Namastente | 29.06.2015 21:46 | Hier kommt FRST Teil 2 Code:
C:\Windows\SysWOW64\credui.dll
2015-06-28 04:32 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2015-06-28 04:32 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2015-06-28 04:31 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-28 04:31 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-28 04:31 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-06-28 04:31 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-06-28 04:31 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2015-06-28 04:31 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2015-06-28 04:31 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-06-28 04:31 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2015-06-28 04:31 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2015-06-28 04:31 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2015-06-28 04:31 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2015-06-28 04:31 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2015-06-28 04:31 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2015-06-28 04:31 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2015-06-28 04:31 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2015-06-28 04:31 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2015-06-28 04:31 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2015-06-28 04:31 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2015-06-28 04:31 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2015-06-28 04:31 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2015-06-28 04:31 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2015-06-28 04:31 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2015-06-28 04:31 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2015-06-28 04:31 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2015-06-28 04:31 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2015-06-28 04:31 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2015-06-28 04:31 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2015-06-28 04:31 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2015-06-28 04:31 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2015-06-28 04:31 - 2013-11-27 03:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2015-06-28 04:31 - 2013-11-27 03:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2015-06-28 04:31 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2015-06-28 04:31 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2015-06-28 04:31 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2015-06-28 04:31 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2015-06-28 04:31 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2015-06-28 04:31 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2015-06-28 04:31 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2015-06-28 04:31 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2015-06-28 04:31 - 2012-11-29 00:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2015-06-28 04:31 - 2012-11-29 00:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2015-06-28 04:31 - 2012-11-29 00:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-06-28 04:31 - 2012-10-03 19:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2015-06-28 04:31 - 2012-10-03 19:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-06-28 04:31 - 2012-10-03 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-06-28 04:31 - 2012-10-03 19:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2015-06-28 04:31 - 2012-10-03 19:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2015-06-28 04:31 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2015-06-28 04:31 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2015-06-28 04:31 - 2012-10-03 18:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2015-06-28 04:31 - 2012-08-22 20:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-06-28 04:31 - 2012-07-04 22:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2015-06-28 04:31 - 2011-03-11 08:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2015-06-28 04:31 - 2011-03-11 08:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2015-06-28 04:31 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2015-06-28 04:31 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2015-06-28 04:30 - 2014-11-11 03:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-06-28 04:30 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2015-06-28 04:30 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2015-06-28 04:30 - 2011-03-03 08:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-06-28 04:30 - 2011-03-03 08:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2015-06-28 04:30 - 2011-03-03 08:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2015-06-28 04:30 - 2011-03-03 07:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2015-06-28 04:30 - 2011-03-03 07:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2015-06-28 04:29 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-06-28 04:29 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-06-28 04:29 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2015-06-28 04:29 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2015-06-28 04:29 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2015-06-28 04:29 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2015-06-28 04:29 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2015-06-28 04:29 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2015-06-28 04:29 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2015-06-28 04:29 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2015-06-28 04:29 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2015-06-28 04:29 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2015-06-28 04:29 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2015-06-28 04:29 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2015-06-28 04:29 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2015-06-28 04:29 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2015-06-28 04:29 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-06-28 04:29 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-06-28 04:29 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-06-28 04:29 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-06-28 04:29 - 2012-11-02 07:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2015-06-28 04:29 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2015-06-28 04:28 - 2012-08-21 23:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2015-06-28 04:27 - 2015-03-10 05:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-06-28 04:27 - 2015-03-10 05:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-06-28 04:27 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-06-28 04:27 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-06-28 04:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-06-28 04:27 - 2014-08-12 04:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2015-06-28 04:27 - 2014-08-12 03:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2015-06-28 04:27 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2015-06-28 04:27 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2015-06-28 04:27 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2015-06-28 04:27 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2015-06-28 04:27 - 2012-12-07 15:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2015-06-28 04:27 - 2012-12-07 15:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2015-06-28 04:27 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2015-06-28 04:27 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2015-06-28 04:27 - 2012-12-07 13:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2015-06-28 04:27 - 2012-12-07 13:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2015-06-28 04:27 - 2012-12-07 13:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2015-06-28 04:27 - 2012-12-07 13:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2015-06-28 04:27 - 2012-12-07 13:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2015-06-28 04:27 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2015-06-28 04:27 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2015-06-28 04:27 - 2012-12-07 13:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2015-06-28 04:27 - 2012-12-07 13:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2015-06-28 04:27 - 2012-12-07 13:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2015-06-28 04:27 - 2012-12-07 13:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2015-06-28 04:27 - 2012-12-07 13:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2015-06-28 04:27 - 2012-12-07 13:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2015-06-28 04:27 - 2012-12-07 13:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2015-06-28 04:27 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2015-06-28 04:27 - 2011-04-29 05:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-06-28 04:27 - 2011-04-29 05:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2015-06-28 04:27 - 2011-04-29 05:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2015-06-28 04:27 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2015-06-28 04:26 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-28 04:26 - 2011-08-17 07:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2015-06-28 04:26 - 2011-08-17 07:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2015-06-28 04:26 - 2011-08-17 06:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2015-06-28 04:26 - 2011-08-17 06:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2015-06-28 04:25 - 2014-11-26 05:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-06-28 04:25 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-06-28 04:24 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-06-28 04:24 - 2015-02-18 09:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-06-28 04:24 - 2014-11-11 05:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2015-06-28 04:24 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2015-06-28 04:24 - 2012-03-17 09:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2015-06-28 04:22 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-28 04:22 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-06-28 04:22 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2015-06-28 04:22 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2015-06-28 04:22 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2015-06-28 04:22 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2015-06-28 04:22 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2015-06-28 04:22 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2015-06-28 04:22 - 2012-09-26 00:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2015-06-28 04:21 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2015-06-28 04:21 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2015-06-28 04:21 - 2011-02-05 19:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2015-06-28 04:21 - 2011-02-05 19:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2015-06-28 04:21 - 2011-02-05 19:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2015-06-28 04:20 - 2015-01-31 05:48 - 01113088 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-06-28 04:20 - 2015-01-31 05:05 - 00162816 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-06-28 04:20 - 2015-01-31 05:04 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-06-28 04:20 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-06-28 04:20 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-06-28 04:20 - 2014-10-30 04:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-06-28 04:20 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2015-06-28 04:20 - 2014-10-04 04:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-06-28 04:20 - 2014-10-04 03:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-06-28 04:20 - 2014-10-04 03:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-06-28 04:20 - 2014-10-03 04:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-06-28 04:20 - 2014-10-03 04:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-06-28 04:20 - 2014-10-03 04:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-06-28 04:20 - 2014-10-03 04:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-06-28 04:20 - 2014-10-03 04:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-06-28 04:20 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-06-28 04:20 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2015-06-28 04:20 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2015-06-28 04:20 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2015-06-28 04:20 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2015-06-28 04:20 - 2014-09-04 07:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2015-06-28 04:20 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2015-06-28 04:20 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2015-06-28 04:20 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2015-06-28 04:20 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2015-06-28 04:20 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2015-06-28 04:20 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2015-06-28 04:20 - 2011-05-24 13:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2015-06-28 04:20 - 2011-05-24 12:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2015-06-28 04:20 - 2011-05-24 12:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2015-06-28 04:20 - 2011-05-24 12:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2015-06-28 04:20 - 2011-05-24 12:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2015-06-28 04:19 - 2015-03-04 06:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-06-28 04:19 - 2015-03-04 06:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-06-28 04:19 - 2015-03-04 06:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-06-28 04:19 - 2015-03-04 06:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-06-28 04:19 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
2015-06-28 04:19 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2015-06-28 04:19 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-06-28 04:19 - 2014-11-08 05:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-06-28 04:19 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-06-28 04:19 - 2014-10-25 03:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2015-06-28 04:19 - 2014-10-25 03:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2015-06-28 04:19 - 2014-07-17 04:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-06-28 04:19 - 2014-07-17 04:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-06-28 04:19 - 2014-07-17 04:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2015-06-28 04:19 - 2014-07-17 04:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2015-06-28 04:19 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2015-06-28 04:19 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2015-06-28 04:19 - 2014-07-17 03:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-06-28 04:19 - 2014-07-17 03:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2015-06-28 04:19 - 2013-02-15 08:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-06-28 04:19 - 2013-02-15 08:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-06-28 04:19 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-06-28 04:19 - 2012-04-26 07:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2015-06-28 04:19 - 2012-04-26 07:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2015-06-28 04:18 - 2012-07-05 00:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2015-06-28 04:18 - 2012-07-05 00:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2015-06-28 04:18 - 2012-07-05 00:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2015-06-28 04:18 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2015-06-28 04:18 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2015-06-28 04:18 - 2011-02-18 12:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2015-06-28 04:18 - 2011-02-18 07:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2015-06-28 04:17 - 2014-12-08 05:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-06-28 04:17 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-06-28 04:17 - 2014-10-14 04:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-06-28 04:17 - 2014-10-14 03:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-06-28 04:17 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-06-28 04:17 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-06-28 04:17 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-06-28 04:17 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-06-28 04:17 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-06-28 04:17 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-06-28 04:17 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2015-06-28 04:17 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2015-06-28 04:17 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2015-06-28 04:17 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2015-06-28 04:17 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2015-06-28 04:17 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2015-06-28 04:17 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2015-06-28 04:17 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2015-06-28 04:17 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2015-06-28 04:17 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2015-06-28 04:17 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2015-06-28 04:17 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2015-06-28 04:17 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-06-28 04:17 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2015-06-28 04:17 - 2011-12-16 10:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2015-06-28 04:17 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2015-06-28 04:17 - 2011-05-03 07:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-28 04:17 - 2011-05-03 06:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-28 04:17 - 2011-02-12 13:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2015-06-28 04:16 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-06-28 04:16 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-06-28 04:16 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-06-28 04:16 - 2012-06-06 08:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2015-06-28 04:16 - 2012-06-06 07:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2015-06-28 04:16 - 2012-05-14 07:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-06-28 04:16 - 2011-10-15 08:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2015-06-28 04:16 - 2011-10-15 07:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2015-06-28 04:16 - 2011-08-27 07:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2015-06-28 04:16 - 2011-08-27 06:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2015-06-28 04:16 - 2011-02-23 06:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2015-06-28 04:15 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-06-28 04:15 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-06-28 04:15 - 2013-10-12 04:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2015-06-28 04:15 - 2013-10-12 04:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-06-28 04:15 - 2013-10-12 04:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2015-06-28 04:15 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2015-06-28 04:15 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2015-06-28 04:15 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2015-06-28 03:51 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-06-28 03:51 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-06-28 03:51 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-06-28 03:47 - 2015-06-28 03:47 - 00000000 ____D C:\Users\Entimate\AppData\Local\NVIDIA Corporation
2015-06-28 03:46 - 2015-06-28 03:46 - 00000000 ____D C:\Users\Entimate\AppData\Local\NVIDIA
2015-06-28 03:43 - 2015-06-29 19:53 - 00000000 ____D C:\ProgramData\NVIDIA
2015-06-28 03:43 - 2015-06-28 03:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-06-28 03:43 - 2015-06-17 11:10 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-06-28 03:43 - 2015-06-17 11:10 - 01571696 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-06-28 03:43 - 2015-06-17 11:10 - 01320304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-06-28 03:43 - 2015-06-17 11:10 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-06-28 03:43 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2015-06-28 03:43 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2015-06-28 03:43 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2015-06-28 03:43 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2015-06-28 03:43 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-06-28 03:43 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2015-06-28 03:42 - 2015-06-28 03:43 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-06-28 03:42 - 2015-06-17 11:10 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-06-28 03:42 - 2015-06-17 11:10 - 00105288 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-06-28 03:42 - 2015-06-17 08:48 - 06873232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-06-28 03:42 - 2015-06-17 08:48 - 03492168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-06-28 03:42 - 2015-06-17 08:48 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-06-28 03:42 - 2015-06-17 08:48 - 00937616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-06-28 03:42 - 2015-06-17 08:48 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-06-28 03:42 - 2015-06-17 08:48 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-06-28 03:42 - 2015-06-17 08:03 - 00571024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-06-28 03:42 - 2015-06-02 16:11 - 04421614 _____ C:\Windows\system32\nvcoproc.bin
2015-06-28 03:41 - 2015-06-28 16:01 - 01591464 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-06-28 03:29 - 2015-06-28 03:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-06-28 03:29 - 2015-06-28 03:29 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-06-28 03:29 - 2015-06-17 11:10 - 42729104 _____ C:\Windows\system32\nvcompiler.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 37748880 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 30481552 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 22947144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 17724600 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 16145200 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 15866992 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 15224784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 14497520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 13263056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 12855416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 11831856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 11011216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-06-28 03:29 - 2015-06-17 11:10 - 03395648 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 02997544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 02932368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 02599752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435330.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 01567576 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 01557832 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435330.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 01099992 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 01060168 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 01050768 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00982672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00975176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00938752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00204648 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-06-28 03:29 - 2015-06-17 11:10 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00061616 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00057520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00046768 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-06-28 03:29 - 2015-06-17 11:10 - 00040280 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-06-28 03:29 - 2015-06-17 11:10 - 00030966 _____ C:\Windows\system32\nvinfo.pb
2015-06-28 03:28 - 2015-06-28 03:43 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-06-28 03:28 - 2015-06-28 03:28 - 00000000 ____D C:\NVIDIA
2015-06-28 03:21 - 2015-06-28 03:21 - 00000000 ____D C:\Users\Entimate\AppData\Roaming\Easeware
2015-06-28 02:53 - 2015-06-28 02:53 - 00000332 _____ C:\Windows\system32\2015-06-28-00-53-43.075-aswFe.exe-4024.log
2015-06-28 02:49 - 2015-06-28 02:49 - 00000000 ____D C:\Windows\SysWOW64\vbox
2015-06-28 02:49 - 2015-06-28 02:49 - 00000000 ____D C:\Windows\system32\vbox
2015-06-28 02:48 - 2015-06-29 18:38 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-06-28 02:48 - 2015-06-28 02:48 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-06-28 02:48 - 2015-06-28 02:48 - 00272248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00065736 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-06-28 02:48 - 2015-06-28 02:48 - 00029168 _____ C:\Windows\system32\Drivers\aswHwid.sys
2015-06-28 02:48 - 2015-06-28 02:48 - 00000000 ____D C:\Users\Entimate\AppData\Roaming\AVAST Software
2015-06-28 02:48 - 2015-06-28 02:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-06-28 02:47 - 2015-06-28 02:47 - 00000000 ____D C:\ProgramData\AVAST Software
2015-06-28 02:47 - 2015-06-28 02:47 - 00000000 ____D C:\Program Files\AVAST Software
2015-06-28 02:44 - 2015-06-29 19:02 - 00000000 ____D C:\Users\Entimate\AppData\Local\Google
2015-06-28 02:44 - 2015-06-29 19:01 - 00000000 ____D C:\Users\Entimate\AppData\Local\Deployment
2015-06-28 02:44 - 2015-06-28 14:06 - 00058016 _____ C:\Users\Entimate\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-28 02:44 - 2015-06-28 02:44 - 00000000 ____D C:\Users\Entimate\AppData\Local\Apps\2.0
2015-06-28 02:36 - 2015-06-29 20:24 - 00000000 ____D C:\Users\Entimate
2015-06-28 02:36 - 2015-06-28 15:35 - 00001417 _____ C:\Users\Entimate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-28 02:36 - 2015-06-28 03:46 - 00000000 ____D C:\Users\Entimate\AppData\Local\VirtualStore
2015-06-28 02:36 - 2015-06-28 02:36 - 00000020 ___SH C:\Users\Entimate\ntuser.ini
2015-06-28 02:36 - 2015-06-28 02:36 - 00000000 __SHD C:\Recovery
2015-06-28 02:36 - 2009-07-14 06:54 - 00000000 ___RD C:\Users\Entimate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-28 02:36 - 2009-07-14 06:49 - 00000000 ___RD C:\Users\Entimate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-06-28 02:34 - 2015-06-29 20:03 - 01612272 _____ C:\Windows\WindowsUpdate.log
2015-06-28 02:34 - 2015-06-28 02:34 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-06-28 02:34 - 2015-06-28 02:34 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-06-28 02:33 - 2015-06-28 02:33 - 00001355 _____ C:\Windows\TSSysprep.log
2015-06-28 02:32 - 2015-06-28 02:32 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-29 20:03 - 2009-07-14 06:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-29 20:03 - 2009-07-14 06:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-29 19:55 - 2009-07-14 06:51 - 00027684 _____ C:\Windows\setupact.log
2015-06-29 19:54 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-29 19:53 - 2010-11-21 05:47 - 00097930 _____ C:\Windows\PFRO.log
2015-06-29 19:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PLA
2015-06-29 18:40 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2015-06-29 00:13 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-06-28 18:59 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-28 17:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\LiveKernelReports
2015-06-28 16:36 - 2010-11-21 05:24 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-06-28 16:36 - 2010-11-21 05:24 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-06-28 16:36 - 2010-11-21 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2015-06-28 16:36 - 2010-11-21 05:24 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2015-06-28 16:36 - 2010-11-21 05:23 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2015-06-28 16:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-06-28 15:54 - 2010-11-21 09:16 - 00000000 ____D C:\Program Files\Windows Journal
2015-06-28 15:54 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\winrm
2015-06-28 15:54 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\WCN
2015-06-28 15:54 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\sysprep
2015-06-28 15:54 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\slmgr
2015-06-28 15:54 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2015-06-28 15:54 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\winrm
2015-06-28 15:54 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\slmgr
2015-06-28 15:54 - 2009-07-14 07:37 - 00000000 ____D C:\Windows\DigitalLocker
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2015-06-28 15:54 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\oobe
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\migwiz
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\IME
2015-06-28 15:54 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-06-28 15:53 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\WCN
2015-06-28 15:53 - 2010-11-21 09:06 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2015-06-28 15:53 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\MUI
2015-06-28 15:53 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Dism
2015-06-28 15:53 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\com
2015-06-28 15:30 - 2009-07-14 06:45 - 00267816 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-28 15:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing
2015-06-28 15:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
2015-06-28 15:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
2015-06-28 15:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK
2015-06-28 15:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR
2015-06-28 15:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
2015-06-28 12:22 - 2009-07-14 07:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
2015-06-28 12:22 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2015-06-28 03:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help
2015-06-28 02:40 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\restore
2015-06-28 02:40 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-28 02:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Recovery
2015-06-28 02:34 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-28 02:34 - 2009-07-14 06:46 - 00002790 _____ C:\Windows\DtcInstall.log
2015-06-28 02:34 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-28 02:31 - 2010-11-21 09:16 - 00000000 ____D C:\Windows\CSC
==================== Files in the root of some directories =======
2010-09-20 00:03 - 2010-09-20 00:03 - 0000000 _____ () C:\Users\Entimate\AppData\Local\{9B4066CC-4818-4C4E-B7E1-3ABB7357FBFB}
Some files in TEMP:
====================
C:\Users\Entimate\AppData\Local\Temp\130799977221365782.exe
C:\Users\Entimate\AppData\Local\Temp\13079997738571148528.exe
C:\Users\Entimate\AppData\Local\Temp\Quarantine.exe
C:\Users\Entimate\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-28 02:31
==================== End of log ============================
Hier kommt Addition (zum FRST)
FRST Additions Logfile: Code:
Additional
FRST Logfile:
Code:
scan result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01
Ran by Entimate at 2015-06-29 20:26:32
Running from C:\Users\Entimate\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1464251018-2182050062-3487427115-500 - Administrator - Disabled)
Entimate (S-1-5-21-1464251018-2182050062-3487427115-1000 - Administrator - Enabled) => C:\Users\Entimate
Guest (S-1-5-21-1464251018-2182050062-3487427115-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1464251018-2182050062-3487427115-1002 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Magicka: Wizard Wars (HKLM-x32\...\Steam App 202090) (Version: - Paradox North)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Metro: Last Light (c) Deep Silver version 1 (HKLM-x32\...\TWV0cm9MYXN0TGlnaHQ=_is1) (Version: 1 - )
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.30 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.5.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.44 - NVIDIA Corporation)
NVIDIA Graphics Driver 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.30 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.5.44 - NVIDIA Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Unturned (HKLM-x32\...\Steam App 304930) (Version: - Nelson Sexton)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
28-06-2015 03:37:39 Windows Update
28-06-2015 03:43:41 Installed DirectX
28-06-2015 04:20:46 Installed 7-Zip 9.20 (x64 edition)
28-06-2015 05:00:02 Windows Update
28-06-2015 11:37:31 Windows Update
28-06-2015 12:29:59 Windows Update
28-06-2015 13:52:15 Windows Update
28-06-2015 15:47:36 Windows Update
28-06-2015 16:34:00 Windows Update
28-06-2015 16:43:41 Windows Update
28-06-2015 17:18:17 Installed Minecraft
28-06-2015 17:21:31 Installed LogMeIn Hamachi
28-06-2015 17:49:02 Removed Java 8 Update 45
28-06-2015 18:19:18 Windows Update
28-06-2015 19:21:09 Removed LogMeIn Hamachi
28-06-2015 21:01:28 DirectX wurde installiert
28-06-2015 21:25:36 DirectX wurde installiert
28-06-2015 21:37:02 Installed Unigine Heaven Benchmark v2.1
28-06-2015 21:46:40 DirectX wurde installiert
28-06-2015 21:57:19 DirectX wurde installiert
28-06-2015 21:58:56 DirectX wurde installiert
28-06-2015 22:14:40 Windows Update
28-06-2015 22:47:45 DirectX wurde installiert
28-06-2015 23:08:50 Windows Update
28-06-2015 23:12:45 Windows Update
28-06-2015 23:40:26 Windows Update
29-06-2015 00:00:42 Removed Unigine Heaven Benchmark v2.1
29-06-2015 00:13:43 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
29-06-2015 00:15:30 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
29-06-2015 00:18:26 DirectX wurde installiert
29-06-2015 01:00:30 Removed Java 8 Update 45 (64-bit)
29-06-2015 01:05:07 Windows Update
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {36C544E8-FE25-4DB1-A13C-4474B3A9AA3E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-29] (Google Inc.)
Task: {43AA6BBE-E901-42B5-889D-35A7BF4BD52A} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2015-06-28] (Microsoft Corporation)
Task: {8D7518DC-D28C-45E1-99AC-D072001D0A8C} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-28] (Avast Software s.r.o.)
Task: {C8F92E53-D63E-4375-B931-A4BA02136A02} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-29] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-06-29 19:02 - 2015-06-20 09:20 - 01670472 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll
2015-06-29 19:02 - 2015-06-20 09:20 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll
2015-06-28 02:48 - 2015-06-28 02:48 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-06-28 02:48 - 2015-06-28 02:48 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-06-29 19:18 - 2015-06-29 19:18 - 02952704 _____ () C:\Program Files\AVAST Software\Avast\defs\15062901\algo.dll
2015-06-28 02:48 - 2015-06-28 02:48 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Entimate\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{2AD468AB-87C2-46BE-AB36-FDEE24BDB236}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{D5CF1A92-E0D9-4661-9BD3-02B4D044B84A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{95F5DB39-FB7C-4C45-8D1A-773C7F0C19B0}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C63A571C-7B84-40BC-B592-88E5E6691C1C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{A0026637-FF93-49A4-9FB3-B8BB5F750409}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{B40F16B1-CD6C-4D75-A2E2-04527356154E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{8C24B4EA-8DAC-474F-9C93-22419CE2D385}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{52A64FC9-5AA6-49EA-A1E0-CFD08AC3F981}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{96153C38-5F9B-4492-897A-D794130C739C}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{74D88428-BBB1-4BE1-9127-5D319A7906FD}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{141018C2-B8EE-46D2-934A-78A7FE8B71FE}] => (Allow) C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
FirewallRules: [{58D7E915-9FDF-4A72-8E8F-D953DC96D3E8}] => (Allow) C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
FirewallRules: [{737774AD-0171-4D76-B679-0811288DF8A4}] => (Allow) C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
FirewallRules: [{8CB3FE37-F0FC-4335-A64F-A20ED086F93C}] => (Allow) C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
FirewallRules: [{3E69A66D-DB19-4848-994F-AA986C85EA09}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3EB28260-4CB7-4B1A-8A2A-32D553B672CC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{415669E0-D676-4B98-AF3F-905FF0136ADF}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{FF1A61EB-DDD4-4BF8-A42A-55D0AE532B33}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{B986D29D-B79D-40CB-BBBB-49991AB8176A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{80484721-DAD4-4C17-B7D4-B506DB8DC77B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C50FACE9-1378-413D-A855-5C51213F0A79}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MagickaWizardWars\WizardWarsLauncher.exe
FirewallRules: [{CB03D615-2FB9-4404-9ACE-7D96BE879D5C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\MagickaWizardWars\WizardWarsLauncher.exe
FirewallRules: [TCP Query User{D7DA27E3-94EC-46C2-AD2A-E7BC4B577668}C:\program files (x86)\jdownloader\jre\bin\javaw.exe] => (Allow) C:\program files (x86)\jdownloader\jre\bin\javaw.exe
FirewallRules: [UDP Query User{BEF9E8C3-0A29-4875-97F9-C7F13DF19C2B}C:\program files (x86)\jdownloader\jre\bin\javaw.exe] => (Allow) C:\program files (x86)\jdownloader\jre\bin\javaw.exe
FirewallRules: [{50CE39FB-D06F-47AF-BB2B-F2D5D8A81976}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/29/2015 07:55:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/29/2015 07:50:56 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
Error: (06/29/2015 07:50:51 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Data.OracleClient, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=x86 . Error code = 0x80070005
Error: (06/29/2015 07:50:50 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
Error: (06/29/2015 07:50:47 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Configuration, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005
Error: (06/29/2015 07:50:46 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Xml, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
Error: (06/29/2015 07:50:44 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Data.SqlXml, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
Error: (06/29/2015 07:50:42 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Security, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005
Error: (06/29/2015 07:50:42 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Data, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
Error: (06/29/2015 07:50:39 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: Microsoft.VisualC, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005
System errors:
=============
Error: (06/29/2015 08:03:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Software Protection" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Restart the service.
Error: (06/29/2015 08:03:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Restart the service.
Error: (06/29/2015 08:03:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Microsoft .NET Framework NGEN v4.0.30319_X64" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Restart the service.
Error: (06/29/2015 08:03:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Microsoft .NET Framework NGEN v4.0.30319_X86" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Restart the service.
Error: (06/29/2015 08:03:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/29/2015 08:03:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player Network Sharing Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Restart the service.
Error: (06/29/2015 08:03:03 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Streamer Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/29/2015 08:03:03 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Network Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/29/2015 08:03:02 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA GeForce Experience Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/29/2015 08:03:02 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Print Spooler" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Restart the service.
Microsoft Office:
=========================
Error: (06/29/2015 07:55:29 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/29/2015 07:50:56 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
Error: (06/29/2015 07:50:51 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Data.OracleClient, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=x86 . Error code = 0x80070005
System.Data.OracleClient, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=x86
Error: (06/29/2015 07:50:50 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
Error: (06/29/2015 07:50:47 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Configuration, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005
System.Configuration, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Error: (06/29/2015 07:50:46 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Xml, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
System.Xml, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
Error: (06/29/2015 07:50:44 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Data.SqlXml, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
System.Data.SqlXml, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
Error: (06/29/2015 07:50:42 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Security, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005
System.Security, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Error: (06/29/2015 07:50:42 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: System.Data, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070005
System.Data, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
Error: (06/29/2015 07:50:39 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile: Microsoft.VisualC, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070005
Microsoft.VisualC, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
==================== Memory info ===========================
Processor: AMD Phenom(tm) II X4 965 Processor
Percentage of memory in use: 34%
Total physical RAM: 4095.3 MB
Available physical RAM: 2691.76 MB
Total Pagefile: 8188.82 MB
Available Pagefile: 6588.94 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:440.76 GB) (Free:312.21 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0D400D40)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=440.8 GB) - (Type=07 NTFS)
==================== End of log ============================ --- --- ---
--- --- ---
Hier kommt Gmer:
Code:
GMER Logfile:
Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-06-29 20:34:50
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-6 SAMSUNG_HD501LJ rev.CR100-12 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Entimate\AppData\Local\Temp\awryqkod.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2068] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000754e8781 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077093260 4 bytes JMP 000000007fff075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077096f30 5 bytes JMP 000000007fff03a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5484] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000770bde30 16 bytes [50, 48, B8, 30, 35, 62, F5, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077093260 5 bytes JMP 000000010026075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077096f30 5 bytes JMP 00000001002603a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000770bdc80 16 bytes [50, 48, B8, 5C, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 00000000770bddf0 16 bytes [50, 48, B8, B4, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 00000000770bde10 48 bytes [50, 48, B8, 30, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 00000000770bde50 16 bytes [50, 48, B8, 80, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 00000000770bdea0 32 bytes [50, 48, B8, D8, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770bdee0 16 bytes [50, 48, B8, C0, E8, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 00000000770bdf80 16 bytes [50, 48, B8, 08, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 00000000770be100 16 bytes [50, 48, B8, 84, E7, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 00000000770beb70 16 bytes [50, 48, B8, 54, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 00000000770bebc0 16 bytes [50, 48, B8, 90, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4908] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 00000000770bed10 16 bytes [50, 48, B8, 1C, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077093260 5 bytes JMP 00000001004f075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077096f30 5 bytes JMP 00000001004f03a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000770bdc80 16 bytes [50, 48, B8, 5C, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 00000000770bddf0 16 bytes [50, 48, B8, B4, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 00000000770bde10 48 bytes [50, 48, B8, 30, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 00000000770bde50 16 bytes [50, 48, B8, 80, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 00000000770bdea0 32 bytes [50, 48, B8, D8, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770bdee0 16 bytes [50, 48, B8, C0, E8, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 00000000770bdf80 16 bytes [50, 48, B8, 08, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 00000000770be100 16 bytes [50, 48, B8, 84, E7, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 00000000770beb70 16 bytes [50, 48, B8, 54, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 00000000770bebc0 16 bytes [50, 48, B8, 90, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5500] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 00000000770bed10 16 bytes [50, 48, B8, 1C, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077093260 5 bytes JMP 000000010023075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077096f30 5 bytes JMP 00000001002303a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00000000770bdc80 16 bytes [50, 48, B8, 5C, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 00000000770bddf0 16 bytes [50, 48, B8, B4, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 00000000770bde10 48 bytes [50, 48, B8, 30, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 00000000770bde50 16 bytes [50, 48, B8, 80, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 00000000770bdea0 32 bytes [50, 48, B8, D8, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 00000000770bdee0 16 bytes [50, 48, B8, C0, E8, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 00000000770bdf80 16 bytes [50, 48, B8, 08, EA, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 00000000770be100 16 bytes [50, 48, B8, 84, E7, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 00000000770beb70 16 bytes [50, 48, B8, 54, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 00000000770bebc0 16 bytes [50, 48, B8, 90, E9, B1, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5224] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 00000000770bed10 16 bytes [50, 48, B8, 1C, EA, B1, 3F, ...]
---- Threads - GMER 2.1 ----
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2064:384] 0000000075617587
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2064:2824] 0000000074388aa6
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2064:4424] 0000000077291415
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2064:4456] 00000000772a2855
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2064:2052] 00000000772a2855
---- EOF - GMER 2.1 ---- --- --- --- Hier defogger_disable:
Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 20:24 on 29/06/2015 (Entimate)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
und hier der Rest:
Mbam:
Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.06.2015
Suchlauf-Zeit: 19:16:15
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.29.03
Rootkit Datenbank: v2015.06.26.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Entimate
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 328841
Verstrichene Zeit: 9 Min, 54 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 11
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}, In Quarantäne, [4136e5db5832cd69e25b224de3209868],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [3d3a4a76ddad13235b98d6b363a223dd],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, In Quarantäne, [e79012ae04866acccb5c4dbdc2429868],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\istartsurfSoftware, In Quarantäne, [dc9bb50b0585d6605d1b6db225df728e],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [92e5efd1a1e964d26390f594d53023dd],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [7ff81ea2751584b22bc396877f8514ec],
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [dc9ba21e1a70e94dae44a7e281849a66],
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}, In Quarantäne, [a2d5427e6f1b0b2b8270ccbd3acb669a],
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [6b0cf6ca1b6fe650f5fdc4c581847888],
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}, In Quarantäne, [c3b4962a5d2dc27481713f4ae71e1fe1],
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\PRODUCTSETUP, In Quarantäne, [3443c000d4b672c40a922c6940c5728e],
Registrierungswerte: 12
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, In Quarantäne, [3d3a4a76ddad13235b98d6b363a223dd]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.istartsurf.com/web/?type=dspp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&q={searchTerms}, In Quarantäne, [85f2526ef19968ce47ac008952b3cb35]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, In Quarantäne, [92e5efd1a1e964d26390f594d53023dd]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.istartsurf.com/web/?type=dspp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&q={searchTerms}, In Quarantäne, [9fd84f717317a195df143c4dc1445ca4]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [7ff81ea2751584b22bc396877f8514ec]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&ts=1435524247&type=default&q={searchTerms}, In Quarantäne, [dc9ba21e1a70e94dae44a7e281849a66]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&ts=1435524247&type=default&q={searchTerms}, In Quarantäne, [a2d5427e6f1b0b2b8270ccbd3acb669a]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, hxxp://www.istartsurf.com//favicon.ico, In Quarantäne, [0176e3dd800a11255d95fe8b3fc64eb2]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, istartsurf, In Quarantäne, [6b0cf6ca1b6fe650f5fdc4c581847888]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.istartsurf.com/web/?type=dspp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&q={searchTerms}, In Quarantäne, [a7d01aa6e5a55adcf1010b7e1ee73ec2]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&ts=1435524247&type=default&q={searchTerms}, In Quarantäne, [c3b4962a5d2dc27481713f4ae71e1fe1]
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-1464251018-2182050062-3487427115-1000\SOFTWARE\PRODUCTSETUP|tb, In Quarantäne, [3443c000d4b672c40a922c6940c5728e],
Registrierungsdaten: 5
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=dspp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=dspp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&q={searchTerms}),Ersetzt,[294ea61af09ac0768ddfcc75c73f8e72]
PUP.Optional.HttpBreaker.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453),Ersetzt,[096e3d830585c1751de7fd4438cec937]
PUP.Optional.HttpBreaker.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453),Ersetzt,[f97e90304446bc7acf35cf72c5414bb5]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.istartsurf.com/web/?type=dspp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=dspp&ts=1435524231&z=5c8221b8e6f5997cadd6a19g3z9cdwewco8z6ofe7q&from=cor&uid=SAMSUNGXHD501LJ_S0MUJFWQ253453&q={searchTerms}),Ersetzt,[93e4bf0189016dc9ea82da67b254e917]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[aec9368af99189ad232cba93d82ead53]
Ordner: 2
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, In Quarantäne, [b3c4e4dc7a10b0861f766a822cd7768a],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, In Quarantäne, [b3c4e4dc7a10b0861f766a822cd7768a],
Dateien: 3
HackTool.Wpakill, C:\Windows\System32\RemoveWAT.exe, In Quarantäne, [1463f8c8800ada5ceee3671d15eb5da3],
PUP.Optional.FilterResults.A, C:\Users\Entimate\AppData\Local\Temp\is1201216051\6980ABDB_stp.EXE, In Quarantäne, [680fe2dea4e64fe7f677fa90868039c7],
PUP.Optional.IStartSurf.A, C:\Users\Entimate\AppData\Local\Temp\is1201216051\6CB529C8_stp\June3_3897_cor_istartsurf.exe, In Quarantäne, [e691922ef595ad89ba278dfa9d69c33d],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end)
AdwCleaner:
AdwCleaner Logfile:
Code:
# AdwCleaner v4.207 - Bericht erstellt 29/06/2015 um 19:36:29
# Aktualisiert 21/06/2015 von Xplode
# Datenbank : 2015-06-23.1 [Server]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (x64)
# Benutzername : Entimate - ENTIMATE-PC
# Gestarted von : C:\Users\Entimate\Downloads\AdwCleaner_4.207.exe
# Option : Suchlauf
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istartsurf.com
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.istartsurf.com
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gefunden : HKLM\SOFTWARE\SupDp
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17728
-\\ Google Chrome v43.0.2357.130
*************************
AdwCleaner[R0].txt - [1268 Bytes] - [29/06/2015 19:36:29]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1327 Bytes] ########## --- --- ---
Die zweite AdwCleaner Datei:
AdwCleaner Logfile: Code:
# AdwCleaner v4.207 - Bericht erstellt 29/06/2015 um 19:51:57
# Aktualisiert 21/06/2015 von Xplode
# Datenbank : 2015-06-23.1 [Server]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (x64)
# Benutzername : Entimate - ENTIMATE-PC
# Gestarted von : C:\Users\Entimate\Downloads\AdwCleaner_4.207.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\SupDp
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istartsurf.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.istartsurf.com
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17728
-\\ Google Chrome v43.0.2357.130
*************************
AdwCleaner[R0].txt - [1414 Bytes] - [29/06/2015 19:36:29]
AdwCleaner[S0].txt - [1284 Bytes] - [29/06/2015 19:51:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1343 Bytes] ########## --- --- ---
[/CODE]
JRT:
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.2.1 (06.28.2015:2)
OS: Windows 7 Ultimate x64
Ran by Entimate on 29.06.2015 at 20:02:31,42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Chrome
[C:\Users\Entimate\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Entimate\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Entimate\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Entimate\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.06.2015 at 20:05:03,70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
[/CODE]
Leider weiß ich nicht wo ich den Log von meinem Avast finde.
Ich hoffe das war jetzt richtig so viel zu posten und hoffe das ich nicht nerve.
Vielen Dank! |