Metaller666 | 27.04.2014 20:06 | Malwarebytes und Adwcleaner wurden - wie im Anfangspost erwähnt - bereits ausgeführt, hier habe ich dir jeweils den Log der ersten und der heutigen Prüfung angehängt.
Malwarebytes (15.04.14): Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.04.2014
Suchlauf-Zeit: 22:26:26
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.15.11
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Metaller666
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 334875
Verstrichene Zeit: 14 Min, 4 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Tiefer Rootkit-Suchlauf: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 12
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, In Quarantäne, [fe027789d62a1de3089af5557b8709f7],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, In Quarantäne, [fe027789d62a1de3089af5557b8709f7],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [1ae6639dfd03c23e505381c9d32f0df3],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [1ae6639dfd03c23e505381c9d32f0df3],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\priam_bho.DLL, In Quarantäne, [9d6312ee6c94c73928cf97fdeb1834cc],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\Wajam, In Quarantäne, [04fce61ad927847c3652bdef9e654ab6],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\priam_bho.DLL, In Quarantäne, [8a76c040c7390ef205f29ff543c0b24e],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\jpmbfleldcgkldadpdinhjjopdfpjfjp, In Quarantäne, [689833cdbf417987b9b31c5857ab7987],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2104731482-4251404017-3914828187-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [3dc38f71e61ab848164c34479b67a35d],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2104731482-4251404017-3914828187-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [768a51af2cd432cec7d6f0a1748f827e],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2104731482-4251404017-3914828187-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [c23eed13e11f669a2c4c5f0af50d5ba5],
PUP.Optional.Wajam.A, HKU\S-1-5-21-2104731482-4251404017-3914828187-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM, In Quarantäne, [cc34de2241bf6f916d8ca2f21ae96799],
Registrierungswerte: 2
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2104731482-4251404017-3914828187-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0Q1O2W1R1D0D1S1J, In Quarantäne, [768a51af2cd432cec7d6f0a1748f827e]
PUP.Optional.Wajam.A, HKU\S-1-5-21-2104731482-4251404017-3914828187-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM|affiliate_id, 6447, In Quarantäne, [cc34de2241bf6f916d8ca2f21ae96799]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 2
PUP.Optional.Wajam.A, C:\Users\Metaller666\AppData\Local\Wajam, In Quarantäne, [c9379070679954ac72df0c54a85ae61a],
PUP.Optional.Wajam.A, C:\Users\Metaller666\AppData\Local\Wajam\Chrome, In Quarantäne, [c9379070679954ac72df0c54a85ae61a],
Dateien: 3
PUP.Optional.Conduit.A, C:\Users\Metaller666\AppData\Roaming\uTorrent\ism.exe, In Quarantäne, [4eb2d92769979e620230cd5242becf31],
PUP.Optional.Iminent.A, C:\Users\Metaller666\AppData\Local\DownloadGuide\Offers\iminent.exe, In Quarantäne, [6898d22e1ce4ce3269b017114bb627d9],
PUP.Optional.Wajam.A, C:\Users\Metaller666\AppData\Local\Wajam\Chrome\wajam.crx, In Quarantäne, [c9379070679954ac72df0c54a85ae61a],
Physische Sektoren: 0
(No malicious items detected)
(end) Malwarebytes (27.04.14): Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.04.2014
Suchlauf-Zeit: 20:35:30
Logdatei: mbam2.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.27.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Metaller666
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 356059
Verstrichene Zeit: 13 Min, 58 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Tiefer Rootkit-Suchlauf: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end) Adwcleaner (16.04.14): Code:
# AdwCleaner v3.023 - Bericht erstellt am 16/04/2014 um 09:37:06
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Metaller666 - METALLER188-PC
# Gestartet von : D:\Downloads\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : SystemStoreService
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Windows\System32\Tasks\Software Updater
Ordner Gefunden C:\ProgramData\boost_interprocess
Ordner Gefunden C:\Users\Metaller666\AppData\Local\DownloadGuide
Ordner Gefunden C:\Users\Metaller666\AppData\Local\Software_Updater
Ordner Gefunden C:\Users\Metaller666\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gefunden C:\Windows\SysWOW64\AI_RecycleBin
Ordner Gefunden E:\Program Files (x86)\Conduit
Ordner Gefunden E:\Program Files (x86)\SoftwareUpdater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\APN PIP
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKCU\Software\Headlight
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : [x64] HKCU\Software\APN PIP
Schlüssel Gefunden : [x64] HKCU\Software\Conduit
Schlüssel Gefunden : [x64] HKCU\Software\Headlight
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\Softonic
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\Freeze.com
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_facebook-messenger-fur-windows_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_facebook-messenger-fur-windows_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\Software\PIP
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\systweak
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v18.0.2 (de)
[ Datei : C:\Users\Metaller666\AppData\Roaming\Mozilla\Firefox\Profiles\lsb27ga5.STandalone\prefs.js ]
[ Datei : C:\Users\Metaller666\AppData\Roaming\Mozilla\Firefox\Profiles\w3kqp5bj.default\prefs.js ]
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [4825 octets] - [16/04/2014 09:37:06]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4885 octets] ########## Adwcleaner (27.04.14) Code:
# AdwCleaner v3.204 - Bericht erstellt am 27/04/2014 um 20:39:40
# Aktualisiert 26/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Metaller666 - METALLER188-PC
# Gestartet von : D:\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Metaller666\.android
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\hempmfkijmahkaddljkmchcmjbojoedl
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C55BBCD6-41AD-48AD-9953-3609C48EACC7}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}]
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Metaller666\AppData\Roaming\Mozilla\Firefox\Profiles\8ozx4akk.Standalone\prefs.js ]
[ Datei : C:\Users\Metaller666\AppData\Roaming\Mozilla\Firefox\Profiles\x25d4xqu.default\prefs.js ]
-\\ Google Chrome v34.0.1847.131
[ Datei : C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [5009 octets] - [16/04/2014 09:37:06]
AdwCleaner[R1].txt - [1182 octets] - [18/04/2014 21:10:18]
AdwCleaner[R2].txt - [1243 octets] - [24/04/2014 18:39:15]
AdwCleaner[R3].txt - [1939 octets] - [27/04/2014 20:38:20]
AdwCleaner[S0].txt - [4839 octets] - [16/04/2014 13:29:00]
AdwCleaner[S1].txt - [1304 octets] - [24/04/2014 18:40:38]
AdwCleaner[S2].txt - [1852 octets] - [27/04/2014 20:39:40]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1912 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Metaller666 on 27.04.2014 at 20:48:41,68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Metaller666\AppData\Roaming\mozilla\firefox\profiles\x25d4xqu.default\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.04.2014 at 20:57:13,27
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 01
Ran by Metaller666 (administrator) on METALLER188-PC on 27-04-2014 20:58:21
Running from D:\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(Sandboxie Holdings, LLC) E:\Program Files\Sandboxie\SbieSvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) E:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) E:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Hewlett-Packard Company) E:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Microsoft Corporation) E:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) E:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) E:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Elgato Systems) E:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe
(Microsoft Corporation) E:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\Metaller666\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Skype Technologies S.A.) E:\Program Files (x86)\Skype\Phone\Skype.exe
(Sandboxie Holdings, LLC) E:\Program Files\Sandboxie\SbieCtrl.exe
() C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\always-on-top.exe
(Microsoft Corporation) E:\Program Files\Windows Media Player\wmpnetwk.exe
(Dropbox, Inc.) C:\Users\Metaller666\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Power Software Ltd) E:\Program Files\PowerISO\PWRISOVM.EXE
(Oracle Corporation) E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(VIA) E:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Beepa P/L) E:\Program Files (x86)\Fraps\fraps.exe
(Mozilla Corporation) E:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Logitech Inc.) E:\Program Files\Logitech\SetPoint II\SetPointII.exe
(Apple Inc.) E:\Program Files\iTunes\iTunesHelper.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastUI.exe
(Logitech, Inc.) E:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
(Advanced Micro Devices Inc.) E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Apple Inc.) E:\Program Files\iPod\bin\iPodService.exe
(Oracle Corporation) E:\Program Files\Java\jre7\bin\java.exe
(Beepa P/L) E:\Program Files (x86)\Fraps\fraps64.dat
(ATI Technologies Inc.) E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Nero AG) E:\Program Files (x86)\Nero\Update\NASvc.exe
(Thisisu) D:\Desktop\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [AdobeCEPServiceManager] => E:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PWRISOVM.EXE] => E:\Program Files\PowerISO\PWRISOVM.EXE [377368 2013-10-23] (Power Software Ltd)
HKLM-x32\...\Run: [SunJavaUpdateSched] => E:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [WD Print Share] => E:\Program Files (x86)\Western Digital\WD Print Share\WDPrintShare.exe [4328448 2012-12-21] ()
HKLM-x32\...\Run: [iTunesHelper] => E:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => E:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-21] (AVAST Software)
HKLM-x32\...\Run: [StartCCC] => E:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-15] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2104731482-4251404017-3914828187-1006\...\Run: [Remote Control Editor] => E:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe [1834496 2012-05-14] (Elgato Systems)
HKU\S-1-5-21-2104731482-4251404017-3914828187-1006\...\Run: [Spotify Web Helper] => C:\Users\Metaller666\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd)
HKU\S-1-5-21-2104731482-4251404017-3914828187-1006\...\Run: [Skype] => E:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2104731482-4251404017-3914828187-1006\...\Run: [SandboxieControl] => E:\Program Files\Sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-2104731482-4251404017-3914828187-1006\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2104731482-4251404017-3914828187-1006\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
IFEO\taskmgr.exe: [Debugger] procexp.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\always-on-top.exe ()
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Metaller666\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fraps.lnk
ShortcutTarget: Fraps.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HD VDeck.lnk
ShortcutTarget: HD VDeck.lnk -> E:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk
ShortcutTarget: Mozilla Thunderbird.lnk -> E:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SetPointII.lnk
ShortcutTarget: SetPointII.lnk -> E:\Program Files\Logitech\SetPoint II\SetPointII.exe (Logitech Inc.)
Startup: C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TV-Browser.lnk
ShortcutTarget: TV-Browser.lnk -> E:\Program Files (x86)\TV-Browser3.3\tvbrowser.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - E:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - E:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: No Name - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - No File
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - E:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - No File
Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - E:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - E:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - E:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - E:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - E:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Metaller666\AppData\Roaming\Mozilla\Firefox\Profiles\8ozx4akk.Standalone
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - E:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - E:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.1 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 - E:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - E:\Program Files (x86)\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - E:\Program Files (x86)\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - E:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - E:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - E:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~3\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - E:\PROGRA~3\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - E:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM - E:\PROGRA~3\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - E:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - E:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - E:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect - E:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File
FF Plugin HKCU: ubisoft.com/uplaypc - E:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Extension: Adblock Plus - C:\Users\Metaller666\AppData\Roaming\Mozilla\Firefox\Profiles\8ozx4akk.Standalone\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-16]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - E:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-21]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Extension: (YouTube) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-26]
CHR Extension: (Google-Suche) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-26]
CHR Extension: (Collusion for Chrome) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\ganlifbpkcplnldliibcbegplfmcfigp [2014-04-26]
CHR Extension: (AdBlock) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-26]
CHR Extension: (Speed Dial 2) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik [2014-04-26]
CHR Extension: (Google Wallet) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-26]
CHR Extension: (YouTube Unblocker) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\npnkeeiehehhefofiekoflfedgehcdhl [2014-04-26]
CHR Extension: (ScriptSafe) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiigbmnaadbkfbmpbfijlflahbdbdgdf [2014-04-26]
CHR Extension: (Google Mail) - C:\Users\Metaller666\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-26]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - E:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-04-21]
==================== Services (Whitelisted) =================
S3 Adobe LM Service; E:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-01-09] (Adobe Systems)
R2 AMD FUEL Service; E:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-15] (Advanced Micro Devices, Inc.)
R2 Apple Mobile Device; E:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [43336 2014-02-12] (Apple Inc.)
R2 avast! Antivirus; E:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-21] (AVAST Software)
S2 AxAutoMntSrv; E:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S2 CLKMSVC10_173EB256; E:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [240112 2010-11-18] (CyberLink)
S3 DAUpdaterSvc; E:\Games\Dragon Age\Dragon Age Origins\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-12-15] (BioWare)
S3 Futuremark SystemInfo Service; E:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2014-01-29] (Futuremark)
S2 gupdate1ce9c1e86dd3230; E:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648 2013-12-06] (Google Inc.)
S3 gupdatem; E:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648 2013-12-06] (Google Inc.)
S3 IDriverT; E:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation)
R3 iPod Service; E:\Program Files\iPod\bin\iPodService.exe [641352 2014-02-21] (Apple Inc.)
R2 LightScribeService; E:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2013-01-16] (Hewlett-Packard Company)
S3 Microsoft SharePoint Workspace Audit Service; E:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation)
S3 MozillaMaintenance; E:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [119408 2014-03-15] (Mozilla Foundation)
R2 NAUpdate; E:\Program Files (x86)\Nero\Update\NASvc.exe [762192 2013-07-18] (Nero AG)
S3 ose; E:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [149352 2010-01-09] (Microsoft Corporation)
R2 osppsvc; E:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [4925184 2010-01-09] (Microsoft Corporation)
R2 SbieSvc; E:\Program Files\Sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC)
S2 SkypeUpdate; E:\Program Files (x86)\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies)
R2 SQLWriter; E:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [129624 2012-02-11] (Microsoft Corporation)
S3 Steam Client Service; E:\Program Files (x86)\Common Files\Steam\SteamService.exe [572096 2014-04-24] (Valve Corporation)
R2 TeamViewer9; E:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [4972864 2014-04-02] (TeamViewer GmbH)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation)
R2 wlidsvc; E:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480 2012-07-17] (Microsoft Corp.)
S2 AIPS; E:\Program Files (x86)\netcut\services\AIPS.exe [X]
S3 rpcapd; "%ProgramFiles(x86)%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles(x86)%\WinPcap\rpcapd.ini" [X]
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.1; E:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 AODDriver4.2.0; E:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 AODDriver4.3; E:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-21] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-04-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-21] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-02-12] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31136 2013-11-23] (REALiX(tm))
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-02-12] ()
R1 networx; C:\Windows\System32\drivers\networx.sys [59384 2014-03-06] (NetFilterSDK.com)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S4 nvoclk64; C:\Windows\System32\DRIVERS\nvoclk64.sys [42088 2009-09-15] (NVIDIA Corp.)
R3 SbieDrv; E:\Program Files\Sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-02-12] (Duplex Secure Ltd.)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [115488 2014-03-26] (Oracle Corporation)
R3 WDUDSMBus; C:\Windows\System32\drivers\WDUDSMBus.sys [106632 2012-06-09] (Windows (R) Codename Longhorn DDK provider)
S3 WDUDSTcpBus; C:\Windows\System32\Drivers\WDUDSTcpBus.sys [180360 2012-06-09] (Windows (R) Codename Longhorn DDK provider)
U3 a9pwv9kl; C:\Windows\System32\Drivers\a9pwv9kl.sys [0 ] (Advanced Micro Devices)
S3 ALSysIO; \??\C:\Users\METALL~4\AppData\Local\Temp\ALSysIO64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
U5 HCWBT8XX; C:\Windows\SysWOW64\Drivers\HCWBT8XX.sys [472644 2006-01-25] (Hauppauge Computer Works)
S4 NVHDA; system32\drivers\nvhda64v.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-27 20:38 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-04-27 14:40 - 2014-04-27 14:40 - 00000000 ___RD () C:\Sandbox
2014-04-27 14:39 - 2014-04-27 14:41 - 00001856 _____ () C:\Windows\Sandboxie.ini
2014-04-27 14:39 - 2014-04-27 14:39 - 00000000 ____D () E:\Program Files\Sandboxie
2014-04-27 14:39 - 2014-04-27 14:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2014-04-27 10:52 - 2014-04-27 11:41 - 00000000 ____D () E:\Program Files (x86)\Tor
2014-04-26 23:34 - 2014-04-26 23:34 - 00035938 _____ () C:\ComboFix.txt
2014-04-26 23:22 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-26 23:22 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-26 23:22 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-26 23:22 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-26 23:22 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-26 23:22 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-26 23:22 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-26 23:22 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-26 23:21 - 2014-04-26 23:34 - 00000000 ____D () C:\Qoobox
2014-04-26 23:21 - 2014-04-26 23:33 - 00000000 ____D () C:\Windows\erdnt
2014-04-26 16:35 - 2014-04-26 16:35 - 00000000 ____D () E:\Program Files (x86)\ESET
2014-04-26 09:40 - 2014-04-27 20:58 - 00000000 ____D () C:\FRST
2014-04-25 14:57 - 2014-04-25 14:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-25 14:57 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-25 14:57 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-24 22:13 - 2014-04-24 22:13 - 00017408 ___SH () C:\Users\Metaller666\Thumbs.db
2014-04-24 14:36 - 2014-04-24 14:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2014-04-22 17:17 - 2014-04-22 17:17 - 00000000 ____D () C:\ProgramData\ATI
2014-04-22 17:10 - 2014-04-22 17:10 - 00067420 _____ () C:\Windows\SysWOW64\CCCInstall_201404221710383312.log
2014-04-22 17:10 - 2014-04-22 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-04-22 16:59 - 2014-04-22 16:59 - 00065920 _____ () C:\Windows\SysWOW64\CCCInstall_201404221659138977.log
2014-04-22 16:46 - 2014-04-22 16:46 - 00066765 _____ () C:\Windows\SysWOW64\CCCInstall_201404221646266389.log
2014-04-22 16:17 - 2014-04-22 16:17 - 00000000 ____D () E:\Program Files (x86)\AMD AVT
2014-04-22 16:12 - 2014-04-22 16:12 - 00000000 ____D () E:\Program Files (x86)\ATI Technologies
2014-04-22 16:10 - 2014-04-22 17:09 - 00000000 ____D () E:\Program Files\ATI Technologies
2014-04-22 15:55 - 2014-04-22 15:55 - 00065920 _____ () C:\Windows\SysWOW64\CCCInstall_201404221555331783.log
2014-04-21 22:26 - 2014-04-21 22:26 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-21 22:26 - 2014-04-21 22:26 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-21 09:26 - 2014-04-21 09:26 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\AVAST Software
2014-04-21 09:25 - 2014-04-26 18:35 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-21 09:25 - 2014-04-21 22:26 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-21 09:25 - 2014-04-21 22:26 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-21 09:25 - 2014-04-21 22:26 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-21 09:25 - 2014-04-21 22:26 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-21 09:25 - 2014-04-21 22:26 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-21 09:25 - 2014-04-21 22:26 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-21 09:25 - 2014-04-21 22:26 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-21 09:25 - 2014-04-21 22:26 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-21 09:25 - 2014-04-21 09:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-04-21 09:24 - 2014-04-21 09:24 - 00000000 ____D () E:\Program Files\AVAST Software
2014-04-20 20:06 - 2014-04-20 20:06 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 20:37 - 2014-04-18 20:37 - 00000000 ____D () E:\Program Files (x86)\VisiPics
2014-04-18 20:37 - 2014-04-18 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VisiPics
2014-04-18 18:22 - 2014-04-18 18:22 - 00000000 _____ () C:\Users\Metaller666\Sti_Trace.log
2014-04-16 19:04 - 2014-04-16 19:04 - 00004224 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log
2014-04-16 19:04 - 2014-03-17 22:11 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-16 19:04 - 2014-03-17 22:02 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-16 19:04 - 2014-03-17 22:02 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-16 19:04 - 2014-03-17 22:02 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-16 14:20 - 2014-04-26 16:56 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-04-16 14:20 - 2014-04-16 14:20 - 00001017 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-16 09:37 - 2014-04-27 20:39 - 00000000 ____D () C:\AdwCleaner
2014-04-16 04:43 - 2014-04-16 04:43 - 10335208 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 08866928 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 08010968 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 07520200 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 06799688 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 06796592 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 01343272 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 01117184 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00127872 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00117584 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00117560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00099520 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2014-04-16 04:39 - 2014-04-16 04:39 - 00274656 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys
2014-04-16 04:37 - 2014-04-16 04:37 - 15376384 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2014-04-16 04:23 - 2014-04-16 04:23 - 28685824 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00231424 _____ () C:\Windows\system32\clinfo.exe
2014-04-16 04:23 - 2014-04-16 04:23 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2014-04-16 04:20 - 2014-04-16 04:20 - 24107520 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2014-04-16 04:17 - 2014-04-16 04:17 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-04-16 04:17 - 2014-04-16 04:17 - 00058880 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-04-16 04:13 - 2014-04-16 04:13 - 05442048 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2014-04-16 04:13 - 2014-04-16 04:13 - 00127488 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2014-04-16 04:13 - 2014-04-16 04:13 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2014-04-16 04:12 - 2014-04-16 04:12 - 27907584 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2014-04-16 03:58 - 2014-04-16 03:58 - 04358656 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2014-04-16 03:51 - 2014-04-16 03:51 - 23409152 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00580816 _____ () C:\Windows\SysWOW64\atiapfxx.blb
2014-04-16 03:46 - 2014-04-16 03:46 - 00580816 _____ () C:\Windows\system32\atiapfxx.blb
2014-04-16 03:46 - 2014-04-16 03:46 - 00368128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2014-04-16 03:46 - 2014-04-16 03:46 - 00091136 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00085504 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2014-04-16 03:42 - 2014-04-16 03:42 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2014-04-16 03:33 - 2014-04-16 03:33 - 00048128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2014-04-16 03:33 - 2014-04-16 03:33 - 00037888 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2014-04-16 03:30 - 2014-04-16 03:30 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2014-04-16 03:29 - 2014-04-16 03:29 - 00586240 _____ (AMD) C:\Windows\system32\atieclxx.exe
2014-04-16 03:29 - 2014-04-16 03:29 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2014-04-16 03:29 - 2014-04-16 03:29 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll
2014-04-16 03:28 - 2014-04-16 03:28 - 03437632 _____ () C:\Windows\system32\atiumd6a.cap
2014-04-16 03:28 - 2014-04-16 03:28 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll
2014-04-16 03:19 - 2014-04-16 03:19 - 00806912 _____ (AMD) C:\Windows\system32\coinst_14.100.dll
2014-04-16 03:17 - 2014-04-16 03:17 - 03471376 _____ () C:\Windows\SysWOW64\atiumdva.cap
2014-04-16 03:08 - 2014-04-16 03:08 - 00848896 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00095744 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00638976 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2014-04-16 03:07 - 2014-04-16 03:07 - 00146944 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00133632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2014-04-16 03:04 - 2014-04-16 03:04 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2014-04-15 22:07 - 2014-04-27 20:19 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-15 22:07 - 2014-04-15 22:07 - 00000000 ____D () E:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-15 22:07 - 2014-04-15 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-15 22:07 - 2014-04-15 22:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-15 22:07 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-15 22:07 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-15 22:07 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-14 21:46 - 2014-04-14 21:46 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-14 20:44 - 2014-04-14 21:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2014-04-13 22:21 - 2014-04-13 22:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-13 22:20 - 2014-04-13 22:21 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-13 22:20 - 2014-04-13 22:20 - 00000000 ____D () E:\Program Files\iPod
2014-04-13 22:18 - 2014-04-13 22:18 - 00000000 ____D () E:\Program Files\Common Files\Apple
2014-04-10 19:58 - 2014-04-10 19:58 - 00082128 _____ () C:\Windows\system32\ativce02.dat
2014-04-09 18:44 - 2014-04-09 18:44 - 00000312 _____ () C:\Users\Metaller666\2014-04-09-16-44-33.043-VBoxSVC.exe-6236.log
2014-04-09 18:30 - 2014-04-09 18:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2014-04-09 18:30 - 2014-03-26 19:01 - 00254240 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2014-04-09 18:30 - 2014-03-26 19:00 - 00128288 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2014-04-08 21:00 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-08 21:00 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-08 21:00 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-08 21:00 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-08 21:00 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-08 21:00 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-08 21:00 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-08 21:00 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-08 21:00 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-08 21:00 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-08 21:00 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-08 21:00 - 2014-02-24 04:35 - 01188864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 12296192 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 09074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 02458112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 01495040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 00735232 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-08 21:00 - 2014-02-24 04:34 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 11020800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 06041088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 02078208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 01232896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 00981504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 00132096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-04-08 21:00 - 2014-02-24 04:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-08 21:00 - 2014-02-24 03:34 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-08 21:00 - 2014-02-24 03:15 - 01638912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-08 21:00 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-08 21:00 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-08 21:00 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-08 21:00 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-08 21:00 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-08 21:00 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-06 23:17 - 2014-04-06 23:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-04-05 12:22 - 2014-04-05 12:22 - 00000000 ____D () E:\Program Files (x86)\FreeMind
2014-04-05 12:22 - 2014-04-05 12:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeMind
2014-04-01 00:06 - 2014-04-01 00:06 - 00234804 _____ () C:\Windows\system32\ativvaxy_cik.dat
2014-04-01 00:04 - 2014-04-01 00:04 - 00233008 _____ () C:\Windows\system32\ativvaxy_cik_nd.dat
2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () E:\Program Files (x86)\Western Digital
2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2014-03-31 17:30 - 2012-06-09 10:24 - 00106632 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\WDUDSMBus.sys
2014-03-31 17:30 - 2012-06-09 10:22 - 00180360 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\WDUDSTcpBus.sys
==================== One Month Modified Files and Folders =======
2014-04-27 20:58 - 2014-04-26 09:40 - 00000000 ____D () C:\FRST
2014-04-27 20:51 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-27 20:51 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-27 20:45 - 2012-07-28 20:48 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Dropbox
2014-04-27 20:43 - 2012-03-25 10:04 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Skype
2014-04-27 20:41 - 2013-08-18 16:23 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-27 20:40 - 2013-04-21 09:03 - 00458044 _____ () C:\Windows\PFRO.log
2014-04-27 20:40 - 2013-04-20 10:08 - 00274378 _____ () C:\Windows\setupact.log
2014-04-27 20:40 - 2013-03-08 22:01 - 01118918 _____ () C:\Windows\WindowsUpdate.log
2014-04-27 20:40 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-27 20:39 - 2014-04-16 09:37 - 00000000 ____D () C:\AdwCleaner
2014-04-27 20:39 - 2012-03-24 17:43 - 00000000 ____D () C:\Users\Metaller666
2014-04-27 20:37 - 2012-04-10 11:34 - 00000000 ____D () C:\Windows\System32\Tasks\TerraTec
2014-04-27 20:31 - 2013-08-18 16:23 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-27 20:19 - 2014-04-15 22:07 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-27 18:01 - 2013-04-28 09:50 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Spotify
2014-04-27 15:07 - 2012-03-26 18:08 - 00000000 ____D () E:\Program Files (x86)\Steam
2014-04-27 14:41 - 2014-04-27 14:39 - 00001856 _____ () C:\Windows\Sandboxie.ini
2014-04-27 14:40 - 2014-04-27 14:40 - 00000000 ___RD () C:\Sandbox
2014-04-27 14:39 - 2014-04-27 14:39 - 00000000 ____D () E:\Program Files\Sandboxie
2014-04-27 14:39 - 2014-04-27 14:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2014-04-27 13:27 - 2013-09-21 14:13 - 00000000 ____D () C:\Users\Metaller666\AppData\Local\Vidalia
2014-04-27 12:31 - 2013-08-21 10:15 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{C79624AB-E946-4E99-B9F8-9FAFB81F6E5E}
2014-04-27 12:02 - 2013-09-21 14:14 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\tor
2014-04-27 11:41 - 2014-04-27 10:52 - 00000000 ____D () E:\Program Files (x86)\Tor
2014-04-27 10:05 - 2013-09-27 20:02 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\TV-Browser
2014-04-26 23:34 - 2014-04-26 23:34 - 00035938 _____ () C:\ComboFix.txt
2014-04-26 23:34 - 2014-04-26 23:21 - 00000000 ____D () C:\Qoobox
2014-04-26 23:33 - 2014-04-26 23:21 - 00000000 ____D () C:\Windows\erdnt
2014-04-26 23:33 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-26 23:08 - 2012-04-15 07:52 - 00000000 ____D () C:\ProgramData\Win7codecs
2014-04-26 22:37 - 2012-03-25 18:18 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Mp3tag
2014-04-26 18:44 - 2014-03-14 17:33 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\MusicBee
2014-04-26 18:35 - 2014-04-21 09:25 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-26 18:31 - 2013-02-03 16:12 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\uTorrent
2014-04-26 16:56 - 2014-04-16 14:20 - 00000000 ____D () E:\Program Files (x86)\Mozilla Firefox
2014-04-26 16:35 - 2014-04-26 16:35 - 00000000 ____D () E:\Program Files (x86)\ESET
2014-04-26 15:56 - 2013-09-04 15:59 - 00000000 ____D () C:\Users\Metaller666\AppData\Local\Adobe
2014-04-26 15:55 - 2012-03-30 19:25 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-26 15:55 - 2012-03-30 19:25 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-25 14:57 - 2014-04-25 14:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-24 22:13 - 2014-04-24 22:13 - 00017408 ___SH () C:\Users\Metaller666\Thumbs.db
2014-04-24 18:41 - 2012-03-25 12:12 - 00000000 ____D () E:\Program Files (x86)\Mp3tag
2014-04-24 15:58 - 2011-04-12 09:43 - 00813034 _____ () C:\Windows\system32\perfh007.dat
2014-04-24 15:58 - 2011-04-12 09:43 - 00189100 _____ () C:\Windows\system32\perfc007.dat
2014-04-24 15:58 - 2009-07-14 07:13 - 01891264 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-24 14:36 - 2014-04-24 14:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2014-04-24 13:41 - 2012-08-16 16:18 - 00000000 ____D () E:\Program Files (x86)\JDownloader
2014-04-22 17:34 - 2013-04-28 09:50 - 00000000 ____D () C:\Users\Metaller666\AppData\Local\Spotify
2014-04-22 17:32 - 2014-01-06 17:51 - 00000000 ____D () C:\Users\DefaultAppPool
2014-04-22 17:32 - 2012-08-04 09:11 - 00000000 ____D () C:\Users\Gast
2014-04-22 17:32 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-04-22 17:17 - 2014-04-22 17:17 - 00000000 ____D () C:\ProgramData\ATI
2014-04-22 17:10 - 2014-04-22 17:10 - 00067420 _____ () C:\Windows\SysWOW64\CCCInstall_201404221710383312.log
2014-04-22 17:10 - 2014-04-22 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-04-22 17:09 - 2014-04-22 16:10 - 00000000 ____D () E:\Program Files\ATI Technologies
2014-04-22 17:09 - 2013-09-29 17:19 - 00000000 ____D () C:\ProgramData\AMD
2014-04-22 16:59 - 2014-04-22 16:59 - 00065920 _____ () C:\Windows\SysWOW64\CCCInstall_201404221659138977.log
2014-04-22 16:46 - 2014-04-22 16:46 - 00066765 _____ () C:\Windows\SysWOW64\CCCInstall_201404221646266389.log
2014-04-22 16:17 - 2014-04-22 16:17 - 00000000 ____D () E:\Program Files (x86)\AMD AVT
2014-04-22 16:12 - 2014-04-22 16:12 - 00000000 ____D () E:\Program Files (x86)\ATI Technologies
2014-04-22 15:55 - 2014-04-22 15:55 - 00065920 _____ () C:\Windows\SysWOW64\CCCInstall_201404221555331783.log
2014-04-21 22:26 - 2014-04-21 22:26 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-21 22:26 - 2014-04-21 22:26 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-21 22:26 - 2014-04-21 09:25 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-21 22:26 - 2014-04-21 09:25 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-21 22:26 - 2014-04-21 09:25 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-21 22:26 - 2014-04-21 09:25 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-21 22:26 - 2014-04-21 09:25 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-21 22:26 - 2014-04-21 09:25 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-21 22:26 - 2014-04-21 09:25 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-21 22:26 - 2014-04-21 09:25 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-21 21:27 - 2013-08-21 22:08 - 00000000 ____D () E:\Program Files\VideoLAN
2014-04-21 20:05 - 2013-09-07 11:00 - 00000132 _____ () C:\Users\Metaller666\AppData\Roaming\Adobe PNG-Format CC - Voreinstellungen
2014-04-21 09:26 - 2014-04-21 09:26 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\AVAST Software
2014-04-21 09:25 - 2014-04-21 09:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-04-21 09:24 - 2014-04-21 09:24 - 00000000 ____D () E:\Program Files\AVAST Software
2014-04-21 09:23 - 2012-03-24 15:17 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-20 20:06 - 2014-04-20 20:06 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 20:37 - 2014-04-18 20:37 - 00000000 ____D () E:\Program Files (x86)\VisiPics
2014-04-18 20:37 - 2014-04-18 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VisiPics
2014-04-18 18:22 - 2014-04-18 18:22 - 00000000 _____ () C:\Users\Metaller666\Sti_Trace.log
2014-04-17 12:28 - 2013-02-08 19:07 - 00000000 ____D () E:\Program Files (x86)\Mozilla Maintenance Service
2014-04-16 23:11 - 2013-12-10 19:03 - 00001018 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-04-16 23:04 - 2012-07-04 22:28 - 00000600 _____ () C:\Users\Metaller666\AppData\Local\PUTTY.RND
2014-04-16 21:34 - 2012-10-02 22:09 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\KeePass
2014-04-16 20:06 - 2012-04-24 16:53 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\TeamViewer
2014-04-16 19:10 - 2013-09-25 20:13 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-16 19:04 - 2014-04-16 19:04 - 00004224 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log
2014-04-16 19:04 - 2013-04-23 18:31 - 00000000 ____D () E:\Program Files (x86)\Java
2014-04-16 14:20 - 2014-04-16 14:20 - 00001017 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-16 14:20 - 2012-03-25 10:54 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Mozilla
2014-04-16 04:43 - 2014-04-16 04:43 - 10335208 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 08866928 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 08010968 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 07520200 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 06799688 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 06796592 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 01343272 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 01117184 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00143304 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00127872 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amdhcp64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00126336 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00117584 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00117560 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amdhcp32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00099520 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00078432 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2014-04-16 04:43 - 2014-04-16 04:43 - 00071704 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2014-04-16 04:39 - 2014-04-16 04:39 - 00274656 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys
2014-04-16 04:37 - 2014-04-16 04:37 - 15376384 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2014-04-16 04:23 - 2014-04-16 04:23 - 28685824 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00231424 _____ () C:\Windows\system32\clinfo.exe
2014-04-16 04:23 - 2014-04-16 04:23 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2014-04-16 04:23 - 2014-04-16 04:23 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2014-04-16 04:20 - 2014-04-16 04:20 - 24107520 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2014-04-16 04:17 - 2014-04-16 04:17 - 00065024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-04-16 04:17 - 2014-04-16 04:17 - 00058880 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-04-16 04:13 - 2014-04-16 04:13 - 05442048 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2014-04-16 04:13 - 2014-04-16 04:13 - 00127488 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2014-04-16 04:13 - 2014-04-16 04:13 - 00113664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2014-04-16 04:12 - 2014-04-16 04:12 - 27907584 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2014-04-16 03:58 - 2014-04-16 03:58 - 04358656 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2014-04-16 03:51 - 2014-04-16 03:51 - 23409152 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 15716352 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00580816 _____ () C:\Windows\SysWOW64\atiapfxx.blb
2014-04-16 03:46 - 2014-04-16 03:46 - 00580816 _____ () C:\Windows\system32\atiapfxx.blb
2014-04-16 03:46 - 2014-04-16 03:46 - 00368128 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2014-04-16 03:46 - 2014-04-16 03:46 - 00091136 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00085504 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00062464 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00055808 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00052224 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2014-04-16 03:46 - 2014-04-16 03:46 - 00049152 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2014-04-16 03:42 - 2014-04-16 03:42 - 14302208 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2014-04-16 03:33 - 2014-04-16 03:33 - 00048128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2014-04-16 03:33 - 2014-04-16 03:33 - 00037888 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2014-04-16 03:30 - 2014-04-16 03:30 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2014-04-16 03:29 - 2014-04-16 03:29 - 00586240 _____ (AMD) C:\Windows\system32\atieclxx.exe
2014-04-16 03:29 - 2014-04-16 03:29 - 00239616 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2014-04-16 03:29 - 2014-04-16 03:29 - 00031232 _____ (AMD) C:\Windows\system32\atimuixx.dll
2014-04-16 03:28 - 2014-04-16 03:28 - 03437632 _____ () C:\Windows\system32\atiumd6a.cap
2014-04-16 03:28 - 2014-04-16 03:28 - 00190976 _____ (AMD) C:\Windows\system32\atitmm64.dll
2014-04-16 03:19 - 2014-04-16 03:19 - 00806912 _____ (AMD) C:\Windows\system32\coinst_14.100.dll
2014-04-16 03:17 - 2014-04-16 03:17 - 03471376 _____ () C:\Windows\SysWOW64\atiumdva.cap
2014-04-16 03:09 - 2014-02-24 04:28 - 01177600 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00848896 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00095744 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdave64.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00090112 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdave32.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00089088 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atisamu64.dll
2014-04-16 03:08 - 2014-04-16 03:08 - 00080896 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atisamu32.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00638976 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2014-04-16 03:07 - 2014-04-16 03:07 - 00146944 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00133632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00075264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2014-04-16 03:07 - 2014-04-16 03:07 - 00069632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2014-04-16 03:04 - 2014-04-16 03:04 - 00043520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2014-04-15 22:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas
2014-04-15 22:07 - 2014-04-15 22:07 - 00000000 ____D () E:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-15 22:07 - 2014-04-15 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-15 22:07 - 2014-04-15 22:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-15 15:07 - 2013-09-04 20:13 - 00001456 _____ () C:\Users\Metaller666\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2014-04-15 14:39 - 2012-04-13 14:34 - 00000000 ____D () C:\Users\Metaller666\.VirtualBox
2014-04-15 12:17 - 2013-06-09 09:37 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Opera Software
2014-04-15 12:14 - 2012-07-19 18:01 - 00000000 ____D () E:\Program Files (x86)\Firefox Nightly
2014-04-15 12:12 - 2013-05-29 09:10 - 00000000 ____D () E:\Program Files (x86)\Opera Next
2014-04-15 12:11 - 2013-12-06 21:33 - 00000000 ____D () E:\Program Files (x86)\Opera Developer
2014-04-14 21:52 - 2014-04-14 20:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2014-04-14 21:46 - 2014-04-14 21:46 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-14 21:46 - 2013-11-13 12:50 - 00001251 _____ () C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-04-14 21:46 - 2013-11-13 11:35 - 00001273 _____ () C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-14 21:46 - 2012-09-10 20:55 - 00000000 ____D () C:\Users\Metaller666\AppData\Local\Opera
2014-04-14 04:24 - 2014-04-25 14:57 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-25 14:57 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-13 22:21 - 2014-04-13 22:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-13 22:21 - 2014-04-13 22:20 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-13 22:21 - 2013-09-19 21:21 - 00000000 ____D () E:\Program Files\iTunes
2014-04-13 22:20 - 2014-04-13 22:20 - 00000000 ____D () E:\Program Files\iPod
2014-04-13 22:18 - 2014-04-13 22:18 - 00000000 ____D () E:\Program Files\Common Files\Apple
2014-04-13 22:06 - 2012-03-24 15:46 - 00000000 ____D () C:\ProgramData\Apple
2014-04-10 19:58 - 2014-04-10 19:58 - 00082128 _____ () C:\Windows\system32\ativce02.dat
2014-04-09 18:44 - 2014-04-09 18:44 - 00000312 _____ () C:\Users\Metaller666\2014-04-09-16-44-33.043-VBoxSVC.exe-6236.log
2014-04-09 18:30 - 2014-04-09 18:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2014-04-09 16:43 - 2013-05-22 18:25 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\Foxit Software
2014-04-08 22:22 - 2013-11-13 10:17 - 00000000 ____D () C:\Windows\rescache
2014-04-08 21:13 - 2012-04-23 16:14 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-08 21:12 - 2013-07-27 12:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-08 21:03 - 2012-03-24 18:56 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-07 17:55 - 2013-09-26 14:36 - 00000000 ____D () E:\Program Files (x86)\SEE Electrical Schulversion V5
2014-04-07 17:54 - 2013-09-27 21:16 - 00001276 _____ () C:\ProgramData\CADdy++1100.ini
2014-04-07 17:54 - 2013-09-27 21:16 - 00001276 _____ () C:\ProgramData\CADdy++1010.ini
2014-04-07 17:54 - 2013-09-27 21:16 - 00001276 _____ () C:\ProgramData\CADdy++1000.ini
2014-04-06 23:17 - 2014-04-06 23:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-04-06 13:30 - 2012-03-24 17:58 - 00000000 ___HD () E:\Program Files (x86)\InstallShield Installation Information
2014-04-06 13:30 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-04-05 14:44 - 2013-02-08 18:44 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-04-05 13:33 - 2013-09-27 20:01 - 00000000 ____D () E:\Program Files (x86)\TV-Browser3.3
2014-04-05 12:22 - 2014-04-05 12:22 - 00000000 ____D () E:\Program Files (x86)\FreeMind
2014-04-05 12:22 - 2014-04-05 12:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeMind
2014-04-04 21:34 - 2013-02-08 18:40 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-04-03 09:51 - 2014-04-15 22:07 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-15 22:07 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-15 22:07 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 21:22 - 2012-09-26 20:20 - 00000000 ____D () C:\Users\Metaller666\AppData\Roaming\FileZilla
2014-04-02 21:18 - 2012-12-12 21:28 - 00000000 ___RD () C:\Users\Metaller666\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-02 16:33 - 2012-03-28 20:18 - 00000000 ____D () E:\Program Files (x86)\phase5
2014-04-01 00:06 - 2014-04-01 00:06 - 00234804 _____ () C:\Windows\system32\ativvaxy_cik.dat
2014-04-01 00:04 - 2014-04-01 00:04 - 00233008 _____ () C:\Windows\system32\ativvaxy_cik_nd.dat
2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () E:\Program Files (x86)\Western Digital
2014-03-31 17:30 - 2014-03-31 17:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2014-03-29 11:26 - 2013-08-18 16:23 - 00004116 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-29 11:26 - 2013-08-18 16:23 - 00003864 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-29 11:14 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-29 11:13 - 2012-04-28 14:16 - 00000000 ____D () E:\Program Files (x86)\Synchredible
2014-03-28 20:15 - 2012-12-01 22:41 - 00000000 ____D () C:\Users\Metaller666\AppData\Local\My Games
Some content of TEMP:
====================
C:\Users\Metaller666\AppData\Local\Temp\procexp64.exe
C:\Users\Metaller666\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-19 16:06
==================== End Of Log ============================ --- --- --- |