Code:
ComboFix 13-09-30.02 - kofler 30.09.2013 11:11:25.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4094.2512 [GMT 2:00]
ausgeführt von:: c:\users\kofler\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\IsUn0407.exe
c:\windows\IsUn0410.exe
c:\windows\SysWow64\frapsvid.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-08-28 bis 2013-09-30 ))))))))))))))))))))))))))))))
.
.
2013-09-30 09:19 . 2013-09-30 09:19 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-09-30 09:19 . 2013-09-30 09:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-30 08:52 . 2013-09-30 08:52 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{613DAD22-1746-454F-8ABB-002D1B11710E}\offreg.dll
2013-09-30 08:44 . 2013-09-30 08:44 -------- d-----w- C:\FRST
2013-09-30 08:18 . 2013-08-30 07:48 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-09-30 08:18 . 2013-08-30 07:48 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-09-30 08:18 . 2013-08-30 07:48 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-09-30 08:18 . 2013-08-30 07:48 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-09-30 08:18 . 2013-08-30 07:48 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-09-30 08:18 . 2013-08-30 07:48 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-09-30 08:18 . 2013-08-30 07:48 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-09-30 08:18 . 2013-08-30 07:48 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-09-30 08:18 . 2013-08-30 07:47 41664 ----a-w- c:\windows\avastSS.scr
2013-09-30 08:17 . 2013-09-30 08:17 -------- d-----w- c:\program files\AVAST Software
2013-09-27 09:57 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{613DAD22-1746-454F-8ABB-002D1B11710E}\mpengine.dll
2013-09-16 09:59 . 2013-09-16 09:59 -------- d-----w- c:\program files (x86)\HyperCam 2
2013-09-11 09:09 . 2013-08-02 01:59 3968960 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-09-10 10:29 . 2013-09-10 10:29 -------- d-----w- c:\windows\de
2013-09-10 10:28 . 2013-09-10 10:28 -------- d-----w- c:\program files (x86)\Microsoft SQL Server Compact Edition
2013-09-10 10:24 . 2013-09-10 10:24 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\dc53aeeb1ceae0f04\DSETUP.dll
2013-09-10 10:24 . 2013-09-10 10:24 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\dc53aeeb1ceae0f04\DXSETUP.exe
2013-09-10 10:24 . 2013-09-10 10:24 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\dc53aeeb1ceae0f04\dsetup32.dll
2013-09-10 10:23 . 2013-09-10 10:23 525656 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\d99b899a1ceae0f03\DXSETUP.exe
2013-09-10 10:23 . 2013-09-10 10:23 94040 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\d99b899a1ceae0f03\DSETUP.dll
2013-09-10 10:23 . 2013-09-10 10:23 1691480 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\d99b899a1ceae0f03\dsetup32.dll
2013-09-10 10:23 . 2013-09-10 10:23 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\d84802911ceae0f02\DSETUP.dll
2013-09-10 10:23 . 2013-09-10 10:23 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\d84802911ceae0f02\DXSETUP.exe
2013-09-10 10:23 . 2013-09-10 10:23 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\d84802911ceae0f02\dsetup32.dll
2013-09-10 10:23 . 2013-09-10 10:32 -------- d-----w- c:\users\kofler\AppData\Local\Windows Live
2013-09-09 13:10 . 2013-09-09 13:41 -------- d-----w- c:\program files (x86)\Hearthstone
2013-09-06 16:27 . 2013-09-06 16:27 -------- d-----w- c:\users\kofler\AppData\Local\Blizzard
2013-09-06 15:44 . 2013-09-12 12:37 -------- d-----w- c:\users\kofler\AppData\Local\Battle.net
2013-09-06 15:44 . 2013-09-06 15:57 -------- d-----w- c:\users\kofler\AppData\Roaming\Battle.net
2013-09-06 15:44 . 2013-09-06 15:45 -------- d-----w- c:\program files (x86)\Battle.net
2013-09-06 08:39 . 2013-09-06 08:39 -------- d-----w- c:\program files (x86)\CamStudio 2.7
2013-09-03 09:37 . 2013-09-16 14:53 -------- d-----w- c:\program files (x86)\DevPro
2013-09-01 14:13 . 2013-09-01 14:13 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2013-09-01 08:36 . 2013-09-30 08:06 -------- d-----w- c:\users\kofler\AppData\Local\Htc
2013-09-01 08:35 . 2013-09-01 08:36 -------- d-----w- c:\users\kofler\AppData\Roaming\HTC
2013-09-01 08:33 . 2013-09-01 08:33 -------- d-----w- c:\program files (x86)\Spirent Communications
2013-09-01 08:33 . 2013-09-01 08:35 -------- d-----w- c:\program files (x86)\HTC
2013-09-01 07:37 . 2013-09-06 07:33 -------- d-----w- c:\users\kofler\MyStuff
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-20 17:20 . 2012-04-17 14:29 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-20 17:20 . 2011-05-27 15:27 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-11 13:22 . 2009-08-24 08:35 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-09-10 10:27 . 2012-07-17 12:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-08-30 07:47 . 2011-03-10 11:58 287840 ----a-w- c:\windows\system32\aswBoot.exe
2013-08-07 02:22 . 2009-10-26 09:10 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-08-02 01:48 . 2013-09-11 09:09 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2013-07-25 09:25 . 2013-08-25 21:11 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-25 08:57 . 2013-08-25 21:11 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58 . 2013-08-25 21:11 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-19 01:41 . 2013-08-25 21:11 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-07-09 05:52 . 2013-08-25 21:12 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-07-09 05:51 . 2013-08-25 21:11 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 05:46 . 2013-08-25 21:12 1472512 ----a-w- c:\windows\system32\crypt32.dll
2013-07-09 05:46 . 2013-08-25 21:12 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-09 05:46 . 2013-08-25 21:12 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-09 04:52 . 2013-08-25 21:11 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2013-07-09 04:52 . 2013-08-25 21:12 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
2013-07-09 04:46 . 2013-08-25 21:12 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-07-09 04:46 . 2013-08-25 21:12 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-07-09 04:46 . 2013-08-25 21:12 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-07-06 06:03 . 2013-08-25 21:11 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 519DC3239A027F822032E928A11309DB . 2389504 . . [6.1.7600.16385] .. c:\windows\explorer.exe
[7] 2010-11-20 . AC4C51EB24AA95B77F705AB159189E24 . 2872320 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[7] 2009-10-31 . B8EC4BD49CE8F6FC457721BFC210B67F . 2870272 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[7] 2009-10-31 . 9AAAEC8DAC27AA17B053E6352AD233AE . 2870272 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[7] 2009-08-03 . 700073016DAC1C3D2E7E2CE4223334B6 . 2868224 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[7] 2009-08-03 . F170B4A061C9E026437B193B4D571799 . 2868224 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[7] 2009-07-14 . C235A51CB740E45FFA0EBFB9BAFCDA64 . 2868224 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-07-25 20684656]
"Spotify"="c:\users\kofler\AppData\Roaming\Spotify\Spotify.exe" [2013-09-24 4728320]
"Spotify Web Helper"="c:\users\kofler\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-09-24 1140736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2013-05-13 659456]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968]
.
c:\users\kofler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2013-6-9 38072]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetPointII.exe [2009-7-21 815104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R0 aswRvrt;aswRvrt; [x]
R1 aswSnx;aswSnx; [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswVmm;aswVmm; [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - ASWVMM
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-30 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 17:20]
.
2013-09-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1254090876-3804836020-1009838053-1003Core.job
- c:\users\kofler\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-29 20:04]
.
2013-09-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1254090876-3804836020-1009838053-1003UA.job
- c:\users\kofler\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-29 20:04]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-06-25 7883296]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://it.ask.com/?l=dis&o=1586&gct=hp
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\kofler\AppData\Roaming\Mozilla\Firefox\Profiles\ryuc3id6.default\
FF - prefs.js: browser.startup.homepage - hxxp://mysearch.avg.com/?cid={32022FCD-F83E-4EC6-8A5C-D805E7727242}&mid=046a1e1c6c5847d0942cbdb90ff7050f-5b1780bcfb0f83e3aa8c93b9d284a0bae719187f&lang=ge/finishurl=hxxp://toolbar.avg.com/p-install?lang=ge&ds=ht011&pr=sa&d=&v=&pid=safeguard&sg=0&sap=hp
FF - prefs.js: keyword.URL -
FF - ExtSQL: 2013-09-01 16:15; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\kofler\AppData\Roaming\Mozilla\Firefox\Profiles\ryuc3id6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF - user.js: extensions.Softonic.rvrtMsg - Click Yes to keep current home page and default search settings, Click No to restore original settings
FF - user.js: extensions.Softonic.autoRvrt - false
FF - user.js: extensions.Softonic_i.newTab - false
FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MON00015/tb_v1?SearchSource=1&cc=&q=
FF - user.js: extensions.Softonic.id - 5cd882ad0000000000006cf04913ecfc
FF - user.js: extensions.Softonic.instlDay - 15498
FF - user.js: extensions.Softonic.vrsn - 1.5.24.3
FF - user.js: extensions.Softonic.vrsni - 1.5.24.3
FF - user.js: extensions.Softonic_i.vrsnTs - 1.5.24.311:36
FF - user.js: extensions.Softonic.prtnrId - softonic
FF - user.js: extensions.Softonic.prdct - Softonic
FF - user.js: extensions.Softonic.aflt - SD
FF - user.js: extensions.Softonic_i.smplGrp - none
FF - user.js: extensions.Softonic.tlbrId - base
FF - user.js: extensions.Softonic.instlRef - MON00015
FF - user.js: extensions.Softonic.dfltLng - de
FF - user.js: extensions.Softonic.excTlbr - false
FF - user.js: extensions.Softonic.admin - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
AddRemove-Adobe Acrobat 5.0 - c:\windows\ISUN0410.EXE
AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE
AddRemove-uTorrent - c:\ptr\uTorrent.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1254090876-3804836020-1009838053-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:dc,60,87,c9,ec,72,78,c8,c5,75,2f,b0,64,a8,2e,6c,18,3e,b5,ba,08,f5,61,
c8,a0,b3,7a,c8,75,dd,a8,0e,5a,2b,51,fa,ba,28,36,da,a8,d7,d8,ff,8a,4d,10,85,\
"??"=hex:41,e0,42,8c,cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-09-30 11:21:26
ComboFix-quarantined-files.txt 2013-09-30 09:21
.
Vor Suchlauf: 16 Verzeichnis(se), 245.821.616.128 Bytes frei
Nach Suchlauf: 22 Verzeichnis(se), 245.958.582.272 Bytes frei
.
- - End Of File - - 9FD1469B1BB3FDC20B9BEBB6E687158D
A36C5E4F47E84449FF07ED3517B43A31
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2013 02
Ran by kofler (administrator) on TEHKOF on 30-09-2013 11:23:36
Running from C:\Users\kofler\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint II\SetPointII.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Users\kofler\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\kofler\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\kofler\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\kofler\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\kofler\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\kofler\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7883296 2009-06-25] (Realtek Semiconductor)
HKLM\...\Run: [snpstd3] - C:\Windows\vsnpstd3.exe [827392 2006-09-19] ()
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.)
HKCU\...\Run: [Spotify] - C:\Users\kofler\AppData\Roaming\Spotify\Spotify.exe [4728320 2013-09-24] (Spotify Ltd)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\kofler\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1140736 2013-09-24] (Spotify Ltd)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [659456 2013-05-13] ()
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
Startup: C:\Users\kofler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://it.ask.com/?l=dis&o=1586&gct=hp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7F1136F0512ECB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - Plasmoo URL = hxxp://plasmoo.com/index.htm?SearchMashine=true&q={searchTerms}
SearchScopes: HKCU - {46A0923D-EF63-48E8-919B-8D2E5A2C46DD} URL = hxxp://it.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=867034&p={searchTerms}
SearchScopes: HKCU - {AF295EA1-364B-469E-8507-06E433965322} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=DVS2&o=1586&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AAA&apn_dtid=^YYYYYY^YY^IT&apn_uid=108ef067-1a15-4083-9e43-dad54759eaab&apn_sauid=8E4FB332-78B3-4C2E-86CF-54B847FE9398
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\kofler\AppData\Roaming\Mozilla\Firefox\Profiles\ryuc3id6.default
FF user.js: detected! => C:\Users\kofler\AppData\Roaming\Mozilla\Firefox\Profiles\ryuc3id6.default\user.js
FF Homepage: hxxp://mysearch.avg.com/?cid={32022FCD-F83E-4EC6-8A5C-D805E7727242}&mid=046a1e1c6c5847d0942cbdb90ff7050f-5b1780bcfb0f83e3aa8c93b9d284a0bae719187f&lang=ge/finishurl=hxxp://toolbar.avg.com/p-install?lang=ge&ds=ht011&pr=sa&d=&v=&pid=safeguard&sg=0&sap=hp
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\kofler\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\kofler\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\kofler\AppData\Roaming\Mozilla\Firefox\Profiles\ryuc3id6.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR Extension: (Unbenannt) - C:\Users\kofler\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfflclienhejkfddbbljfikiknlallhb\1.0_0
CHR Extension: (Adblock Plus) - C:\Users\kofler\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0
CHR Extension: (avast! Online Security) - C:\Users\kofler\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\kofler\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR StartMenuInternet: Google Chrome - C:\Users\kofler\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10550272 2007-03-27] (Sonix Co. Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-06-28] (Duplex Secure Ltd.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
U3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 gdrv; \??\C:\Windows\gdrv.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-30 11:23 - 2013-09-30 11:23 - 01953880 _____ (Farbar) C:\Users\kofler\Desktop\FRST64.exe
2013-09-30 11:21 - 2013-09-30 11:21 - 00022128 _____ C:\ComboFix.txt
2013-09-30 11:09 - 2013-09-30 11:21 - 00000000 ____D C:\Qoobox
2013-09-30 11:09 - 2013-09-30 11:19 - 00000000 ____D C:\Windows\erdnt
2013-09-30 11:09 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-09-30 11:09 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-09-30 11:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-09-30 11:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-09-30 11:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-09-30 11:09 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-09-30 11:09 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-09-30 11:09 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-09-30 11:06 - 2013-09-30 11:07 - 05131234 ____R (Swearware) C:\Users\kofler\Desktop\ComboFix.exe
2013-09-30 10:44 - 2013-09-30 10:44 - 00000000 ____D C:\FRST
2013-09-30 10:42 - 2013-09-30 10:42 - 01953880 _____ (Farbar) C:\Users\kofler\Downloads\FRST64.exe
2013-09-30 10:18 - 2013-09-30 10:18 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-30 10:18 - 2013-09-30 10:18 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-09-30 10:18 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-09-30 10:18 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-09-30 10:18 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-09-30 10:18 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-09-30 10:18 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-09-30 10:18 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-09-30 10:18 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-09-30 10:18 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-09-30 10:18 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-09-30 10:17 - 2013-09-30 10:17 - 00000000 ____D C:\Program Files\AVAST Software
2013-09-30 10:14 - 2013-09-30 10:16 - 131918888 _____ C:\Users\kofler\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe
2013-09-29 14:57 - 2013-09-29 14:57 - 00732299 _____ C:\Users\kofler\Downloads\template.psd
2013-09-29 10:01 - 2013-09-29 10:15 - 573104836 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 25 [1080p].mkv
2013-09-26 19:51 - 2013-09-26 19:51 - 00000000 ____D C:\Users\kofler\Downloads\ONE OK ROCK
2013-09-22 13:03 - 2013-09-22 13:17 - 578237682 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 22 [1080p].mkv
2013-09-22 12:14 - 2013-09-22 12:52 - 579328026 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 19 [1080p].mkv
2013-09-22 12:14 - 2013-09-22 12:51 - 578129109 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 21 [1080p].mkv
2013-09-22 12:13 - 2013-09-22 12:51 - 578151737 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 20 [1080p].mkv
2013-09-22 11:18 - 2013-09-22 11:32 - 579790960 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 24 [1080p].mkv
2013-09-22 11:16 - 2013-09-22 11:16 - 00044808 _____ C:\Users\kofler\Downloads\[katproxy.com]horriblesubs.shingeki.no.kyojin.24.1080p.mkv.torrent
2013-09-16 12:15 - 2013-09-16 12:15 - 04684602 _____ C:\Users\kofler\Documents\clip0001.avi
2013-09-16 11:59 - 2013-09-16 11:59 - 00000000 ____D C:\Users\kofler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperCam 2
2013-09-16 11:59 - 2013-09-16 11:59 - 00000000 ____D C:\Program Files (x86)\HyperCam 2
2013-09-16 11:58 - 2013-09-16 11:58 - 05401856 _____ C:\Users\kofler\Downloads\HC228SetDE.exe
2013-09-15 21:35 - 2013-09-25 18:17 - 00000000 ____D C:\Users\kofler\Desktop\Yugi
2013-09-15 09:58 - 2013-09-15 10:16 - 578736008 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 23 [1080p].mkv
2013-09-11 15:23 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 15:23 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 15:23 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 15:23 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 15:23 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 15:23 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 15:23 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 15:23 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-11 15:23 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 15:23 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-11 15:23 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 15:23 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-11 15:23 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-11 15:23 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-11 11:09 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 11:09 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-11 11:09 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-11 11:09 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-11 11:09 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-11 11:09 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-11 11:09 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-11 11:09 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-11 11:09 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-11 11:09 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-11 11:09 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-11 11:09 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-11 11:09 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-11 11:09 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-11 11:09 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-11 11:09 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-11 11:09 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-11 11:09 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-11 11:09 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-11 11:09 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-11 11:09 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 11:09 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-11 11:09 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-11 11:09 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-11 11:09 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-11 11:09 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-10 12:29 - 2013-09-10 12:29 - 00000000 ____D C:\Windows\de
2013-09-10 12:28 - 2013-09-10 12:28 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-09-10 12:23 - 2013-09-10 12:32 - 00000000 ____D C:\Users\kofler\AppData\Local\Windows Live
2013-09-10 12:22 - 2013-09-10 12:22 - 01245168 _____ (Microsoft Corporation) C:\Users\kofler\Downloads\wlsetup-web.exe
2013-09-09 15:10 - 2013-09-09 15:41 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-09-09 15:09 - 2013-09-09 15:09 - 05906904 _____ (Blizzard Entertainment) C:\Users\kofler\Downloads\Hearthstone-Beta-Setup-enGB.exe
2013-09-06 18:27 - 2013-09-06 18:27 - 00000000 ____D C:\Users\kofler\AppData\Local\Blizzard
2013-09-06 17:44 - 2013-09-12 14:37 - 00000000 ____D C:\Users\kofler\AppData\Local\Battle.net
2013-09-06 17:44 - 2013-09-06 17:57 - 00000000 ____D C:\Users\kofler\AppData\Roaming\Battle.net
2013-09-06 17:44 - 2013-09-06 17:45 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-09-06 17:41 - 2013-09-06 17:41 - 05906904 _____ (Blizzard Entertainment) C:\Users\kofler\Downloads\Hearthstone-Beta-Setup-deDE.exe
2013-09-06 11:28 - 2013-09-06 14:52 - 00004519 _____ C:\Users\kofler\AppData\Roaming\CamStudio.cfg
2013-09-06 11:28 - 2013-09-06 14:52 - 00000408 _____ C:\Users\kofler\AppData\Roaming\CamShapes.ini
2013-09-06 11:28 - 2013-09-06 14:52 - 00000408 _____ C:\Users\kofler\AppData\Roaming\CamLayout.ini
2013-09-06 11:28 - 2013-09-06 14:52 - 00000104 _____ C:\Users\kofler\AppData\Roaming\Camdata.ini
2013-09-06 10:39 - 2013-09-06 10:39 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7
2013-09-06 10:32 - 2013-09-06 10:32 - 03099532 _____ (CamStudio Open Source ) C:\Users\kofler\Downloads\CamStudio_2.7_r316_setup.exe
2013-09-03 11:37 - 2013-09-16 16:53 - 00000000 ____D C:\Program Files (x86)\DevPro
2013-09-03 11:15 - 2013-09-03 11:24 - 379543952 _____ (YGOPro DevPro Online ) C:\Users\kofler\Downloads\SetupDevPro1.9.4r3.exe
2013-09-01 16:13 - 2013-09-01 16:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-01 16:13 - 2013-09-01 16:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-01 16:11 - 2013-09-01 16:12 - 22240760 _____ (Mozilla) C:\Users\kofler\Downloads\Firefox_Setup_23.0.1.exe
2013-09-01 10:59 - 2013-09-01 10:59 - 00000000 ____D C:\Users\kofler\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2013-09-01 10:36 - 2013-09-30 10:06 - 00000000 ____D C:\Users\kofler\AppData\Local\Htc
2013-09-01 10:35 - 2013-09-01 10:36 - 00000000 ____D C:\Users\kofler\AppData\Roaming\HTC
2013-09-01 10:33 - 2013-09-01 10:35 - 00000000 ____D C:\Program Files (x86)\HTC
2013-09-01 10:33 - 2013-09-01 10:33 - 00000000 ____D C:\Program Files (x86)\Spirent Communications
2013-09-01 09:53 - 2013-09-01 09:53 - 00000000 ____D C:\Users\kofler\Downloads\LinkList
2013-09-01 09:52 - 2013-09-01 09:52 - 00035406 _____ C:\Users\kofler\Downloads\linklist___launcher_by_wittydesign-d351yj4.zip
2013-09-01 09:37 - 2013-09-06 09:33 - 00000000 ____D C:\Users\kofler\MyStuff
==================== One Month Modified Files and Folders =======
2013-09-30 11:23 - 2013-09-30 11:23 - 01953880 _____ (Farbar) C:\Users\kofler\Desktop\FRST64.exe
2013-09-30 11:21 - 2013-09-30 11:21 - 00022128 _____ C:\ComboFix.txt
2013-09-30 11:21 - 2013-09-30 11:09 - 00000000 ____D C:\Qoobox
2013-09-30 11:21 - 2010-04-02 21:12 - 06194688 ___SH C:\Users\kofler\Desktop\Thumbs.db
2013-09-30 11:21 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-09-30 11:20 - 2012-08-25 12:56 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-30 11:19 - 2013-09-30 11:09 - 00000000 ____D C:\Windows\erdnt
2013-09-30 11:19 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-09-30 11:07 - 2013-09-30 11:06 - 05131234 ____R (Swearware) C:\Users\kofler\Desktop\ComboFix.exe
2013-09-30 10:58 - 2013-02-04 23:09 - 00000000 ____D C:\Program Files (x86)\THQ
2013-09-30 10:58 - 2010-01-06 09:49 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-30 10:53 - 2010-02-12 11:07 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-30 10:51 - 2010-01-20 17:34 - 00000000 ____D C:\Users\kofler\AppData\Roaming\Adobe
2013-09-30 10:51 - 2010-01-20 14:47 - 00000000 ___RD C:\Users\kofler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-30 10:50 - 2012-06-03 17:32 - 00000000 ____D C:\wow 2
2013-09-30 10:45 - 2012-06-29 22:04 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1254090876-3804836020-1009838053-1003UA.job
2013-09-30 10:44 - 2013-09-30 10:44 - 00000000 ____D C:\FRST
2013-09-30 10:42 - 2013-09-30 10:42 - 01953880 _____ (Farbar) C:\Users\kofler\Downloads\FRST64.exe
2013-09-30 10:21 - 2013-02-13 04:22 - 00000000 ____D C:\Users\kofler\AppData\Roaming\aicon
2013-09-30 10:18 - 2013-09-30 10:18 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-09-30 10:18 - 2013-09-30 10:18 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-09-30 10:18 - 2011-03-10 13:58 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-09-30 10:17 - 2013-09-30 10:17 - 00000000 ____D C:\Program Files\AVAST Software
2013-09-30 10:17 - 2011-03-10 13:58 - 00000000 ____D C:\ProgramData\AVAST Software
2013-09-30 10:16 - 2013-09-30 10:14 - 131918888 _____ C:\Users\kofler\Downloads\avast_free_antivirus_setup_8.0.1497.376.exe
2013-09-30 10:13 - 2009-07-14 06:45 - 00018880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-30 10:13 - 2009-07-14 06:45 - 00018880 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-30 10:09 - 2010-01-20 14:45 - 01518184 ____N C:\Windows\WindowsUpdate.log
2013-09-30 10:06 - 2013-09-01 10:36 - 00000000 ____D C:\Users\kofler\AppData\Local\Htc
2013-09-30 10:06 - 2013-03-19 07:43 - 00000000 ____D C:\Users\kofler\AppData\Roaming\Spotify
2013-09-30 10:06 - 2010-01-20 17:26 - 00000000 ____D C:\Users\kofler\AppData\Roaming\Skype
2013-09-30 10:05 - 2010-01-06 09:57 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-30 10:05 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-29 23:01 - 2010-02-01 16:34 - 00000000 ____D C:\Users\kofler\AppData\Roaming\vlc
2013-09-29 17:35 - 2013-03-19 07:43 - 00000000 ____D C:\Users\kofler\AppData\Local\Spotify
2013-09-29 14:57 - 2013-09-29 14:57 - 00732299 _____ C:\Users\kofler\Downloads\template.psd
2013-09-29 10:24 - 2010-04-15 15:21 - 00000000 ____D C:\Users\kofler\AppData\Roaming\uTorrent
2013-09-29 10:15 - 2013-09-29 10:01 - 573104836 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 25 [1080p].mkv
2013-09-28 23:45 - 2012-06-29 22:04 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1254090876-3804836020-1009838053-1003Core.job
2013-09-26 19:51 - 2013-09-26 19:51 - 00000000 ____D C:\Users\kofler\Downloads\ONE OK ROCK
2013-09-25 18:17 - 2013-09-15 21:35 - 00000000 ____D C:\Users\kofler\Desktop\Yugi
2013-09-24 17:12 - 2013-02-11 12:28 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-09-24 17:12 - 2010-01-20 17:26 - 00000000 ____D C:\ProgramData\Skype
2013-09-22 13:17 - 2013-09-22 13:03 - 578237682 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 22 [1080p].mkv
2013-09-22 12:52 - 2013-09-22 12:14 - 579328026 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 19 [1080p].mkv
2013-09-22 12:51 - 2013-09-22 12:14 - 578129109 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 21 [1080p].mkv
2013-09-22 12:51 - 2013-09-22 12:13 - 578151737 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 20 [1080p].mkv
2013-09-22 11:32 - 2013-09-22 11:18 - 579790960 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 24 [1080p].mkv
2013-09-22 11:16 - 2013-09-22 11:16 - 00044808 _____ C:\Users\kofler\Downloads\[katproxy.com]horriblesubs.shingeki.no.kyojin.24.1080p.mkv.torrent
2013-09-20 19:20 - 2012-08-25 12:56 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-09-20 19:20 - 2012-04-17 16:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-20 19:20 - 2011-05-27 17:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-16 16:53 - 2013-09-03 11:37 - 00000000 ____D C:\Program Files (x86)\DevPro
2013-09-16 12:15 - 2013-09-16 12:15 - 04684602 _____ C:\Users\kofler\Documents\clip0001.avi
2013-09-16 11:59 - 2013-09-16 11:59 - 00000000 ____D C:\Users\kofler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperCam 2
2013-09-16 11:59 - 2013-09-16 11:59 - 00000000 ____D C:\Program Files (x86)\HyperCam 2
2013-09-16 11:58 - 2013-09-16 11:58 - 05401856 _____ C:\Users\kofler\Downloads\HC228SetDE.exe
2013-09-15 10:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-15 10:16 - 2013-09-15 09:58 - 578736008 _____ C:\Users\kofler\Downloads\[HorribleSubs] Shingeki no Kyojin - 23 [1080p].mkv
2013-09-13 23:30 - 2009-08-21 08:55 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-12 14:37 - 2013-09-06 17:44 - 00000000 ____D C:\Users\kofler\AppData\Local\Battle.net
2013-09-11 17:00 - 2010-01-20 14:47 - 00000000 ___RD C:\Users\kofler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-11 16:59 - 2009-07-14 06:45 - 00442552 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-11 15:23 - 2013-08-26 00:19 - 00000000 ____D C:\Windows\system32\MRT
2013-09-11 15:22 - 2009-08-24 10:35 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-10 12:32 - 2013-09-10 12:23 - 00000000 ____D C:\Users\kofler\AppData\Local\Windows Live
2013-09-10 12:29 - 2013-09-10 12:29 - 00000000 ____D C:\Windows\de
2013-09-10 12:28 - 2013-09-10 12:28 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-09-10 12:28 - 2010-01-20 17:29 - 00000000 ____D C:\Program Files (x86)\Windows Live
2013-09-10 12:27 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-09-10 12:22 - 2013-09-10 12:22 - 01245168 _____ (Microsoft Corporation) C:\Users\kofler\Downloads\wlsetup-web.exe
2013-09-10 12:19 - 2009-07-14 19:58 - 03813770 _____ C:\Windows\system32\perfh007.dat
2013-09-10 12:19 - 2009-07-14 19:58 - 01123912 _____ C:\Windows\system32\perfc007.dat
2013-09-10 12:19 - 2009-07-14 07:13 - 00006220 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-09 15:41 - 2013-09-09 15:10 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-09-09 15:09 - 2013-09-09 15:09 - 05906904 _____ (Blizzard Entertainment) C:\Users\kofler\Downloads\Hearthstone-Beta-Setup-enGB.exe
2013-09-06 18:27 - 2013-09-06 18:27 - 00000000 ____D C:\Users\kofler\AppData\Local\Blizzard
2013-09-06 17:57 - 2013-09-06 17:44 - 00000000 ____D C:\Users\kofler\AppData\Roaming\Battle.net
2013-09-06 17:45 - 2013-09-06 17:44 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-09-06 17:44 - 2010-01-20 17:41 - 00000000 ____D C:\Users\kofler\AppData\Local\Blizzard Entertainment
2013-09-06 17:41 - 2013-09-06 17:41 - 05906904 _____ (Blizzard Entertainment) C:\Users\kofler\Downloads\Hearthstone-Beta-Setup-deDE.exe
2013-09-06 14:52 - 2013-09-06 11:28 - 00004519 _____ C:\Users\kofler\AppData\Roaming\CamStudio.cfg
2013-09-06 14:52 - 2013-09-06 11:28 - 00000408 _____ C:\Users\kofler\AppData\Roaming\CamShapes.ini
2013-09-06 14:52 - 2013-09-06 11:28 - 00000408 _____ C:\Users\kofler\AppData\Roaming\CamLayout.ini
2013-09-06 14:52 - 2013-09-06 11:28 - 00000104 _____ C:\Users\kofler\AppData\Roaming\Camdata.ini
2013-09-06 10:39 - 2013-09-06 10:39 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7
2013-09-06 10:32 - 2013-09-06 10:32 - 03099532 _____ (CamStudio Open Source ) C:\Users\kofler\Downloads\CamStudio_2.7_r316_setup.exe
2013-09-06 09:33 - 2013-09-01 09:37 - 00000000 ____D C:\Users\kofler\MyStuff
2013-09-04 12:06 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-04 10:35 - 2010-11-13 16:58 - 00007602 _____ C:\Users\kofler\AppData\Local\Resmon.ResmonCfg
2013-09-03 21:17 - 2010-01-20 14:57 - 00115016 _____ C:\Users\kofler\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-03 11:24 - 2013-09-03 11:15 - 379543952 _____ (YGOPro DevPro Online ) C:\Users\kofler\Downloads\SetupDevPro1.9.4r3.exe
2013-09-01 16:13 - 2013-09-01 16:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-01 16:13 - 2013-09-01 16:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-01 16:12 - 2013-09-01 16:11 - 22240760 _____ (Mozilla) C:\Users\kofler\Downloads\Firefox_Setup_23.0.1.exe
2013-09-01 10:59 - 2013-09-01 10:59 - 00000000 ____D C:\Users\kofler\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2013-09-01 10:36 - 2013-09-01 10:35 - 00000000 ____D C:\Users\kofler\AppData\Roaming\HTC
2013-09-01 10:35 - 2013-09-01 10:33 - 00000000 ____D C:\Program Files (x86)\HTC
2013-09-01 10:35 - 2013-08-27 13:16 - 00003612 _____ C:\Windows\System32\Tasks\Launch HTC Sync Loader
2013-09-01 10:34 - 2011-01-13 20:27 - 00000000 ____D C:\Users\kofler\AppData\Local\Downloaded Installations
2013-09-01 10:33 - 2013-09-01 10:33 - 00000000 ____D C:\Program Files (x86)\Spirent Communications
2013-09-01 10:00 - 2010-01-20 14:45 - 00000000 ____D C:\Users\kofler
2013-09-01 09:53 - 2013-09-01 09:53 - 00000000 ____D C:\Users\kofler\Downloads\LinkList
2013-09-01 09:52 - 2013-09-01 09:52 - 00035406 _____ C:\Users\kofler\Downloads\linklist___launcher_by_wittydesign-d351yj4.zip
Files to move or delete:
====================
C:\Users\kofler\AppData\Roaming\CamLayout.ini
C:\Users\kofler\AppData\Roaming\CamShapes.ini
C:\Users\kofler\loleusetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2013-08-28 21:05] - [2010-11-20 15:24] - 2389504 ____A (Microsoft Corporation) 519DC3239A027F822032E928A11309DB
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-15 10:40
==================== End Of Log ============================ --- --- ---
--- --- --- |