|
Plagegeister aller Art und deren Bekämpfung: Adware Roll around eingefangenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
31.03.2015, 16:54 | #61 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Morgen Abend 18 Uhr? Schick mir mal ne PM hier am Forum.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.04.2015, 10:13 | #62 |
Adware Roll around eingefangen Hallo Schrauber, leider ist die Fehlermeldung wieder da...
__________________ShellExecuteEx fehlgeschlagen; Code 1155. Ca. 18 Pop Ups beim Systemstart... Was können wir jetzt noch machen? Ach ja: FROHE OSTERN! Achja und der PUP.optional.trovi ist auch wieder da Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 04.04.2015 Suchlauf-Zeit: 11:03:43 Logdatei: Malwarebytes.txt Administrator: Ja Version: 2.01.4.1018 Malware Datenbank: v2015.04.04.02 Rootkit Datenbank: v2015.03.31.01 Lizenz: Premium Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Aktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Basiliuws Eber Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 411490 Verstrichene Zeit: 6 Min, 55 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente gefunden) Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 0 (Keine schädliche Elemente gefunden) Registrierungswerte: 0 (Keine schädliche Elemente gefunden) Registrierungsdaten: 0 (Keine schädliche Elemente gefunden) Ordner: 0 (Keine schädliche Elemente gefunden) Dateien: 1 PUP.Optional.Trovi.A, C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5D03F840-0A34-4EF1-B1D2-7A24EF265FAD&SearchSource=55&CUI=&UM=5&UP=SPDD7AE828-8266-469E-A82F-77BE9505BDA3&SSPV=",), Ersetzt,[fe94ed7b7d0dd660c7cb5ed8689e6b95] Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) |
04.04.2015, 19:58 | #63 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Poste mal bitte frische FRST logs.
__________________
__________________ |
05.04.2015, 15:40 | #64 |
Adware Roll around eingefangen Alles klar, dann auf ein Neues: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by Basiliuws Eber (administrator) on BASILGAMING on 05-04-2015 16:34:49 Running from C:\Users\Basiliuws Eber\Downloads Loaded Profiles: Basiliuws Eber & (Available profiles: Basiliuws Eber & Basilius Eberle) Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-I16OQ.tmp\Basiliuws.tmp (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-TSJS7.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-IV9RQ.tmp\Basiliuws.tmp (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Program Files (x86)\Opera\28.0.1750.48\opera_crashreporter.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-UE0UK.tmp\Basiliuws.tmp (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-VM6SV.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-74ANH.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-QP4BK.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-KCH31.tmp\Basiliuws.tmp (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Dropbox, Inc.) C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-04S4U.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-F8KRI.tmp\Basiliuws.tmp (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-1P3V4.tmp\Basiliuws.tmp (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-SKN1C.tmp\Basiliuws.tmp (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\CTJckCfg.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-85PMR.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-N3J1F.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-COPC8.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-P3GRA.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-GIDJS.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-EFTB5.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-5BR8N.tmp\Basiliuws.tmp (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.48\opera.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [590144 2015-03-12] (Razer Inc.) HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [Sound Blaster Recon3Di SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe [976896 2012-11-28] (Creative Technology Ltd) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-03-22] (Avast Software s.r.o.) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-03-07] (Oracle Corporation) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2014-11-19] (Cisco Systems, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [Google Update] => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-12-07] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [MusicManager] => C:\Users\Basiliuws Eber\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7475200 2014-11-13] (Google Inc.) Code:
ATTFilter HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2015-01-28] (Garmin Ltd or its subsidiaries) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [GoogleChromeAutoLaunch_BB14199DEB214827D168BBB684CEEF8F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2015-03-30] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {39a7bf0b-76dd-11e4-8299-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {3aed501f-9b74-11e4-82a3-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {8cb957cc-cd4d-11e4-82b6-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-12-07] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MusicManager] => C:\Users\Basiliuws Eber\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7475200 2014-11-13] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2015-01-28] (Garmin Ltd or its subsidiaries) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_BB14199DEB214827D168BBB684CEEF8F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2015-03-30] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {39a7bf0b-76dd-11e4-8299-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {3aed501f-9b74-11e4-82a3-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {8cb957cc-cd4d-11e4-82b6-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_480223198B15635E392F8E5BDE9F021E] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2015-03-30] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11776 2014-10-29] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178512 2015-03-13] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [164568 2015-03-13] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC) Startup: C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (Avast Software s.r.o.) ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-24] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-22] (Avast Software s.r.o.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-24] (Oracle Corporation) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-22] (Avast Software s.r.o.) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-22] () FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-24] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-24] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-22] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2013-04-19] (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-03-13] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-03-13] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-04-04] () FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=3 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=9 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-04-04] () FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-31] Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5D03F840-0A34-4EF1-B1D2-7A24EF265FAD&SearchSource=55&CUI=&UM=5&UP=SPDD7AE828-8266-469E-A82F-77BE9505BDA3&SSPV= CHR StartupUrls: Default -> "hxxp://www.jura.uni-muenchen.de/index.html" CHR Profile: C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-02] CHR Extension: (Avast Online Security) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-31] CHR Extension: (KML, KMZ Viewer with Drive) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbolhellljccdahaeelobbojpfdgjgco [2015-04-02] CHR Extension: (Hangouts) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-04-02] CHR Extension: (Google Wallet) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-31] CHR Extension: (Citavi Picker) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2015-04-04] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-22] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - https://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-03-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-22] (Avast Software s.r.o.) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4030800 2015-03-22] (Avast Software) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-05-31] (Creative Labs) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-05-31] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2012-10-08] (Creative Technology Ltd) [File not signed] R2 CtHdaSvc; C:\Windows\sysWow64\CtHdaSvc.exe [103936 2014-04-29] (Creative Technology Ltd) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3736520 2015-01-29] (devolo AG) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [528096 2014-06-08] (Futuremark) R2 gadjservice; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [16384 2014-04-16] () [File not signed] S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [517464 2015-01-28] (Garmin Ltd or its subsidiaries) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-06-27] (Nero AG) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-01] () R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros) [File not signed] R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] () R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.) R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] () R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-03-22] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-03-22] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-03-22] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-03-22] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-03-22] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [441728 2015-03-22] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-03-22] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [268640 2015-03-22] () S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [75056 2013-02-13] (Qualcomm Atheros, Inc.) R3 cthda; C:\Windows\system32\drivers\cthda.sys [1050904 2014-04-29] (Creative Technology Ltd) R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [13760 2013-07-21] () R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [13760 2013-07-21] () S3 etocdrv; C:\Windows\etocdrv.sys [15584 2013-10-30] (Giga-Byte Technology CO., LTD.) S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.) R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [107736 2015-03-17] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-05] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2015-01-29] (CACE Technologies) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] () R3 rzdaendpt; C:\Windows\System32\drivers\rzdaendpt.sys [33448 2014-09-05] (Razer Inc) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-02-05] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-10-23] (Razer, Inc.) R3 rzvkeyboard; C:\Windows\System32\drivers\rzvkeyboard.sys [31912 2014-12-30] (Razer Inc) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed] S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] () R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-03-22] (Avast Software) S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-11-19] (Cisco Systems, Inc.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 16:34 - 2015-04-05 16:34 - 02095616 _____ (Farbar) C:\Users\Basiliuws Eber\Downloads\FRST64.exe 2015-04-05 16:34 - 2015-04-05 16:34 - 00037051 _____ () C:\Users\Basiliuws Eber\Downloads\FRST.txt 2015-04-05 16:34 - 2015-04-05 16:34 - 00000000 ____D () C:\FRST 2015-04-04 20:59 - 2015-04-04 20:59 - 00003619 _____ () C:\Users\Basiliuws Eber\Downloads\download.ris 2015-04-04 17:35 - 2015-04-04 17:35 - 00166325 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_tief_c_ein_bordun_trichter.mp4 2015-04-04 17:34 - 2015-04-04 17:34 - 00194216 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_1_in_g_ein_bordun_trichter.mp4 2015-04-04 17:10 - 2015-04-04 17:14 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Mp3tag 2015-04-04 17:09 - 2015-04-04 17:09 - 00001002 _____ () C:\Users\Public\Desktop\Mp3tag.lnk 2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag 2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\Program Files (x86)\Mp3tag 2015-04-04 17:08 - 2015-04-04 17:08 - 02802944 _____ () C:\Users\Basiliuws Eber\Downloads\mp3tagv269setup.exe 2015-04-04 16:53 - 2015-04-04 16:53 - 00000823 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 4 Gold Edition.lnk 2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-04 11:12 - 2015-04-04 11:12 - 00001543 _____ () C:\Users\Basiliuws Eber\Desktop\Malwarebytes.txt 2015-04-04 11:06 - 2015-04-04 16:57 - 00037174 _____ () C:\Windows\DirectX.log 2015-04-04 11:01 - 2015-04-04 11:01 - 00001404 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2015-04-04 11:01 - 2015-04-04 11:01 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA 2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2015-04-04 11:01 - 2015-03-28 05:43 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2015-04-04 11:01 - 2015-03-28 05:43 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2015-04-04 11:01 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2015-04-04 11:01 - 2014-11-22 12:46 - 00035472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2015-04-04 11:01 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2015-04-04 11:00 - 2015-04-04 11:00 - 36450560 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\GeForce_Experience_v2.4.1.21.exe 2015-04-03 16:08 - 2015-04-03 16:08 - 00000222 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 3 Blood Dragon.url 2015-04-02 14:57 - 2015-04-02 14:57 - 00000000 ____D () C:\ProgramData\Gibraltar 2015-04-02 13:48 - 2015-04-02 13:48 - 00002267 _____ () C:\Users\Basiliuws Eber\Downloads\Lesch2014deutsche.bib 2015-04-01 21:23 - 2015-04-01 21:23 - 00001846 _____ () C:\DelFix.txt 2015-04-01 21:23 - 2015-04-01 21:23 - 00000000 ____D () C:\Windows\ERUNT 2015-04-01 20:55 - 2015-04-01 20:55 - 00781312 _____ () C:\Users\Basiliuws Eber\Downloads\delfix_10.9.exe 2015-04-01 20:29 - 2015-04-01 20:29 - 01125626 _____ () C:\Users\Basiliuws Eber\Desktop\ProcessExplorer.zip 2015-04-01 20:29 - 2015-04-01 20:29 - 00000000 ____D () C:\Users\Basiliuws Eber\Desktop\ProcessExplorer 2015-04-01 20:28 - 2015-04-01 20:29 - 01125626 _____ () C:\Users\Basiliuws Eber\Downloads\ProcessExplorer.zip 2015-04-01 18:30 - 2015-03-16 16:38 - 01713824 _____ (techPowerUp (www.techpowerup.com)) C:\Users\Basiliuws Eber\Downloads\GPU-Z.0.8.2.exe 2015-04-01 18:30 - 2007-02-18 04:34 - 00000140 _____ () C:\Users\Basiliuws Eber\Downloads\SysProfile.de--Dein_Systemprofil_online.url 2015-04-01 18:29 - 2015-04-01 18:29 - 00109549 _____ () C:\Users\Basiliuws Eber\Documents\BASILGAMING.txt 2015-04-01 18:25 - 2015-04-01 18:26 - 01582736 _____ ( ) C:\Users\Basiliuws Eber\Downloads\cpu-z_1.72-en.exe 2015-04-01 18:11 - 2015-04-01 18:11 - 08146560 _____ (TeamViewer GmbH) C:\Users\Basiliuws Eber\Downloads\TeamViewer_Setup.exe 2015-03-31 13:20 - 2015-03-31 13:22 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-31 2015-03-31 11:17 - 2015-03-31 11:17 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\Chip.txt 2015-03-31 10:51 - 2015-04-04 11:44 - 00002202 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-03-31 10:51 - 2015-03-31 10:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-03-31 10:50 - 2015-03-31 10:50 - 00880208 _____ (Google Inc.) C:\Users\Basiliuws Eber\Downloads\ChromeSetup.exe 2015-03-31 10:45 - 2015-03-31 10:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Basiliuws Eber\Downloads\revosetup95.exe 2015-03-31 10:45 - 2015-03-31 10:45 - 00001291 _____ () C:\Users\Basiliuws Eber\Desktop\Revo Uninstaller.lnk 2015-03-31 10:45 - 2015-03-31 10:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-30 19:35 - 2015-03-30 19:35 - 00008793 _____ () C:\Users\Basiliuws Eber\Downloads\28.3.2015 10-07.kmz 2015-03-30 18:33 - 2015-03-30 18:35 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-30 2015-03-30 16:24 - 2015-03-30 16:24 - 13087456 _____ (Microsoft Corporation) C:\Users\Basiliuws Eber\Downloads\Silverlight_x64.exe 2015-03-30 14:23 - 2015-03-30 14:23 - 00000165 _____ () C:\Users\Basiliuws Eber\Downloads\scholar.enw 2015-03-30 08:39 - 2015-04-01 20:49 - 00000000 ____D () C:\Program Files (x86)\Universal Media Server 2015-03-30 08:39 - 2015-04-01 18:09 - 00000000 ____D () C:\ProgramData\UMS 2015-03-30 08:39 - 2015-03-30 09:01 - 00001951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server.lnk 2015-03-30 08:39 - 2015-03-30 09:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server 2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2015-03-30 08:38 - 2015-03-30 08:38 - 60871278 _____ () C:\Users\Basiliuws Eber\Downloads\UMS-5.1.0-Java7.exe 2015-03-29 22:09 - 2015-03-29 22:09 - 00000000 ____D () C:\ProgramData\Creative Labs 2015-03-29 22:02 - 2015-03-29 22:02 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2015-03-29 19:54 - 2015-03-29 19:54 - 00000195 _____ () C:\Users\Basiliuws Eber\Desktop\Hotline Miami.url 2015-03-28 19:41 - 2015-03-28 19:41 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\regfix.reg 2015-03-27 01:46 - 2015-03-27 01:46 - 00001209 _____ () C:\Users\Basiliuws Eber\Downloads\HTC Support Chat.txt 2015-03-26 09:47 - 2015-03-26 09:52 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Garmin Blitzer 2015-03-26 09:31 - 2015-03-26 09:31 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Garmin 2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Mein Garmin 2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Garmin 2015-03-26 09:20 - 2015-03-26 09:20 - 00003556 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask 2015-03-26 09:20 - 2015-03-26 09:20 - 00001911 _____ () C:\Users\Public\Desktop\Garmin Express.lnk 2015-03-26 09:19 - 2015-03-26 09:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2015-03-26 09:16 - 2015-03-26 09:16 - 00000319 _____ () C:\Users\Basiliuws Eber\Downloads\Garmin-InternetExplorer-Shortcut.vbs 2015-03-26 09:03 - 2015-04-05 16:29 - 00005950 _____ () C:\Windows\PFRO.log Code:
ATTFilter 2015-03-25 22:37 - 2015-03-26 00:45 - 00000000 ____D () C:\ProgramData\boost_interprocess 2015-03-25 22:33 - 2015-03-25 22:33 - 00001364 _____ () C:\Users\Public\Desktop\NAVIGON Fresh.lnk 2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NAVIGON 2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\Program Files (x86)\NAVIGON 2015-03-25 22:30 - 2015-03-25 22:30 - 24192080 _____ (GARMIN Würzburg GmbH) C:\Users\Basiliuws Eber\Downloads\ud_setup_win_351.exe 2015-03-25 22:13 - 2015-03-25 22:13 - 01917440 _____ () C:\Users\Basiliuws Eber\Downloads\XmlNotepad25.msi 2015-03-25 22:13 - 2015-03-25 22:13 - 00001950 _____ () C:\Users\Basiliuws Eber\Desktop\XML Notepad 2007.lnk 2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XML Notepad 2007 2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Program Files (x86)\XML Notepad 2007 2015-03-25 15:15 - 2015-03-25 15:15 - 00030950 _____ () C:\Windows\DPINST.LOG 2015-03-25 15:04 - 2015-04-05 16:30 - 00006973 _____ () C:\Windows\setupact.log 2015-03-25 15:04 - 2015-03-25 15:04 - 03344552 _____ (Cisco Systems, Inc.) C:\Users\Basiliuws Eber\Downloads\anyconnect-win-3.1.06073-web-deploy-k9.exe 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Program Files (x86)\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 _____ () C:\Windows\setuperr.log 2015-03-25 15:04 - 2014-11-19 17:09 - 00112496 ____R (Cisco Systems, Inc.) C:\Windows\system32\Drivers\acsock64.sys 2015-03-25 14:53 - 2015-04-05 16:33 - 02083967 _____ () C:\Windows\WindowsUpdate.log 2015-03-25 10:26 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-03-24 18:02 - 2015-03-24 18:02 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Swiss Academic Software 2015-03-24 17:54 - 2015-04-04 20:38 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Citavi 4 2015-03-24 17:54 - 2015-04-02 14:57 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Swiss Academic Software 2015-03-24 17:54 - 2015-04-02 13:43 - 00000000 ____D () C:\ProgramData\Swiss Academic Software 2015-03-24 17:51 - 2015-03-24 17:51 - 00001972 _____ () C:\Users\Public\Desktop\Citavi 4.lnk 2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citavi 4 2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\Program Files (x86)\Citavi 4 2015-03-24 17:40 - 2015-03-24 17:41 - 81307064 _____ (Swiss Academic Software) C:\Users\Basiliuws Eber\Downloads\Citavi4Setup.exe 2015-03-24 14:14 - 2015-03-24 14:14 - 00002160 _____ () C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk 2015-03-24 14:14 - 2015-03-13 17:38 - 00622224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-03-24 14:13 - 2015-03-13 21:41 - 32114888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 25460880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 24775368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 20466376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 17258024 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 13297144 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 13210080 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 10775080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 10715864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 10262160 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-03-24 14:13 - 2015-03-13 21:41 - 03611792 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 03249352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 02906928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 01896136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434788.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434788.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00997856 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00970384 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00944784 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00930448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00909512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00878328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00833680 _____ () C:\Windows\system32\nvmcumd.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00400584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00390288 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00354112 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00346824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-03-24 14:13 - 2015-03-13 21:41 - 00306208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-03-24 13:33 - 2007-08-11 15:38 - 00810952 _____ (Charles DeWeese) C:\Users\Basiliuws Eber\Downloads\FlashSfv.exe 2015-03-24 13:13 - 2015-03-24 13:13 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2015-03-24 13:13 - 2015-03-24 13:13 - 00000000 ____D () C:\Program Files\Java 2015-03-24 13:12 - 2015-03-24 13:12 - 42925480 _____ (Oracle Corporation) C:\Users\Basiliuws Eber\Downloads\jre-8u40-windows-x64.exe 2015-03-24 12:35 - 2015-03-24 15:26 - 00000000 ____D () C:\Program Files (x86)\Dr. Hardware 2015 2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basiliuws Eber\Desktop\Dr. Hardware 2015.lnk 2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basilius Eberle\Desktop\Dr. Hardware 2015.lnk 2015-03-24 12:35 - 2015-03-24 12:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr. Hardware 2015 2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\SysWOW64\Drivers\DRHMSR64.sys 2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\system32\Drivers\DRHMSR64.sys 2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\SysWOW64\Drivers\DRHARD64.sys 2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\system32\Drivers\DRHARD64.sys 2015-03-24 11:37 - 2015-03-24 11:37 - 11800240 _____ () C:\Users\Basiliuws Eber\Downloads\SetupAnyDVD7590.exe 2015-03-23 09:48 - 2015-03-23 09:48 - 00001732 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iTunes 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iPod 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-03-22 23:27 - 2015-03-22 23:27 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe 2015-03-22 23:27 - 2015-03-22 23:27 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr 2015-03-20 09:53 - 2015-03-20 09:53 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-53-19.037-AvastVBoxSVC.exe-3568.log 2015-03-20 09:09 - 2015-03-20 09:09 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-09-20.093-AvastVBoxSVC.exe-3640.log 2015-03-20 00:56 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-56-47.018-aswFe.exe-5100.log 2015-03-20 00:55 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-55-00.053-aswFe.exe-892.log 2015-03-20 00:54 - 2015-03-20 00:54 - 00000197 _____ () C:\Windows\system32\2015-03-19-22-54-59.047-AvastVBoxSVC.exe-3240.log 2015-03-20 00:44 - 2015-03-20 00:44 - 00588816 _____ () C:\Users\Basiliuws Eber\Downloads\Autoruns.zip 2015-03-20 00:44 - 2015-03-20 00:44 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Autoruns 2015-03-20 00:27 - 2015-03-20 00:27 - 05325696 _____ (Piriform Ltd) C:\Users\Basiliuws Eber\Downloads\ccsetup503.exe 2015-03-18 15:06 - 2015-03-20 00:49 - 00001540 _____ () C:\Users\Basiliuws Eber\Downloads\malwarebytes.txt 2015-03-18 14:54 - 2015-03-18 14:54 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-54-46.089-AvastVBoxSVC.exe-3700.log 2015-03-18 14:53 - 2015-03-18 14:53 - 00000358 _____ () C:\Windows\system32\.crusader 2015-03-18 14:23 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-23-15.080-aswFe.exe-7992.log 2015-03-18 14:22 - 2015-03-18 14:22 - 04479304 _____ (Google) C:\Users\Basiliuws Eber\Downloads\software_removal_tool.exe 2015-03-18 14:21 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-21-12.001-aswFe.exe-3104.log 2015-03-18 14:21 - 2015-03-18 14:21 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-21-10.073-AvastVBoxSVC.exe-956.log 2015-03-18 14:07 - 2015-03-18 14:07 - 00002323 _____ () C:\Users\Basiliuws Eber\Downloads\software_removal_tool.log 2015-03-18 13:04 - 2015-03-18 13:04 - 02953520 _____ (AVAST Software) C:\Users\Basiliuws Eber\Downloads\avast-browser-cleanup.exe 2015-03-18 12:31 - 2015-01-29 15:24 - 00221184 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopcap.dll 2015-03-18 12:31 - 2015-01-29 15:24 - 00081920 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopacket.dll 2015-03-18 12:31 - 2015-01-29 15:24 - 00034048 _____ (CACE Technologies) C:\Windows\SysWOW64\Drivers\npf_devolo.sys 2015-03-18 11:04 - 2015-03-18 11:05 - 00000197 _____ () C:\Windows\system32\2015-03-18-09-04-59.098-AvastVBoxSVC.exe-3500.log 2015-03-18 10:50 - 2015-03-18 10:50 - 00000197 _____ () C:\Windows\system32\2015-03-18-08-50-08.045-AvastVBoxSVC.exe-3460.log 2015-03-18 10:46 - 2015-03-18 10:46 - 00001178 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2015-03-18 10:46 - 2015-03-18 10:46 - 00001128 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canneverbe Limited 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\ProgramData\Canneverbe Limited 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2015-03-18 10:45 - 2015-03-18 10:45 - 05409016 _____ (Canneverbe Limited ) C:\Users\Basiliuws Eber\Downloads\cdbxp_setup_4.5.4.5306_minimal.exe 2015-03-17 23:37 - 2015-03-17 23:36 - 03312872 _____ (DVDVideoSoft Ltd. ) C:\Users\Basiliuws 2015-03-17 23:36 - 2015-03-18 09:55 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\DVDVideoSoft 2015-03-17 11:03 - 2015-03-17 11:03 - 00005364 _____ () C:\Users\Basiliuws Eber\Downloads\13.3.2015 19-50.kmz 2015-03-16 19:43 - 2015-03-16 19:43 - 00000197 _____ () C:\Windows\system32\2015-03-16-17-43-42.097-AvastVBoxSVC.exe-3712.log 2015-03-16 11:50 - 2015-03-16 11:50 - 19759661 _____ () C:\Users\Basiliuws Eber\Downloads\SpringBloomsRebeccaHeigel.themepack 2015-03-15 21:35 - 2015-03-15 21:35 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-35-41.095-AvastVBoxSVC.exe-3548.log 2015-03-15 21:26 - 2015-03-15 21:26 - 00000000 ____D () C:\Users\Basiliuws Eber\Tracing 2015-03-15 21:24 - 2015-03-15 21:26 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-03-15 21:24 - 2015-03-15 21:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-15 21:06 - 2015-03-15 21:07 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-06-30.070-AvastVBoxSVC.exe-3456.log 2015-03-15 20:57 - 2015-03-15 20:58 - 00000197 _____ () C:\Windows\system32\2015-03-15-18-57-47.015-AvastVBoxSVC.exe-3552.log 2015-03-14 19:09 - 2015-03-06 04:53 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-14 19:09 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-03-14 19:09 - 2015-02-26 01:26 - 04178944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-14 19:09 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-14 19:09 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-03-14 19:09 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-03-14 19:09 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-03-14 19:09 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-03-14 19:09 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-14 19:09 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-03-14 19:09 - 2015-02-20 05:03 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-14 19:09 - 2015-02-20 04:58 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-14 19:09 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-14 19:09 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-14 19:09 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-14 19:09 - 2015-02-20 04:35 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-03-14 19:09 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-14 19:09 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-14 19:09 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-03-14 19:09 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-03-14 19:09 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-03-14 19:09 - 2015-02-20 04:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2015-03-14 19:09 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-03-14 19:09 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-14 19:09 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-03-14 19:09 - 2015-02-20 03:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-03-14 19:09 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-03-14 19:09 - 2015-02-20 03:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-03-14 19:09 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-14 19:09 - 2015-02-20 03:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-14 19:09 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-14 19:09 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-14 19:09 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-03-14 19:09 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-03-14 19:09 - 2015-02-20 03:29 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-03-14 19:09 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-14 19:09 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-03-14 19:09 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-03-14 19:09 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-03-14 19:09 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-14 19:09 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-14 19:09 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-03-14 19:09 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-03-14 19:09 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-03-14 19:09 - 2015-02-07 01:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml 2015-03-14 19:09 - 2015-02-06 03:28 - 02257408 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-03-14 19:09 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-03-14 19:09 - 2015-02-05 22:24 - 01113920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00264000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00044024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2015-03-14 19:09 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2015-03-14 19:09 - 2015-02-03 02:02 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2015-03-14 19:09 - 2015-02-03 01:53 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll 2015-03-14 19:09 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll 2015-03-14 19:09 - 2015-01-31 01:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2015-03-14 19:09 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2015-03-14 19:09 - 2015-01-31 01:20 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-14 19:09 - 2015-01-30 05:01 - 00097792 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys 2015-03-14 19:09 - 2015-01-30 05:00 - 00167424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys 2015-03-14 19:09 - 2015-01-30 04:03 - 01488896 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2015-03-14 19:09 - 2015-01-30 04:03 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2015-03-14 19:09 - 2015-01-30 04:02 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll 2015-03-14 19:09 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2015-03-14 19:09 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2015-03-14 19:09 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll 2015-03-14 19:09 - 2015-01-30 03:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll 2015-03-14 19:09 - 2015-01-30 03:29 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atlthunk.dll 2015-03-14 19:09 - 2015-01-30 03:24 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll 2015-03-14 19:09 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll 2015-03-14 19:09 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll 2015-03-14 19:09 - 2015-01-30 03:08 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll 2015-03-14 19:09 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll 2015-03-14 19:09 - 2015-01-29 03:58 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll 2015-03-14 19:09 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll 2015-03-14 19:09 - 2015-01-29 03:11 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-14 19:09 - 2015-01-29 03:04 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2015-03-14 19:09 - 2015-01-29 03:04 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2015-03-14 19:09 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-14 19:09 - 2015-01-29 02:59 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-03-14 19:09 - 2015-01-29 02:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2015-03-14 19:09 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2015-03-14 19:09 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-03-14 19:09 - 2015-01-28 17:41 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-14 19:09 - 2015-01-28 17:41 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-03-14 19:09 - 2015-01-28 17:41 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-03-14 19:09 - 2015-01-28 04:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll 2015-03-14 19:09 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll 2015-03-14 19:09 - 2015-01-27 06:22 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-14 19:09 - 2015-01-27 05:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe 2015-03-14 19:09 - 2015-01-27 04:11 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-14 19:09 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe 2015-03-14 19:09 - 2015-01-23 09:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2015-03-14 19:09 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2015-03-14 19:08 - 2015-02-12 19:40 - 22291584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-14 19:08 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-03-14 19:08 - 2015-02-08 01:57 - 01090048 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2015-03-14 19:08 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2015-03-14 19:08 - 2015-01-29 20:45 - 01763352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-14 19:08 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-14 19:08 - 2015-01-28 03:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-14 19:08 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2015-03-14 19:08 - 2015-01-28 01:47 - 02501368 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2015-03-14 19:08 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2015-03-14 19:08 - 2015-01-21 07:54 - 01384712 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-14 19:08 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2015-03-14 19:08 - 2014-12-11 07:36 - 00046456 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe 2015-03-14 19:06 - 2015-03-14 19:06 - 00000197 _____ () C:\Windows\system32\2015-03-14-17-06-15.019-AvastVBoxSVC.exe-3404.log 2015-03-14 07:49 - 2015-03-14 07:49 - 00009728 _____ (Razer Inc.) C:\Windows\SysWOW64\RzStats.IPC.dll Code:
ATTFilter ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 16:33 - 2014-09-15 21:39 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-05 16:33 - 2014-05-31 11:30 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{ADF8F266-BC9E-412C-B8EE-DDA5E6A3C8C5} 2015-04-05 16:32 - 2014-12-25 15:31 - 00006464 _____ () C:\Windows\SysWOW64\Gms.log 2015-04-05 16:32 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-04-05 16:30 - 2014-11-30 14:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\HTC MediaHub 2015-04-05 16:30 - 2014-05-31 13:33 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox 2015-04-05 16:30 - 2014-05-31 12:28 - 00000000 ___DO () C:\Users\Basiliuws Eber\SkyDrive 2015-04-05 16:30 - 2014-05-31 12:22 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2015-04-05 16:30 - 2014-05-31 12:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-05 16:29 - 2014-08-23 19:22 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-04-05 16:29 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-04 21:54 - 2014-05-31 15:38 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\ClassicShell 2015-04-04 21:44 - 2014-05-31 12:19 - 00001142 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-04 21:43 - 2014-08-03 20:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-04 21:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2015-04-04 20:58 - 2014-12-07 16:02 - 00001180 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001UA.job 2015-04-04 20:26 - 2014-05-31 17:26 - 01789004 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-04 20:26 - 2013-08-23 01:24 - 00768888 _____ () C:\Windows\system32\perfh007.dat 2015-04-04 20:26 - 2013-08-23 01:24 - 00160706 _____ () C:\Windows\system32\perfc007.dat 2015-04-04 18:17 - 2014-05-31 17:28 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2245731289-3221781707-2474736645-1001 2015-04-04 18:17 - 2014-05-31 16:21 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-04-04 17:30 - 2015-03-03 11:18 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\JDownloader 2.0 2015-04-04 12:37 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-04-04 11:37 - 2014-06-01 15:26 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\My Games 2015-04-04 11:16 - 2014-06-01 10:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\my games 2015-04-04 11:01 - 2014-08-23 19:44 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA Corporation 2015-04-04 11:01 - 2014-08-23 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-04-04 11:01 - 2014-08-23 19:21 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-04-04 11:01 - 2014-08-23 19:20 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-04-04 11:01 - 2014-05-31 17:47 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-04-03 23:39 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Vss 2015-04-03 23:39 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-04-03 23:38 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF 2015-04-03 22:58 - 2014-12-07 16:02 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001Core.job 2015-04-03 16:08 - 2014-05-31 16:49 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-04-01 18:26 - 2014-06-01 16:00 - 00000852 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Program Files\WinRAR 2015-04-01 18:12 - 2014-10-20 21:45 - 00001201 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2015-04-01 18:12 - 2014-10-20 21:45 - 00001189 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2015-03-31 13:21 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canon 2015-03-31 11:04 - 2014-06-01 20:09 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Skype 2015-03-31 10:51 - 2014-05-31 12:19 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Google 2015-03-31 10:50 - 2014-05-31 12:19 - 00000000 ____D () C:\Program Files (x86)\Google 2015-03-31 10:44 - 2014-08-04 09:41 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Adobe 2015-03-31 10:44 - 2014-08-03 20:04 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-03-30 22:51 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2014-07-08 2015-03-30 22:48 - 2015-01-25 13:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Congstar Rechnungen 2015-03-30 08:54 - 2014-06-03 16:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\vlc 2015-03-30 08:39 - 2014-06-03 13:58 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5 2015-03-27 01:12 - 2014-09-15 21:39 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-03-26 23:49 - 2014-08-22 00:44 - 00005468 _____ () C:\Users\Basiliuws Eber\Documents\Database.kdb 2015-03-26 09:23 - 2014-06-09 10:10 - 00000000 ____D () C:\ProgramData\Garmin 2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Garmin 2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Program Files (x86)\Garmin 2015-03-26 09:20 - 2014-06-09 10:10 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Garmin 2015-03-26 09:20 - 2014-05-31 11:35 - 00000000 ____D () C:\ProgramData\Package Cache 2015-03-26 00:52 - 2014-12-10 00:39 - 00000000 ____D () C:\Windows\system32\appraiser 2015-03-26 00:52 - 2014-07-12 10:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-03-25 23:27 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Adobe 2015-03-25 22:37 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber 2015-03-25 15:16 - 2014-11-30 14:34 - 00002054 _____ () C:\Users\Public\Desktop\HTC Sync Manager.lnk 2015-03-25 15:15 - 2014-05-31 11:59 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Downloaded Installations 2015-03-25 14:24 - 2014-11-24 15:43 - 00031232 ___SH () C:\Users\Basiliuws Eber\Desktop\Thumbs.db 2015-03-25 14:09 - 2014-06-16 17:11 - 00000000 ____D () C:\Windows\Minidump 2015-03-25 14:09 - 2014-06-01 20:03 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\TS3Client 2015-03-24 13:33 - 2014-06-16 12:00 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\CyberLink PowerDVD Ultra 14.0.4028.58 2015-03-24 13:30 - 2014-06-09 11:37 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\OMC ModPack 2015-03-24 13:13 - 2014-10-26 21:18 - 00000000 ____D () C:\Program Files (x86)\Java 2015-03-24 12:44 - 2014-06-01 18:41 - 00000000 ____D () C:\Program Files (x86)\SpeedFan 2015-03-24 11:37 - 2014-06-03 13:50 - 00001128 _____ () C:\Users\Public\Desktop\AnyDVD.lnk 2015-03-24 11:33 - 2014-05-31 12:04 - 00000000 ____D () C:\ProgramData\CyberLink 2015-03-24 11:32 - 2014-06-16 12:23 - 00000000 ____D () C:\ProgramData\SUPPORTDIR 2015-03-23 09:48 - 2014-06-20 10:52 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2015-03-23 09:48 - 2014-06-20 10:51 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-03-22 23:27 - 2014-05-31 13:31 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00441728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00268640 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00136752 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00088408 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00065736 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00029168 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-03-22 23:12 - 2014-06-01 15:26 - 00125664 _____ () C:\Users\Basiliuws Eber\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-20 11:16 - 2014-05-31 11:46 - 01807894 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-03-20 09:07 - 2013-08-22 16:44 - 00492672 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-20 01:08 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2015-03-20 00:27 - 2014-05-31 16:19 - 00000801 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-03-20 00:27 - 2014-05-31 16:19 - 00000000 ____D () C:\Program Files\CCleaner 2015-03-18 14:53 - 2014-09-15 21:53 - 00000000 ____D () C:\ProgramData\HitmanPro 2015-03-18 14:22 - 2015-01-11 20:23 - 00003858 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1421000576 2015-03-18 14:22 - 2015-01-11 20:22 - 00001070 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2015-03-18 14:22 - 2015-01-11 20:22 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-03-18 14:17 - 2014-08-24 18:44 - 00000000 ____D () C:\Temp 2015-03-18 12:32 - 2015-01-24 13:45 - 00000000 ____D () C:\Program Files (x86)\devolo 2015-03-18 10:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Performance 2015-03-18 09:56 - 2014-05-31 11:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2015-03-17 11:17 - 2014-09-16 19:05 - 00019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-03-17 07:15 - 2014-09-15 21:39 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-03-17 07:15 - 2014-09-15 21:39 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-03-17 07:15 - 2014-09-15 21:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2015-03-15 21:26 - 2014-06-01 20:09 - 00000000 ____D () C:\ProgramData\Skype 2015-03-15 21:24 - 2014-06-01 20:09 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-03-14 23:21 - 2014-05-31 18:34 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-03-14 23:21 - 2014-05-31 14:17 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-14 23:18 - 2014-05-31 14:17 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-13 21:41 - 2015-02-08 17:06 - 16022016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-03-13 21:41 - 2014-08-23 19:42 - 14121624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-03-13 21:41 - 2014-08-23 19:21 - 03303448 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-03-13 21:41 - 2014-08-23 19:21 - 00178512 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-03-13 21:41 - 2014-08-23 19:21 - 00164568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-03-13 21:41 - 2014-08-23 19:21 - 00027441 _____ () C:\Windows\system32\nvinfo.pb 2015-03-13 21:41 - 2014-03-20 23:03 - 18580512 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-03-13 18:16 - 2014-08-23 19:22 - 06861968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-03-13 18:16 - 2014-08-23 19:22 - 03526856 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-03-13 18:16 - 2014-08-23 19:22 - 02559808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-03-13 18:16 - 2014-08-23 19:22 - 00935056 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-03-13 18:16 - 2014-08-23 19:22 - 00386248 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-03-13 18:16 - 2014-08-23 19:22 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-03-13 09:53 - 2014-05-31 13:37 - 00001105 _____ () C:\Users\Basiliuws Eber\Desktop\Dropbox.lnk 2015-03-13 09:53 - 2014-05-31 13:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-03-11 15:10 - 2014-08-23 19:22 - 04246327 _____ () C:\Windows\system32\nvcoproc.bin ==================== Files in the root of some directories ======= 2014-09-16 19:05 - 2015-03-17 11:17 - 0019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-03 13:55 - 2014-06-16 14:35 - 0000040 ___SH () C:\ProgramData\.zreglib Some content of TEMP: ==================== C:\Users\Basiliuws Eber\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpel14kl.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\proxy_vole7158415824673718289.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-02 08:18 ==================== End Of Log ============================ |
05.04.2015, 15:43 | #65 |
Adware Roll around eingefangen Und die Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by Basiliuws Eber at 2015-04-05 16:35:15 Running from C:\Users\Basiliuws Eber\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) @BIOS B14.0418.1 (HKLM-x32\...\InstallShield_{C9D46F25-5F9D-4E25-B24F-BC00E9EDF529}) (Version: 3.00.0000 - GIGABYTE) @BIOS B14.0418.1 (x32 Version: 3.00.0000 - GIGABYTE) Hidden 3DMark 11 (HKLM-x32\...\{f9e83b9c-ab7e-4005-8f32-4ea69703a5e4}) (Version: 1.0.132.0 - Futuremark) 3DMark 11 (Version: 1.0.132.0 - Futuremark) Hidden Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated) Adobe Flash Player 17 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden AnyDVD (HKLM-x32\...\AnyDVD) (Version: 7.5.9.0 - SlySoft) APP Center (HKLM-x32\...\InstallShield_{F3D47276-0E35-42CF-A677-B45118470E21}) (Version: 1.14.1205 - Gigabyte) APP Center (x32 Version: 1.14.1205 - Gigabyte) Hidden Apple Application Support (32-Bit) (HKLM-x32\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.) Apple Application Support (64-Bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2214 - AVAST Software) AviSynth (HKLM-x32\...\AviSynth) (Version: 2.6.0 MT - ) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Borderlands: The Pre-Sequel (HKLM-x32\...\Steam App 261640) (Version: - 2K Australia) BUSB (HKLM-x32\...\{0AADC50C-C4F8-49A7-8699-AFE46875CA67}) (Version: 1.13.0911.1 - GIGABYTE) calibre 64bit (HKLM\...\{98EF3B25-E714-46D7-AD9E-13CF2E29F741}) (Version: 2.10.0 - Kovid Goyal) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: 4.1.6 - Canon Inc.) Canon iP4800 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4800_series) (Version: - Canon Inc.) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.2.0 - Canon Inc.) CanoScan Toolbox Ver4.6 (HKLM-x32\...\{088A077A-8028-408C-AE7B-4512AE2A65A0}) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5306 - CDBurnerXP) CD-LabelPrint (HKLM-x32\...\MediaNavigation.CDLabelPrint) (Version: - ) Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine) Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.06073 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.06073 - Cisco Systems, Inc.) Hidden Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.5.0.11 - Swiss Academic Software) Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft) Company of Heroes 2 (HKLM-x32\...\Steam App 231430) (Version: - Relic Entertainment) CPUID CPU-Z 1.72 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) DataNumen RAR Repair v2.1 (HKLM-x32\...\DataNumen RAR Repair v2.1) (Version: - ) Dead Island (HKLM-x32\...\Steam App 91310) (Version: - Techland) devolo Cockpit (HKLM-x32\...\dlancockpit) (Version: 4.3.0.0 - devolo AG) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) Dr. Hardware 2015 15.0d (HKLM-x32\...\Dr. Hardware 2015_is1) (Version: - Peter A. Gebhard) Dropbox (HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Dropbox) (Version: 3.2.9 - Dropbox, Inc.) Dropbox (HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 3.2.9 - Dropbox, Inc.) EasyTune (HKLM-x32\...\InstallShield_{7F635314-EE21-4E4B-A68D-69AE70BA0E9B}) (Version: 1.00.0002 - GIGABYTE) EasyTune (x32 Version: 1.00.0002 - GIGABYTE) Hidden Elevated Installer (x32 Version: 3.2.29.0 - Garmin Ltd or its subsidiaries) Hidden EZSetupN B13.1114.1 (HKLM-x32\...\InstallShield_{9EAB60B6-70FE-4EC7-8DF4-54773E4EAC05}) (Version: 1.00.0000 - GIGABYTE) EZSetupN B13.1114.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden Far Cry 4 Gold Edition Incl. Update 4 & Hotfix MULTi2 v1.6.0 (HKLM-x32\...\Far Cry 4 Gold Edition Incl. Update 4 & Hotfix MULTi2 v1.6.0) (Version: - ) Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version: - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai) Far Cry® 3 Blood Dragon (HKLM-x32\...\Steam App 233270) (Version: - Ubisoft Montreal) Fast Boot (HKLM-x32\...\InstallShield_{FA8FB4F2-F524-48E1-A06C-45602FBF26CD}) (Version: 1.00.0000 - GIGABYTE) Fast Boot (x32 Version: 1.00.0000 - GIGABYTE) Hidden ffdshow v1.3.4504 [2013-03-12] (HKLM-x32\...\ffdshow_is1) (Version: 1.3.4504.0 - ) Futuremark SystemInfo (HKLM-x32\...\{4115C9AA-35E0-45D8-9363-47635B8750C7}) (Version: 4.29.438.0 - Futuremark) Garmin Express (HKLM-x32\...\{714dc1e5-69a4-4ecd-9552-93397e084298}) (Version: 3.2.29.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 3.2.29.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 3.2.29.0 - Garmin Ltd or its subsidiaries) Hidden Garmin MapSource (HKLM-x32\...\{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}) (Version: 6.16.3 - Garmin Ltd or its subsidiaries) Garmin POI Loader (HKLM-x32\...\{3213ED5E-7BBE-4613-BE69-8B1E4FE520DD}) (Version: 2.7.3 - Garmin Ltd or its subsidiaries) Garmin USB Drivers (HKLM-x32\...\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries) Geeks3D FurMark 1.13.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D) GIGABYTE OC_GURU II (HKLM-x32\...\InstallShield_{5588D686-D23B-4C9D-BDFA-2A7875CD3722}) (Version: 1.47.0000 - GIGABYTE Technology Co.,Ltd.) GIGABYTE OC_GURU II (x32 Version: 1.47.0000 - GIGABYTE Technology Co.,Ltd.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.118 - Google Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version: - ) HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.240 - SurfRight B.V.) Hotline Miami (HKLM-x32\...\Steam App 219150) (Version: - Dennaton Games) HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.16.0.001 - HTC Corporation) HTC Sync Manager (HKLM-x32\...\{231D0C79-98A6-4693-A366-36DE7D7346EC}) (Version: 3.1.44.5 - HTC) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1204 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3412 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.3.1001 - Intel Corporation) Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.20 - Intel(R) Corporation) Hidden IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) iTunes (HKLM\...\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.) Java 8 Update 40 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418040F0}) (Version: 8.0.400 - Oracle Corporation) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) KeePass Password Safe 1.27 (HKLM-x32\...\KeePass Password Safe_is1) (Version: 1.27 - Dominik Reichl) Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve) Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Ultimate 2007 (HKLM-x32\...\ULTIMATER) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) MonitorTest V3.1 (HKLM-x32\...\MonitorTest_is1) (Version: 3.1 - PassMark Software) Mp3tag v2.69 (HKLM-x32\...\Mp3tag) (Version: v2.69 - Florian Heidenreich) Music Manager (HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MusicManager) (Version: - Google, Inc.) Music Manager (HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MusicManager) (Version: - Google, Inc.) MyFreeCodec (HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MyFreeCodec) (Version: - ) MyFreeCodec (HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MyFreeCodec) (Version: - ) NAVIGON Fresh 3.5.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.5.1 - NAVIGON) NVIDIA 3D Vision Controller-Treiber 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.88 - NVIDIA Corporation) NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation) NVIDIA Grafiktreiber 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.88 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation) NVIDIA Miracast Virtueller Ton 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 347.88 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) OMC ModPack Client Version 1.1.7.28 (HKLM-x32\...\{E2F3187C-2B94-486F-8914-E69211487FB6}_is1) (Version: 1.1.7.28 - Odem Mortis) ON_OFF Charge 2 B13.1028.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) ON_OFF Charge 2 B13.1028.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Opera Stable 28.0.1750.48 (HKLM-x32\...\Opera 28.0.1750.48) (Version: 28.0.1750.48 - Opera Software ASA) PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge) Planetary Annihilation (HKLM-x32\...\Steam App 233250) (Version: - Uber Entertainment) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden Qualcomm Atheros Killer E220x Drivers (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\...\{FE5DFB80-6937-4154-A2C7-EF845C1301F8}) (Version: 1.0.30.1259 - Qualcomm Atheros) Qualcomm Atheros Network Manager (Version: 1.0.30.1259 - Qualcomm Atheros) Hidden Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.24735 - Razer Inc.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14074.11 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.6.3.14074.11 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.) SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.) Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation) Skype™ 7.2 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.) Smart Recovery 2 B14.0418.3 (x64) (HKLM-x32\...\{BC1FA5CF-A36F-4C61-9638-09D0B431B006}) (Version: 1.00.0001 - GIGABYTE) Smart TimeLock B14.0416.2 (HKLM-x32\...\InstallShield_{5D93E30A-78A3-4890-962F-56B61A5873DD}) (Version: 1.00.0001 - GIGABYTE) Smart TimeLock B14.0416.2 (x32 Version: 1.00.0001 - GIGABYTE) Hidden Sound Blaster Recon3Di (HKLM-x32\...\{918F3CE9-7164-4C6D-9530-66F12EFB4585}) (Version: 1.03.00 - Creative Technology Limited) Sound Blaster Recon3Di Extras (HKLM-x32\...\{536BDBFC-CA1A-4AC0-A8EB-BB2D0F1F522E}) (Version: 1.0 - Creative Technology Limited) SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - ) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) Supreme Commander (HKLM-x32\...\Steam App 9350) (Version: - Gas Powered Games) Supreme Commander: Forged Alliance (HKLM-x32\...\Steam App 9420) (Version: - Gas Powered Games) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.38846 - TeamViewer) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) The Incredible Adventures of Van Helsing II (HKLM-x32\...\Steam App 272470) (Version: - NeocoreGames) Tropico 4 (HKLM-x32\...\Steam App 57690) (Version: - Haemimont Games) Universal Media Server (HKLM-x32\...\Universal Media Server) (Version: 5.1.0 - Universal Media Server) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ULTIMATER_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ULTIMATER_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ULTIMATER_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ULTIMATER_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (HKLM\...\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin) Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software) WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH) Wolfenstein The New Order German Subbed Edition 1.0.0.1 (HKLM-x32\...\Wolfenstein The New Order German Subbed Edition 1.0.0.1) (Version: - ) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net) World of Warplanes (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C813EU}_is1) (Version: - Wargaming.net) XML Notepad 2007 (HKLM-x32\...\{FC7BACF0-1FFA-4605-B3B4-A66AB382752D}) (Version: 2.3.0.0 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-2245731289-3221781707-2474736645-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= 01-04-2015 21:23:30 Ende der Bereinigung 04-04-2015 11:06:12 DirectX wurde installiert ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0604B6FC-1952-46DA-B317-AFCCAE6F6D0B} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation) Task: {0AC142D6-EA42-4FA5-8A5B-F74EB02FB739} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-31] (Adobe Systems Incorporated) Task: {0D155BBB-3E93-4370-94ED-669D7E7720DE} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation) Task: {18A1A523-16FE-4222-A7AF-EAA2374ED1F4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-31] (Google Inc.) Task: {2F7DF15F-E295-4ED8-AA5A-4E06E83E2224} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001UA => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe [2014-12-07] (Google Inc.) Task: {3CB6A5CB-EB45-4EB7-AA37-415FDD276BC4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001Core => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe [2014-12-07] (Google Inc.) Task: {46207CC6-0C3D-4342-94BF-25918834239C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {4A0ABE79-F227-4B12-BB42-A99D0FE89D81} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2015-01-28] () Task: {64FEEF54-3A29-4DD8-8861-505EA37ED73E} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation) Task: {718DBB07-4AF7-4843-99A4-0A105B4B6478} - System32\Tasks\Opera scheduled Autoupdate 1421000576 => C:\Program Files (x86)\Opera\launcher.exe [2015-03-16] (Opera Software) Task: {8E6A3393-6E86-4ED0-B252-E38D690A4429} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-03-14] (Microsoft Corporation) Task: {9306AE10-05E3-4AE8-8D0C-EB585CA59C4E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-03-22] (Avast Software s.r.o.) Task: {94FA85E2-BA5C-4A0B-A97B-866727194B90} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation) Task: {9DF73875-F3ED-47BA-8CE5-57BA039F699F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {A507A936-0D1B-439A-93EE-153675B70688} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {A5CDFE9E-F172-43EF-AEE7-7E24195AAEF4} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {AE6037F6-E545-4DA5-BA59-2EDA092AE756} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {B32FABBD-3FD1-4D35-81B2-7FB39738E5FD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-31] (Google Inc.) Task: {B569FE0B-CBF0-411D-91A5-DDDA6B37A21D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd) Task: {E96DD7FB-A1FC-464E-BAD7-03F57AA27272} - System32\Tasks\{BA0A05E3-B0FF-4188-8584-4E7EB5F010A2} => pcalua.exe -a "C:\Users\Basiliuws Eber\Downloads\USB_Acer_2.0_B1-730FHD\drvinstall.exe" -d "C:\Users\Basiliuws Eber\Downloads\USB_Acer_2.0_B1-730FHD" Task: {EE080969-7FAC-4FBB-BB4C-45BC1081B38E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001Core.job => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001UA.job => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-08-23 19:22 - 2015-03-13 18:16 - 00118472 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2015-02-13 05:20 - 2015-02-13 05:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2014-04-16 17:09 - 2014-04-16 17:09 - 00016384 _____ () C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe 2013-10-17 16:27 - 2013-10-17 16:27 - 00166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe 2014-06-01 12:00 - 2014-06-01 12:00 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2015-02-05 02:24 - 2015-02-05 02:25 - 00187072 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe 2014-07-08 21:49 - 2006-06-27 16:28 - 00322048 _____ () C:\Windows\system32\CNQL3203.DLL 2014-11-25 22:06 - 2014-11-25 22:07 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\ErrorReporting.dll 2015-03-19 18:17 - 2015-03-19 18:17 - 00821600 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-I16OQ.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-TSJS7.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-IV9RQ.tmp\Basiliuws.tmp 2015-03-18 14:22 - 2015-03-18 14:22 - 00484472 _____ () C:\Program Files (x86)\Opera\28.0.1750.48\opera_crashreporter.exe 2014-01-25 02:22 - 2014-01-25 02:22 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-UE0UK.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-VM6SV.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-74ANH.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-QP4BK.tmp\Basiliuws.tmp 2015-02-19 23:40 - 2015-02-19 23:40 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-KCH31.tmp\Basiliuws.tmp 2013-08-08 14:30 - 2013-08-08 14:30 - 00283648 _____ () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-04S4U.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-F8KRI.tmp\Basiliuws.tmp 2015-04-04 11:44 - 2015-03-30 22:38 - 01530184 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libglesv2.dll 2015-04-04 11:44 - 2015-03-30 22:38 - 00091976 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\libegl.dll 2015-04-04 11:44 - 2015-03-30 22:39 - 11266376 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\pdf.dll 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-1P3V4.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-SKN1C.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-85PMR.tmp\Basiliuws.tmp 2015-04-05 16:30 - 2015-04-05 16:30 - 01174552 _____ () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-N3J1F.tmp\Basiliuws.tmp 2014-11-19 17:36 - 2014-11-19 17:36 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2015-03-22 23:27 - 2015-03-22 23:27 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2015-03-22 23:27 - 2015-03-22 23:27 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2015-04-04 15:03 - 2015-04-04 15:03 - 02923520 _____ () C:\Program Files\AVAST Software\Avast\defs\15040400\algo.dll 2015-04-05 16:30 - 2015-04-05 16:30 - 02923520 _____ () C:\Program Files\AVAST Software\Avast\defs\15040500\algo.dll 2012-11-27 09:03 - 2012-11-27 09:03 - 00102400 _____ () C:\Program Files (x86)\Gigabyte\AppCenter\ycc.DLL 2014-11-03 12:04 - 2014-11-03 12:04 - 00031080 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DbAccess.dll 2015-03-19 18:16 - 2015-03-19 18:16 - 00607376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\sqlite3.dll 2014-11-03 12:05 - 2014-11-03 12:05 - 00059752 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NAdvLog.dll 2014-11-03 12:05 - 2014-11-03 12:05 - 00036216 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NFileCacheDBAccess.dll 2014-11-03 12:05 - 2014-11-03 12:05 - 00080248 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\ninstallerhelper.dll 2014-11-03 12:06 - 2014-11-03 12:06 - 00129376 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\zlib1.dll 2014-11-03 12:07 - 2014-11-03 12:07 - 00223592 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DevConnMon.dll 2015-04-04 11:01 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-03-18 14:22 - 2015-03-18 14:22 - 00157304 _____ () C:\Program Files (x86)\Opera\28.0.1750.48\message_center_win8.dll 2015-03-18 14:22 - 2015-03-18 14:22 - 01488504 _____ () C:\Program Files (x86)\Opera\28.0.1750.48\libglesv2.dll 2015-03-18 14:22 - 2015-03-18 14:22 - 00079992 _____ () C:\Program Files (x86)\Opera\28.0.1750.48\libegl.dll 2015-03-18 14:22 - 2015-03-18 14:22 - 09625720 _____ () C:\Program Files (x86)\Opera\28.0.1750.48\pdf.dll 2015-03-05 00:08 - 2015-03-05 00:08 - 00750080 _____ () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-04-05 16:30 - 2015-04-05 16:30 - 00043008 _____ () c:\Users\Basiliuws Eber\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpel14kl.dll 2015-03-05 00:08 - 2015-03-05 00:08 - 00047616 _____ () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-03-05 00:08 - 2015-03-05 00:08 - 00865280 _____ () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-03-05 00:07 - 2015-03-05 00:07 - 00200704 _____ () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2015-02-05 11:20 - 2015-02-05 11:20 - 00137728 _____ () C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll 2015-03-22 23:27 - 2015-03-22 23:27 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-03-22 23:27 - 2015-03-22 23:27 - 01359872 _____ () C:\Program Files\AVAST Software\Avast\libglesv2.dll 2015-03-22 23:27 - 2015-03-22 23:27 - 00212992 _____ () C:\Program Files\AVAST Software\Avast\libegl.dll 2014-05-31 11:43 - 2013-09-16 12:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:966F7784 AlternateDataStreams: C:\ProgramData\Temp:CB0AACC9 AlternateDataStreams: C:\Users\Basiliuws Eber\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper HKU\S-1-5-21-2245731289-3221781707-2474736645-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Basilius Eberle\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) HKLM\...\StartupApproved\StartupFolder: => "GIGABYTE OC_GURU.lnk" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "PowerDVD14Agent" HKLM\...\StartupApproved\Run32: => "KiesTrayAgent" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\StartupApproved\Run: => "MusicManager" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "MusicManager" ==================== Accounts: ============================= Administrator (S-1-5-21-2245731289-3221781707-2474736645-500 - Administrator - Disabled) Basilius Eberle (S-1-5-21-2245731289-3221781707-2474736645-1004 - Limited - Enabled) => C:\Users\Basilius Eberle Basiliuws Eber (S-1-5-21-2245731289-3221781707-2474736645-1001 - Administrator - Enabled) => C:\Users\Basiliuws Eber Gast (S-1-5-21-2245731289-3221781707-2474736645-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2245731289-3221781707-2474736645-1003 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/04/2015 01:49:22 PM) (Source: gadjservice) (EventID: 0) (User: ) Description: gadjservice Get time form NTP server fail. Error: (04/04/2015 01:25:06 PM) (Source: gadjservice) (EventID: 0) (User: ) Description: gadjservice Get time form NTP server fail. Error: (04/04/2015 01:12:46 PM) (Source: gadjservice) (EventID: 0) (User: ) Description: gadjservice Get time form NTP server fail. Error: (04/04/2015 00:57:51 PM) (Source: gadjservice) (EventID: 0) (User: ) Description: gadjservice Get time form NTP server fail. Error: (04/04/2015 11:06:14 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary Microsoft-Verbindungsschichterkennungsprotokoll. System Error: Zugriff verweigert . Error: (04/04/2015 10:51:05 AM) (Source: NvStreamSvc) (EventID: 2001) (User: ) Description: NvStreamSvcFailed continue stopping. [0] Error: (04/03/2015 11:38:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: rundll32.exe_winethc.dll, Version: 6.3.9600.17415, Zeitstempel: 0x54504eb8 Name des fehlerhaften Moduls: USER32.dll, Version: 6.3.9600.17668, Zeitstempel: 0x54c850f5 Ausnahmecode: 0xc0000142 Fehleroffset: 0x00000000000ec500 ID des fehlerhaften Prozesses: 0x4b64 Startzeit der fehlerhaften Anwendung: 0xrundll32.exe_winethc.dll0 Pfad der fehlerhaften Anwendung: rundll32.exe_winethc.dll1 Pfad des fehlerhaften Moduls: rundll32.exe_winethc.dll2 Berichtskennung: rundll32.exe_winethc.dll3 Vollständiger Name des fehlerhaften Pakets: rundll32.exe_winethc.dll4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rundll32.exe_winethc.dll5 Error: (04/03/2015 11:38:35 PM) (Source: gadjservice) (EventID: 0) (User: ) Description: gadjservice Get time form NTP server fail. Error: (04/03/2015 11:37:35 PM) (Source: gadjservice) (EventID: 0) (User: ) Description: gadjservice Get time form NTP server fail. Error: (04/03/2015 11:37:17 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm WINWORD.EXE, Version 12.0.6718.5000 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2f98 Startzeit: 01d06d3a608f12f1 Endzeit: 12 Anwendungspfad: C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE Berichts-ID: 9005a44c-da49-11e4-82c2-001109e5f38b Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: System errors: ============= Error: (04/05/2015 04:30:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/05/2015 04:30:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Garmin Core Update Service erreicht. Error: (04/05/2015 04:29:55 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 04.04.2015 um 21:20:49 unerwartet heruntergefahren. Error: (04/05/2015 04:29:47 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT-AUTORITÄT) Description: 32212256844791396797056256 Error: (04/03/2015 11:39:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/03/2015 11:39:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Garmin Core Update Service erreicht. Error: (04/03/2015 11:39:01 PM) (Source: DCOM) (EventID: 10010) (User: BASILGAMING) Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} Error: (04/03/2015 11:39:01 PM) (Source: DCOM) (EventID: 10010) (User: BASILGAMING) Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} Error: (04/02/2015 08:07:38 AM) (Source: DCOM) (EventID: 10010) (User: BASILGAMING) Description: {2F93C02D-77F9-46B4-95FB-8CBB81EEB62C} Error: (04/01/2015 09:27:09 PM) (Source: DCOM) (EventID: 10010) (User: BASILGAMING) Description: {9AA46009-3CE0-458A-A354-715610A075E6} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz Percentage of memory in use: 22% Total physical RAM: 16262.34 MB Available physical RAM: 12682.39 MB Total Pagefile: 18694.34 MB Available Pagefile: 13868.48 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:223.23 GB) (Free:127.71 GB) NTFS Drive e: (Fotos, Musik, UNI) (Fixed) (Total:931.46 GB) (Free:891.13 GB) NTFS Drive f: (Videos) (Fixed) (Total:931.46 GB) (Free:280.29 GB) NTFS Drive g: (Spiele) (Fixed) (Total:931.46 GB) (Free:531.13 GB) NTFS Drive h: (MP3 STICK) (Removable) (Total:7.45 GB) (Free:1.45 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: F189E976) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=223.2 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 097CA2F8) Partition: GPT Partition Type. ======================================================== Disk: 2 (Size: 7.5 GB) (Disk ID: 6E652072) No partition Table on disk 2. ==================== End Of Log ============================ |
06.04.2015, 10:30 | #66 | |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangenZitat:
OAWrapper.exe NvOAWrapperCache.exe Dann Temps leeren und rebooten.
__________________ --> Adware Roll around eingefangen |
06.04.2015, 12:11 | #67 |
Adware Roll around eingefangen Hallo Schrauber, bisher gibt es jetzt nach der Ausführung Deiner oben genannten Schritte keine Fehlermeldung mehr, allerdings funktioniert jetzt Geforce Experience nicht mehr. Sollte ich das ganze NVidia Paket (Treiber und Expereince) neu installieren? |
06.04.2015, 15:01 | #68 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Jap.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.04.2015, 08:54 | #69 |
Adware Roll around eingefangen Bisher gibt er Ruhe... nur den Pup.Trovi findet Malwarebytes immer noch jeden Tag. |
07.04.2015, 17:31 | #70 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.04.2015, 11:04 | #71 |
Adware Roll around eingefangenCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by Basiliuws Eber at 2015-04-08 12:04:20 Run:1 Running from C:\Users\Basiliuws Eber\Downloads Loaded Profiles: Basiliuws Eber (Available profiles: Basiliuws Eber & Basilius Eberle) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ***************** C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences => Moved successfully. ==== End of Fixlog 12:04:20 ==== |
08.04.2015, 11:19 | #72 |
Adware Roll around eingefangen Malwarebytes findet den Trovi immer noch... :-( |
08.04.2015, 17:57 | #73 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen What? Schau mal ob die Datei neu angelegt wurde, wenn ja hier anhängen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.04.2015, 10:07 | #74 |
Adware Roll around eingefangen ..Und die ShellExecutEx Meldung ist auch wieder da. Vielen Dank, Chip.de und DVDVideo Soft! Wird mir wohl nix anderes übrig bleiben als das System platt zu machen? Und das wegen soe einem Sch*'? Programm. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by Basiliuws Eber (administrator) on BASILGAMING on 09-04-2015 10:59:10 Running from C:\Users\Basiliuws Eber\Downloads Loaded Profiles: Basiliuws Eber & Basilius Eberle (Available profiles: Basiliuws Eber & Basilius Eberle) Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe (Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-DU7GR.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-KM831.tmp\Basiliuws.tmp (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-2SN8R.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-THH8S.tmp\Basiliuws.tmp (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-MSFUL.tmp\Basiliuws.tmp (Intel Corporation) C:\Windows\System32\igfxpers.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-OMQ97.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-92VQT.tmp\Basiliuws.tmp (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-8G0C9.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-V6CV7.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-53POI.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-L50L3.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-INGIG.tmp\Basiliuws.tmp () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Dropbox, Inc.) C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-I0ES9.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-QL27D.tmp\Basiliuws.tmp (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\CTJckCfg.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-CEA80.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-BSKP8.tmp\Basiliuws.tmp (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-GC29O.tmp\Basiliuws.tmp (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-JHK73.tmp\Basiliuws.tmp (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-BG5VI.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-0KREE.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-D71QN.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-DE39R.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-OTOAF.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-Q3VC1.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-JGD89.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-OOOJK.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-U93A9.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-II8MK.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-VBLTS.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-4J19D.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-44KPH.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-CH8GQ.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-AD5HI.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-4NMJL.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-A0I53.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-CRP9L.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-R5K23.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-UC5I1.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-P74P3.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-F98TT.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-H9OUB.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-T90CB.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-PV8EK.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-QU3AH.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-F63MT.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-0O4EO.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-9QN5T.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Program Files (x86)\Opera\28.0.1750.51\opera_crashreporter.exe () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-50FHD.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-GS1SE.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-QQSBM.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-06K9S.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-85F65.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-OAB9G.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-UCCH4.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-55QKG.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-FPCLG.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-VU7Q6.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-L524V.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-UQ17Q.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-3PAHB.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-5OFQD.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-OAMF8.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-FTQFA.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-L38JC.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-0H410.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-849P9.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-SL0K9.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-GBMTM.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-MCCSQ.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-I5BPB.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-R436E.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-JD1SJ.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-260TV.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-0VOGV.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-K9HIB.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-4RQP1.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-S691C.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-AIKDS.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-N1IHB.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-7PAVI.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-09LCN.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-IR946.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-HFH2L.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-LKUTG.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-7TC07.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-GFAO8.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-HKM1B.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-QN6F1.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-MMLGO.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-J4I9O.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-V9MH5.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-QV37R.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-CF27P.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-BGAIG.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-GJ0N5.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-SUTL5.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-A5NES.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-FI1UK.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-OQ0R9.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-A4R91.tmp\Basiliuws.tmp (DVDVideoSoft Ltd. ) C:\Users\Basiliuws () C:\Users\Basiliuws Eber\AppData\Local\Temp\is-9ICPK.tmp\Basiliuws.tmp (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [590144 2015-03-12] (Razer Inc.) HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [Sound Blaster Recon3Di SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe [976896 2012-11-28] (Creative Technology Ltd) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-03-22] (Avast Software s.r.o.) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-03-07] (Oracle Corporation) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2014-11-19] (Cisco Systems, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [Google Update] => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-12-07] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [MusicManager] => C:\Users\Basiliuws Eber\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7475200 2015-04-01] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2015-01-28] (Garmin Ltd or its subsidiaries) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [GoogleChromeAutoLaunch_BB14199DEB214827D168BBB684CEEF8F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2015-03-30] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {39a7bf0b-76dd-11e4-8299-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {3aed501f-9b74-11e4-82a3-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {8cb957cc-cd4d-11e4-82b6-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\...\Run: [GoogleChromeAutoLaunch_480223198B15635E392F8E5BDE9F021E] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859464 2015-03-30] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11776 2014-10-29] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178512 2015-03-13] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [164568 2015-03-13] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC) Startup: C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (Avast Software s.r.o.) ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) Code:
ATTFilter ================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-24] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-22] (Avast Software s.r.o.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-24] (Oracle Corporation) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-22] (Avast Software s.r.o.) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-22] () FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-24] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-24] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-22] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2013-04-19] (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-03-13] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-03-13] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-04-04] () FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-31] Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5D03F840-0A34-4EF1-B1D2-7A24EF265FAD&SearchSource=55&CUI=&UM=5&UP=SPDD7AE828-8266-469E-A82F-77BE9505BDA3&SSPV= CHR StartupUrls: Default -> "hxxp://www.jura.uni-muenchen.de/index.html" CHR Profile: C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-08] CHR Extension: (Avast Online Security) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-31] CHR Extension: (KML, KMZ Viewer with Drive) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbolhellljccdahaeelobbojpfdgjgco [2015-04-08] CHR Extension: (Hangouts) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-04-08] CHR Extension: (Google Wallet) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-31] CHR Extension: (Citavi Picker) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2015-04-04] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-22] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - https://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-03-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-22] (Avast Software s.r.o.) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4030800 2015-03-22] (Avast Software) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-05-31] (Creative Labs) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-05-31] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2012-10-08] (Creative Technology Ltd) [File not signed] R2 CtHdaSvc; C:\Windows\sysWow64\CtHdaSvc.exe [103936 2014-04-29] (Creative Technology Ltd) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3736520 2015-01-29] (devolo AG) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [528096 2014-06-08] (Futuremark) R2 gadjservice; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [16384 2014-04-16] () [File not signed] S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [517464 2015-01-28] (Garmin Ltd or its subsidiaries) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-06-27] (Nero AG) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-01] () R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros) [File not signed] R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] () R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) Code:
ATTFilter ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.) R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] () R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-03-22] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-03-22] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-03-22] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-03-22] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-03-22] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [441728 2015-03-22] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-03-22] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [268640 2015-03-22] () S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [75056 2013-02-13] (Qualcomm Atheros, Inc.) R3 cthda; C:\Windows\system32\drivers\cthda.sys [1050904 2014-04-29] (Creative Technology Ltd) R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [13760 2013-07-21] () R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [13760 2013-07-21] () S3 etocdrv; C:\Windows\etocdrv.sys [15584 2013-10-30] (Giga-Byte Technology CO., LTD.) S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.) R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [107736 2015-03-17] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-09] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2015-01-29] (CACE Technologies) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] () R3 rzdaendpt; C:\Windows\System32\drivers\rzdaendpt.sys [33448 2014-09-05] (Razer Inc) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-02-05] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-10-23] (Razer, Inc.) R3 rzvkeyboard; C:\Windows\System32\drivers\rzvkeyboard.sys [31912 2014-12-30] (Razer Inc) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed] S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] () R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-03-22] (Avast Software) S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-11-19] (Cisco Systems, Inc.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-08 21:23 - 2015-04-08 21:23 - 00000000 ____D () C:\Users\Basiliuws Eber\.pdfsam 2015-04-08 21:18 - 2015-04-08 21:18 - 30843037 _____ () C:\Users\Basiliuws Eber\Downloads\PDFsam_224 (1).zip 2015-04-08 21:18 - 2015-04-08 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Split And Merge Basic 2015-04-08 21:18 - 2015-04-08 21:18 - 00000000 ____D () C:\Program Files\PDF Split And Merge Basic 2015-04-08 21:18 - 2014-06-26 09:23 - 16358440 _____ () C:\Users\Basiliuws Eber\Downloads\pdfsam-x64-v2_2_4.msi 2015-04-08 21:18 - 2014-06-26 09:22 - 16358452 _____ () C:\Users\Basiliuws Eber\Downloads\pdfsam-x86-v2_2_4.msi 2015-04-08 21:14 - 2015-04-08 21:14 - 30843037 _____ () C:\Users\Basiliuws Eber\Downloads\PDFsam_224.zip 2015-04-08 18:34 - 2015-04-08 18:34 - 02209056 _____ () C:\Users\Basiliuws Eber\Downloads\avira-eu-cleaner_de.exe 2015-04-08 18:34 - 2015-04-08 18:34 - 00002105 _____ () C:\Users\Basiliuws Eber\Desktop\Entfernen des Avira EU-Cleaners.lnk 2015-04-08 18:34 - 2015-04-08 18:34 - 00002049 _____ () C:\Users\Basiliuws Eber\Desktop\Avira EU-Cleaner.lnk 2015-04-06 18:05 - 2015-04-06 18:05 - 00000201 _____ () C:\Users\Basiliuws Eber\Downloads\fhsexport_endnote.enw 2015-04-06 17:02 - 2015-04-06 17:02 - 36450560 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\GeForce_Experience_v2.4.1.21 (1).exe 2015-04-06 17:02 - 2015-04-06 17:02 - 00002160 _____ () C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk 2015-04-06 17:01 - 2015-04-06 17:01 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-04-06 17:01 - 2015-03-13 18:16 - 06861968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 03526856 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 02559808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 00935056 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-04-06 17:01 - 2015-03-13 18:16 - 00386248 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-04-06 17:01 - 2015-03-13 17:38 - 00622224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-04-06 17:01 - 2015-03-11 15:10 - 04246327 _____ () C:\Windows\system32\nvcoproc.bin 2015-04-06 17:00 - 2015-04-06 17:00 - 00000000 ____D () C:\NVIDIA 2015-04-06 17:00 - 2015-03-13 21:41 - 32114888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 25460880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 24775368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 20466376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 18580512 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 17258024 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 16022016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 14121624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 13297144 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 13210080 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 10775080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 10715864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 10262160 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-04-06 17:00 - 2015-03-13 21:41 - 03611792 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 03303448 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 03249352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 02906928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01896136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434788.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434788.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01556624 _____ (NVIDIA Corporation) C:\Windows\system32\nvir3dgenco64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01540240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00997856 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00970384 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00944784 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00930448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00909512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00878328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00833680 _____ () C:\Windows\system32\nvmcumd.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00452424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstusb.sys 2015-04-06 17:00 - 2015-03-13 21:41 - 00400584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00390288 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00354112 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00346824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00306208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2015-04-06 17:00 - 2015-03-13 21:41 - 00178512 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00164568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00027441 _____ () C:\Windows\system32\nvinfo.pb 2015-04-06 16:57 - 2015-04-06 16:59 - 309143408 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\347.88-desktop-win8-win7-winvista-64bit-international-whql.exe 2015-04-05 16:35 - 2015-04-05 16:35 - 00046575 _____ () C:\Users\Basiliuws Eber\Downloads\Addition.txt 2015-04-05 16:34 - 2015-04-09 10:59 - 00047382 _____ () C:\Users\Basiliuws Eber\Downloads\FRST.txt 2015-04-05 16:34 - 2015-04-09 10:59 - 00000000 ____D () C:\FRST 2015-04-05 16:34 - 2015-04-05 16:34 - 02095616 _____ (Farbar) C:\Users\Basiliuws Eber\Downloads\FRST64.exe 2015-04-04 20:59 - 2015-04-04 20:59 - 00003619 _____ () C:\Users\Basiliuws Eber\Downloads\download.ris 2015-04-04 17:35 - 2015-04-04 17:35 - 00166325 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_tief_c_ein_bordun_trichter.mp4 2015-04-04 17:34 - 2015-04-04 17:34 - 00194216 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_1_in_g_ein_bordun_trichter.mp4 2015-04-04 17:10 - 2015-04-06 22:13 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Mp3tag 2015-04-04 17:09 - 2015-04-04 17:09 - 00001002 _____ () C:\Users\Public\Desktop\Mp3tag.lnk 2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag 2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\Program Files (x86)\Mp3tag 2015-04-04 17:08 - 2015-04-04 17:08 - 02802944 _____ () C:\Users\Basiliuws Eber\Downloads\mp3tagv269setup.exe 2015-04-04 16:53 - 2015-04-04 16:53 - 00000823 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 4 Gold Edition.lnk 2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-04 11:06 - 2015-04-04 16:57 - 00037174 _____ () C:\Windows\DirectX.log 2015-04-04 11:01 - 2015-04-06 17:11 - 00001404 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2015-04-04 11:01 - 2015-04-04 11:01 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA 2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2015-04-04 11:01 - 2015-03-28 05:43 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2015-04-04 11:01 - 2015-03-28 05:43 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2015-04-04 11:01 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2015-04-04 11:01 - 2014-11-22 12:46 - 00035472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2015-04-04 11:01 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2015-04-04 11:00 - 2015-04-04 11:00 - 36450560 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\GeForce_Experience_v2.4.1.21.exe 2015-04-03 16:08 - 2015-04-03 16:08 - 00000222 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 3 Blood Dragon.url 2015-04-02 14:57 - 2015-04-02 14:57 - 00000000 ____D () C:\ProgramData\Gibraltar 2015-04-02 13:48 - 2015-04-02 13:48 - 00002267 _____ () C:\Users\Basiliuws Eber\Downloads\Lesch2014deutsche.bib 2015-04-01 21:23 - 2015-04-01 21:23 - 00001846 _____ () C:\DelFix.txt 2015-04-01 21:23 - 2015-04-01 21:23 - 00000000 ____D () C:\Windows\ERUNT 2015-04-01 20:55 - 2015-04-01 20:55 - 00781312 _____ () C:\Users\Basiliuws Eber\Downloads\delfix_10.9.exe 2015-04-01 20:29 - 2015-04-01 20:29 - 00000000 ____D () C:\Users\Basiliuws Eber\Desktop\ProcessExplorer 2015-04-01 20:28 - 2015-04-01 20:29 - 01125626 _____ () C:\Users\Basiliuws Eber\Downloads\ProcessExplorer.zip 2015-04-01 18:30 - 2015-03-16 16:38 - 01713824 _____ (techPowerUp (www.techpowerup.com)) C:\Users\Basiliuws Eber\Downloads\GPU-Z.0.8.2.exe 2015-04-01 18:30 - 2007-02-18 04:34 - 00000140 _____ () C:\Users\Basiliuws Eber\Downloads\SysProfile.de--Dein_Systemprofil_online.url 2015-04-01 18:29 - 2015-04-01 18:29 - 00109549 _____ () C:\Users\Basiliuws Eber\Documents\BASILGAMING.txt 2015-04-01 18:25 - 2015-04-01 18:26 - 01582736 _____ ( ) C:\Users\Basiliuws Eber\Downloads\cpu-z_1.72-en.exe 2015-04-01 18:11 - 2015-04-01 18:11 - 08146560 _____ (TeamViewer GmbH) C:\Users\Basiliuws Eber\Downloads\TeamViewer_Setup.exe 2015-03-31 13:20 - 2015-03-31 13:22 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-31 2015-03-31 11:17 - 2015-03-31 11:17 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\Chip.txt 2015-03-31 10:51 - 2015-04-04 11:44 - 00002202 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-03-31 10:51 - 2015-03-31 10:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-03-31 10:50 - 2015-03-31 10:50 - 00880208 _____ (Google Inc.) C:\Users\Basiliuws Eber\Downloads\ChromeSetup.exe 2015-03-31 10:45 - 2015-03-31 10:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Basiliuws Eber\Downloads\revosetup95.exe 2015-03-31 10:45 - 2015-03-31 10:45 - 00001291 _____ () C:\Users\Basiliuws Eber\Desktop\Revo Uninstaller.lnk 2015-03-31 10:45 - 2015-03-31 10:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-30 19:35 - 2015-03-30 19:35 - 00008793 _____ () C:\Users\Basiliuws Eber\Downloads\28.3.2015 10-07.kmz 2015-03-30 18:33 - 2015-03-30 18:35 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-30 2015-03-30 16:24 - 2015-03-30 16:24 - 13087456 _____ (Microsoft Corporation) C:\Users\Basiliuws Eber\Downloads\Silverlight_x64.exe 2015-03-30 14:23 - 2015-03-30 14:23 - 00000165 _____ () C:\Users\Basiliuws Eber\Downloads\scholar.enw 2015-03-30 08:39 - 2015-04-01 20:49 - 00000000 ____D () C:\Program Files (x86)\Universal Media Server 2015-03-30 08:39 - 2015-04-01 18:09 - 00000000 ____D () C:\ProgramData\UMS 2015-03-30 08:39 - 2015-03-30 09:01 - 00001951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server.lnk 2015-03-30 08:39 - 2015-03-30 09:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server 2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2015-03-30 08:38 - 2015-03-30 08:38 - 60871278 _____ () C:\Users\Basiliuws Eber\Downloads\UMS-5.1.0-Java7.exe 2015-03-29 22:09 - 2015-03-29 22:09 - 00000000 ____D () C:\ProgramData\Creative Labs 2015-03-29 22:02 - 2015-03-29 22:02 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2015-03-28 19:41 - 2015-03-28 19:41 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\regfix.reg 2015-03-27 01:46 - 2015-03-27 01:46 - 00001209 _____ () C:\Users\Basiliuws Eber\Downloads\HTC Support Chat.txt 2015-03-26 09:47 - 2015-03-26 09:52 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Garmin Blitzer 2015-03-26 09:31 - 2015-03-26 09:31 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Garmin 2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Mein Garmin 2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Garmin 2015-03-26 09:20 - 2015-03-26 09:20 - 00003556 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask 2015-03-26 09:20 - 2015-03-26 09:20 - 00001911 _____ () C:\Users\Public\Desktop\Garmin Express.lnk 2015-03-26 09:19 - 2015-03-26 09:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2015-03-26 09:16 - 2015-03-26 09:16 - 00000319 _____ () C:\Users\Basiliuws Eber\Downloads\Garmin-InternetExplorer-Shortcut.vbs 2015-03-26 09:03 - 2015-04-05 16:29 - 00005950 _____ () C:\Windows\PFRO.log 2015-03-25 22:37 - 2015-03-26 00:45 - 00000000 ____D () C:\ProgramData\boost_interprocess 2015-03-25 22:33 - 2015-03-25 22:33 - 00001364 _____ () C:\Users\Public\Desktop\NAVIGON Fresh.lnk 2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NAVIGON 2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\Program Files (x86)\NAVIGON 2015-03-25 22:30 - 2015-03-25 22:30 - 24192080 _____ (GARMIN Würzburg GmbH) C:\Users\Basiliuws Eber\Downloads\ud_setup_win_351.exe 2015-03-25 22:13 - 2015-03-25 22:13 - 01917440 _____ () C:\Users\Basiliuws Eber\Downloads\XmlNotepad25.msi 2015-03-25 22:13 - 2015-03-25 22:13 - 00001950 _____ () C:\Users\Basiliuws Eber\Desktop\XML Notepad 2007.lnk 2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XML Notepad 2007 2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Program Files (x86)\XML Notepad 2007 2015-03-25 15:15 - 2015-03-25 15:15 - 00030950 _____ () C:\Windows\DPINST.LOG 2015-03-25 15:04 - 2015-04-06 17:10 - 00008571 _____ () C:\Windows\setupact.log 2015-03-25 15:04 - 2015-03-25 15:04 - 03344552 _____ (Cisco Systems, Inc.) C:\Users\Basiliuws Eber\Downloads\anyconnect-win-3.1.06073-web-deploy-k9.exe 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Program Files (x86)\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 _____ () C:\Windows\setuperr.log 2015-03-25 15:04 - 2014-11-19 17:09 - 00112496 ____R (Cisco Systems, Inc.) C:\Windows\system32\Drivers\acsock64.sys 2015-03-25 14:53 - 2015-04-09 10:48 - 01843798 _____ () C:\Windows\WindowsUpdate.log 2015-03-25 10:26 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-03-24 18:02 - 2015-03-24 18:02 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Swiss Academic Software 2015-03-24 17:54 - 2015-04-08 12:24 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Citavi 4 2015-03-24 17:54 - 2015-04-08 00:16 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Swiss Academic Software 2015-03-24 17:54 - 2015-04-02 13:43 - 00000000 ____D () C:\ProgramData\Swiss Academic Software 2015-03-24 17:51 - 2015-03-24 17:51 - 00001972 _____ () C:\Users\Public\Desktop\Citavi 4.lnk 2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citavi 4 2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\Program Files (x86)\Citavi 4 2015-03-24 17:40 - 2015-03-24 17:41 - 81307064 _____ (Swiss Academic Software) C:\Users\Basiliuws Eber\Downloads\Citavi4Setup.exe 2015-03-24 13:33 - 2007-08-11 15:38 - 00810952 _____ (Charles DeWeese) C:\Users\Basiliuws Eber\Downloads\FlashSfv.exe 2015-03-24 13:13 - 2015-03-24 13:13 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2015-03-24 13:13 - 2015-03-24 13:13 - 00000000 ____D () C:\Program Files\Java 2015-03-24 13:12 - 2015-03-24 13:12 - 42925480 _____ (Oracle Corporation) C:\Users\Basiliuws Eber\Downloads\jre-8u40-windows-x64.exe 2015-03-24 12:35 - 2015-03-24 15:26 - 00000000 ____D () C:\Program Files (x86)\Dr. Hardware 2015 2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basiliuws Eber\Desktop\Dr. Hardware 2015.lnk 2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basilius Eberle\Desktop\Dr. Hardware 2015.lnk 2015-03-24 12:35 - 2015-03-24 12:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr. Hardware 2015 2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\SysWOW64\Drivers\DRHMSR64.sys 2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\system32\Drivers\DRHMSR64.sys 2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\SysWOW64\Drivers\DRHARD64.sys 2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\system32\Drivers\DRHARD64.sys 2015-03-24 11:37 - 2015-03-24 11:37 - 11800240 _____ () C:\Users\Basiliuws Eber\Downloads\SetupAnyDVD7590.exe 2015-03-23 09:48 - 2015-03-23 09:48 - 00001732 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iTunes 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iPod 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-03-22 23:27 - 2015-03-22 23:27 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe 2015-03-22 23:27 - 2015-03-22 23:27 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr 2015-03-20 09:53 - 2015-03-20 09:53 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-53-19.037-AvastVBoxSVC.exe-3568.log 2015-03-20 09:09 - 2015-03-20 09:09 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-09-20.093-AvastVBoxSVC.exe-3640.log 2015-03-20 00:56 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-56-47.018-aswFe.exe-5100.log 2015-03-20 00:55 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-55-00.053-aswFe.exe-892.log 2015-03-20 00:54 - 2015-03-20 00:54 - 00000197 _____ () C:\Windows\system32\2015-03-19-22-54-59.047-AvastVBoxSVC.exe-3240.log 2015-03-20 00:44 - 2015-03-20 00:44 - 00588816 _____ () C:\Users\Basiliuws Eber\Downloads\Autoruns.zip 2015-03-20 00:44 - 2015-03-20 00:44 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Autoruns 2015-03-20 00:27 - 2015-03-20 00:27 - 05325696 _____ (Piriform Ltd) C:\Users\Basiliuws Eber\Downloads\ccsetup503.exe 2015-03-18 15:06 - 2015-03-20 00:49 - 00001540 _____ () C:\Users\Basiliuws Eber\Downloads\malwarebytes.txt 2015-03-18 14:54 - 2015-03-18 14:54 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-54-46.089-AvastVBoxSVC.exe-3700.log 2015-03-18 14:53 - 2015-03-18 14:53 - 00000358 _____ () C:\Windows\system32\.crusader 2015-03-18 14:23 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-23-15.080-aswFe.exe-7992.log 2015-03-18 14:22 - 2015-03-18 14:22 - 04479304 _____ (Google) C:\Users\Basiliuws Eber\Downloads\software_removal_tool.exe 2015-03-18 14:21 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-21-12.001-aswFe.exe-3104.log 2015-03-18 14:21 - 2015-03-18 14:21 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-21-10.073-AvastVBoxSVC.exe-956.log 2015-03-18 14:07 - 2015-03-18 14:07 - 00002323 _____ () C:\Users\Basiliuws Eber\Downloads\software_removal_tool.log 2015-03-18 13:04 - 2015-03-18 13:04 - 02953520 _____ (AVAST Software) C:\Users\Basiliuws Eber\Downloads\avast-browser-cleanup.exe 2015-03-18 12:31 - 2015-01-29 15:24 - 00221184 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopcap.dll 2015-03-18 12:31 - 2015-01-29 15:24 - 00081920 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopacket.dll 2015-03-18 12:31 - 2015-01-29 15:24 - 00034048 _____ (CACE Technologies) C:\Windows\SysWOW64\Drivers\npf_devolo.sys 2015-03-18 11:04 - 2015-03-18 11:05 - 00000197 _____ () C:\Windows\system32\2015-03-18-09-04-59.098-AvastVBoxSVC.exe-3500.log 2015-03-18 10:50 - 2015-03-18 10:50 - 00000197 _____ () C:\Windows\system32\2015-03-18-08-50-08.045-AvastVBoxSVC.exe-3460.log 2015-03-18 10:46 - 2015-03-18 10:46 - 00001178 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2015-03-18 10:46 - 2015-03-18 10:46 - 00001128 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canneverbe Limited 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\ProgramData\Canneverbe Limited 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2015-03-18 10:45 - 2015-03-18 10:45 - 05409016 _____ (Canneverbe Limited ) C:\Users\Basiliuws Eber\Downloads\cdbxp_setup_4.5.4.5306_minimal.exe 2015-03-17 23:37 - 2015-03-17 23:36 - 03312872 _____ (DVDVideoSoft Ltd. ) C:\Users\Basiliuws 2015-03-17 23:36 - 2015-03-18 09:55 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\DVDVideoSoft 2015-03-17 11:03 - 2015-03-17 11:03 - 00005364 _____ () C:\Users\Basiliuws Eber\Downloads\13.3.2015 19-50.kmz 2015-03-16 19:43 - 2015-03-16 19:43 - 00000197 _____ () C:\Windows\system32\2015-03-16-17-43-42.097-AvastVBoxSVC.exe-3712.log 2015-03-16 11:50 - 2015-03-16 11:50 - 19759661 _____ () C:\Users\Basiliuws Eber\Downloads\SpringBloomsRebeccaHeigel.themepack 2015-03-15 21:35 - 2015-03-15 21:35 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-35-41.095-AvastVBoxSVC.exe-3548.log 2015-03-15 21:26 - 2015-03-15 21:26 - 00000000 ____D () C:\Users\Basiliuws Eber\Tracing 2015-03-15 21:24 - 2015-03-15 21:26 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-03-15 21:24 - 2015-03-15 21:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-15 21:06 - 2015-03-15 21:07 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-06-30.070-AvastVBoxSVC.exe-3456.log 2015-03-15 20:57 - 2015-03-15 20:58 - 00000197 _____ () C:\Windows\system32\2015-03-15-18-57-47.015-AvastVBoxSVC.exe-3552.log 2015-03-14 19:09 - 2015-03-06 04:53 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-14 19:09 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-03-14 19:09 - 2015-02-26 01:26 - 04178944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-14 19:09 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-14 19:09 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-03-14 19:09 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-03-14 19:09 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-03-14 19:09 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-03-14 19:09 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-14 19:09 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-03-14 19:09 - 2015-02-20 05:03 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-14 19:09 - 2015-02-20 04:58 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-14 19:09 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-14 19:09 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-14 19:09 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-14 19:09 - 2015-02-20 04:35 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-03-14 19:09 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-14 19:09 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-14 19:09 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-03-14 19:09 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-03-14 19:09 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-03-14 19:09 - 2015-02-20 04:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2015-03-14 19:09 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-03-14 19:09 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-14 19:09 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-03-14 19:09 - 2015-02-20 03:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-03-14 19:09 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-03-14 19:09 - 2015-02-20 03:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-03-14 19:09 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-14 19:09 - 2015-02-20 03:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-14 19:09 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-14 19:09 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-14 19:09 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-03-14 19:09 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-03-14 19:09 - 2015-02-20 03:29 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-03-14 19:09 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-14 19:09 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-03-14 19:09 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-03-14 19:09 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-03-14 19:09 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-14 19:09 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-14 19:09 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-03-14 19:09 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-03-14 19:09 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-03-14 19:09 - 2015-02-07 01:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml 2015-03-14 19:09 - 2015-02-06 03:28 - 02257408 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-03-14 19:09 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-03-14 19:09 - 2015-02-05 22:24 - 01113920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00264000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00044024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2015-03-14 19:09 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2015-03-14 19:09 - 2015-02-03 02:02 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2015-03-14 19:09 - 2015-02-03 01:53 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll 2015-03-14 19:09 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll 2015-03-14 19:09 - 2015-01-31 01:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2015-03-14 19:09 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2015-03-14 19:09 - 2015-01-31 01:20 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-14 19:09 - 2015-01-30 05:01 - 00097792 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys 2015-03-14 19:09 - 2015-01-30 05:00 - 00167424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys 2015-03-14 19:09 - 2015-01-30 04:03 - 01488896 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2015-03-14 19:09 - 2015-01-30 04:03 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2015-03-14 19:09 - 2015-01-30 04:02 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll 2015-03-14 19:09 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2015-03-14 19:09 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2015-03-14 19:09 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll 2015-03-14 19:09 - 2015-01-30 03:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll 2015-03-14 19:09 - 2015-01-30 03:29 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atlthunk.dll 2015-03-14 19:09 - 2015-01-30 03:24 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll 2015-03-14 19:09 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll 2015-03-14 19:09 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll 2015-03-14 19:09 - 2015-01-30 03:08 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll 2015-03-14 19:09 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll 2015-03-14 19:09 - 2015-01-29 03:58 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll 2015-03-14 19:09 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll 2015-03-14 19:09 - 2015-01-29 03:11 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-14 19:09 - 2015-01-29 03:04 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2015-03-14 19:09 - 2015-01-29 03:04 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2015-03-14 19:09 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-14 19:09 - 2015-01-29 02:59 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-03-14 19:09 - 2015-01-29 02:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2015-03-14 19:09 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2015-03-14 19:09 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-03-14 19:09 - 2015-01-28 17:41 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-14 19:09 - 2015-01-28 17:41 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-03-14 19:09 - 2015-01-28 17:41 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-03-14 19:09 - 2015-01-28 04:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll 2015-03-14 19:09 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll 2015-03-14 19:09 - 2015-01-27 06:22 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-14 19:09 - 2015-01-27 05:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe 2015-03-14 19:09 - 2015-01-27 04:11 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-14 19:09 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe 2015-03-14 19:09 - 2015-01-23 09:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2015-03-14 19:09 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2015-03-14 19:08 - 2015-02-12 19:40 - 22291584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-14 19:08 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-03-14 19:08 - 2015-02-08 01:57 - 01090048 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2015-03-14 19:08 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2015-03-14 19:08 - 2015-01-29 20:45 - 01763352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-14 19:08 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-14 19:08 - 2015-01-28 03:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-14 19:08 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2015-03-14 19:08 - 2015-01-28 01:47 - 02501368 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2015-03-14 19:08 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2015-03-14 19:08 - 2015-01-21 07:54 - 01384712 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-14 19:08 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2015-03-14 19:08 - 2014-12-11 07:36 - 00046456 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe 2015-03-14 19:06 - 2015-03-14 19:06 - 00000197 _____ () C:\Windows\system32\2015-03-14-17-06-15.019-AvastVBoxSVC.exe-3404.log 2015-03-14 07:49 - 2015-03-14 07:49 - 00009728 _____ (Razer Inc.) C:\Windows\SysWOW64\RzStats.IPC.dll Code:
ATTFilter ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-09 10:58 - 2014-12-07 16:02 - 00001180 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001UA.job 2015-04-09 10:55 - 2014-05-31 17:28 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2245731289-3221781707-2474736645-1001 2015-04-09 10:51 - 2014-05-31 11:30 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{ADF8F266-BC9E-412C-B8EE-DDA5E6A3C8C5} 2015-04-09 10:49 - 2014-09-15 21:39 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-09 10:49 - 2014-05-31 13:33 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox 2015-04-09 10:49 - 2014-05-31 12:28 - 00000000 __RDO () C:\Users\Basiliuws Eber\SkyDrive 2015-04-09 10:49 - 2014-05-31 12:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-09 10:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2015-04-09 00:54 - 2014-05-31 15:38 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\ClassicShell 2015-04-09 00:44 - 2014-05-31 12:19 - 00001142 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-09 00:43 - 2014-08-03 20:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-08 22:58 - 2014-12-07 16:02 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001Core.job 2015-04-08 21:23 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber 2015-04-08 18:41 - 2015-03-03 11:18 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\JDownloader 2.0 2015-04-08 16:00 - 2014-06-03 16:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\vlc 2015-04-08 13:22 - 2015-01-11 20:23 - 00003858 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1421000576 2015-04-08 13:22 - 2015-01-11 20:22 - 00001070 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2015-04-08 13:22 - 2015-01-11 20:22 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-04-08 08:05 - 2014-12-25 15:31 - 00016974 _____ () C:\Windows\SysWOW64\Gms.log 2015-04-07 22:43 - 2014-05-31 16:21 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-04-06 17:02 - 2014-08-23 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-04-06 17:01 - 2014-08-23 19:21 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-04-06 17:01 - 2014-08-23 19:20 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-04-06 17:01 - 2014-05-31 17:47 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-04-06 17:01 - 2014-05-31 17:26 - 01789004 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-06 17:01 - 2013-08-23 01:24 - 00768888 _____ () C:\Windows\system32\perfh007.dat 2015-04-06 17:01 - 2013-08-23 01:24 - 00160706 _____ () C:\Windows\system32\perfc007.dat 2015-04-06 17:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Help 2015-04-06 16:56 - 2014-11-30 14:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\HTC MediaHub 2015-04-06 16:55 - 2014-05-31 12:22 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2015-04-06 16:55 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-06 16:55 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-04-06 08:45 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-04-05 18:24 - 2014-06-01 10:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\my games 2015-04-04 12:37 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-04-04 11:37 - 2014-06-01 15:26 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\My Games 2015-04-04 11:01 - 2014-08-23 19:44 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA Corporation 2015-04-03 23:39 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Vss 2015-04-03 23:38 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF 2015-04-03 16:08 - 2014-05-31 16:49 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-04-01 18:26 - 2014-06-01 16:00 - 00000852 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Program Files\WinRAR 2015-04-01 18:12 - 2014-10-20 21:45 - 00001201 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2015-04-01 18:12 - 2014-10-20 21:45 - 00001189 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2015-03-31 13:21 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canon 2015-03-31 11:04 - 2014-06-01 20:09 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Skype 2015-03-31 10:51 - 2014-05-31 12:19 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Google 2015-03-31 10:50 - 2014-05-31 12:19 - 00000000 ____D () C:\Program Files (x86)\Google 2015-03-31 10:44 - 2014-08-04 09:41 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Adobe 2015-03-31 10:44 - 2014-08-03 20:04 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-03-30 22:51 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2014-07-08 2015-03-30 22:48 - 2015-01-25 13:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Congstar Rechnungen 2015-03-30 08:39 - 2014-06-03 13:58 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5 2015-03-27 01:12 - 2014-09-15 21:39 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-03-26 23:49 - 2014-08-22 00:44 - 00005468 _____ () C:\Users\Basiliuws Eber\Documents\Database.kdb 2015-03-26 09:23 - 2014-06-09 10:10 - 00000000 ____D () C:\ProgramData\Garmin 2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Garmin 2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Program Files (x86)\Garmin 2015-03-26 09:20 - 2014-06-09 10:10 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Garmin 2015-03-26 09:20 - 2014-05-31 11:35 - 00000000 ____D () C:\ProgramData\Package Cache 2015-03-26 00:52 - 2014-12-10 00:39 - 00000000 ____D () C:\Windows\system32\appraiser 2015-03-26 00:52 - 2014-07-12 10:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-03-25 23:27 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Adobe 2015-03-25 15:16 - 2014-11-30 14:34 - 00002054 _____ () C:\Users\Public\Desktop\HTC Sync Manager.lnk 2015-03-25 15:15 - 2014-05-31 11:59 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Downloaded Installations 2015-03-25 14:24 - 2014-11-24 15:43 - 00031232 ___SH () C:\Users\Basiliuws Eber\Desktop\Thumbs.db 2015-03-25 14:09 - 2014-06-16 17:11 - 00000000 ____D () C:\Windows\Minidump 2015-03-25 14:09 - 2014-06-01 20:03 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\TS3Client 2015-03-24 13:33 - 2014-06-16 12:00 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\CyberLink PowerDVD Ultra 14.0.4028.58 2015-03-24 13:30 - 2014-06-09 11:37 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\OMC ModPack 2015-03-24 13:13 - 2014-10-26 21:18 - 00000000 ____D () C:\Program Files (x86)\Java 2015-03-24 12:44 - 2014-06-01 18:41 - 00000000 ____D () C:\Program Files (x86)\SpeedFan 2015-03-24 11:37 - 2014-06-03 13:50 - 00001128 _____ () C:\Users\Public\Desktop\AnyDVD.lnk 2015-03-24 11:33 - 2014-05-31 12:04 - 00000000 ____D () C:\ProgramData\CyberLink 2015-03-24 11:32 - 2014-06-16 12:23 - 00000000 ____D () C:\ProgramData\SUPPORTDIR 2015-03-23 09:48 - 2014-06-20 10:52 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2015-03-23 09:48 - 2014-06-20 10:51 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-03-22 23:27 - 2014-05-31 13:31 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00441728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00268640 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00136752 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00088408 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00065736 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00029168 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-03-22 23:12 - 2014-06-01 15:26 - 00125664 _____ () C:\Users\Basiliuws Eber\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-20 11:16 - 2014-05-31 11:46 - 01807894 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-03-20 09:07 - 2013-08-22 16:44 - 00492672 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-20 01:08 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2015-03-20 00:27 - 2014-05-31 16:19 - 00000801 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-03-20 00:27 - 2014-05-31 16:19 - 00000000 ____D () C:\Program Files\CCleaner 2015-03-18 14:53 - 2014-09-15 21:53 - 00000000 ____D () C:\ProgramData\HitmanPro 2015-03-18 14:17 - 2014-08-24 18:44 - 00000000 ____D () C:\Temp 2015-03-18 12:32 - 2015-01-24 13:45 - 00000000 ____D () C:\Program Files (x86)\devolo 2015-03-18 10:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Performance 2015-03-18 09:56 - 2014-05-31 11:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2015-03-17 11:17 - 2014-09-16 19:05 - 00019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-03-17 07:15 - 2014-09-15 21:39 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-03-17 07:15 - 2014-09-15 21:39 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-03-17 07:15 - 2014-09-15 21:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2015-03-15 21:26 - 2014-06-01 20:09 - 00000000 ____D () C:\ProgramData\Skype 2015-03-15 21:24 - 2014-06-01 20:09 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-03-14 23:21 - 2014-05-31 18:34 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-03-14 23:21 - 2014-05-31 14:17 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-14 23:18 - 2014-05-31 14:17 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-13 09:53 - 2014-05-31 13:37 - 00001105 _____ () C:\Users\Basiliuws Eber\Desktop\Dropbox.lnk 2015-03-13 09:53 - 2014-05-31 13:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox ==================== Files in the root of some directories ======= 2014-09-16 19:05 - 2015-03-17 11:17 - 0019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-03 13:55 - 2014-06-16 14:35 - 0000040 ___SH () C:\ProgramData\.zreglib Some content of TEMP: ==================== C:\Users\Basiliuws Eber\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnnzqgy.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\nvStInst.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-02 08:18 ==================== End Of Log ============================ |
09.04.2015, 17:50 | #75 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Meine Frage?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |