Rüttelpirat | 10.09.2013 12:51 | Danke für die schnelle Hilfe!
Combofix hat kurz gemeckert. Beim Start des Programms hatte ich die Firewall (Comodo) noch an. Combofix wollte, dass ich die Firewall schließe bevor ich auf OK klicke - gesagt, getan. Obwohl die Firewall aus war, meinte Combofix quasi "Comodo Firewall ist immer noch an, aber ich leg dann einfach mal los" und hat ohne weitere Mucken den Scan ausgeführt.
P.S.: Die Scans scheinen das Problem erstmal gelöst zu haben. Der Browser ist wieder schnell, es gibt keine Wortverlinkungen, Youtube-Werbevideos o.ä. :singsing:
Log Combofix Code:
ComboFix 13-09-10.01 - Rocko 10.09.2013 13:06:35.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.4095.2391 [GMT 2:00]
ausgeführt von:: c:\users\Rocko\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
AV: ZoneAlarm Antivirus *Disabled/Updated* {DE038A5B-9EDD-18A9-2361-FF7D98D43730}
FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
FW: ZoneAlarm Firewall *Disabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *Disabled/Updated* {65626BBF-B8E7-1727-19D1-C40FE3537D8D}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\Google\Desktop\Install
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\@
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\GoogleUpdate.exe
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\L\00000004.@
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\L\201d3dde
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\L\6715e287
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\L\76603ac3
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\U\00000004.@
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\U\00000008.@
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\U\000000cb.@
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\U\80000000.@
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\U\80000032.@
c:\program files (x86)\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\9519~1\A535~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\U\80000064.@
c:\program files (x86)\update.exe
c:\users\Rocko\AppData\Local\bloson.bmp
c:\users\Rocko\AppData\Local\datos.txt
c:\users\Rocko\AppData\Local\dealply.bmp
c:\users\Rocko\AppData\Local\facemoods.bmp
c:\users\Rocko\AppData\Local\Google\Desktop\Install
c:\users\Rocko\AppData\Local\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\2E2F~1\28F0~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\@
c:\users\Rocko\AppData\Local\Google\Desktop\Install\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\2E2F~1\28F0~1\E628~1\{51c4e2b5-3f13-f3c5-9cd4-167a95da1735}\GoogleUpdate.exe
c:\users\Rocko\AppData\Local\lateral1.bmp
c:\users\Rocko\AppData\Local\lateral2.bmp
c:\users\Rocko\AppData\Local\lateral3.bmp
c:\users\Rocko\AppData\Local\save_en.bmp
c:\users\Rocko\AppData\Local\save_es.bmp
c:\users\Rocko\AppData\Roaming\.#
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-08-10 bis 2013-09-10 ))))))))))))))))))))))))))))))
.
.
2013-09-10 10:23 . 2013-09-10 10:23 -------- d-----w- C:\FRST
2013-09-10 09:58 . 2013-09-10 09:58 -------- d-----w- c:\program files (x86)\CCleaner
2013-09-09 21:57 . 2013-09-10 09:37 -------- d-----w- C:\AdwCleaner
2013-09-09 21:45 . 2013-09-09 21:45 -------- d-----w- c:\users\Rocko\AppData\Roaming\Opera Software
2013-09-09 21:45 . 2013-09-09 21:45 -------- d-----w- c:\users\Rocko\AppData\Local\Opera Software
2013-09-09 21:45 . 2013-09-10 09:41 -------- d-----w- c:\program files (x86)\Opera
2013-09-09 16:59 . 2013-09-09 16:59 -------- d-----w- c:\program files (x86)\Google
2013-09-09 13:09 . 2013-09-09 13:10 -------- d-----w- C:\e5a4b5827c8f65ea316f3b80f7b2
2013-09-09 12:59 . 2013-09-10 09:34 -------- d-----w- c:\program files (x86)\Red Faction Guerrilla
2013-09-08 17:39 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{ADC6004B-A24D-4883-A6AF-FB8B8AF15B83}\mpengine.dll
2013-09-07 13:49 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-09-06 18:05 . 2013-09-06 18:05 -------- d-----w- c:\users\Rocko\AppData\Roaming\XRay Engine
2013-09-04 18:52 . 2013-09-04 19:19 -------- d-----w- c:\program files (x86)\Fallout
2013-09-04 18:24 . 2013-09-04 21:29 -------- d-----w- c:\users\Rocko\AppData\Local\GOG.com
2013-09-04 18:24 . 2013-09-04 18:24 -------- d-----w- c:\program files (x86)\GOG.com
2013-09-01 11:55 . 2013-09-01 12:15 53248 ----a-w- c:\windows\ipuninst.exe
2013-08-18 21:47 . 2013-08-30 15:45 -------- d-----w- c:\program files (x86)\Mars War Logs
2013-08-17 13:23 . 2013-08-17 13:44 -------- d-----w- c:\program files\Firefox
2013-08-14 13:47 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-08-12 14:24 . 2013-08-12 14:24 -------- d-----w- c:\program files (x86)\Common Files\SWF Studio
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-03 21:09 . 2013-06-16 16:51 88480 ----a-w- c:\windows\system32\drivers\atksgt.sys
2013-09-03 21:09 . 2013-06-16 16:51 46400 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2013-08-14 16:24 . 2012-07-27 12:40 78161360 ----a-w- c:\windows\system32\MRT.exe
2013-08-07 13:10 . 2013-08-07 13:09 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll
2013-07-27 21:30 . 2012-03-31 13:35 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-07-27 21:30 . 2011-10-11 18:06 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-07-09 04:45 . 2013-08-14 13:47 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-06-25 09:55 . 2013-06-25 09:55 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-25 09:55 . 2012-06-14 09:43 867240 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2013-06-25 09:55 . 2011-10-11 19:42 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-20 22:48 . 2012-04-20 09:18 13164528 ----a-w- c:\program files (x86)\ts3client_win64.exe
2012-11-20 22:48 . 2012-04-20 09:18 229360 ----a-w- c:\program files (x86)\package_inst.exe
2012-10-12 12:12 . 2012-04-20 09:18 497648 ----a-w- c:\program files (x86)\_old_update.exe
2012-07-10 13:37 . 2012-04-20 09:18 110106 ----a-w- c:\program files (x86)\createfileassoc.exe
2012-04-20 09:18 . 2012-04-20 09:18 188912 ----a-w- c:\program files (x86)\error_report.exe
2012-01-15 02:58 . 2012-01-15 02:58 2740192 ----a-w- c:\program files (x86)\mumble11x.exe
2012-01-15 02:58 . 2012-01-15 02:58 4431328 ----a-w- c:\program files (x86)\mumble.exe
2011-02-19 12:47 . 2011-02-19 12:47 168104 ----a-w- c:\program files (x86)\speex.dll
2011-02-19 12:47 . 2011-02-19 12:47 129192 ----a-w- c:\program files (x86)\mumble_ol.dll
2011-02-19 12:47 . 2011-02-19 12:47 79528 ----a-w- c:\program files (x86)\celt0.0.7.0.sse2.dll
2011-02-19 12:47 . 2011-02-19 12:47 72360 ----a-w- c:\program files (x86)\celt0.0.7.0.dll
2011-02-19 12:46 . 2011-02-19 12:46 94888 ----a-w- c:\program files (x86)\celt0.0.11.0.sse2.dll
2011-02-19 12:46 . 2011-02-19 12:46 88744 ----a-w- c:\program files (x86)\celt0.0.11.0.dll
2011-01-10 18:32 . 2011-01-10 18:32 1070760 ----a-w- c:\program files (x86)\libprotobuf.dll
2011-01-10 18:31 . 2011-01-10 18:31 243368 ----a-w- c:\program files (x86)\ssleay32.dll
2011-01-10 18:31 . 2011-01-10 18:31 1233576 ----a-w- c:\program files (x86)\libeay32.dll
2011-01-10 18:21 . 2011-01-10 18:21 8223744 ----a-w- c:\program files (x86)\QtGui4.dll
2010-12-04 14:47 . 2010-12-04 14:47 957952 ----a-w- c:\program files (x86)\QtNetwork4.dll
2010-11-09 20:46 . 2010-11-09 20:46 271360 ----a-w- c:\program files (x86)\QtSvg4.dll
2010-11-09 20:39 . 2010-11-09 20:39 691712 ----a-w- c:\program files (x86)\QtOpenGL4.dll
2010-11-09 20:24 . 2010-11-09 20:24 679936 ----a-w- c:\program files (x86)\QtSql4.dll
2010-11-09 20:05 . 2010-11-09 20:05 342528 ----a-w- c:\program files (x86)\QtXml4.dll
2010-11-09 20:05 . 2010-11-09 20:05 2343424 ----a-w- c:\program files (x86)\QtCore4.dll
2010-10-04 00:50 . 2010-10-04 00:50 2259968 ----a-w- c:\program files (x86)\libsndfile-1.dll
2010-07-09 06:41 . 2010-07-09 06:41 2359296 ----a-w- c:\program files (x86)\libmysql.dll
2009-09-09 14:28 . 2009-09-09 14:28 59904 ----a-w- c:\program files (x86)\zlib1.dll
2009-02-25 08:31 . 2009-02-25 08:31 1080656 ----a-w- c:\program files (x86)\dbghelp.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="c:\program files (x86)\Vtune\TBPanel.exe" [2010-09-02 2158592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-06-05 2171904]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
c:\users\Rocko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Spamihilator.lnk - c:\programme\Spamihilator\spamihilator.exe [2013-1-7 2472448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
OnlineControl.lnk - c:\program files (x86)\OnlineControl\ocontrol.exe [2011-10-11 126976]
Ralink Wireless Utility.lnk - c:\program files (x86)\Ralink\Common\RaUI.exe -s [2011-10-11 7485792]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files (x86)\QuickTime\qttask.exe" -atboottime
"FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe"
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;c:\programme\BitComet\tools\BitCometService.exe;c:\programme\BitComet\tools\BitCometService.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;NisSrv;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
R3 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
R3 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys;c:\windows\SYSNATIVE\DRIVERS\kl2.sys [x]
S2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [x]
S2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [x]
S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\Ralink\Common\RaRegistry64.exe;c:\program files (x86)\Ralink\Common\RaRegistry64.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr7364.sys;c:\windows\SYSNATIVE\DRIVERS\netr7364.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3413079893-2748142594-2118063921-1000Core.job
- c:\users\Rocko\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-06 19:44]
.
2013-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3413079893-2748142594-2118063921-1000UA.job
- c:\users\Rocko\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-06 19:44]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-11-07 9577680]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyServer = localhost:21320
IE: &Alles mit BitComet herunterladen - c:\programme\BitComet\BitComet.exe/AddAllLink.htm
IE: Mit BitComet herunter&laden - c:\programme\BitComet\BitComet.exe/AddLink.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.2.1
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
FF - ProfilePath - c:\users\Rocko\AppData\Roaming\Mozilla\Firefox\Profiles\o2i0dduh.default-1378761206884\
FF - prefs.js: browser.startup.homepage - hxxp://z0r.de/?id=36
FF - ExtSQL: 2013-09-09 23:34; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Rocko\AppData\Roaming\Mozilla\Firefox\Profiles\o2i0dduh.default-1378761206884\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Notify-SDWinLogon - SDWinLogon.dll
HKLM-Run-ISW - (no file)
AddRemove-{43B74FAB-FB58-447D-8D3A-5F638AF36FD1} - c:\programdata\{87B61FE8-334F-4066-B7AA-68DC81782D4D}\Netzmanager1.071.0301_120720a.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3413079893-2748142594-2118063921-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ñ1[ ¶^]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3413079893-2748142594-2118063921-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ñ1[ ¶^\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-3413079893-2748142594-2118063921-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7F472B7E-9A19-35E0-45EF-913D88128490}*]
"oagbahfjjeockgfdpfmbkllfclidlh"=hex:69,61,6f,65,6f,64,70,67,6d,6e,65,6f,6f,6e,
6c,66,68,69,00,00
.
[HKEY_USERS\S-1-5-21-3413079893-2748142594-2118063921-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:cf,78,d3,c5,81,95,87,a7,72,55,2b,b9,02,84,0f,a1,3c,48,a0,52,4c,6e,75,
b0,b5,57,56,1b,ce,a1,6c,cd,f9,e9,6e,80,5a,fa,9e,cb,67,9d,63,db,28,48,28,f8,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-3413079893-2748142594-2118063921-1000\Software\SecuROM\License information*]
"datasecu"=hex:11,08,00,02,85,89,02,2c,05,8a,14,dc,b1,7f,5b,5f,0b,81,a5,0e,85,
66,78,78,b6,ae,4a,ef,ec,e7,02,14,c3,d7,34,83,87,26,76,3c,62,3c,15,3f,c0,ab,\
"rkeysecu"=hex:5a,77,91,24,34,59,e1,93,0e,9e,d9,98,7b,1e,3f,ed
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Ralink\Common\RaRegistry.exe
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\Ralink\Common\RaUI.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-09-10 13:41:22 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-09-10 11:41
.
Vor Suchlauf: 18 Verzeichnis(se), 37.255.733.248 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 37.101.793.280 Bytes frei
.
- - End Of File - - FDFF3517866904A268A10018A74F537D
A36C5E4F47E84449FF07ED3517B43A31 FSS Code:
Farbar Service Scanner Version: 05-09-2013
Ran by Rocko (administrator) on 10-09-2013 at 13:45:31
Running from "C:\Users\Rocko\Desktop"
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.
Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1
Other Services:
==============
Checking ServiceDll of RemoteAccess: ATTENTION!=====> Unable to open RemoteAccess registry key. The service key does not exist.
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log **** FRST
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-09-2013 01
Ran by Rocko (administrator) on RODRIGUEZ on 10-09-2013 13:47:25
Running from C:\Users\Rocko\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
() C:\Program Files (x86)\Vtune\TBPANEL.exe
(T-Com Bereich Endgeräte) C:\Program Files (x86)\OnlineControl\ocontrol.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
(Michel Krämer) C:\Programme\Spamihilator\spamihilator.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files\Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
(Farbar) C:\Users\Rocko\Desktop\FSS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation)
HKLM\...\Run: [ISW] - [x]
HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [9577680 2012-11-08] (COMODO)
HKCU\...\Run: [TBPanel] - C:\Program Files (x86)\Vtune\TBPanel.exe [2158592 2010-09-02] ()
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2171904 2009-06-05] (VIA)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs: C:\Windows\System32\guard64.dll [390392 2012-11-08] (COMODO)
AppInit_DLLs-x32: C:\Windows\SysWOW64\guard32.dll [301264 2012-11-08] (COMODO)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\OnlineControl.lnk
ShortcutTarget: OnlineControl.lnk -> C:\Program Files (x86)\OnlineControl\ocontrol.exe (T-Com Bereich Endgeräte)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
Startup: C:\Users\Rocko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Spamihilator.lnk
ShortcutTarget: Spamihilator.lnk -> C:\Programme\Spamihilator\spamihilator.exe (Michel Krämer)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
ProxyServer: localhost:21320
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Programme\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
DPF: HKLM-x32 {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Rocko\AppData\Roaming\Mozilla\Firefox\Profiles\o2i0dduh.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Rocko\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Rocko\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] C:\Program Files\CheckPoint\ZAForceField\TrustChecker
FF Extension: No Name - C:\Program Files\CheckPoint\ZAForceField\TrustChecker
FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF Extension: ZoneAlarm Security Engine - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Firefox\firefox.exe
Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Users\Rocko\AppData\Local\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Rocko\AppData\Local\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Rocko\AppData\Local\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.0.3) - C:\Program Files\Firefox\plugins\npqtplugin.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.3) - C:\Program Files\Firefox\plugins\npqtplugin2.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.3) - C:\Program Files\Firefox\plugins\npqtplugin3.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.3) - C:\Program Files\Firefox\plugins\npqtplugin4.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.3) - C:\Program Files\Firefox\plugins\npqtplugin5.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.3) - C:\Program Files\Firefox\plugins\npqtplugin6.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.3) - C:\Program Files\Firefox\plugins\npqtplugin7.dll (Apple Computer, Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files\Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Media Go Detector) - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\Rocko\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Docs) - C:\Users\Rocko\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Rocko\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\Rocko\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Rocko\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Gmail) - C:\Users\Rocko\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
S3 BITCOMET_HELPER_SERVICE; C:\Programme\BitComet\tools\BitCometService.exe [1296728 2010-12-28] (www.BitComet.com)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2828408 2012-11-08] (COMODO)
R2 IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [827520 2012-04-30] (Check Point Software Technologies)
S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-12-26] ()
S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
S3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
S3 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2446392 2012-06-01] (Check Point Software Technologies LTD)
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-03] ()
R3 Cardex; C:\Windows\SysWOW64\drivers\TBPANELX64.SYS [15648 2007-03-16] (Windows (R) Server 2003 DDK provider)
R3 Cardex; C:\Windows\SysWOW64\drivers\TBPANELX64.SYS [15648 2007-03-16] (Windows (R) Server 2003 DDK provider)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [584056 2012-11-08] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [38144 2012-11-08] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [271424 2011-10-18] (DT Soft Ltd)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [94288 2012-11-08] (COMODO)
R2 ISWKL; C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [33672 2012-04-30] (Check Point Software Technologies)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [460888 2012-01-09] (Kaspersky Lab ZAO)
R1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11864 2012-01-09] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [485680 2012-01-09] (Kaspersky Lab)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-03] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] ()
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2011-10-11] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-03] (Anchorfree Inc.)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [454232 2011-05-07] (Check Point Software Technologies LTD)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
S3 WinRing0_1_2_0; C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [14544 2010-11-01] (OpenLibSys.org)
U3 a2747q6w; C:\Windows\System32\Drivers\a2747q6w.sys [0 ] (Advanced Micro Devices)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 TBPanel; No ImagePath
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-10 13:45 - 2013-09-10 13:45 - 00002608 _____ C:\Users\Rocko\Desktop\FSS.txt
2013-09-10 13:44 - 2013-09-10 13:44 - 00358609 _____ (Farbar) C:\Users\Rocko\Desktop\FSS.exe
2013-09-10 13:41 - 2013-09-10 13:41 - 00023125 _____ C:\ComboFix.txt
2013-09-10 13:20 - 2013-09-10 13:22 - 00019646 _____ C:\Windows\WindowsUpdate.log
2013-09-10 13:18 - 2013-09-10 13:18 - 00001270 _____ C:\Windows\PFRO.log
2013-09-10 13:03 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-10 13:03 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-10 13:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-10 13:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-10 13:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-10 13:03 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-10 13:03 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-10 13:03 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-10 13:02 - 2013-09-10 13:41 - 00000000 ____D C:\Qoobox
2013-09-10 13:01 - 2013-09-10 13:39 - 00000000 ____D C:\Windows\erdnt
2013-09-10 13:01 - 2013-09-10 13:01 - 05125565 ____R (Swearware) C:\Users\Rocko\Desktop\ComboFix.exe
2013-09-10 12:23 - 2013-09-10 12:23 - 00000000 ____D C:\FRST
2013-09-10 12:08 - 2013-09-10 13:37 - 00000784 _____ C:\Windows\setupact.log
2013-09-10 12:08 - 2013-09-10 12:08 - 00000000 _____ C:\Windows\setuperr.log
2013-09-10 11:58 - 2013-09-10 11:58 - 00000000 ____D C:\Program Files (x86)\CCleaner
2013-09-09 23:57 - 2013-09-10 11:37 - 00000000 ____D C:\AdwCleaner
2013-09-09 23:57 - 2013-09-09 23:57 - 01037278 _____ C:\Users\Rocko\Downloads\3003-adwcleaner.exe
2013-09-09 23:45 - 2013-09-10 11:41 - 00000000 ____D C:\Program Files (x86)\Opera
2013-09-09 23:45 - 2013-09-09 23:45 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\Opera Software
2013-09-09 23:45 - 2013-09-09 23:45 - 00000000 ____D C:\Users\Rocko\AppData\Local\Opera Software
2013-09-09 23:42 - 2013-09-09 23:44 - 32093736 _____ (Opera Software ASA) C:\Users\Rocko\Downloads\Opera_16.0.1196.73_Setup.exe
2013-09-09 18:59 - 2013-09-09 18:59 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-09 15:09 - 2013-09-09 15:10 - 00000000 ____D C:\e5a4b5827c8f65ea316f3b80f7b2
2013-09-09 14:59 - 2013-09-10 11:34 - 00000000 ____D C:\Program Files (x86)\Red Faction Guerrilla
2013-09-06 20:05 - 2013-09-06 20:05 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\XRay Engine
2013-09-04 21:19 - 2013-09-04 21:19 - 00001880 _____ C:\Users\Public\Desktop\Fallout.lnk
2013-09-04 20:52 - 2013-09-04 21:19 - 00000000 ____D C:\Program Files (x86)\Fallout
2013-09-04 20:26 - 2013-09-04 20:52 - 00000000 ____D C:\Users\Rocko\Desktop\GOG
2013-09-04 20:24 - 2013-09-04 23:29 - 00000000 ____D C:\Users\Rocko\AppData\Local\GOG.com
2013-09-04 20:24 - 2013-09-04 20:24 - 00000000 ____D C:\Program Files (x86)\GOG.com
2013-09-03 23:25 - 2013-09-06 19:45 - 00006592 _____ C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
2013-09-03 23:23 - 2013-09-03 23:30 - 00000000 ____D C:\Users\Public\Documents\s.t.a.l.k.e.r. - call of pripyat
2013-09-01 21:38 - 2013-09-01 21:46 - 00000000 ____D C:\Users\Public\Documents\stalker-stcs
2013-09-01 13:55 - 2013-09-01 14:15 - 00053248 _____ (Interplay Productions) C:\Windows\ipuninst.exe
2013-09-01 13:55 - 2013-09-01 13:55 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Black Isle
2013-08-30 20:06 - 2013-08-30 20:06 - 00000000 ____D C:\Users\Rocko\Documents\Ubisoft
2013-08-26 19:26 - 2013-09-09 22:34 - 00000000 ____D C:\Users\Rocko\Desktop\Ghost Recon Advanced Warfighter 2
2013-08-20 15:37 - 2013-08-20 18:49 - 00000000 ____D C:\Users\Rocko\Desktop\Metro DLC
2013-08-18 21:08 - 2013-08-21 17:57 - 00000000 ____D C:\Users\Rocko\Desktop\SKYRIM DLC
2013-08-17 15:23 - 2013-08-17 15:44 - 00000000 ____D C:\Program Files\Firefox
2013-08-14 18:22 - 2013-07-25 05:54 - 17830400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 18:22 - 2013-07-25 05:37 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 18:22 - 2013-07-25 05:35 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 18:22 - 2013-07-25 05:31 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 18:22 - 2013-07-25 05:30 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 18:22 - 2013-07-25 05:29 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-14 18:22 - 2013-07-25 05:29 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-14 18:22 - 2013-07-25 05:29 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 18:22 - 2013-07-25 05:28 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 18:22 - 2013-07-25 05:28 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 18:22 - 2013-07-25 05:28 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 18:22 - 2013-07-25 05:28 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-14 18:22 - 2013-07-25 05:28 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-14 18:22 - 2013-07-25 05:27 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 18:22 - 2013-07-25 05:27 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-14 18:22 - 2013-07-25 05:26 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 18:22 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 18:22 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 18:22 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 18:22 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 18:22 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 18:22 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-08-14 18:22 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-08-14 18:22 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 18:22 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 18:22 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 18:22 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 18:22 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-08-14 18:22 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-08-14 18:22 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 18:22 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 18:22 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-08-14 15:47 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 15:47 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 15:47 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 15:47 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 15:47 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 15:47 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 15:47 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 15:47 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 15:47 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 15:47 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 15:47 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 15:47 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 15:47 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 15:47 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 15:47 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 15:47 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 15:47 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 15:47 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 15:47 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 15:47 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 15:47 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 15:47 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 15:47 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 15:47 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 15:47 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 15:47 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 15:47 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-09-10 13:47 - 2013-09-10 13:47 - 01949196 _____ (Farbar) C:\Users\Rocko\Desktop\FRST64.exe
2013-09-10 13:45 - 2013-09-10 13:45 - 00002608 _____ C:\Users\Rocko\Desktop\FSS.txt
2013-09-10 13:44 - 2013-09-10 13:44 - 00358609 _____ (Farbar) C:\Users\Rocko\Desktop\FSS.exe
2013-09-10 13:41 - 2013-09-10 13:41 - 00023125 _____ C:\ComboFix.txt
2013-09-10 13:41 - 2013-09-10 13:02 - 00000000 ____D C:\Qoobox
2013-09-10 13:41 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-09-10 13:39 - 2013-09-10 13:01 - 00000000 ____D C:\Windows\erdnt
2013-09-10 13:37 - 2013-09-10 12:08 - 00000784 _____ C:\Windows\setupact.log
2013-09-10 13:37 - 2011-10-11 21:07 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\Spamihilator
2013-09-10 13:37 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-09-10 13:25 - 2009-07-14 06:45 - 00018432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-10 13:25 - 2009-07-14 06:45 - 00018432 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-10 13:22 - 2013-09-10 13:20 - 00019646 _____ C:\Windows\WindowsUpdate.log
2013-09-10 13:18 - 2013-09-10 13:18 - 00001270 _____ C:\Windows\PFRO.log
2013-09-10 13:18 - 2011-10-11 17:36 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-10 13:18 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-10 13:04 - 2013-06-06 21:44 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3413079893-2748142594-2118063921-1000UA.job
2013-09-10 13:02 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-10 13:01 - 2013-09-10 13:01 - 05125565 ____R (Swearware) C:\Users\Rocko\Desktop\ComboFix.exe
2013-09-10 12:23 - 2013-09-10 12:23 - 00000000 ____D C:\FRST
2013-09-10 12:08 - 2013-09-10 12:08 - 00000000 _____ C:\Windows\setuperr.log
2013-09-10 12:04 - 2013-03-06 16:12 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\Winamp
2013-09-10 12:04 - 2011-10-13 14:14 - 00000000 ____D C:\Users\Rocko\AppData\Local\MediaMonkey
2013-09-10 12:04 - 2011-10-11 23:42 - 00000000 ____D C:\Program Files (x86)\Steam
2013-09-10 12:04 - 2011-10-11 20:09 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\DAEMON Tools Pro
2013-09-10 11:58 - 2013-09-10 11:58 - 00000000 ____D C:\Program Files (x86)\CCleaner
2013-09-10 11:58 - 2013-06-06 18:26 - 00002784 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-09-10 11:41 - 2013-09-09 23:45 - 00000000 ____D C:\Program Files (x86)\Opera
2013-09-10 11:37 - 2013-09-09 23:57 - 00000000 ____D C:\AdwCleaner
2013-09-10 11:34 - 2013-09-09 14:59 - 00000000 ____D C:\Program Files (x86)\Red Faction Guerrilla
2013-09-10 01:09 - 2011-10-30 21:14 - 00000000 ____D C:\Users\Rocko\Documents\My Games
2013-09-10 01:09 - 2011-10-11 17:27 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-10 00:01 - 2012-06-17 15:22 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\CheckPoint
2013-09-09 23:57 - 2013-09-09 23:57 - 01037278 _____ C:\Users\Rocko\Downloads\3003-adwcleaner.exe
2013-09-09 23:45 - 2013-09-09 23:45 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\Opera Software
2013-09-09 23:45 - 2013-09-09 23:45 - 00000000 ____D C:\Users\Rocko\AppData\Local\Opera Software
2013-09-09 23:44 - 2013-09-09 23:42 - 32093736 _____ (Opera Software ASA) C:\Users\Rocko\Downloads\Opera_16.0.1196.73_Setup.exe
2013-09-09 23:22 - 2012-02-26 00:30 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-09-09 23:22 - 2011-11-27 21:42 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\FreeArc
2013-09-09 23:22 - 2011-10-11 20:59 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-09-09 23:22 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-09 23:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-09-09 22:34 - 2013-08-26 19:26 - 00000000 ____D C:\Users\Rocko\Desktop\Ghost Recon Advanced Warfighter 2
2013-09-09 18:59 - 2013-09-09 18:59 - 00000000 ____D C:\Program Files (x86)\Google
2013-09-09 18:59 - 2013-06-06 21:44 - 00000000 ____D C:\Users\Rocko\AppData\Local\Google
2013-09-09 16:46 - 2013-06-25 18:08 - 00000000 ____D C:\Users\Rocko\Desktop\Game ISOs
2013-09-09 15:10 - 2013-09-09 15:09 - 00000000 ____D C:\e5a4b5827c8f65ea316f3b80f7b2
2013-09-09 14:04 - 2013-06-06 21:44 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3413079893-2748142594-2118063921-1000Core.job
2013-09-08 21:27 - 2011-10-11 20:29 - 00000000 ____D C:\Users\Rocko\Desktop\Stuff
2013-09-08 20:01 - 2011-10-11 18:13 - 00000000 ____D C:\Filme
2013-09-08 01:39 - 2012-02-26 00:30 - 00002026 _____ C:\Windows\epplauncher.mif
2013-09-06 20:05 - 2013-09-06 20:05 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\XRay Engine
2013-09-06 19:45 - 2013-09-03 23:25 - 00006592 _____ C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
2013-09-05 16:05 - 2011-10-11 17:44 - 00078912 _____ C:\Users\Rocko\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-05 16:04 - 2009-07-14 06:45 - 00327704 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-04 23:29 - 2013-09-04 20:24 - 00000000 ____D C:\Users\Rocko\AppData\Local\GOG.com
2013-09-04 21:19 - 2013-09-04 21:19 - 00001880 _____ C:\Users\Public\Desktop\Fallout.lnk
2013-09-04 21:19 - 2013-09-04 20:52 - 00000000 ____D C:\Program Files (x86)\Fallout
2013-09-04 20:52 - 2013-09-04 20:26 - 00000000 ____D C:\Users\Rocko\Desktop\GOG
2013-09-04 20:24 - 2013-09-04 20:24 - 00000000 ____D C:\Program Files (x86)\GOG.com
2013-09-03 23:30 - 2013-09-03 23:23 - 00000000 ____D C:\Users\Public\Documents\s.t.a.l.k.e.r. - call of pripyat
2013-09-03 23:09 - 2013-06-16 18:51 - 00088480 _____ C:\Windows\system32\Drivers\atksgt.sys
2013-09-03 23:09 - 2013-06-16 18:51 - 00046400 _____ C:\Windows\system32\Drivers\lirsgt.sys
2013-09-03 15:00 - 2011-10-11 18:17 - 00000000 ____D C:\Musik
2013-09-01 21:46 - 2013-09-01 21:38 - 00000000 ____D C:\Users\Public\Documents\stalker-stcs
2013-09-01 14:18 - 2012-11-20 17:10 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-01 14:15 - 2013-09-01 13:55 - 00053248 _____ (Interplay Productions) C:\Windows\ipuninst.exe
2013-09-01 13:55 - 2013-09-01 13:55 - 00000000 ____D C:\Users\Rocko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Black Isle
2013-08-30 20:06 - 2013-08-30 20:06 - 00000000 ____D C:\Users\Rocko\Documents\Ubisoft
2013-08-30 17:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-28 14:47 - 2011-10-11 17:19 - 00000000 ____D C:\Users\Rocko
2013-08-28 14:28 - 2013-05-28 01:31 - 00000000 ____D C:\Users\Rocko\Desktop\DR2-0003_data
2013-08-22 15:52 - 2011-10-28 17:47 - 00000000 ____D C:\Program Files (x86)\LucasArts
2013-08-21 17:57 - 2013-08-18 21:08 - 00000000 ____D C:\Users\Rocko\Desktop\SKYRIM DLC
2013-08-20 19:32 - 2013-05-21 01:01 - 00000000 ____D C:\ProgramData\Steam
2013-08-20 19:31 - 2013-05-21 00:43 - 00000000 ____D C:\Program Files (x86)\Metro Last Light
2013-08-20 18:49 - 2013-08-20 15:37 - 00000000 ____D C:\Users\Rocko\Desktop\Metro DLC
2013-08-18 23:51 - 2012-12-10 19:01 - 00000000 ____D C:\ProgramData\RELOADED
2013-08-18 15:39 - 2012-05-02 19:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-17 15:44 - 2013-08-17 15:23 - 00000000 ____D C:\Program Files\Firefox
2013-08-16 03:04 - 2009-07-14 19:58 - 00696620 _____ C:\Windows\system32\perfh007.dat
2013-08-16 03:04 - 2009-07-14 19:58 - 00147916 _____ C:\Windows\system32\perfc007.dat
2013-08-16 03:04 - 2009-07-14 07:13 - 01633540 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-14 18:26 - 2013-07-13 19:57 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 18:24 - 2012-07-27 14:40 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-01 16:27
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- |