polypropylen | 25.10.2013 12:00 | Windows 7: CPU-Auslastung fast dauerhaft auf 25+ % Hallo zusammen,
ich habe folgendes Problem: Meine CPU wird fast dauerhaft mit 25 % (oder mehr) ausgelastet. Im TaskManager wiederrum verbraucht kein Prozess diese 25%. Selbst wenn der PC neu gestartet wurde, ist diese Auslastung da.
Achja, da ich es in den Logs gesehen habe: Wenn das Datum 27.04.2012 mit 00:xx Uhr, dann ist das vom 25.10.2013. Das entstand dadurch, da ich ein Bios-Reset durchführen musste, da es Probleme mit einem 8GB-RAM-Riegel gab. Da wurde das Datum zurückgesetzt.
Hier mal die Scans, die ich schon durchgeführt habe (wurde laut Anleitung ja so empfohlen):
MalwareBytes: Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.10.25.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
Stephan :: STEPHANS-PC [Administrator]
25.10.2013 12:46:31
mbam-log-2013-10-25 (12-46-31).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 237203
Laufzeit: 2 Minute(n), 42 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) ----------------------------
Defogger: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 12:35 on 25/10/2013 (Stephan)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- -----------------------
FRST64:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-10-2013
Ran by Stephan (administrator) on STEPHANS-PC on 25-10-2013 12:38:37
Running from C:\Users\Stephan\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) D:\Gdata\AVK\AVKWCtlx64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) D:\Gdata\AVK\AVKService.exe
(G Data Software AG) D:\Gdata\AVKBackup\AVKBackupService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(O&O Software GmbH) D:\Programme\O&O Defrag Free Edition\oodag.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(VMware, Inc.) D:\Programme\VMware2\vmware-authd.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(G Data Software AG) D:\Gdata\Firewall\GDFwSvcx64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(SoftPerfect Research) D:\Programme\NetWorx\networx.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(O&O Software GmbH) D:\Programme\O&O Defrag Free Edition\oodtray.exe
(Akamai Technologies, Inc.) C:\Users\Stephan\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Akamai Technologies, Inc.) C:\Users\Stephan\AppData\Local\Akamai\netsession_win.exe
() D:\Programme\Rainmeter\Rainmeter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(G Data Software AG) D:\Gdata\AVKTray\AVKTray.exe
(G Data Software AG) D:\Gdata\Firewall\GDFirewallTray.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(G Data Software) D:\Gdata\TSNxG\TSNxGService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [NetWorx] - D:\Programme\NetWorx\networx.exe [4875472 2013-09-20] (SoftPerfect Research)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKLM\...\Run: [OODefragTray] - D:\Programme\O&O Defrag Free Edition\oodtray.exe [3942216 2011-01-25] (O&O Software GmbH)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,d:\gdata\avkkid\avkcks.exe
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Stephan\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKCU\...\Run: [BitTorrent] - C:\Users\Stephan\AppData\Roaming\BitTorrent\BitTorrent.exe [898648 2013-10-17] (BitTorrent Inc.)
HKCU\...\Run: [iLivid] - "C:\Users\Stephan\AppData\Local\iLivid\iLivid.exe" -autorun
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [G Data ASM] - "C:\Program Files (x86)\G Data\InternetSecurity\DelayLoader\AutorunDelayLoader.exe" /autostart
HKLM-x32\...\Run: [G Data AntiVirus Tray] - D:\Gdata\AVKTray\AVKTray.exe [1444472 2013-08-21] (G Data Software AG)
HKLM-x32\...\Run: [GDFirewallTray] - D:\Gdata\Firewall\GDFirewallTray.exe [1854928 2013-03-22] (G Data Software AG)
AppInit_DLLs-x32: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll [ ] ()
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk
ShortcutTarget: DSL-Manager.lnk -> D:\Programme\DSL-Manager_6.9\DslMgr.exe (No File)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk
ShortcutTarget: DSL-Manager.lnk -> D:\Programme\DSL-Manager_6.9\DslMgr.exe (No File)
Startup: C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> D:\Programme\Rainmeter\Rainmeter.exe ()
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x07CC5E0086ACCE01
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programme\Java 64 Bit\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Programme\Java 64 Bit\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Programme\Java\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: saVenshare e - {A7E6FF3E-6928-56BA-E4BD-86D23D38F7D5} - C:\ProgramData\saVenshare e\FQzdtn.dll No File
BHO-x32: saveeNShaare - {AA87ACD4-3399-FCCF-BD87-8ABB93F16850} - C:\ProgramData\saveeNShaare\7W.dll No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Programme\Java\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF NetworkProxy: "autoconfig_url", "data:application/x-ns-proxy-autoconfig;base64,ZnVuY3Rpb24gRmluZFByb3h5Rm9yVVJMKHVybCwgaG9zdCkgewogIGlmICgoaG9zdCA9PSAnd3d3LnlvdXR1YmUuY29tJyAmJiB1cmwuaW5kZXhPZigneW91dHViZS5jb20vd2F0Y2g/ZmVhdHVyZT1wbGF5ZXJfZW1iZWRkZWQmdj00SHd3ZWhXSVYzSSZweHRyeT00JykgIT0gLTEpIHx8IChob3N0LmluZGV4T2YoJ2MueW91dHViZS5jb20nKSAhPSAtMSAmJiB1cmwuaW5kZXhPZignYy55b3V0dWJlLmNvbS92aWRlb3BsYXliYWNrJykgIT0gLTEgJiYgdXJsLmluZGV4T2YoJ2djcj11cycpICE9IC0xKSkKICAgIHJldHVybiAnUFJPWFkgMTczLjIyNC4xMTIuMTc6MzEzMSc7CiAgcmV0dXJuICdESVJFQ1QnOwp9"
FF NetworkProxy: "http", "www-proxy.t-online.de"
FF NetworkProxy: "http_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - D:\Programme\Java 64 Bit\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - D:\Programme\Java 64 Bit\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 - D:\Programme\VLC\npvlc.dll (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - D:\PROGRAMME\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - D:\PROGRAMME\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - D:\Programme\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - D:\Programme\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Stephan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FoxyProxy Basic - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\foxyproxy@eric.h.jung
FF Extension: Personas Rotator - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\{6e73f6b7-b9ab-44b8-b744-6393e3c2e351}
FF Extension: WOT - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF Extension: info - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\info@maltegoetz.de.xpi
FF Extension: info - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\info@virustotal.com.xpi
FF Extension: jid0-UVAeBCfd34Kk5usS8A1CBiobvM8 - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\jid0-UVAeBCfd34Kk5usS8A1CBiobvM8@jetpack.xpi
FF Extension: personas - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\personas@christopher.beard.xpi
FF Extension: No Name - C:\Users\Stephan\AppData\Roaming\Mozilla\Firefox\Profiles\1bvvms2h.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
Chrome:
=======
CHR Extension: (GData Centers 8 Hamina, Finland) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaalghjmbckkabmhhocliklkjglhbgam\2_0
CHR Extension: (Google Docs) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (WOT) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.2.0_0
CHR Extension: (YouTube) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (SmoothScroll) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cccpiddacjljmfbbgeimpelpndgpoknn\1.2.9_0
CHR Extension: (Google Search) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (WOT Safe Search) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddcihbboebboehpkkdfdkhbodacmmfkk\2_0
CHR Extension: (Where\u2019s My Water?) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dppkanhlnhknbjopeodjbhgmnjppdijc\1.0.0_0
CHR Extension: (GFACE Experience Plugin) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdlfmdbdibkbfdpjocdaolcheehmpol\0.38.0_0
CHR Extension: (Cut the Rope) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\16_0
CHR Extension: (Where Is My Water) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgklcgpnkamlodmgnponcegackdgfkhd\1.0_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Gmail) - C:\Users\Stephan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1970296 2013-08-26] (G Data Software AG)
R2 AVKService; D:\Gdata\AVK\AVKService.exe [635000 2013-08-21] (G Data Software AG)
R2 AVKWCtl; D:\Gdata\AVK\AVKWCtlx64.exe [2562208 2013-10-15] (G Data Software AG)
S3 COMSysApp; C:\Windows\SysWow64\dllhost.exe [7168 2009-07-14] (Microsoft Corporation)
S4 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] ()
S4 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [137336 2013-02-17] (Futuremark Corporation)
R2 GDBackupSvc; D:\Gdata\AVKBackup\AVKBackupService.exe [1947768 2013-08-21] (G Data Software AG)
R3 GDFwSvc; D:\Gdata\Firewall\GDFwSvcx64.exe [2942808 2013-10-17] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [695416 2013-08-22] (G Data Software AG)
S3 GDTunerSvc; D:\Gdata\AVKTuner\AVKTunerService.exe [1711568 2013-02-25] (G Data Software AG)
S4 MBAMScheduler; D:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S4 MBAMService; D:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 msiserver; C:\Windows\SysWow64\msiexec.exe [73216 2010-11-21] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWow64\GameMon.des [3804120 2011-08-07] (INCA Internet Co., Ltd.)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 OODefragAgent; D:\Programme\O&O Defrag Free Edition\oodag.exe [3051848 2011-01-25] (O&O Software GmbH)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-04] ()
S4 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [247152 2012-10-25] ()
R3 TSNxGService; D:\Gdata\TSNxG\TSNxGService.exe [257512 2013-02-25] (G Data Software)
R2 VMAuthdService; D:\Programme\VMware2\vmware-authd.exe [86096 2013-08-27] (VMware, Inc.)
R2 WSearch; C:\Windows\SysWow64\SearchIndexer.exe [427520 2011-05-04] (Microsoft Corporation)
S4 TDslMgrService; "D:\Programme\DSL-Manager_6.9\DslMgrSvc.exe" [x]
==================== Drivers (Whitelisted) ====================
R3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-09-27] ()
R1 CLVirtualDrive; C:\Windows\System32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 CXCVBS; C:\Windows\System32\drivers\cxCVBS.sys [244096 2012-11-06] (Conexant Systems, Inc.)
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider)
R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [19008 2007-08-01] (T-Systems Enterprise Services GmbH)
R2 EkaProt6; C:\Windows\System32\DRIVERS\ekaprot6.sys [27288 2012-03-23] (Ekahau Inc.)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-09-27] (G Data Software AG)
R3 gddcd; C:\Windows\system32\drivers\gddcd64.sys [79704 2013-10-22] (G Data Software AG)
R1 gddcv; C:\Windows\system32\drivers\gddcv64.sys [59736 2013-10-22] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [130392 2013-09-27] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [63320 2013-09-27] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-10-22] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2013-09-27] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65368 2013-09-27] (G Data Software AG)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [39248 2013-03-15] (Paragon Software Group)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-09-27] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 networx; C:\Windows\System32\drivers\networx.sys [43392 2013-09-13] (NetFilterSDK.com)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 PciDumpr; C:\Program Files (x86)\Common Files\T-Com\DSLCheck\PciDumpr.sys [2144 2001-01-26] ()
S3 PciPPorts; C:\Windows\System32\DRIVERS\PciPPorts.sys [96768 2009-07-23] ()
S3 PciSPorts; C:\Windows\System32\DRIVERS\PciSPorts.sys [122880 2008-12-19] ()
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 TS4NT; C:\Windows\System32\Drivers\TS4nt.sys [98760 2013-10-22] (G Data Software)
R1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [90960 2013-03-15] (Windows (R) 2000 DDK provider)
R1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [633680 2013-03-15] (Paragon)
R1 Uim_VIM; C:\Windows\System32\Drivers\uim_vimx64.sys [390352 2013-03-15] (Paragon)
R3 vmkbd2; C:\Windows\system32\drivers\VMkbd.sys [32848 2013-08-27] (VMware, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-08-15] (VMware, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 AsrIbDrv; \??\C:\Windows\SysWOW64\Drivers\AsrIbDrv.sys [x]
S3 Cardex; \??\C:\Windows\SysWOW64\drivers\TBPANELX64.SYS [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz130; \??\C:\Users\Stephan\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-25 12:37 - 2013-10-25 12:37 - 01955412 _____ (Farbar) C:\Users\Stephan\Desktop\FRST64.exe
2013-10-25 12:36 - 2013-10-25 12:36 - 00000000 ____D C:\FRST
2013-10-25 12:35 - 2013-10-25 12:35 - 00000476 _____ C:\Users\Stephan\Desktop\defogger_disable.log
2013-10-25 12:35 - 2013-10-25 12:35 - 00000000 _____ C:\Users\Stephan\defogger_reenable
2013-10-24 23:34 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-24 23:34 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-24 23:34 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-24 23:34 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-24 23:34 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-24 23:34 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-24 23:34 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-24 20:50 - 2013-10-24 20:55 - 00000000 ____D C:\AdwCleaner
2013-10-24 20:17 - 2013-10-24 20:17 - 00024064 ____H C:\Users\Stephan\Desktop\~WRL2996.tmp
2013-10-22 22:42 - 2013-10-22 22:42 - 00000652 _____ C:\Users\Stephan\Desktop\RX-SSTV.lnk
2013-10-22 16:50 - 2013-10-22 16:50 - 00001589 _____ C:\Users\Stephan\AppData\Local\recently-used.xbel
2013-10-22 09:40 - 2013-10-22 09:40 - 00000614 _____ C:\Users\Public\Desktop\G Data TotalProtection 2014.lnk
2013-10-22 00:10 - 2013-10-22 00:10 - 00377856 _____ C:\Users\Stephan\Desktop\d56ne4no.exe
2013-10-22 00:05 - 2013-10-22 00:05 - 00050477 _____ C:\Users\Stephan\Desktop\Defogger.exe
2013-10-21 23:30 - 2011-09-11 14:41 - 00065152 _____ (Etron Technology Inc) C:\Windows\system32\Drivers\EtronHub3.sys
2013-10-21 20:27 - 2013-10-24 18:21 - 00000000 ____D C:\ProgramData\GFACE
2013-10-21 19:12 - 2013-06-16 14:38 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2013-10-21 19:12 - 2013-06-16 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 30344992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 22933280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 18243632 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 15858664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 15244272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 12537632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-10-21 19:11 - 2013-10-16 02:48 - 11415232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 11362672 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 09516872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 09472600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-10-21 19:11 - 2013-10-16 02:48 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-10-21 13:38 - 2013-10-21 13:38 - 00050511 _____ C:\Users\Stephan\Desktop\Bussystem.htm
2013-10-21 13:38 - 2013-10-21 13:38 - 00000000 ____D C:\Users\Stephan\Desktop\Bussystem_files
2013-10-20 15:08 - 2013-10-20 15:08 - 00019456 _____ C:\Users\Stephan\Desktop\ARCOR.msg
2013-10-19 21:23 - 2013-10-19 21:23 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-19 21:23 - 2013-10-19 21:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-19 21:23 - 2013-10-19 21:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-19 21:23 - 2013-10-19 21:23 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-19 21:20 - 2013-10-19 21:19 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-19 21:19 - 2013-10-19 21:19 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-19 21:19 - 2013-10-19 21:19 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-19 21:19 - 2013-10-19 21:19 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-19 19:48 - 2013-10-19 19:48 - 00000000 ____D C:\Program Files\7-Zip
2013-10-18 22:38 - 2013-10-20 20:13 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Spotify
2013-10-18 22:38 - 2013-10-19 09:17 - 00000000 ____D C:\Users\Stephan\AppData\Local\Spotify
2013-10-18 22:38 - 2013-10-18 22:38 - 00001812 _____ C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2013-10-18 20:05 - 2013-10-18 20:05 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Mael
2013-10-15 16:54 - 2013-10-15 16:54 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-10-12 20:25 - 2013-10-12 20:25 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2013-10-12 20:25 - 2013-10-12 20:25 - 00000000 ____D C:\Users\Stephan\AppData\Local\2K Games
2013-10-12 17:19 - 2013-10-12 17:19 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2013-10-12 17:19 - 2013-06-06 22:41 - 00489392 _____ (Ask Partner Network) C:\Users\Stephan\Documents\ApnStub1.exe
2013-10-12 16:56 - 2013-10-12 16:56 - 00000733 _____ C:\Users\UpdatusUser\Desktop\Notepad++.lnk
2013-10-12 16:56 - 2013-10-12 16:56 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Notepad++
2013-10-12 16:56 - 2013-10-12 16:56 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2013-10-10 21:28 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 21:28 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 21:28 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-10 21:28 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 21:28 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 21:28 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-10 21:28 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 21:28 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-10 21:28 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 21:28 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 21:28 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 21:28 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-10 16:20 - 2013-09-14 04:20 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2013-10-10 16:20 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-10 16:20 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-10 16:20 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-10 16:20 - 2013-09-07 04:27 - 01896896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-10 16:20 - 2013-09-07 04:27 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-10-10 16:20 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-10 16:20 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-10 16:20 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-10 16:20 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-10 16:20 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-10 16:20 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-10 16:20 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-10 16:20 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-10 16:20 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-10 16:20 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-10 16:20 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-10 16:20 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-10 16:20 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-10 16:20 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-10 16:20 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-10 16:15 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 16:15 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-10 16:15 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 16:15 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-10 16:15 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-10 16:15 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-10 16:15 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 16:15 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-10 16:15 - 2013-07-03 06:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 16:15 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 16:15 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 16:15 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 16:15 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 16:15 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 16:15 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 16:15 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 16:15 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-10 16:15 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-10 16:15 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-10 16:15 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 16:15 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-10 16:15 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 16:10 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 16:05 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-10 16:05 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 16:05 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 16:05 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-07 20:55 - 2013-10-07 20:55 - 00000719 _____ C:\Users\UpdatusUser\Desktop\Bridge Building Game.lnk
2013-10-07 20:55 - 2013-10-07 20:55 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bridge Building Game
2013-10-07 20:33 - 2013-10-07 20:33 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-07 20:33 - 2013-10-07 20:33 - 00000000 ____D C:\Program Files\iTunes
2013-10-07 20:33 - 2013-10-07 20:33 - 00000000 ____D C:\Program Files\iPod
2013-10-07 20:02 - 2013-10-07 20:06 - 00000000 ____D C:\Users\Stephan\Documents\Battlefield 4 Beta
2013-10-07 17:52 - 2013-10-07 17:52 - 00000000 ____D C:\Users\Stephan\Documents\HDSDR
2013-10-06 16:07 - 2013-10-19 13:53 - 00000000 ____D C:\Users\Stephan\Desktop\Neuer Ordner
2013-10-04 23:11 - 2013-10-05 12:39 - 00000000 ____D C:\Users\Stephan\Ekahau Site Survey
2013-10-04 18:58 - 2013-10-04 18:58 - 00000000 ____D C:\Users\Stephan\Documents\Battlefield 4
2013-10-04 16:23 - 2013-10-04 16:25 - 00000000 ____D C:\Users\Stephan\Downloads\Download.am
2013-10-04 16:22 - 2013-10-04 16:22 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Download.am
2013-10-03 16:41 - 2013-09-27 10:57 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433140.dll
2013-10-03 16:41 - 2013-09-27 10:57 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433140.dll
2013-10-02 23:40 - 2013-10-24 21:44 - 00000000 ____D C:\Users\Stephan\AppData\Local\CrashDumps
2013-09-29 13:33 - 2013-10-03 12:00 - 00000000 ____D C:\Users\Stephan\Desktop\Retro TReiber usw
2013-09-28 09:37 - 2013-09-28 09:37 - 00000000 ____D C:\Users\Stephan\Documents\Camtasia Studio
2013-09-28 09:37 - 2013-09-28 09:37 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\TechSmith
2013-09-28 09:36 - 2013-09-28 09:36 - 00000000 ____D C:\ProgramData\TechSmith
2013-09-28 09:36 - 2013-09-28 09:36 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2013-09-27 23:55 - 2013-10-08 18:26 - 00004520 _____ C:\Users\Stephan\AppData\Roaming\CamStudio.cfg
2013-09-27 23:55 - 2013-10-08 18:26 - 00000408 _____ C:\Users\Stephan\AppData\Roaming\CamShapes.ini
2013-09-27 23:55 - 2013-10-08 18:26 - 00000408 _____ C:\Users\Stephan\AppData\Roaming\CamLayout.ini
2013-09-27 23:55 - 2013-10-08 18:26 - 00000107 _____ C:\Users\Stephan\AppData\Roaming\Camdata.ini
2013-09-27 22:02 - 2013-09-27 22:02 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2013-09-25 19:25 - 2013-08-27 12:42 - 00930384 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
2013-09-25 19:25 - 2013-08-27 12:42 - 00437328 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2013-09-25 19:25 - 2013-08-27 12:42 - 00358480 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2013-09-25 19:25 - 2013-08-27 12:42 - 00064080 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
2013-09-25 19:25 - 2013-08-27 12:42 - 00030800 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
2013-09-25 19:25 - 2013-08-27 12:41 - 00032848 _____ (VMware, Inc.) C:\Windows\system32\Drivers\VMkbd.sys
2013-09-25 19:25 - 2013-08-26 23:33 - 00053816 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
2013-09-25 19:25 - 2013-08-15 18:25 - 00073296 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vsock.sys
2013-09-25 19:25 - 2013-08-15 18:25 - 00067664 _____ (VMware, Inc.) C:\Windows\system32\vsocklib.dll
2013-09-25 19:25 - 2013-08-15 18:25 - 00063568 _____ (VMware, Inc.) C:\Windows\SysWOW64\vsocklib.dll
2013-09-25 19:24 - 2013-09-25 19:24 - 00000000 ____D C:\Program Files\Common Files\VMware
2013-09-25 19:23 - 2013-09-25 19:23 - 00000000 ____D C:\Users\Stephan\Neuer Ordner
==================== One Month Modified Files and Folders =======
2013-10-25 12:37 - 2013-10-25 12:37 - 01955412 _____ (Farbar) C:\Users\Stephan\Desktop\FRST64.exe
2013-10-25 12:36 - 2013-10-25 12:36 - 00000000 ____D C:\FRST
2013-10-25 12:35 - 2013-10-25 12:35 - 00000476 _____ C:\Users\Stephan\Desktop\defogger_disable.log
2013-10-25 12:35 - 2013-10-25 12:35 - 00000000 _____ C:\Users\Stephan\defogger_reenable
2013-10-25 12:35 - 2012-03-22 21:52 - 00000000 ____D C:\Users\Stephan
2013-10-25 12:35 - 2009-07-14 06:45 - 00028912 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-25 12:35 - 2009-07-14 06:45 - 00028912 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-25 12:33 - 2013-05-09 21:53 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\BitTorrent
2013-10-25 12:32 - 2012-03-22 21:52 - 01627887 _____ C:\Windows\WindowsUpdate.log
2013-10-25 08:54 - 2012-03-30 19:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-25 08:47 - 2012-04-02 17:49 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-24 21:44 - 2013-10-02 23:40 - 00000000 ____D C:\Users\Stephan\AppData\Local\CrashDumps
2013-10-24 21:34 - 2013-02-22 20:43 - 00000000 ____D C:\Users\Stephan\Documents\Euro Truck Simulator 2
2013-10-24 21:29 - 2012-04-29 14:11 - 00000000 ____D C:\Users\Stephan\Documents\Outlook-Dateien
2013-10-24 21:23 - 2012-03-27 20:10 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\vlc
2013-10-24 20:55 - 2013-10-24 20:50 - 00000000 ____D C:\AdwCleaner
2013-10-24 20:17 - 2013-10-24 20:17 - 00024064 ____H C:\Users\Stephan\Desktop\~WRL2996.tmp
2013-10-24 18:21 - 2013-10-21 20:27 - 00000000 ____D C:\ProgramData\GFACE
2013-10-24 09:43 - 2012-07-31 22:08 - 00000000 ____D C:\Windows\Minidump
2013-10-24 09:43 - 2012-03-22 21:45 - 00301401 ____N C:\Windows\Minidump\102413-19952-01.dmp
2013-10-23 19:30 - 2011-04-12 09:43 - 00716132 _____ C:\Windows\system32\perfh007.dat
2013-10-23 19:30 - 2011-04-12 09:43 - 00156594 _____ C:\Windows\system32\perfc007.dat
2013-10-23 19:30 - 2009-07-14 07:13 - 01666434 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-23 09:50 - 2012-03-27 20:45 - 00631320 _____ C:\Windows\PFRO.log
2013-10-22 23:11 - 2013-03-16 21:02 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\VMware
2013-10-22 23:11 - 2013-03-16 21:02 - 00000000 ____D C:\Users\Stephan\AppData\Local\VMware
2013-10-22 22:42 - 2013-10-22 22:42 - 00000652 _____ C:\Users\Stephan\Desktop\RX-SSTV.lnk
2013-10-22 22:11 - 2012-09-27 17:07 - 00000000 ____D C:\Users\Stephan\Desktop\Spiele
2013-10-22 16:50 - 2013-10-22 16:50 - 00001589 _____ C:\Users\Stephan\AppData\Local\recently-used.xbel
2013-10-22 16:46 - 2013-08-23 18:23 - 00000000 ____D C:\Users\Stephan\.gimp-2.8
2013-10-22 09:40 - 2013-10-22 09:40 - 00000614 _____ C:\Users\Public\Desktop\G Data TotalProtection 2014.lnk
2013-10-22 09:40 - 2013-09-19 18:58 - 00098760 _____ (G Data Software) C:\Windows\system32\Drivers\TS4nt.sys
2013-10-22 09:40 - 2013-09-19 18:58 - 00079704 _____ (G Data Software AG) C:\Windows\system32\Drivers\gddcd64.sys
2013-10-22 09:40 - 2013-09-19 18:58 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2013-10-22 09:40 - 2013-09-19 18:58 - 00059736 _____ (G Data Software AG) C:\Windows\system32\Drivers\gddcv64.sys
2013-10-22 09:32 - 2013-03-17 15:04 - 00000000 ____D C:\Users\Stephan\Desktop\System
2013-10-22 08:46 - 2013-09-19 19:55 - 00000000 __SHD C:\#GDATA.Trash.Store#
2013-10-22 00:10 - 2013-10-22 00:10 - 00377856 _____ C:\Users\Stephan\Desktop\d56ne4no.exe
2013-10-22 00:05 - 2013-10-22 00:05 - 00050477 _____ C:\Users\Stephan\Desktop\Defogger.exe
2013-10-21 19:14 - 2012-03-22 22:14 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-10-21 19:14 - 2012-03-22 22:14 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-10-21 18:35 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-21 14:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-10-21 13:38 - 2013-10-21 13:38 - 00050511 _____ C:\Users\Stephan\Desktop\Bussystem.htm
2013-10-21 13:38 - 2013-10-21 13:38 - 00000000 ____D C:\Users\Stephan\Desktop\Bussystem_files
2013-10-20 23:51 - 2012-05-16 16:04 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Skype
2013-10-20 22:16 - 2012-06-20 15:47 - 00000000 ____D C:\Program Files (x86)\Origin
2013-10-20 20:13 - 2013-10-18 22:38 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Spotify
2013-10-20 17:39 - 2012-04-02 17:49 - 00000000 ____D C:\Users\Stephan\AppData\Local\Google
2013-10-20 17:39 - 2012-04-02 17:49 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-20 15:08 - 2013-10-20 15:08 - 00019456 _____ C:\Users\Stephan\Desktop\ARCOR.msg
2013-10-19 21:23 - 2013-10-19 21:23 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-10-19 21:23 - 2013-10-19 21:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-10-19 21:23 - 2013-10-19 21:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-10-19 21:23 - 2013-10-19 21:23 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2013-10-19 21:19 - 2013-10-19 21:20 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-19 21:19 - 2013-10-19 21:19 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-19 21:19 - 2013-10-19 21:19 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-19 21:19 - 2013-10-19 21:19 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-19 19:48 - 2013-10-19 19:48 - 00000000 ____D C:\Program Files\7-Zip
2013-10-19 15:49 - 2012-03-22 21:52 - 00000000 ___RD C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-19 13:53 - 2013-10-06 16:07 - 00000000 ____D C:\Users\Stephan\Desktop\Neuer Ordner
2013-10-19 09:17 - 2013-10-18 22:38 - 00000000 ____D C:\Users\Stephan\AppData\Local\Spotify
2013-10-18 22:38 - 2013-10-18 22:38 - 00001812 _____ C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2013-10-18 20:05 - 2013-10-18 20:05 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Mael
2013-10-16 02:48 - 2013-10-21 19:11 - 30344992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 22933280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 18243632 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 15858664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 15244272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 12537632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-10-16 02:48 - 2013-10-21 19:11 - 11415232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 11362672 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 09516872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 09472600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2013-10-16 02:48 - 2013-10-21 19:11 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2013-10-16 02:48 - 2012-03-23 17:29 - 18290536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-10-16 02:48 - 2012-03-23 17:29 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2013-10-16 02:48 - 2012-03-22 22:13 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2013-10-16 02:48 - 2012-03-22 22:13 - 02694664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2013-10-16 02:48 - 2012-03-22 22:13 - 00023287 _____ C:\Windows\system32\nvinfo.pb
2013-10-15 23:47 - 2012-03-22 22:14 - 06665504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2013-10-15 23:47 - 2012-03-22 22:14 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2013-10-15 23:47 - 2012-03-22 22:14 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2013-10-15 23:47 - 2012-03-22 22:14 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2013-10-15 23:47 - 2012-03-22 22:14 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2013-10-15 23:47 - 2012-03-22 22:14 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2013-10-15 16:54 - 2013-10-15 16:54 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2013-10-14 19:03 - 2012-03-23 20:23 - 00000000 ____D C:\Windows\System32\Tasks\Games
2013-10-13 20:20 - 2013-02-02 10:07 - 00000000 ____D C:\Users\Stephan\AppData\Local\Paint.NET
2013-10-13 08:42 - 2012-04-02 17:49 - 00004108 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-13 08:42 - 2012-04-02 17:49 - 00003856 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-12 20:25 - 2013-10-12 20:25 - 00000000 ____D C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2013-10-12 20:25 - 2013-10-12 20:25 - 00000000 ____D C:\Users\Stephan\AppData\Local\2K Games
2013-10-12 20:25 - 2013-06-05 17:08 - 00283704 _____ C:\Windows\DirectX.log
2013-10-12 20:02 - 2013-09-13 23:28 - 00000000 ____D C:\Windows\system32\oodag
2013-10-12 17:19 - 2013-10-12 17:19 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2013-10-12 16:56 - 2013-10-12 16:56 - 00000733 _____ C:\Users\UpdatusUser\Desktop\Notepad++.lnk
2013-10-12 16:56 - 2013-10-12 16:56 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Notepad++
2013-10-12 16:56 - 2013-10-12 16:56 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2013-10-11 19:03 - 2012-03-22 21:45 - 00301447 ____N C:\Windows\Minidump\101113-13150-01.dmp
2013-10-11 19:00 - 2012-03-22 21:45 - 00301447 ____N C:\Windows\Minidump\101113-32183-01.dmp
2013-10-11 15:50 - 2009-07-14 06:45 - 00472304 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 21:30 - 2012-04-29 14:09 - 01639778 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-10 21:29 - 2012-03-25 17:52 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-10 21:27 - 2012-05-11 15:45 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 21:27 - 2012-05-11 15:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 21:26 - 2013-08-15 00:26 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 21:24 - 2012-03-23 20:51 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-10 17:38 - 2012-08-09 23:13 - 00215416 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-10 17:38 - 2012-08-09 23:13 - 00215416 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-10-10 16:54 - 2012-03-30 19:44 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-10 16:54 - 2012-03-30 19:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-10 16:54 - 2012-03-23 17:53 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-08 21:14 - 2012-03-23 17:31 - 03398914 _____ C:\Windows\system32\nvcoproc.bin
2013-10-08 18:26 - 2013-09-27 23:55 - 00004520 _____ C:\Users\Stephan\AppData\Roaming\CamStudio.cfg
2013-10-08 18:26 - 2013-09-27 23:55 - 00000408 _____ C:\Users\Stephan\AppData\Roaming\CamShapes.ini
2013-10-08 18:26 - 2013-09-27 23:55 - 00000408 _____ C:\Users\Stephan\AppData\Roaming\CamLayout.ini
2013-10-08 18:26 - 2013-09-27 23:55 - 00000107 _____ C:\Users\Stephan\AppData\Roaming\Camdata.ini
2013-10-07 20:55 - 2013-10-07 20:55 - 00000719 _____ C:\Users\UpdatusUser\Desktop\Bridge Building Game.lnk
2013-10-07 20:55 - 2013-10-07 20:55 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bridge Building Game
2013-10-07 20:33 - 2013-10-07 20:33 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-07 20:33 - 2013-10-07 20:33 - 00000000 ____D C:\Program Files\iTunes
2013-10-07 20:33 - 2013-10-07 20:33 - 00000000 ____D C:\Program Files\iPod
2013-10-07 20:06 - 2013-10-07 20:02 - 00000000 ____D C:\Users\Stephan\Documents\Battlefield 4 Beta
2013-10-07 17:52 - 2013-10-07 17:52 - 00000000 ____D C:\Users\Stephan\Documents\HDSDR
2013-10-07 17:21 - 2012-03-22 21:45 - 00301895 ____N C:\Windows\Minidump\100713-13431-01.dmp
2013-10-07 15:02 - 2012-11-16 20:42 - 00000000 ____D C:\Users\Stephan\fldigi.files
2013-10-07 15:02 - 2012-11-16 20:42 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fldigi
2013-10-05 12:39 - 2013-10-04 23:11 - 00000000 ____D C:\Users\Stephan\Ekahau Site Survey
2013-10-04 18:59 - 2012-03-23 18:19 - 00000000 ____D C:\Users\Stephan\AppData\Local\PunkBuster
2013-10-04 18:58 - 2013-10-04 18:58 - 00000000 ____D C:\Users\Stephan\Documents\Battlefield 4
2013-10-04 17:02 - 2013-03-08 20:46 - 00000000 ____D C:\ProgramData\Package Cache
2013-10-04 17:02 - 2012-06-20 19:07 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-10-04 17:02 - 2012-03-23 18:17 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-04 16:25 - 2013-10-04 16:23 - 00000000 ____D C:\Users\Stephan\Downloads\Download.am
2013-10-04 16:22 - 2013-10-04 16:22 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Download.am
2013-10-03 20:14 - 2012-03-22 22:13 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-10-03 19:53 - 2012-10-27 16:00 - 00000000 ____D C:\Program Files (x86)\Nikon
2013-10-03 12:00 - 2013-09-29 13:33 - 00000000 ____D C:\Users\Stephan\Desktop\Retro TReiber usw
2013-10-01 13:47 - 2012-03-23 17:32 - 00000000 ____D C:\Users\Stephan\Documents\Schulische Aufgaben
2013-09-30 20:41 - 2012-03-25 17:52 - 00000000 ____D C:\Users\Stephan\AppData\Local\Microsoft Help
2013-09-29 17:28 - 2013-02-24 15:19 - 00000000 ____D C:\Users\Stephan\AppData\Local\Akamai
2013-09-28 10:52 - 2013-04-08 18:48 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Benchmark Sims
2013-09-28 10:52 - 2013-02-11 23:57 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Challenger
2013-09-28 09:54 - 2012-03-27 20:09 - 00012800 _____ C:\Users\Stephan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-28 09:37 - 2013-09-28 09:37 - 00000000 ____D C:\Users\Stephan\Documents\Camtasia Studio
2013-09-28 09:37 - 2013-09-28 09:37 - 00000000 ____D C:\Users\Stephan\AppData\Roaming\TechSmith
2013-09-28 09:36 - 2013-09-28 09:36 - 00000000 ____D C:\ProgramData\TechSmith
2013-09-28 09:36 - 2013-09-28 09:36 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2013-09-27 22:28 - 2012-12-05 17:47 - 00000000 ____D C:\Users\Stephan\Documents\Screen Recording Suite
2013-09-27 22:02 - 2013-09-27 22:02 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2013-09-27 19:36 - 2013-09-19 18:58 - 00130392 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2013-09-27 19:36 - 2013-09-19 18:58 - 00065368 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2013-09-27 19:36 - 2013-09-19 18:58 - 00063320 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2013-09-27 19:36 - 2013-09-19 18:58 - 00060248 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2013-09-27 16:57 - 2013-03-06 20:52 - 00088480 _____ C:\Windows\system32\Drivers\atksgt.sys
2013-09-27 16:57 - 2013-03-06 20:52 - 00046400 _____ C:\Windows\system32\Drivers\lirsgt.sys
2013-09-27 10:57 - 2013-10-03 16:41 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433140.dll
2013-09-27 10:57 - 2013-10-03 16:41 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433140.dll
2013-09-25 19:24 - 2013-09-25 19:24 - 00000000 ____D C:\Program Files\Common Files\VMware
2013-09-25 19:23 - 2013-09-25 19:23 - 00000000 ____D C:\Users\Stephan\Neuer Ordner
Files to move or delete:
====================
C:\Users\Stephan\AppData\Roaming\CamLayout.ini
C:\Users\Stephan\AppData\Roaming\CamShapes.ini
C:\ProgramData\PKP_DLeo.DAT
C:\ProgramData\PKP_DLes.DAT
C:\ProgramData\PKP_DLet.DAT
C:\ProgramData\PKP_DLev.DAT
Some content of TEMP:
====================
C:\Users\Stephan\AppData\Local\Temp\Checkupdate.exe
C:\Users\Stephan\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Stephan\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Stephan\AppData\Local\Temp\gcapi_dll.dll
C:\Users\Stephan\AppData\Local\Temp\gtapi_signed.dll
C:\Users\Stephan\AppData\Local\Temp\ICReinstall_DriverGuide_Driver_Download_3209.exe
C:\Users\Stephan\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Stephan\AppData\Local\Temp\nvStInst.exe
C:\Users\Stephan\AppData\Local\Temp\Quarantine.exe
C:\Users\Stephan\AppData\Local\Temp\xmlUpdater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-21 14:24
==================== End Of Log ============================ --- --- ---
und die Addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-10-2013
Ran by Stephan at 2013-10-25 12:39:47
Running from C:\Users\Stephan\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: G Data TotalProtection 2014 (Disabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: G Data TotalProtection 2014 (Disabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: G Data Personal Firewall (Disabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B}
==================== Installed Programs ======================
3DMark (x32 Version: 1.1)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe AIR (x32 Version: 3.8.0.1430)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Help Manager (x32 Version: 4.0.244)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.4.144)
Adobe Widget Browser (x32 Version: 2.0 Build 348)
Adobe Widget Browser (x32 Version: 2.0.348)
AIDA64 Extreme Edition v2.85 (x32 Version: 2.85)
Akamai NetSession Interface (HKCU)
Anno 1701 (x32 Version: 1.02)
Apple Application Support (x32 Version: 2.3.6)
Apple Mobile Device Support (Version: 7.0.0.117)
Apple Software Update (x32 Version: 2.1.3.127)
applicationupdater (HKCU)
AREA-51 (remove only) (x32 Version: 1.7.0.11.2.4.3)
Ashampoo Burning Studio 2013 v.11.0.5 (x32 Version: 11.0.5)
Ashampoo Photo Commander 9 v.9.4.2 (x32 Version: 9.4.2)
Assessment and Deployment Kit (x32 Version: 8.59.25584)
Audacity 2.0.4 (x32 Version: 2.0.4)
Bad Piggies (x32 Version: 1.3.0.0)
Bad Rats (x32)
Battlefield 1942™ (x32 Version: 1.6.20.0)
Battlefield 3™ (x32 Version: 1.4.0.0)
Battlefield 4™ Beta (x32 Version: 1.0.0.0)
Battlelog Web Plugins (x32 Version: 2.3.0)
Binary Domain (x32)
BitTorrent (HKCU Version: 7.8.2.30182)
Bonjour (Version: 3.0.0.10)
Bridge Building Game (x32)
Bus-Simulator 2012 (x32)
Call of Duty 4: Modern Warfare (x32)
CamStudio Lossless Codec v1.5 (x32 Version: 1.5)
Camtasia Studio 8 (x32 Version: 8.1.2.1344)
Core Temp 1.0 RC6 (Version: 1.0)
CPUID CPU-Z 1.64.0
Cry of Fear (x32)
Crysis (x32)
Crysis 2 Maximum Edition (x32)
Crysis Warhead (x32)
Crysis Wars (x32)
CyberLink Power2Go 8 (x32 Version: 8.0.0.1920)
CyberLink PowerDirector (x32 Version: 9.0.0.3815c)
CyberLink PowerProducer 5.5 (x32 Version: 5.5.3.4519)
D3DX10 (x32 Version: 15.4.2368.0902)
Das große Franzis Paket Office - Office Vorlagen Teil 1 (x32)
Das große Franzis Paket Office - Office Vorlagen Teil 2 (x32)
Das große Franzis Paket Office - Office Vorlagen Teil 3 (x32)
Das große Franzis Paket Office - Office Vorlagen Teil 4 (x32)
DC-Bass Source 1.3.0 (x32)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
DHTML Editing Component (x32 Version: 6.02.0001)
DirectVobSub 2.40.4209 (x32 Version: 2.40.4209)
Dishonored (x32 Version: 1.0)
Divinity II - Ego Draconis (x32)
DivX Player (x32 Version: 2.5.5)
DivX-Setup (x32 Version: 2.6.1.8)
Dokan Library 0.6.0 (x32)
Drakensang - Am Fluss der Zeit (x32)
Ekahau HeatMapper (Version: 1.1.4.39795)
Emicsoft MOV Converter (x32)
EPSON BX535WD Series Printer Uninstall
EPSON Scan (x32)
ESET Online Scanner v3 (x32)
ESN Sonar (x32 Version: 0.70.4)
Etron USB3.0 Host Controller (x32 Version: 0.118)
Euro Truck Simulator 2 (x32)
EVEREST Home Edition v2.20 (x32 Version: 2.20)
FAKEFACTORY Cinematic Mod 2013 (x32 Version: alpha1)
Far Cry (x32)
Far Cry® 3 (x32)
ffdshow v1.1.4399 [2012-03-22] (x32 Version: 1.1.4399.0)
Fldigi 3.21.76 (x32 Version: 3.21.76)
FlightGear 2.10.0.3
Foxit Reader (x32 Version: 6.0.6.722)
Freemake Video Converter Version 4.0.0 (x32 Version: 4.0.0)
Futuremark SystemInfo (x32 Version: 4.17.0)
G Data TotalProtection 2014 (x32 Version: 24.0.3.4)
gamelauncher-ps2-psg (HKCU)
GIMP 2.8.6 (Version: 2.8.6)
Google Chrome (x32 Version: 31.0.1650.34)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.21.165)
Haali Media Splitter (x32)
Half-Life 2 (x32)
Half-Life 2: Deathmatch (x32)
Half-Life 2: Episode One (x32)
Half-Life 2: Episode Two (x32)
Half-Life 2: Lost Coast (x32)
HD Tune 2.55 (x32)
HDSDR 2.63 (x32)
HxD Hex Editor Version 1.7.7.0 (x32 Version: 1.7.7.0)
HyperCam 3 (x32 Version: 3.5.1210.30)
inSSIDer 3 (x32 Version: 3.0.7.48)
Intel(R) Management Engine Components (x32 Version: 7.1.40.1161)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008)
iTunes (Version: 11.1.1.11)
Jack (x32)
James Cameron's AVATAR(tm): DAS SPIEL (Demo) (x32 Version: 1.00.00)
James Cameron's AVATAR(tm): DAS SPIEL (x32 Version: 1.02.00)
Java 7 Update 45 (64-bit) (Version: 7.0.450)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
JavaFX 2.1.1 (x32 Version: 2.1.1)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Kits Configuration Installer (x32 Version: 8.59.25584)
Klett Service-CD Lambacher Schweizer Oberstufe Sachsen (x32)
Lagarith Lossless Codec (1.3.27) (x32)
LAME v3.99.3 (for Windows) (x32)
Landwirtschafts-Simulator 2009 Gold (x32)
Mafia II (x32)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Matrix-ks (x32 Version: 3.6)
Medion Home Cinema 10 (x32 Version: 10.0)
Medion Home Cinema 10 (x32 Version: 10.1924)
Mesh Runtime (x32 Version: 15.4.5722.2)
Messenger Companion (x32 Version: 15.4.3502.0922)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 4.5 (Version: 4.5.50709)
Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709)
Microsoft Application Compatibility Toolkit 5.6 (x32 Version: 5.6.7324.0)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Expression Web 4 (x32 Version: 4.0.1460.0)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Professional 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Office Single Image 2010 (Version: 14.0.7015.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610)
MOUSE Editor (x32 Version: 12.02.0004)
Mouse Editor (x32 Version: 12.02.0004)
Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
MSI Afterburner 3.0.0 Beta 14 (x32 Version: 3.0.0 Beta 14)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT Redists (x32 Version: 1.0)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
NetWorx 5.2.10
Nikon Movie Editor (x32 Version: 2.5.0)
Notepad++ (x32 Version: 6.5)
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19)
NVIDIA 3D Vision Controller-Treiber 331.58 (Version: 331.58)
NVIDIA 3D Vision Treiber 331.58 (Version: 331.58)
NVIDIA GeForce Experience 1.5 (Version: 1.5)
NVIDIA Grafiktreiber 331.58 (Version: 331.58)
NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4)
NVIDIA Install Application (Version: 2.1002.133.902)
NVIDIA PhysX (x32 Version: 9.13.0725)
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3158)
NVIDIA Systemsteuerung 331.58 (Version: 331.58)
NVIDIA Update 4.11.9 (Version: 4.11.9)
NVIDIA Update Components (Version: 8.3.23)
NVIDIA Virtual Audio 1.2.5 (Version: 1.2.5)
O&O Defrag Free Edition (Version: 14.1.431)
OpenAL (x32)
OpenSource Flash Video Splitter 1.0.0.5 (x32 Version: 1.0.0.5)
Origin (x32 Version: 8.6.0.357)
Paint.NET v3.5.11 (Version: 3.61.0)
Paragon Backup & Recovery™ 2013 Free (x32 Version: 90.00.0003)
PCGH VGA-Tool 1.0.1 (x32)
PCGH-Testdatenbank Version 1.21 (x32 Version: 1.21)
PDF Experte 8 Ultimate (x32 Version: 8.0.0140.0)
Picture Control Utility x64 (Version: 1.4.6)
PlanetSide 2 (HKCU Version: 1.0.3.181)
Ports Of Call - classic - Windows (x32)
PunkBuster Services (x32 Version: 0.993)
Python 2.7.5 (x32 Version: 2.7.5150)
QuickTime (x32 Version: 7.74.80.86)
R.U.S.E (x32)
Rainmeter (x32 Version: 3.0 r2116)
Realtek Ethernet Controller Driver For Windows 7 (x32 Version: 7.23.623.2010)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6662)
Risen (x32 Version: 1.00.0000)
RivaTuner Statistics Server 5.3.0 (x32 Version: 5.3.0)
RollerCoaster Tycoon 3 (x32)
RX-SSTV Version 1.3.1b (x32)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition
SHIELD Streaming (Version: 1.05.28)
SIW 2013 Home Edition (x32 Version: 2013.05.14)
Skype™ 6.6 (x32 Version: 6.6.106)
Source SDK Base 2007 (x32)
SpeedFan (remove only) (x32)
Spotify (HKCU Version: 0.9.4.185.g7545a404)
Steam (x32 Version: 1.0.0.0)
Storm in a Teacup (x32)
Supreme Commander 2 (x32)
Surgeon Simulator 2013 (x32)
swMSM (x32 Version: 12.0.0.1)
TechPowerUp GPU-Z (x32)
TeraCopy 2.3 beta 2
test2
The Suffering (remove only) (x32 Version: 1.7.0.11.2.4.3)
The Walking Dead (x32)
T-Online DSL-Manager (x32)
Toolkit Documentation (x32 Version: 8.59.25584)
Two Worlds II (x32 Version: 1.3.0.0)
UAC-Ausnahmen
Ulead PhotoImpact X3 (x32 Version: 13.0)
Unity Web Player (HKCU Version: )
Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 64-Bit Edition
Uplay (x32 Version: 2.0)
USB2.0 Audio Capture (Version: 1.0.0.0)
USB2.0 Video Capture (Version: 1.0.0.0)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
ViewNX 2 (Version: 2.5.1)
Visual Studio C++ 10.0 Runtime (x32 Version: 10.0.0)
VLC media player 2.1.0 (Version: 2.1.0)
VMware Player (Version: 6.0.0)
VMware Player (x32 Version: 6.0.0)
War Thunder (x32)
War Thunder Launcher 1.0.1.252 (x32)
WhoCrashed 4.02
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinRAR 4.20 (64-Bit) (Version: 4.20.0)
World of Tanks (x32)
World of Warplanes (x32)
WPT Redistributables (x32 Version: 8.59.25584)
WPTx64 (x32 Version: 8.59.25584)
X2 - Die Bedrohung (V1.4) (x32 Version: 1.04.0000)
Xvid Video Codec (x32 Version: 1.3.2)
==================== Restore Points =========================
24-10-2013 21:48:07 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2012-12-12 21:59 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {1CB7CD56-71DB-4E25-AC2F-4B2CCC8A6227} - System32\Tasks\{C3045D47-0840-4E68-87C0-1F78742A70F8} => D:\Downloads\cw\_ISDEL.EXE
Task: {25CE044D-355C-476E-83DC-C56B673319D4} - System32\Tasks\{BB821C28-4D48-4397-98FA-606FF748700C} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {2A4C377D-B9F0-482D-B751-0E94F4254D44} - System32\Tasks\{33D9B85E-34C0-4633-B4A4-5EC7E49BB1DC} => D:\Downloads\cw\_ISDEL.EXE
Task: {32636A0A-CEC3-40B4-9D7F-E6266412A8CE} - System32\Tasks\{8C2318DB-3952-4F8C-B637-00341099774A} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {342B3242-CBE5-47BF-AC5C-295A4A3BD416} - System32\Tasks\{F28BA32F-6F6C-4A29-9524-A05F9380564C} => D:\Downloads\cw\_ISDEL.EXE
Task: {373ACE46-0699-4AA7-ACDE-08302293B71C} - System32\Tasks\{FEDAB767-4A33-4561-8757-5A17D7E42206} => D:\win2000\Spiele\Schneemann\frosty.exe [2003-07-03] ()
Task: {3834B950-CF10-464D-9A19-324BF5796A3F} - System32\Tasks\{B47171F9-6870-42B8-AEAB-E398D3BE8EA4} => D:\win2000\Spiele\TIM\TIM.EXE [1992-12-02] ()
Task: {394260ED-D15A-4506-836E-6D02A9244562} - System32\Tasks\{3DB30AE5-EB10-4154-BAF5-36DBFDAACFC2} => D:\Downloads\cw\_ISDEL.EXE
Task: {46785D91-7011-4386-B450-EE480E4BD9B7} - System32\Tasks\{5115D58C-14D6-4B4F-84B2-3AEC92A0D362} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {4682C553-29B9-4931-AF25-227F52C2D1B7} - System32\Tasks\{787AC935-DBB2-43D0-B856-A5BA586FC56A} => D:\Downloads\cw\_ISDEL.EXE
Task: {525B451C-9B59-42E9-BB3C-B5011B359C34} - System32\Tasks\{ABEA25F9-604D-49C6-AC4D-398665A71D51} => D:\Downloads\cw\_ISDEL.EXE
Task: {528AA887-829C-41EA-A259-637FF0E92514} - System32\Tasks\{287AAA3E-4261-4AED-A1C8-FC32FC428849} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {53DD6AA5-240D-4988-8716-D4D1FEB50C3F} - System32\Tasks\{FE34D50A-E948-4809-A48E-5F5E302F082D} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?source=lightinstaller&LastError=1618
Task: {56CCC03D-6FF8-4044-A56D-6D81039B07C4} - System32\Tasks\{096B0511-E9E1-4783-BA12-1F82320D241E} => D:\win2000\GOLDCITY\GOLDCITY.EXE [2003-10-05] (Odin4000)
Task: {61139361-0589-4750-968D-63E60B48C38A} - System32\Tasks\{E70B2D74-F697-4321-AA2E-9106BC1369F1} => D:\Downloads\cw\_ISDEL.EXE
Task: {61F7EA1F-C3A1-4977-877D-5633BD6C0005} - System32\Tasks\{7CFD341C-FCC7-4DFD-9FC6-A24F37C2A4E1} => D:\Downloads\cw\_ISDEL.EXE
Task: {62142CE3-8369-49BB-9961-CDA43DBCAD81} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {6449CA69-40C0-4AA0-978A-7AF52F7894A9} - System32\Tasks\{B6442C8E-2833-434C-80B9-3ED4DB054F14} => D:\Programme\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe [2013-06-13] (Telltale Games)
Task: {6A0B865D-B6EA-4B75-A05A-F5093FDB0560} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: {6C8BF352-98F5-41CA-BEAC-96108848E9A7} - System32\Tasks\{788D2B0E-3C3B-4BC1-B431-1E12DCC0A01A} => D:\Downloads\cw\_ISDEL.EXE
Task: {70F9344D-2161-4B26-AF96-B922EC0F3ABB} - System32\Tasks\{3CF7E229-28D7-4331-BF9B-1CDCF6B4F4FF} => D:\Downloads\cw\_ISDEL.EXE
Task: {843F19A6-C9D5-42AE-BC06-46A167A912DC} - System32\Tasks\{B96C25D8-330D-41BF-8883-9649DAEF8860} => D:\Programme\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe [2013-06-13] (Telltale Games)
Task: {85219D1F-CE4B-46D8-B9F9-E63F1A072D75} - System32\Tasks\{2E91CA63-603D-48AD-8938-BE786B129D6F} => D:\Downloads\cw\_ISDEL.EXE
Task: {87064252-2B89-48E8-9842-A01535EB0A2B} - System32\Tasks\{C241B640-E594-4445-834E-C98E09E502C2} => D:\win2000\Spiele\TIM\TIM.EXE [1992-12-02] ()
Task: {893EDC64-BA89-4ED9-ACAD-34E35E8EA9D2} - System32\Tasks\{EA10D796-2F7D-4DBA-8E59-ED17C68364E1} => D:\Downloads\cw\_ISDEL.EXE
Task: {8C9D1022-45C0-45C9-885E-064EAC862BB8} - System32\Tasks\Games\UpdateCheck_S-1-5-21-947829332-907023176-1988660606-1000
Task: {92975852-5C4E-4EDF-9D33-5A23D32FD7C8} - System32\Tasks\CoreTemp => C:\Program Files\Core Temp\Core Temp.exe [2013-10-08] ()
Task: {93C851BF-76CD-4E74-B65A-C35C1525286C} - System32\Tasks\{8E425AD3-5B54-4C6D-96AF-53AABB33EB42} => D:\Downloads\cw\_ISDEL.EXE
Task: {94319EEC-614C-4641-8753-3F3D4E29C818} - System32\Tasks\{95D5D9C2-B16F-4912-BB29-D178CA73D8AD} => D:\Downloads\cw\_ISDEL.EXE
Task: {955D9BD4-3E10-4B79-873D-3224570E7EF6} - System32\Tasks\{95BBF6BF-FAE9-41C1-ABEA-36906C71AAB4} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {96EE00EA-983A-4BD3-8E6B-7B2E322A6187} - System32\Tasks\{234728B8-89C1-47DF-8090-31B04CC64829} => D:\Downloads\cw\_ISDEL.EXE
Task: {97621CFA-2AFD-4821-B525-F512726D756B} - System32\Tasks\{83DE6C96-A7F9-4652-9D0A-2DDC40CEEA92} => D:\win2000\Spiele\TIM\TIM.EXE [1992-12-02] ()
Task: {9C40B4EB-54FC-4ED1-B261-4D9AA777A036} - System32\Tasks\{26ACD699-6450-42C5-A6A0-5A10759AF95B} => D:\Programme\Steam\SteamApps\common\The Walking Dead\WalkingDead101.exe [2013-06-13] (Telltale Games)
Task: {A0E007CF-413C-4265-BA02-2D4159DF766C} - System32\Tasks\{BF63503B-FC7F-40DE-9371-C24BAAA82258} => D:\Downloads\cw\_ISDEL.EXE
Task: {A122469E-DFB4-4063-BFF1-A60ECC28F37F} - System32\Tasks\{0917D354-037A-4DFC-BF65-DF46FF3364C3} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {A55714CD-DC44-48BC-B7B5-64EFEA875F2B} - System32\Tasks\{465A9385-147D-4B1A-99C8-72299246B498} => D:\Downloads\cw\_ISDEL.EXE
Task: {AE4D2AE7-B993-42CA-A1E2-E24F3E7DAEFE} - System32\Tasks\{B9A44044-F3A2-4DED-A0A5-B0E5D8325B43} => D:\Downloads\cw\_ISDEL.EXE
Task: {BBB7BF45-C805-4763-B3FE-F44181255713} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {BBD49039-0275-4DC0-999A-B77F68DF1F45} - System32\Tasks\{42093772-688F-446F-882F-34E944E3B59F} => D:\win2000\Spiele\TIM\TIM.EXE [1992-12-02] ()
Task: {BC860AA1-4ADC-4D2F-8BCB-CCC2511E3C25} - System32\Tasks\{3BD19485-3C97-4EE0-BCFB-A47C8082AA31} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {CC7C91BB-25DA-4B3A-BADC-46C4421B93F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-02] (Google Inc.)
Task: {D4C40817-28DF-4951-84D7-0F4489DDA0AE} - System32\Tasks\{418F172E-36FD-4325-AE74-A44C6A6B0E7C} => D:\win2000\Spiele\TIM\TIM.EXE [1992-12-02] ()
Task: {D97D9C21-0550-4A6F-81B9-710115BA803A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-02] (Google Inc.)
Task: {DA5AB32D-6DF1-400C-AC08-0B8FDA07D49C} - System32\Tasks\{C6ADAA44-BC5C-4C5C-A17C-E5FDCA7BB0B4} => D:\Downloads\cw\_ISDEL.EXE
Task: {DE3ED77A-680C-4E82-84B7-89157BC86AE8} - System32\Tasks\{1C36A80E-60E4-48F8-BB6D-B61F4CB6B7D0} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {E0A55270-59E4-44AA-B6AA-F6BD0898D3C4} - System32\Tasks\{857FAFAD-158D-49AC-9720-EEC266A135CD} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {E361BACB-06EA-403F-8229-E4C9E30A92D3} - System32\Tasks\{AD046883-E857-4CCB-884F-F5B963E40308} => D:\Downloads\cw\_ISDEL.EXE
Task: {E69F4FD0-D512-4150-8E84-F8E4ED323BF4} - System32\Tasks\{1F480388-6D7E-4D65-83D0-96D2E09D69B9} => D:\Downloads\cw\_ISDEL.EXE
Task: {ED8002D8-6155-40EF-ACB5-9F4C2F1F13F5} - System32\Tasks\{122499FC-A903-4E96-8E3C-258AFACB2668} => D:\Downloads\cw\_ISDEL.EXE
Task: {F15F4F1F-AEDE-450B-87B0-0F6A900F2FE3} - System32\Tasks\{8FC48BF0-DC4E-4057-A7EF-57CB57117C27} => D:\win2000\MCCLEVER\9BALL10\SETUP.EXE [1994-11-03] ()
Task: {F3DA0080-0A60-4293-9A85-AD0835ACE498} - System32\Tasks\{1BB51E4D-8CDC-4BB9-8A49-0759A9F9F87A} => D:\Downloads\cw\_ISDEL.EXE
Task: {F49FF781-8308-45F9-929F-9D112D17535F} - \DSite No Task File
Task: {F9C08971-3591-4307-8DAC-8F0F02647F1C} - System32\Tasks\{0A63B5D2-796B-4C12-A737-18EA0ABF2277} => D:\Downloads\cw\_ISDEL.EXE
Task: {FA1CEDA6-4EE9-4FC7-BA75-293D15B15C2F} - System32\Tasks\{A6DC2A50-0E7E-422A-8922-78618293EECC} => D:\Downloads\cw\_ISDEL.EXE
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-09-13 23:24 - 2012-01-29 09:55 - 00657920 _____ () D:\Programme\TeraCopy\TeraCopy64.dll
2013-05-12 10:38 - 2013-07-19 15:20 - 00687616 _____ () D:\Programme\NetWorx\sqlite.dll
2013-05-12 10:38 - 2013-07-20 11:12 - 00115704 _____ () D:\Programme\NetWorx\nfapi.dll
2013-10-13 18:05 - 2013-10-13 18:05 - 00752824 _____ () D:\Programme\Rainmeter\Rainmeter.dll
2013-10-13 18:04 - 2013-10-13 18:04 - 00022528 _____ () D:\Programme\Rainmeter\Plugins\WifiStatus.dll
2013-10-13 18:01 - 2013-10-13 18:01 - 00011264 _____ () D:\Programme\Rainmeter\Plugins\CoreTemp.DLL
2013-10-13 18:04 - 2013-10-13 18:04 - 00064000 _____ () D:\Programme\Rainmeter\Plugins\WebParser.dll
2013-08-27 12:42 - 2013-08-27 12:42 - 01260624 _____ () D:\Programme\VMware2\libxml2.dll
2013-08-15 09:10 - 2013-08-15 09:10 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\eb4812681f6ab4406053f3a1803e6da0\IsdiInterop.ni.dll
2012-03-22 21:59 - 2010-11-06 00:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-10-24 09:48 - 2013-10-23 21:29 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.34\libglesv2.dll
2013-10-24 09:48 - 2013-10-23 21:29 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.34\libegl.dll
2013-10-24 09:48 - 2013-10-23 21:29 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.34\pdf.dll
2013-10-24 09:48 - 2013-10-23 21:29 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.34\ppGoogleNaClPluginChrome.dll
2013-10-24 09:48 - 2013-10-23 21:29 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.34\ffmpegsumo.dll
2013-10-24 09:48 - 2013-10-23 21:29 - 13584336 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.34\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/25/2013 00:29:45 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/27/2012 00:03:13 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2013 00:13:44 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2013 08:46:12 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (10/25/2013 08:03:21 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2013 00:04:09 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 11:09:48 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 10:44:23 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 10:28:10 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 10:02:36 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (04/27/2012 00:06:49 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst G Data Personal Firewall konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Error: (04/27/2012 00:02:34 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (04/27/2012 00:02:33 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (04/27/2012 00:02:32 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (04/27/2012 00:02:32 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (04/27/2012 00:02:16 AM) (Source: VDS Basic Provider) (User: )
Description: Unerwarteter Fehler. Fehlercode: D@01010004
Error: (04/27/2012 00:02:15 AM) (Source: VDS Basic Provider) (User: )
Description: Unerwarteter Fehler. Fehlercode: D@01010004
Error: (10/25/2013 00:14:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst G Data Personal Firewall konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Error: (10/25/2013 09:26:11 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst G Data Personal Firewall konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Error: (10/25/2013 00:14:13 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst G Data Personal Firewall konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Microsoft Office Sessions:
=========================
Error: (10/25/2013 00:29:45 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/27/2012 00:03:13 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2013 00:13:44 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2013 08:46:12 AM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe
Error: (10/25/2013 08:03:21 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2013 00:04:09 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 11:09:48 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 10:44:23 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 10:28:10 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/24/2013 10:02:36 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2013-01-26 16:36:18.266
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Stephan\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-01-26 16:36:18.251
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\Stephan\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-01-26 16:36:18.207
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Programme\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-01-26 16:36:18.192
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Programme\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-12-12 20:22:25.081
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-12-12 20:22:25.081
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-08-01 15:03:19.645
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Common Files\T-Com\DSLCheck\PCIDumpr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-08-01 15:03:19.638
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Common Files\T-Com\DSLCheck\PCIDumpr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-08-01 15:03:05.311
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Common Files\T-Com\DSLCheck\PCIDumpr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-08-01 15:03:05.303
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Common Files\T-Com\DSLCheck\PCIDumpr.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 32%
Total physical RAM: 12252.16 MB
Available physical RAM: 8321.22 MB
Total Pagefile: 12266.34 MB
Available Pagefile: 7636.9 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive b: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive c: (System) (Fixed) (Total:97.66 GB) (Free:13.36 GB) NTFS
Drive d: (Daten) (Fixed) (Total:833.76 GB) (Free:410.89 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: DCF43BDA)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=98 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=834 GB) - (Type=07 NTFS)
==================== End Of Log ============================ ----------------------
GMER: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-25 12:44:36
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EZRX-00A8LB0 rev.01.01A01 931,51GB
Running: d56ne4no.exe; Driver: C:\Users\Stephan\AppData\Local\Temp\fwrdrkoc.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1112] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1112] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
.text D:\Programme\O&O Defrag Free Edition\oodag.exe[1528] C:\Windows\system32\kernel32.dll!SetUnhandledExceptionFilter 0000000077a39b80 13 bytes {MOV R11, 0x140001400; JMP R11}
.text C:\Windows\SysWOW64\PnkBstrA.exe[1924] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000073051a22 2 bytes [05, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1924] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000073051ad0 2 bytes [05, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1924] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000073051b08 2 bytes [05, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1924] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000073051bba 2 bytes [05, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1924] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000073051bda 2 bytes [05, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 26 00000000722f13c6 2 bytes [2F, 72]
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 74 00000000722f13f6 2 bytes [2F, 72]
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 257 00000000722f14ad 2 bytes [2F, 72]
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 303 00000000722f14db 2 bytes [2F, 72]
.text ... * 2
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 79 00000000722f1577 2 bytes [2F, 72]
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 175 00000000722f15d7 2 bytes [2F, 72]
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 620 00000000722f1794 2 bytes [2F, 72]
.text C:\Windows\SysWOW64\vmnat.exe[2168] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 921 00000000722f18c1 2 bytes [2F, 72]
.text D:\Programme\VMware2\vmware-authd.exe[2424] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text D:\Programme\VMware2\vmware-authd.exe[2424] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
.text C:\Users\Stephan\AppData\Local\Akamai\netsession_win.exe[3936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text C:\Users\Stephan\AppData\Local\Akamai\netsession_win.exe[3936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
.text C:\Users\Stephan\AppData\Local\Akamai\netsession_win.exe[4008] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text C:\Users\Stephan\AppData\Local\Akamai\netsession_win.exe[4008] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
.text D:\Gdata\Firewall\GDFirewallTray.exe[3724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text D:\Gdata\Firewall\GDFirewallTray.exe[3724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[7536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766c1465 2 bytes [6C, 76]
.text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[7536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766c14bb 2 bytes [6C, 76]
.text ... * 2
---- EOF - GMER 2.1 ---- Hoffentlich kann mir jemand helfen :)
lg
Polypropylen |