6270 sh=FB3F7E2BF56F5EA06763303CDAA0E962E975E063 ft=1 fh=c0dea5299389dc4e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Johannes\AppData\Local\Temp\DMR\dmr_72.exe" sh=9A07E735581D0CCB8793CB38B7BEC115E6C766F7 ft=1 fh=baca106c4a9b1082 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\Audacity - CHIP-Installer.exe" sh=161C8D5BDE6572A7301ABC31BAC582051E56343A ft=1 fh=2d189c213637ddf6 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\Biet O Matic - CHIP-Installer.exe" sh=8B841B46D3B230027DF38AE56C768CD7A9B0873E ft=1 fh=b67d5bc088f403f7 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\BlueStacks App Player - CHIP-Installer.exe" sh=96F698048672C30FBDB2E529EEB7650C9FDEC25A ft=1 fh=0869f1009151abbd vn="Variante von Win32/WinloadSDA.I evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\Camtasia-Studio-lnstall.exe" sh=1463B84282FF3DF69FC6CC40E9EEF30F6A40DAC5 ft=1 fh=42f41ca6b97fe444 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\Fast IP Changer - CHIP-Installer.exe" sh=D0845097CF6B09769A99F396C0BDA3093C0B7C92 ft=1 fh=43b1ac72f17e7fd8 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\mp3DirectCut - CHIP-Installer.exe" sh=6322A6D11D280665D99E87F67295C921F787C029 ft=1 fh=98f17a51123516d6 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\Ping Plotter Free - CHIP-Installer.exe" sh=BC8EB192DD0183AC32B1E01583A8A7A45E820FF2 ft=1 fh=552ea0299696d972 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\Process Explorer - CHIP-Installer.exe" sh=AE542600B84F68DE95B3D8AAA32BBD07BDD3C324 ft=1 fh=f057117ac7e11de9 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer(1).exe" sh=46E099661AC8AAF11001AFCE4F6EEA81324A0CDB ft=1 fh=043603fa88ca0f6e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer.exe" sh=DC9700B8AE790DD021F839BC00F8EFCAA88F8FE0 ft=1 fh=8a70fc65eb14ec6b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\Tor Browser Paket - CHIP-Installer.exe" sh=1F8DAC5C7E9F9ED9F48C40107385D006DC17A31F ft=1 fh=aad5ed9d50cdd4f1 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="E:\Daten\Download\TrackMania Nations Forever - CHIP-Installer.exe" checkup.txt Code:
ATTFilter Results of screen317's Security Check version 0.99.95 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 67 Java 8 Update 25 Java version 32-bit out of Date! Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Mozilla Firefox (35.0.1) Google Chrome (40.0.2214.93) Google Chrome (40.0.2214.94) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Probleme gibts sonst keine mehr, wenn der Virus dann weg ist Nur frag ich mich noch 2 Sachen... Erstens sind die Schritte mit den Programmen eigentlich nur nötig um zu versichern dass wirklich alles weg ist oder löschen die den Virus letztendlich auch, weil ich hab den ja eigentlich mit Avira schon gelöscht als es den erkannt hat? Es wär doch eigentlich schon recht madig wenn Avira Premium, für welches man ja bezahlt, es nicht schafft den Virus den es erkennt unschädlich zu machen, obwohl ja die Technik anscheinend vorhanden ist? und zweitens immer wenn ich einen Virus hab frag ich mich was der eigentlich macht, gibts da irgentwo eine Seite o.ä. wo sowas nachlesbar ist, bzw. was hat denn der TR/dldr.bagle.ay nun letztendlich auf meinem PC gemacht? |
07.02.2015, 11:05 | #10 |
/// the machine /// TB-Ausbilder | TR/dldr.bagle.ay von Avira gefunden, was ist das? Das frische FRST log fehlt noch. WIr haben mit den Tools auch Malware entfernt. Malware erkennen und beseitigen sind 2 paar Schuhe. Manuell entfernen is immer besser. Du kannst zu jeder Malware, wenn Du den Namen in Google eingibst, nen Datenblatt finden, was die macht. Aber ob die dann auch in der Praxis, auf deinem Rechner so agiert, muss nicht sein.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.02.2015, 19:23 | #11 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? ah stimmt die hab ich vergessen hier FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015 Ran by Johannes (administrator) on JOH on 08-02-2015 19:21:35 Running from E:\Daten\Download Loaded Profiles: Johannes (Available profiles: Johannes) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SUPERAntiSpyware.com) G:\SASCORE64.EXE (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Nero AG) G:\Program Files (x86)\HSMServiceEntry.exe () C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe () C:\Program Files (x86)\MSI\CommandCenter\MSISaveLoadService.exe () G:\Program Files (x86)\HTC Sync\adb.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Electronic Arts) G:\Origin\Origin.exe (Valve Corporation) G:\Program Files (x86)\Steam\Steam.exe (SUPERAntiSpyware) G:\SUPERANTISPYWARE.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Autodesk Inc.) C:\Users\Johannes\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Valve Corporation) G:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Valve Corporation) G:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-27] (Realtek Semiconductor) HKLM\...\Run: [MBCfg64] => C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\MBCfg64.dll,RunDLLEntry MBCfg64 HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation) HKLM-x32\...\Run: [CommandCenter] => C:\Program Files (x86)\MSI\CommandCenter\StartCommandCenter.exe [797680 2013-06-19] () HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [488328 2014-09-04] (Autodesk Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [EADM] => G:\Origin\Origin.exe [3619160 2015-01-27] (Electronic Arts) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Steam] => G:\Program Files (x86)\Steam\Steam.exe [1942720 2015-01-23] (Valve Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [SUPERAntiSpyware] => G:\SUPERAntiSpyware.exe [7780120 2015-02-04] (SUPERAntiSpyware) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {0182337f-ac65-11e4-8176-d43d7ee34be9} - "H:\LGAutoRun.exe" HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {8f88013a-7b8c-11e3-bf31-fbc38769574a} - "M:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {e4fd87da-0abb-11e4-8053-e47334489d3d} - "H:\LGAutoRun.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default FF DefaultSearchEngine: Bing FF SelectedSearchEngine: Bing FF Homepage: google.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: ubisoft.com/uplaypc -> G:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-maps.xml FF Extension: Better Battlelog (BBLog) - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack [2015-01-27] FF Extension: WOT - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: ProxTube - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11] FF Extension: Restartless Restart - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\restartless.restart@erikvold.com.xpi [2013-10-22] FF Extension: Google Translator for Firefox - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\translator@zoli.bod.xpi [2014-07-26] FF Extension: NoScript - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-28] FF Extension: Adblock Plus - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-22] FF Extension: BetterPrivacy - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-10-22] FF HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> hxxp://freebitco.in/ CHR Profile: C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-14] CHR Extension: (Google Drive) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-14] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-25] CHR Extension: (YouTube) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-14] CHR Extension: (Google-Suche) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-14] CHR Extension: (ThemeBeta.com) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnomoddmmgfhcejjblojoaandlmkfmla [2015-01-27] CHR Extension: (Google Wallet) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-14] CHR Extension: (Google Mail) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-14] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; G:\SASCORE64.EXE [172344 2014-08-13] (SUPERAntiSpyware.com) R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [597896 2014-09-04] (Autodesk Inc.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-12-16] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [610688 2014-10-29] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation) R2 HTCMonitorService; G:\Program Files (x86)\HSMServiceEntry.exe [87368 2014-04-02] (Nero AG) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S3 mi-raysat_3dsmax2015_64; G:\Program Files (x86)\3dMax\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [86016 2011-09-15] () [File not signed] S2 MSIBIOSData_CC; C:\Program Files (x86)\MSI\CommandCenter\BIOSData\MSIBIOSDataService.exe [2055680 2013-06-06] (MSI) [File not signed] S2 MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\MSIClockService.exe [305152 2013-06-19] () [File not signed] S2 MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\MSICommService.exe [2104832 2013-06-24] () [File not signed] S2 MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\MSICPUService.exe [4101120 2013-06-19] () [File not signed] R2 MSICTL_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe [1982976 2013-06-24] () [File not signed] S2 MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\MSIDDRService.exe [2237440 2013-06-19] () [File not signed] R2 MSISaveLoad_CC; C:\Program Files (x86)\MSI\CommandCenter\MSISaveLoadService.exe [3957248 2013-04-18] () [File not signed] S2 MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\MSISMBService.exe [175616 2013-05-28] () [File not signed] S2 MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\MSISuperIOService.exe [481280 2013-06-19] () [File not signed] S2 MSIWMI_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIWMIService.exe [181760 2013-04-18] () [File not signed] R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833544 2015-01-16] (NVIDIA Corporation) S3 Origin Client Service; G:\Origin\OriginClientService.exe [1910128 2015-01-27] (Electronic Arts) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2015-02-04] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2013-04-30] () [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [15888 2013-04-01] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AcpiCtlDrv; C:\Windows\System32\drivers\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43064 2014-10-14] (Avira Operations GmbH & Co. KG) S1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2013-04-30] (Qualcomm Atheros, Inc.) S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.) S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [25448 2013-01-07] (Intel Corporation) R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [174448 2013-04-30] (Qualcomm Atheros, Inc.) R3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI) R3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\NTIOLib_X64.sys [13368 2012-11-19] (MSI) R3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI) R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI) S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MSI) S3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MSI) S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI) S3 NTIOLib_MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\NTIOLib_X64.sys [13368 2012-11-19] (MSI) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3068120 2014-01-10] (Realtek Semiconductor Corporation ) R1 SASDIFSV; G:\\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; G:\\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-06 14:21 - 2015-02-06 14:21 - 00000000 ____D () C:\Program Files (x86)\ESET 2015-02-05 18:11 - 2015-02-05 18:11 - 00000827 _____ () C:\Users\Johannes\Desktop\JRT.txt 2015-02-05 18:02 - 2015-02-05 18:05 - 00000000 ____D () C:\AdwCleaner 2015-02-05 17:52 - 2015-02-05 17:52 - 00001117 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-04 23:57 - 2015-02-04 23:57 - 00000651 _____ () C:\Users\Public\Desktop\Battlefield Hardline Beta.lnk 2015-02-04 23:57 - 2015-02-04 23:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield Hardline Beta 2015-02-04 21:55 - 2015-02-04 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-02-04 18:14 - 2015-02-04 18:14 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Microsoft_Corporation 2015-02-04 17:27 - 2015-02-04 17:27 - 00000000 ____D () C:\Program Files (x86)\LG Electronics 2015-01-31 21:58 - 2015-01-13 05:15 - 01540240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 32102544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 25459856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 24765584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 20465296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13295552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13210248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10774544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10714488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10274448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2015-01-31 21:58 - 2015-01-10 09:07 - 03607184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 03245712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01895240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01556808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00994712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00969360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00942736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00929424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00906384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00877488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00833864 _____ () C:\WINDOWS\system32\nvmcumd.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00496456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00399688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00390472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00353040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00345744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00305320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00177624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00164568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2015-01-31 21:58 - 2015-01-09 23:27 - 00621200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2015-01-27 23:19 - 2015-01-27 23:19 - 00000049 _____ () C:\WINDOWS\SysWOW64\ScrRecX.log 2015-01-27 23:19 - 2008-08-18 18:18 - 00077824 _____ (Fox Magic Software) C:\WINDOWS\SysWOW64\fmcodec.DLL 2015-01-27 13:36 - 2015-01-27 13:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-01-14 22:05 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2015-01-14 22:05 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2015-01-14 22:05 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-01-14 22:05 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2015-01-14 22:05 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2015-01-14 22:05 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-01-14 22:05 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2015-01-14 22:05 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2015-01-14 22:05 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-01-14 22:05 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-08 19:21 - 2014-09-09 13:59 - 00000000 ____D () C:\FRST 2015-02-08 19:03 - 2014-05-14 15:30 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-08 19:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-02-08 18:51 - 2013-10-30 14:52 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-02-08 18:51 - 2013-10-22 15:11 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\TS3Client 2015-02-08 18:32 - 2014-07-09 12:51 - 01736816 _____ () C:\WINDOWS\WindowsUpdate.log 2015-02-08 15:44 - 2014-09-08 20:48 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Akamai 2015-02-08 10:49 - 2013-09-30 05:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-02-08 10:49 - 2013-09-30 04:56 - 00750632 _____ () C:\WINDOWS\system32\perfh007.dat 2015-02-08 10:49 - 2013-09-30 04:56 - 00155144 _____ () C:\WINDOWS\system32\perfc007.dat 2015-02-08 10:45 - 2013-10-21 21:01 - 00000000 ____D () C:\ProgramData\Origin 2015-02-08 10:44 - 2014-08-02 12:47 - 00044059 _____ () C:\WINDOWS\setupact.log 2015-02-08 10:44 - 2014-05-14 15:30 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-08 10:44 - 2013-10-20 22:37 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-02-08 10:44 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-02-08 03:25 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-02-07 20:50 - 2014-12-21 00:04 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Arma 3 2015-02-07 20:49 - 2013-10-18 22:12 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-07 18:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-02-07 13:37 - 2013-10-16 21:57 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-597342630-187561070-3433799475-1001 2015-02-06 14:27 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-02-05 22:58 - 2014-05-14 15:30 - 00004098 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-05 22:58 - 2014-05-14 15:30 - 00003862 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-05 21:13 - 2013-12-09 18:43 - 00226680 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2015-02-05 20:59 - 2013-10-21 21:44 - 00000000 ____D () C:\Users\Johannes\AppData\Local\PunkBuster 2015-02-05 20:59 - 2013-10-21 21:39 - 00226680 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2015-02-05 18:06 - 2014-08-14 13:03 - 00024814 _____ () C:\WINDOWS\PFRO.log 2015-02-05 17:53 - 2014-09-09 13:21 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-02-05 17:52 - 2014-09-09 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-02-05 17:52 - 2014-09-09 13:21 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-04 23:57 - 2014-09-06 18:01 - 00178191 _____ () C:\WINDOWS\DirectX.log 2015-02-04 23:57 - 2013-12-09 18:43 - 00076152 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2015-02-04 19:51 - 2013-10-30 14:52 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-02-03 20:31 - 2014-04-29 22:34 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-02-03 20:31 - 2014-04-29 22:34 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-03 17:59 - 2013-12-08 19:01 - 00000072 _____ () C:\Users\Public\LMDebug.log 2015-02-03 15:54 - 2013-10-18 21:55 - 00000000 ____D () C:\ProgramData\Bigfoot Networks 2015-01-31 21:59 - 2014-10-08 14:12 - 00000000 ____D () C:\TEMP 2015-01-31 21:59 - 2013-10-18 22:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-01-31 16:55 - 2013-10-21 21:44 - 00348928 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2015-01-31 16:46 - 2014-05-24 14:42 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\vlc 2015-01-28 13:33 - 2013-10-30 15:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 23:19 - 2014-06-14 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher 2015-01-27 23:19 - 2013-11-05 17:40 - 00000919 _____ () C:\Users\Public\Desktop\aTube Catcher.lnk 2015-01-16 20:41 - 2014-12-22 19:23 - 00000000 ____D () C:\Users\Johannes\AppData\Local\ftblauncher 2015-01-16 07:41 - 2014-06-03 13:15 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2015-01-16 07:41 - 2014-06-03 13:15 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01514528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01278920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2015-01-16 00:44 - 2013-12-08 22:40 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Skype 2015-01-15 20:43 - 2014-03-14 19:53 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-01-15 20:43 - 2013-12-08 22:40 - 00000000 ____D () C:\ProgramData\Skype 2015-01-15 17:49 - 2013-10-20 11:35 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-01-15 17:48 - 2013-10-20 11:35 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-01-15 17:48 - 2013-08-22 14:25 - 00008192 ___SH () C:\WINDOWS\system32\config\ELAM 2015-01-14 00:35 - 2014-11-09 23:29 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Mp3tag 2015-01-10 09:07 - 2014-12-16 19:59 - 17250776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2015-01-10 09:07 - 2014-12-16 19:59 - 16009120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 18566296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 14115944 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 03298816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 02902456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 00027441 _____ () C:\WINDOWS\system32\nvinfo.pb 2015-01-10 00:30 - 2013-10-20 22:37 - 06860432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2015-01-10 00:30 - 2013-10-20 22:37 - 03517256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00935056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2015-01-10 00:29 - 2013-10-20 22:37 - 00385352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2015-01-09 20:47 - 2013-10-20 22:37 - 04173527 _____ () C:\WINDOWS\system32\nvcoproc.bin ==================== Files in the root of some directories ======= 2014-07-16 14:30 - 2014-07-16 14:30 - 0001456 _____ () C:\Users\Johannes\AppData\Local\Adobe Für Web speichern 11.0 Prefs 2013-10-18 17:13 - 2013-10-18 22:01 - 0001008 _____ () C:\Users\Johannes\AppData\Local\killertool.log 2013-10-18 23:18 - 2014-09-09 15:57 - 0007651 _____ () C:\Users\Johannes\AppData\Local\Resmon.ResmonCfg 2013-10-18 17:21 - 2013-10-21 10:12 - 0062352 _____ () C:\ProgramData\dxdiag.txt Some content of TEMP: ==================== C:\Users\Johannes\AppData\Local\Temp\avgnt.exe C:\Users\Johannes\AppData\Local\Temp\camtasiade.exe C:\Users\Johannes\AppData\Local\Temp\drm_dyndata_7380014.dll C:\Users\Johannes\AppData\Local\Temp\exe2pin.exe C:\Users\Johannes\AppData\Local\Temp\jansi-32-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Johannes\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Johannes\AppData\Local\Temp\nvStInst.exe C:\Users\Johannes\AppData\Local\Temp\procexp0364.exe C:\Users\Johannes\AppData\Local\Temp\Quarantine.exe C:\Users\Johannes\AppData\Local\Temp\sdanircmdc.exe C:\Users\Johannes\AppData\Local\Temp\sdapskill.exe C:\Users\Johannes\AppData\Local\Temp\sdaspwn.exe C:\Users\Johannes\AppData\Local\Temp\sHID.dll C:\Users\Johannes\AppData\Local\Temp\sonarinst.exe C:\Users\Johannes\AppData\Local\Temp\sqlite3.dll C:\Users\Johannes\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-04 13:17 ==================== End Of Log ============================ |
09.02.2015, 06:40 | #12 |
/// the machine /// TB-Ausbilder | TR/dldr.bagle.ay von Avira gefunden, was ist das? Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Johannes\AppData\Local\Temp\DMR\dmr_72.exe E:\Daten\Download\Audacity - CHIP-Installer.exe E:\Daten\Download\Biet O Matic - CHIP-Installer.exe E:\Daten\Download\BlueStacks App Player - CHIP-Installer.exe E:\Daten\Download\Camtasia-Studio-lnstall.exe E:\Daten\Download\Fast IP Changer - CHIP-Installer.exe E:\Daten\Download\mp3DirectCut - CHIP-Installer.exe E:\Daten\Download\Ping Plotter Free - CHIP-Installer.exe E:\Daten\Download\Process Explorer - CHIP-Installer.exe E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer(1).exe E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer.exe E:\Daten\Download\Tor Browser Paket - CHIP-Installer.exe E:\Daten\Download\TrackMania Nations Forever - CHIP-Installer.exe Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.02.2015, 15:46 | #13 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? oh stimmt hab ich vergessen FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015 Ran by Johannes (administrator) on JOH on 09-02-2015 15:45:20 Running from E:\Daten\Download Loaded Profiles: Johannes (Available profiles: Johannes) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SUPERAntiSpyware.com) G:\SASCORE64.EXE (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Nero AG) G:\Program Files (x86)\HSMServiceEntry.exe () C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe () C:\Program Files (x86)\MSI\CommandCenter\MSISaveLoadService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () G:\Program Files (x86)\HTC Sync\adb.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Valve Corporation) G:\Program Files (x86)\Steam\Steam.exe (SUPERAntiSpyware) G:\SUPERANTISPYWARE.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Autodesk Inc.) C:\Users\Johannes\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Valve Corporation) G:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe (Intel(R) Corporation) C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-27] (Realtek Semiconductor) HKLM\...\Run: [MBCfg64] => C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\MBCfg64.dll,RunDLLEntry MBCfg64 HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation) HKLM-x32\...\Run: [CommandCenter] => C:\Program Files (x86)\MSI\CommandCenter\StartCommandCenter.exe [797680 2013-06-19] () HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd) HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [488328 2014-09-04] (Autodesk Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [EADM] => G:\Origin\Origin.exe [3619160 2015-01-27] (Electronic Arts) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Steam] => G:\Program Files (x86)\Steam\Steam.exe [1942720 2015-01-23] (Valve Corporation) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [SUPERAntiSpyware] => G:\SUPERAntiSpyware.exe [7780120 2015-02-04] (SUPERAntiSpyware) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Johannes\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {0182337f-ac65-11e4-8176-d43d7ee34be9} - "H:\LGAutoRun.exe" HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {8f88013a-7b8c-11e3-bf31-fbc38769574a} - "M:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\MountPoints2: {e4fd87da-0abb-11e4-8053-e47334489d3d} - "H:\LGAutoRun.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-597342630-187561070-3433799475-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default FF DefaultSearchEngine: LEO Eng-Deu FF SelectedSearchEngine: Bing FF Homepage: google.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-597342630-187561070-3433799475-1001: ubisoft.com/uplaypc -> G:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\searchplugins\google-maps.xml FF Extension: Better Battlelog (BBLog) - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack [2015-01-27] FF Extension: WOT - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: ProxTube - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11] FF Extension: Restartless Restart - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\restartless.restart@erikvold.com.xpi [2013-10-22] FF Extension: Google Translator for Firefox - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\translator@zoli.bod.xpi [2014-07-26] FF Extension: NoScript - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-28] FF Extension: Adblock Plus - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-22] FF Extension: BetterPrivacy - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-10-22] FF HKU\S-1-5-21-597342630-187561070-3433799475-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\1o4elyyo.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> hxxp://freebitco.in/ CHR Profile: C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-14] CHR Extension: (Google Drive) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-14] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-25] CHR Extension: (YouTube) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-14] CHR Extension: (Google-Suche) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-14] CHR Extension: (ThemeBeta.com) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnomoddmmgfhcejjblojoaandlmkfmla [2015-01-27] CHR Extension: (Google Wallet) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-14] CHR Extension: (Google Mail) - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-14] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; G:\SASCORE64.EXE [172344 2014-08-13] (SUPERAntiSpyware.com) R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [597896 2014-09-04] (Autodesk Inc.) R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-12-16] (Avira Operations GmbH & Co. KG) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [610688 2014-10-29] () R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation) R2 HTCMonitorService; G:\Program Files (x86)\HSMServiceEntry.exe [87368 2014-04-02] (Nero AG) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] S3 mi-raysat_3dsmax2015_64; G:\Program Files (x86)\3dMax\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [86016 2011-09-15] () [File not signed] S2 MSIBIOSData_CC; C:\Program Files (x86)\MSI\CommandCenter\BIOSData\MSIBIOSDataService.exe [2055680 2013-06-06] (MSI) [File not signed] S2 MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\MSIClockService.exe [305152 2013-06-19] () [File not signed] S2 MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\MSICommService.exe [2104832 2013-06-24] () [File not signed] S2 MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\MSICPUService.exe [4101120 2013-06-19] () [File not signed] R2 MSICTL_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe [1982976 2013-06-24] () [File not signed] S2 MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\MSIDDRService.exe [2237440 2013-06-19] () [File not signed] R2 MSISaveLoad_CC; C:\Program Files (x86)\MSI\CommandCenter\MSISaveLoadService.exe [3957248 2013-04-18] () [File not signed] S2 MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\MSISMBService.exe [175616 2013-05-28] () [File not signed] S2 MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\MSISuperIOService.exe [481280 2013-06-19] () [File not signed] S2 MSIWMI_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIWMIService.exe [181760 2013-04-18] () [File not signed] R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833544 2015-01-16] (NVIDIA Corporation) S3 Origin Client Service; G:\Origin\OriginClientService.exe [1910128 2015-01-27] (Electronic Arts) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2015-02-04] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2013-04-30] () [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe [15888 2013-04-01] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 AcpiCtlDrv; C:\Windows\System32\drivers\AcpiCtlDrv.sys [25880 2012-07-17] (Intel Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43064 2014-10-14] (Avira Operations GmbH & Co. KG) S1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2013-04-30] (Qualcomm Atheros, Inc.) S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-09-04] (LogMeIn Inc.) S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [25448 2013-01-07] (Intel Corporation) R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [174448 2013-04-30] (Qualcomm Atheros, Inc.) R3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI) R3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\NTIOLib_X64.sys [13368 2012-11-19] (MSI) R3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI) R3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI) S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MSI) S3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MSI) R3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3068120 2014-01-10] (Realtek Semiconductor Corporation ) R1 SASDIFSV; G:\\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; G:\\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-06 14:21 - 2015-02-06 14:21 - 00000000 ____D () C:\Program Files (x86)\ESET 2015-02-05 18:11 - 2015-02-05 18:11 - 00000827 _____ () C:\Users\Johannes\Desktop\JRT.txt 2015-02-05 18:02 - 2015-02-05 18:05 - 00000000 ____D () C:\AdwCleaner 2015-02-05 17:52 - 2015-02-05 17:52 - 00001117 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-02-04 23:57 - 2015-02-04 23:57 - 00000651 _____ () C:\Users\Public\Desktop\Battlefield Hardline Beta.lnk 2015-02-04 23:57 - 2015-02-04 23:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield Hardline Beta 2015-02-04 21:55 - 2015-02-04 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-02-04 18:14 - 2015-02-04 18:14 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Microsoft_Corporation 2015-02-04 17:27 - 2015-02-04 17:27 - 00000000 ____D () C:\Program Files (x86)\LG Electronics 2015-01-31 21:58 - 2015-01-13 05:15 - 01540240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 32102544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 25459856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 24765584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 20465296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13295552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 13210248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10774544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10714488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 10274448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys 2015-01-31 21:58 - 2015-01-10 09:07 - 03607184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 03245712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01895240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 01556808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434725.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00994712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00969360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00942736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00929424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00906384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00877488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00833864 _____ () C:\WINDOWS\system32\nvmcumd.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00496456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00399688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00390472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00353040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00345744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00305320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00177624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll 2015-01-31 21:58 - 2015-01-10 09:07 - 00164568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll 2015-01-31 21:58 - 2015-01-09 23:27 - 00621200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe 2015-01-27 23:19 - 2015-01-27 23:19 - 00000049 _____ () C:\WINDOWS\SysWOW64\ScrRecX.log 2015-01-27 23:19 - 2008-08-18 18:18 - 00077824 _____ (Fox Magic Software) C:\WINDOWS\SysWOW64\fmcodec.DLL 2015-01-27 13:36 - 2015-01-27 13:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-01-15 20:43 - 2015-01-15 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-01-14 22:05 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2015-01-14 22:05 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2015-01-14 22:05 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-01-14 22:05 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll 2015-01-14 22:05 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-01-14 22:05 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2015-01-14 22:05 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2015-01-14 22:05 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-01-14 22:05 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2015-01-14 22:05 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2015-01-14 22:05 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2015-01-14 22:05 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-01-14 22:05 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2015-01-14 22:05 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2015-01-14 22:05 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2015-01-14 22:05 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-01-14 22:05 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-09 15:45 - 2014-09-09 13:59 - 00000000 ____D () C:\FRST 2015-02-09 15:06 - 2013-09-30 05:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-02-09 15:06 - 2013-09-30 04:56 - 00750632 _____ () C:\WINDOWS\system32\perfh007.dat 2015-02-09 15:06 - 2013-09-30 04:56 - 00155144 _____ () C:\WINDOWS\system32\perfc007.dat 2015-02-09 15:03 - 2014-05-14 15:30 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-09 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-02-09 14:51 - 2013-10-30 14:52 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-02-09 14:38 - 2014-07-09 12:51 - 01834449 _____ () C:\WINDOWS\WindowsUpdate.log 2015-02-09 14:12 - 2014-09-08 20:48 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Akamai 2015-02-09 14:11 - 2014-05-14 15:30 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-09 14:11 - 2013-10-21 21:01 - 00000000 ____D () C:\ProgramData\Origin 2015-02-09 14:10 - 2014-08-02 12:47 - 00044290 _____ () C:\WINDOWS\setupact.log 2015-02-09 14:10 - 2013-10-20 22:37 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-02-09 14:10 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-02-08 20:48 - 2013-10-22 15:11 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\TS3Client 2015-02-08 03:25 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-02-07 20:50 - 2014-12-21 00:04 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Arma 3 2015-02-07 20:49 - 2013-10-18 22:12 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-07 18:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-02-07 13:37 - 2013-10-16 21:57 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-597342630-187561070-3433799475-1001 2015-02-06 16:12 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-02-05 22:58 - 2014-05-14 15:30 - 00004098 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-05 22:58 - 2014-05-14 15:30 - 00003862 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-05 21:13 - 2013-12-09 18:43 - 00226680 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2015-02-05 20:59 - 2013-10-21 21:44 - 00000000 ____D () C:\Users\Johannes\AppData\Local\PunkBuster 2015-02-05 20:59 - 2013-10-21 21:39 - 00226680 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2015-02-05 18:06 - 2014-08-14 13:03 - 00024814 _____ () C:\WINDOWS\PFRO.log 2015-02-05 17:53 - 2014-09-09 13:21 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-02-05 17:52 - 2014-09-09 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-02-05 17:52 - 2014-09-09 13:21 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-02-04 23:57 - 2014-09-06 18:01 - 00178191 _____ () C:\WINDOWS\DirectX.log 2015-02-04 23:57 - 2013-12-09 18:43 - 00076152 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2015-02-04 19:51 - 2013-10-30 14:52 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-02-03 20:31 - 2014-04-29 22:34 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-02-03 20:31 - 2014-04-29 22:34 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-03 17:59 - 2013-12-08 19:01 - 00000072 _____ () C:\Users\Public\LMDebug.log 2015-02-03 15:54 - 2013-10-18 21:55 - 00000000 ____D () C:\ProgramData\Bigfoot Networks 2015-01-31 21:59 - 2014-10-08 14:12 - 00000000 ____D () C:\TEMP 2015-01-31 21:59 - 2013-10-18 22:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-01-31 16:55 - 2013-10-21 21:44 - 00348928 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2015-01-31 16:46 - 2014-05-24 14:42 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\vlc 2015-01-28 13:33 - 2013-10-30 15:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 23:19 - 2014-06-14 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher 2015-01-27 23:19 - 2013-11-05 17:40 - 00000919 _____ () C:\Users\Public\Desktop\aTube Catcher.lnk 2015-01-16 20:41 - 2014-12-22 19:23 - 00000000 ____D () C:\Users\Johannes\AppData\Local\ftblauncher 2015-01-16 07:41 - 2014-06-03 13:15 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2015-01-16 07:41 - 2014-06-03 13:15 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01514528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2015-01-16 07:41 - 2013-10-31 12:57 - 01278920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2015-01-16 00:44 - 2013-12-08 22:40 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Skype 2015-01-15 20:43 - 2014-03-14 19:53 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-01-15 20:43 - 2013-12-08 22:40 - 00000000 ____D () C:\ProgramData\Skype 2015-01-15 17:49 - 2013-10-20 11:35 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-01-15 17:48 - 2013-10-20 11:35 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-01-15 17:48 - 2013-08-22 14:25 - 00008192 ___SH () C:\WINDOWS\system32\config\ELAM 2015-01-14 00:35 - 2014-11-09 23:29 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Mp3tag 2015-01-10 09:07 - 2014-12-16 19:59 - 17250776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll 2015-01-10 09:07 - 2014-12-16 19:59 - 16009120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 18566296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 14115944 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 03298816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 02902456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2015-01-10 09:07 - 2013-10-20 11:13 - 00027441 _____ () C:\WINDOWS\system32\nvinfo.pb 2015-01-10 00:30 - 2013-10-20 22:37 - 06860432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2015-01-10 00:30 - 2013-10-20 22:37 - 03517256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00935056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe 2015-01-10 00:29 - 2013-10-20 22:37 - 00385352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2015-01-10 00:29 - 2013-10-20 22:37 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll ==================== Files in the root of some directories ======= 2014-07-16 14:30 - 2014-07-16 14:30 - 0001456 _____ () C:\Users\Johannes\AppData\Local\Adobe Für Web speichern 11.0 Prefs 2013-10-18 17:13 - 2013-10-18 22:01 - 0001008 _____ () C:\Users\Johannes\AppData\Local\killertool.log 2013-10-18 23:18 - 2014-09-09 15:57 - 0007651 _____ () C:\Users\Johannes\AppData\Local\Resmon.ResmonCfg 2013-10-18 17:21 - 2013-10-21 10:12 - 0062352 _____ () C:\ProgramData\dxdiag.txt Some content of TEMP: ==================== C:\Users\Johannes\AppData\Local\Temp\avgnt.exe C:\Users\Johannes\AppData\Local\Temp\camtasiade.exe C:\Users\Johannes\AppData\Local\Temp\drm_dyndata_7380014.dll C:\Users\Johannes\AppData\Local\Temp\exe2pin.exe C:\Users\Johannes\AppData\Local\Temp\jansi-32-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.3-2-g85f5776-b3023jnks.dll C:\Users\Johannes\AppData\Local\Temp\nv3DVStreaming.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Johannes\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Johannes\AppData\Local\Temp\nvStereoApiI.dll C:\Users\Johannes\AppData\Local\Temp\nvStInst.exe C:\Users\Johannes\AppData\Local\Temp\procexp0364.exe C:\Users\Johannes\AppData\Local\Temp\Quarantine.exe C:\Users\Johannes\AppData\Local\Temp\sdanircmdc.exe C:\Users\Johannes\AppData\Local\Temp\sdapskill.exe C:\Users\Johannes\AppData\Local\Temp\sdaspwn.exe C:\Users\Johannes\AppData\Local\Temp\sHID.dll C:\Users\Johannes\AppData\Local\Temp\sonarinst.exe C:\Users\Johannes\AppData\Local\Temp\sqlite3.dll C:\Users\Johannes\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-04 13:17 ==================== End Of Log ============================ |
09.02.2015, 18:15 | #14 |
/// the machine /// TB-Ausbilder | TR/dldr.bagle.ay von Avira gefunden, was ist das? fertig
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.02.2015, 22:00 | #15 |
| TR/dldr.bagle.ay von Avira gefunden, was ist das? oh mir ist gerade aufgefallen dass ich die falsche txt gepostet hab, das war die FRST.txt von einem früheren scan hier ist noch die Fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-02-2015 Ran by Johannes at 2015-02-10 21:55:37 Run:1 Running from E:\Daten\Download Loaded Profiles: Johannes (Available profiles: Johannes) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Johannes\AppData\Local\Temp\DMR\dmr_72.exe E:\Daten\Download\Audacity - CHIP-Installer.exe E:\Daten\Download\Biet O Matic - CHIP-Installer.exe E:\Daten\Download\BlueStacks App Player - CHIP-Installer.exe E:\Daten\Download\Camtasia-Studio-lnstall.exe E:\Daten\Download\Fast IP Changer - CHIP-Installer.exe E:\Daten\Download\mp3DirectCut - CHIP-Installer.exe E:\Daten\Download\Ping Plotter Free - CHIP-Installer.exe E:\Daten\Download\Process Explorer - CHIP-Installer.exe E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer(1).exe E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer.exe E:\Daten\Download\Tor Browser Paket - CHIP-Installer.exe E:\Daten\Download\TrackMania Nations Forever - CHIP-Installer.exe Emptytemp: ***************** C:\Users\Johannes\AppData\Local\Temp\DMR\dmr_72.exe => Moved successfully. E:\Daten\Download\Audacity - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\Biet O Matic - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\BlueStacks App Player - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\Camtasia-Studio-lnstall.exe => Moved successfully. E:\Daten\Download\Fast IP Changer - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\mp3DirectCut - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\Ping Plotter Free - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\Process Explorer - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer(1).exe => Moved successfully. E:\Daten\Download\SketchUp Make 2014 - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\Tor Browser Paket - CHIP-Installer.exe => Moved successfully. E:\Daten\Download\TrackMania Nations Forever - CHIP-Installer.exe => Moved successfully. EmptyTemp: => Removed 2.9 GB temporary data. The system needed a reboot. ==== End of Fixlog 21:55:55 ==== |
Themen zu TR/dldr.bagle.ay von Avira gefunden, was ist das? |
andere, antivirus, avira, bilder, datei, entfernt, gen, guten, heute, kaputte, löschen, neue, neuen, nicht löschen, ordner, programm, quarantäne, schädlich, secure, stick, unternehmen, usb, usb stick, verschieben, virus? |