snicksnick | 20.10.2013 09:12 | Moin t'john,
schonmal vielen Dank für deine Hilfe, hier sind wie gefordert die Logfiles: Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.10.20.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
snick :: SNICKSNICK [Administrator]
20.10.2013 09:58:12
mbam-log-2013-10-20 (09-58-12).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 229011
Laufzeit: 1 Minute(n), 53 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
C:\Users\snick\AppData\Roaming\DVDVideoSoft\FreeYouTubeToMP3Converter.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Hier der Log vom AWD-Cleaner: Code:
# AdwCleaner v3.009 - Bericht erstellt am 20/10/2013 um 10:05:27
# Updated 19/10/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : snick - SNICKSNICK
# Gestartet von : C:\Users\snick\Desktop\AdwCleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\foxydeal.sqlite
Ordner Gefunden C:\ProgramData\boost_interprocess
Ordner Gefunden C:\Users\snick\AppData\Roaming\dvdvideosoftiehelpers
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16720
-\\ Mozilla Firefox v24.0 (de)
[ Datei : C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\prefs.js ]
Zeile gefunden : user_pref("foxgame.userprefs.foxgameDeltaTime-uni56.ogame.de", "117296");
*************************
AdwCleaner[R0].txt - [1236 octets] - [20/10/2013 10:05:27]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1296 octets] ########## Und schlussendlich der Log vom FRST, wobei mir keine Addition.txt angelegt wurde!!!
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-10-2013
Ran by snick (administrator) on SNICKSNICK on 20-10-2013 10:09:42
Running from C:\Users\snick\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Tanuki Software, Ltd.) C:\Program Files (x86)\PS3 Media Server\win32\service\wrapper.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Oracle Corporation) C:\Program Files (x86)\PS3 Media Server\jre64\bin\java.exe
(Microsoft Corporation) C:\Windows\system32\UI0Detect.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Valve Corporation) S:\Steam\Steam.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Dropbox, Inc.) C:\Users\snick\AppData\Roaming\Dropbox\bin\Dropbox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-08-12] (Microsoft Corporation)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7406392 2012-11-29] (Logitech Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Steam] - S:\Steam\steam.exe [1813928 2013-10-09] (Valve Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20684656 2013-07-25] (Skype Technologies S.A.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-09-12] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-12] (NVIDIA Corporation)
Startup: C:\Users\snick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\snick\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xAB5AD1FAD7B2CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - No File
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: HKLM {AEA3991E-3109-4C98-989E-33994FEB1A91} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri64_4.5.1.0.cab
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default
FF Homepage: www.google.de
FF NetworkProxy: "autoconfig_url", "localhost"
FF NetworkProxy: "backup.ftp", "83.216.166.21"
FF NetworkProxy: "backup.ftp_port", 80
FF NetworkProxy: "backup.gopher", "83.216.166.21"
FF NetworkProxy: "backup.gopher_port", 80
FF NetworkProxy: "backup.socks", "83.216.166.21"
FF NetworkProxy: "backup.socks_port", 80
FF NetworkProxy: "backup.ssl", "83.216.166.21"
FF NetworkProxy: "backup.ssl_port", 80
FF NetworkProxy: "http", "localhost"
FF NetworkProxy: "http_port", 8118
FF NetworkProxy: "socks", "localhost"
FF NetworkProxy: "socks_port", 9050
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "localhost"
FF NetworkProxy: "ssl_port", 8118
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin1017325.dll (Amazon.com, Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\searchplugins\leo.xml
FF SearchPlugin: C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\searchplugins\qipsearch.xml
FF SearchPlugin: C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\ich@maltegoetz.de
FF Extension: Pocket - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\isreaditlater@ideashower.com
FF Extension: No Name - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\temp
FF Extension: PDF Download - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
FF Extension: HTLiveSight - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{469b7d40-de9a-11e0-9572-0800200c9a66}
FF Extension: FEBE - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
FF Extension: All-in-One Gestures - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
FF Extension: FoxTrick - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{9d1f059c-cada-4111-9696-41a62d64e3ba}
FF Extension: DownloadHelper - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: DeviantCopyPaste - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{d5e41cd-997d-135b-2aa5-7e5c952d427}
FF Extension: No Name - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\Extensions.rdf
FF Extension: firefox - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\firefox@ghostery.com.xpi
FF Extension: No Name - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\installed-extensions.txt
FF Extension: secureLogin - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\secureLogin@blueimp.net.xpi
FF Extension: spam - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\spam@trashmail.net.xpi
FF Extension: No Name - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{7E77F5DF-8022-40e3-9122-F03DEBEFC43B}.xpi
FF Extension: No Name - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
FF Extension: No Name - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\snick\AppData\Roaming\Mozilla\Firefox\Profiles\9emip29u.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
==================== Services (Whitelisted) =================
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-08-12] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-08-12] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-02] ()
R2 PS3 Media Server; C:\Program Files (x86)\PS3 Media Server\win32\service\wrapper.exe [384280 2012-11-27] (Tanuki Software, Ltd.)
==================== Drivers (Whitelisted) ====================
S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] ()
S3 cpudrv64; C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [17864 2011-06-02] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-22] (DT Soft Ltd)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66360 2012-10-03] (Logitech Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-09-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 ASUSProcObsrv; \??\Z:\I386\AsPrOb64.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-20 10:07 - 2013-10-20 10:07 - 01954548 _____ (Farbar) C:\Users\snick\Desktop\FRST64.exe
2013-10-20 10:06 - 2013-10-20 10:06 - 00001376 _____ C:\Users\snick\Desktop\AdwCleaner[R0].txt
2013-10-20 10:05 - 2013-10-20 10:05 - 00000000 ____D C:\AdwCleaner
2013-10-20 10:03 - 2013-10-20 10:03 - 01056666 _____ C:\Users\snick\Desktop\AdwCleaner.exe
2013-10-20 09:56 - 2013-10-20 09:56 - 00000000 ____D C:\Users\snick\AppData\Roaming\Malwarebytes
2013-10-20 09:55 - 2013-10-20 09:55 - 00001131 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-20 09:55 - 2013-10-20 09:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-20 09:55 - 2013-10-20 09:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-20 09:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-19 14:51 - 2013-10-19 14:51 - 00002211 _____ C:\Users\Public\Desktop\Synology Photo Station Uploader.lnk
2013-10-19 14:51 - 2013-10-19 14:51 - 00000000 ____D C:\Users\snick\AppData\Local\Synology
2013-10-19 14:51 - 2013-10-19 14:51 - 00000000 ____D C:\Program Files (x86)\Synology
2013-10-17 18:43 - 2013-10-20 10:04 - 00000952 _____ C:\Windows\PFRO.log
2013-10-16 20:25 - 2013-10-16 20:25 - 00026150 _____ C:\ComboFix.txt
2013-10-16 20:19 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-16 20:19 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-16 20:19 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-16 20:19 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-16 20:19 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-16 20:19 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-16 20:19 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-16 20:19 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-16 20:17 - 2013-10-16 20:25 - 00000000 ____D C:\Qoobox
2013-10-16 20:17 - 2013-10-16 20:23 - 00000000 ____D C:\Windows\erdnt
2013-10-16 20:16 - 2013-10-16 20:16 - 05133109 ____R (Swearware) C:\Users\snick\Desktop\ComboFix.exe
2013-10-13 21:45 - 2013-10-20 10:04 - 00000000 ____D C:\ProgramData\PMS
2013-10-13 21:45 - 2013-10-15 22:16 - 00000000 ____D C:\Program Files (x86)\PS3 Media Server
2013-10-13 13:07 - 2013-10-13 13:07 - 1401176627 _____ C:\Windows\MEMORY.DMP
2013-10-13 13:07 - 2013-10-13 13:07 - 00287768 _____ C:\Windows\Minidump\101313-7956-01.dmp
2013-10-13 12:59 - 2013-10-13 12:59 - 00063830 _____ C:\Users\snick\Desktop\gmer.log
2013-10-13 12:48 - 2013-10-13 12:48 - 00000000 ____D C:\FRST
2013-10-13 12:46 - 2013-10-13 12:51 - 00000472 _____ C:\Users\snick\Desktop\defogger_disable.log
2013-10-13 12:46 - 2013-10-13 12:46 - 00000000 _____ C:\Users\snick\defogger_reenable
2013-10-13 10:54 - 2013-10-20 10:04 - 00003472 _____ C:\Windows\setupact.log
2013-10-13 10:54 - 2013-10-13 10:54 - 00000000 _____ C:\Windows\setuperr.log
2013-10-13 00:40 - 2013-10-19 19:11 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-13 00:40 - 2013-10-13 00:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-13 00:40 - 2013-10-13 00:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-13 00:40 - 2013-10-13 00:40 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-11 18:10 - 2013-10-11 18:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-11 17:08 - 2013-10-11 17:08 - 00052199 _____ C:\Users\snick\Desktop\Garderobe.skp
2013-10-11 16:49 - 2013-10-11 16:49 - 00000837 _____ C:\Users\snick\AppData\Local\recently-used.xbel
2013-10-11 07:21 - 2013-10-11 07:21 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-11 07:21 - 2013-10-11 07:21 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-11 07:21 - 2013-10-11 07:21 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-11 07:21 - 2013-10-11 07:21 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-10 17:27 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 17:27 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 17:27 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-10 17:27 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 17:27 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 17:27 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-10 17:27 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 17:27 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-10 17:27 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 17:27 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 17:27 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 17:27 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-09 17:38 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-09 17:38 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-09 17:38 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-09 17:38 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-09 17:38 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-09 17:38 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-09 17:38 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-09 17:38 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-09 17:38 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-09 17:38 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-09 17:38 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-09 17:38 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-09 17:38 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-09 17:38 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-09 17:38 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-09 17:38 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-09 17:38 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-09 17:38 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-09 17:38 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-09 17:38 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-09 17:38 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-09 17:38 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-09 17:38 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-09 17:38 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-09 17:38 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-09 17:38 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-09 17:38 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-09 17:38 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 17:38 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-09 17:38 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-09 17:38 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-09 17:38 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 17:38 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-09 17:38 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-09 17:38 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-09 17:38 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-09 17:38 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-09 17:38 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-09 17:38 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-09 17:38 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 17:38 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 17:38 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-09 17:37 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-09 17:37 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-09 17:37 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-09 17:37 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-09 17:37 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-09 17:37 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-09 17:37 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-09 17:37 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-09 17:37 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-09 17:37 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 17:37 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-08 18:51 - 2013-10-12 19:08 - 00000000 __SHD C:\ProgramData\Windows Update Service0
2013-10-08 18:51 - 2013-10-09 17:28 - 00003298 _____ C:\Windows\System32\Tasks\Windows Update Check - 0x1FE004EA
2013-10-08 18:46 - 2013-10-08 18:46 - 00000000 ____D C:\Users\snick\AppData\Local\MPlayer
2013-10-06 14:14 - 2013-10-06 14:15 - 00000000 ____D C:\Users\snick\AppData\Local\Alt.Binz
2013-10-06 14:14 - 2013-10-06 14:14 - 00000000 ____D C:\Program Files (x86)\Alt.Binz
2013-10-03 11:07 - 2013-10-03 11:13 - 00000000 ____D C:\Users\snick\Documents\Battlefield 4
2013-10-02 20:30 - 2013-10-02 20:30 - 00000921 _____ C:\Users\Public\Desktop\Battlefield 4™ Beta.lnk
2013-10-02 20:30 - 2013-10-02 20:30 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-02 19:54 - 2013-10-07 20:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-29 14:18 - 2013-10-13 21:09 - 00000000 ____D C:\Users\snick\Desktop\diverse Fotos
2013-09-21 01:12 - 2013-09-29 14:16 - 00000000 ____D C:\Users\snick\Desktop\Bauch
2013-09-20 23:25 - 2013-09-20 23:25 - 00000000 ____D C:\Users\snick\Documents\Egosoft
2013-09-20 23:00 - 2013-09-20 23:00 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-09-20 23:00 - 2013-09-20 23:00 - 00000000 ____D C:\Windows\system32\NV
2013-09-20 22:58 - 2013-09-22 17:18 - 00022528 _____ C:\Users\snick\Desktop\Auto.xls
2013-09-20 19:20 - 2013-09-20 19:20 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-20 19:17 - 2013-09-12 10:58 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-09-20 19:17 - 2013-09-12 10:58 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 00300320 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvkflt.sys
2013-09-20 19:17 - 2013-09-12 10:58 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-09-20 19:17 - 2013-09-12 10:58 - 00032032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2013-09-20 19:17 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2013-09-20 19:17 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
==================== One Month Modified Files and Folders =======
2013-10-20 10:07 - 2013-10-20 10:07 - 01954548 _____ (Farbar) C:\Users\snick\Desktop\FRST64.exe
2013-10-20 10:07 - 2013-01-27 12:44 - 01496657 _____ C:\Windows\WindowsUpdate.log
2013-10-20 10:06 - 2013-10-20 10:06 - 00001376 _____ C:\Users\snick\Desktop\AdwCleaner[R0].txt
2013-10-20 10:05 - 2013-10-20 10:05 - 00000000 ____D C:\AdwCleaner
2013-10-20 10:05 - 2013-08-25 16:55 - 00000000 ____D C:\Users\snick\AppData\Roaming\Skype
2013-10-20 10:05 - 2012-05-13 09:52 - 00000000 ____D C:\Users\snick\AppData\Roaming\Dropbox
2013-10-20 10:04 - 2013-10-17 18:43 - 00000952 _____ C:\Windows\PFRO.log
2013-10-20 10:04 - 2013-10-13 21:45 - 00000000 ____D C:\ProgramData\PMS
2013-10-20 10:04 - 2013-10-13 10:54 - 00003472 _____ C:\Windows\setupact.log
2013-10-20 10:04 - 2013-03-15 20:49 - 00000326 _____ C:\Windows\Tasks\GlaryInitialize.job
2013-10-20 10:04 - 2012-10-29 22:13 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-20 10:04 - 2012-05-13 01:01 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-20 10:04 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-20 10:03 - 2013-10-20 10:03 - 01056666 _____ C:\Users\snick\Desktop\AdwCleaner.exe
2013-10-20 09:56 - 2013-10-20 09:56 - 00000000 ____D C:\Users\snick\AppData\Roaming\Malwarebytes
2013-10-20 09:56 - 2009-07-14 06:45 - 00016016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-20 09:56 - 2009-07-14 06:45 - 00016016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-20 09:55 - 2013-10-20 09:55 - 00001131 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-20 09:55 - 2013-10-20 09:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-20 09:55 - 2013-10-20 09:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-20 09:55 - 2009-07-14 19:58 - 02738378 _____ C:\Windows\system32\perfh007.dat
2013-10-20 09:55 - 2009-07-14 19:58 - 00801914 _____ C:\Windows\system32\perfc007.dat
2013-10-20 09:55 - 2009-07-14 07:13 - 00006256 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-19 19:23 - 2012-10-29 22:13 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-19 19:11 - 2013-10-13 00:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-19 17:22 - 2012-05-12 20:51 - 00000000 ____D C:\Users\snick\Documents\WISO Mein Geld
2013-10-19 14:51 - 2013-10-19 14:51 - 00002211 _____ C:\Users\Public\Desktop\Synology Photo Station Uploader.lnk
2013-10-19 14:51 - 2013-10-19 14:51 - 00000000 ____D C:\Users\snick\AppData\Local\Synology
2013-10-19 14:51 - 2013-10-19 14:51 - 00000000 ____D C:\Program Files (x86)\Synology
2013-10-18 23:37 - 2012-05-12 16:12 - 00000000 ____D C:\Users\snick\AppData\Roaming\vlc
2013-10-16 20:25 - 2013-10-16 20:25 - 00026150 _____ C:\ComboFix.txt
2013-10-16 20:25 - 2013-10-16 20:17 - 00000000 ____D C:\Qoobox
2013-10-16 20:23 - 2013-10-16 20:17 - 00000000 ____D C:\Windows\erdnt
2013-10-16 20:23 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-10-16 20:16 - 2013-10-16 20:16 - 05133109 ____R (Swearware) C:\Users\snick\Desktop\ComboFix.exe
2013-10-16 19:44 - 2013-08-24 11:23 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-10-16 19:44 - 2013-08-24 09:12 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-16 19:43 - 2013-08-24 09:12 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-10-15 22:16 - 2013-10-13 21:45 - 00000000 ____D C:\Program Files (x86)\PS3 Media Server
2013-10-13 21:09 - 2013-09-29 14:18 - 00000000 ____D C:\Users\snick\Desktop\diverse Fotos
2013-10-13 21:02 - 2012-05-11 18:48 - 00000000 ___RD C:\Users\snick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-13 13:07 - 2013-10-13 13:07 - 1401176627 _____ C:\Windows\MEMORY.DMP
2013-10-13 13:07 - 2013-10-13 13:07 - 00287768 _____ C:\Windows\Minidump\101313-7956-01.dmp
2013-10-13 13:07 - 2012-05-17 17:58 - 00000000 ____D C:\Windows\Minidump
2013-10-13 12:59 - 2013-10-13 12:59 - 00063830 _____ C:\Users\snick\Desktop\gmer.log
2013-10-13 12:55 - 2013-06-15 12:22 - 00000000 ____D C:\Users\snick\AppData\Roaming\Winamp
2013-10-13 12:51 - 2013-10-13 12:46 - 00000472 _____ C:\Users\snick\Desktop\defogger_disable.log
2013-10-13 12:48 - 2013-10-13 12:48 - 00000000 ____D C:\FRST
2013-10-13 12:46 - 2013-10-13 12:46 - 00000000 _____ C:\Users\snick\defogger_reenable
2013-10-13 12:46 - 2012-05-11 18:48 - 00000000 ____D C:\Users\snick
2013-10-13 10:54 - 2013-10-13 10:54 - 00000000 _____ C:\Windows\setuperr.log
2013-10-13 00:40 - 2013-10-13 00:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-13 00:40 - 2013-10-13 00:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-13 00:40 - 2013-10-13 00:40 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-13 00:06 - 2012-05-11 19:40 - 00000000 ____D C:\Windows\Panther
2013-10-12 19:08 - 2013-10-08 18:51 - 00000000 __SHD C:\ProgramData\Windows Update Service0
2013-10-11 21:29 - 2012-06-23 12:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-11 18:14 - 2013-10-11 18:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-11 17:08 - 2013-10-11 17:08 - 00052199 _____ C:\Users\snick\Desktop\Garderobe.skp
2013-10-11 17:08 - 2013-01-20 15:25 - 00000000 ____D C:\Users\snick\.gimp-2.8
2013-10-11 17:04 - 2013-04-26 06:58 - 00000000 ____D C:\Users\snick\Desktop\Wohnung
2013-10-11 16:49 - 2013-10-11 16:49 - 00000837 _____ C:\Users\snick\AppData\Local\recently-used.xbel
2013-10-11 07:21 - 2013-10-11 07:21 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-11 07:21 - 2013-10-11 07:21 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-11 07:21 - 2013-10-11 07:21 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-11 07:21 - 2013-10-11 07:21 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-11 07:21 - 2012-10-07 17:25 - 01095080 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-10-11 07:21 - 2012-10-07 17:25 - 00973736 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-10-11 07:18 - 2012-10-29 22:13 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-11 07:18 - 2012-10-29 22:13 - 00003852 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-10 18:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-10-10 17:45 - 2009-07-14 06:45 - 00289544 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 17:44 - 2012-09-25 21:42 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 17:44 - 2012-09-25 21:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 17:24 - 2013-07-14 16:05 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 17:22 - 2012-05-15 17:52 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 17:21 - 2012-05-11 23:11 - 00001912 _____ C:\Windows\epplauncher.mif
2013-10-10 17:21 - 2012-05-11 23:11 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-10-10 17:21 - 2012-05-11 23:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2013-10-09 17:28 - 2013-10-08 18:51 - 00003298 _____ C:\Windows\System32\Tasks\Windows Update Check - 0x1FE004EA
2013-10-08 18:46 - 2013-10-08 18:46 - 00000000 ____D C:\Users\snick\AppData\Local\MPlayer
2013-10-07 20:57 - 2013-10-02 19:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-07 19:10 - 2012-05-22 07:51 - 00000000 ____D C:\Users\snick\AppData\Roaming\DAEMON Tools Lite
2013-10-06 14:15 - 2013-10-06 14:14 - 00000000 ____D C:\Users\snick\AppData\Local\Alt.Binz
2013-10-06 14:14 - 2013-10-06 14:14 - 00000000 ____D C:\Program Files (x86)\Alt.Binz
2013-10-03 11:13 - 2013-10-03 11:07 - 00000000 ____D C:\Users\snick\Documents\Battlefield 4
2013-10-03 11:07 - 2013-08-24 11:22 - 00000000 ____D C:\Users\snick\AppData\Local\PunkBuster
2013-10-03 09:56 - 2012-05-11 23:41 - 00000000 ____D C:\Users\snick\AppData\Local\Mozilla
2013-10-02 20:30 - 2013-10-02 20:30 - 00000921 _____ C:\Users\Public\Desktop\Battlefield 4™ Beta.lnk
2013-10-02 20:30 - 2013-10-02 20:30 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-02 20:30 - 2013-08-24 09:12 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-09-30 21:36 - 2013-08-24 11:22 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-09-29 14:16 - 2013-09-21 01:12 - 00000000 ____D C:\Users\snick\Desktop\Bauch
2013-09-29 14:03 - 2012-05-12 13:17 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-09-28 01:00 - 2012-05-12 12:53 - 00000000 ____D C:\Users\snick\Documents\OpenTTD
2013-09-23 01:28 - 2013-10-10 17:27 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-23 01:28 - 2013-10-10 17:27 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-23 01:27 - 2013-10-10 17:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-23 00:55 - 2013-10-10 17:27 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-23 00:55 - 2013-10-10 17:27 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-23 00:55 - 2013-10-10 17:27 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-23 00:54 - 2013-10-10 17:27 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-23 00:54 - 2013-10-10 17:27 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-22 17:18 - 2013-09-20 22:58 - 00022528 _____ C:\Users\snick\Desktop\Auto.xls
2013-09-21 05:38 - 2013-10-10 17:27 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-21 05:30 - 2013-10-10 17:27 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-21 04:48 - 2013-10-10 17:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-21 04:39 - 2013-10-10 17:27 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-20 23:25 - 2013-09-20 23:25 - 00000000 ____D C:\Users\snick\Documents\Egosoft
2013-09-20 23:13 - 2012-09-23 02:29 - 00000000 ____D C:\Users\snick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-20 23:00 - 2013-09-20 23:00 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-09-20 23:00 - 2013-09-20 23:00 - 00000000 ____D C:\Windows\system32\NV
2013-09-20 19:20 - 2013-09-20 19:20 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-20 19:20 - 2012-05-13 01:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-13 20:40
==================== End Of Log ============================ --- --- ---
Gruß
snicksnick |