Hallo und Danke für deine Hilfe. Ich poste hier mal die Logs, welche ich im Anhang hatte. Alles andere kann ich dann erst heute Abend machen. Malewarebytes und Adware-Cleaner hatte ich die Funde bereits entfernen lassen. Die Logs waren vor der Entfernung. Bei den Logs danach war es sauber.
Hier also meine Anhänge als Code-Block. Alles weitere (auch da frische FRST) wie gesagt dann heute Abend. Danke!
Hier Gmer, dass nach der Entfernung von Malewarebytes und Adware-Cleaner ausgeführt wurde. Danach wurde nichts mehr gemacht. Code:
GMER Logfile:
Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-02-06 01:04:18
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003e Samsung_SSD_840_EVO_250GB rev.EXT0BB0Q 232,89GB
Running: Gmer-19357.exe; Driver: C:\Users\Togge\AppData\Local\Temp\uglcipod.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960000c1700 15 bytes [00, EA, 0F, 02, 00, 7F, 6F, ...]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff960000c1710 11 bytes [00, 1F, FC, FF, 80, 52, DE, ...]
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\dwm.exe[632] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffff8dc169a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\system32\dwm.exe[632] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffff8dc16a2 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\system32\dwm.exe[632] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffff8dc181a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\system32\dwm.exe[632] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffff8dc1832 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[780] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffff8dc169a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[780] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffff8dc16a2 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[780] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffff8dc181a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\system32\nvvsvc.exe[780] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffff8dc1832 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1564] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffff8dc169a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1564] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffff8dc16a2 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1564] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffff8dc181a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\System32\spoolsv.exe[1564] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffff8dc1832 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe[2084] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffff8dc169a 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe[2084] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffff8dc16a2 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe[2084] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffff8dc181a 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe[2084] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffff8dc1832 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2112] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffff8dc169a 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2112] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffff8dc16a2 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2112] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ffff8dc181a 4 bytes [DC, F8, FF, 7F]
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2112] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ffff8dc1832 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\Explorer.EXE[3620] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffff8dc169a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\Explorer.EXE[3620] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffff8dc16a2 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\Explorer.EXE[3620] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffff8dc181a 4 bytes [DC, F8, FF, 7F]
.text C:\WINDOWS\Explorer.EXE[3620] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffff8dc1832 4 bytes [DC, F8, FF, 7F]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [744:768] fffff960009a24d0
Thread C:\WINDOWS\system32\svchost.exe [1596:2892] 00007fffecf71584
Thread C:\WINDOWS\system32\svchost.exe [1596:2872] 00007fffece51b30
Thread C:\WINDOWS\system32\svchost.exe [1596:4076] 00007fffe8e04608
Thread C:\WINDOWS\system32\svchost.exe [1596:3264] 00007fffe8e01040
Thread C:\WINDOWS\Explorer.EXE [3620:3344] 00007fffe45cd6bc
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemStartTime 0xE8 0x51 0x4A 0xB1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemLastStartTime 0x35 0x4D 0x07 0x83 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData\BootLanguages@de-DE 56
Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\ACI24A3D4LMQS074337_10_07DD_2E^2FA938F23C9EDAD985BA6AB0B34E2ED6@Timestamp 0x02 0xCB 0xC7 0xB1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 784
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{9BEC4EAC-1C04-4262-B52B-9731EDA609B8}\Connection@Name isatap.fritz.box
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{FACE3870-21F4-4E72-B69E-48F2A1BBCD83}\Connection@Name isatap.{1AC6C65D-51D5-4410-A72A-4F9C16B2C0E7}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Executive@UuidSequenceNumber 4521642
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed 1564673931
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 59
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 403648031
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 12504
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 11802
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID 71f953a0-1d59-46d1-bf09-f4cfbb8
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AITEventLog@FileCounter 2
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SQMLogger@FileCounter 9
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog@FileCounter 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\Probe\{bb220563-15ab-4915-bb3b-39bdea2e5dc4}@LastProbeTime 1391646394
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{9BEC4EAC-1C04-4262-B52B-9731EDA609B8}@InterfaceName isatap.fritz.box
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{9BEC4EAC-1C04-4262-B52B-9731EDA609B8}@DefunctTimestamp 0xA5 0xC8 0xF2 0x52 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{FACE3870-21F4-4E72-B69E-48F2A1BBCD83}@InterfaceName isatap.{1AC6C65D-51D5-4410-A72A-4F9C16B2C0E7}
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{FACE3870-21F4-4E72-B69E-48F2A1BBCD83}@ReusableType 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{FACE3870-21F4-4E72-B69E-48F2A1BBCD83}@DefunctTimestamp 0xA5 0xC8 0xF2 0x52 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\rdyboost\Parameters@LastBootPlanUserTime ?Do?, ?Feb ?06 ?14, 12:27:20??????i???????i???????????????i????
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 1928
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 265
Reg HKLM\SYSTEM\CurrentControlSet\Services\srvnet\Parameters@MajorSequence 58
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1EFD1E53-E93F-4F9B-8F07-4F305C5492BF}@LeaseObtainedTime 1391642793
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1EFD1E53-E93F-4F9B-8F07-4F305C5492BF}@T1 1392074793
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1EFD1E53-E93F-4F9B-8F07-4F305C5492BF}@T2 1392398793
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1EFD1E53-E93F-4F9B-8F07-4F305C5492BF}@LeaseTerminatesTime 1392506793
Reg HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters@ServiceDllUnloadOnStop 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shutdown@CleanShutdown 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce@Report C:\AdwCleaner\AdwCleaner[S1].txt
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Store@LastTileRefresh 0x69 0xD0 0xCA 0xF0 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Store\RefreshBannedAppList@BannedAppsLastModified 0x00 0x9D 0x55 0x48 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\UFH\SHC@27 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveSupport\Uninstall LiveSupport.lnk?C:\Program Files (x86)\LiveSupport\unins000.exe??
---- EOF - GMER 2.1 ---- --- --- --- AdwareCleaner nach der Reinigung
AdwCleaner Logfile: Code:
# AdwCleaner v3.018 - Bericht erstellt am 06/02/2014 um 00:20:23
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows 8.1 Pro (64 bits)
# Benutzername : Togge - TOGGE-PC
# Gestartet von : E:\Daten\Togge\Downloads\adwcleaner-3.018.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Togge\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Ordner Gefunden C:\Program Files (x86)\optimizer pro
Ordner Gefunden C:\ProgramData\SpeedyPC Software
Ordner Gefunden C:\Users\Togge\AppData\Roaming\DriverCure
Ordner Gefunden C:\Users\Togge\AppData\Roaming\SpeedyPC Software
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKCU\Software\SpeedyPC Software
Schlüssel Gefunden : [x64] HKCU\Software\SpeedyPC Software
Schlüssel Gefunden : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gefunden : HKLM\Software\SpeedyPC Software
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16384
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Togge\AppData\Roaming\Mozilla\Firefox\Profiles\lvpsugq8.default\prefs.js ]
[ Datei : C:\Users\Carina\AppData\Roaming\Mozilla\Firefox\Profiles\xwohm1gs.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [1644 octets] - [06/02/2014 00:20:23]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1704 octets] ########## --- --- ---
[/CODE]
Malewarebytes nach der Reinigung Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.02.04.01
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16476
Togge :: TOGGE-PC [Administrator]
06.02.2014 00:00:23
mbam-log-2014-02-06 (00-00-23).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|E:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 482250
Laufzeit: 13 Minute(n), 55 Sekunde(n)
Infizierte Speicherprozesse: 1
C:\Program Files\V-bates\ExtensionUpdaterService.exe (PUP.Optional.VbatesHelper.A) -> 2192 -> Löschen bei Neustart.
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 9
HKCR\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} (PUP.Optional.VBates) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} (PUP.Optional.VBates) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} (PUP.Optional.VBates) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Extension.ExtensionHelperObject.1 (PUP.Optional.VBates) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Extension.ExtensionHelperObject (PUP.Optional.VBates) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744} (PUP.Optional.VBates) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SYSTEM\CurrentControlSet\Services\V-bates Updater (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\V-bates (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 2
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744} (PUP.Optional.VBates) -> Daten: C:\Program Files\V-bates\Firefox -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} (PUP.Optional.VBates) -> Daten: -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 13
C:\Program Files\V-bates (PUP.Optional.VbatesHelper.A) -> Löschen bei Neustart.
C:\Program Files\V-bates\Firefox (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\content (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\content\libraries (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\content\resources (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\locale (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\locale\en-US (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\skin (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\defaults (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\defaults\preferences (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\libraries (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\resources (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 26
C:\Program Files\V-bates\Extension32.dll (PUP.Optional.VBates) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Togge\AppData\Local\Temp\bitool.dll (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Togge\AppData\Local\Temp\OptimizerPro.exe (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Togge\AppData\Local\Temp\SSStub_Somo_SpeedyPC.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\source.crx (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\DGChrome.exe (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Extension64.dll (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\ExtensionUpdaterService.exe (PUP.Optional.VbatesHelper.A) -> Löschen bei Neustart.
C:\Program Files\V-bates\InstallerHelper.dll (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\NMHClient.exe (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\NMHClient.json (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\PrefHelper.exe (PUP.Optional.VbatesHelper.A) -> Löschen bei Neustart.
C:\Program Files\V-bates\unins000.dat (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\unins000.exe (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome.manifest (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\icon.png (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\install.rdf (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\content\main.js (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\content\main.xul (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\content\libraries\DataExchangeScript.js (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\content\resources\LocalScript.js (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\locale\en-US\overlay.dtd (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\chrome\skin\overlay.css (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\Firefox\defaults\preferences\defaults.js (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\libraries\DataExchangeScript.js (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files\V-bates\resources\LocalScript.js (PUP.Optional.VbatesHelper.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Okay, das war es. Heute Abend werde ich gleich deine Schritte ausführen und alles posten, was du sehen wolltest. Nochmals Danke.
Gruß Marbuel
Hallo,
hier die gewünschten Logs.
Spyware-Removal: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows 8.1 Pro x64
Ran by MeinName on 06.02.2014 at 20:08:27,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\MeinName\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk"
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\MeinName\AppData\Roaming\mozilla\firefox\profiles\lvpsugq8.default\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.02.2014 at 20:11:11,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frisches FRST
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2014
Ran by MeinName (administrator) on MeinName-PC on 06-02-2014 20:13:58
Running from E:\TrojanerBoard\FRST64
Windows 8.1 Pro (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
() C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Windows\System32\vmms.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MBCfg64] - C:\Windows\system32\MBCfg64.dll [34432 2013-04-23] (Creative Technology Ltd.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506136 2013-12-06] (Realtek Semiconductor)
HKLM-x32\...\Run: [Sound Blaster Cinema] - C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [1047536 2013-11-12] (MSI)
HKLM-x32\...\Run: [Live Update 5] - C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe [315392 2012-01-30] ()
HKLM-x32\...\Run: [CommandCenter] - C:\Program Files (x86)\MSI\CommandCenter\StartCommandCenter.exe [809968 2014-01-07] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF1FF1354CD09CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope {E1B3FD65-C521-4F1B-A773-4D585C717626} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {E1B3FD65-C521-4F1B-A773-4D585C717626} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - DefaultScope {E1B3FD65-C521-4F1B-A773-4D585C717626} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - {E1B3FD65-C521-4F1B-A773-4D585C717626} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: V-bates - {21EAF666-26B3-4a3c-ABD0-CA2F5A326744} - C:\Program Files\V-bates\Extension64.dll No File
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.DLL (Symantec Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coIEPlg.dll (Symantec Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\MeinName\AppData\Roaming\Mozilla\Firefox\Profiles\lvpsugq8.default
FF DefaultSearchEngine: SuchMaschine
FF SearchEngineOrder.1: SuchMaschine
FF SelectedSearchEngine: SuchMaschine
FF Homepage: www.google.de
FF Keyword.URL: hxxp://www.sm.de/?q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.2 - E:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\MeinName\AppData\Roaming\Mozilla\Firefox\Profiles\lvpsugq8.default\searchplugins\search_engine.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DownloadHelper - C:\Users\MeinName\AppData\Roaming\Mozilla\Firefox\Profiles\lvpsugq8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-02-01]
FF HKLM\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF [2014-01-05]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ []
==================== Services (Whitelisted) =================
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2014-02-05] (Microsoft Corporation)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [14760 2013-01-01] (Microsoft Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-01] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-17] (Intel Corporation)
S3 MSIBIOSData_CC; C:\Program Files (x86)\MSI\CommandCenter\BIOSData\MSIBIOSDataService.exe [2100736 2013-09-11] (MSI)
S3 MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\MSIClockService.exe [309248 2013-11-04] ()
S3 MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\MSICommService.exe [2114560 2013-09-12] ()
S3 MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\MSICPUService.exe [4110848 2013-12-31] ()
R2 MSICTL_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIControlService.exe [1985536 2013-12-11] ()
S3 MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\MSIDDRService.exe [2224640 2013-09-11] ()
S3 MSISaveLoad_CC; C:\Program Files (x86)\MSI\CommandCenter\MSISaveLoadService.exe [3957248 2013-07-18] ()
S3 MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\MSISMBService.exe [175616 2013-12-16] ()
S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\MSISuperIOService.exe [529920 2013-12-16] ()
S3 MSIWMI_CC; C:\Program Files (x86)\MSI\CommandCenter\MSIWMIService.exe [182784 2013-11-26] ()
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161776 2013-09-09] (MSI)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-09-11] (Qualcomm Atheros)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation)
R2 vmms; C:\Windows\system32\vmms.exe [13368832 2014-02-05] (Microsoft Corporation)
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [75056 2013-02-13] (Qualcomm Atheros, Inc.)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140121.001\BHDrvx64.sys [1526488 2013-12-18] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2014-01-04] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2014-01-04] (Symantec Corporation)
R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [68960 2014-02-05] (Microsoft Corporation)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140205.001\IDSvia64.sys [521944 2014-01-21] (Symantec Corporation)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21408 2013-08-01] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21920 2013-08-01] ()
R3 INETMON; C:\WINDOWS\System32\Drivers\INETMON.sys [29088 2013-08-01] ()
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-01-06] (Microsoft Corporation)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-03-14] ()
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-11-14] (Microsoft Corporation)
R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [19456 2014-02-05] (Microsoft Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-17] (Intel Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140204.024\ENG64.SYS [126040 2014-01-04] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140204.024\EX64.SYS [2099288 2014-01-04] (Symantec Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
S3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\CommandCenter\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
R3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\CommandCenter\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\CommandCenter\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\CommandCenter\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\CommandCenter\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
R3 NTIOLib_MSISuperIO_CC; C:\Program Files (x86)\MSI\CommandCenter\SuperIO\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [22016 2014-02-05] (Microsoft Corporation)
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [27136 2014-02-05] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-01-06] (Microsoft Corporation)
R3 SRTSP; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NISx64\1501000.012\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-01-05] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\system32\drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [19456 2014-02-05] (Microsoft Corporation)
R3 VMSMP; C:\Windows\system32\DRIVERS\vmswitch.sys [686080 2013-11-14] (Microsoft Corporation)
S3 VMSP; C:\Windows\system32\DRIVERS\vmswitch.sys [686080 2013-11-14] (Microsoft Corporation)
S3 VMSVSF; C:\Windows\system32\DRIVERS\vmswitch.sys [686080 2013-11-14] (Microsoft Corporation)
S3 VMSVSP; C:\Windows\system32\DRIVERS\vmswitch.sys [686080 2013-11-14] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-06 20:11 - 2014-02-06 20:11 - 00000892 _____ () C:\Users\MeinName\Desktop\JRT.txt
2014-02-06 20:08 - 2014-02-06 20:08 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-02-06 02:11 - 2014-02-06 02:11 - 00000000 ____D () C:\Users\MeinName\AppData\Local\Intel_Corporation
2014-02-06 01:59 - 2014-02-06 01:59 - 00399136 _____ () C:\WINDOWS\Minidump\020614-4656-01.dmp
2014-02-06 00:44 - 2014-02-06 20:13 - 00000000 ____D () C:\FRST
2014-02-06 00:36 - 2014-02-06 00:36 - 00000000 _____ () C:\Users\MeinName\defogger_reenable
2014-02-06 00:20 - 2014-02-06 00:30 - 00000000 ____D () C:\AdwCleaner
2014-02-05 23:48 - 2014-02-06 20:05 - 27590656 _____ () C:\WINDOWS\system32\vmguest.iso
2014-02-05 23:47 - 2014-02-05 23:47 - 00000000 ____D () C:\WINDOWS\vmguest
2014-02-05 23:47 - 2014-02-05 23:47 - 00000000 ____D () C:\WINDOWS\system32\BestPractices
2014-02-05 23:47 - 2014-02-05 23:47 - 00000000 ____D () C:\Program Files\Hyper-V
2014-02-05 23:43 - 2014-02-06 20:13 - 00000300 _____ () C:\WINDOWS\Tasks\FF Watcher {9A61AA10-C90C-43C4-B2FC-1D863CBA815E}.job
2014-02-05 23:43 - 2014-02-05 23:43 - 00003246 _____ () C:\WINDOWS\System32\Tasks\FF Watcher {9A61AA10-C90C-43C4-B2FC-1D863CBA815E}
2014-02-05 23:39 - 2014-02-05 23:39 - 13368832 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmms.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 06172672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwp.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 02159616 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdp4vs.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 01466522 _____ () C:\WINDOWS\system32\WindowsVirtualization.V2.mof
2014-02-05 23:39 - 2014-02-05 23:39 - 01427296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 01386336 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 01379680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2014-02-05 23:39 - 2014-02-05 23:39 - 01252192 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 00705024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wnv.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmconnect.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmprox.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\synthnic.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00398336 _____ (Microsoft Corporation) C:\WINDOWS\system32\vsconfig.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmulatedNic.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\synthstor.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\synthfcvdev.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteFileBrowse.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmickvpexchange.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicshutdown.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicvss.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicrdv.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00144967 _____ () C:\WINDOWS\system32\virtmgmt.msc
2014-02-05 23:39 - 2014-02-05 23:39 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicheartbeat.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicguestinterface.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmictimesync.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbusvdev.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00068960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wnvapi.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwpctrl.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdvGpuInfo.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00039739 _____ () C:\WINDOWS\system32\hypervisor.mof
2014-02-05 23:39 - 2014-02-05 23:39 - 00033280 _____ () C:\WINDOWS\system32\ActivationVdev.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\HyperVSysprepProvider.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pvhdparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\passthruparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\lunparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00014688 _____ () C:\WINDOWS\system32\sbresources.dll
2014-02-05 23:33 - 2014-02-05 23:33 - 00000727 _____ () C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2014-02-05 23:23 - 2014-02-05 23:23 - 00000000 ____D () C:\WINDOWS\SysWOW64\Visual Studio 2013
2014-02-05 23:23 - 2014-02-05 23:23 - 00000000 ____D () C:\Program Files (x86)\Windows Phone Kits
2014-02-05 23:22 - 2014-02-05 23:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft XDE
2014-02-05 23:20 - 2014-02-05 23:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files\Windows Identity Foundation
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files\Microsoft Identity Extensions
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Workflow Manager Tools
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Open XML SDK
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-02-05 23:18 - 2014-02-05 23:18 - 00000000 ____D () C:\Program Files\Application Verifier
2014-02-05 23:18 - 2014-02-05 23:18 - 00000000 ____D () C:\Program Files (x86)\Application Verifier
2014-02-05 23:17 - 2014-02-05 23:17 - 00000000 ____D () C:\ProgramData\Windows App Certification Kit
2014-02-05 23:12 - 2014-02-05 23:12 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
2014-02-05 23:10 - 2014-02-05 23:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-02-05 23:10 - 2014-02-05 23:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Web Tools
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\ProgramData\NuGet
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files\IIS Express
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files\IIS
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\NuGet
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\Microsoft WCF Data Services
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\IIS Express
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\IIS
2014-02-05 23:07 - 2014-02-05 23:15 - 00000000 ____D () C:\Program Files (x86)\Windows Kits
2014-02-05 23:04 - 2014-02-05 23:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Help Viewer
2014-02-05 23:04 - 2014-02-05 23:04 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
2014-02-05 23:02 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2014-02-05 23:02 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
2014-02-05 23:02 - 2014-02-05 23:06 - 00000000 ____D () C:\WINDOWS\SysWOW64\1033
2014-02-05 22:52 - 2014-02-05 22:52 - 00000000 ____D () C:\WINDOWS\symbols
2014-02-05 22:51 - 2014-02-05 22:51 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 11.0
2014-02-05 22:50 - 2014-02-05 23:23 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
2014-02-05 22:50 - 2014-02-05 23:21 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 12.0
2014-02-05 22:50 - 2014-02-05 23:02 - 00000000 ____D () C:\WINDOWS\system32\1033
2014-02-05 22:50 - 2014-02-05 22:50 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_SensorsSimulatorDriver_01_11_00.Wdf
2014-02-05 22:50 - 2014-02-05 22:50 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 12.0
2014-02-05 22:48 - 2014-02-05 23:39 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-04 00:50 - 2014-02-04 00:50 - 00001174 _____ () C:\Users\Public\Desktop\CommandCenter.lnk
2014-02-04 00:50 - 2013-02-08 11:04 - 00000000 _____ () C:\RAMDiskImage.img
2014-02-01 01:21 - 2014-02-03 23:11 - 00000000 ____D () C:\Users\MeinName\dwhelper
2014-01-20 00:38 - 2014-01-20 00:38 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_INETMON_01011.Wdf
2014-01-20 00:38 - 2013-08-01 17:01 - 00029088 _____ () C:\WINDOWS\system32\Drivers\INETMON.sys
2014-01-20 00:32 - 2014-01-20 00:37 - 00000000 ____D () C:\Program Files\Intel
2014-01-20 00:32 - 2013-09-17 03:20 - 00016344 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\IntelMEFWVer.dll
2014-01-20 00:29 - 2014-01-20 00:29 - 00000000 ____D () C:\Program Files\Realtek
2014-01-20 00:28 - 2013-12-10 20:20 - 03771352 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2014-01-20 00:28 - 2013-12-10 10:17 - 00693385 _____ () C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2014-01-20 00:28 - 2013-12-09 16:15 - 01998104 _____ (Creative Technology Ltd.) C:\WINDOWS\system32\MBAPO264.dll
2014-01-20 00:28 - 2013-12-09 16:15 - 01727256 _____ (Creative Technology Ltd.) C:\WINDOWS\SysWOW64\MBAPO232.dll
2014-01-20 00:28 - 2013-12-06 17:29 - 00397592 _____ (Creative Technology Ltd.) C:\WINDOWS\system32\MBWrp64.dll
2014-01-20 00:28 - 2013-12-05 20:21 - 00153304 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2014-01-20 00:28 - 2013-12-04 16:27 - 01958616 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2014-01-20 00:28 - 2013-11-26 17:26 - 00618200 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2014-01-20 00:28 - 2013-11-25 15:59 - 02810072 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2014-01-20 00:28 - 2013-11-25 15:59 - 02588888 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkAPO64.dll
2014-01-20 00:28 - 2013-11-14 15:49 - 01286872 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2014-01-20 00:28 - 2013-11-13 18:52 - 01013504 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
2014-01-20 00:28 - 2013-11-13 18:10 - 02103040 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\WavesGUILib64.dll
2014-01-20 00:28 - 2013-11-13 18:07 - 02036992 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioEQ64.dll
2014-01-20 00:28 - 2013-10-28 17:29 - 01021656 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2014-01-20 00:28 - 2013-10-16 03:43 - 00209096 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAC64.dll
2014-01-20 00:28 - 2013-10-11 12:47 - 00113576 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2014-01-20 00:28 - 2013-08-05 18:11 - 02743328 _____ (Fortemedia Corporation) C:\WINDOWS\system32\FMAPO64.dll
2014-01-20 00:28 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\WINDOWS\system32\AERTAR64.dll
2014-01-20 00:28 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2014-01-20 00:28 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2014-01-20 00:28 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2014-01-20 00:28 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2014-01-20 00:28 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2014-01-20 00:28 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2014-01-20 00:28 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2014-01-20 00:28 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2014-01-20 00:28 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2014-01-20 00:28 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\WINDOWS\system32\MaxxAudioAPO20.dll
2014-01-20 00:28 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2014-01-20 00:28 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2014-01-20 00:28 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2014-01-20 00:28 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2014-01-20 00:28 - 2009-11-18 07:12 - 00032344 _____ (Creative Technology Ltd.) C:\WINDOWS\system32\Drivers\MBfilt64.sys
2014-01-20 00:25 - 2014-01-20 00:25 - 00002799 _____ () C:\Users\Public\Desktop\Killer Network Manager.lnk
2014-01-20 00:25 - 2014-01-20 00:25 - 00000000 ____D () C:\ProgramData\Qualcomm
2014-01-20 00:25 - 2014-01-20 00:25 - 00000000 ____D () C:\Program Files\Qualcomm Atheros
2014-01-20 00:17 - 2014-01-20 00:17 - 00000000 ____D () C:\WINDOWS\system32\appmgmt
2014-01-19 23:42 - 2014-01-20 00:24 - 00000000 ____D () C:\ProgramData\Downloaded Installations
2014-01-19 22:11 - 2014-01-20 00:24 - 00000000 _____ () C:\Users\MeinName\AppData\Local\Driver_LOM_8161Present.flag
2014-01-19 22:07 - 2014-01-19 22:07 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2014-01-19 22:07 - 2013-09-17 03:20 - 01795952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
2014-01-19 22:07 - 2013-09-17 03:20 - 00099288 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverx64.sys
2014-01-19 21:59 - 2014-01-19 21:59 - 00002019 _____ () C:\Users\Public\Desktop\Live Update 5.lnk
2014-01-19 21:59 - 2012-08-22 10:19 - 00011832 _____ (Windows (R) Codename Longhorn DDK provider) C:\WINDOWS\acpimof.dll
2014-01-19 21:52 - 2014-01-19 21:52 - 00002075 _____ () C:\Users\Public\Desktop\Super-Charger.lnk
2014-01-19 21:52 - 2014-01-19 21:52 - 00000000 ___HD () C:\SuperChargerProfile
2014-01-19 21:40 - 2014-02-04 01:30 - 00000000 ___HD () C:\MSIServiceCfg_CC
2014-01-19 21:40 - 2014-02-04 00:49 - 00000000 ____D () C:\Program Files (x86)\MSI
2014-01-19 20:59 - 2014-01-19 20:59 - 00001117 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-19 20:59 - 2014-01-19 20:59 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\Malwarebytes
2014-01-19 20:59 - 2014-01-19 20:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-19 20:59 - 2014-01-19 20:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-19 20:59 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-01-15 21:52 - 2013-12-09 01:15 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-01-15 21:52 - 2013-11-27 16:36 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2014-01-15 21:52 - 2013-11-27 12:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
2014-01-15 21:52 - 2013-11-27 11:34 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll
2014-01-15 21:52 - 2013-11-27 10:54 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll
2014-01-15 21:52 - 2013-11-27 09:48 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 21:52 - 2013-11-27 09:45 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2014-01-15 21:52 - 2013-11-27 09:40 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 21:52 - 2013-11-27 09:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2014-01-15 21:52 - 2013-11-27 09:17 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-01-15 21:52 - 2013-11-27 09:12 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-01-15 00:01 - 2014-01-21 22:45 - 00002076 _____ () C:\Users\Gast\Desktop\Skyrim (SKSE).lnk
2014-01-15 00:01 - 2014-01-21 22:45 - 00002076 _____ () C:\Users\NameFreundin\Desktop\Skyrim (SKSE).lnk
2014-01-13 19:50 - 2014-01-22 22:29 - 00000000 ____D () C:\ProgramData\Adobe
2014-01-13 19:50 - 2014-01-13 19:50 - 00002039 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-13 19:50 - 2014-01-13 19:50 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-01-13 19:48 - 2014-01-19 12:40 - 00000000 ____D () C:\Users\MeinName\AppData\Local\Adobe
2014-01-13 00:28 - 2014-02-03 01:50 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\vlc
2014-01-13 00:25 - 2014-01-13 00:25 - 00000628 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-01-13 00:16 - 2014-01-13 00:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-01-12 17:39 - 2014-01-12 17:39 - 00000000 ___HD () C:\WINDOWS\system32\CanonIJ Uninstaller Information
2014-01-12 17:39 - 2014-01-12 17:39 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-01-12 17:39 - 2010-08-25 05:00 - 00361472 _____ (CANON INC.) C:\WINDOWS\system32\CNMLMAE.DLL
2014-01-11 19:39 - 2014-01-11 19:39 - 00000000 ____D () C:\Users\Gast\AppData\Local\NVIDIA Corporation
2014-01-11 19:38 - 2014-01-11 19:38 - 00001442 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-11 19:38 - 2014-01-11 19:38 - 00000020 ___SH () C:\Users\Gast\ntuser.ini
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Vorlagen
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Startmenü
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Lokale Einstellungen
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Eigene Dateien
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Anwendungsdaten
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Anwendungsdaten
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\VirtualStore
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\Packages
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\NVIDIA
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast
2014-01-11 19:38 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-01-11 19:38 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-11 19:38 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-01-11 19:38 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-01-11 14:52 - 2014-01-11 14:52 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2014-01-11 14:48 - 2014-01-11 14:48 - 00297392 _____ () C:\WINDOWS\Minidump\011114-3656-01.dmp
2014-01-11 03:24 - 2014-01-11 10:22 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-01-11 03:14 - 2014-02-06 01:59 - 834851538 _____ () C:\WINDOWS\MEMORY.DMP
2014-01-11 03:14 - 2014-02-06 01:59 - 00000000 ____D () C:\WINDOWS\Minidump
2014-01-11 03:14 - 2014-01-11 03:14 - 00297424 _____ () C:\WINDOWS\Minidump\011114-4000-01.dmp
2014-01-10 23:44 - 2014-01-20 00:43 - 00000000 ____D () C:\Users\MeinName\AppData\Local\CrashDumps
2014-01-10 21:40 - 2014-01-12 19:47 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\Awesomium
2014-01-08 20:48 - 2014-02-06 20:08 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{90FE373C-9B29-4A86-912D-D523A98EC8B1}
2014-01-08 19:26 - 2014-01-08 19:26 - 00001274 _____ () C:\Users\MeinName\Desktop\TESO-Launcher.lnk
2014-01-08 19:24 - 2014-01-08 19:24 - 00000000 ____D () C:\ProgramData\Elder Scrolls Online
2014-01-08 19:07 - 2014-01-08 19:07 - 00002145 _____ () C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2014-01-08 19:06 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 15877216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2014-01-08 19:06 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433221.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433221.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 01242400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00168616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2014-01-08 19:06 - 2013-12-19 21:33 - 00141336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2014-01-08 19:06 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2014-01-08 18:56 - 2014-01-08 18:56 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\Macromedia
2014-01-08 18:39 - 2014-01-08 18:39 - 00000000 ____D () C:\Users\NameFreundin\AppData\Roaming\Mozilla
2014-01-08 18:39 - 2014-01-08 18:39 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\Mozilla
2014-01-08 18:36 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2014-01-08 18:36 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2014-01-08 18:36 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2014-01-08 18:36 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2014-01-08 18:36 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2014-01-08 18:36 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2014-01-08 18:36 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2014-01-08 18:36 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2014-01-08 18:36 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2014-01-08 18:36 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2014-01-08 15:51 - 2014-01-08 15:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-01-08 15:50 - 2014-02-02 14:42 - 00003590 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-80106094-910237502-200634186-1002
2014-01-08 15:46 - 2014-02-01 20:47 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C9CAE793-71D4-4381-89E6-BEAF868EC747}
2014-01-08 15:46 - 2014-01-08 15:46 - 00000000 ____D () C:\Users\NameFreundin\AppData\Roaming\Macromedia
2014-01-08 15:46 - 2014-01-08 15:46 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\NVIDIA Corporation
2014-01-08 15:45 - 2014-01-13 21:40 - 00000000 ____D () C:\Users\NameFreundin
2014-01-08 15:45 - 2014-01-11 19:36 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\Packages
2014-01-08 15:45 - 2014-01-08 15:45 - 00001446 _____ () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-08 15:45 - 2014-01-08 15:45 - 00000020 ___SH () C:\Users\NameFreundin\ntuser.ini
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Vorlagen
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Startmenü
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Netzwerkumgebung
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Lokale Einstellungen
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Eigene Dateien
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Druckumgebung
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\AppData\Local\Verlauf
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\AppData\Local\Anwendungsdaten
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Anwendungsdaten
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ___RD () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ___RD () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin\AppData\Roaming\Adobe
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\VirtualStore
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\NVIDIA
2014-01-08 15:45 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-01-08 15:45 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-08 15:45 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-01-08 15:45 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
==================== One Month Modified Files and Folders =======
2014-02-06 20:13 - 2014-02-06 00:44 - 00000000 ____D () C:\FRST
2014-02-06 20:13 - 2014-02-05 23:43 - 00000300 _____ () C:\WINDOWS\Tasks\FF Watcher {9A61AA10-C90C-43C4-B2FC-1D863CBA815E}.job
2014-02-06 20:11 - 2014-02-06 20:11 - 00000892 _____ () C:\Users\MeinName\Desktop\JRT.txt
2014-02-06 20:11 - 2013-11-14 08:26 - 01886824 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-06 20:11 - 2013-11-14 08:11 - 00806122 _____ () C:\WINDOWS\system32\perfh007.dat
2014-02-06 20:11 - 2013-11-14 08:11 - 00176634 _____ () C:\WINDOWS\system32\perfc007.dat
2014-02-06 20:08 - 2014-02-06 20:08 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-02-06 20:08 - 2014-01-08 20:48 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{90FE373C-9B29-4A86-912D-D523A98EC8B1}
2014-02-06 20:07 - 2014-01-06 22:28 - 01255969 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-06 20:05 - 2014-02-05 23:48 - 27590656 _____ () C:\WINDOWS\system32\vmguest.iso
2014-02-06 20:04 - 2014-01-06 22:28 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-06 20:04 - 2013-08-22 15:46 - 00356222 _____ () C:\WINDOWS\setupact.log
2014-02-06 20:04 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-06 02:13 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-02-06 02:11 - 2014-02-06 02:11 - 00000000 ____D () C:\Users\MeinName\AppData\Local\Intel_Corporation
2014-02-06 02:05 - 2014-01-05 04:53 - 00003590 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-80106094-910237502-200634186-1001
2014-02-06 02:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-02-06 01:59 - 2014-02-06 01:59 - 00399136 _____ () C:\WINDOWS\Minidump\020614-4656-01.dmp
2014-02-06 01:59 - 2014-01-11 03:14 - 834851538 _____ () C:\WINDOWS\MEMORY.DMP
2014-02-06 01:59 - 2014-01-11 03:14 - 00000000 ____D () C:\WINDOWS\Minidump
2014-02-06 00:58 - 2014-01-05 05:42 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-02-06 00:36 - 2014-02-06 00:36 - 00000000 _____ () C:\Users\MeinName\defogger_reenable
2014-02-06 00:36 - 2014-01-06 22:29 - 00000000 ____D () C:\Users\MeinName
2014-02-06 00:30 - 2014-02-06 00:20 - 00000000 ____D () C:\AdwCleaner
2014-02-06 00:17 - 2013-11-13 23:18 - 00026676 _____ () C:\WINDOWS\PFRO.log
2014-02-05 23:48 - 2013-08-22 15:44 - 00364096 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-02-05 23:47 - 2014-02-05 23:47 - 00000000 ____D () C:\WINDOWS\vmguest
2014-02-05 23:47 - 2014-02-05 23:47 - 00000000 ____D () C:\WINDOWS\system32\BestPractices
2014-02-05 23:47 - 2014-02-05 23:47 - 00000000 ____D () C:\Program Files\Hyper-V
2014-02-05 23:47 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\schemas
2014-02-05 23:43 - 2014-02-05 23:43 - 00003246 _____ () C:\WINDOWS\System32\Tasks\FF Watcher {9A61AA10-C90C-43C4-B2FC-1D863CBA815E}
2014-02-05 23:39 - 2014-02-05 23:39 - 13368832 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmms.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 06172672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwp.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 02159616 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdp4vs.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 01466522 _____ () C:\WINDOWS\system32\WindowsVirtualization.V2.mof
2014-02-05 23:39 - 2014-02-05 23:39 - 01427296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 01386336 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 01379680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2014-02-05 23:39 - 2014-02-05 23:39 - 01252192 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 00705024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wnv.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmconnect.exe
2014-02-05 23:39 - 2014-02-05 23:39 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmprox.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\synthnic.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00398336 _____ (Microsoft Corporation) C:\WINDOWS\system32\vsconfig.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmulatedNic.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\synthstor.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\synthfcvdev.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteFileBrowse.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmickvpexchange.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicshutdown.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicvss.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicrdv.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00144967 _____ () C:\WINDOWS\system32\virtmgmt.msc
2014-02-05 23:39 - 2014-02-05 23:39 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicheartbeat.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmicguestinterface.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmictimesync.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbusvdev.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00068960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wnvapi.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmwpctrl.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdvGpuInfo.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00039739 _____ () C:\WINDOWS\system32\hypervisor.mof
2014-02-05 23:39 - 2014-02-05 23:39 - 00033280 _____ () C:\WINDOWS\system32\ActivationVdev.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\HyperVSysprepProvider.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pvhdparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\passthruparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2014-02-05 23:39 - 2014-02-05 23:39 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\lunparser.sys
2014-02-05 23:39 - 2014-02-05 23:39 - 00014688 _____ () C:\WINDOWS\system32\sbresources.dll
2014-02-05 23:39 - 2014-02-05 22:48 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-05 23:34 - 2014-01-06 12:18 - 00000000 ____D () C:\Users\MeinName\AppData\Local\Skyrim
2014-02-05 23:33 - 2014-02-05 23:33 - 00000727 _____ () C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2014-02-05 23:33 - 2014-01-06 12:43 - 00000000 ____D () C:\Users\MeinName\AppData\Local\Black_Tree_Gaming
2014-02-05 23:33 - 2014-01-05 01:09 - 00000000 ____D () C:\Spiele
2014-02-05 23:23 - 2014-02-05 23:23 - 00000000 ____D () C:\WINDOWS\SysWOW64\Visual Studio 2013
2014-02-05 23:23 - 2014-02-05 23:23 - 00000000 ____D () C:\Program Files (x86)\Windows Phone Kits
2014-02-05 23:23 - 2014-02-05 22:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
2014-02-05 23:23 - 2014-01-06 22:26 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-02-05 23:22 - 2014-02-05 23:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft XDE
2014-02-05 23:21 - 2014-02-05 22:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 12.0
2014-02-05 23:20 - 2014-02-05 23:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files\Windows Identity Foundation
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files\Microsoft Identity Extensions
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Workflow Manager Tools
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Open XML SDK
2014-02-05 23:19 - 2014-02-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-02-05 23:19 - 2014-02-05 23:02 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2014-02-05 23:19 - 2014-02-05 23:02 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
2014-02-05 23:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-02-05 23:18 - 2014-02-05 23:18 - 00000000 ____D () C:\Program Files\Application Verifier
2014-02-05 23:18 - 2014-02-05 23:18 - 00000000 ____D () C:\Program Files (x86)\Application Verifier
2014-02-05 23:17 - 2014-02-05 23:17 - 00000000 ____D () C:\ProgramData\Windows App Certification Kit
2014-02-05 23:15 - 2014-02-05 23:07 - 00000000 ____D () C:\Program Files (x86)\Windows Kits
2014-02-05 23:12 - 2014-02-05 23:12 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
2014-02-05 23:12 - 2014-01-06 22:26 - 00000000 ____D () C:\Program Files\MSBuild
2014-02-05 23:11 - 2014-02-05 23:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-02-05 23:10 - 2014-02-05 23:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Web Tools
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\ProgramData\NuGet
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files\IIS Express
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files\IIS
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\NuGet
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\Microsoft WCF Data Services
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\IIS Express
2014-02-05 23:09 - 2014-02-05 23:09 - 00000000 ____D () C:\Program Files (x86)\IIS
2014-02-05 23:06 - 2014-02-05 23:02 - 00000000 ____D () C:\WINDOWS\SysWOW64\1033
2014-02-05 23:04 - 2014-02-05 23:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Help Viewer
2014-02-05 23:04 - 2014-02-05 23:04 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
2014-02-05 23:02 - 2014-02-05 22:50 - 00000000 ____D () C:\WINDOWS\system32\1033
2014-02-05 22:52 - 2014-02-05 22:52 - 00000000 ____D () C:\WINDOWS\symbols
2014-02-05 22:51 - 2014-02-05 22:51 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 11.0
2014-02-05 22:50 - 2014-02-05 22:50 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_SensorsSimulatorDriver_01_11_00.Wdf
2014-02-05 22:50 - 2014-02-05 22:50 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 12.0
2014-02-05 21:30 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-02-04 20:58 - 2014-01-05 05:42 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-02-04 01:30 - 2014-01-19 21:40 - 00000000 ___HD () C:\MSIServiceCfg_CC
2014-02-04 00:50 - 2014-02-04 00:50 - 00001174 _____ () C:\Users\Public\Desktop\CommandCenter.lnk
2014-02-04 00:49 - 2014-01-19 21:40 - 00000000 ____D () C:\Program Files (x86)\MSI
2014-02-03 23:11 - 2014-02-01 01:21 - 00000000 ____D () C:\Users\MeinName\dwhelper
2014-02-03 20:19 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-02-03 01:50 - 2014-01-13 00:28 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\vlc
2014-02-02 14:42 - 2014-01-08 15:50 - 00003590 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-80106094-910237502-200634186-1002
2014-02-01 20:47 - 2014-01-08 15:46 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C9CAE793-71D4-4381-89E6-BEAF868EC747}
2014-01-22 22:29 - 2014-01-13 19:50 - 00000000 ____D () C:\ProgramData\Adobe
2014-01-21 22:45 - 2014-01-15 00:01 - 00002076 _____ () C:\Users\Gast\Desktop\Skyrim (SKSE).lnk
2014-01-21 22:45 - 2014-01-15 00:01 - 00002076 _____ () C:\Users\NameFreundin\Desktop\Skyrim (SKSE).lnk
2014-01-21 22:45 - 2014-01-06 19:51 - 00002076 _____ () C:\Users\MeinName\Desktop\Skyrim (SKSE).lnk
2014-01-20 00:43 - 2014-01-10 23:44 - 00000000 ____D () C:\Users\MeinName\AppData\Local\CrashDumps
2014-01-20 00:40 - 2014-01-05 05:03 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-01-20 00:38 - 2014-01-20 00:38 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_INETMON_01011.Wdf
2014-01-20 00:37 - 2014-01-20 00:32 - 00000000 ____D () C:\Program Files\Intel
2014-01-20 00:37 - 2014-01-05 06:50 - 00012986 _____ () C:\WINDOWS\DPINST.LOG
2014-01-20 00:32 - 2014-01-05 06:51 - 00000000 ____D () C:\ProgramData\Intel
2014-01-20 00:29 - 2014-01-20 00:29 - 00000000 ____D () C:\Program Files\Realtek
2014-01-20 00:29 - 2014-01-06 22:28 - 00000000 ____D () C:\WINDOWS\SysWOW64\RTCOM
2014-01-20 00:25 - 2014-01-20 00:25 - 00002799 _____ () C:\Users\Public\Desktop\Killer Network Manager.lnk
2014-01-20 00:25 - 2014-01-20 00:25 - 00000000 ____D () C:\ProgramData\Qualcomm
2014-01-20 00:25 - 2014-01-20 00:25 - 00000000 ____D () C:\Program Files\Qualcomm Atheros
2014-01-20 00:25 - 2014-01-05 05:09 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-01-20 00:24 - 2014-01-19 23:42 - 00000000 ____D () C:\ProgramData\Downloaded Installations
2014-01-20 00:24 - 2014-01-19 22:11 - 00000000 _____ () C:\Users\MeinName\AppData\Local\Driver_LOM_8161Present.flag
2014-01-20 00:22 - 2014-01-05 05:09 - 00000788 _____ () C:\Users\MeinName\AppData\Local\killertool.log
2014-01-20 00:17 - 2014-01-20 00:17 - 00000000 ____D () C:\WINDOWS\system32\appmgmt
2014-01-19 23:46 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-01-19 22:07 - 2014-01-19 22:07 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2014-01-19 21:59 - 2014-01-19 21:59 - 00002019 _____ () C:\Users\Public\Desktop\Live Update 5.lnk
2014-01-19 21:52 - 2014-01-19 21:52 - 00002075 _____ () C:\Users\Public\Desktop\Super-Charger.lnk
2014-01-19 21:52 - 2014-01-19 21:52 - 00000000 ___HD () C:\SuperChargerProfile
2014-01-19 20:59 - 2014-01-19 20:59 - 00001117 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-19 20:59 - 2014-01-19 20:59 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\Malwarebytes
2014-01-19 20:59 - 2014-01-19 20:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-01-19 20:59 - 2014-01-19 20:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-19 12:40 - 2014-01-13 19:48 - 00000000 ____D () C:\Users\MeinName\AppData\Local\Adobe
2014-01-16 01:12 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-01-15 22:27 - 2014-01-06 14:23 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-01-15 22:26 - 2014-01-06 14:22 - 86054176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-13 21:40 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin
2014-01-13 20:05 - 2014-01-05 04:47 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\Adobe
2014-01-13 19:50 - 2014-01-13 19:50 - 00002039 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-01-13 19:50 - 2014-01-13 19:50 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-01-13 00:25 - 2014-01-13 00:25 - 00000628 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-01-13 00:16 - 2014-01-13 00:16 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-01-12 19:47 - 2014-01-10 21:40 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\Awesomium
2014-01-12 17:39 - 2014-01-12 17:39 - 00000000 ___HD () C:\WINDOWS\system32\CanonIJ Uninstaller Information
2014-01-12 17:39 - 2014-01-12 17:39 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-01-11 19:39 - 2014-01-11 19:39 - 00000000 ____D () C:\Users\Gast\AppData\Local\NVIDIA Corporation
2014-01-11 19:38 - 2014-01-11 19:38 - 00001442 _____ () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-11 19:38 - 2014-01-11 19:38 - 00000020 ___SH () C:\Users\Gast\ntuser.ini
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Vorlagen
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Startmenü
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Netzwerkumgebung
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Lokale Einstellungen
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Eigene Dateien
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Druckumgebung
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Verlauf
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\AppData\Local\Anwendungsdaten
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 _SHDL () C:\Users\Gast\Anwendungsdaten
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\VirtualStore
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\Packages
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast\AppData\Local\NVIDIA
2014-01-11 19:38 - 2014-01-11 19:38 - 00000000 ____D () C:\Users\Gast
2014-01-11 19:36 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\Packages
2014-01-11 14:52 - 2014-01-11 14:52 - 00000000 ____D () C:\Users\MeinName\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2014-01-11 14:48 - 2014-01-11 14:48 - 00297392 _____ () C:\WINDOWS\Minidump\011114-3656-01.dmp
2014-01-11 10:22 - 2014-01-11 03:24 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2014-01-11 10:22 - 2014-01-05 04:46 - 00000000 ____D () C:\Users\MeinName\AppData\Local\Packages
2014-01-11 03:24 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-01-11 03:14 - 2014-01-11 03:14 - 00297424 _____ () C:\WINDOWS\Minidump\011114-4000-01.dmp
2014-01-08 19:26 - 2014-01-08 19:26 - 00001274 _____ () C:\Users\MeinName\Desktop\TESO-Launcher.lnk
2014-01-08 19:24 - 2014-01-08 19:24 - 00000000 ____D () C:\ProgramData\Elder Scrolls Online
2014-01-08 19:07 - 2014-01-08 19:07 - 00002145 _____ () C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2014-01-08 19:07 - 2014-01-06 22:28 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-01-08 18:56 - 2014-01-08 18:56 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\Macromedia
2014-01-08 18:39 - 2014-01-08 18:39 - 00000000 ____D () C:\Users\NameFreundin\AppData\Roaming\Mozilla
2014-01-08 18:39 - 2014-01-08 18:39 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\Mozilla
2014-01-08 18:36 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\restore
2014-01-08 16:28 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\LiveKernelReports
2014-01-08 15:51 - 2014-01-08 15:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-01-08 15:46 - 2014-01-08 15:46 - 00000000 ____D () C:\Users\NameFreundin\AppData\Roaming\Macromedia
2014-01-08 15:46 - 2014-01-08 15:46 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\NVIDIA Corporation
2014-01-08 15:45 - 2014-01-08 15:45 - 00001446 _____ () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-08 15:45 - 2014-01-08 15:45 - 00000020 ___SH () C:\Users\NameFreundin\ntuser.ini
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Vorlagen
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Startmenü
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Netzwerkumgebung
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Lokale Einstellungen
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Eigene Dateien
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Druckumgebung
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\AppData\Local\Verlauf
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\AppData\Local\Anwendungsdaten
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 _SHDL () C:\Users\NameFreundin\Anwendungsdaten
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ___RD () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ___RD () C:\Users\NameFreundin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin\AppData\Roaming\Adobe
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\VirtualStore
2014-01-08 15:45 - 2014-01-08 15:45 - 00000000 ____D () C:\Users\NameFreundin\AppData\Local\NVIDIA
2014-01-08 15:45 - 2014-01-05 04:47 - 00000000 ____D () C:\WINDOWS\System32\Tasks\WPD
2014-01-07 19:20 - 2014-01-06 22:27 - 00000000 ___DC () C:\WINDOWS\Panther
Some content of TEMP:
====================
C:\Users\MeinName\AppData\Local\Temp\devcon64.exe
C:\Users\MeinName\AppData\Local\Temp\LiveSupport_setup.exe
C:\Users\MeinName\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\MeinName\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\MeinName\AppData\Local\Temp\nvStInst.exe
C:\Users\MeinName\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\MeinName\AppData\Local\Temp\Quarantine.exe
C:\Users\MeinName\AppData\Local\Temp\sqlite3.exe
C:\Users\MeinName\AppData\Local\Temp\v-bates.exe
C:\Users\MeinName\AppData\Local\Temp\_is10A1.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-01 14:02
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
Gruß Marbuel |