|
Log-Analyse und Auswertung: PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.07.2015, 18:25 | #16 |
| PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. Hallo, seit Freitag sind die Probleme nicht wieder aufgetreten. Anbei die 3 neusten Logs. Nochmals vielen Dank für deine Hilfe! FRST: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015 Ran by Scotty (administrator) on SCOTTY-PC on 14-07-2015 19:22:31 Running from C:\Users\Scotty\Desktop Loaded Profiles: Scotty (Available Profiles: Scotty) Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avast Software s.r.o.) D:\Avast Antivir\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Windows\SysWOW64\ASGT.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () D:\GnuPG\dirmngr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\System32\PnkBstrA.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe () C:\Program Files (x86)\Photodex\ProShow Producer\scsiaccess.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Flux Software LLC) C:\Users\Scotty\AppData\Local\FluxSoftware\Flux\flux.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Avast Software s.r.o.) D:\Avast Antivir\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Mozilla Corporation) D:\Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-24] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7660760 2000-01-01] (Realtek Semiconductor) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [BCSSync] => D:\Office 2010\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [AvastUI.exe] => D:\Avast Antivir\AvastUI.exe [5515496 2015-07-07] (Avast Software s.r.o.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKU\S-1-5-21-4268881813-2952948070-2875398935-1000\...\Run: [f.lux] => C:\Users\Scotty\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC) AppInit_DLLs: D:\Sophos\SOPHOS~1\sophos_detoured_x64.dll => D:\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [218256 2012-09-21] (Sophos Limited) AppInit_DLLs-x32: D:\Sophos\SOPHOS~1\sophos_detoured.dll => D:\Sophos\Sophos Anti-Virus\sophos_detoured.dll [221840 2012-09-21] (Sophos Limited) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\Avast Antivir\ashShA64.dll [2015-07-07] (Avast Software s.r.o.) ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => D:\Office 2010\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => D:\Office 2010\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => D:\Office 2010\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => D:\Office 2010\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => D:\Office 2010\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-4268881813-2952948070-2875398935-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-4268881813-2952948070-2875398935-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\Avast Antivir\aswWebRepIE64.dll [2015-07-07] (Avast Software s.r.o.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Office 2010\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-07-06] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\Avast Antivir\aswWebRepIE.dll [2015-07-07] (Avast Software s.r.o.) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Office 2010\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-06] (Oracle Corporation) Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{9F464A7F-1380-41B4-9A30-B723D70986A3}: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{B7416966-CFB3-445C-9893-0E14162E8441}: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default FF NewTab: about:blank FF DefaultSearchEngine: DuckDuckGo FF SearchEngineOrder.1: Google FF Homepage: facebook.com | http://www.trojaner-board.de/168529-...rt-noetig.html FF Keyword.URL: https://www.google.com/search FF NetworkProxy: "ftp", "131.109.42.105" FF NetworkProxy: "ftp_port", 80 FF NetworkProxy: "http", "131.109.42.105" FF NetworkProxy: "http_port", 80 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "131.109.42.105" FF NetworkProxy: "socks_port", 80 FF NetworkProxy: "ssl", "131.109.42.105" FF NetworkProxy: "ssl_port", 80 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-13] () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> D:\PDF_XViewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-17] (Tracker Software Products (Canada) Ltd.) FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File FF Plugin: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelogx64.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> D:\PDF_XViewer\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-17] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-13] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> D:\PDF_XViewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-06-17] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.7.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.7.1\npbattlelog.dll [2015-04-30] (EA Digital Illusions CE AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-06] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-06] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> D:\OFFICE~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> D:\OFFICE~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-17] (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @photodex.com/PhotodexPresenter -> C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll [2015-06-26] ( ) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> D:\PDF_XViewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-06-17] (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> D:\VLC Player\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> D:\VLC Player\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> D:\VLC Player\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> D:\VLC Player\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> D:\VLC Player\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> D:\VLC Player\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-4268881813-2952948070-2875398935-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> D:\PDF_XViewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-06-17] (Tracker Software Products (Canada) Ltd.) FF Plugin HKU\S-1-5-21-4268881813-2952948070-2875398935-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Scotty\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-05-26] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-4268881813-2952948070-2875398935-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-06-16] () FF SearchPlugin: C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\searchplugins\duckduckgo.xml [2014-09-22] FF SearchPlugin: C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\searchplugins\metager.xml [2014-12-28] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-12-20] FF Extension: Disconnect - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\2.0@disconnect.me.xpi [2015-04-18] FF Extension: Element Hiding Helper for Adblock Plus - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\elemhidehelper@adblockplus.org.xpi [2013-08-18] FF Extension: Ghostery - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\firefox@ghostery.com.xpi [2014-01-08] FF Extension: MEGA - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\firefox@mega.co.nz.xpi [2015-02-03] FF Extension: YouTube Enhancer Plus - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\firefoxaddon@youtubeenhancer.com.xpi [2015-04-07] FF Extension: Privacy Badger Firefox - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2015-04-18] FF Extension: Reddit Enhancement Suite - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi [2013-10-29] FF Extension: ProxTube - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-09-12] FF Extension: Adblock Plus - C:\Users\Scotty\AppData\Roaming\Mozilla\Firefox\Profiles\85szks6p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-18] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2014-12-20] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\Avast Antivir\WebRep\FF FF Extension: Avast Online Security - D:\Avast Antivir\WebRep\FF [2013-08-18] FF HKU\S-1-5-21-4268881813-2952948070-2875398935-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-12-20] StartMenuInternet: FIREFOX.EXE - D:\Firefox\firefox.exe Chrome: ======= CHR Profile: C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-18] CHR Extension: (Google Drive) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-18] CHR Extension: (YouTube) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-18] CHR Extension: (Adblock Plus) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-08-18] CHR Extension: (Google Search) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-18] CHR Extension: (AdBlock) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-08-18] CHR Extension: (Avast Online Security) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-09-16] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-19] CHR Extension: (Ghostery) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2014-02-25] CHR Extension: (Google Wallet) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23] CHR Extension: (Gmail) - C:\Users\Scotty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-18] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - D:\Avast Antivir\WebRep\Chrome\aswWebRepChrome.crx [2015-03-19] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed] R2 avast! Antivirus; D:\Avast Antivir\AvastSvc.exe [343336 2015-07-07] (Avast Software s.r.o.) R2 DirMngr; D:\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed] R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-24] (NVIDIA Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] S2 MBAMService; D:\Malwarebytes' Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) S3 Microsoft SharePoint Workspace Audit Service; D:\Office 2010\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1868432 2015-06-24] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-24] (NVIDIA Corporation) S3 Origin Client Service; G:\Origin\OriginClientService.exe [2004488 2015-07-01] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-06-20] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-06-16] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) [File not signed] R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Producer\ScsiAccess.exe [186760 2015-06-26] () S2 SkypeUpdate; D:\Skype\Updater\Updater.exe [315496 2014-12-11] (Skype Technologies) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-07-07] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-07-07] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-07] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-07-07] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-07-07] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-07-07] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-07-07] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-07-07] () R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-10-26] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-20] (DT Soft Ltd) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-10-26] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-24] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46768 2015-05-19] (NVIDIA Corporation) R1 truecrypt; C:\Windows\SysWOW64\drivers\truecrypt.sys [191264 2006-07-03] (TrueCrypt Foundation) [File not signed] S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 19:21 - 2015-07-14 19:21 - 00000894 _____ C:\Users\Scotty\Desktop\checkup.txt 2015-07-14 19:21 - 2015-07-14 19:21 - 00000000 ____D C:\Users\Scotty\Desktop\FRST-OlderVersion 2015-07-14 11:19 - 2015-07-14 11:19 - 00000000 ____D C:\Program Files (x86)\ESET 2015-07-14 11:06 - 2015-07-14 11:06 - 02870984 _____ (ESET) C:\Users\Scotty\Desktop\esetsmartinstaller_deu.exe 2015-07-14 11:06 - 2015-07-14 11:06 - 00852662 _____ C:\Users\Scotty\Desktop\SecurityCheck.exe 2015-07-14 10:19 - 2015-07-14 10:19 - 00000022 _____ C:\Windows\S.dirmngr 2015-07-13 13:38 - 2015-07-13 13:38 - 00012944 _____ C:\Users\Scotty\Desktop\Kosten JGA.xlsx 2015-07-13 12:30 - 2015-07-13 12:30 - 00001510 _____ C:\Users\Scotty\Desktop\JRT.txt 2015-07-13 12:28 - 2015-07-13 12:28 - 00000207 _____ C:\Windows\tweaking.com-regbackup-SCOTTY-PC-Windows-7-Professional-N-(64-bit).dat 2015-07-13 12:28 - 2015-07-13 12:28 - 00000000 ____D C:\RegBackup 2015-07-13 12:10 - 2015-07-13 12:10 - 03034492 _____ (Malwarebytes Corporation) C:\Users\Scotty\Desktop\JRT.exe 2015-07-13 12:10 - 2015-07-13 12:10 - 02248704 _____ C:\Users\Scotty\Desktop\AdwCleaner_4.208.exe 2015-07-09 23:36 - 2015-07-09 23:36 - 00000154 _____ C:\Users\Scotty\Desktop\Tod des Fernsehens.txt 2015-07-09 17:54 - 2015-07-09 17:54 - 00019752 _____ C:\ComboFix.txt 2015-07-09 17:39 - 2015-07-09 17:54 - 00000000 ____D C:\Qoobox 2015-07-09 17:39 - 2015-07-09 17:53 - 00000000 ____D C:\Windows\erdnt 2015-07-09 17:39 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2015-07-09 17:39 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2015-07-09 17:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-07-09 17:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-07-09 17:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-07-09 17:39 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2015-07-09 17:39 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2015-07-09 17:39 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2015-07-09 17:37 - 2015-07-09 17:37 - 05632279 ____R (Swearware) C:\Users\Scotty\Desktop\ComboFix.exe 2015-07-09 11:38 - 2015-07-09 11:38 - 00000000 ____D C:\TDSSKiller_Quarantine 2015-07-08 20:44 - 2015-06-17 08:03 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-07-08 20:42 - 2015-07-08 20:42 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-07-08 20:42 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 37748880 _____ C:\Windows\SysWOW64\nvcompiler.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 22947144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 17724600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 15866992 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 13263056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 11831856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-07-08 20:42 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 02599752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 01099992 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00975176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00938752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00503408 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00408392 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00407296 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00364176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00204648 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2015-07-08 20:42 - 2015-06-17 11:10 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-07-08 20:42 - 2015-06-17 11:10 - 00040280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2015-07-08 20:27 - 2015-05-19 05:29 - 00046768 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2015-07-08 20:27 - 2015-05-19 05:14 - 00057520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2015-07-08 19:12 - 2015-07-08 19:12 - 00322816 _____ C:\Windows\Minidump\070815-14352-01.dmp 2015-07-08 10:48 - 2015-07-08 10:48 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Scotty\Desktop\tdsskiller.exe 2015-07-08 10:42 - 2015-07-08 10:48 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2015-07-08 10:39 - 2015-07-08 10:48 - 00000000 ____D C:\Users\Scotty\Desktop\mbar 2015-07-08 10:37 - 2015-07-08 10:37 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Scotty\Desktop\mbar-1.09.1.1004.exe 2015-07-07 23:09 - 2015-07-07 23:09 - 00022195 _____ C:\Users\Scotty\Desktop\Gmer-19357.zip 2015-07-07 22:33 - 2015-07-07 22:33 - 00000000 ____D C:\Program Files\avast software 2015-07-07 22:32 - 2015-07-07 22:32 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe 2015-07-07 22:32 - 2015-07-07 22:32 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr 2015-07-07 22:30 - 2015-07-07 22:30 - 00607347 _____ C:\Users\Scotty\Desktop\Gmer-19357.txt 2015-07-07 22:25 - 2015-07-07 22:37 - 00069043 _____ C:\Users\Scotty\Desktop\Addition.txt 2015-07-07 22:24 - 2015-07-14 19:22 - 00023098 _____ C:\Users\Scotty\Desktop\FRST.txt 2015-07-07 22:24 - 2015-07-14 19:22 - 00000000 ____D C:\FRST 2015-07-07 22:24 - 2015-07-07 22:24 - 00000474 _____ C:\Users\Scotty\Desktop\defogger_disable.log 2015-07-07 22:24 - 2015-07-07 22:24 - 00000000 _____ C:\Users\Scotty\defogger_reenable 2015-07-07 20:25 - 2015-07-09 17:51 - 00003684 _____ C:\Windows\PFRO.log 2015-07-07 13:19 - 2015-07-13 00:31 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-07 13:19 - 2015-07-13 00:31 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-07 12:33 - 2015-07-07 12:33 - 00380416 _____ C:\Users\Scotty\Desktop\Gmer-19357.exe 2015-07-07 12:30 - 2015-07-14 19:21 - 02133504 _____ (Farbar) C:\Users\Scotty\Desktop\FRST64.exe 2015-07-07 12:29 - 2015-07-07 12:29 - 00050477 _____ C:\Users\Scotty\Desktop\Defogger.exe 2015-07-07 11:17 - 2015-07-14 10:19 - 00003678 _____ C:\Windows\setupact.log 2015-07-07 11:17 - 2015-07-08 19:12 - 708359207 _____ C:\Windows\MEMORY.DMP 2015-07-07 11:17 - 2015-07-07 11:17 - 00315280 _____ C:\Windows\Minidump\070715-13821-01.dmp 2015-07-07 11:17 - 2015-07-07 11:17 - 00000000 _____ C:\Windows\setuperr.log 2015-07-07 11:07 - 2015-07-08 19:21 - 00010765 _____ C:\Users\Scotty\AppData\Local\Temp8.html 2015-07-07 11:05 - 2015-07-08 19:21 - 00001667 _____ C:\Users\Scotty\AppData\Local\Temp1.html 2015-07-06 20:58 - 2015-07-06 20:58 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-07-06 20:58 - 2015-07-06 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-07-06 20:58 - 2015-07-06 20:58 - 00000000 ____D C:\Program Files (x86)\Java 2015-07-06 20:03 - 2015-07-06 20:03 - 02884055 ____H C:\Users\Scotty\Desktop\~WRL0132.tmp 2015-07-05 21:36 - 2015-07-08 18:54 - 00011372 _____ C:\Users\Scotty\Desktop\Kosten Amsterdam.xlsx 2015-06-28 14:51 - 2015-06-28 14:51 - 00000000 ____D C:\Users\Scotty\Documents\Thief 2015-06-26 13:07 - 2015-06-26 13:07 - 00000000 ____D C:\Program Files (x86)\Photodex Presenter 2015-06-26 13:07 - 2015-06-26 13:07 - 00000000 ____D C:\Program Files (x86)\Photodex 2015-06-26 13:01 - 2015-06-26 13:01 - 00003114 _____ C:\Windows\System32\Tasks\{425D08CC-E5E1-475C-94DB-7668F900B965} 2015-06-23 23:42 - 2015-06-23 23:42 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\Netscape 2015-06-23 23:41 - 2015-06-23 23:41 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\Photodex 2015-06-23 23:41 - 2015-06-23 23:41 - 00000000 ____D C:\ProgramData\Photodex 2015-06-23 23:35 - 2015-06-23 23:38 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\Ashampoo Slideshow Studio HD 3 2015-06-23 23:34 - 2015-06-23 23:34 - 00000000 ____D C:\Users\Scotty\AppData\Local\ashampoo 2015-06-23 23:34 - 2015-06-23 23:34 - 00000000 ____D C:\ProgramData\Ashampoo 2015-06-23 20:30 - 2015-06-23 20:30 - 00000761 _____ C:\Users\Scotty\Desktop\Scavenger Slideshow.lnk 2015-06-23 20:08 - 2015-06-23 20:08 - 00000000 ____D C:\Users\Scotty\Documents\MAGIX_MusicEditor 2015-06-23 20:08 - 2015-06-23 20:08 - 00000000 ____D C:\Users\Scotty\AppData\Local\Magix 2015-06-23 20:07 - 2015-06-23 22:55 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\MAGIX 2015-06-23 20:07 - 2015-06-23 20:07 - 00000000 ____D C:\Users\Scotty\AppData\Local\Xara 2015-06-23 20:06 - 2015-06-29 12:04 - 00000000 ___RD C:\Users\Scotty\Documents\MAGIX 2015-06-23 20:06 - 2015-06-29 12:04 - 00000000 ____D C:\ProgramData\MAGIX 2015-06-20 22:20 - 2015-06-20 22:20 - 00000000 ____D C:\Users\Scotty\AppData\Local\ESN ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-14 19:14 - 2009-07-14 06:50 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-14 19:14 - 2009-07-14 06:50 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-14 19:09 - 2015-06-07 21:38 - 01149339 _____ C:\Windows\WindowsUpdate.log 2015-07-14 19:09 - 2013-08-18 17:21 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-14 10:34 - 2013-08-18 17:21 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-14 10:23 - 2011-04-12 10:14 - 00699416 _____ C:\Windows\system32\perfh007.dat 2015-07-14 10:23 - 2011-04-12 10:14 - 00149556 _____ C:\Windows\system32\perfc007.dat 2015-07-14 10:23 - 2009-07-14 07:12 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-14 10:19 - 2013-08-18 16:06 - 00000000 ____D C:\ProgramData\NVIDIA 2015-07-14 10:19 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-13 23:56 - 2015-03-20 00:28 - 00226168 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2015-07-13 23:50 - 2013-08-28 21:34 - 00000000 ____D C:\ProgramData\Origin 2015-07-13 15:39 - 2013-08-19 15:29 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\vlc 2015-07-13 12:22 - 2015-06-07 21:08 - 00000000 ____D C:\AdwCleaner 2015-07-13 12:18 - 2015-06-06 23:36 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-13 01:39 - 2013-08-29 13:00 - 00226168 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2015-07-13 00:31 - 2014-10-23 11:41 - 00000000 ____D C:\Users\Scotty\AppData\Local\Adobe 2015-07-10 18:59 - 2013-08-18 17:41 - 00004140 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2015-07-10 08:53 - 2014-06-23 16:20 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\avidemux 2015-07-09 17:54 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2015-07-09 17:52 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2015-07-08 20:44 - 2013-08-18 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-07-08 20:44 - 2013-08-18 16:06 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2015-07-08 19:12 - 2015-01-04 23:08 - 00000000 ____D C:\Windows\Minidump 2015-07-08 10:41 - 2015-06-06 23:35 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-07-08 10:35 - 2013-08-18 17:45 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-07-07 22:33 - 2013-08-18 17:41 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys 2015-07-07 22:32 - 2014-05-18 15:45 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys 2015-07-07 22:32 - 2014-01-03 21:37 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys 2015-07-07 22:32 - 2013-08-18 17:41 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys 2015-07-07 22:32 - 2013-08-18 17:41 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys 2015-07-07 22:32 - 2013-08-18 17:41 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys 2015-07-07 22:32 - 2013-08-18 17:41 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-07-07 22:32 - 2013-08-18 17:41 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2015-07-07 22:24 - 2013-08-18 15:22 - 00000000 ____D C:\Users\Scotty 2015-07-07 20:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SchCache 2015-07-07 12:20 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2015-07-07 11:13 - 2013-08-26 17:35 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\Azureus 2015-07-06 20:59 - 2013-10-01 12:55 - 00000000 ____D C:\ProgramData\Oracle 2015-07-06 15:44 - 2013-08-18 16:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-06-24 13:36 - 2014-11-15 03:27 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2015-06-24 13:36 - 2014-11-15 03:27 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2015-06-24 13:36 - 2013-12-11 20:47 - 01571696 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2015-06-24 13:36 - 2013-12-11 20:47 - 01320120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2015-06-24 11:34 - 2009-07-14 06:50 - 00456392 _____ C:\Windows\system32\FNTCACHE.DAT 2015-06-23 23:42 - 2013-08-18 16:49 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\Mozilla 2015-06-23 20:13 - 2013-08-18 16:47 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-06-23 20:13 - 2013-08-18 16:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-06-23 20:10 - 2013-08-18 16:04 - 00136720 _____ C:\Users\Scotty\AppData\Local\GDIPFONTCACHEV1.DAT 2015-06-23 20:06 - 2015-05-09 03:00 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2015-06-23 20:05 - 2013-09-30 20:46 - 00000000 ____D C:\ProgramData\Package Cache 2015-06-23 13:30 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-06-22 00:41 - 2013-08-29 14:33 - 00281688 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2015-06-21 11:51 - 2013-08-29 14:29 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2015-06-20 22:22 - 2014-06-28 13:32 - 00076152 _____ C:\Windows\system32\PnkBstrA.exe 2015-06-20 22:10 - 2014-01-24 17:14 - 00000000 ____D C:\Users\Scotty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2015-06-18 08:41 - 2015-06-06 23:35 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-06-18 08:41 - 2015-06-06 23:35 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-06-17 11:10 - 2015-05-20 14:16 - 12855416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-06-17 11:10 - 2015-05-20 14:16 - 01567576 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2015-06-17 11:10 - 2014-03-20 23:03 - 15224784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-06-17 11:10 - 2013-08-18 16:06 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2015-06-17 11:10 - 2013-08-18 16:06 - 00105288 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2015-06-17 11:10 - 2013-08-18 16:06 - 00030966 _____ C:\Windows\system32\nvinfo.pb 2015-06-17 11:10 - 2013-08-18 16:05 - 03395648 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-06-17 11:10 - 2013-08-18 16:05 - 02997544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-06-17 08:48 - 2013-08-18 16:06 - 06873232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-06-17 08:48 - 2013-08-18 16:06 - 03492168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-06-17 08:48 - 2013-08-18 16:06 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-06-17 08:48 - 2013-08-18 16:06 - 00937616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-06-17 08:48 - 2013-08-18 16:06 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-06-17 08:48 - 2013-08-18 16:06 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-06-16 23:04 - 2013-12-30 03:24 - 00000000 ____D C:\Users\Scotty\Documents\My Games 2015-06-16 23:04 - 2013-08-29 14:33 - 00000000 ____D C:\Users\Scotty\AppData\Local\PunkBuster 2015-06-16 23:02 - 2014-01-17 02:25 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe ==================== Files in the root of some directories ======= 2014-02-21 17:57 - 2014-02-21 17:57 - 0000000 ___SH () C:\Users\Scotty\AppData\Local\LumaEmu 2014-02-27 19:54 - 2014-02-27 19:54 - 0001488 _____ () C:\Users\Scotty\AppData\Local\recently-used.xbel 2015-07-07 11:05 - 2015-07-08 19:21 - 0001667 _____ () C:\Users\Scotty\AppData\Local\Temp1.html 2015-07-07 11:07 - 2015-07-08 19:21 - 0010765 _____ () C:\Users\Scotty\AppData\Local\Temp8.html 2015-05-20 14:40 - 2015-05-20 14:40 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2015-03-25 16:02 - 2015-03-25 16:02 - 0001534 _____ () C:\ProgramData\ss.ini Some files in TEMP: ==================== C:\Users\Scotty\AppData\Local\Temp\Quarantine.exe C:\Users\Scotty\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-07-13 18:22 ==================== End of log ============================ Code:
ATTFilter Results of screen317's Security Check version 1.004 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 8 Update 45 Adobe Flash Player 18.0.0.203 Mozilla Firefox (39.0) Mozilla Thunderbird 24.5.0 Thunderbird out of Date! Google Chrome (43.0.2357.130) Google Chrome (43.0.2357.132) ````````Process Check: objlist.exe by Laurent```````` windows defender MpCmdRun.exe AvastSvc.exe AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=17d8b5d4b1e33a46aaf52a5c61c55911 # end=init # utc_time=2015-07-14 09:19:25 # local_time=2015-07-14 11:19:25 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 24788 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=17d8b5d4b1e33a46aaf52a5c61c55911 # end=updated # utc_time=2015-07-14 09:21:18 # local_time=2015-07-14 11:21:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=17d8b5d4b1e33a46aaf52a5c61c55911 # engine=24788 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-07-14 12:28:18 # local_time=2015-07-14 02:28:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 11354 188506748 0 0 # scanned=625641 # found=1 # cleaned=0 # scan_time=11219 sh=C2397715DCDDAA8C64E38586834F2C9D2D489942 ft=1 fh=a4c2d831ae09d33b vn="Variante von Win32/Toolbar.Widgi.N evtl. unerwünschte Anwendung" ac=I fn="D:\Downloads\setup-freeripmp3_4.5.4.exe" |
15.07.2015, 09:50 | #17 |
/// the machine /// TB-Ausbilder | PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. Thunderbird updaten.
__________________Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter D:\Downloads\setup-freeripmp3_4.5.4.exe Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Cleanup: (Die Reihenfolge ist hier entscheidend) Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken. Falls Combofix verwendet wurde: Combofix deinstallieren
Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen. Absicherung: Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen: Browser Java Flash-Player PDF-Reader Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen. Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig. Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank. Meine Empfehlung: Emsisoft Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen. Optional: NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen. Lade Software von einem sauberen Portal wie . Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen. Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwcleaner . Abschließend noch ein paar grundsätzliche Bemerkungen: Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems. Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________ |
16.07.2015, 16:30 | #18 |
| PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. Hi, hier der Fixlog:
__________________Code:
ATTFilter Fix result of Farbar Recovery Scan Tool (x64) Version:13-07-2015 Ran by Scotty at 2015-07-16 16:44:22 Run:1 Running from C:\Users\Scotty\Desktop Loaded Profiles: Scotty (Available Profiles: Scotty) Boot Mode: Normal ============================================== fixlist content: ***************** D:\Downloads\setup-freeripmp3_4.5.4.exe Emptytemp: ***************** D:\Downloads\setup-freeripmp3_4.5.4.exe => moved successfully. EmptyTemp: => 725.2 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 16:44:27 ==== Vielen Dank für die Hilfe. Ich werde mich später auch noch in dem anderen Unterforum bedanken und auch etwas spenden. Ich habe hier schon einige Male Hilfe bekommen und war immer Student (=knauserig) ;-) |
17.07.2015, 10:40 | #19 |
/// the machine /// TB-Ausbilder | PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.07.2015, 20:32 | #20 |
| PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. So, Spende ist auch raus! |
21.07.2015, 07:08 | #21 |
/// the machine /// TB-Ausbilder | PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. danke
__________________ --> PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. |
Themen zu PC friert ein wenn Browser benutzt wird. Kein Blue Screen/Fehlermeldung. Manueller Neustart nötig. |
antivir, antivirus, bonjour, browser, fehler, firefox, flash player, ftp, google, helper, homepage, maus, mozilla, mp3, newtab, problem, realtek, registry, rundll, scan, security, software, starten, svchost.exe, torbrowser, tracker, usb, windows |