Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: PC gekapert?

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Thema geschlossen
Alt 17.12.2013, 15:30   #1
Gottel62
 
PC gekapert? - Standard

PC gekapert?



Hallo!

Ich habe die Vermutung das mein PC gekapert worden ist.Ich hatte Malwarebytes durchlaufen lassen und der fand mehrere PUP Optional Viren.Daraufhin formatierte ich meinen Pc und nach der Neuaufspielung meines Win7 home 64 bit ,hatte ich dieselben Probleme wieder.Ich bitte um Hilfe weiss mir langsam keinen Rat mehr.Danke im voraus Gotthard Bienias

Alt 17.12.2013, 15:55   #2
schrauber
/// the machine
/// TB-Ausbilder
 

PC gekapert? - Standard

PC gekapert?



Hi,

haste mal geschaut was PUP ist?

What is PUP (potentially unwanted program)? - Definition from WhatIs.com

Das ist einfach nur Adware oder ein Tool was Du installierst, wo ne Toolbar dabei ist.


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 18.12.2013, 05:47   #3
Gottel62
 
PC gekapert? - Standard

PC gekapert?



Hallo

Vielen Dank für die schnelle Antwort.Hier sind die Logfiles.
__________________

Alt 18.12.2013, 12:08   #4
schrauber
/// the machine
/// TB-Ausbilder
 

PC gekapert? - Standard

PC gekapert?



Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 18.12.2013, 17:00   #5
Gottel62
 
PC gekapert? - Standard

PC gekapert?



FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2013 02
Ran by Gotthard Bienias (administrator) on MEINER on 18-12-2013 05:33:21
Running from C:\Users\Gotthard Bienias\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7883296 2009-06-16] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-06-16] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-12-16] (Kaspersky Lab ZAO)
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default
Startup: C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung SSD Magician.lnk
ShortcutTarget: Samsung SSD Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung SSD Magician.exe (Samsung Electronics.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 62.117.1.25 89.16.129.25

FireFox:
========
FF ProfilePath: C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default
FF user.js: detected! => C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @kaspersky.com/Password Manager - I:\Kaspersky Password Manager\npkpmAutofill.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: WOT - C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF Extension: Adblock Plus - C:\Users\Gotthard Bienias\AppData\Roaming\Mozilla\Firefox\Profiles\nja4rs1t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com

Chrome: 
=======
CHR DefaultSearchKeyword: google.de
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding}
CHR Extension: (Google Docs) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\14.0.0.4651_0
CHR Extension: (Safe Money) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\14.0.0.4651_0
CHR Extension: (Dangerous Websites Blocker) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0
CHR Extension: (Virtual Keyboard) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\14.0.0.4794_0
CHR Extension: (Google Wallet) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR Extension: (Anti-Banner) - C:\Users\Gotthard Bienias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\14.0.0.4651_0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx

==================== Services (Whitelisted) =================

R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-12-16] (Kaspersky Lab ZAO)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-12-01] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2409272 2013-12-10] (TuneUp Software)

==================== Drivers (Whitelisted) ====================

R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-30] (Intel Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-16] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-12-16] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-16] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-12-16] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-12-16] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-12-16] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-12-16] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2013-03-26] (TuneUp Software)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-12-16] (Kaspersky Lab ZAO)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-18 05:33 - 2013-12-18 05:33 - 00016576 _____ C:\Users\Gotthard Bienias\Downloads\FRST.txt
2013-12-18 05:32 - 2013-12-18 05:32 - 00000000 ____D C:\FRST
2013-12-18 05:31 - 2013-12-18 05:31 - 01928214 _____ (Farbar) C:\Users\Gotthard Bienias\Downloads\FRST64.exe
2013-12-17 15:44 - 2013-12-17 15:44 - 00001188 _____ C:\Users\Gotthard Bienias\Desktop\OpenOffice 4.0.1.lnk
2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ___SD C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\OpenOffice
2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-12-17 15:12 - 2013-12-17 15:18 - 163606685 _____ C:\Users\Gotthard Bienias\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2013-12-17 05:43 - 2013-12-18 05:18 - 00000504 _____ C:\Windows\setupact.log
2013-12-17 05:43 - 2013-12-17 05:43 - 00000000 _____ C:\Windows\setuperr.log
2013-12-16 19:55 - 2013-12-16 19:55 - 00002344 _____ C:\Users\Gotthard Bienias\Desktop\Sicherer Zahlungsverkehr.lnk
2013-12-16 19:55 - 2013-12-16 19:54 - 00001150 _____ C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
2013-12-16 19:54 - 2013-12-18 05:21 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-12-16 19:54 - 2013-12-16 20:01 - 00626272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-12-16 19:54 - 2013-12-16 20:01 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Windows\ELAMBKUP
2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2013-12-16 19:54 - 2012-07-11 17:09 - 00064856 _____ (Kaspersky Lab) C:\Windows\system32\klfphc.dll
2013-12-16 19:48 - 2013-12-18 05:21 - 00164523 _____ C:\Windows\WindowsUpdate.log
2013-12-16 19:40 - 2013-12-16 19:41 - 165974760 _____ (Kaspersky Lab) C:\Users\Gotthard Bienias\Downloads\kis13.0.1.4190de-de.exe
2013-12-16 19:28 - 2013-12-16 19:28 - 00078776 _____ C:\Users\Gotthard Bienias\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-16 19:27 - 2013-12-18 05:18 - 00366544 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-16 16:04 - 2013-12-16 16:04 - 00000000 _____ C:\Users\Gotthard Bienias\Desktop\Neues Textdokument.txt
2013-12-15 18:11 - 2013-12-15 18:11 - 00000000 ____D C:\Program Files\7-Zip
2013-12-15 17:57 - 2013-12-15 18:05 - 136952609 _____ C:\Users\Gotthard Bienias\Downloads\T-GAP8DEUC-1029.0.exe
2013-12-14 16:01 - 2013-12-14 16:01 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\NVIDIA
2013-12-14 15:31 - 2013-12-14 15:31 - 00000222 _____ C:\Users\Gotthard Bienias\Desktop\Neverwinter.url
2013-12-14 15:31 - 2013-12-14 15:31 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-12-12 17:31 - 2013-12-10 18:43 - 00038200 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll
2013-12-12 17:31 - 2013-12-10 18:43 - 00030520 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll
2013-12-12 06:39 - 2013-12-12 06:39 - 23867560 _____ (Mozilla) C:\Users\Gotthard Bienias\Downloads\Firefox_Setup_26.0.exe
2013-12-11 05:50 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-11 05:50 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-11 05:50 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-11 05:50 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-11 05:49 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 05:49 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 05:49 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-11 05:49 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-11 05:49 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-11 05:49 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-11 05:49 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 05:49 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 05:49 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-11 05:49 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-11 05:49 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 05:49 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 05:49 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-11 05:49 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-11 05:49 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-11 05:49 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-11 05:49 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-11 05:49 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 05:49 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-11 05:49 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-11 05:49 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-11 05:49 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 05:49 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 05:49 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-11 05:49 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-11 05:49 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 05:49 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 05:49 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-11 05:49 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-11 05:49 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-11 05:49 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 05:48 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 05:48 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 05:48 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 05:48 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 05:48 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 05:48 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 05:48 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 05:48 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 05:48 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 05:48 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 05:48 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 05:48 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 05:48 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 05:48 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 05:48 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 05:48 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 05:48 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 05:48 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 05:48 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 17:12 - 2013-12-10 17:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-12-10 17:10 - 2013-12-10 17:10 - 00000000 ____D C:\Program Files\SAMSUNG
2013-12-10 17:10 - 2013-08-21 05:31 - 00204568 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2013-12-10 17:10 - 2013-08-21 05:31 - 00103576 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2013-12-10 17:08 - 2013-12-14 09:06 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Downloaded Installations
2013-12-10 17:08 - 2013-12-10 17:08 - 00001973 _____ C:\Users\Public\Desktop\Samsung Kies 3.lnk
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\SelfMV
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\samsung
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Samsung
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-12-10 17:07 - 2013-12-10 17:07 - 38825784 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Gotthard Bienias\Downloads\Kies3Setup.exe
2013-12-10 16:17 - 2013-12-10 16:17 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Kaspersky Lab
2013-12-10 15:27 - 2013-12-10 15:30 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\vlc
2013-12-10 15:27 - 2013-12-10 15:27 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-12-10 15:26 - 2013-12-10 15:26 - 24097311 _____ C:\Users\Gotthard Bienias\Downloads\vlc-2.1.2-win32.exe
2013-12-10 15:26 - 2013-12-10 15:26 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\PunkBuster
2013-12-03 06:46 - 2013-10-30 18:03 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-12-03 06:46 - 2013-10-30 18:02 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-12-02 06:19 - 2013-12-08 18:24 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\CrashDumps
2013-12-01 17:21 - 2013-12-01 17:24 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\Battlefield 4
2013-12-01 17:21 - 2013-12-01 17:21 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\ESN
2013-12-01 17:15 - 2013-12-09 16:00 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-01 17:15 - 2013-12-02 05:36 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-12-01 17:15 - 2013-12-01 17:15 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-12-01 17:14 - 2013-12-01 17:14 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-12-01 17:14 - 2013-12-01 17:14 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-01 14:36 - 2013-12-01 14:36 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-01 13:52 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-12-01 13:50 - 2013-12-01 13:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-01 13:50 - 2013-12-01 13:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-01 13:50 - 2013-12-01 13:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-01 13:50 - 2013-12-01 13:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-01 13:50 - 2013-12-01 13:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-01 13:29 - 2013-11-23 20:26 - 30361888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 22951200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 18208624 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 15862272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 12613920 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-12-01 13:29 - 2013-11-23 20:26 - 11566648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 11441664 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 09663656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 09619872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433193.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433193.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00707360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00657184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00609568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00562464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-12-01 13:29 - 2013-11-23 20:26 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-12-01 13:27 - 2013-12-03 06:46 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NVIDIA Corporation
2013-12-01 10:14 - 2013-12-17 15:51 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-01 10:14 - 2013-12-01 10:14 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk
2013-12-01 09:55 - 2013-12-01 17:19 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Origin
2013-12-01 09:55 - 2013-12-01 13:36 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Origin
2013-12-01 09:54 - 2013-12-14 15:32 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-12-01 09:54 - 2013-12-09 15:23 - 00000000 ____D C:\Program Files (x86)\Origin
2013-12-01 09:54 - 2013-12-01 17:21 - 00000000 ____D C:\ProgramData\Origin
2013-12-01 09:54 - 2013-12-01 09:54 - 00000983 _____ C:\Users\Public\Desktop\Origin.lnk
2013-12-01 09:54 - 2013-12-01 09:54 - 00000074 _____ C:\Windows\wininit.ini
2013-11-29 16:02 - 2013-11-29 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-11-29 15:57 - 2013-11-29 15:57 - 00001440 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-29 15:52 - 2013-11-19 03:33 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-29 15:48 - 2013-11-29 15:57 - 00001243 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-11-29 15:48 - 2013-11-29 15:57 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\DVDVideoSoft
2013-11-29 15:48 - 2013-11-29 15:57 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-11-29 15:48 - 2013-11-29 15:48 - 00001536 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-29 15:16 - 2013-11-29 15:16 - 00249444 _____ C:\ProgramData\1385734552.bdinstall.bin
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJSolutionMenuEX
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonEPP
2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\ProgramData\CanonIJMSetup
2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\Program Files\Common Files\CANON
2013-11-23 19:06 - 2013-11-23 19:06 - 00002079 _____ C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
2013-11-23 19:06 - 2013-11-23 19:06 - 00000000 ____D C:\ProgramData\CanonIJWSpt
2013-11-23 19:04 - 2013-11-23 19:04 - 00002360 _____ C:\Users\Public\Desktop\Canon MG6100 series Online-Handbuch.lnk
2013-11-23 19:04 - 2013-11-23 19:04 - 00000000 ____D C:\Program Files\Canon
2013-11-23 18:58 - 2013-11-23 18:58 - 00000000 ____D C:\Windows\system32\STRING
2013-11-23 18:58 - 2010-02-05 02:37 - 00327680 _____ (CANON INC.) C:\Windows\system32\CNMN6PPM.DLL
2013-11-23 18:58 - 2010-02-05 02:37 - 00037376 _____ (CANON INC.) C:\Windows\system32\CNMN6UI.DLL
2013-11-23 18:56 - 2013-11-23 19:10 - 00000000 ____D C:\Program Files (x86)\Canon
2013-11-23 12:18 - 2013-11-23 12:18 - 00590112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-11-23 06:59 - 2013-12-12 06:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-23 06:47 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-23 06:47 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-23 06:47 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-23 06:47 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-23 06:47 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-23 06:47 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-23 06:47 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-23 06:47 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-23 06:47 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-23 06:47 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-23 06:47 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-23 06:47 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-23 06:47 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-23 06:47 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-23 06:47 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-23 06:47 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-23 06:47 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-23 06:47 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-23 06:47 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-23 06:47 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-23 06:47 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-23 06:47 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-23 06:47 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-23 06:47 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-23 06:47 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-23 06:47 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-23 06:47 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-23 06:47 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-23 06:47 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-23 06:47 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys

==================== One Month Modified Files and Folders =======

2013-12-18 05:33 - 2013-12-18 05:33 - 00016576 _____ C:\Users\Gotthard Bienias\Downloads\FRST.txt
2013-12-18 05:32 - 2013-12-18 05:32 - 00000000 ____D C:\FRST
2013-12-18 05:31 - 2013-12-18 05:31 - 01928214 _____ (Farbar) C:\Users\Gotthard Bienias\Downloads\FRST64.exe
2013-12-18 05:30 - 2013-11-02 09:17 - 00001130 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-18 05:25 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-18 05:25 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-18 05:24 - 2013-10-28 23:13 - 00700454 _____ C:\Windows\system32\perfh007.dat
2013-12-18 05:24 - 2013-10-28 23:13 - 00150092 _____ C:\Windows\system32\perfc007.dat
2013-12-18 05:24 - 2009-07-14 06:13 - 01624034 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-18 05:21 - 2013-12-16 19:54 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-12-18 05:21 - 2013-12-16 19:48 - 00164523 _____ C:\Windows\WindowsUpdate.log
2013-12-18 05:20 - 2013-11-02 09:17 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-18 05:18 - 2013-12-17 05:43 - 00000504 _____ C:\Windows\setupact.log
2013-12-18 05:18 - 2013-12-16 19:27 - 00366544 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-18 05:18 - 2013-10-30 14:47 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-18 05:18 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-17 19:57 - 2013-10-30 17:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-17 15:51 - 2013-12-01 10:14 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-17 15:44 - 2013-12-17 15:44 - 00001188 _____ C:\Users\Gotthard Bienias\Desktop\OpenOffice 4.0.1.lnk
2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ___SD C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\OpenOffice
2013-12-17 15:44 - 2013-12-17 15:44 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-12-17 15:42 - 2013-10-31 15:16 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\PrivaZer
2013-12-17 15:18 - 2013-12-17 15:12 - 163606685 _____ C:\Users\Gotthard Bienias\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2013-12-17 05:43 - 2013-12-17 05:43 - 00000000 _____ C:\Windows\setuperr.log
2013-12-16 20:01 - 2013-12-16 19:54 - 00626272 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-12-16 20:01 - 2013-12-16 19:54 - 00090208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2013-12-16 20:01 - 2012-08-13 16:49 - 00178448 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2013-12-16 20:01 - 2012-08-02 15:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys
2013-12-16 20:01 - 2012-07-25 14:53 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klmouflt.sys
2013-12-16 20:01 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2013-12-16 20:01 - 2012-06-08 11:38 - 00054368 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kltdi.sys
2013-12-16 20:01 - 2012-05-25 19:38 - 00029280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2013-12-16 19:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-12-16 19:55 - 2013-12-16 19:55 - 00002344 _____ C:\Users\Gotthard Bienias\Desktop\Sicherer Zahlungsverkehr.lnk
2013-12-16 19:54 - 2013-12-16 19:55 - 00001150 _____ C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Windows\ELAMBKUP
2013-12-16 19:54 - 2013-12-16 19:54 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2013-12-16 19:51 - 2013-10-31 06:54 - 00000000 ____D C:\Users\Gast
2013-12-16 19:41 - 2013-12-16 19:40 - 165974760 _____ (Kaspersky Lab) C:\Users\Gotthard Bienias\Downloads\kis13.0.1.4190de-de.exe
2013-12-16 19:34 - 2009-07-14 06:08 - 00001386 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-16 19:28 - 2013-12-16 19:28 - 00078776 _____ C:\Users\Gotthard Bienias\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-16 16:04 - 2013-12-16 16:04 - 00000000 _____ C:\Users\Gotthard Bienias\Desktop\Neues Textdokument.txt
2013-12-15 18:11 - 2013-12-15 18:11 - 00000000 ____D C:\Program Files\7-Zip
2013-12-15 18:05 - 2013-12-15 17:57 - 136952609 _____ C:\Users\Gotthard Bienias\Downloads\T-GAP8DEUC-1029.0.exe
2013-12-14 16:01 - 2013-12-14 16:01 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\NVIDIA
2013-12-14 15:32 - 2013-12-01 09:54 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-12-14 15:31 - 2013-12-14 15:31 - 00000222 _____ C:\Users\Gotthard Bienias\Desktop\Neverwinter.url
2013-12-14 15:31 - 2013-12-14 15:31 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-12-14 09:06 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Downloaded Installations
2013-12-14 09:06 - 2013-10-31 08:30 - 00000000 ____D C:\ProgramData\DriverGenius
2013-12-12 17:31 - 2013-10-31 10:16 - 00000000 ____D C:\Program Files (x86)\TuneUp Utilities 2013
2013-12-12 15:58 - 2013-10-30 15:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-12 06:57 - 2013-10-30 17:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-12 06:57 - 2013-10-30 17:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-12 06:57 - 2013-10-30 17:20 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-12 06:40 - 2013-11-23 06:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-12 06:40 - 2013-10-30 15:32 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-12-12 06:39 - 2013-12-12 06:39 - 23867560 _____ (Mozilla) C:\Users\Gotthard Bienias\Downloads\Firefox_Setup_26.0.exe
2013-12-11 05:52 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-11 05:49 - 2013-10-30 14:34 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 05:48 - 2013-10-30 14:34 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-10 18:43 - 2013-12-12 17:31 - 00038200 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll
2013-12-10 18:43 - 2013-12-12 17:31 - 00030520 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll
2013-12-10 18:43 - 2013-10-31 10:17 - 00035640 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2013-12-10 18:43 - 2013-10-31 10:17 - 00026936 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2013-12-10 18:43 - 2013-10-31 10:17 - 00022328 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll
2013-12-10 17:12 - 2013-12-10 17:12 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-12-10 17:10 - 2013-12-10 17:10 - 00000000 ____D C:\Program Files\SAMSUNG
2013-12-10 17:10 - 2013-10-30 14:13 - 00000000 ____D C:\ProgramData\Samsung
2013-12-10 17:08 - 2013-12-10 17:08 - 00001973 _____ C:\Users\Public\Desktop\Samsung Kies 3.lnk
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\SelfMV
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\samsung
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Samsung
2013-12-10 17:08 - 2013-12-10 17:08 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-12-10 17:08 - 2009-09-17 22:04 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-10 17:07 - 2013-12-10 17:07 - 38825784 _____ (Samsung Electronics Co., Ltd.                                ) C:\Users\Gotthard Bienias\Downloads\Kies3Setup.exe
2013-12-10 16:17 - 2013-12-10 16:17 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Kaspersky Lab
2013-12-10 16:05 - 2013-10-31 08:47 - 00000000 ____D C:\Windows\SysWOW64\sda
2013-12-10 16:01 - 2013-10-28 14:25 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-12-10 15:31 - 2009-07-14 08:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-12-10 15:30 - 2013-12-10 15:27 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\vlc
2013-12-10 15:27 - 2013-12-10 15:27 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-12-10 15:26 - 2013-12-10 15:26 - 24097311 _____ C:\Users\Gotthard Bienias\Downloads\vlc-2.1.2-win32.exe
2013-12-10 15:26 - 2013-12-10 15:26 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\PunkBuster
2013-12-09 16:00 - 2013-12-01 17:15 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-09 15:23 - 2013-12-01 09:54 - 00000000 ____D C:\Program Files (x86)\Origin
2013-12-08 18:24 - 2013-12-02 06:19 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\CrashDumps
2013-12-08 15:25 - 2013-11-02 09:17 - 00004126 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-08 15:25 - 2013-11-02 09:17 - 00003874 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-06 07:32 - 2013-11-02 07:54 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NPE
2013-12-06 07:23 - 2013-11-02 07:54 - 03057128 ____N (Symantec Corporation) C:\Users\Gotthard Bienias\Downloads\NPE.exe
2013-12-06 07:11 - 2013-10-31 14:03 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\Ubisoft
2013-12-06 07:11 - 2013-10-31 10:44 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-12-06 06:26 - 2013-11-02 09:18 - 00002179 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-04 15:34 - 2013-10-28 14:31 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\VirtualStore
2013-12-03 06:47 - 2013-10-31 08:59 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NVIDIA
2013-12-03 06:46 - 2013-12-01 13:27 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\NVIDIA Corporation
2013-12-03 06:46 - 2013-10-30 14:46 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-12-03 06:46 - 2013-10-30 14:46 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-12-03 06:46 - 2013-10-30 14:46 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-12-02 05:36 - 2013-12-01 17:15 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-12-01 17:24 - 2013-12-01 17:21 - 00000000 ____D C:\Users\Gotthard Bienias\Documents\Battlefield 4
2013-12-01 17:21 - 2013-12-01 17:21 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\ESN
2013-12-01 17:21 - 2013-12-01 09:54 - 00000000 ____D C:\ProgramData\Origin
2013-12-01 17:19 - 2013-12-01 09:55 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Origin
2013-12-01 17:15 - 2013-12-01 17:15 - 00281872 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-12-01 17:14 - 2013-12-01 17:14 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-12-01 17:14 - 2013-12-01 17:14 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-01 16:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-01 14:36 - 2013-12-01 14:36 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-01 14:36 - 2013-10-31 10:42 - 00000000 ____D C:\Program Files\CCleaner
2013-12-01 14:36 - 2009-09-17 22:59 - 00000000 ____D C:\Windows\Panther
2013-12-01 14:17 - 2013-10-28 14:31 - 00001425 _____ C:\Users\Gotthard Bienias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 14:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-12-01 13:50 - 2013-12-01 13:50 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-12-01 13:50 - 2013-12-01 13:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-01 13:50 - 2013-12-01 13:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-01 13:50 - 2013-12-01 13:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-12-01 13:50 - 2013-12-01 13:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-01 13:50 - 2013-12-01 13:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-12-01 13:50 - 2013-12-01 13:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-12-01 13:50 - 2013-12-01 13:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-01 13:50 - 2013-12-01 13:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-12-01 13:36 - 2013-12-01 09:55 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\Origin
2013-12-01 10:14 - 2013-12-01 10:14 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk
2013-12-01 09:54 - 2013-12-01 09:54 - 00000983 _____ C:\Users\Public\Desktop\Origin.lnk
2013-12-01 09:54 - 2013-12-01 09:54 - 00000074 _____ C:\Windows\wininit.ini
2013-12-01 09:49 - 2013-10-31 08:39 - 01597378 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-11-29 17:56 - 2013-10-31 09:02 - 01096480 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-29 17:56 - 2013-10-31 09:02 - 00979744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-29 16:02 - 2013-11-29 16:02 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2013-11-29 15:57 - 2013-11-29 15:57 - 00001440 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-29 15:57 - 2013-11-29 15:48 - 00001243 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2013-11-29 15:57 - 2013-11-29 15:48 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Roaming\DVDVideoSoft
2013-11-29 15:57 - 2013-11-29 15:48 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-11-29 15:48 - 2013-11-29 15:48 - 00001536 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-29 15:17 - 2013-10-30 14:01 - 00000000 ____D C:\Program Files\Bitdefender
2013-11-29 15:16 - 2013-11-29 15:16 - 00249444 _____ C:\ProgramData\1385734552.bdinstall.bin
2013-11-29 15:16 - 2013-10-30 14:01 - 00000000 ____D C:\ProgramData\Bitdefender
2013-11-29 15:16 - 2013-10-30 14:01 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-11-26 12:54 - 2013-12-11 05:49 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 11:19 - 2013-12-11 05:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 11:18 - 2013-12-11 05:49 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 11:11 - 2013-12-11 05:49 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 10:48 - 2013-12-11 05:49 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 10:46 - 2013-12-11 05:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 10:41 - 2013-12-11 05:49 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 10:29 - 2013-12-11 05:49 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 10:27 - 2013-12-11 05:49 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 10:23 - 2013-12-11 05:49 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 10:21 - 2013-12-11 05:49 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 10:18 - 2013-12-11 05:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 10:18 - 2013-12-11 05:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 10:16 - 2013-12-11 05:49 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 09:57 - 2013-12-11 05:49 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 09:38 - 2013-12-11 05:49 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 09:38 - 2013-12-11 05:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 09:35 - 2013-12-11 05:49 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 09:32 - 2013-12-11 05:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 09:28 - 2013-12-11 05:49 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 09:16 - 2013-12-11 05:49 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 09:02 - 2013-12-11 05:49 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 08:48 - 2013-12-11 05:49 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 08:32 - 2013-12-11 05:49 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 08:26 - 2013-12-11 05:49 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 08:07 - 2013-12-11 05:49 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 07:40 - 2013-12-11 05:49 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 07:34 - 2013-12-11 05:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 07:34 - 2013-12-11 05:49 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 07:33 - 2013-12-11 05:49 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 07:27 - 2013-12-11 05:49 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 30361888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 22951200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 18208624 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 15862272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 12613920 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-23 20:26 - 2013-12-01 13:29 - 11566648 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 11441664 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 09663656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 09619872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433193.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433193.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00707360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00657184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00609568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00562464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-11-23 20:26 - 2013-12-01 13:29 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-11-23 20:26 - 2013-10-31 09:06 - 18293096 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-11-23 20:26 - 2013-10-31 08:56 - 15218504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-11-23 20:26 - 2013-10-31 08:56 - 02697248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-11-23 20:26 - 2013-10-30 14:46 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2013-11-23 20:26 - 2013-10-30 14:46 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2013-11-23 20:26 - 2013-09-17 22:22 - 03069608 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-11-23 20:26 - 2013-09-17 22:22 - 01436528 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-11-23 20:26 - 2013-09-17 22:22 - 00023754 _____ C:\Windows\system32\nvinfo.pb
2013-11-23 19:56 - 2013-10-28 14:33 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Google
2013-11-23 19:26 - 2013-12-11 05:48 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-11-23 19:10 - 2013-11-23 18:56 - 00000000 ____D C:\Program Files (x86)\Canon
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJSolutionMenuEX
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJMyPrinter
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2
2013-11-23 19:09 - 2013-11-23 19:09 - 00000000 ___HD C:\ProgramData\CanonEPP
2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\ProgramData\CanonIJMSetup
2013-11-23 19:07 - 2013-11-23 19:07 - 00000000 ____D C:\Program Files\Common Files\CANON
2013-11-23 19:06 - 2013-11-23 19:06 - 00002079 _____ C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
2013-11-23 19:06 - 2013-11-23 19:06 - 00000000 ____D C:\ProgramData\CanonIJWSpt
2013-11-23 19:04 - 2013-11-23 19:04 - 00002360 _____ C:\Users\Public\Desktop\Canon MG6100 series Online-Handbuch.lnk
2013-11-23 19:04 - 2013-11-23 19:04 - 00000000 ____D C:\Program Files\Canon
2013-11-23 18:58 - 2013-11-23 18:58 - 00000000 ____D C:\Windows\system32\STRING
2013-11-23 18:47 - 2013-12-11 05:48 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-11-23 18:42 - 2013-10-30 14:47 - 06674208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-11-23 18:42 - 2013-10-30 14:47 - 03490080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-11-23 18:42 - 2013-10-30 14:47 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-11-23 18:42 - 2013-10-30 14:47 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-11-23 18:42 - 2013-10-30 14:47 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-11-23 18:42 - 2013-10-30 14:47 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-11-23 12:18 - 2013-11-23 12:18 - 00590112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-11-23 06:57 - 2013-10-30 13:38 - 00000000 ____D C:\Users\Gotthard Bienias\AppData\Local\Adobe
2013-11-22 17:28 - 2013-10-30 14:47 - 03498475 _____ C:\Windows\system32\nvcoproc.bin
2013-11-19 03:33 - 2013-11-29 15:52 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-01 16:14

==================== End Of Log ============================
         
--- --- ---

--- --- ---
aAdditional scan result of Farbar Recovery Scan Tool (x64) Version: 17-12-2013 02
Ran by Gotthard Bienias at 2013-12-18 05:33:46
Running from C:\Users\Gotthard Bienias\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}

==================== Installed Programs ======================

7-Zip 9.22 (x64 edition) (Version: 9.22.00.0)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Canon Easy-PhotoPrint EX (x32)
Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data (x32)
Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data (x32)
Canon Easy-PhotoPrint Pro (x32)
Canon MG6100 series Benutzerregistrierung (x32)
Canon MG6100 series MP Drivers
Canon MP Navigator EX 4.0 (x32)
Canon My Printer (x32)
Canon Solution Menu EX (x32)
CCleaner (Version: 4.08)
CD-LabelPrint (x32)
Driver Genius (x32 Version: 12.0)
ESN Sonar (x32 Version: 0.70.4)
Free YouTube Download version 3.2.17.1125 (x32 Version: 3.2.17.1125)
Free YouTube to MP3 Converter version 3.12.17.1125 (x32 Version: 3.12.17.1125)
GeForce Experience NvStream Client Components (Version: 1.6.28)
Google Chrome (x32 Version: 31.0.1650.63)
Google Update Helper (x32 Version: 1.3.22.3)
ImagXpress (x32 Version: 7.0.74.0)
Intel(R) Network Connections 18.6.110.0 (Version: 18.6.110.0)
Intel(R) Rapid Storage Technology (Version: 12.8.2.1000)
Intel® Matrix Storage Manager
JMicron JMB36X Driver (x32 Version: 1.17.65.11)
Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938)
Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0)
Mozilla Maintenance Service (x32 Version: 26.0)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
neroxml (x32 Version: 1.0.0)
Neverwinter (x32)
NVIDIA 3D Vision Controller-Treiber 331.93 (Version: 331.93)
NVIDIA 3D Vision Treiber 331.93 (Version: 331.93)
NVIDIA GeForce Experience 1.8 (Version: 1.8)
NVIDIA Grafiktreiber 331.93 (Version: 331.93)
NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4)
NVIDIA Install Application (Version: 2.1002.142.992)
NVIDIA LED Visualizer 1.0 (Version: 1.0)
NVIDIA Network Service (Version: 1.0)
NVIDIA PhysX (x32 Version: 9.13.0725)
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725)
NVIDIA ShadowPlay 10.10.5 (Version: 10.10.5)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3193)
NVIDIA Systemsteuerung 331.93 (Version: 331.93)
NVIDIA Update 10.10.5 (Version: 10.10.5)
NVIDIA Update Core (Version: 10.10.5)
NVIDIA Virtual Audio 1.2.12 (Version: 1.2.12)
OpenOffice 4.0.1 (x32 Version: 4.01.9714)
Origin (x32 Version: 9.3.11.2762)
PrivaZer (x32 Version: 2.6.3.0)
Realtek Card Reader (x32 Version: 6.2.9600.30169)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5874)
Samsung Kies3 (x32 Version: 3.2.13114.22)
Samsung SSD Magician (x32 Version: 3.1)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0)
SHIELD Streaming (Version: 1.6.75)
Steam (x32)
TuneUp Utilities 2013 (x32 Version: 13.0.4000.179)
TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.179)
Uplay (x32 Version: 4.0)
VC_CRT_x64 (Version: 1.02.0000)
VLC media player 2.1.2 (x32 Version: 2.1.2)

==================== Restore Points =========================

15-12-2013 17:11:18 Installed 7-Zip 9.22 (x64 edition)
17-12-2013 14:43:28 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
17-12-2013 14:43:41 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
17-12-2013 14:44:07 OpenOffice 4.0.1 wird installiert
17-12-2013 14:46:26 Windows Update

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {1140B751-F375-4466-B26C-82F43D6F7F63} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {3F3A6EDB-692B-4C45-B110-FF66FF08E864} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-12] (Adobe Systems Incorporated)
Task: {57D70009-4839-412A-B025-27CE37CDD900} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated)
Task: {8B9D54B2-C6E6-4372-918F-A7CCB5E619E4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.)
Task: {9A34391A-49EE-4577-A0E2-39337F74209A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.)
Task: {BC040C1D-8889-4397-81EF-94FD582829F2} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe [2013-12-10] (TuneUp Software)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-10-31 15:18 - 2013-10-31 15:18 - 03525687 _____ () C:\Program Files (x86)\PrivaZer\PrivaMenu3.dll
2012-08-17 21:39 - 2013-12-16 19:59 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll
2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
2013-12-06 06:26 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll
2013-12-06 06:26 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll
2013-12-06 06:26 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll
2013-12-06 06:26 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
2013-12-06 06:26 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E3C56885

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============

Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Microsoft PS/2-Maus
Description: Microsoft PS/2-Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/02/2013 06:19:04 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: bf4.exe, Version: 1.0.0.0, Zeitstempel: 0x527cfab6
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000009c7dced0
ID des fehlerhaften Prozesses: 0x13a4
Startzeit der fehlerhaften Anwendung: 0xbf4.exe0
Pfad der fehlerhaften Anwendung: bf4.exe1
Pfad des fehlerhaften Moduls: bf4.exe2
Berichtskennung: bf4.exe3

Error: (11/29/2013 03:48:24 PM) (Source: MsiInstaller) (User: meiner)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\GoogleUpdateHelper.msi


System errors:
=============
Error: (12/16/2013 07:32:58 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147024846.

Error: (12/16/2013 07:32:58 PM) (Source: Microsoft-Windows-Bits-Client) (User: NT-AUTORITÄT)
Description: Fehler beim Starten des BITS-Dienstes. Fehler: 2147942450.

Error: (12/15/2013 03:12:50 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (12/15/2013 03:12:50 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (12/12/2013 05:31:42 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "TuneUp Designerweiterung" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1083

Error: (12/10/2013 04:15:05 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden.

Error: (12/10/2013 04:15:04 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden.

Error: (12/10/2013 04:15:04 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden.

Error: (12/10/2013 04:15:03 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk6\DR10 gefunden.

Error: (12/08/2013 10:14:00 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068


Microsoft Office Sessions:
=========================
Error: (12/02/2013 06:19:04 AM) (Source: Application Error)(User: )
Description: bf4.exe1.0.0.0527cfab6unknown0.0.0.000000000c0000005000000009c7dced013a401ceef1b3a8c7096C:\Program Files (x86)\Origin Games\Battlefield 4\bf4.exeunknown421c3a5f-5b11-11e3-8422-90fba62b103b

Error: (11/29/2013 03:48:24 PM) (Source: MsiInstaller)(User: meiner)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL)


CodeIntegrity Errors:
===================================
Date: 2013-12-08 10:21:47.210
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 10:21:47.210
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 10:21:47.210
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 10:17:42.242
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 10:17:42.242
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 10:17:42.242
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 07:26:31.165
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 07:26:31.164
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 07:26:31.162
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

Date: 2013-12-08 07:20:22.741
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 24%
Total physical RAM: 8183.11 MB
Available physical RAM: 6206.64 MB
Total Pagefile: 16364.4 MB
Available Pagefile: 14042.31 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:119.24 GB) (Free:72.01 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive j: (Volume) (Fixed) (Total:931.51 GB) (Free:931.21 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 7596B406)
Partition 1: (Active) - (Size=119 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 7596B413)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================[/CODE]

Entschuldige meine Blödheit.Schreibe nicht soviel am PC.Ich hoffe ich habe jetzt alles richtig gemacht.DANKE


Alt 19.12.2013, 11:56   #6
schrauber
/// the machine
/// TB-Ausbilder
 

PC gekapert? - Standard

PC gekapert?



Alles sauber. Wie oben schon erklärt, aufpassen wo du was lädst, und aufpasen beim Installieren
__________________
--> PC gekapert?

Alt 19.12.2013, 15:34   #7
Gottel62
 
PC gekapert? - Standard

PC gekapert?



Danke

Alt 20.12.2013, 09:56   #8
schrauber
/// the machine
/// TB-Ausbilder
 

PC gekapert? - Standard

PC gekapert?



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 06.04.2017, 07:25   #9
Gottel62
 
PC gekapert? - Standard

Amazon Pishingmail



Hallo

Ich habe heute die in Umlauf befindliche Amazon DHLmail göffnet weil ich eine Lieferung erwarte.Habe dann mit MWB gescannt keine Bedrohungen gefunden.Dann habe ich mit Adwarecleaner gescannt und folgenden Key gefunden der sich nicht löschen lässt:HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}.Auch der Esetonlinescanner hat eine Datei gefunden und sie gelöscht.Nur weiß ich jetzt nicht ob ich verseucht bin oder nicht,da der Adwarecleaner den Regeintrag nicht löscht.Bitte um Eure professionelle Hilfe,Danke im voraus Gottel

Alt 06.04.2017, 14:43   #10
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
PC gekapert? - Standard

PC gekapert?



Bitte keine uralten Threads aufwärmen. Neues Anliegen => neuer Thread.
__________________
Logfiles bitte immer in CODE-Tags posten

Thema geschlossen

Themen zu PC gekapert?
64 bit, bitte um hilfe, dieselbe, dieselben, formatierte, gekapert, hilfe, home, langsam, malwarebytes, optional, probleme, pup optional, vermutung, win, win7



Ähnliche Themen: PC gekapert?


  1. Plötzlich unfassbar viele Spammails, wurde mein Account gekapert?
    Überwachung, Datenschutz und Spam - 03.08.2015 (2)
  2. Microsoft-Blog gekapert
    Nachrichten - 12.01.2014 (0)
  3. Windows 8.1: Nationzoom hat die Browser gekapert (nutze in erster Linie Firefox)
    Plagegeister aller Art und deren Bekämpfung - 17.12.2013 (9)
  4. Metasploit-Domain gekapert
    Nachrichten - 11.10.2013 (0)
  5. Win7 Dienste gekapert.
    Plagegeister aller Art und deren Bekämpfung - 10.08.2013 (9)
  6. Browser gekapert google wird auf isearch.avg weitergeleitet
    Log-Analyse und Auswertung - 20.02.2013 (21)
  7. Email und Ebayzugang gekapert - befürchte Virus auf meinem Rechner
    Log-Analyse und Auswertung - 10.02.2013 (24)
  8. Accounts des israelischen Vizepremiers von Hackern gekapert
    Nachrichten - 21.11.2012 (0)
  9. Rechner gekapert; wollen SFR 100.- für Deblockierung
    Log-Analyse und Auswertung - 28.08.2012 (15)
  10. Mailadresse gekapert, verschickt böse links
    Plagegeister aller Art und deren Bekämpfung - 03.04.2012 (0)
  11. rechner gekapert: mediashift.com + sirefef.ch + rootkit.kryptik.gx
    Plagegeister aller Art und deren Bekämpfung - 18.01.2012 (45)
  12. Opera/Firefox und Office (?) gekapert
    Log-Analyse und Auswertung - 13.04.2011 (27)
  13. PC gekapert, wird als Mailversender mißbraucht, Arbeitsplan ableiten
    Plagegeister aller Art und deren Bekämpfung - 27.01.2011 (24)
  14. Domain des Sicherheitsdienstleisters Secunia gekapert
    Nachrichten - 25.11.2010 (0)
  15. virenschutz gekapert - bagel?
    Log-Analyse und Auswertung - 04.03.2008 (9)
  16. Das Übliche... Startseite gekapert.
    Plagegeister aller Art und deren Bekämpfung - 14.02.2005 (3)
  17. Startseite gekapert, Trojaner werden wiederhergestellt
    Plagegeister aller Art und deren Bekämpfung - 17.11.2004 (4)

Zum Thema PC gekapert? - Hallo! Ich habe die Vermutung das mein PC gekapert worden ist.Ich hatte Malwarebytes durchlaufen lassen und der fand mehrere PUP Optional Viren.Daraufhin formatierte ich meinen Pc und nach der Neuaufspielung - PC gekapert?...
Archiv
Du betrachtest: PC gekapert? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.