Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Mein PC (Windows 7) fährt ab und an einfach herunter und dann wieder hoch (https://www.trojaner-board.de/145140-pc-windows-7-faehrt-ab-einfach-herunter-dann-hoch.html)

Tron Legacy 25.11.2013 13:10

Mein PC (Windows 7) fährt ab und an einfach herunter und dann wieder hoch
 
Guten Tag,

mein PC fährt ab und an einfach herunter und dann wieder hoch. Beim Herunterfahren erscheint für ganz kurze Zeit ein blauer Bildschirm (vielleicht 2 Sekunden), dann beginnt das hochfahren. Habe als Maßnahme bereits unerwünschte Software (Toolbars etc.) gelöscht und eine Bereinigung mit adwcleaner.exe durchgeführt. Da ich mich fachlich leider gar nicht auskenne und das Problem weiterhin unregelmässig auftritt, wende ich mich nun an dieses Forum. Ich habe in diesem Forum bei einem ähnlichen Problem gelesen, dass die Minidump - Datei wohl hilfreich sein kann. Die Datei vom letzten "Absturz" habe ich als Anlage beigefügt!



Über die Unterstützung eines Administrators hier in diesem Forum freue ich mich sehr!

MfG

schrauber 25.11.2013 14:26

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Tron Legacy 25.11.2013 18:43

Hallo und Danke für die schnelle Reaktion.
Ich habe Deine Anweisungen ausgeführt.
Die beiden Dateien sind angehängt!...

schrauber 26.11.2013 10:42

Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Tron Legacy 26.11.2013 11:32

Okay, sorry! Habe das jetzt hier über den angegebenen Weg hinterlegt.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-11-2013
Ran by Matze (administrator) on MATZE on 25-11-2013 18:38:07
Running from C:\Users\Oliver\Downloads
Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
() C:\Windows\FixCamera.exe
() C:\Windows\tsnp325.exe
() C:\Windows\vsnp325.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [FixCamera] - C:\Windows\FixCamera.exe [20480 2007-02-12] ()
HKLM\...\Run: [tsnp325] - C:\Windows\tsnp325.exe [270336 2007-04-21] ()
HKLM\...\Run: [snp325] - C:\Windows\vsnp325.exe [835584 2007-05-10] ()
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-13] (AVAST Software)
HKLM\...\Run: [20131121] - C:\Program Files\AVAST Software\Avast\setup\emupdate\d34f9bf2-9998-4757-b5fd-d14c82bfe111.exe [180184 2013-11-24] (AVAST Software)
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
MountPoints2: {45331aad-3803-11e3-8c1f-806e6f6e6963} - H:\SETUP.EXE

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x40B7EEEFDFB5CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {18AFC003-D470-4A4A-9530-E8F855ECC625} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=452F443A-770F-452D-843B-D39DE0A4F915&apn_sauid=7E900D89-93AA-4259-8AD9-AA531B0A729C
SearchScopes: HKCU - {D139E9D3-CC3C-4E7B-855E-F48B22905211} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=a06cb25d000000000000000ea6a14a85&r=265
SearchScopes: HKCU - {E756FA29-DFAC-4122-ADB2-78B2C8930399} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3279453&CUI=UN39287179881133811&UM=2
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\8u6g1zla.default
FF NewTab: hxxp://www.google.com/firefox
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com/firefox
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.169\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.169\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt

Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_1
CHR Extension: (Google Drive) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1
CHR Extension: (YouTube) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1
CHR Extension: (Google Search) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1
CHR Extension: (Google Wallet) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-13] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [116776 2013-11-13] (AVAST Software)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)

==================== Drivers (Whitelisted) ====================

R3 3xHybrid; C:\Windows\System32\DRIVERS\3xHybrid.sys [1141888 2010-12-01] (NXP Semiconductors Germany GmbH)
R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [35656 2013-11-13] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26136 2013-11-13] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2013-11-13] (AVAST Software)
R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [259928 2013-11-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-11-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-11-13] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [774392 2013-11-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [403440 2013-11-13] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2013-11-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [178304 2013-11-13] ()
R3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd6.sys [44032 2009-07-13] (VIA Technologies, Inc.              )
R3 SNP325; C:\Windows\System32\DRIVERS\snp325.sys [10343168 2007-05-07] (Sonix Co. Ltd.)
R3 W8100PCI; C:\Windows\System32\DRIVERS\mrv8k51.sys [311936 2005-06-08] (Marvell Semiconductor, Inc)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-25 18:38 - 2013-11-25 18:38 - 00009081 _____ C:\Users\Oliver\Downloads\FRST.txt
2013-11-25 18:38 - 2013-11-25 18:38 - 00000000 ____D C:\FRST
2013-11-25 18:36 - 2013-11-25 18:37 - 01091583 _____ (Farbar) C:\Users\Oliver\Downloads\FRST.exe
2013-11-25 13:08 - 2013-11-25 13:08 - 00013851 _____ C:\Users\Oliver\Desktop\Crash 2.zip
2013-11-25 13:04 - 2013-11-25 13:04 - 00014852 _____ C:\Users\Oliver\Desktop\Crash 3.txt
2013-11-25 13:03 - 2013-11-25 13:03 - 00198520 _____ C:\Users\Oliver\Desktop\Crash 2.txt
2013-11-25 13:01 - 2013-11-25 13:01 - 00002102 _____ C:\Users\Oliver\Desktop\Crash.txt
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Program Files\NirSoft
2013-11-25 12:56 - 2013-11-25 12:56 - 00141480 _____ C:\Users\Oliver\Downloads\bluescreenview_152setup.exe
2013-11-25 11:32 - 2013-11-25 11:33 - 00143048 _____ C:\Windows\Minidump\112513-15531-01.dmp
2013-11-20 15:25 - 2013-11-20 15:25 - 00143048 _____ C:\Windows\Minidump\112013-20000-01.dmp
2013-11-20 01:05 - 2013-11-20 01:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 01:05 - 2013-11-20 01:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 01:05 - 2013-11-20 01:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 01:05 - 2013-11-20 01:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 01:05 - 2013-11-20 01:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-20 01:04 - 2013-11-20 01:09 - 00010261 _____ C:\Windows\IE11_main.log
2013-11-18 10:31 - 2013-11-18 10:31 - 00000000 ____D C:\ProgramData\McAfee
2013-11-17 21:30 - 2013-11-18 10:25 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-16 11:10 - 2013-11-16 11:10 - 00734008 _____ C:\Windows\Minidump\111613-14031-01.dmp
2013-11-16 02:12 - 2013-11-24 23:11 - 00019165 _____ C:\Users\Oliver\Desktop\Likes.odt
2013-11-15 13:40 - 2013-11-15 13:40 - 00000000 ____D C:\Users\Oliver\Documents\Paradox Interactive
2013-11-15 13:39 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2013-11-15 13:39 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2013-11-15 13:39 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2013-11-15 13:11 - 2013-11-15 13:11 - 00000216 _____ C:\Users\Oliver\Desktop\March of the Eagles.url
2013-11-15 12:43 - 2013-11-15 12:43 - 00000000 ____D C:\Program Files\dumps
2013-11-15 12:41 - 2013-11-25 18:27 - 00000000 ____D C:\Program Files\Steam
2013-11-15 12:41 - 2013-11-15 13:03 - 00000947 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-15 12:41 - 2013-11-15 12:41 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-11-15 12:40 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-11-15 12:40 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-11-15 12:40 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-11-15 12:40 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-11-15 12:40 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-11-15 12:40 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-11-15 12:40 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-11-15 12:40 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-11-15 12:40 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-11-15 12:40 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-11-15 12:40 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-11-15 12:40 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-11-15 12:40 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-11-15 12:40 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-11-15 12:40 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-11-15 12:40 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-11-15 12:40 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-11-15 12:40 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-11-15 12:40 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-11-15 12:40 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-11-15 12:40 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-11-15 12:40 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-11-15 12:40 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-11-15 12:40 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-11-15 12:40 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-11-15 12:40 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-11-15 12:40 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-11-15 12:40 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-11-15 12:40 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-11-15 12:40 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-11-15 12:40 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-11-15 12:40 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-11-15 12:40 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-11-15 12:40 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-11-15 12:40 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-11-15 12:40 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-11-15 12:40 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-11-15 12:40 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-11-15 12:40 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-11-15 12:40 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-11-15 12:40 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-11-15 12:40 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-11-15 12:40 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-11-15 12:40 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-11-15 12:40 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-11-15 12:40 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-11-15 12:40 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-11-15 12:40 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-11-15 12:40 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-11-15 12:40 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-11-15 12:40 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-11-15 12:40 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-11-15 12:40 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-11-15 12:40 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-11-15 12:40 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-11-15 12:40 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-11-15 12:40 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-11-15 12:40 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-11-15 12:40 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-11-15 12:40 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-11-15 12:40 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-11-15 12:40 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-11-15 12:40 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-11-15 12:40 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-11-15 12:40 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-11-15 12:40 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-11-15 12:40 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-11-15 12:40 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-11-15 12:40 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-11-15 12:40 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-11-15 12:39 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-11-15 12:39 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-11-15 12:39 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-11-15 12:39 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-11-13 15:34 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-13 15:34 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 15:34 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 15:34 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 15:34 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-13 15:34 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-13 15:34 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 15:34 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 15:34 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 15:34 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 15:34 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-13 15:34 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-13 15:34 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-13 15:34 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-13 15:34 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-13 15:34 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-13 15:34 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-13 15:33 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-13 02:41 - 2013-11-22 13:24 - 00000000 ____D C:\AdwCleaner
2013-11-13 02:40 - 2013-11-13 02:40 - 01085542 _____ C:\Users\Oliver\Downloads\adwcleaner_3012.exe
2013-11-13 02:17 - 2013-11-13 02:17 - 00026136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2013-11-13 02:17 - 2013-11-13 02:17 - 00002113 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk
2013-11-13 02:17 - 2013-11-13 02:17 - 00002053 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk
2013-11-13 02:11 - 2013-11-13 02:11 - 00774392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00403440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00178304 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00070384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00049944 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-11-13 02:11 - 2013-11-13 02:11 - 00035656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-12 23:33 - 2013-11-12 23:34 - 00143048 _____ C:\Windows\Minidump\111213-22625-01.dmp
2013-11-12 23:32 - 2013-11-12 23:32 - 00259928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2013-11-11 22:52 - 2013-11-18 01:34 - 00000000 ____D C:\Users\Oliver\Desktop\Bilder
2013-11-11 15:57 - 2013-11-11 15:57 - 00001112 _____ C:\Users\Oliver\Desktop\OpenOffice.org Writer.lnk
2013-11-11 15:57 - 2013-11-11 15:57 - 00001076 _____ C:\Users\Oliver\Desktop\OpenOffice.org Calc.lnk
2013-11-08 21:48 - 2013-11-08 21:49 - 00143048 _____ C:\Windows\Minidump\110813-16093-01.dmp
2013-11-04 22:27 - 2013-11-12 11:37 - 00000000 ____D C:\Users\Oliver\Desktop\Dokumente
2013-11-04 18:25 - 2013-11-04 18:25 - 00000000 ____D C:\ProgramData\Oracle
2013-11-04 18:18 - 2012-08-23 15:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-11-04 18:18 - 2012-08-23 15:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-11-04 18:18 - 2012-08-23 15:40 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-11-04 18:18 - 2012-08-23 15:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-04 18:18 - 2012-08-23 15:10 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-04 18:18 - 2012-08-23 14:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-11-04 18:18 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-11-04 18:18 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-11-04 18:18 - 2012-08-23 14:32 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-04 18:18 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-11-04 18:18 - 2012-08-23 12:40 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-11-04 18:18 - 2012-08-23 12:32 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-11-04 18:18 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-11-04 18:18 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-11-04 18:18 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-11-04 18:18 - 2012-08-23 11:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-11-04 18:18 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-11-04 18:16 - 2013-11-13 17:10 - 00000000 ____D C:\Windows\system32\MRT
2013-11-04 18:16 - 2013-11-13 17:09 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-04 18:15 - 2013-09-04 02:15 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-04 18:15 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-11-03 23:58 - 2013-11-03 23:58 - 00143048 _____ C:\Windows\Minidump\110313-23906-01.dmp
2013-11-03 18:48 - 2013-11-03 18:48 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-11-03 18:48 - 2013-11-03 18:48 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-03 18:44 - 2013-11-03 18:44 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\PDF Architect
2013-11-03 18:43 - 2013-11-03 18:43 - 00000963 _____ C:\Users\Oliver\Desktop\PDF Architect.lnk
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Users\Oliver\Documents\PDF Architect Files
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\PDF Architect
2013-11-03 18:42 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\PDFCreator
2013-11-03 18:42 - 2013-11-03 18:42 - 00000989 _____ C:\Users\Public\Desktop\PDFCreator.lnk
2013-11-03 18:42 - 2013-04-09 15:13 - 00095416 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2013-11-03 18:42 - 2013-01-09 15:52 - 01070152 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCTL.OCX
2013-11-03 18:42 - 2012-05-05 11:54 - 00662288 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCT2.OCX
2013-11-03 18:42 - 2012-05-05 11:54 - 00137000 _____ (Microsoft Corporation) C:\Windows\system32\MSMAPI32.OCX
2013-11-03 18:42 - 2012-05-05 11:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\MSMPIDE.DLL
2013-11-03 18:42 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\system32\VB6DE.DLL
2013-11-03 18:42 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\MSCMCDE.DLL
2013-11-03 18:42 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\MSCC2DE.DLL
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\InstallShield
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Program Files\Common Files\snp325
2013-11-03 14:41 - 2007-05-10 13:18 - 00835584 _____ () C:\Windows\vsnp325.exe
2013-11-03 14:41 - 2007-05-07 17:58 - 10343168 _____ (Sonix Co. Ltd.) C:\Windows\system32\Drivers\snp325.sys
2013-11-03 14:41 - 2007-04-21 09:36 - 00270336 _____ () C:\Windows\tsnp325.exe
2013-11-03 14:41 - 2007-04-20 16:40 - 00057344 _____ ( ) C:\Windows\system32\vsnp325.dll
2013-11-03 14:41 - 2007-02-12 14:50 - 00020480 _____ () C:\Windows\FixCamera.exe
2013-11-03 14:41 - 2006-07-03 10:31 - 00094208 _____ (Microsoft Corporation) C:\Windows\amcap.exe
2013-11-03 14:41 - 2006-04-12 12:11 - 00147456 _____ ( ) C:\Windows\system32\rsnp325.dll
2013-11-03 14:41 - 2005-11-23 13:55 - 00053248 _____ ( ) C:\Windows\system32\csnp325.dll
2013-11-03 14:41 - 2004-02-27 17:36 - 00015498 _____ C:\Windows\snp325.ini
2013-11-03 14:41 - 2004-02-27 17:36 - 00013023 _____ C:\Windows\snp325.src
2013-10-29 13:55 - 2013-10-29 13:55 - 00001150 _____ C:\Users\Oliver\Desktop\Eigene Musik - Verknüpfung.lnk
2013-10-29 13:41 - 2013-10-29 13:41 - 00002272 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-10-29 13:40 - 2013-10-29 13:41 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-10-27 12:48 - 2013-10-27 12:48 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\AVAST Software
2013-10-27 12:45 - 2013-11-15 11:53 - 00002121 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-27 12:44 - 2013-11-13 02:11 - 00269216 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-10-27 12:43 - 2013-11-13 02:10 - 00000000 ____D C:\ProgramData\AVAST Software

==================== One Month Modified Files and Folders =======

2013-11-25 18:38 - 2013-11-25 18:38 - 00009081 _____ C:\Users\Oliver\Downloads\FRST.txt
2013-11-25 18:38 - 2013-11-25 18:38 - 00000000 ____D C:\FRST
2013-11-25 18:37 - 2013-11-25 18:36 - 01091583 _____ (Farbar) C:\Users\Oliver\Downloads\FRST.exe
2013-11-25 18:32 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-25 18:32 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-25 18:31 - 2013-09-07 13:09 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-25 18:30 - 2009-07-14 05:39 - 00035236 _____ C:\Windows\setupact.log
2013-11-25 18:28 - 2013-09-07 12:59 - 01455678 _____ C:\Windows\WindowsUpdate.log
2013-11-25 18:27 - 2013-11-15 12:41 - 00000000 ____D C:\Program Files\Steam
2013-11-25 18:25 - 2013-09-28 10:40 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-25 18:25 - 2013-09-20 19:05 - 00396062 _____ C:\Windows\PFRO.log
2013-11-25 18:25 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-25 13:08 - 2013-11-25 13:08 - 00013851 _____ C:\Users\Oliver\Desktop\Crash 2.zip
2013-11-25 13:04 - 2013-11-25 13:04 - 00014852 _____ C:\Users\Oliver\Desktop\Crash 3.txt
2013-11-25 13:03 - 2013-11-25 13:03 - 00198520 _____ C:\Users\Oliver\Desktop\Crash 2.txt
2013-11-25 13:01 - 2013-11-25 13:01 - 00002102 _____ C:\Users\Oliver\Desktop\Crash.txt
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Program Files\NirSoft
2013-11-25 12:56 - 2013-11-25 12:56 - 00141480 _____ C:\Users\Oliver\Downloads\bluescreenview_152setup.exe
2013-11-25 12:49 - 2013-09-28 10:40 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-25 11:33 - 2013-11-25 11:32 - 00143048 _____ C:\Windows\Minidump\112513-15531-01.dmp
2013-11-25 11:33 - 2009-07-14 05:53 - 00032630 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-25 11:32 - 2013-10-24 23:06 - 00000000 ____D C:\Windows\Minidump
2013-11-25 03:04 - 2013-10-25 13:48 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Skype
2013-11-24 23:11 - 2013-11-16 02:12 - 00019165 _____ C:\Users\Oliver\Desktop\Likes.odt
2013-11-22 13:24 - 2013-11-13 02:41 - 00000000 ____D C:\AdwCleaner
2013-11-21 00:22 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-11-20 23:40 - 2013-09-07 16:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-11-20 23:40 - 2013-09-07 16:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-11-20 15:25 - 2013-11-20 15:25 - 00143048 _____ C:\Windows\Minidump\112013-20000-01.dmp
2013-11-20 15:15 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-20 01:09 - 2013-11-20 01:04 - 00010261 _____ C:\Windows\IE11_main.log
2013-11-20 01:05 - 2013-11-20 01:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 01:05 - 2013-11-20 01:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 01:05 - 2013-11-20 01:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 01:05 - 2013-11-20 01:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 01:05 - 2013-11-20 01:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-18 10:36 - 2013-09-20 08:28 - 00000000 ____D C:\Users\Oliver\AppData\Local\Adobe
2013-11-18 10:31 - 2013-11-18 10:31 - 00000000 ____D C:\ProgramData\McAfee
2013-11-18 10:25 - 2013-11-17 21:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-18 01:34 - 2013-11-11 22:52 - 00000000 ____D C:\Users\Oliver\Desktop\Bilder
2013-11-16 11:10 - 2013-11-16 11:10 - 00734008 _____ C:\Windows\Minidump\111613-14031-01.dmp
2013-11-15 13:40 - 2013-11-15 13:40 - 00000000 ____D C:\Users\Oliver\Documents\Paradox Interactive
2013-11-15 13:11 - 2013-11-15 13:11 - 00000216 _____ C:\Users\Oliver\Desktop\March of the Eagles.url
2013-11-15 13:03 - 2013-11-15 12:41 - 00000947 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-15 12:43 - 2013-11-15 12:43 - 00000000 ____D C:\Program Files\dumps
2013-11-15 12:41 - 2013-11-15 12:41 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-11-15 12:40 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-11-15 11:53 - 2013-10-27 12:45 - 00002121 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-13 17:10 - 2013-11-04 18:16 - 00000000 ____D C:\Windows\system32\MRT
2013-11-13 17:09 - 2013-11-04 18:16 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 02:40 - 2013-11-13 02:40 - 01085542 _____ C:\Users\Oliver\Downloads\adwcleaner_3012.exe
2013-11-13 02:19 - 2013-09-28 10:40 - 00000000 ____D C:\Program Files\Google
2013-11-13 02:19 - 2013-05-08 17:59 - 00000000 ____D C:\Program Files\epson
2013-11-13 02:17 - 2013-11-13 02:17 - 00026136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2013-11-13 02:17 - 2013-11-13 02:17 - 00002113 _____ C:\Users\Public\Desktop\avast! SafeZone.lnk
2013-11-13 02:17 - 2013-11-13 02:17 - 00002053 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk
2013-11-13 02:11 - 2013-11-13 02:11 - 00774392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00403440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00178304 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00070384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00049944 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-11-13 02:11 - 2013-11-13 02:11 - 00035656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-13 02:11 - 2013-10-27 12:44 - 00269216 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-11-13 02:10 - 2013-10-27 12:43 - 00000000 ____D C:\ProgramData\AVAST Software
2013-11-13 02:09 - 2013-05-07 07:34 - 00000000 ____D C:\Program Files\Elaborate Bytes
2013-11-13 01:49 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\twain_32
2013-11-13 01:48 - 2013-09-07 14:58 - 00000000 ____D C:\Users\Oliver\AppData\Local\Google
2013-11-13 01:47 - 2013-09-20 10:02 - 00000000 ____D C:\ProgramData\EPSON
2013-11-13 01:09 - 2013-09-20 15:14 - 00000862 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-11-12 23:34 - 2013-11-12 23:33 - 00143048 _____ C:\Windows\Minidump\111213-22625-01.dmp
2013-11-12 23:32 - 2013-11-12 23:32 - 00259928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2013-11-12 11:37 - 2013-11-04 22:27 - 00000000 ____D C:\Users\Oliver\Desktop\Dokumente
2013-11-12 07:56 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-11-11 15:57 - 2013-11-11 15:57 - 00001112 _____ C:\Users\Oliver\Desktop\OpenOffice.org Writer.lnk
2013-11-11 15:57 - 2013-11-11 15:57 - 00001076 _____ C:\Users\Oliver\Desktop\OpenOffice.org Calc.lnk
2013-11-11 05:50 - 2013-09-07 15:05 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-08 21:49 - 2013-11-08 21:48 - 00143048 _____ C:\Windows\Minidump\110813-16093-01.dmp
2013-11-04 18:28 - 2009-07-14 09:47 - 00000000 ____D C:\Windows\system32\Drivers\de-DE
2013-11-04 18:25 - 2013-11-04 18:25 - 00000000 ____D C:\ProgramData\Oracle
2013-11-03 23:58 - 2013-11-03 23:58 - 00143048 _____ C:\Windows\Minidump\110313-23906-01.dmp
2013-11-03 22:44 - 2013-09-20 15:17 - 00000000 ____D C:\ProgramData\Adobe
2013-11-03 18:52 - 2013-09-07 16:10 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Adobe
2013-11-03 18:48 - 2013-11-03 18:48 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-11-03 18:48 - 2013-11-03 18:48 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-03 18:48 - 2013-09-20 07:48 - 00000000 ____D C:\Program Files\Adobe
2013-11-03 18:44 - 2013-11-03 18:44 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\PDF Architect
2013-11-03 18:43 - 2013-11-03 18:43 - 00000963 _____ C:\Users\Oliver\Desktop\PDF Architect.lnk
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Users\Oliver\Documents\PDF Architect Files
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\PDF Architect
2013-11-03 18:43 - 2013-11-03 18:42 - 00000000 ____D C:\Program Files\PDFCreator
2013-11-03 18:42 - 2013-11-03 18:42 - 00000989 _____ C:\Users\Public\Desktop\PDFCreator.lnk
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\InstallShield
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Program Files\Common Files\snp325
2013-11-03 14:41 - 2009-07-14 03:04 - 00000461 _____ C:\Windows\win.ini
2013-10-29 14:13 - 2013-05-25 08:37 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\DVDVideoSoft
2013-10-29 13:55 - 2013-10-29 13:55 - 00001150 _____ C:\Users\Oliver\Desktop\Eigene Musik - Verknüpfung.lnk
2013-10-29 13:41 - 2013-10-29 13:41 - 00002272 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-10-29 13:41 - 2013-10-29 13:40 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-10-29 13:41 - 2013-05-25 08:37 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-10-27 12:48 - 2013-10-27 12:48 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\AVAST Software

Some content of TEMP:
====================
C:\Users\Oliver\AppData\Local\Temp\Foxit Updater.exe
C:\Users\Oliver\AppData\Local\Temp\nsl6A72.exe
C:\Users\Oliver\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-21 00:14

==================== End Of Log ============================

--- --- ---



Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-11-2013
Ran by Matze at 2013-11-25 18:38:51
Running from C:\Users\Oliver\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Internet Security (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Internet Security (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Internet Security (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

Adobe Flash Player 11 ActiveX (Version: 11.9.900.152)
Adobe Flash Player 11 Plugin (Version: 11.9.900.152)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
avast! Internet Security (Version: 9.0.2008)
Free Audio CD to MP3 Converter version 1.3.12.1228 (Version: 1.3.12.1228)
Free YouTube to MP3 Converter version 3.12.14.1022 (Version: 3.12.14.1022)
Google Chrome (Version: 31.0.1650.57)
Google Update Helper (Version: 1.3.21.169)
hama PC-Webcam AC-140 (Version: 0.1.0.000)
March of the Eagles
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 25.0.1 (x86 de) (Version: 25.0.1)
NirSoft BlueScreenView
OpenOffice.org 3.4.1 (Version: 3.41.9593)
PDF Architect (Version: 1.1.83.9982)
PDFCreator (Version: 1.7.1)
Skype™ 6.9 (Version: 6.9.106)
Steam (Version: 1.0.0.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)

==================== Restore Points  =========================


==================== Hosts content: ==========================

2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {2B9243B1-4DCE-4C6F-9483-7017BBC3E7EE} - System32\Tasks\Google Updater and Installer => C:\Users\Oliver\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {30CED296-BD8D-4E02-857E-004D665EFC71} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-09-28] (Google Inc.)
Task: {3A48D740-3B64-40DC-824C-59B4A6F5F858} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe
Task: {44A7769E-52B7-477B-A74B-B776D1044972} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-11-13] (AVAST Software)
Task: {4A31CB34-2860-43DE-951A-ED29507013E4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-09-28] (Google Inc.)
Task: {B922E7FB-C990-49FC-B3A4-E70B34F332AE} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-11-13 02:11 - 2013-11-13 02:11 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-10-24 09:45 - 2013-10-24 18:45 - 00691200 _____ () C:\Program Files\Steam\SDL2.dll
2013-10-30 11:25 - 2013-10-30 20:25 - 01123240 _____ () C:\Program Files\Steam\bin\chromehtml.DLL
2013-10-23 12:07 - 2013-10-23 21:07 - 20625832 _____ () C:\Program Files\Steam\bin\libcef.dll
2013-06-14 15:49 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files\Steam\bin\avcodec-53.dll
2013-06-14 15:49 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files\Steam\bin\avutil-51.dll
2013-06-14 15:49 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files\Steam\bin\avformat-53.dll
2013-11-15 11:53 - 2013-11-14 12:28 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-15 11:53 - 2013-11-14 12:28 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\libegl.dll
2013-11-15 11:53 - 2013-11-14 12:29 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-15 11:53 - 2013-11-14 12:29 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-15 11:53 - 2013-11-14 12:28 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2013-11-15 11:53 - 2013-11-14 12:29 - 13582800 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/15/2013 01:45:26 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MotE.exe, Version: 0.0.0.0, Zeitstempel: 0x51a6028e
Name des fehlerhaften Moduls: MotE.exe, Version: 0.0.0.0, Zeitstempel: 0x51a6028e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x004655b6
ID des fehlerhaften Prozesses: 0x1194
Startzeit der fehlerhaften Anwendung: 0xMotE.exe0
Pfad der fehlerhaften Anwendung: MotE.exe1
Pfad des fehlerhaften Moduls: MotE.exe2
Berichtskennung: MotE.exe3

Error: (11/15/2013 00:39:00 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {e24e17ac-09ae-4875-8f62-275703c5268b}

Error: (11/15/2013 00:38:42 PM) (Source: Steam Client Service) (User: )
Description: Failed to find Steam.exe

Error: (11/13/2013 02:36:50 AM) (Source: MsiInstaller) (User: MATZE)
Description: Produkt: Ask Toolbar -- Fehler 1316. Vous devez quitter les applications ci-dessous pour pouvoir continuer l'installation.

Error: (11/13/2013 02:27:00 AM) (Source: MsiInstaller) (User: MATZE)
Description: Produkt: Ask Toolbar -- Fehler 1316. Vous devez quitter les applications ci-dessous pour pouvoir continuer l'installation.

Error: (11/13/2013 02:16:11 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary unbrplad.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/13/2013 02:16:11 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary AnyDVD.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/13/2013 02:11:13 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary unbrplad.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/13/2013 02:11:13 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary AnyDVD.

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (11/13/2013 02:06:47 AM) (Source: MsiInstaller) (User: MATZE)
Description: Produkt: Ask Toolbar -- Fehler 1316. Vous devez quitter les applications ci-dessous pour pouvoir continuer l'installation.


System errors:
=============
Error: (11/25/2013 06:25:20 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (11/25/2013 11:32:52 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (11/25/2013 11:33:05 AM) (Source: BugCheck) (User: )
Description: 0x00000019 (0x00000020, 0x82d65048, 0x82d65788, 0x08e8db70)C:\Windows\MEMORY.DMP112513-15531-01

Error: (11/25/2013 11:32:58 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎25.‎11.‎2013 um 11:31:04 unerwartet heruntergefahren.

Error: (11/25/2013 11:06:04 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (11/24/2013 10:11:54 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (11/24/2013 10:43:06 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (11/22/2013 01:25:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.

Error: (11/22/2013 11:17:44 AM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (11/22/2013 11:08:48 AM) (Source: Microsoft-Windows-Kernel-Processor-Power) (User: NT-AUTORITÄT)
Description: Einige Funktionen zur Energieverwaltung im Leistungsstatus wurden im Prozessor aufgrund eines bekannten Firmwareproblems deaktiviert. Wenden Sie sich an den Computerhersteller, um aktualisierte Firmware zu erhalten.


Microsoft Office Sessions:
=========================
Error: (11/15/2013 01:45:26 PM) (Source: Application Error)(User: )
Description: MotE.exe0.0.0.051a6028eMotE.exe0.0.0.051a6028ec0000005004655b6119401cee2008d5b82c4C:\Program Files\Steam\steamapps\common\March of the Eagles\MotE.exeC:\Program Files\Steam\steamapps\common\March of the Eagles\MotE.execcab3a0d-4df3-11e3-8560-00138fd9a7fa

Error: (11/15/2013 00:39:00 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert


Vorgang:
  Generatordaten werden gesammelt

Kontext:
  Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
  Generatorname: System Writer
  Generatorinstanz-ID: {e24e17ac-09ae-4875-8f62-275703c5268b}

Error: (11/15/2013 00:38:42 PM) (Source: Steam Client Service)(User: )
Description: Failed to find Steam.exe

Error: (11/13/2013 02:36:50 AM) (Source: MsiInstaller)(User: MATZE)
Description: Produkt: Ask Toolbar -- Fehler 1316. Vous devez quitter les applications ci-dessous pour pouvoir continuer l'installation. (NULL)(NULL)(NULL)(NULL)(NULL)

Error: (11/13/2013 02:27:00 AM) (Source: MsiInstaller)(User: MATZE)
Description: Produkt: Ask Toolbar -- Fehler 1316. Vous devez quitter les applications ci-dessous pour pouvoir continuer l'installation. (NULL)(NULL)(NULL)(NULL)(NULL)

Error: (11/13/2013 02:16:11 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary unbrplad.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (11/13/2013 02:16:11 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary AnyDVD.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (11/13/2013 02:11:13 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary unbrplad.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (11/13/2013 02:11:13 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary AnyDVD.

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (11/13/2013 02:06:47 AM) (Source: MsiInstaller)(User: MATZE)
Description: Produkt: Ask Toolbar -- Fehler 1316. Vous devez quitter les applications ci-dessous pour pouvoir continuer l'installation. (NULL)(NULL)(NULL)(NULL)(NULL)


==================== Memory info ===========================

Percentage of memory in use: 46%
Total physical RAM: 2047.3 MB
Available physical RAM: 1097.64 MB
Total Pagefile: 4094.61 MB
Available Pagefile: 2613.56 MB
Total Virtual: 2047.88 MB
Available Virtual: 1894.86 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:24.9 GB) (Free:2.99 GB) NTFS
Drive d: (Musik2) (Fixed) (Total:50 GB) (Free:45.07 GB) NTFS
Drive e: (Musik) (Fixed) (Total:60 GB) (Free:59.91 GB) NTFS
Drive f: (Filme/Bilder) (Fixed) (Total:62.88 GB) (Free:61.55 GB) NTFS
Drive g: (Programme) (Fixed) (Total:35.01 GB) (Free:34.74 GB) NTFS
Drive h: (MOTE) (CDROM) (Total:0.35 GB) (Free:0 GB) UDF
Drive j: (Transcend) (Removable) (Total:3.73 GB) (Free:2.79 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 55F23D99)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=25 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=35 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=173 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 4 GB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)

==================== End Of Log ============================


schrauber 27.11.2013 08:36

hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Tron Legacy 27.11.2013 11:00

So, auch diesen Punkt habe ich nun umgesetzt. Das Antivirus-Programm (Avast) ist während der Anwendung - nach dem Neustart im laufenden Prozess - automatisch wieder aktiviert worden. Gab wohl aber dadurch keine Einschränkung. Ansonsten bin ich jetzt mal sehr auf Deine Einschätzung gespannt!!! GlG.


Code:

omboFix 13-11-27.01 - Matze 27.11.2013  10:07:58.1.2 - x86
Microsoft Windows 7 Professional  6.1.7601.1.1252.49.1031.18.2047.1382 [GMT 1:00]
ausgeführt von:: c:\users\Oliver\Downloads\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Internet Security *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((  Weitere Löschungen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\FlashPlayerApp.exe
.
Infizierte Kopie von c:\windows\system32\Drivers\atapi.sys wurde gefunden und desinfiziert
Kopie von - c:\windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_a5025d31bee4647c\atapi.sys wurde wiederhergestellt
.
.
(((((((((((((((((((((((  Dateien erstellt von 2013-10-27 bis 2013-11-27  ))))))))))))))))))))))))))))))
.
.
2013-11-27 09:16 . 2013-11-27 09:16        62576        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{C0E2F4CE-D57D-451C-8DA0-D95ABEEB1AF3}\offreg.dll
2013-11-27 09:15 . 2013-11-27 09:18        --------        d-----w-        c:\users\Oliver\AppData\Local\temp
2013-11-27 09:15 . 2013-11-27 09:15        --------        d-----w-        c:\users\Default\AppData\Local\temp
2013-11-26 10:18 . 2013-11-08 01:15        7772552        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{C0E2F4CE-D57D-451C-8DA0-D95ABEEB1AF3}\mpengine.dll
2013-11-25 17:38 . 2013-11-25 17:38        --------        d-----w-        C:\FRST
2013-11-25 11:57 . 2013-11-25 11:57        --------        d-----w-        c:\program files\NirSoft
2013-11-18 09:31 . 2013-11-18 09:31        --------        d-----w-        c:\programdata\McAfee
2013-11-15 12:39 . 2010-06-02 03:55        74072        ----a-w-        c:\windows\system32\XAPOFX1_5.dll
2013-11-15 12:39 . 2010-06-02 03:55        527192        ----a-w-        c:\windows\system32\XAudio2_7.dll
2013-11-15 12:39 . 2010-06-02 03:55        239960        ----a-w-        c:\windows\system32\xactengine3_7.dll
2013-11-15 12:39 . 2010-05-26 10:41        470880        ----a-w-        c:\windows\system32\d3dx10_43.dll
2013-11-15 12:39 . 2010-05-26 10:41        248672        ----a-w-        c:\windows\system32\d3dx11_43.dll
2013-11-15 12:39 . 2010-05-26 10:41        2106216        ----a-w-        c:\windows\system32\D3DCompiler_43.dll
2013-11-15 12:39 . 2010-05-26 10:41        1868128        ----a-w-        c:\windows\system32\d3dcsx_43.dll
2013-11-15 12:39 . 2010-05-26 10:41        1998168        ----a-w-        c:\windows\system32\D3DX9_43.dll
2013-11-15 11:43 . 2013-11-15 11:43        --------        d-----w-        c:\program files\dumps
2013-11-15 11:41 . 2013-11-15 11:41        --------        d-----w-        c:\program files\Common Files\Steam
2013-11-15 11:41 . 2013-11-27 09:18        --------        d-----w-        c:\program files\Steam
2013-11-15 11:39 . 2005-05-26 14:34        2297552        ----a-w-        c:\windows\system32\d3dx9_26.dll
2013-11-13 14:33 . 2013-10-05 19:57        1168384        ----a-w-        c:\windows\system32\crypt32.dll
2013-11-13 01:41 . 2013-11-22 12:24        --------        d-----w-        C:\AdwCleaner
2013-11-13 01:17 . 2013-11-13 01:17        26136        ----a-w-        c:\windows\system32\drivers\aswKbd.sys
2013-11-13 01:11 . 2013-11-13 01:11        79720        ----a-w-        c:\windows\system32\drivers\aswRdr2.sys
2013-11-13 01:11 . 2013-11-13 01:11        774392        ----a-w-        c:\windows\system32\drivers\aswSnx.sys
2013-11-13 01:11 . 2013-11-13 01:11        70384        ----a-w-        c:\windows\system32\drivers\aswMonFlt.sys
2013-11-13 01:11 . 2013-11-13 01:11        57672        ----a-w-        c:\windows\system32\drivers\aswTdi.sys
2013-11-13 01:11 . 2013-11-13 01:11        49944        ----a-w-        c:\windows\system32\drivers\aswRvrt.sys
2013-11-13 01:11 . 2013-11-13 01:11        403440        ----a-w-        c:\windows\system32\drivers\aswSP.sys
2013-11-13 01:11 . 2013-11-13 01:11        35656        ----a-w-        c:\windows\system32\drivers\aswFsBlk.sys
2013-11-13 01:11 . 2013-11-13 01:11        178304        ----a-w-        c:\windows\system32\drivers\aswVmm.sys
2013-11-13 01:11 . 2013-11-13 01:11        43152        ----a-w-        c:\windows\avastSS.scr
2013-11-13 01:11 . 2013-11-13 01:11        --------        d-----w-        c:\program files\AVAST Software
2013-11-12 22:32 . 2013-11-12 22:32        259928        ----a-w-        c:\windows\system32\drivers\aswNdisFlt.sys
2013-11-04 17:25 . 2013-11-04 17:25        --------        d-----w-        c:\programdata\Oracle
2013-11-04 17:16 . 2013-11-13 16:10        --------        d-----w-        c:\windows\system32\MRT
2013-11-04 17:15 . 2012-05-04 09:59        514560        ----a-w-        c:\windows\system32\qdvd.dll
2013-11-04 17:15 . 2013-09-04 01:15        258560        ----a-w-        c:\windows\system32\drivers\usbhub.sys
2013-11-04 17:15 . 2013-09-04 01:14        76288        ----a-w-        c:\windows\system32\drivers\usbccgp.sys
2013-11-04 17:15 . 2013-09-04 01:14        284672        ----a-w-        c:\windows\system32\drivers\usbport.sys
2013-11-04 17:15 . 2013-09-04 01:14        43008        ----a-w-        c:\windows\system32\drivers\usbehci.sys
2013-11-04 17:15 . 2013-09-04 01:14        20480        ----a-w-        c:\windows\system32\drivers\usbohci.sys
2013-11-04 17:15 . 2013-09-04 01:14        24064        ----a-w-        c:\windows\system32\drivers\usbuhci.sys
2013-11-04 17:15 . 2013-09-04 01:14        6016        ----a-w-        c:\windows\system32\drivers\usbd.sys
2013-11-03 17:48 . 2013-11-03 17:48        --------        d-----w-        c:\program files\Common Files\Adobe
2013-11-03 17:44 . 2013-11-03 17:44        --------        d-----w-        c:\users\Oliver\AppData\Roaming\PDF Architect
2013-11-03 17:43 . 2013-11-03 17:43        --------        d-----w-        c:\program files\PDF Architect
2013-11-03 17:42 . 2012-05-05 10:54        137000        ----a-w-        c:\windows\system32\MSMAPI32.OCX
2013-11-03 17:42 . 2013-04-09 14:13        95416        ----a-w-        c:\windows\system32\pdfcmon.dll
2013-11-03 17:42 . 2013-01-09 14:52        1070152        ----a-w-        c:\windows\system32\MSCOMCTL.OCX
2013-11-03 17:42 . 2012-05-05 10:54        662288        ----a-w-        c:\windows\system32\MSCOMCT2.OCX
2013-11-03 17:42 . 2012-05-05 10:54        23552        ----a-w-        c:\windows\system32\MSMPIDE.DLL
2013-11-03 17:42 . 1998-07-06 17:56        125712        ----a-w-        c:\windows\system32\VB6DE.DLL
2013-11-03 17:42 . 1998-07-06 17:55        158208        ----a-w-        c:\windows\system32\MSCMCDE.DLL
2013-11-03 17:42 . 1998-07-06 17:55        64512        ----a-w-        c:\windows\system32\MSCC2DE.DLL
2013-11-03 17:42 . 2013-11-03 17:43        --------        d-----w-        c:\program files\PDFCreator
2013-11-03 13:41 . 2007-02-12 13:50        20480        ----a-w-        c:\windows\FixCamera.exe
2013-11-03 13:41 . 2006-07-03 09:31        94208        ----a-w-        c:\windows\amcap.exe
2013-11-03 13:41 . 2007-05-10 12:18        835584        ----a-w-        c:\windows\vsnp325.exe
2013-11-03 13:41 . 2007-05-07 16:58        10343168        ----a-w-        c:\windows\system32\drivers\snp325.sys
2013-11-03 13:41 . 2007-04-21 08:36        270336        ----a-w-        c:\windows\tsnp325.exe
2013-11-03 13:41 . 2013-11-03 13:41        --------        d-----w-        c:\program files\Common Files\snp325
2013-11-03 13:41 . 2013-11-03 13:41        --------        d--h--w-        c:\program files\InstallShield Installation Information
2013-11-03 13:41 . 2007-04-20 15:40        57344        ----a-w-        c:\windows\system32\vsnp325.dll
2013-11-03 13:41 . 2006-04-12 11:11        147456        ----a-w-        c:\windows\system32\rsnp325.dll
2013-11-03 13:41 . 2005-11-23 12:55        53248        ----a-w-        c:\windows\system32\csnp325.dll
2013-11-03 13:41 . 2013-11-03 13:41        --------        d-----w-        c:\users\Oliver\AppData\Roaming\InstallShield
2013-10-29 12:40 . 2013-10-29 12:41        --------        d-----w-        c:\program files\DVDVideoSoft
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-20 22:40 . 2013-09-07 15:10        71048        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2013-11-13 01:11 . 2013-10-27 11:44        269216        ----a-w-        c:\windows\system32\aswBoot.exe
2013-11-11 04:50 . 2013-09-07 14:05        230048        ------w-        c:\windows\system32\MpSigStub.exe
2013-09-14 00:48 . 2013-10-24 20:56        338944        ----a-w-        c:\windows\system32\drivers\afd.sys
2013-09-08 02:07 . 2013-10-24 20:56        1294272        ----a-w-        c:\windows\system32\drivers\tcpip.sys
2013-09-08 02:03 . 2013-10-24 20:56        231424        ----a-w-        c:\windows\system32\mswsock.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-11-13 01:11        321752        ----a-w-        c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2013-10-30 1820584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-12 20480]
"tsnp325"="c:\windows\tsnp325.exe" [2007-04-21 270336]
"snp325"="c:\windows\vsnp325.exe" [2007-05-10 835584]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-11-13 3568312]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-05-01 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Oliver\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-20 108032]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2013-11-13 26136]
S1 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys [2013-11-12 259928]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-11-13 774392]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-11-13 403440]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-11-13 35656]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-11-13 70384]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2013-11-13 116776]
S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\PDF Architect\HelperService.exe [2013-04-08 1320496]
S2 PDF Architect Service;PDF Architect Service;c:\program files\PDF Architect\ConversionService.exe [2013-04-08 799280]
S3 3xHybrid;SAA713x TV Card Service;c:\windows\system32\DRIVERS\3xHybrid.sys [2010-12-01 1141888]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\DRIVERS\snp325.sys [2007-05-07 10343168]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-11-15 10:50        1210320        ----a-w-        c:\program files\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-09-28 09:40]
.
2013-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-09-28 09:40]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.bing.com
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\8u6g1zla.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - ExtSQL: 2013-11-03 18:43; FFPDFArchitectConverter@pdfarchitect.com; c:\program files\PDF Architect\FFPDFArchitectExt
FF - ExtSQL: 2013-11-13 02:17; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKU-Default-Run-SearchProtect - \SearchProtect\bin\cltmng.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-11-27  10:23:26 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-11-27 09:23
.
Vor Suchlauf: 2.486.321.152 Bytes frei
Nach Suchlauf: 2.894.069.760 Bytes frei
.
- - End Of File - - AABDD469B36FDA2EB37A2A8733480EA3
A36C5E4F47E84449FF07ED3517B43A31


schrauber 27.11.2013 14:55

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

Tron Legacy 27.11.2013 16:23

Okay, wird gemacht. Kannst Du mir schonmal etwas zu Deiner Diagnose sagen. Auch der ein oder andere praktische Tipp zum zukünftigen Handling wäre hilfreich. Ich bin halt täglicher Nutzer, besitze kein Computerwissen und arbeite ausschließlich mit meinem logischen Menschenverstand und nach bestem Wissen und Gewissen. Vlt. gibts ja irgendwas auf was ich - aus Deiner Sicht - zukünftig achten sollte! MfG.

Sobald die Scans abgeschlossen sind, poste ich die Inhalte!...

Code:

Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.11.27.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16428
Matze :: MATZE [Administrator]

Schutz: Aktiviert

27.11.2013 15:10:57
mbam-log-2013-11-27 (15-10-57).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 283687
Laufzeit: 34 Minute(n), 45 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 7
C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\File System\000\t\00\00000000 (PUP.Optional.OneClickDownloader.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\DVDvideoSoft_2.0\DVDvideoSoft_2.0ToolbarHelper.exe.vir (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Program Files\DVDvideoSoft_2.0\DVDvideoSoft_2.0ToolbarHelper1.exe.vir (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Users\Oliver\AppData\Local\Conduit\CT3279453\DVDvideoSoft_2.0AutoUpdateHelper.exe.vir (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Users\Oliver\AppData\Local\Conduit\CT3293887\Vgrabber_V1.6AutoUpdateHelper.exe.vir (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Users\Oliver\AppData\Roaming\OpenCandy\208BB7BB743148C2B981A4C238E9BF05\LatestDLMgr.exe.vir (PUP.Optional.OpenCandy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\AdwCleaner\Quarantine\C\Users\Oliver\AppData\Roaming\OpenCandy\C95BAD2ED16747E3B427EF7CDC45E6B3\LatestDLMgr.exe.vir (PUP.Optional.OpenCandy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Code:

2013/11/27 15:08:51 +0100        MATZE        Matze        MESSAGE        Starting protection
2013/11/27 15:08:51 +0100        MATZE        Matze        MESSAGE        Protection started successfully
2013/11/27 15:08:51 +0100        MATZE        Matze        MESSAGE        Starting IP protection
2013/11/27 15:09:21 +0100        MATZE        Matze        MESSAGE        IP Protection started successfully
2013/11/27 15:09:43 +0100        MATZE        Matze        MESSAGE        Starting database refresh
2013/11/27 15:09:43 +0100        MATZE        Matze        MESSAGE        Stopping IP protection
2013/11/27 15:09:45 +0100        MATZE        Matze        MESSAGE        IP Protection stopped successfully
2013/11/27 15:09:49 +0100        MATZE        Matze        MESSAGE        Database refreshed successfully
2013/11/27 15:09:49 +0100        MATZE        Matze        MESSAGE        Starting IP protection
2013/11/27 15:09:57 +0100        MATZE        Matze        MESSAGE        IP Protection started successfully
2013/11/27 15:57:13 +0100        MATZE        Matze        MESSAGE        Starting protection
2013/11/27 15:57:13 +0100        MATZE        Matze        MESSAGE        Protection started successfully
2013/11/27 15:57:13 +0100        MATZE        Matze        MESSAGE        Starting IP protection
2013/11/27 15:57:21 +0100        MATZE        Matze        MESSAGE        IP Protection started successfully

Code:

# AdwCleaner v3.013 - Bericht erstellt am 27/11/2013 um 16:05:28
# Updated 24/11/2013 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Matze - MATZE
# Gestartet von : C:\Users\Oliver\Downloads\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v25.0.1 (de)

[ Datei : C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\8u6g1zla.default\prefs.js ]


[ Datei : C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\8u6g1zla.default\prefs.js ]


-\\ Google Chrome v31.0.1650.57

[ Datei : C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [21689 octets] - [13/11/2013 02:41:19]
AdwCleaner[R1].txt - [1155 octets] - [22/11/2013 13:22:54]
AdwCleaner[R2].txt - [1271 octets] - [27/11/2013 16:04:38]
AdwCleaner[S0].txt - [19073 octets] - [13/11/2013 02:42:48]
AdwCleaner[S1].txt - [1217 octets] - [22/11/2013 13:24:02]
AdwCleaner[S2].txt - [1192 octets] - [27/11/2013 16:05:28]

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Professional x86
Ran by Matze on 27.11.2013 at 16:13:49,35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{18AFC003-D470-4A4A-9530-E8F855ECC625}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D139E9D3-CC3C-4E7B-855E-F48B22905211}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E756FA29-DFAC-4122-ADB2-78B2C8930399}
Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Oliver\appdata\local\cre"



~~~ FireFox

Emptied folder: C:\Users\Oliver\AppData\Roaming\mozilla\firefox\profiles\8u6g1zla.default\minidumps [9 files]



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]



~~~ Event Viewer Logs were cleared


schrauber 28.11.2013 10:07


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme? :)

Tron Legacy 28.11.2013 18:53

Okay! Seitdem du mich hier betreust keine Probleme / kein Absturz mehr! Liegt sicher an Deinen guten Ratschlägen. :-)))

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=d92fd3a50b86c54f87e4ac19846ff01f
# engine=16063
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-11-28 05:29:02
# local_time=2013-11-28 06:29:02 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=772 16777213 66 80 522684 1354283 0 0
# compatibility_mode=5893 16776573 100 94 93887 137290933 0 0
# scanned=95670
# found=1
# cleaned=0
# scan_time=2212
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir"

Code:

Results of screen317's Security Check version 0.99.76 
 Windows 7 Service Pack 1 x86 (UAC is disabled!) 
 Internet Explorer 10 
``````````````Antivirus/Firewall Check:``````````````
avast! Internet Security 
 Antivirus up to date!  (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
 Malwarebytes Anti-Malware Version 1.75.0.1300 
 Adobe Flash Player        11.9.900.152 
 Adobe Reader XI 
 Mozilla Firefox (25.0.1)
 Google Chrome 30.0.1599.101 
 Google Chrome 31.0.1650.57 
````````Process Check: objlist.exe by Laurent```````` 
 Malwarebytes Anti-Malware mbamservice.exe 
 Malwarebytes Anti-Malware mbamgui.exe 
 Malwarebytes' Anti-Malware mbamscheduler.exe 
 AVAST Software Avast AvastSvc.exe 
 AVAST Software Avast afwServ.exe 
 AVAST Software Avast AvastUI.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````

Ist die Operation jetzt beendet? :-)))

Bin ich jetzt Sympthomfrei?

Auf was muss ich zukünftig achten?

schrauber 29.11.2013 15:19

Poste noch bitte das frische FRST log :)

Tron Legacy 29.11.2013 20:42

So, hier der frische FRST log...;-)


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-11-2013
Ran by Matze (administrator) on MATZE on 29-11-2013 20:40:04
Running from C:\Users\Oliver\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UUWVSIPK
Microsoft Windows 7 Professional  Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
() C:\Windows\FixCamera.exe
() C:\Windows\tsnp325.exe
() C:\Windows\vsnp325.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [FixCamera] - C:\Windows\FixCamera.exe [20480 2007-02-12] ()
HKLM\...\Run: [tsnp325] - C:\Windows\tsnp325.exe [270336 2007-04-21] ()
HKLM\...\Run: [snp325] - C:\Windows\vsnp325.exe [835584 2007-05-10] ()
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-11-13] (AVAST Software)
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x40B7EEEFDFB5CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope value is missing.
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Oliver\AppData\Roaming\Mozilla\Firefox\Profiles\8u6g1zla.default
FF NewTab: hxxp://www.google.com/firefox
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com/firefox
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.169\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.169\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt

Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_1
CHR Extension: (Google Drive) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1
CHR Extension: (YouTube) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1
CHR Extension: (Google Search) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1
CHR Extension: (Google Wallet) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Oliver\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-11-13] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [116776 2013-11-13] (AVAST Software)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)

==================== Drivers (Whitelisted) ====================

R3 3xHybrid; C:\Windows\System32\DRIVERS\3xHybrid.sys [1141888 2010-12-01] (NXP Semiconductors Germany GmbH)
R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [35656 2013-11-13] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26136 2013-11-13] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2013-11-13] (AVAST Software)
R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [259928 2013-11-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2013-11-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2013-11-13] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [774392 2013-11-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [403440 2013-11-13] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57672 2013-11-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [178304 2013-11-13] ()
R3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd6.sys [44032 2009-07-13] (VIA Technologies, Inc.              )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 SNP325; C:\Windows\System32\DRIVERS\snp325.sys [10343168 2007-05-07] (Sonix Co. Ltd.)
R3 W8100PCI; C:\Windows\System32\DRIVERS\mrv8k51.sys [311936 2005-06-08] (Marvell Semiconductor, Inc)
S3 catchme; \??\C:\Users\Oliver\AppData\Local\Temp\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-29 15:47 - 2013-11-29 20:38 - 00000000 ____D C:\Users\Oliver\Desktop\xxx
2013-11-28 20:21 - 2013-11-28 20:21 - 00013911 _____ C:\Users\Oliver\Desktop\NFL Gamepass.odt
2013-11-28 18:47 - 2013-11-28 18:47 - 00891184 _____ C:\Users\Oliver\Downloads\SecurityCheck.exe
2013-11-28 17:46 - 2013-11-28 17:46 - 02347384 _____ (ESET) C:\Users\Oliver\Downloads\esetsmartinstaller_enu.exe
2013-11-27 16:13 - 2013-11-27 16:13 - 01034531 _____ (Thisisu) C:\Users\Oliver\Downloads\JRT.exe
2013-11-27 16:13 - 2013-11-27 16:13 - 00000000 ____D C:\Windows\ERUNT
2013-11-27 16:04 - 2013-11-27 16:04 - 01091882 _____ C:\Users\Oliver\Downloads\adwcleaner.exe
2013-11-27 15:08 - 2013-11-27 15:08 - 00001067 _____ C:\Users\Public\Desktop\malewarebytes.lnk
2013-11-27 15:08 - 2013-11-27 15:08 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Malwarebytes
2013-11-27 15:08 - 2013-11-27 15:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-27 15:08 - 2013-11-27 15:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-27 15:08 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-27 15:05 - 2013-11-27 15:05 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Oliver\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-27 10:06 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-11-27 10:06 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-11-27 10:06 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-11-27 10:06 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-11-27 10:06 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-11-27 10:06 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-11-27 10:06 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-11-27 10:06 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-11-27 10:05 - 2013-11-27 10:23 - 00000000 ____D C:\Qoobox
2013-11-27 10:05 - 2013-11-27 10:20 - 00000000 ____D C:\Windows\erdnt
2013-11-27 10:04 - 2013-11-27 10:04 - 05150163 ____R (Swearware) C:\Users\Oliver\Downloads\ComboFix.exe
2013-11-26 01:12 - 2013-11-26 01:12 - 00143048 _____ C:\Windows\Minidump\112613-16453-01.dmp
2013-11-25 18:38 - 2013-11-25 18:38 - 00000000 ____D C:\FRST
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Program Files\NirSoft
2013-11-25 12:56 - 2013-11-25 12:56 - 00141480 _____ C:\Users\Oliver\Downloads\bluescreenview_152setup.exe
2013-11-25 11:32 - 2013-11-25 11:33 - 00143048 _____ C:\Windows\Minidump\112513-15531-01.dmp
2013-11-20 15:25 - 2013-11-20 15:25 - 00143048 _____ C:\Windows\Minidump\112013-20000-01.dmp
2013-11-20 01:05 - 2013-11-20 01:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 01:05 - 2013-11-20 01:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 01:05 - 2013-11-20 01:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 01:05 - 2013-11-20 01:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 01:05 - 2013-11-20 01:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-20 01:04 - 2013-11-20 01:09 - 00010261 _____ C:\Windows\IE11_main.log
2013-11-18 10:31 - 2013-11-18 10:31 - 00000000 ____D C:\ProgramData\McAfee
2013-11-17 21:30 - 2013-11-18 10:25 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-16 11:10 - 2013-11-16 11:10 - 00734008 _____ C:\Windows\Minidump\111613-14031-01.dmp
2013-11-15 13:40 - 2013-11-15 13:40 - 00000000 ____D C:\Users\Oliver\Documents\Paradox Interactive
2013-11-15 13:39 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2013-11-15 13:39 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2013-11-15 13:39 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2013-11-15 13:39 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2013-11-15 12:43 - 2013-11-15 12:43 - 00000000 ____D C:\Program Files\dumps
2013-11-15 12:41 - 2013-11-29 20:18 - 00000000 ____D C:\Program Files\Steam
2013-11-15 12:41 - 2013-11-15 12:41 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-11-15 12:40 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-11-15 12:40 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-11-15 12:40 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-11-15 12:40 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-11-15 12:40 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-11-15 12:40 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-11-15 12:40 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-11-15 12:40 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-11-15 12:40 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-11-15 12:40 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-11-15 12:40 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-11-15 12:40 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-11-15 12:40 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-11-15 12:40 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-11-15 12:40 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-11-15 12:40 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-11-15 12:40 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-11-15 12:40 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-11-15 12:40 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-11-15 12:40 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-11-15 12:40 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-11-15 12:40 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-11-15 12:40 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-11-15 12:40 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-11-15 12:40 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-11-15 12:40 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-11-15 12:40 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-11-15 12:40 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-11-15 12:40 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-11-15 12:40 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-11-15 12:40 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-11-15 12:40 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-11-15 12:40 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-11-15 12:40 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-11-15 12:40 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-11-15 12:40 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-11-15 12:40 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-11-15 12:40 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-11-15 12:40 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-11-15 12:40 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-11-15 12:40 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-11-15 12:40 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-11-15 12:40 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-11-15 12:40 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-11-15 12:40 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-11-15 12:40 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-11-15 12:40 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-11-15 12:40 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-11-15 12:40 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-11-15 12:40 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-11-15 12:40 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-11-15 12:40 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-11-15 12:40 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-11-15 12:40 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-11-15 12:40 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-11-15 12:40 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-11-15 12:40 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-11-15 12:40 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-11-15 12:40 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-11-15 12:40 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-11-15 12:40 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-11-15 12:40 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-11-15 12:40 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-11-15 12:40 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-11-15 12:40 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-11-15 12:40 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-11-15 12:40 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-11-15 12:40 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-11-15 12:40 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-11-15 12:40 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-11-15 12:40 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-11-15 12:40 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-11-15 12:39 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-11-15 12:39 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-11-15 12:39 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-11-15 12:39 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-11-13 15:34 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-13 15:34 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 15:34 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 15:34 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 15:34 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-13 15:34 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-13 15:34 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 15:34 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 15:34 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 15:34 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 15:34 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-13 15:34 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-13 15:34 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-13 15:34 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-13 15:34 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-13 15:34 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-13 15:34 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-13 15:33 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-13 02:41 - 2013-11-27 16:05 - 00000000 ____D C:\AdwCleaner
2013-11-13 02:17 - 2013-11-13 02:17 - 00026136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2013-11-13 02:17 - 2013-11-13 02:17 - 00002053 _____ C:\Users\Public\Desktop\avast.lnk
2013-11-13 02:11 - 2013-11-13 02:11 - 00774392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00403440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00178304 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00070384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00049944 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-11-13 02:11 - 2013-11-13 02:11 - 00035656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-12 23:33 - 2013-11-12 23:34 - 00143048 _____ C:\Windows\Minidump\111213-22625-01.dmp
2013-11-12 23:32 - 2013-11-12 23:32 - 00259928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2013-11-11 22:52 - 2013-11-29 15:34 - 00000000 ____D C:\Users\Oliver\Desktop\pics
2013-11-11 15:57 - 2013-11-11 15:57 - 00001112 _____ C:\Users\Oliver\Desktop\write.lnk
2013-11-11 15:57 - 2013-11-11 15:57 - 00001076 _____ C:\Users\Oliver\Desktop\calc.lnk
2013-11-08 21:48 - 2013-11-08 21:49 - 00143048 _____ C:\Windows\Minidump\110813-16093-01.dmp
2013-11-04 22:27 - 2013-11-28 20:20 - 00000000 ____D C:\Users\Oliver\Desktop\dokumente
2013-11-04 18:25 - 2013-11-04 18:25 - 00000000 ____D C:\ProgramData\Oracle
2013-11-04 18:18 - 2012-08-23 15:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2013-11-04 18:18 - 2012-08-23 15:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2013-11-04 18:18 - 2012-08-23 15:40 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2013-11-04 18:18 - 2012-08-23 15:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-04 18:18 - 2012-08-23 15:10 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-04 18:18 - 2012-08-23 14:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2013-11-04 18:18 - 2012-08-23 14:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2013-11-04 18:18 - 2012-08-23 14:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2013-11-04 18:18 - 2012-08-23 14:32 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-04 18:18 - 2012-08-23 14:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2013-11-04 18:18 - 2012-08-23 12:40 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2013-11-04 18:18 - 2012-08-23 12:32 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2013-11-04 18:18 - 2012-08-23 12:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2013-11-04 18:18 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2013-11-04 18:18 - 2012-08-23 11:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-11-04 18:18 - 2012-08-23 11:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-11-04 18:18 - 2012-08-23 09:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-11-04 18:16 - 2013-11-13 17:10 - 00000000 ____D C:\Windows\system32\MRT
2013-11-04 18:16 - 2013-11-13 17:09 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-04 18:15 - 2013-09-04 02:15 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-11-04 18:15 - 2013-09-04 02:14 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-04 18:15 - 2012-05-04 10:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2013-11-03 23:58 - 2013-11-03 23:58 - 00143048 _____ C:\Windows\Minidump\110313-23906-01.dmp
2013-11-03 18:48 - 2013-11-03 18:48 - 00001989 _____ C:\Users\Public\Desktop\adobe.lnk
2013-11-03 18:48 - 2013-11-03 18:48 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-03 18:44 - 2013-11-03 18:44 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\PDF Architect
2013-11-03 18:43 - 2013-11-03 18:43 - 00000963 _____ C:\Users\Oliver\Desktop\pdf1.lnk
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Users\Oliver\Documents\PDF Architect Files
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\PDF Architect
2013-11-03 18:42 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\PDFCreator
2013-11-03 18:42 - 2013-11-03 18:42 - 00000989 _____ C:\Users\Public\Desktop\pdf2.lnk
2013-11-03 18:42 - 2013-04-09 15:13 - 00095416 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2013-11-03 18:42 - 2013-01-09 15:52 - 01070152 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCTL.OCX
2013-11-03 18:42 - 2012-05-05 11:54 - 00662288 _____ (Microsoft Corporation) C:\Windows\system32\MSCOMCT2.OCX
2013-11-03 18:42 - 2012-05-05 11:54 - 00137000 _____ (Microsoft Corporation) C:\Windows\system32\MSMAPI32.OCX
2013-11-03 18:42 - 2012-05-05 11:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\MSMPIDE.DLL
2013-11-03 18:42 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\Windows\system32\VB6DE.DLL
2013-11-03 18:42 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\MSCMCDE.DLL
2013-11-03 18:42 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\MSCC2DE.DLL
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\InstallShield
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Program Files\Common Files\snp325
2013-11-03 14:41 - 2007-05-10 13:18 - 00835584 _____ () C:\Windows\vsnp325.exe
2013-11-03 14:41 - 2007-05-07 17:58 - 10343168 _____ (Sonix Co. Ltd.) C:\Windows\system32\Drivers\snp325.sys
2013-11-03 14:41 - 2007-04-21 09:36 - 00270336 _____ () C:\Windows\tsnp325.exe
2013-11-03 14:41 - 2007-04-20 16:40 - 00057344 _____ ( ) C:\Windows\system32\vsnp325.dll
2013-11-03 14:41 - 2007-02-12 14:50 - 00020480 _____ () C:\Windows\FixCamera.exe
2013-11-03 14:41 - 2006-07-03 10:31 - 00094208 _____ (Microsoft Corporation) C:\Windows\amcap.exe
2013-11-03 14:41 - 2006-04-12 12:11 - 00147456 _____ ( ) C:\Windows\system32\rsnp325.dll
2013-11-03 14:41 - 2005-11-23 13:55 - 00053248 _____ ( ) C:\Windows\system32\csnp325.dll
2013-11-03 14:41 - 2004-02-27 17:36 - 00015498 _____ C:\Windows\snp325.ini
2013-11-03 14:41 - 2004-02-27 17:36 - 00013023 _____ C:\Windows\snp325.src

==================== One Month Modified Files and Folders =======

2013-11-29 20:38 - 2013-11-29 15:47 - 00000000 ____D C:\Users\Oliver\Desktop\xxx
2013-11-29 20:25 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-29 20:25 - 2009-07-14 05:34 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-29 20:23 - 2013-09-07 13:09 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-29 20:21 - 2013-09-07 12:59 - 01616212 _____ C:\Windows\WindowsUpdate.log
2013-11-29 20:18 - 2013-11-15 12:41 - 00000000 ____D C:\Program Files\Steam
2013-11-29 20:18 - 2013-09-28 10:40 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-29 20:18 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-29 20:18 - 2009-07-14 05:39 - 00035964 _____ C:\Windows\setupact.log
2013-11-29 15:51 - 2013-10-29 13:55 - 00001150 _____ C:\Users\Oliver\Desktop\music.lnk
2013-11-29 15:49 - 2013-09-28 10:40 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-29 15:34 - 2013-11-11 22:52 - 00000000 ____D C:\Users\Oliver\Desktop\pics
2013-11-29 03:46 - 2013-10-25 13:48 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Skype
2013-11-28 20:21 - 2013-11-28 20:21 - 00013911 _____ C:\Users\Oliver\Desktop\NFL Gamepass.odt
2013-11-28 20:20 - 2013-11-04 22:27 - 00000000 ____D C:\Users\Oliver\Desktop\dokumente
2013-11-28 18:47 - 2013-11-28 18:47 - 00891184 _____ C:\Users\Oliver\Downloads\SecurityCheck.exe
2013-11-28 17:46 - 2013-11-28 17:46 - 02347384 _____ (ESET) C:\Users\Oliver\Downloads\esetsmartinstaller_enu.exe
2013-11-27 16:13 - 2013-11-27 16:13 - 01034531 _____ (Thisisu) C:\Users\Oliver\Downloads\JRT.exe
2013-11-27 16:13 - 2013-11-27 16:13 - 00000000 ____D C:\Windows\ERUNT
2013-11-27 16:05 - 2013-11-13 02:41 - 00000000 ____D C:\AdwCleaner
2013-11-27 16:04 - 2013-11-27 16:04 - 01091882 _____ C:\Users\Oliver\Downloads\adwcleaner.exe
2013-11-27 15:56 - 2013-09-20 19:05 - 00399396 _____ C:\Windows\PFRO.log
2013-11-27 15:56 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\AppCompat
2013-11-27 15:08 - 2013-11-27 15:08 - 00001067 _____ C:\Users\Public\Desktop\malewarebytes.lnk
2013-11-27 15:08 - 2013-11-27 15:08 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Malwarebytes
2013-11-27 15:08 - 2013-11-27 15:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-27 15:08 - 2013-11-27 15:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-11-27 15:05 - 2013-11-27 15:05 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Oliver\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-27 10:23 - 2013-11-27 10:05 - 00000000 ____D C:\Qoobox
2013-11-27 10:23 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default
2013-11-27 10:23 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2013-11-27 10:20 - 2013-11-27 10:05 - 00000000 ____D C:\Windows\erdnt
2013-11-27 10:18 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini
2013-11-27 10:04 - 2013-11-27 10:04 - 05150163 ____R (Swearware) C:\Users\Oliver\Downloads\ComboFix.exe
2013-11-26 01:12 - 2013-11-26 01:12 - 00143048 _____ C:\Windows\Minidump\112613-16453-01.dmp
2013-11-26 01:12 - 2013-10-24 23:06 - 00000000 ____D C:\Windows\Minidump
2013-11-25 18:38 - 2013-11-25 18:38 - 00000000 ____D C:\FRST
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2013-11-25 12:57 - 2013-11-25 12:57 - 00000000 ____D C:\Program Files\NirSoft
2013-11-25 12:56 - 2013-11-25 12:56 - 00141480 _____ C:\Users\Oliver\Downloads\bluescreenview_152setup.exe
2013-11-25 11:33 - 2013-11-25 11:32 - 00143048 _____ C:\Windows\Minidump\112513-15531-01.dmp
2013-11-25 11:33 - 2009-07-14 05:53 - 00032630 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-21 00:22 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-11-20 23:40 - 2013-09-07 16:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-11-20 15:25 - 2013-11-20 15:25 - 00143048 _____ C:\Windows\Minidump\112013-20000-01.dmp
2013-11-20 15:15 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-11-20 01:09 - 2013-11-20 01:04 - 00010261 _____ C:\Windows\IE11_main.log
2013-11-20 01:05 - 2013-11-20 01:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 01:05 - 2013-11-20 01:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 01:05 - 2013-11-20 01:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 01:05 - 2013-11-20 01:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 01:05 - 2013-11-20 01:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 01:05 - 2013-11-20 01:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 01:05 - 2013-11-20 01:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-18 10:36 - 2013-09-20 08:28 - 00000000 ____D C:\Users\Oliver\AppData\Local\Adobe
2013-11-18 10:31 - 2013-11-18 10:31 - 00000000 ____D C:\ProgramData\McAfee
2013-11-18 10:25 - 2013-11-17 21:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-16 11:10 - 2013-11-16 11:10 - 00734008 _____ C:\Windows\Minidump\111613-14031-01.dmp
2013-11-15 13:40 - 2013-11-15 13:40 - 00000000 ____D C:\Users\Oliver\Documents\Paradox Interactive
2013-11-15 12:43 - 2013-11-15 12:43 - 00000000 ____D C:\Program Files\dumps
2013-11-15 12:41 - 2013-11-15 12:41 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-11-15 12:40 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-11-15 11:53 - 2013-10-27 12:45 - 00002121 _____ C:\Users\Public\Desktop\chrome.lnk
2013-11-13 17:10 - 2013-11-04 18:16 - 00000000 ____D C:\Windows\system32\MRT
2013-11-13 17:09 - 2013-11-04 18:16 - 80340640 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 02:19 - 2013-09-28 10:40 - 00000000 ____D C:\Program Files\Google
2013-11-13 02:19 - 2013-05-08 17:59 - 00000000 ____D C:\Program Files\epson
2013-11-13 02:17 - 2013-11-13 02:17 - 00026136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2013-11-13 02:17 - 2013-11-13 02:17 - 00002053 _____ C:\Users\Public\Desktop\avast.lnk
2013-11-13 02:11 - 2013-11-13 02:11 - 00774392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00403440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00178304 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00070384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00057672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00049944 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-11-13 02:11 - 2013-11-13 02:11 - 00035656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-11-13 02:11 - 2013-11-13 02:11 - 00000000 ____D C:\Program Files\AVAST Software
2013-11-13 02:11 - 2013-10-27 12:44 - 00269216 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-11-13 02:10 - 2013-10-27 12:43 - 00000000 ____D C:\ProgramData\AVAST Software
2013-11-13 02:09 - 2013-05-07 07:34 - 00000000 ____D C:\Program Files\Elaborate Bytes
2013-11-13 01:49 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\twain_32
2013-11-13 01:48 - 2013-09-07 14:58 - 00000000 ____D C:\Users\Oliver\AppData\Local\Google
2013-11-13 01:47 - 2013-09-20 10:02 - 00000000 ____D C:\ProgramData\EPSON
2013-11-13 01:09 - 2013-09-20 15:14 - 00000862 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-11-12 23:34 - 2013-11-12 23:33 - 00143048 _____ C:\Windows\Minidump\111213-22625-01.dmp
2013-11-12 23:32 - 2013-11-12 23:32 - 00259928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2013-11-12 07:56 - 2009-07-14 05:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-11-11 15:57 - 2013-11-11 15:57 - 00001112 _____ C:\Users\Oliver\Desktop\write.lnk
2013-11-11 15:57 - 2013-11-11 15:57 - 00001076 _____ C:\Users\Oliver\Desktop\calc.lnk
2013-11-11 05:50 - 2013-09-07 15:05 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-08 21:49 - 2013-11-08 21:48 - 00143048 _____ C:\Windows\Minidump\110813-16093-01.dmp
2013-11-04 18:28 - 2009-07-14 09:47 - 00000000 ____D C:\Windows\system32\Drivers\de-DE
2013-11-04 18:25 - 2013-11-04 18:25 - 00000000 ____D C:\ProgramData\Oracle
2013-11-03 23:58 - 2013-11-03 23:58 - 00143048 _____ C:\Windows\Minidump\110313-23906-01.dmp
2013-11-03 22:44 - 2013-09-20 15:17 - 00000000 ____D C:\ProgramData\Adobe
2013-11-03 18:52 - 2013-09-07 16:10 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\Adobe
2013-11-03 18:48 - 2013-11-03 18:48 - 00001989 _____ C:\Users\Public\Desktop\adobe.lnk
2013-11-03 18:48 - 2013-11-03 18:48 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-03 18:48 - 2013-09-20 07:48 - 00000000 ____D C:\Program Files\Adobe
2013-11-03 18:44 - 2013-11-03 18:44 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\PDF Architect
2013-11-03 18:43 - 2013-11-03 18:43 - 00000963 _____ C:\Users\Oliver\Desktop\pdf1.lnk
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Users\Oliver\Documents\PDF Architect Files
2013-11-03 18:43 - 2013-11-03 18:43 - 00000000 ____D C:\Program Files\PDF Architect
2013-11-03 18:43 - 2013-11-03 18:42 - 00000000 ____D C:\Program Files\PDFCreator
2013-11-03 18:42 - 2013-11-03 18:42 - 00000989 _____ C:\Users\Public\Desktop\pdf2.lnk
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Users\Oliver\AppData\Roaming\InstallShield
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Program Files\Common Files\snp325
2013-11-03 14:41 - 2009-07-14 03:04 - 00000461 _____ C:\Windows\win.ini

Some content of TEMP:
====================
C:\Users\Oliver\AppData\Local\temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-21 00:14

==================== End Of Log ============================

--- --- ---

schrauber 30.11.2013 17:01

Fertig :)

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

Tron Legacy 01.12.2013 17:07

Hallo,

erstmal vielen Dank für Deine gesamte Unterstützung. Das scheint ja alles hervorragend geklappt zu haben. Seit dieser Prozess hier läuft, gab es keine Probleme mehr. Deine Tipps habe ich nun nach bestem Wissen und Gewissen umgesetzt. Zei Fragen bleiben allerdings noch über:

Mit "Registry Cleanern" meinst Du solche Programme wie den genutzten adwcleaner.exe, richtig?

Bei einem Download (WOT) hat sich allerdings wieder eine auffällige Toolbar eingenistet, die sich nicht entfernen lässt. Villeich kannst Du mir zu diesem Punkt nochmals kurz einen Tipp geben.

Und zwar: Free Games (4357) / Zula Games (Browser Extensions and Add-ons Development: Firefox, Google Chrome, Internet Explorer, Safari, Opera. -). Wie das passieren konnte, weiß ich jetzt nicht. Ist auf jeden Fall drauf. Lässt sich in meinen beiden Browsern (Firefox & Chrome) zwar entfernen, taucht aber bei Systemsteuerung / Programme weiter auf und lässt sich dort nicht entfernen bzw. deinstalieren.

Vlt. kannst Du mir zu diesem Punkt nochmal was schreiben! Vielen Dank.

So, jetzt hab ichs über Computer / C / Programme wegbekommen. Da war wohl der Ordner noch über. Jetzt taucht Zula nirgendswo mehr auf (zumindest für mich nicht sichtbar!).

schrauber 02.12.2013 10:44

Zitat:

Mit "Registry Cleanern" meinst Du solche Programme wie den genutzten adwcleaner.exe, richtig?
Nein, ccleaner, TuneUp und Co.
Zitat:

Und zwar: Free Games (4357) / Zula Games (Browser Extensions and Add-ons Development: Firefox, Google Chrome, Internet Explorer, Safari, Opera. -). Wie das passieren konnte, weiß ich jetzt nicht. Ist auf jeden Fall drauf. Lässt sich in meinen beiden Browsern (Firefox & Chrome) zwar entfernen, taucht aber bei Systemsteuerung / Programme weiter auf und lässt sich dort nicht entfernen bzw. deinstalieren.
Niemals etwas auf Standard installieren, immer benutzerdefiniert, so kannste Toolbars und Co abwählen.

Tron Legacy 08.12.2013 14:14

Hallo Schrauber,

ich weiß nicht mehr weiter! Leider ist der PC eben nach längerer Zeit wieder mal einfach so herunter- und wieder hochgefahren. Besteht dann weiter ein Problem, oder wie ist das jetzt zu werten?

Über eine kurze Rückantwort freue ich mich sehr!

MfG

Matthias

Code:

120813-18265-01.dmp        08.12.2013 13:49:23        BAD_POOL_CALLER        0x000000c2        0x00000007        0x0000109b        0x0813001f        0x875d5ee0        ndis.sys        ndis.sys+41000        NDIS 6.20-Treiber        Betriebssystem Microsoft® Windows®        Microsoft Corporation        6.1.7600.16385 (win7_rtm.090713-1255)        32-bit        ntoskrnl.exe+118c4e        ndis.sys+3623        wfplwf.sys+1ab8        ndis.sys+31b4                C:\Windows\Minidump\120813-18265-01.dmp        2        15        7601        143.096        08.12.2013 13:51:06
Code:

halmacpi.dll        halmacpi.dll+3700        0x82c13000        0x82c4a000        0x00037000        0x4ce788d2        20.11.2010 09:37:38        Microsoft® Windows® Operating System        Hardware Abstraction Layer DLL        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\halmacpi.dll       
ndis.sys        ndis.sys+41000        0x89a87000        0x89b3e000        0x000b7000        0x5034f1da        22.08.2012 15:51:06        Betriebssystem Microsoft® Windows®        NDIS 6.20-Treiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\ndis.sys       
ndisuio.sys        ndisuio.sys+16896ba8        0x8beae000        0x8bebe000        0x00010000        0x4ce79dac        20.11.2010 11:06:36        Betriebssystem Microsoft® Windows®        E/A-Treiber für NDIS-Benutzermodus        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\ndisuio.sys       
ntoskrnl.exe        ntoskrnl.exe+1fafac14        0x82c4a000        0x8304f000        0x00405000        0x521e9c63        29.08.2013 01:57:07        Microsoft® Windows® Operating System        NT Kernel & System        6.1.7601.18247 (win7sp1_gdr.130828-1532)        Microsoft Corporation        C:\Windows\system32\ntoskrnl.exe       
pacer.sys        pacer.sys+129007a8        0x8fe44000        0x8fe63000        0x0001f000        0x4a5bc916        14.07.2009 00:53:58        Betriebssystem Microsoft® Windows®        QoS-Paketplaner        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\pacer.sys       
wfplwf.sys        wfplwf.sys+1ab8        0x8fe3d000        0x8fe44000        0x00007000        0x4a5bc90f        14.07.2009 00:53:51        Microsoft® Windows® Operating System        WFP NDIS 6.20 Lightweight Filter Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\wfplwf.sys       
kdcom.dll                0x80baf000        0x80bb7000        0x00008000        0x4a5bdaaa        14.07.2009 02:08:58        Microsoft® Windows® Operating System        Serial Kernel Debugger        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\kdcom.dll       
mcupdate_GenuineIntel.dll                0x89404000        0x89489000        0x00085000        0x4ce7b876        20.11.2010 13:00:54        Microsoft® Windows® Operating System        Intel Microcode Update Library        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\mcupdate_GenuineIntel.dll       
PSHED.dll                0x89489000        0x8949a000        0x00011000        0x4a5bdad0        14.07.2009 02:09:36        Betriebssystem Microsoft® Windows®        Plattformspezifischer Hardwarefehlertreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\PSHED.dll       
BOOTVID.dll                0x8949a000        0x894a2000        0x00008000        0x4a5bd9a2        14.07.2009 02:04:34        Microsoft® Windows® Operating System        VGA Boot Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\BOOTVID.dll       
CLFS.SYS                0x894a2000        0x894e4000        0x00042000        0x4a5bbf0e        14.07.2009 00:11:10        Microsoft® Windows® Operating System        Common Log File System Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\CLFS.SYS       
CI.dll                0x894e4000        0x8958f000        0x000ab000        0x4ce7b97d        20.11.2010 13:05:17        Betriebssystem Microsoft® Windows®        Codeintegritätsmodul        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\CI.dll       
Wdf01000.sys                0x8958f000        0x89610000        0x00081000        0x51c50c11        22.06.2013 03:29:37        Betriebssystem Microsoft® Windows®        Kernelmodustreiber-Frameworklaufzeit        1.11.9200.16384 (win8_rtm.120725-1247)        Microsoft Corporation        C:\Windows\system32\drivers\Wdf01000.sys       
WDFLDR.SYS                0x89610000        0x8961e000        0x0000e000        0x5010ad36        26.07.2012 03:36:38        Microsoft® Windows® Operating System        Kernel Mode Driver Framework Loader        1.11.9200.16384 (win8_rtm.120725-1247)        Microsoft Corporation        C:\Windows\system32\drivers\WDFLDR.SYS       
ACPI.sys                0x8961e000        0x89666000        0x00048000        0x4ce788e0        20.11.2010 09:37:52        Betriebssystem Microsoft® Windows®        ACPI-Treiber für NT        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\ACPI.sys       
WMILIB.SYS                0x89666000        0x8966f000        0x00009000        0x4a5bbf1a        14.07.2009 00:11:22        Microsoft® Windows® Operating System        WMILIB WMI support library Dll        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\WMILIB.SYS       
msisadrv.sys                0x8966f000        0x89677000        0x00008000        0x4a5bbf0d        14.07.2009 00:11:09        Microsoft® Windows® Operating System        ISA Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\msisadrv.sys       
pci.sys                0x89677000        0x896a1000        0x0002a000        0x4ce788e5        20.11.2010 09:37:57        Betriebssystem Microsoft® Windows®        NT-Plug & Play PCI-Enumerator        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\pci.sys       
vdrvroot.sys                0x896a1000        0x896ac000        0x0000b000        0x4a5bc74b        14.07.2009 00:46:19        Betriebssystem Microsoft® Windows®        Stammenumerator für virtuelles Laufwerk        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\vdrvroot.sys       
partmgr.sys                0x896ac000        0x896bd000        0x00011000        0x4f641b0c        17.03.2012 06:03:08        Microsoft® Windows® Operating System        Partition Management Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\partmgr.sys       
volmgr.sys                0x896bd000        0x896cd000        0x00010000        0x4ce788ee        20.11.2010 09:38:06        Microsoft® Windows® Operating System        Volume Manager Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\volmgr.sys       
volmgrx.sys                0x896cd000        0x89718000        0x0004b000        0x00000000                Betriebssystem Microsoft® Windows®        Treiber für Erweiterung des Volume-Managers        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\volmgrx.sys       
viaide.sys                0x89718000        0x89720000        0x00008000        0x4a5bbf18        14.07.2009 00:11:20        VIA PCI IDE MINI Driver        VIA Generic PCI IDE Bus Driver        6,0,6000,170        VIA Technologies, Inc.        C:\Windows\system32\drivers\viaide.sys       
PCIIDEX.SYS                0x89720000        0x8972e000        0x0000e000        0x4a5bbf13        14.07.2009 00:11:15        Microsoft® Windows® Operating System        PCI IDE Bus Driver Extension        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\PCIIDEX.SYS       
mountmgr.sys                0x8972e000        0x89744000        0x00016000        0x4ce788f1        20.11.2010 09:38:09        Betriebssystem Microsoft® Windows®        Bereitstellungspunkt-Manager        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\mountmgr.sys       
vmbus.sys                0x89744000        0x8976d180        0x00029180        0x4ce79192        20.11.2010 10:14:58        Microsoft® Windows® Operating System        Virtual Machine Bus        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\vmbus.sys       
winhv.sys                0x8976e000        0x89780000        0x00012000        0x4ce788f7        20.11.2010 09:38:15        Microsoft® Windows® Operating System        Windows Hypervisor Interface Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\winhv.sys       
atapi.sys                0x89780000        0x89789000        0x00009000        0x4a5bbf13        14.07.2009 00:11:15        Microsoft® Windows® Operating System        ATAPI IDE Miniport Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\atapi.sys       
ataport.SYS                0x89789000        0x897ac000        0x00023000        0x51fef603        05.08.2013 01:46:59        Microsoft® Windows® Operating System        ATAPI Driver Extension        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\ataport.SYS       
vsmraid.sys                0x897ac000        0x897d1000        0x00025000        0x4983a5b9        31.01.2009 02:13:29        VIA RAID driver        VIA RAID DRIVER FOR AMD-X86-64        6.0.6000.6210        VIA Technologies Inc.,Ltd        C:\Windows\system32\drivers\vsmraid.sys       
storport.sys                0x89810000        0x89858000        0x00048000        0x4d799d50        11.03.2011 04:56:00        Microsoft® Windows® Operating System        Microsoft Storage Port Driver        6.1.7601.17577 (win7sp1_gdr.110310-1504)        Microsoft Corporation        C:\Windows\system32\drivers\storport.sys       
amdxata.sys                0x89858000        0x89861000        0x00009000        0x4ba3a3f5        19.03.2010 17:19:01        Storage Filter Driver        Storage Filter Driver        1.1.2.5 (NT.091202-1711)        Advanced Micro Devices        C:\Windows\system32\drivers\amdxata.sys       
fltmgr.sys                0x89861000        0x89895000        0x00034000        0x4a5bbf11        14.07.2009 00:11:13        Betriebssystem Microsoft® Windows®        Microsoft Dateisystem-Filter-Manager        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\fltmgr.sys       
fileinfo.sys                0x89895000        0x898a6000        0x00011000        0x4a5bc18f        14.07.2009 00:21:51        Microsoft® Windows® Operating System        FileInfo Filter Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\fileinfo.sys       
Ntfs.sys                0x898a6000        0x899d5000        0x0012f000        0x5167f0ab        12.04.2013 12:31:55        Betriebssystem Microsoft® Windows®        NT-Dateisystemtreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\Ntfs.sys       
msrpc.sys                0x899d5000        0x89a00000        0x0002b000        0x00000000                Microsoft® Windows® Operating System        Kernel Remote Procedure Call Provider        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\msrpc.sys       
ksecdd.sys                0x89a00000        0x89a13000        0x00013000        0x5242330d        25.09.2013 01:49:17        Microsoft® Windows® Operating System        Kernel Security Support Provider Interface        6.1.7601.18270 (win7sp1_gdr.130924-1532)        Microsoft Corporation        C:\Windows\system32\drivers\ksecdd.sys       
cng.sys                0x89a13000        0x89a70000        0x0005d000        0x501946b4        01.08.2012 16:09:40        Microsoft® Windows® Operating System        Kernel Cryptography, Next Generation        6.1.7601.17919 (win7sp1_gdr.120801-0333)        Microsoft Corporation        C:\Windows\system32\drivers\cng.sys       
pcw.sys                0x89a70000        0x89a7e000        0x0000e000        0x4a5bbf0e        14.07.2009 00:11:10        Microsoft® Windows® Operating System        Performance Counters for Windows Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\pcw.sys       
Fs_Rec.sys                0x89a7e000        0x89a87000        0x00009000        0x00000000                Microsoft® Windows® Operating System        File System Recognizer Driver        6.1.7601.17787 (win7sp1_gdr.120229-1502)        Microsoft Corporation        C:\Windows\system32\drivers\Fs_Rec.sys       
NETIO.SYS                0x89b3e000        0x89b7c000        0x0003e000        0x5034f1ea        22.08.2012 15:51:22        Microsoft® Windows® Operating System        Network I/O Subsystem        6.1.7601.17939 (win7sp1_gdr.120822-0331)        Microsoft Corporation        C:\Windows\system32\drivers\NETIO.SYS       
ksecpkg.sys                0x89b7c000        0x89ba2000        0x00026000        0x52423688        25.09.2013 02:04:08        Microsoft® Windows® Operating System        Kernel Security Support Provider Interface Packages        6.1.7601.18270 (win7sp1_gdr.130924-1532)        Microsoft Corporation        C:\Windows\system32\drivers\ksecpkg.sys       
tcpip.sys                0x89c2b000        0x89d77000        0x0014c000        0x522bca92        08.09.2013 01:53:38        Betriebssystem Microsoft® Windows®        TCP/IP-Treiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\tcpip.sys       
fwpkclnt.sys                0x89d77000        0x89da8000        0x00031000        0x50e4f0fb        03.01.2013 03:46:19        Microsoft® Windows® Operating System        FWP/IPsec Kernel-Mode API        6.1.7601.18042 (win7sp1_gdr.130102-1436)        Microsoft Corporation        C:\Windows\system32\drivers\fwpkclnt.sys       
vmstorfl.sys                0x89da8000        0x89db1000        0x00009000        0x00000000                Microsoft® Windows® Operating System        Virtual Storage Filter Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\vmstorfl.sys       
volsnap.sys                0x89db1000        0x89df0000        0x0003f000        0x4ce788f5        20.11.2010 09:38:13        Betriebssystem Microsoft® Windows®        Volumeschattenkopie-Treiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\volsnap.sys       
uagp35.sys                0x89df0000        0x89e01000        0x00011000        0x4a5bc274        14.07.2009 00:25:40        Betriebssystem Microsoft® Windows®        MS AGPv3.5-Filter        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\uagp35.sys       
spldr.sys                0x89e01000        0x89e09000        0x00008000        0x4a084ebb        11.05.2009 17:13:47        Microsoft® Windows® Operating System        loader for security processor        6.1.7127.0 (fbl_security_bugfix(sepbld-s).090511-0900)        Microsoft Corporation        C:\Windows\system32\drivers\spldr.sys       
rdyboost.sys                0x89e09000        0x89e36000        0x0002d000        0x4ce78e17        20.11.2010 10:00:07        Microsoft® Windows® Operating System        ReadyBoost Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\rdyboost.sys       
mup.sys                0x89e36000        0x89e46000        0x00010000        0x4a5bbfc6        14.07.2009 00:14:14        Microsoft® Windows® Operating System        Multiple UNC Provider Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\mup.sys       
hwpolicy.sys                0x89e46000        0x89e4e000        0x00008000        0x4ce788cf        20.11.2010 09:37:35        Microsoft® Windows® Operating System        Hardware Policy Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\hwpolicy.sys       
fvevol.sys                0x89e4e000        0x89e80000        0x00032000        0x51009f61        24.01.2013 03:41:37        Microsoft® Windows® Operating System        BitLocker Drive Encryption Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\fvevol.sys       
disk.sys                0x89e80000        0x89e91000        0x00011000        0x4a5bbf20        14.07.2009 00:11:28        Microsoft® Windows® Operating System        PnP Disk Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\disk.sys       
CLASSPNP.SYS                0x89e91000        0x89eb6000        0x00025000        0x4a5bbf18        14.07.2009 00:11:20        Microsoft® Windows® Operating System        SCSI Class System Dll        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\CLASSPNP.SYS       
aswVmm.sys                0x89eb6000        0x89edef80        0x00028f80        0x524e72ea        04.10.2013 08:48:58                                        C:\Windows\system32\drivers\aswVmm.sys       
aswRvrt.sys                0x89edf000        0x89ee9000        0x0000a000        0x00000000                                                C:\Windows\system32\drivers\aswRvrt.sys       
cdrom.sys                0x89f36000        0x89f55000        0x0001f000        0x4ce788f1        20.11.2010 09:38:09        Microsoft® Windows® Operating System        SCSI CD-ROM Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\cdrom.sys       
aswSnx.sys                0x8fc28000        0x8fce8000        0x000c0000        0x527a3807        06.11.2013 13:37:27        avast! Antivirus        avast! Virtualization Driver        9.0.2008.177        AVAST Software        C:\Windows\system32\drivers\aswSnx.sys       
Null.SYS                0x8fce8000        0x8fcef000        0x00007000        0x00000000                Microsoft® Windows® Operating System        NULL Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\Null.SYS       
Beep.SYS                0x8fcef000        0x8fcf6000        0x00007000        0x4a5bc6fc        14.07.2009 00:45:00        Microsoft® Windows® Operating System        BEEP Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\Beep.SYS       
vga.sys                0x8fcf6000        0x8fd02000        0x0000c000        0x4a5bc27e        14.07.2009 00:25:50        Microsoft® Windows® Operating System        VGA/Super VGA Video Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\vga.sys       
VIDEOPRT.SYS                0x8fd02000        0x8fd23000        0x00021000        0x4a5bc27d        14.07.2009 00:25:49        Microsoft® Windows® Operating System        Video Port Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\VIDEOPRT.SYS       
watchdog.sys                0x8fd23000        0x8fd30000        0x0000d000        0x4a5bc21a        14.07.2009 00:24:10        Microsoft® Windows® Operating System        Watchdog Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\watchdog.sys       
RDPCDD.sys                0x8fd30000        0x8fd38000        0x00008000        0x4ce7a15b        20.11.2010 11:22:19        Microsoft® Windows® Operating System        RDP Miniport        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\RDPCDD.sys       
rdpencdd.sys                0x8fd38000        0x8fd40000        0x00008000        0x4a5bcae3        14.07.2009 01:01:39        Microsoft® Windows® Operating System        RDP Encoder Miniport        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\rdpencdd.sys       
rdprefmp.sys                0x8fd40000        0x8fd48000        0x00008000        0x4a5bcae5        14.07.2009 01:01:41        Microsoft® Windows® Operating System        RDP Reflector Driver Miniport        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\rdprefmp.sys       
Msfs.SYS                0x8fd48000        0x8fd53000        0x0000b000        0x00000000                Microsoft® Windows® Operating System        Mailslot driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\Msfs.SYS       
Npfs.SYS                0x8fd53000        0x8fd61000        0x0000e000        0x4a5bbf23        14.07.2009 00:11:31        Microsoft® Windows® Operating System        NPFS Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\Npfs.SYS       
tdx.sys                0x8fd61000        0x8fd78000        0x00017000        0x4ce78935        20.11.2010 09:39:17        Microsoft® Windows® Operating System        TDI Translation Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\tdx.sys       
TDI.SYS                0x8fd78000        0x8fd84000        0x0000c000        0x4ce78936        20.11.2010 09:39:18        Microsoft® Windows® Operating System        TDI Wrapper        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\TDI.SYS       
aswTdi.sys                0x8fd84000        0x8fd8fb00        0x0000bb00        0x527a37b6        06.11.2013 13:36:06        avast! Antivirus        avast! TDI Filter Driver        9.0.2008.177 built by: WinDDK        AVAST Software        C:\Windows\system32\drivers\aswTdi.sys       
afd.sys                0x8fd90000        0x8fdea000        0x0005a000        0x5233b278        14.09.2013 01:48:56        Betriebssystem Microsoft® Windows®        Ancillary Function Driver for WinSock        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\afd.sys       
aswRdr2.sys                0x8fdea000        0x8fe02000        0x00018000        0x5257dcdb        11.10.2013 12:11:23        avast! Antivirus        avast! WFP Redirect Driver        9.0.2006.149 built by: WinDDK        AVAST Software        C:\Windows\system32\drivers\aswRdr2.sys       
netbt.sys                0x8fe02000        0x8fe34000        0x00032000        0x4ce7893a        20.11.2010 09:39:22        Microsoft® Windows® Operating System        MBT Transport driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\netbt.sys       
ws2ifsl.sys                0x8fe34000        0x8fe3d000        0x00009000        0x4a5bc955        14.07.2009 00:55:01        Betriebssystem Microsoft® Windows®        Winsock2-IFS-Schicht        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\ws2ifsl.sys       
netbios.sys                0x8fe63000        0x8fe71000        0x0000e000        0x4a5bc912        14.07.2009 00:53:54        Microsoft® Windows® Operating System        NetBIOS interface driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\netbios.sys       
serial.sys                0x8fe71000        0x8fe8b000        0x0001a000        0x4a5bc71d        14.07.2009 00:45:33        Betriebssystem Microsoft® Windows®        Serieller Gerätetreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\serial.sys       
wanarp.sys                0x8fe8b000        0x8fe9e000        0x00013000        0x4ce79df1        20.11.2010 11:07:45        Microsoft® Windows® Operating System        MS Remote Access and Routing ARP Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\wanarp.sys       
termdd.sys                0x8fe9e000        0x8feaf000        0x00011000        0x4ce7a116        20.11.2010 11:21:10        Microsoft® Windows® Operating System        Remote Desktop Server Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\termdd.sys       
rdbss.sys                0x8feaf000        0x8fef0000        0x00041000        0x4ce78a04        20.11.2010 09:42:44        Betriebssystem Microsoft® Windows®        Subsystemtreiber für Pufferung des umgeleiteten Laufwerks        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\rdbss.sys       
nsiproxy.sys                0x8fef0000        0x8fefa000        0x0000a000        0x4a5bbf48        14.07.2009 00:12:08        Microsoft® Windows® Operating System        NSI Proxy        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\nsiproxy.sys       
mssmbios.sys                0x8fefa000        0x8ff04000        0x0000a000        0x4a5bc0fd        14.07.2009 00:19:25        Microsoft® Windows® Operating System        System Management BIOS Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\mssmbios.sys       
discache.sys                0x8ff04000        0x8ff10000        0x0000c000        0x4a5bc214        14.07.2009 00:24:04        Microsoft® Windows® Operating System        System Indexer/Cache Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\discache.sys       
csc.sys                0x8ff10000        0x8ff74000        0x00064000        0x4ce78a70        20.11.2010 09:44:32        Microsoft® Windows® Operating System        Windows Client Side Caching Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\csc.sys       
dfsc.sys                0x8ff74000        0x8ff8c000        0x00018000        0x4ce789f8        20.11.2010 09:42:32        Microsoft® Windows® Operating System        DFS Namespace Client Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\dfsc.sys       
blbdrive.sys                0x8ff8c000        0x8ff9a000        0x0000e000        0x4a5bc1d8        14.07.2009 00:23:04        Microsoft® Windows® Operating System        BLB Drive Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\blbdrive.sys       
aswSP.sys                0x8ff9a000        0x8fff9980        0x0005f980        0x5272538b        31.10.2013 13:56:43        avast! Antivirus        avast! self protection module        9.0.2007.172        AVAST Software        C:\Windows\system32\drivers\aswSP.sys       
tunnel.sys                0x8fc00000        0x8fc21000        0x00021000        0x4ce79db0        20.11.2010 11:06:40        Betriebssystem Microsoft® Windows®        Microsoft-Tunnelschnittstellentreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\tunnel.sys       
intelppm.sys                0x89f55000        0x89f67000        0x00012000        0x4a5bbf07        14.07.2009 00:11:03        Microsoft® Windows® Operating System        Processor Device Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\intelppm.sys       
atikmdag.sys                0x91425000        0x91879000        0x00454000        0x49f1996c        24.04.2009 11:50:20        ATI Radeon-Familie        ATI Radeon-Kernelmodustreiber        8.01.01.859        ATI Technologies Inc.        C:\Windows\system32\drivers\atikmdag.sys       
dxgkrnl.sys                0x91879000        0x91931000        0x000b8000        0x51fa113c        01.08.2013 08:41:48        Microsoft® Windows® Operating System        DirectX Graphics Kernel        6.1.7601.18228 (win7sp1_gdr.130731-2222)        Microsoft Corporation        C:\Windows\system32\drivers\dxgkrnl.sys       
dxgmms1.sys                0x91931000        0x9196a000        0x00039000        0x5164d8b5        10.04.2013 04:12:53        Microsoft® Windows® Operating System        DirectX Graphics MMS        6.1.7601.18126 (win7sp1_gdr.130409-1534)        Microsoft Corporation        C:\Windows\system32\drivers\dxgmms1.sys       
3xHybrid.sys                0x9196a000        0x91a80c80        0x00116c80        0x4cf7077f        02.12.2010 03:42:07        SAA713x TV Card        SAA713x TV Card Driver        2, 4, 0, 4        NXP Semiconductors Germany GmbH        C:\Windows\system32\drivers\3xHybrid.sys       
ks.sys                0x91a81000        0x91ab5000        0x00034000        0x4ce799d9        20.11.2010 10:50:17        Microsoft® Windows® Operating System        Kernel CSA Library        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\ks.sys       
BdaSup.SYS                0x91ab5000        0x91ab8000        0x00003000        0x4a5bc87b        14.07.2009 00:51:23        Microsoft® Windows® Operating System        Microsoft BDA Driver Support Library        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\BdaSup.SYS       
Rtnicxp.sys                0x91ab8000        0x91ac7000        0x0000f000        0x4840194b        30.05.2008 16:12:11        Realtek 10/100 NIC Family all in one NDIS Driver        Realtek 10/100 NDIS 5.1 Driver        6,109,0530,2008 built by: WinDDK        Realtek Semiconductor Corporation        C:\Windows\system32\drivers\Rtnicxp.sys       
mrv8k51.sys                0x91ac7000        0x91b13280        0x0004c280        0x42a6c736        08.06.2005 11:23:50        Device driver for Marvell 802.11 NIC        NDIS 5.1 driver        2.07.01.19 built by: WinDDK        Marvell Semiconductor, Inc        C:\Windows\system32\drivers\mrv8k51.sys       
usbuhci.sys                0x91b14000        0x91b1f000        0x0000b000        0x52268983        04.09.2013 02:14:43        Microsoft® Windows® Operating System        UHCI USB Miniport Driver        6.1.7601.18251 (win7sp1_gdr.130903-1532)        Microsoft Corporation        C:\Windows\system32\drivers\usbuhci.sys       
USBPORT.SYS                0x91b1f000        0x91b6a000        0x0004b000        0x5226898a        04.09.2013 02:14:50        Betriebssystem Microsoft® Windows®        USB 1.1 & 2.0-Porttreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\USBPORT.SYS       
usbehci.sys                0x91b6a000        0x91b79000        0x0000f000        0x52268985        04.09.2013 02:14:45        Microsoft® Windows® Operating System        EHCI eUSB Miniport Driver        6.1.7601.18251 (win7sp1_gdr.130903-1532)        Microsoft Corporation        C:\Windows\system32\drivers\usbehci.sys       
fdc.sys                0x91b79000        0x91b84000        0x0000b000        0x4a5bc729        14.07.2009 00:45:45        Microsoft® Windows® Operating System        Floppy Disk Controller Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\fdc.sys       
parport.sys                0x91b84000        0x91b9c000        0x00018000        0x4a5bc71e        14.07.2009 00:45:34        Betriebssystem Microsoft® Windows®        Treiber für parallelen Anschluss        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\parport.sys       
serenum.sys                0x91b9c000        0x91ba6000        0x0000a000        0x4a5bc717        14.07.2009 00:45:27        Microsoft® Windows® Operating System        Serial Port Enumerator        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\serenum.sys       
fetnd6.sys                0x91ba6000        0x91bb0c00        0x0000ac00        0x485a46e5        19.06.2008 12:45:41        VIA Rhine Family Fast Ethernet Adapter        NDIS 6.0 miniport driver        1.9.0.10        VIA Technologies, Inc.        C:\Windows\system32\drivers\fetnd6.sys       
HDAudBus.sys                0x91bb1000        0x91bd0000        0x0001f000        0x4ce79c00        20.11.2010 10:59:28        Microsoft® Windows® Operating System        High Definition Audio Bus Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\HDAudBus.sys       
CompositeBus.sys                0x91bd0000        0x91bdd000        0x0000d000        0x4ce799dd        20.11.2010 10:50:21        Microsoft® Windows® Operating System        Multi-Transport Composite Bus Enumerator        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\CompositeBus.sys       
AgileVpn.sys                0x91bdd000        0x91bef000        0x00012000        0x4a5bc954        14.07.2009 00:55:00        Microsoft® Windows® Operating System        RAS Agile Vpn Miniport Call Manager        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\AgileVpn.sys       
rasl2tp.sys                0x91400000        0x91418000        0x00018000        0x4a5bc939        14.07.2009 00:54:33        Microsoft® Windows® Operating System        RAS L2TP mini-port/call-manager driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\rasl2tp.sys       
ndistapi.sys                0x91418000        0x91423000        0x0000b000        0x4a5bc930        14.07.2009 00:54:24        Microsoft® Windows® Operating System        NDIS 3.0 connection wrapper driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\ndistapi.sys       
ndiswan.sys                0x89f67000        0x89f89000        0x00022000        0x4ce79df4        20.11.2010 11:07:48        Microsoft® Windows® Operating System        MS PPP Framing Driver (Strong Encryption)        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\ndiswan.sys       
raspppoe.sys                0x89f89000        0x89fa1000        0x00018000        0x4a5bc94d        14.07.2009 00:54:53        Microsoft® Windows® Operating System        RAS PPPoE mini-port/call-manager driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\raspppoe.sys       
raspptp.sys                0x89fa1000        0x89fb8000        0x00017000        0x4a5bc947        14.07.2009 00:54:47        Microsoft® Windows® Operating System        Peer-to-Peer Tunneling Protocol        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\raspptp.sys       
rassstp.sys                0x89fb8000        0x89fcf000        0x00017000        0x4a5bc951        14.07.2009 00:54:57        Microsoft® Windows® Operating System        RAS SSTP Miniport Call Manager        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\rassstp.sys       
rdpbus.sys                0x91bef000        0x91bf9000        0x0000a000        0x4a5bcb20        14.07.2009 01:02:40        Microsoft® Windows® Operating System        Microsoft RDP Bus Device driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\rdpbus.sys       
kbdclass.sys                0x89fcf000        0x89fdc000        0x0000d000        0x4a5bbf13        14.07.2009 00:11:15        Betriebssystem Microsoft® Windows®        Tastaturklassentreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\kbdclass.sys       
mouclass.sys                0x89fdc000        0x89fe9000        0x0000d000        0x4a5bbf13        14.07.2009 00:11:15        Betriebssystem Microsoft® Windows®        Mausklassentreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\mouclass.sys       
swenum.sys                0x91bf9000        0x91bfa380        0x00001380        0x4a5bc704        14.07.2009 00:45:08        Microsoft® Windows® Operating System        Plug and Play Software Device Enumerator        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\swenum.sys       
umbus.sys                0x89fe9000        0x89ff7000        0x0000e000        0x4ce79c37        20.11.2010 11:00:23        Microsoft® Windows® Operating System        User-Mode Bus Enumerator        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\umbus.sys       
ew_jubusenum.sys                0x89c00000        0x89c11e00        0x00011e00        0x4d453b14        30.01.2011 11:19:00        ew_jubusenum Driver (x86)        ew_jubusenum Driver        2.6.2.1605 built by: Huawei        Huawei Technologies Co., Ltd.        C:\Windows\system32\drivers\ew_jubusenum.sys       
usbhub.sys                0x89ba2000        0x89be6000        0x00044000        0x522689b2        04.09.2013 02:15:30        Microsoft® Windows® Operating System        Default Hub Driver for USB        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\usbhub.sys       
flpydisk.sys                0x89c12000        0x89c1c000        0x0000a000        0x4a5bc729        14.07.2009 00:45:45        Microsoft® Windows® Operating System        Floppy Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\flpydisk.sys       
NDProxy.SYS                0x89be6000        0x89bf7000        0x00011000        0x4ce79deb        20.11.2010 11:07:39        Microsoft® Windows® Operating System        NDIS Proxy        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\NDProxy.SYS       
HdAudio.sys                0x82011000        0x82061000        0x00050000        0x4ce79c33        20.11.2010 11:00:19        Microsoft® Windows® Operating System        High Definition Audio Function Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\HdAudio.sys       
portcls.sys                0x82061000        0x82090000        0x0002f000        0x4a5bc864        14.07.2009 00:51:00        Microsoft® Windows® Operating System        Port Class (Class Driver for Port/Miniport Devices)        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\portcls.sys       
drmk.sys                0x82090000        0x820a9000        0x00019000        0x4a5bd2f5        14.07.2009 01:36:05        Microsoft® Windows® Operating System        Microsoft Trusted Audio Drivers        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\drmk.sys       
win32k.sys                0x94880000        0x94ad1000        0x00251000        0x521d4c8d        28.08.2013 02:04:13        Betriebssystem Microsoft® Windows®        Mehrbenutzer-Win32-Treiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\win32k.sys       
Dxapi.sys                0x820a9000        0x820b3000        0x0000a000        0x4a5bc265        14.07.2009 00:25:25        Microsoft® Windows® Operating System        DirectX API Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\Dxapi.sys       
udfs.sys                0x820b3000        0x820f3000        0x00040000        0x4ce789f3        20.11.2010 09:42:27        Microsoft® Windows® Operating System        UDF File System Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\udfs.sys       
crashdmp.sys                0x820f3000        0x82100000        0x0000d000        0x4a5bc72e        14.07.2009 00:45:50        Microsoft® Windows® Operating System        Crash Dump Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\crashdmp.sys       
dump_diskdump.sys                0x82100000        0x8210a000        0x0000a000        0x4db1bc51        22.04.2011 18:35:13                                               
dump_vsmraid.sys                0x8210a000        0x8212f000        0x00025000        0x4983a5b9        31.01.2009 02:13:29                                               
dump_dumpfve.sys                0x8212f000        0x82140000        0x00011000        0x4a5bbf6f        14.07.2009 00:12:47                                               
usbccgp.sys                0x82140000        0x82157000        0x00017000        0x5226898c        04.09.2013 02:14:52        Microsoft® Windows® Operating System        USB Common Class Generic Parent Driver        6.1.7601.18251 (win7sp1_gdr.130903-1532)        Microsoft Corporation        C:\Windows\system32\drivers\usbccgp.sys       
USBD.SYS                0x82157000        0x82158780        0x00001780        0x52268980        04.09.2013 02:14:40        Microsoft® Windows® Operating System        Universal Serial Bus Driver        6.1.7601.18251 (win7sp1_gdr.130903-1532)        Microsoft Corporation        C:\Windows\system32\drivers\USBD.SYS       
hidusb.sys                0x82159000        0x82164000        0x0000b000        0x4ce79c0a        20.11.2010 10:59:38        Microsoft® Windows® Operating System        USB Miniport Driver for Input Devices        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\hidusb.sys       
HIDCLASS.SYS                0x82164000        0x82177000        0x00013000        0x51d39c38        03.07.2013 04:36:24        Microsoft® Windows® Operating System        Hid Class Library        6.1.7601.18199 (win7sp1_gdr.130702-1534)        Microsoft Corporation        C:\Windows\system32\drivers\HIDCLASS.SYS       
HIDPARSE.SYS                0x82177000        0x8217d480        0x00006480        0x51d39c36        03.07.2013 04:36:22        Microsoft® Windows® Operating System        Hid Parsing Library        6.1.7601.18199 (win7sp1_gdr.130702-1534)        Microsoft Corporation        C:\Windows\system32\drivers\HIDPARSE.SYS       
kbdhid.sys                0x8217e000        0x8218a000        0x0000c000        0x4ce799d2        20.11.2010 10:50:10        Betriebssystem Microsoft® Windows®        HID-Tastaturfiltertreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\kbdhid.sys       
mouhid.sys                0x8218a000        0x82195000        0x0000b000        0x4a5bc704        14.07.2009 00:45:08        Betriebssystem Microsoft® Windows®        HID-Mausfiltertreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\mouhid.sys       
USBSTOR.SYS                0x82195000        0x821ac000        0x00017000        0x4d799e88        11.03.2011 05:01:12        Microsoft® Windows® Operating System        USB Mass Storage Class Driver        6.1.7601.17577 (win7sp1_gdr.110310-1504)        Microsoft Corporation        C:\Windows\system32\drivers\USBSTOR.SYS       
snp325.sys                0x8b414000        0x8bdf1300        0x009dd300        0x463ef852        07.05.2007 10:58:42        USB PC Camera        USB PC Camera driver        1, 5, 4, 13        Sonix Co. Ltd.        C:\Windows\system32\drivers\snp325.sys       
STREAM.SYS                0x8bdf2000        0x8bdff180        0x0000d180        0x4a5bc861        14.07.2009 00:50:57        Microsoft® Windows® Operating System        WDM CODEC Class Device Driver 2.0        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\STREAM.SYS       
monitor.sys                0x8be00000        0x8be0b000        0x0000b000        0x4a5bc286        14.07.2009 00:25:58        Microsoft® Windows® Operating System        Monitor Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\monitor.sys       
TSDDD.dll                0x94af0000        0x94af9000        0x00009000        0x4a5bcae4        14.07.2009 01:01:40        Microsoft® Windows® Operating System        Framebuffer Display Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\TSDDD.dll       
cdd.dll                0x94b20000        0x94b3e000        0x0001e000        0x00000000                Microsoft® Windows® Operating System        Canonical Display Driver        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\cdd.dll       
luafv.sys                0x8be0b000        0x8be26000        0x0001b000        0x4a5bc020        14.07.2009 00:15:44        Betriebssystem Microsoft® Windows®        LUA-Filtertreiber zur Dateivirtualisierung        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\luafv.sys       
aswMonFlt.sys                0x8be26000        0x8be4d000        0x00027000        0x527a37ac        06.11.2013 13:35:56        avast! Antivirus        avast! File System Minifilter for Windows 2003/Vista        9.0.2008.177        AVAST Software        C:\Windows\system32\drivers\aswMonFlt.sys       
mbam.sys                0x8be4d000        0x8be50a00        0x00003a00        0x512fbf04        28.02.2013 21:33:08        Malwarebytes Anti-Malware        Malwarebytes Anti-Malware        1.60.2.0000 built by: WinDDK        Malwarebytes Corporation        C:\Windows\system32\drivers\mbam.sys       
aswFsBlk.sys                0x8be51000        0x8be57580        0x00006580        0x527a37b3        06.11.2013 13:36:03        avast! Antivirus        avast! File System Access Blocking Driver        9.0.2008.177        AVAST Software        C:\Windows\system32\drivers\aswFsBlk.sys       
lltdio.sys                0x8be58000        0x8be68000        0x00010000        0x4a5bc8ee        14.07.2009 00:53:18        Microsoft® Windows® Operating System        Link-Layer Topology Mapper I/O Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\lltdio.sys       
nwifi.sys                0x8be68000        0x8beae000        0x00046000        0x4a5bc89f        14.07.2009 00:51:59        Betriebssystem Microsoft® Windows®        Systemeigener WiFi-Miniporttreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\nwifi.sys       
rspndr.sys                0x8bebe000        0x8bed1000        0x00013000        0x4a5bc8f0        14.07.2009 00:53:20        Microsoft® Windows® Operating System        Link-Layer Topology Responder Driver for NDIS 6        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\rspndr.sys       
HTTP.sys                0x8bed1000        0x8bf56000        0x00085000        0x4ce78971        20.11.2010 09:40:17        Betriebssystem Microsoft® Windows®        HTTP-Protokollstapel        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\HTTP.sys       
fastfat.SYS                0x8bf56000        0x8bf80000        0x0002a000        0x4a5bbfb9        14.07.2009 00:14:01        Microsoft® Windows® Operating System        Fast FAT File System Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\fastfat.SYS       
bowser.sys                0x8bf80000        0x8bf99000        0x00019000        0x4d649164        23.02.2011 05:47:32        Microsoft® Windows® Operating System        NT Lan Manager Datagram Receiver Driver        6.1.7601.17565 (win7sp1_gdr.110222-1630)        Microsoft Corporation        C:\Windows\system32\drivers\bowser.sys       
mpsdrv.sys                0x8bf99000        0x8bfab000        0x00012000        0x4a5bc8d4        14.07.2009 00:52:52        Microsoft® Windows® Operating System        Microsoft Protection Service Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\mpsdrv.sys       
mrxsmb.sys                0x8bfab000        0x8bfce000        0x00023000        0x4db77cb0        27.04.2011 03:17:20        Microsoft® Windows® Operating System        Windows NT SMB Minirdr        6.1.7601.17605 (win7sp1_gdr.110426-1503)        Microsoft Corporation        C:\Windows\system32\drivers\mrxsmb.sys       
mrxsmb10.sys                0x821ac000        0x821e7000        0x0003b000        0x4e17bd25        09.07.2011 03:29:57        Microsoft® Windows® Operating System        Longhorn SMB Downlevel SubRdr        6.1.7601.17647 (win7sp1_gdr.110708-1503)        Microsoft Corporation        C:\Windows\system32\drivers\mrxsmb10.sys       
mrxsmb20.sys                0x8bfce000        0x8bfe9000        0x0001b000        0x4db77cb6        27.04.2011 03:17:26        Microsoft® Windows® Operating System        Longhorn SMB 2.0 Redirector        6.1.7601.17605 (win7sp1_gdr.110426-1503)        Microsoft Corporation        C:\Windows\system32\drivers\mrxsmb20.sys       
parvdm.sys                0x8bfe9000        0x8bff0000        0x00007000        0x00000000                Betriebssystem Microsoft® Windows®        VDM-Paralleltreiber        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\parvdm.sys       
peauth.sys                0x821e7000        0x8227e000        0x00097000        0x4a5bd2e0        14.07.2009 01:35:44        Microsoft® Windows® Operating System        Protected Environment Authentication and Authorization Export Driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\peauth.sys       
secdrv.SYS                0x8bff0000        0x8bffa000        0x0000a000        0x45080528        13.09.2006 14:18:32        Macrovision SECURITY Driver        Macrovision SECURITY Driver        4.03.086        Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.        C:\Windows\system32\drivers\secdrv.SYS       
srvnet.sys                0x8227e000        0x8229f000        0x00021000        0x4dba2670        29.04.2011 03:46:08        Microsoft® Windows® Operating System        Server Network driver        6.1.7601.17608 (win7sp1_gdr.110428-1525)        Microsoft Corporation        C:\Windows\system32\drivers\srvnet.sys       
tcpipreg.sys                0x8b400000        0x8b40d000        0x0000d000        0x506c5801        03.10.2012 16:21:37        Microsoft® Windows® Operating System        TCP/IP Registry Compatibility Driver        6.1.7601.17964 (win7sp1_gdr.121003-0333)        Microsoft Corporation        C:\Windows\system32\drivers\tcpipreg.sys       
srv2.sys                0x8229f000        0x822ef000        0x00050000        0x4dba2675        29.04.2011 03:46:13        Microsoft® Windows® Operating System        Smb 2.0 Server driver        6.1.7601.17608 (win7sp1_gdr.110428-1525)        Microsoft Corporation        C:\Windows\system32\drivers\srv2.sys       
srv.sys                0x822ef000        0x82341000        0x00052000        0x4dba2686        29.04.2011 03:46:30        Microsoft® Windows® Operating System        Server driver        6.1.7600.16385 (win7_rtm.090713-1255)        Microsoft Corporation        C:\Windows\system32\drivers\srv.sys       
WudfPf.sys                0x8236c000        0x82380000        0x00014000        0x5010ac87        26.07.2012 03:33:43        Microsoft® Windows® Operating System        Windows Driver Foundation - User-mode Driver Framework Platform Driver        6.2.9200.16384 (win8_rtm.120725-1247)        Microsoft Corporation        C:\Windows\system32\drivers\WudfPf.sys       
WUDFRd.sys                0x82380000        0x823ab000        0x0002b000        0x5010ac53        26.07.2012 03:32:51        Microsoft® Windows® Operating System        Windows Driver Foundation - User-mode Driver Framework Reflector        6.2.9200.16384 (win8_rtm.120725-1247)        Microsoft Corporation        C:\Windows\system32\drivers\WUDFRd.sys       
rdpdr.sys                0x823ab000        0x823d0000        0x00025000        0x4ce7a1ec        20.11.2010 11:24:44        Microsoft® Windows® Operating System        Microsoft RDP Device redirector        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\rdpdr.sys       
tdtcp.sys                0x823d0000        0x823db000        0x0000b000        0x4f3dd3e1        17.02.2012 05:13:21        Microsoft® Windows® Operating System        TCP Transport Driver        6.1.7601.17779 (win7sp1_gdr.120216-1503)        Microsoft Corporation        C:\Windows\system32\drivers\tdtcp.sys       
tssecsrv.sys                0x823db000        0x823e8000        0x0000d000        0x51bbe1c2        15.06.2013 04:38:42        Microsoft® Windows® Operating System        TS Security Filter Driver        6.1.7601.18186 (win7sp1_gdr.130614-1531)        Microsoft Corporation        C:\Windows\system32\drivers\tssecsrv.sys       
RDPWD.SYS                0x89ee9000        0x89f1b000        0x00032000        0x4f9b612c        28.04.2012 04:17:00        Betriebssystem Microsoft® Windows®        RDP-Terminalstapeltreiber        6.1.7601.17514 (win7sp1_rtm.101119-1850)        Microsoft Corporation        C:\Windows\system32\drivers\RDPWD.SYS       
psi_mf_x86.sys                0x8b40d000        0x8b40f280        0x00002280        0x511373b4        07.02.2013 10:28:20        Secunia PSI        Secunia PSI Driver        1.0.10.5        Secunia        C:\Windows\system32\drivers\psi_mf_x86.sys


schrauber 08.12.2013 16:52

Häng den Dump mal bitte in einem Zip an.

Tron Legacy 08.12.2013 19:32

Hi Schrauber,

mach ich morgen (Montag) sobald ich wieder zuhause bin!

Kannst mir kurz schreiben, wie ich das als zip schicke.

Vielen Dank

schrauber 09.12.2013 09:55

Einfach zippen, unten in der Schnellantworten-Box auf Erweitert, im neuen Fenster runterscrollen und Anhänge verwalten anklicken :)

Tron Legacy 09.12.2013 17:36

So, ob das jetzt hierso richtig ist? Keine Ahnung...

Tron Legacy 09.12.2013 17:48

Also ich kann diese ZIP - Dateien irgendwie nicht öffnen / entpacken!

Tron Legacy 09.12.2013 18:11

Liste der Anhänge anzeigen (Anzahl: 1)
Vlt. kannst Du mit den Daten auch im PDF - Format etwas anfangen...

schrauber 10.12.2013 10:29

Schick mir bitte heute Abend ne PM, ich schau dann. Auf Arbeit kann ich keine Anhänge laden.

Tron Legacy 11.12.2013 13:01

Okay, vlt. kannst Du mich dann nochmal kontaktieren...

Liebe Grüße

schrauber 12.12.2013 09:21

Du solltest mir eigentlich ne PM (Private Nachricht) schicken, damit ich dran denke und Abends schauen kann ;).

Ich hab knapp über 200 aktive Themen hier, ich kann mir die nit alle merken :D

Tron Legacy 12.12.2013 11:44

Hallo,

habeDir nach Deiner Aufforderung direkt ne PM hinterlassen.
Außerdem gab es eben gerade einen erneuten Crash mit meinem PC.

Liebe Grüße

Tron Legacy 12.12.2013 12:02

Liste der Anhänge anzeigen (Anzahl: 1)
...

Tron Legacy 12.12.2013 12:20

Code:

121213-22031-01.dmp        12.12.2013 11:35:02        BAD_POOL_HEADER        0x00000019        0x00000020        0x84f73ae8        0x84f73b50        0x080d0001        ndis.sys        ndis.sys+41000        NDIS 6.20-Treiber        Betriebssystem Microsoft® Windows®        Microsoft Corporation        6.1.7600.16385 (win7_rtm.090713-1255)        32-bit        ntoskrnl.exe+118c4e        ndis.sys+3623        pacer.sys+610e        ndis.sys+31b4                C:\Windows\Minidump\121213-22031-01.dmp        2        15        7601        143.096        12.12.2013 11:36:20       
120813-18265-01.dmp        08.12.2013 13:49:23        BAD_POOL_CALLER        0x000000c2        0x00000007        0x0000109b        0x0813001f        0x875d5ee0        ndis.sys        ndis.sys+41000        NDIS 6.20-Treiber        Betriebssystem Microsoft® Windows®        Microsoft Corporation        6.1.7600.16385 (win7_rtm.090713-1255)        32-bit        ntoskrnl.exe+118c4e        ndis.sys+3623        wfplwf.sys+1ab8        ndis.sys+31b4                C:\Windows\Minidump\120813-18265-01.dmp        2        15        7601        143.096        08.12.2013 13:51:06


schrauber 13.12.2013 08:59

Zitat:

habeDir nach Deiner Aufforderung direkt ne PM hinterlassen.
Irgendwie reden wir aneinander vorbei.

Ich kann auf Arbeit keine Anhänge laden, öffnen, oder Dumps analysieren. Wenn Du mir direkt ne PM schickst bringt das gar nichts. Ich seh erst von wem sie ist und was drin steht, wenn ich sie öffne. Damit ist sie dann gelesen und weg.

Ich brauch eine PM am Nachmittag, wenn ich zu Hause bin. Dann öffne ich die PM, sehe "ahja, da ist noch ein Dump zum analysieren" und mache es direkt.

Sorry, anders geht es nit. Als ich eben das FOrum geöffnet hab hatte ich 137 user die auf Antwort warten (ohne die anderne Foren), ich kann mir das nit alles merken.


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:16 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19