Hallo hatte inzwischen das Problem mit dem Spiel erneut nachdem ich das Log mit Malwarebytes Anti-Malware erstellt hab...
Hier die Logs :): Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 25.04.2015
Suchlauf-Zeit: 19:30:59
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.03.09.05
Rootkit Datenbank: v2015.04.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Felix
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 359867
Verstrichene Zeit: 14 Min, 18 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 10
Backdoor.Bot, C:\Users\Felix\Downloads\Audacity - CHIP-Installer.exe, In Quarantäne, [a4d584bf088257dfff0a412c817f7c84],
PUP.Optional.Downloader, C:\Users\Felix\Downloads\SketchUp Make 2014 - CHIP-Installer.exe, In Quarantäne, [f1889aa90f7b979f168a8eddc63a748c],
PUP.Optional.Giga, C:\Users\Felix\Downloads\Sniper_-Ghost-Warrior-lnstall.exe, In Quarantäne, [4633fd465832ed492aa7586d877ec23e],
PUP.Optional.Downloader, C:\Users\Felix\Downloads\System Explorer - CHIP-Installer.exe, In Quarantäne, [ff7ae261d3b7a88e4e527eedd72946ba],
Backdoor.Bot, C:\Users\Felix\Downloads\Avidemux 32 Bit - CHIP-Installer.exe, In Quarantäne, [55244ff4d3b7ea4c46c3e786df21c23e],
Backdoor.Bot, C:\Users\Felix\Downloads\ChemSketch - CHIP-Installer.exe, In Quarantäne, [e9908fb4addd75c1d03991dce31d2ad6],
PUP.Optional.Downloader, C:\Users\Felix\Downloads\TCPView - CHIP-Installer.exe, In Quarantäne, [1465fc47bfcb44f21b855813e41c827e],
Backdoor.Bot, C:\Users\Felix\Downloads\VSDC Free Video Editor - CHIP-Installer.exe, In Quarantäne, [dd9c46fd82089b9b9e6b96d7b05027d9],
Backdoor.Bot, C:\Users\Felix\Downloads\Pinnacle VideoSpin - CHIP-Installer.exe, In Quarantäne, [98e184bf1d6d181ea1682c4104fc3ec2],
Backdoor.Bot, C:\Users\Mama\Downloads\Grewe Scanner Interface - CHIP-Downloader.exe, In Quarantäne, [de9b0340494139fdcc3d224b5fa1cb35],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.202 - Bericht erstellt 25/04/2015 um 20:46:50
# Aktualisiert 23/04/2015 von Xplode
# Datenbank : 2015-04-23.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : Felix - FELIX-PC
# Gestarted von : C:\Users\Felix\Downloads\AdwCleaner_4.202.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\shd4rn04.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\Mama\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\user.js
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\YourFileDownloader
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v37.0.2 (x86 de)
-\\ Google Chrome v42.0.2311.90
-\\ Chromium v
*************************
AdwCleaner[R0].txt - [2454 Bytes] - [25/04/2015 20:45:37]
AdwCleaner[S0].txt - [2374 Bytes] - [25/04/2015 20:46:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2433 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.3 (04.25.2015:1)
OS: Windows 7 Home Premium x86
Ran by Felix on 25.04.2015 at 20:54:43,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\Windows\System32\tasks\Driver Booster SkipUAC (Felix)
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Felix\AppData\Roaming\mozilla\firefox\profiles\bclv7j5u.default\extensions\toolbar@gmx.net
Emptied folder: C:\Users\Felix\AppData\Roaming\mozilla\firefox\profiles\bclv7j5u.default\minidumps [52 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.04.2015 at 20:56:46,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-04-2015 01
Ran by Felix (administrator) on FELIX-PC on 25-04-2015 20:58:11
Running from C:\Users\Felix\Desktop\Sonstiges
Loaded Profiles: Felix (Available profiles: Felix & Mama)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Mister Group) C:\Program Files\System Explorer\SystemExplorer.exe
(Mister Group) C:\Program Files\System Explorer\service\SystemExplorerService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\officeclicktorun.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-07-16] (Realtek Semiconductor)
HKLM\...\Run: [SystemExplorerAutoStart] => C:\Program Files\System Explorer\SystemExplorer.exe [3385192 2014-09-15] (Mister Group)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKU\S-1-5-21-568113160-3411366880-767183668-1000\...\MountPoints2: {9213f2ca-c2ef-11e3-9c7a-806e6f6e6963} - E:\autorun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-04-14] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-568113160-3411366880-767183668-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aldi.com/
HKU\S-1-5-21-568113160-3411366880-767183668-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/
HKU\S-1-5-21-568113160-3411366880-767183668-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://medion.msn.com/
HKU\S-1-5-21-568113160-3411366880-767183668-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-568113160-3411366880-767183668-1000 -> {B4971287-645C-483C-AEAB-F12DDD011522} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-27] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-02-10] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-27] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-568113160-3411366880-767183668-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_67-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0067-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_67-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_67-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-08] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default
FF Homepage: https://www.google.at/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2009-07-21] (Adobe Systems, Inc.)
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-03-26] (CANON INC.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-27] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll [2014-02-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.4 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2009-06-09] (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-04-13] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\englische-ergebnisse.xml [2014-04-13]
FF SearchPlugin: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\gmx-suche-sterreich.xml [2014-04-13]
FF SearchPlugin: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\gmx-suche.xml [2014-04-13]
FF SearchPlugin: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\google-images.xml [2014-09-20]
FF SearchPlugin: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\google-maps.xml [2014-09-20]
FF SearchPlugin: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\lastminute.xml [2014-04-13]
FF SearchPlugin: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\searchplugins\webde-suche.xml [2014-04-13]
FF Extension: Adblock Plus - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-13]
FF HKU\S-1-5-21-568113160-3411366880-767183668-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
FF HKU\S-1-5-21-568113160-3411366880-767183668-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\bclv7j5u.default\extensions\cliqz@cliqz.com
Chrome:
=======
CHR Profile: C:\Users\Felix\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Felix\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-25]
CHR Extension: (Google Drive) - C:\Users\Felix\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-25]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Felix\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-19]
CHR Extension: (Google Wallet) - C:\Users\Felix\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-11]
CHR Extension: (Gmail) - C:\Users\Felix\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-25]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [1843896 2015-02-10] (Microsoft Corporation)
S4 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [17536800 2014-07-25] (NVIDIA Corporation)
S2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2014-04-14] ()
S2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] ()
R3 SystemExplorerHelpService; C:\Program Files\System Explorer\service\SystemExplorerService.exe [567144 2014-08-13] (Mister Group)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2001-11-12] (X10) [File not signed]
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19232 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2014-03-31] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-07-30] (NXP Semiconductors Germany GmbH)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13720 2009-05-13] (X10 Wireless Technology, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27160 2009-05-13] (X10 Wireless Technology, Inc.)
S3 WinRing0_1_2_0; \??\C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-25 20:56 - 2015-04-25 20:56 - 00000953 _____ () C:\Users\Felix\Desktop\JRT.txt
2015-04-25 20:54 - 2015-04-25 20:54 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-FELIX-PC-Windows-7-Home-Premium-(32-bit).dat
2015-04-25 20:54 - 2015-04-25 20:54 - 00000000 ____D () C:\RegBackup
2015-04-25 20:53 - 2015-04-25 20:53 - 02686590 _____ (Thisisu) C:\Users\Felix\Desktop\JRT.exe
2015-04-25 20:51 - 2015-04-25 20:51 - 00002508 _____ () C:\Users\Felix\Desktop\mbam.txt
2015-04-25 20:50 - 2015-04-25 20:50 - 00002513 _____ () C:\Users\Felix\Desktop\AdwCleaner[S0].txt
2015-04-25 20:45 - 2015-04-25 20:46 - 00000000 ____D () C:\AdwCleaner
2015-04-25 20:45 - 2015-04-25 20:45 - 02224640 _____ () C:\Users\Felix\Downloads\AdwCleaner_4.202.exe
2015-04-25 20:41 - 2015-04-25 20:41 - 00368512 _____ () C:\Windows\Minidump\042515-16848-01.dmp
2015-04-25 20:11 - 2015-04-25 20:11 - 00251760 _____ () C:\Windows\Minidump\042515-16239-01.dmp
2015-04-25 19:30 - 2015-04-25 19:30 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-25 19:27 - 2015-04-25 19:30 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Felix\Downloads\mbam-setup-2.1.6.1022.exe
2015-04-24 18:08 - 2015-04-24 18:14 - 00000000 ____D () C:\Users\Mama\Desktop\Musik
2015-04-23 20:48 - 2015-04-24 18:36 - 00008817 _____ () C:\Users\Mama\FreeYouTubeToMP3Converter.xml
2015-04-23 20:48 - 2015-04-23 20:48 - 00000008 _____ () C:\Users\Mama\FreeYouTubeToMP3Converter.xml.lck
2015-04-23 20:32 - 2015-04-24 18:26 - 00000243 _____ () C:\Users\Mama\updhelper.xml
2015-04-23 20:32 - 2015-04-23 20:32 - 00000210 _____ () C:\Users\Mama\FreeYTVDownloader.xml
2015-04-23 20:32 - 2015-04-23 20:32 - 00000008 _____ () C:\Users\Mama\updhelper.xml.lck
2015-04-23 20:32 - 2015-04-23 20:32 - 00000008 _____ () C:\Users\Mama\FreeYTVDownloader.xml.lck
2015-04-23 20:29 - 2015-04-23 20:30 - 00000000 ____D () C:\Users\Mama\AppData\Local\NVIDIA Corporation
2015-04-23 20:29 - 2015-04-23 20:29 - 00000000 ____D () C:\Users\Mama\AppData\Local\NVIDIA
2015-04-23 14:18 - 2015-04-25 20:58 - 00000000 ____D () C:\FRST
2015-04-22 21:51 - 2015-04-22 21:51 - 00007597 _____ () C:\Users\Felix\AppData\Local\Resmon.ResmonCfg
2015-04-22 21:47 - 2015-04-22 21:47 - 00666344 _____ () C:\Windows\Minidump\042215-11778-01.dmp
2015-04-22 21:33 - 2015-04-22 21:33 - 00375712 _____ () C:\Windows\Minidump\042215-16972-01.dmp
2015-04-22 19:59 - 2015-04-22 20:00 - 00407272 _____ () C:\Windows\Minidump\042215-17565-01.dmp
2015-04-22 19:46 - 2015-04-23 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-04-22 19:46 - 2015-04-22 19:46 - 00000000 ____D () C:\Users\Felix\AppData\Local\NVIDIA Corporation
2015-04-22 19:46 - 2015-04-22 19:46 - 00000000 ____D () C:\Users\Felix\AppData\Local\NVIDIA
2015-04-22 19:46 - 2015-04-22 19:46 - 00000000 ____D () C:\Program Files\AGEIA Technologies
2015-04-22 19:46 - 2014-07-25 16:01 - 01291280 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge.dll
2015-04-22 19:46 - 2014-07-25 16:01 - 01126480 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap.dll
2015-04-22 19:45 - 2014-07-02 07:14 - 03826628 _____ () C:\Windows\system32\nvcoproc.bin
2015-04-22 19:43 - 2014-08-11 22:19 - 00162592 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda32v.sys
2015-04-22 19:43 - 2014-08-11 22:19 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap32.dll
2015-04-22 19:43 - 2014-07-02 22:54 - 01054552 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234052.dll
2015-04-22 19:43 - 2014-07-02 22:54 - 00907552 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234052.dll
2015-04-22 19:43 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2015-04-22 19:43 - 2014-03-31 18:42 - 00034080 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2015-04-22 19:42 - 2015-04-22 19:42 - 00000000 ____D () C:\NVIDIA
2015-04-22 19:17 - 2015-04-22 19:42 - 218685256 _____ (NVIDIA Corporation) C:\Users\Felix\Downloads\340.52-desktop-win8-win7-winvista-32bit-international-whql.exe
2015-04-22 19:08 - 2015-04-22 19:08 - 00411576 _____ () C:\Windows\Minidump\042215-18626-01.dmp
2015-04-22 18:41 - 2015-04-22 18:41 - 00003288 ____N () C:\bootsqm.dat
2015-04-22 18:35 - 2015-04-22 18:35 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA%
2015-04-21 20:52 - 2015-04-21 20:53 - 00477385 ____H () C:\Users\Mama\Desktop\Cache.mxc3
2015-04-20 15:49 - 2015-04-20 16:01 - 34736426 _____ () C:\Users\Felix\Downloads\torbrowser-install-4.0.8_de.exe
2015-04-17 16:33 - 2015-04-17 16:33 - 00000000 ____D () C:\Users\Felix\Tracing
2015-04-16 21:11 - 2015-04-21 20:52 - 00000000 ____D () C:\Users\Mama\Desktop\ordner1
2015-04-08 20:18 - 2015-04-08 20:19 - 00004030 _____ () C:\Users\Felix\Desktop\Neues Textdokument (3).txt
2015-04-01 17:11 - 2015-04-01 17:22 - 00000000 ____D () C:\Users\Felix\Desktop\ordner2
2015-03-29 17:37 - 2015-03-29 17:37 - 00000000 ____D () C:\Users\Felix\AppData\Local\CrashDumps
2015-03-27 19:15 - 2015-03-28 13:30 - 00000751 _____ () C:\Users\Felix\Desktop\Neues Textdokument (2).txt
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-25 20:58 - 2014-04-29 15:22 - 00000000 ____D () C:\Users\Felix\Desktop\Sonstiges
2015-04-25 20:55 - 2009-07-14 06:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-25 20:55 - 2009-07-14 06:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-25 20:53 - 2014-06-08 22:33 - 00000601 _____ () C:\Users\Felix\Documents\grstyles.stl
2015-04-25 20:53 - 2009-09-24 16:43 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-25 20:50 - 2014-07-03 13:30 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-25 20:47 - 2015-03-01 13:10 - 00011211 _____ () C:\Windows\setupact.log
2015-04-25 20:47 - 2014-06-25 21:21 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-25 20:47 - 2014-06-25 21:21 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-25 20:47 - 2009-10-22 15:46 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-25 20:47 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-25 20:46 - 2014-04-13 11:50 - 01325935 _____ () C:\Windows\WindowsUpdate.log
2015-04-25 20:41 - 2015-03-02 19:11 - 345096064 _____ () C:\Windows\MEMORY.DMP
2015-04-25 20:41 - 2014-05-12 17:57 - 00000000 ____D () C:\Windows\Minidump
2015-04-25 20:29 - 2014-06-21 14:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-25 20:14 - 2014-04-14 12:45 - 00283032 _____ () C:\Windows\system32\PnkBstrB.xtr
2015-04-25 20:14 - 2014-04-14 08:45 - 00283032 _____ () C:\Windows\system32\PnkBstrB.exe
2015-04-25 20:14 - 2014-04-14 08:45 - 00140360 _____ () C:\Windows\system32\Drivers\PnkBstrK.sys
2015-04-25 20:11 - 2015-03-19 14:24 - 00009468 _____ () C:\Windows\PFRO.log
2015-04-25 19:58 - 2014-04-14 08:45 - 00283032 _____ () C:\Windows\system32\PnkBstrB.ex0
2015-04-25 19:56 - 2014-04-13 13:00 - 00000000 ___RD () C:\Users\Felix\Desktop\Musik
2015-04-25 19:48 - 2014-04-13 12:01 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-25 19:48 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Cursors
2015-04-25 19:43 - 2014-08-07 20:30 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Skype
2015-04-25 19:30 - 2014-07-03 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-25 19:30 - 2014-07-03 13:29 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-24 18:06 - 2014-06-05 19:57 - 00000000 ____D () C:\Users\Mama\Documents\DVDVideoSoft
2015-04-24 16:21 - 2014-04-13 12:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-23 20:48 - 2014-04-16 21:34 - 00000000 ____D () C:\Users\Mama
2015-04-23 20:30 - 2014-09-27 09:42 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-04-22 21:58 - 2014-04-13 18:00 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-04-22 19:46 - 2009-10-22 14:23 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2015-04-21 20:53 - 2014-09-27 15:33 - 00000000 ____D () C:\Users\Mama\Desktop\Minecraft backup 2
2015-04-21 20:53 - 2014-09-27 13:22 - 00000000 ____D () C:\Users\Mama\Desktop\versions
2015-04-21 20:53 - 2014-05-26 17:02 - 00000000 ____D () C:\Users\Mama\Desktop\ordner
2015-04-21 20:52 - 2014-10-02 17:10 - 00000000 ____D () C:\Users\Mama\Desktop\LB Photo Realism x256 10.0.0-converted-1374012707213
2015-04-21 20:52 - 2014-09-27 15:59 - 00000000 ____D () C:\Users\Mama\Desktop\DIM-1 360 Mining
2015-04-21 20:52 - 2014-09-27 13:15 - 00000000 ____D () C:\Users\Mama\Desktop\Minecraft backup
2015-04-21 20:43 - 2014-06-05 19:57 - 00000000 ____D () C:\Users\Mama\AppData\Roaming\DVDVideoSoft
2015-04-21 18:10 - 2014-06-08 19:52 - 00000007 _____ () C:\Users\Felix\Documents\LastLab.sk
2015-04-21 17:32 - 2014-04-14 16:43 - 00000000 ___RD () C:\Users\Felix\Desktop\ordner3
2015-04-21 14:25 - 2014-06-08 19:40 - 00000644 _____ () C:\Users\Felix\Documents\UserStl.sk
2015-04-20 16:05 - 2014-10-20 12:46 - 00000000 ____D () C:\Users\Felix\Desktop\Tor Browser
2015-04-17 16:33 - 2014-09-21 12:57 - 00000000 ___RD () C:\Program Files\Skype
2015-04-17 16:33 - 2014-08-07 20:30 - 00000000 ____D () C:\ProgramData\Skype
2015-04-17 16:33 - 2014-04-13 11:51 - 00000000 ____D () C:\Users\Felix
2015-04-16 21:13 - 2014-08-05 20:04 - 00000000 ____D () C:\Users\Mama\Desktop\ordner4
2015-04-15 16:31 - 2014-06-21 14:14 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 16:31 - 2014-06-21 14:14 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-14 14:40 - 2015-03-18 16:36 - 00000000 ____D () C:\Users\Felix\Desktop\ordner5
2015-04-14 09:37 - 2014-07-03 13:29 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-14 09:37 - 2014-07-03 13:29 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-14 09:37 - 2014-07-03 13:29 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-13 21:01 - 2014-09-08 13:00 - 00000000 ____D () C:\Users\Felix\Desktop\ordner6
2015-04-08 18:59 - 2015-03-14 15:55 - 00000000 ____D () C:\Users\Felix\Desktop\ordner7
==================== Files in the root of some directories =======
2014-04-14 08:45 - 2014-04-14 08:45 - 0138056 _____ () C:\Users\Felix\AppData\Roaming\PnkBstrK.sys
2015-04-22 21:51 - 2015-04-22 21:51 - 0007597 _____ () C:\Users\Felix\AppData\Local\Resmon.ResmonCfg
2014-04-13 18:02 - 2014-04-13 18:02 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\Felix\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Felix\AppData\Local\Temp\nvStInst.exe
C:\Users\Felix\AppData\Local\Temp\Quarantine.exe
C:\Users\Felix\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Felix\AppData\Local\Temp\sqlite3.dll
C:\Users\Felix\AppData\Local\Temp\tmd_34012365.exe
C:\Users\Felix\AppData\Local\Temp\tmd_34014686.exe
C:\Users\Felix\AppData\Local\Temp\tmd_34016589.exe
C:\Users\Mama\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Mama\AppData\Local\Temp\tmd_34014881.exe
C:\Users\Mama\AppData\Local\Temp\tmd_34015620.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-13 22:11
==================== End Of Log ============================ --- --- ---
--- --- --- |