Malware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.05.2014
Suchlauf-Zeit: 17:09:46
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.10.06
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Sören
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 306812
Verstrichene Zeit: 8 Min, 47 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[dde10748e79481b5899ed86a3cc848b8]
Ordner: 0
(No malicious items detected)
Dateien: 2
PUP.Optional.SkyTech.A, C:\Users\Sören\AppData\Local\Temp\3290484\3290484.zip, , [902e2f200a715bdb23f3bb772ad66997],
PUP.Optional.SkyTech.A, C:\Users\Sören\AppData\Local\Temp\3290484\3290484.zipDir\alilog.dll, , [5a64f15e4437a78ff81e71c1c23e817f],
Physische Sektoren: 0
(No malicious items detected)
(end) Junkware Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by S”ren on 10.05.2014 at 15:35:17,77
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\S”ren\AppData\Roaming\mozilla\firefox\profiles\tfitz7bc.default\minidumps [91 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.05.2014 at 15:36:58,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ AdwCleaner Code:
# AdwCleaner v3.207 - Bericht erstellt am 10/05/2014 um 15:38:35
# Aktualisiert 05/05/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Sören - FLOPPAR
# Gestartet von : D:\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\tfitz7bc.default\prefs.js ]
[ Datei : C:\Users\S”ren\AppData\Roaming\Mozilla\Firefox\Profiles\3qbrarwv.default\prefs.js ]
*************************
AdwCleaner[R2].txt - [866 octets] - [10/05/2014 15:17:50]
AdwCleaner[R3].txt - [986 octets] - [10/05/2014 15:38:15]
AdwCleaner[S2].txt - [926 octets] - [10/05/2014 15:18:34]
AdwCleaner[S3].txt - [908 octets] - [10/05/2014 15:38:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [967 octets] ########## FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-05-2014
Ran by Sören (administrator) on FLOPPAR on 10-05-2014 15:40:54
Running from D:\Downloads
Platform: Windows 8.1 (Update 1) (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
() C:\Windows\System32\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\livecomm.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13651672 2013-09-03] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-25] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
HKLM-x32\...\Runonce: [{D48C7D52-8845-4D49-8686-85606831887E}] - cmd.exe /C start /D "C:\Users\SREN~1\AppData\Local\Temp" /B {D48C7D52-8845-4D49-8686-85606831887E}.exe -accepteula -accepteulaksn -activeimages -postboot [X]
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3645720992-1669372208-2754840826-1001\...\Run: [EVEMon] => "C:\Program Files (x86)\EVEMon\EVEMon.exe" -startMinimized
HKU\S-1-5-21-3645720992-1669372208-2754840826-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-3645720992-1669372208-2754840826-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1825984 2014-04-24] (Valve Corporation)
HKU\S-1-5-21-3645720992-1669372208-2754840826-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
Startup: C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\avgnt.exe - Verknüpfung.lnk
ShortcutTarget: avgnt.exe - Verknüpfung.lnk -> C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
Startup: C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x59D10F9E7076CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{03122640-D4C2-4898-901D-19C4BA18A7B0}: [NameServer]192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\tfitz7bc.default
FF Homepage: hxxp://www.spiegel.de/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\tfitz7bc.default\Extensions\ich@maltegoetz.de [2013-12-11]
FF Extension: DownloadHelper - C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\tfitz7bc.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-25]
FF Extension: NoScript - C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\tfitz7bc.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-05-10]
FF Extension: Adblock Plus - C:\Users\Sören\AppData\Roaming\Mozilla\Firefox\Profiles\tfitz7bc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-06]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2014-01-08]
==================== Services (Whitelisted) =================
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [910416 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-12-31] ()
S2 KMService; C:\WINDOWS\SysWOW64\srvany.exe [8192 2014-04-09] ()
S3 NcdAutoSetup; C:\Windows\System32\NcdAutoSetup.dll [0 2013-08-22] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76888 2014-04-12] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [728328 2014-03-31] (DEVGURU Co., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-11-12] (Disc Soft Ltd)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 tap0901_openvpn_accl; C:\Windows\system32\DRIVERS\tap0901_openvpn_accl.sys [37912 2012-08-21] (The OpenVPN Project)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-10 15:16 - 2014-05-10 15:38 - 00000000 ____D () C:\AdwCleaner
2014-05-10 13:46 - 2014-05-10 13:46 - 00000000 ____D () C:\Users\Sören\AppData\Local\Blizzard
2014-05-10 13:42 - 2014-05-10 13:42 - 00000907 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2014-05-10 11:35 - 2014-05-10 11:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-10 10:34 - 2013-08-22 15:25 - 00000824 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.20140510-103428.backup
2014-05-10 10:24 - 2014-05-10 10:24 - 00000318 _____ () C:\Users\Sören\Desktop\Curse Client.appref-ms
2014-05-10 10:24 - 2014-05-10 10:24 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
2014-05-10 01:44 - 2014-05-10 10:31 - 00000000 ____D () C:\Users\Sören\Desktop\Progs
2014-05-10 00:49 - 2014-05-10 00:49 - 00000000 ____D () C:\Users\Sören\Documents\ProcAlyzer Dumps
2014-05-10 00:46 - 2013-08-22 15:25 - 00000824 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.20140510-004650.backup
2014-05-10 00:39 - 2014-05-10 00:43 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-10 00:39 - 2014-05-10 00:40 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-10 00:39 - 2014-05-10 00:39 - 00001407 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-05-10 00:39 - 2014-05-10 00:39 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking
2014-05-10 00:39 - 2014-05-10 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-05-10 00:39 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2014-05-09 22:27 - 2014-05-09 22:27 - 00001517 _____ () C:\Users\Sören\Desktop\Avira.lnk
2014-05-09 17:48 - 2014-05-10 15:16 - 00000000 ____D () C:\Users\Sören\AppData\Local\Deployment
2014-05-09 17:48 - 2014-05-09 17:49 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Curse Advertising
2014-05-09 17:15 - 2014-05-10 15:40 - 00000000 ____D () C:\FRST
2014-05-08 23:16 - 2014-05-08 23:16 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-08 22:57 - 2014-05-08 22:57 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-05-08 22:57 - 2014-05-08 22:57 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-05-08 22:57 - 2014-05-08 22:57 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-05-08 22:57 - 2014-05-08 22:57 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\ProgramData\Sun
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-08 22:48 - 2014-05-10 15:26 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-08 22:47 - 2014-05-08 22:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-08 22:47 - 2014-05-08 22:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-08 22:47 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-05-08 22:47 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-05-08 22:47 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-05-07 19:15 - 2014-05-07 19:15 - 00001000 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2014-05-07 19:15 - 2014-05-07 19:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2014-05-07 19:13 - 2014-05-10 15:14 - 00000000 ____D () C:\Users\Sören\AppData\Local\Battle.net
2014-05-07 19:13 - 2014-05-07 19:14 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Battle.net
2014-05-07 19:13 - 2014-05-07 19:13 - 00000000 ____D () C:\Users\Sören\AppData\Local\Blizzard Entertainment
2014-05-07 19:13 - 2014-05-07 19:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2014-05-07 19:13 - 2014-05-07 19:13 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-05-07 19:12 - 2014-05-10 11:33 - 00000000 ____D () C:\ProgramData\Battle.net
2014-05-06 20:40 - 2014-05-06 20:40 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Avira
2014-05-06 20:40 - 2014-05-06 20:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-06 20:40 - 2014-05-06 20:40 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-06 20:40 - 2014-02-25 11:47 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2014-05-06 20:40 - 2014-02-25 11:47 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2014-05-06 20:40 - 2014-02-25 11:47 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2014-05-06 20:40 - 2014-02-25 11:47 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2014-05-06 19:37 - 2014-05-10 15:39 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-06 19:37 - 2014-05-06 19:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-05-04 09:40 - 2014-05-04 09:40 - 00305232 _____ () C:\WINDOWS\Minidump\050414-62734-01.dmp
2014-05-04 09:40 - 2014-05-04 09:40 - 00000000 ____D () C:\WINDOWS\Minidump
2014-05-04 09:39 - 2014-05-04 09:39 - 566636763 _____ () C:\WINDOWS\MEMORY.DMP
2014-05-03 09:34 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-05-03 09:34 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-05-03 09:33 - 2014-05-03 09:33 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-05-03 09:32 - 2014-05-03 09:32 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-04-28 16:25 - 2014-04-28 16:27 - 00000000 ____D () C:\Trials Fusion
2014-04-28 16:25 - 2014-04-28 16:25 - 00000000 ____D () C:\Users\Sören\Documents\TrialsFusion
2014-04-28 12:26 - 2014-04-28 12:26 - 00000915 _____ () C:\Users\Public\Desktop\Trials Fusion.lnk
2014-04-28 12:26 - 2014-04-28 12:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-04-28 12:21 - 2014-04-28 12:21 - 00000527 _____ () C:\Users\Public\Desktop\LEGO - The Hobbit.lnk
2014-04-27 17:24 - 2014-04-27 17:24 - 00000000 ____D () C:\Program Files\PDFCreator
2014-04-27 17:24 - 2014-04-17 19:36 - 00110776 _____ (pdfforge GmbH) C:\WINDOWS\system32\pdfcmon.dll
2014-04-25 14:02 - 2014-04-26 11:14 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Tropico 5
2014-04-21 03:26 - 2014-04-28 16:25 - 00000000 ____D () C:\Users\Sören\AppData\Local\SKIDROW
2014-04-19 14:27 - 2014-04-19 14:27 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\elsterformular
2014-04-19 14:18 - 2014-04-19 14:22 - 00000000 ____D () C:\ProgramData\elsterformular
2014-04-19 14:18 - 2014-04-19 14:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ElsterFormular
2014-04-19 14:18 - 2014-04-19 14:18 - 00000000 ____D () C:\Program Files (x86)\ElsterFormular
2014-04-18 02:41 - 2014-04-09 14:00 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-04-18 02:41 - 2014-04-09 05:32 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-04-18 02:41 - 2014-04-09 05:31 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-04-18 02:41 - 2014-04-09 05:23 - 01705984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-04-18 02:41 - 2014-04-09 05:21 - 03408896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-04-16 13:59 - 2014-04-18 21:11 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\NCSOFT
2014-04-16 13:59 - 2014-04-18 21:11 - 00000000 ____D () C:\Users\Sören\AppData\Local\NCSOFT
2014-04-12 23:19 - 2014-04-22 13:26 - 00214392 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe
2014-04-12 23:19 - 2014-04-20 22:31 - 00214392 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2014-04-12 23:19 - 2014-04-12 23:19 - 00076888 _____ () C:\WINDOWS\system32\PnkBstrA.exe
==================== One Month Modified Files and Folders =======
2014-05-10 15:40 - 2014-05-09 17:15 - 00000000 ____D () C:\FRST
2014-05-10 15:39 - 2014-05-06 19:37 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-10 15:39 - 2013-12-22 15:32 - 00000000 __RDO () C:\Users\Sören\SkyDrive
2014-05-10 15:39 - 2013-10-18 01:47 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-10 15:39 - 2013-09-29 21:04 - 00776910 _____ () C:\WINDOWS\PFRO.log
2014-05-10 15:39 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-10 15:39 - 2013-04-12 17:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 15:38 - 2014-05-10 15:16 - 00000000 ____D () C:\AdwCleaner
2014-05-10 15:37 - 2013-10-18 01:47 - 01321809 _____ () C:\WINDOWS\WindowsUpdate.log
2014-05-10 15:27 - 2013-04-06 11:20 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3645720992-1669372208-2754840826-1001
2014-05-10 15:26 - 2014-05-08 22:48 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-10 15:26 - 2014-02-15 13:37 - 00098998 _____ () C:\WINDOWS\system32\lvcoinst.log
2014-05-10 15:18 - 2013-08-22 15:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2014-05-10 15:16 - 2014-05-09 17:48 - 00000000 ____D () C:\Users\Sören\AppData\Local\Deployment
2014-05-10 15:15 - 2013-04-06 17:39 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\vlc
2014-05-10 15:14 - 2014-05-07 19:13 - 00000000 ____D () C:\Users\Sören\AppData\Local\Battle.net
2014-05-10 15:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-05-10 14:47 - 2013-04-06 18:47 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-05-10 13:46 - 2014-05-10 13:46 - 00000000 ____D () C:\Users\Sören\AppData\Local\Blizzard
2014-05-10 13:42 - 2014-05-10 13:42 - 00000907 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2014-05-10 12:50 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-05-10 11:35 - 2014-05-10 11:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-10 11:33 - 2014-05-07 19:12 - 00000000 ____D () C:\ProgramData\Battle.net
2014-05-10 10:31 - 2014-05-10 01:44 - 00000000 ____D () C:\Users\Sören\Desktop\Progs
2014-05-10 10:24 - 2014-05-10 10:24 - 00000318 _____ () C:\Users\Sören\Desktop\Curse Client.appref-ms
2014-05-10 10:24 - 2014-05-10 10:24 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
2014-05-10 01:02 - 2013-08-22 05:54 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atl.dll
2014-05-10 00:49 - 2014-05-10 00:49 - 00000000 ____D () C:\Users\Sören\Documents\ProcAlyzer Dumps
2014-05-10 00:43 - 2014-05-10 00:39 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-05-10 00:40 - 2014-05-10 00:39 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-05-10 00:39 - 2014-05-10 00:39 - 00001407 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-05-10 00:39 - 2014-05-10 00:39 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking
2014-05-10 00:39 - 2014-05-10 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-05-09 22:27 - 2014-05-09 22:27 - 00001517 _____ () C:\Users\Sören\Desktop\Avira.lnk
2014-05-09 17:49 - 2014-05-09 17:48 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Curse Advertising
2014-05-09 17:48 - 2013-04-06 11:13 - 00000000 ___RD () C:\Users\Sören\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-08 23:16 - 2014-05-08 23:16 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-08 22:58 - 2013-04-06 19:53 - 00000000 ____D () C:\Users\Sören\AppData\Local\Adobe
2014-05-08 22:57 - 2014-05-08 22:57 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-05-08 22:57 - 2014-05-08 22:57 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-05-08 22:57 - 2014-05-08 22:57 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-05-08 22:57 - 2014-05-08 22:57 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\ProgramData\Sun
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-08 22:57 - 2014-05-08 22:57 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-08 22:47 - 2014-05-08 22:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-08 22:47 - 2014-05-08 22:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-08 20:29 - 2014-03-01 21:47 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Skype
2014-05-07 23:22 - 2013-10-18 02:01 - 00000000 ____D () C:\Users\Sören
2014-05-07 19:15 - 2014-05-07 19:15 - 00001000 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2014-05-07 19:15 - 2014-05-07 19:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2014-05-07 19:14 - 2014-05-07 19:13 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Battle.net
2014-05-07 19:13 - 2014-05-07 19:13 - 00000000 ____D () C:\Users\Sören\AppData\Local\Blizzard Entertainment
2014-05-07 19:13 - 2014-05-07 19:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2014-05-07 19:13 - 2014-05-07 19:13 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-05-06 21:07 - 2013-04-13 12:10 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\TS3Client
2014-05-06 20:40 - 2014-05-06 20:40 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Avira
2014-05-06 20:40 - 2014-05-06 20:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-06 20:40 - 2014-05-06 20:40 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-06 20:40 - 2013-04-06 18:27 - 00000000 ____D () C:\ProgramData\Avira
2014-05-06 19:37 - 2014-05-06 19:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-05-06 19:22 - 2013-04-06 18:43 - 00000000 ____D () C:\ProgramData\Origin
2014-05-06 19:22 - 2013-04-06 18:43 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-05-06 19:00 - 2014-02-15 13:37 - 00000000 ____D () C:\Program Files\Common Files\logishrd
2014-05-06 19:00 - 2013-08-22 16:46 - 00368732 _____ () C:\WINDOWS\setupact.log
2014-05-04 09:40 - 2014-05-04 09:40 - 00305232 _____ () C:\WINDOWS\Minidump\050414-62734-01.dmp
2014-05-04 09:40 - 2014-05-04 09:40 - 00000000 ____D () C:\WINDOWS\Minidump
2014-05-04 09:39 - 2014-05-04 09:39 - 566636763 _____ () C:\WINDOWS\MEMORY.DMP
2014-05-03 22:26 - 2013-09-30 06:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-03 22:26 - 2013-09-30 05:56 - 00764340 _____ () C:\WINDOWS\system32\perfh007.dat
2014-05-03 22:26 - 2013-09-30 05:56 - 00159160 _____ () C:\WINDOWS\system32\perfc007.dat
2014-05-03 09:33 - 2014-05-03 09:33 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-05-03 09:32 - 2014-05-03 09:32 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-04-29 16:01 - 2014-05-03 09:34 - 23547904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-29 14:48 - 2014-05-03 09:34 - 17384448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-04-28 19:47 - 2013-04-06 18:47 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-04-28 16:27 - 2014-04-28 16:25 - 00000000 ____D () C:\Trials Fusion
2014-04-28 16:25 - 2014-04-28 16:25 - 00000000 ____D () C:\Users\Sören\Documents\TrialsFusion
2014-04-28 16:25 - 2014-04-21 03:26 - 00000000 ____D () C:\Users\Sören\AppData\Local\SKIDROW
2014-04-28 12:26 - 2014-04-28 12:26 - 00000915 _____ () C:\Users\Public\Desktop\Trials Fusion.lnk
2014-04-28 12:26 - 2014-04-28 12:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-04-28 12:21 - 2014-04-28 12:21 - 00000527 _____ () C:\Users\Public\Desktop\LEGO - The Hobbit.lnk
2014-04-27 17:24 - 2014-04-27 17:24 - 00000000 ____D () C:\Program Files\PDFCreator
2014-04-27 17:23 - 2014-01-08 15:41 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-04-26 11:14 - 2014-04-25 14:02 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\Tropico 5
2014-04-23 02:24 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-04-23 02:24 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-22 13:26 - 2014-04-12 23:19 - 00214392 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe
2014-04-21 03:54 - 2013-04-06 23:11 - 00000000 ____D () C:\Users\Sören\Documents\My Games
2014-04-20 22:31 - 2014-04-12 23:19 - 00214392 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2014-04-19 15:03 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-04-19 14:27 - 2014-04-19 14:27 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\elsterformular
2014-04-19 14:22 - 2014-04-19 14:18 - 00000000 ____D () C:\ProgramData\elsterformular
2014-04-19 14:18 - 2014-04-19 14:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ElsterFormular
2014-04-19 14:18 - 2014-04-19 14:18 - 00000000 ____D () C:\Program Files (x86)\ElsterFormular
2014-04-18 21:11 - 2014-04-16 13:59 - 00000000 ____D () C:\Users\Sören\AppData\Roaming\NCSOFT
2014-04-18 21:11 - 2014-04-16 13:59 - 00000000 ____D () C:\Users\Sören\AppData\Local\NCSOFT
2014-04-17 19:36 - 2014-04-27 17:24 - 00110776 _____ (pdfforge GmbH) C:\WINDOWS\system32\pdfcmon.dll
2014-04-12 23:19 - 2014-04-12 23:19 - 00076888 _____ () C:\WINDOWS\system32\PnkBstrA.exe
2014-04-12 15:44 - 2013-04-06 11:22 - 00819742 _____ () C:\WINDOWS\DirectX.log
Some content of TEMP:
====================
C:\Users\Sören\AppData\Local\Temp\avgnt.exe
C:\Users\Sören\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-09 17:31
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Ich kriege das Problem jetzt noch vereinzelt als dxdiag.exe - Ungültiges Bild oder wenn ich Curse starte mit Curse - ungültiges Bild und seltener als systeminfo-ungültiges Bild.
Und zwar kriege ich die Fehlermeldungen für die Linkinfo.dll und wbemprox.dll |