madebygreece | 01.10.2013 15:27 | adw 1. adwcleaner *mein Rechner wurde allerdings nicht neu gestartet, adwcleaner ist sogar 2 mal hängen geblieben.
AdwCleaner Logfile: Code:
# AdwCleaner v3.006 - Bericht erstellt am 01/10/2013 um 15:57:51
# Updated 01/10/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : nextlevel - HOMESWEETHOME
# Gestartet von : C:\Users\nextlevel\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\jetpack
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Mozilla Firefox v24.0 (de)
[ Datei : C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [20429 octets] - [01/10/2013 09:26:02]
AdwCleaner[R1].txt - [1595 octets] - [01/10/2013 09:45:14]
AdwCleaner[R2].txt - [1653 octets] - [01/10/2013 15:53:07]
AdwCleaner[R3].txt - [1222 octets] - [01/10/2013 15:57:28]
AdwCleaner[S0].txt - [19979 octets] - [01/10/2013 09:41:12]
AdwCleaner[S1].txt - [1716 octets] - [01/10/2013 15:55:26]
AdwCleaner[S2].txt - [1146 octets] - [01/10/2013 15:57:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1206 octets] ########## --- --- --- CFix Code:
ComboFix 13-09-30.02 - nextlevel 01.10.2013 16:09:47.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.5996.3824 [GMT 2:00]
ausgeführt von:: c:\users\nextlevel\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\nextlevel\AppData\Local\assembly\tmp
c:\users\nextlevel\AppData\Roaming\Roaming
c:\users\nextlevel\AppData\Roaming\Roaming\HoldemManager\config\FTPRushTables.xml
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-09-01 bis 2013-10-01 ))))))))))))))))))))))))))))))
.
.
2013-10-01 13:33 . 2013-10-01 13:33 -------- d-----w- C:\FRST
2013-10-01 12:23 . 2013-10-01 12:23 -------- d-----w- C:\TDSSKiller_Quarantine
2013-10-01 11:01 . 2013-10-01 11:01 -------- d-----w- c:\users\nextlevel\AppData\Roaming\AVG
2013-10-01 11:00 . 2013-10-01 11:04 -------- d-----w- c:\programdata\AVG
2013-10-01 10:58 . 2013-10-01 11:16 -------- d-sh--w- c:\programdata\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-10-01 09:16 . 2013-10-01 09:16 -------- d-----w- c:\users\nextlevel\AppData\Roaming\TrojanHunter
2013-10-01 08:53 . 2013-10-01 09:17 -------- d-----w- c:\program files (x86)\TrojanHunter 5.5
2013-10-01 07:49 . 2013-10-01 07:49 -------- d-----w- c:\users\nextlevel\AppData\Roaming\Malwarebytes
2013-10-01 07:49 . 2013-10-01 07:49 -------- d-----w- c:\programdata\Malwarebytes
2013-10-01 07:49 . 2013-10-01 07:49 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-10-01 07:49 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-10-01 07:25 . 2013-10-01 13:57 -------- d-----w- C:\AdwCleaner
2013-09-30 15:01 . 2013-09-30 15:01 -------- d-----w- c:\windows\SysWow64\NV
2013-09-30 15:01 . 2013-09-30 15:01 -------- d-----w- c:\windows\system32\NV
2013-09-30 14:54 . 2012-10-02 19:51 3536817 ----a-w- c:\windows\system32\nvcoproc.bin
2013-09-30 14:54 . 2012-10-02 19:51 3293544 ----a-w- c:\windows\system32\nvsvc64.dll
2013-09-30 14:54 . 2012-10-02 19:51 6200680 ----a-w- c:\windows\system32\nvcpl.dll
2013-09-30 14:54 . 2012-10-02 19:50 891240 ----a-w- c:\windows\system32\nvvsvc.exe
2013-09-30 14:54 . 2012-10-02 19:50 866664 ----a-w- c:\windows\system32\nv3dappshext.dll
2013-09-30 14:54 . 2012-10-02 19:50 63336 ----a-w- c:\windows\system32\nvshext.dll
2013-09-30 14:54 . 2012-10-02 19:50 55144 ----a-w- c:\windows\system32\nv3dappshextr.dll
2013-09-30 14:54 . 2012-10-02 19:50 2557800 ----a-w- c:\windows\system32\nvsvcr.dll
2013-09-30 14:54 . 2012-10-02 19:50 118120 ----a-w- c:\windows\system32\nvmctray.dll
2013-09-27 18:32 . 2012-10-08 09:42 60776 ----a-w- c:\windows\system32\OpenCL.dll
2013-09-27 18:32 . 2012-10-08 09:42 52584 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-09-27 17:33 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll
2013-09-27 17:32 . 2013-08-02 02:12 6656 ----a-w- c:\windows\system32\apisetschema.dll
2013-09-27 14:01 . 2011-05-08 05:37 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2013-09-27 14:01 . 2011-05-08 05:37 568832 ----a-w- c:\windows\SysWow64\msvcp90.dll
2013-09-27 14:01 . 2011-05-08 05:37 224768 ----a-w- c:\windows\SysWow64\msvcm90.dll
2013-09-27 14:01 . 2006-05-02 00:33 53248 ----a-w- c:\windows\SysWow64\CommonDL.dll
2013-09-27 14:01 . 2013-09-27 14:04 -------- d-----w- c:\programdata\LGMOBILEAX
2013-09-27 13:42 . 2013-09-27 16:49 -------- d-----w- c:\users\nextlevel\AppData\Roaming\LG Electronics
2013-09-11 09:40 . 2013-09-11 09:40 -------- d-----w- c:\users\nextlevel\AppData\Local\Apps
2013-09-11 09:38 . 2013-09-11 09:38 -------- d-----w- c:\users\nextlevel\AppData\Roaming\HomeMedia
2013-09-11 06:27 . 2013-09-11 06:29 -------- d--h--w- c:\windows\Icons
2013-09-11 05:43 . 2006-09-30 09:36 13008 ----a-w- c:\windows\system32\drivers\pstrip64.sys
2013-09-11 05:00 . 2013-08-20 13:33 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-09-11 05:00 . 2013-08-20 13:32 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-09-11 05:00 . 2013-08-20 13:32 28448 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-09-11 04:59 . 2013-09-11 04:59 -------- d-----w- c:\users\nextlevel\AppData\Local\NVIDIA
2013-09-11 04:49 . 2013-09-30 15:01 -------- d-----w- c:\programdata\NVIDIA
2013-09-11 04:49 . 2013-09-11 04:49 -------- d-----w- c:\users\UpdatusUser
2013-09-11 04:49 . 2013-09-11 04:49 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2013-09-11 04:48 . 2013-09-30 14:52 -------- d-----w- c:\programdata\NVIDIA Corporation
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-28 06:34 . 2012-11-08 20:00 46368 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2013-09-11 07:56 . 2012-06-03 14:37 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-09-11 07:56 . 2012-01-21 23:35 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-01 15:08 . 2012-01-22 00:59 79143768 ----a-w- c:\windows\system32\MRT.exe
2013-08-02 01:48 . 2013-09-27 17:33 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-04-30 284440]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-03-14 1081424]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"Dolby Home Theater v4"="c:\dolby pcee4\pcee4.exe" [2011-02-03 506712]
"AVG_TRAY"="p:\avg2012\avgtray.exe" [2012-11-19 2598520]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-3-9 1137440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0p:\avg2012\avgrsa.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"GrooveMonitor"="p:\microsoft office2007\Office12\GrooveMonitor.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Babylon Client"=p:\babylon\Babylon.exe -AutoStart
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandbus64.sys [x]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lganddiag64.sys [x]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandgps64.sys [x]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandmodem64.sys [x]
R3 andnetadb;ADB Interface DriverNet;c:\windows\system32\Drivers\lgandnetadb.sys;c:\windows\SYSNATIVE\Drivers\lgandnetadb.sys [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
R3 cleanhlp;cleanhlp;p:\eek\RUN\cleanhlp64.sys;p:\eek\RUN\cleanhlp64.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R4 GREGService;GREGService;c:\program files (x86)\Packard Bell\Registration\GREGsvc.exe;c:\program files (x86)\Packard Bell\Registration\GREGsvc.exe [x]
R4 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R4 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe;c:\program files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe [x]
R4 SkypeUpdate;Skype Updater;p:\skype\Updater\Updater.exe;p:\skype\Updater\Updater.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S2 AdobeActiveFileMonitor9.0;Adobe Active File Monitor V9;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe [x]
S2 AVGIDSAgent;AVGIDSAgent;p:\avg2012\AVGIDSAgent.exe;p:\avg2012\AVGIDSAgent.exe [x]
S2 avgwd;AVG WatchDog;p:\avg2012\avgwdsvc.exe;p:\avg2012\avgwdsvc.exe [x]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe;c:\windows\SYSNATIVE\CxAudMsg64.exe [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Live Updater Service;Live Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 postgresql-8.4;PostgreSQL Server 8.4;C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 -D C:/Program Files (x86)/PostgreSQL/8.4/data -w;C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 -D C:/Program Files (x86)/PostgreSQL/8.4/data -w [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsfiltera.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-30 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-30 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-30 418840]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"Power Management"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerTray.exe" [2011-05-10 1831528]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.sparkasse-leipzig.de/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Nach Microsoft E&xel exportieren - p:\micros~1\Office12\EXCEL.EXE/3000
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\
FF - prefs.js: browser.startup.homepage - about:blank
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
SafeBoot-86412215.sys
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:83,04,d7,df,57,26,cd,01
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Launch Manager\LMworker.exe
c:\program files (x86)\Launch Manager\LMutilps32.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.4\bin\postgres.exe
c:\windows\SysWOW64\RunDll32.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-10-01 16:22:28 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2013-10-01 14:22
.
Vor Suchlauf: 11 Verzeichnis(se), 263.550.803.968 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 263.437.537.280 Bytes frei
.
- - End Of File - - E83340DB85306AF15F420E61EFF0266F FRST
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2013 02
Ran by nextlevel (administrator) on HOMESWEETHOME on 01-10-2013 16:24:57
Running from C:\Users\nextlevel\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) P:\AVG2012\avgrsa.exe
(AVG Technologies CZ, s.r.o.) P:\AVG2012\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(AVG Technologies CZ, s.r.o.) P:\AVG2012\avgwdsvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(AVG Technologies CZ, s.r.o.) P:\AVG2012\AVGIDSAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(AVG Technologies CZ, s.r.o.) P:\AVG2012\avgtray.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) P:\mozilla firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] ()
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2723624 2011-03-28] (Synaptics Incorporated)
HKLM\...\Run: [Power Management] - C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [1831528 2011-05-10] (Acer Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [AVG_TRAY] - P:\AVG2012\avgtray.exe [2598520 2012-11-19] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe [154144 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe [154144 2010-07-29] ()
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation)
BootExecute: autocheck autochk * P:\AVG2012\avgrsa.exe /sync /restart
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.sparkasse-leipzig.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=APBTDF&pc=MAPB&src=IE-SearchBox
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - P:\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HistoryTriggerBHO Class - {21A88CB9-84D2-4020-A2D1-B25A21034884} - P:\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - P:\Microsoft Office2007\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.80.2.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - P:\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - P:\Microsoft Office2007\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - P:\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default
FF Homepage: about:blank
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.4.1 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.4.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\searchplugins\samuraifm--new-music-generation.xml
FF SearchPlugin: C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\searchplugins\soundcloud---hear-the-worlds-sounds.xml
FF SearchPlugin: C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\searchplugins\youtube.xml
FF Extension: Battlefield Play4Free - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\battlefieldplay4free@ea.com
FF Extension: Fast Dial - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\fastdial@telega.phpnet.us
FF Extension: No Name - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\foxsplitter@piro.sakura.ne.jp
FF Extension: No Name - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\weidunewtab@gmail.com
FF Extension: No Name - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF Extension: Block site - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
FF Extension: add-to-searchbox - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\add-to-searchbox@maltekraus.de.xpi
FF Extension: GlassMyFox - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\GlassMyFox@ArisT2_Noia4dev.xpi
FF Extension: jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
FF Extension: jid0-t3eeRQgGANLCH9c50lPqcTDuNng - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\jid0-t3eeRQgGANLCH9c50lPqcTDuNng@jetpack.xpi
FF Extension: translator - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\translator@zoli.bod.xpi
FF Extension: UIEnhancer - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\UIEnhancer@girishsharma.xpi
FF Extension: No Name - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi
FF Extension: No Name - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi
FF Extension: No Name - C:\Users\nextlevel\AppData\Roaming\Mozilla\Firefox\Profiles\zk27amfr.default\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}.xpi
FF HKLM\...\Firefox\Extensions: [{FEFE89E5-A43F-4f4b-8211-B11D91D02135}] - C:\Program Files\CoolPic - Fun Social Pictures\Firefox
FF HKLM\...\Firefox\Extensions: [{14DD0E04-D4F6-45d2-A958-F361FBD4F64F}] - C:\Program Files\WBC Engine\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] - P:\AVG2012\Firefox4\
FF Extension: AVG Safe Search - P:\AVG2012\Firefox4\
FF HKLM-x32\...\Firefox\Extensions: [{FEFE89E5-A43F-4f4b-8211-B11D91D02135}] - C:\Program Files\CoolPic - Fun Social Pictures\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{14DD0E04-D4F6-45d2-A958-F361FBD4F64F}] - C:\Program Files\WBC Engine\Firefox
FF StartMenuInternet: FIREFOX.EXE - P:\mozilla firefox\firefox.exe
==================== Services (Whitelisted) =================
R2 AVGIDSAgent; P:\AVG2012\AVGIDSAgent.exe [5174392 2012-11-02] (AVG Technologies CZ, s.r.o.)
R2 avgwd; P:\AVG2012\avgwdsvc.exe [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [872552 2011-05-10] (Acer Incorporated)
S4 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [29696 2011-05-26] (Acer Incorporated)
R2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 Microsoft Office Groove Audit Service; P:\Microsoft Office2007\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S4 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [4573336 2013-04-07] (INCA Internet Co., Ltd.)
S4 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe [257344 2011-03-09] (NTI Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S4 SkypeUpdate; P:\skype\Updater\Updater.exe [160944 2012-07-13] (Skype Technologies)
R2 postgresql-8.4; C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files (x86)/PostgreSQL/8.4/data" -w [x]
==================== Drivers (Whitelisted) ====================
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2013-04-18] (Google Inc)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2013-06-28] (LG Electronics Inc.)
R3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [127328 2012-12-10] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [307040 2012-11-08] (AVG Technologies CZ, s.r.o.)
R1 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [384800 2013-04-11] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-09-28] (AVG Technologies)
S3 cleanhlp; P:\EEK\RUN\cleanhlp64.sys [57024 2013-08-20] (Emsisoft GmbH)
S3 cleanhlp; P:\EEK\RUN\cleanhlp64.sys [57024 2013-08-20] (Emsisoft GmbH)
R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 Andbus; system32\DRIVERS\lgandbus64.sys [x]
S3 AndDiag; system32\DRIVERS\lganddiag64.sys [x]
S3 AndGps; system32\DRIVERS\lgandgps64.sys [x]
S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [x]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 usbbus; system32\DRIVERS\lgx64bus.sys [x]
S3 UsbDiag; system32\DRIVERS\lgx64diag.sys [x]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [x]
S3 wanatw; system32\DRIVERS\wanatw64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-01 16:24 - 2013-10-01 16:24 - 00025653 _____ C:\Users\nextlevel\Desktop\CFix.txt
2013-10-01 16:22 - 2013-10-01 16:22 - 00025653 _____ C:\ComboFix.txt
2013-10-01 16:08 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-01 16:08 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-01 16:08 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-01 16:08 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-01 16:08 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-01 16:08 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-01 16:08 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-01 16:08 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-01 16:05 - 2013-10-01 16:22 - 00000000 ____D C:\Qoobox
2013-10-01 16:05 - 2013-10-01 16:21 - 00000000 ____D C:\Windows\erdnt
2013-10-01 16:04 - 2013-10-01 16:04 - 00002740 _____ C:\Users\nextlevel\Desktop\AdwCleaner[S2].txt
2013-10-01 16:03 - 2013-10-01 16:03 - 05131234 ____R (Swearware) C:\Users\nextlevel\Desktop\ComboFix.exe
2013-10-01 15:35 - 2013-10-01 15:36 - 00027442 _____ C:\Users\nextlevel\Downloads\Addition.txt
2013-10-01 15:33 - 2013-10-01 15:33 - 00000000 ____D C:\FRST
2013-10-01 15:32 - 2013-10-01 15:32 - 01953880 _____ (Farbar) C:\Users\nextlevel\Downloads\FRST64.exe
2013-10-01 14:27 - 2013-10-01 16:17 - 00000336 _____ C:\Windows\setupact.log
2013-10-01 14:27 - 2013-10-01 16:16 - 00002254 _____ C:\Windows\PFRO.log
2013-10-01 14:27 - 2013-10-01 14:27 - 00000000 _____ C:\Windows\setuperr.log
2013-10-01 14:23 - 2013-10-01 14:23 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-10-01 14:18 - 2013-10-01 14:18 - 04099283 _____ C:\Users\nextlevel\Downloads\tdsskiller-3.0.0.11.zip
2013-10-01 13:01 - 2013-10-01 13:01 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\AVG
2013-10-01 13:00 - 2013-10-01 13:04 - 00000000 ____D C:\ProgramData\AVG
2013-10-01 12:58 - 2013-10-01 13:16 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-10-01 12:56 - 2013-10-01 12:58 - 78411688 _____ (AVG) C:\Users\nextlevel\Downloads\avg_tuh_stf_all_2014_174_24c28.exe
2013-10-01 11:52 - 2013-10-01 15:16 - 00000000 ____D C:\Users\nextlevel\Desktop\fff
2013-10-01 11:24 - 2013-10-01 11:24 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2013-10-01 11:23 - 2013-10-01 11:23 - 00818001 _____ C:\Users\nextlevel\Downloads\Unlocker1.9.1-x64.exe
2013-10-01 11:16 - 2013-10-01 11:16 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\TrojanHunter
2013-10-01 11:12 - 2013-10-01 11:12 - 01188386 _____ C:\Users\nextlevel\Downloads\deletedr.exe
2013-10-01 10:53 - 2013-10-01 11:17 - 00000000 ____D C:\Program Files (x86)\TrojanHunter 5.5
2013-10-01 10:53 - 2013-10-01 10:53 - 05843488 _____ (Mischel Internet Security ) C:\Users\nextlevel\Downloads\TrojanHunterSetup_5.5_Build_1003.exe
2013-10-01 10:53 - 2013-10-01 10:53 - 00059392 ____R C:\Windows\SysWOW64\streamhlp.dll
2013-10-01 10:42 - 2013-10-01 10:42 - 00001310 _____ C:\Users\nextlevel\Desktop\Local - Verknüpfung.lnk
2013-10-01 09:49 - 2013-10-01 09:49 - 00001081 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\Malwarebytes
2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-01 09:49 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-01 09:48 - 2013-10-01 09:49 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\nextlevel\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-01 09:25 - 2013-10-01 15:57 - 00000000 ____D C:\AdwCleaner
2013-10-01 09:25 - 2013-10-01 09:25 - 01045226 _____ C:\Users\nextlevel\Downloads\adwcleaner.exe
2013-09-30 22:58 - 2013-09-30 22:58 - 00000521 _____ C:\Users\nextlevel\Desktop\Emsisoft Emergency Kit.lnk
2013-09-30 17:01 - 2013-09-30 17:01 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-09-30 17:01 - 2013-09-30 17:01 - 00000000 ____D C:\Windows\system32\NV
2013-09-30 16:54 - 2012-10-02 21:51 - 06200680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-09-30 16:54 - 2012-10-02 21:51 - 03536817 _____ C:\Windows\system32\nvcoproc.bin
2013-09-30 16:54 - 2012-10-02 21:51 - 03293544 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-09-30 16:54 - 2012-10-02 21:50 - 02557800 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-09-30 16:54 - 2012-10-02 21:50 - 00891240 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-09-30 16:54 - 2012-10-02 21:50 - 00866664 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2013-09-30 16:54 - 2012-10-02 21:50 - 00118120 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-09-30 16:54 - 2012-10-02 21:50 - 00063336 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-09-30 16:54 - 2012-10-02 21:50 - 00055144 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2013-09-27 20:32 - 2012-10-08 11:42 - 00060776 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2013-09-27 20:32 - 2012-10-08 11:42 - 00052584 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2013-09-27 19:50 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-27 19:50 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-27 19:50 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-27 19:50 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-27 19:50 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-27 19:50 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-27 19:50 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-27 19:50 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-27 19:50 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-27 19:50 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-27 19:50 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-27 19:50 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-27 19:50 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-27 19:50 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-27 19:47 - 2013-09-27 19:50 - 00000000 ____D C:\Windows\system32\MRT
2013-09-27 19:33 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-27 19:33 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-27 19:33 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-27 19:33 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-27 19:33 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-27 19:33 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-27 19:33 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-27 19:33 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-27 19:33 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-27 19:33 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-27 19:33 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-27 19:33 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-27 19:33 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-27 19:33 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-27 19:33 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-27 19:33 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-27 19:33 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-27 19:33 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-27 19:33 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-27 19:33 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-09-27 19:33 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-09-27 19:33 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-09-27 19:33 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-09-27 19:33 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-09-27 19:33 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-09-27 19:33 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-09-27 19:33 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-09-27 19:33 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-09-27 19:33 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-09-27 19:33 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-09-27 19:33 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-09-27 19:33 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-09-27 19:33 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-09-27 19:33 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-09-27 19:33 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-09-27 19:32 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-27 19:32 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-27 19:32 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-27 19:32 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-27 19:32 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-27 19:32 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-27 19:32 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-27 19:32 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-27 19:32 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-27 19:32 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-27 19:32 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-27 19:32 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-27 19:32 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-09-27 19:32 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-09-27 19:32 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-09-27 19:32 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-09-27 19:32 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-09-27 19:32 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-09-27 19:32 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-09-27 19:32 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-09-27 19:32 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-09-27 19:32 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-09-27 19:32 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-09-27 19:32 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-09-27 19:32 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-09-27 19:32 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-09-27 19:32 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-09-27 19:32 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-09-27 19:32 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-09-27 16:39 - 2013-09-27 16:39 - 00001585 _____ C:\Users\nextlevel\Desktop\Jwars - Verknüpfung.lnk
2013-09-27 16:21 - 2013-09-27 16:21 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_lgandnetadb_01005.Wdf
2013-09-27 16:01 - 2013-09-27 16:32 - 00002413 _____ C:\Windows\SysWOW64\lgAxconfig.ini
2013-09-27 16:01 - 2013-09-27 16:04 - 00000000 ____D C:\ProgramData\LGMOBILEAX
2013-09-27 16:01 - 2011-05-08 07:37 - 00655872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr90.dll
2013-09-27 16:01 - 2011-05-08 07:37 - 00568832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp90.dll
2013-09-27 16:01 - 2011-05-08 07:37 - 00224768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcm90.dll
2013-09-27 16:01 - 2006-05-02 02:33 - 00053248 _____ () C:\Windows\SysWOW64\CommonDL.dll
2013-09-27 15:48 - 2013-09-27 15:50 - 113013400 _____ (LG Electronics) C:\Users\nextlevel\Downloads\LG_PCSuiteIV_Setup.exe
2013-09-27 15:42 - 2013-09-27 18:49 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\LG Electronics
2013-09-27 15:34 - 2013-09-27 15:39 - 217689144 _____ (LG Electronics) C:\Users\nextlevel\Downloads\LGPCSuite_Setup.exe
2013-09-27 14:18 - 2013-09-27 14:24 - 00000000 ____D C:\Users\nextlevel\Desktop\dd
2013-09-23 17:08 - 2013-09-23 17:08 - 00000186 _____ C:\Users\nextlevel\Desktop\dds.txt
2013-09-11 11:40 - 2013-09-11 11:40 - 00000000 ____D C:\Users\nextlevel\AppData\Local\Apps\2.0
2013-09-11 11:38 - 2013-09-11 11:38 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\HomeMedia
2013-09-11 10:03 - 2013-09-11 10:03 - 01855072 _____ (Irfan Skiljan) C:\Users\nextlevel\Downloads\iview436_setup.exe
2013-09-11 08:27 - 2013-09-11 08:29 - 00000000 ___HD C:\Windows\Icons
2013-09-11 08:18 - 2013-09-11 08:16 - 00006761 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.bko
2013-09-11 08:16 - 2013-09-11 08:18 - 00006751 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.bak
2013-09-11 08:16 - 2013-09-11 08:15 - 00007381 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.bk!
2013-09-11 07:46 - 2013-09-11 08:20 - 00006891 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.ini
2013-09-11 07:43 - 2006-09-30 11:36 - 00013008 _____ C:\Windows\system32\Drivers\pstrip64.sys
2013-09-11 07:00 - 2013-08-20 15:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-09-11 07:00 - 2013-08-20 15:32 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-09-11 07:00 - 2013-08-20 15:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-09-11 06:59 - 2013-09-11 06:59 - 00000000 ____D C:\Users\nextlevel\AppData\Local\NVIDIA
2013-09-11 06:49 - 2013-09-30 17:01 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-11 06:49 - 2013-09-11 06:49 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-11 06:49 - 2013-01-31 14:30 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\TuneUp Software
2013-09-11 06:49 - 2012-01-27 09:01 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Microsoft Help
2013-09-11 06:49 - 2011-07-24 02:13 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Macromedia
2013-09-11 06:49 - 2009-07-14 06:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-09-11 06:49 - 2009-07-14 06:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-09-11 06:48 - 2013-09-30 16:52 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-09-11 06:34 - 2013-09-11 06:40 - 233871960 _____ (NVIDIA Corporation) C:\Users\nextlevel\Downloads\320.49-notebook-win8-win7-64bit-international-whql.exe
2013-09-10 03:59 - 2013-09-10 03:59 - 00000680 __RSH C:\Users\nextlevel\ntuser.pol
==================== One Month Modified Files and Folders =======
2013-10-01 16:25 - 2009-07-14 06:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-01 16:25 - 2009-07-14 06:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-01 16:24 - 2013-10-01 16:24 - 00025653 _____ C:\Users\nextlevel\Desktop\CFix.txt
2013-10-01 16:22 - 2013-10-01 16:22 - 00025653 _____ C:\ComboFix.txt
2013-10-01 16:22 - 2013-10-01 16:05 - 00000000 ____D C:\Qoobox
2013-10-01 16:22 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-10-01 16:21 - 2013-10-01 16:05 - 00000000 ____D C:\Windows\erdnt
2013-10-01 16:17 - 2013-10-01 14:27 - 00000336 _____ C:\Windows\setupact.log
2013-10-01 16:17 - 2012-02-20 00:00 - 00000000 ____D C:\Users\postgres
2013-10-01 16:17 - 2009-07-14 04:34 - 00000243 _____ C:\Windows\system.ini
2013-10-01 16:16 - 2013-10-01 14:27 - 00002254 _____ C:\Windows\PFRO.log
2013-10-01 16:16 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-01 16:04 - 2013-10-01 16:04 - 00002740 _____ C:\Users\nextlevel\Desktop\AdwCleaner[S2].txt
2013-10-01 16:03 - 2013-10-01 16:03 - 05131234 ____R (Swearware) C:\Users\nextlevel\Desktop\ComboFix.exe
2013-10-01 15:57 - 2013-10-01 09:25 - 00000000 ____D C:\AdwCleaner
2013-10-01 15:36 - 2013-10-01 15:35 - 00027442 _____ C:\Users\nextlevel\Downloads\Addition.txt
2013-10-01 15:33 - 2013-10-01 15:33 - 00000000 ____D C:\FRST
2013-10-01 15:32 - 2013-10-01 15:32 - 01953880 _____ (Farbar) C:\Users\nextlevel\Downloads\FRST64.exe
2013-10-01 15:16 - 2013-10-01 11:52 - 00000000 ____D C:\Users\nextlevel\Desktop\fff
2013-10-01 14:27 - 2013-10-01 14:27 - 00000000 _____ C:\Windows\setuperr.log
2013-10-01 14:27 - 2012-04-28 14:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-01 14:23 - 2013-10-01 14:23 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-10-01 14:18 - 2013-10-01 14:18 - 04099283 _____ C:\Users\nextlevel\Downloads\tdsskiller-3.0.0.11.zip
2013-10-01 13:59 - 2012-01-21 18:16 - 00000000 ____D C:\Users\nextlevel\AppData\Local\Mozilla
2013-10-01 13:32 - 2011-07-24 01:50 - 01946584 _____ C:\Windows\WindowsUpdate.log
2013-10-01 13:18 - 2012-01-25 03:51 - 00000000 ____D C:\Users\nextlevel\AppData\Local\CrashDumps
2013-10-01 13:18 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-10-01 13:17 - 2012-10-31 02:45 - 00000000 ____D C:\Users\nextlevel\Documents\Visual Studio 2010
2013-10-01 13:16 - 2013-10-01 12:58 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-10-01 13:16 - 2013-01-29 21:14 - 00000000 ____D C:\Users\nextlevel\AppData\Local\Downloaded Installations
2013-10-01 13:16 - 2012-01-22 02:28 - 00000000 __SHD C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-10-01 13:04 - 2013-10-01 13:00 - 00000000 ____D C:\ProgramData\AVG
2013-10-01 13:01 - 2013-10-01 13:01 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\AVG
2013-10-01 12:58 - 2013-10-01 12:56 - 78411688 _____ (AVG) C:\Users\nextlevel\Downloads\avg_tuh_stf_all_2014_174_24c28.exe
2013-10-01 12:11 - 2012-01-21 17:31 - 00000000 ____D C:\Windows\system32\Drivers\AVG
2013-10-01 11:24 - 2013-10-01 11:24 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2013-10-01 11:23 - 2013-10-01 11:23 - 00818001 _____ C:\Users\nextlevel\Downloads\Unlocker1.9.1-x64.exe
2013-10-01 11:17 - 2013-10-01 10:53 - 00000000 ____D C:\Program Files (x86)\TrojanHunter 5.5
2013-10-01 11:16 - 2013-10-01 11:16 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\TrojanHunter
2013-10-01 11:12 - 2013-10-01 11:12 - 01188386 _____ C:\Users\nextlevel\Downloads\deletedr.exe
2013-10-01 10:53 - 2013-10-01 10:53 - 05843488 _____ (Mischel Internet Security ) C:\Users\nextlevel\Downloads\TrojanHunterSetup_5.5_Build_1003.exe
2013-10-01 10:53 - 2013-10-01 10:53 - 00059392 ____R C:\Windows\SysWOW64\streamhlp.dll
2013-10-01 10:42 - 2013-10-01 10:42 - 00001310 _____ C:\Users\nextlevel\Desktop\Local - Verknüpfung.lnk
2013-10-01 09:49 - 2013-10-01 09:49 - 00001081 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\Malwarebytes
2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-01 09:49 - 2013-10-01 09:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-01 09:49 - 2013-10-01 09:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\nextlevel\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-01 09:25 - 2013-10-01 09:25 - 01045226 _____ C:\Users\nextlevel\Downloads\adwcleaner.exe
2013-10-01 09:04 - 2012-01-21 17:31 - 00000000 ____D C:\ProgramData\AVG2012
2013-10-01 01:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-30 22:58 - 2013-09-30 22:58 - 00000521 _____ C:\Users\nextlevel\Desktop\Emsisoft Emergency Kit.lnk
2013-09-30 18:43 - 2011-07-24 11:42 - 00715210 _____ C:\Windows\system32\perfh007.dat
2013-09-30 18:43 - 2011-07-24 11:42 - 00153918 _____ C:\Windows\system32\perfc007.dat
2013-09-30 18:43 - 2009-07-14 07:13 - 01641132 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-30 17:01 - 2013-09-30 17:01 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-09-30 17:01 - 2013-09-30 17:01 - 00000000 ____D C:\Windows\system32\NV
2013-09-30 17:01 - 2013-09-11 06:49 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-30 16:54 - 2011-07-24 01:54 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-09-30 16:52 - 2013-09-11 06:48 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-09-30 16:52 - 2011-07-24 01:55 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-09-28 08:34 - 2012-11-08 22:00 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-09-27 20:20 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-27 20:12 - 2012-03-02 19:56 - 01619026 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-27 20:00 - 2012-01-17 19:56 - 00000000 ___RD C:\Users\nextlevel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-27 20:00 - 2012-01-17 19:56 - 00000000 ___RD C:\Users\nextlevel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-27 19:59 - 2009-07-14 06:45 - 00438256 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-27 19:56 - 2010-11-21 09:17 - 00000000 ____D C:\Program Files\Windows Journal
2013-09-27 19:56 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-27 19:56 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-09-27 19:50 - 2013-09-27 19:47 - 00000000 ____D C:\Windows\system32\MRT
2013-09-27 19:47 - 2012-01-21 18:51 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-27 18:49 - 2013-09-27 15:42 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\LG Electronics
2013-09-27 18:47 - 2012-02-12 23:41 - 00000000 ____D C:\Users\nextlevel\AppData\Local\LG Electronics
2013-09-27 18:47 - 2012-02-12 23:40 - 00000000 ____D C:\Program Files (x86)\LG Electronics
2013-09-27 16:39 - 2013-09-27 16:39 - 00001585 _____ C:\Users\nextlevel\Desktop\Jwars - Verknüpfung.lnk
2013-09-27 16:32 - 2013-09-27 16:01 - 00002413 _____ C:\Windows\SysWOW64\lgAxconfig.ini
2013-09-27 16:21 - 2013-09-27 16:21 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_lgandnetadb_01005.Wdf
2013-09-27 16:04 - 2013-09-27 16:01 - 00000000 ____D C:\ProgramData\LGMOBILEAX
2013-09-27 15:50 - 2013-09-27 15:48 - 113013400 _____ (LG Electronics) C:\Users\nextlevel\Downloads\LG_PCSuiteIV_Setup.exe
2013-09-27 15:39 - 2013-09-27 15:34 - 217689144 _____ (LG Electronics) C:\Users\nextlevel\Downloads\LGPCSuite_Setup.exe
2013-09-27 15:10 - 2012-02-12 23:41 - 00000000 ____D C:\Users\nextlevel\Documents\LG PC Suite IV
2013-09-27 14:24 - 2013-09-27 14:18 - 00000000 ____D C:\Users\nextlevel\Desktop\dd
2013-09-23 17:08 - 2013-09-23 17:08 - 00000186 _____ C:\Users\nextlevel\Desktop\dds.txt
2013-09-14 22:55 - 2012-11-25 05:45 - 00000000 ____D C:\Users\nextlevel\AppData\Local\cache
2013-09-11 15:57 - 2012-01-22 02:40 - 00003522 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-homesweethome-nextlevel
2013-09-11 11:40 - 2013-09-11 11:40 - 00000000 ____D C:\Users\nextlevel\AppData\Local\Apps\2.0
2013-09-11 11:38 - 2013-09-11 11:38 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\HomeMedia
2013-09-11 11:38 - 2012-01-17 20:11 - 00000000 ____D C:\ProgramData\CyberLink
2013-09-11 10:46 - 2012-01-22 00:45 - 00000000 ____D C:\Users\nextlevel\AppData\Roaming\Winamp
2013-09-11 10:03 - 2013-09-11 10:03 - 01855072 _____ (Irfan Skiljan) C:\Users\nextlevel\Downloads\iview436_setup.exe
2013-09-11 10:00 - 2012-01-17 19:57 - 00000000 ____D C:\Users\nextlevel\AppData\Local\Adobe
2013-09-11 09:56 - 2012-06-03 16:37 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-11 09:56 - 2012-01-22 01:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-11 09:29 - 2012-02-20 19:00 - 00003212 _____ C:\Windows\System32\Tasks\{1E1928BD-FD52-4185-81DF-E90354063FAD}
2013-09-11 09:29 - 2012-01-28 16:11 - 00003216 _____ C:\Windows\System32\Tasks\{D3FBC196-54AE-4645-97DD-E8F9A855E572}
2013-09-11 09:29 - 2012-01-21 20:57 - 00003216 _____ C:\Windows\System32\Tasks\{C754605E-BBF7-4BC9-97A6-F8C042387244}
2013-09-11 08:29 - 2013-09-11 08:27 - 00000000 ___HD C:\Windows\Icons
2013-09-11 08:20 - 2013-09-11 07:46 - 00006891 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.ini
2013-09-11 08:18 - 2013-09-11 08:16 - 00006751 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.bak
2013-09-11 08:16 - 2013-09-11 08:18 - 00006761 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.bko
2013-09-11 08:15 - 2013-09-11 08:16 - 00007381 _____ C:\Users\nextlevel\AppData\Roaming\PStrip.bk!
2013-09-11 06:59 - 2013-09-11 06:59 - 00000000 ____D C:\Users\nextlevel\AppData\Local\NVIDIA
2013-09-11 06:49 - 2013-09-11 06:49 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-09-11 06:49 - 2013-09-11 06:49 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-09-11 06:40 - 2013-09-11 06:34 - 233871960 _____ (NVIDIA Corporation) C:\Users\nextlevel\Downloads\320.49-notebook-win8-win7-64bit-international-whql.exe
2013-09-10 03:59 - 2013-09-10 03:59 - 00000680 __RSH C:\Users\nextlevel\ntuser.pol
2013-09-10 03:59 - 2012-01-17 19:54 - 00000000 ____D C:\Users\nextlevel
2013-09-10 03:59 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-09-05 21:54 - 2013-05-29 21:12 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-09-05 21:54 - 2013-05-29 21:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-09-01 17:08 - 2012-01-22 02:59 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-01 01:09
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- |