Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 02.06.2014
Suchlauf-Zeit: 09:04:22
Logdatei:
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.02.03
Rootkit Datenbank: v2014.05.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: user
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 478232
Verstrichene Zeit: 21 Min, 34 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 1
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-2.2, In Quarantäne, [54bbea6a2d4e33032696c1df0df58a76],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 3
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[65aa8acabac16fc7b119bda3a95b926e]
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SECURITY CENTER|AntiVirusDisableNotify, 1, Gut: (0), Schlecht: (1),Ersetzt,[42cdb79d6c0f3bfb9fecf368dd2749b7]
PUM.Disabled.SecurityCenter, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SECURITY CENTER|UpdatesDisableNotify, 1, Gut: (0), Schlecht: (1),Ersetzt,[3bd4e76dbebdaf87f19c62f9c73d3ac6]
Ordner: 7
PUP.Optional.PriceGong.A, C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok, In Quarantäne, [ac63f262afcc3600c385b8c7669c3dc3],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\js, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\options, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\plugins, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\res, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
Dateien: 13
PUP.Optional.Spigot.A, C:\ProgramData\YTD Video Downloader\ytd_installer.exe, In Quarantäne, [d837ec6887f4d5613a459c8aaa5641bf],
Backdoor.Agent.DC, C:\Windows\SysWOW64\DCSCMIN\IMDCSC.exe, In Quarantäne, [3cd394c0572439fdbf669de1bb489868],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\manifest.json, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\pg_background.html, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\js\html_comp.js, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\js\pg_page_injected_script.js, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\js\pg_tab_wrapper.js, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\options\pg_options.html, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\options\pg_options.js, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\plugins\npPriceGong_CH.dll, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\res\pg_icon_128.png, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\res\pg_icon_16.png, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
PUP.Optional.PriceGong.A, C:\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.12_0\res\pg_icon_48.png, In Quarantäne, [ad623e16e6952d09c2868af5b34f0cf4],
Physische Sektoren: 0
(No malicious items detected)
(end) Malware Schutz etc. war wegen Combofix deaktiviert, wieder aktiviert.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014 01
Ran by user (administrator) on STANS-PC on 02-06-2014 09:29:57
Running from C:\Users\user\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
() C:\Program Files (x86)\puush\puush.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Spotify Ltd) C:\Users\user\AppData\Roaming\Spotify\spotify.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(FNet Co., Ltd.) C:\Program Files (x86)\XFastUsb\XFastUsb.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MsmqIntCert] => regsvr32 /s mqrt.dll
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-13] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1225920 2014-04-02] (NVIDIA Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3019376 2011-02-22] (VIA)
HKLM-x32\...\Run: [XFastUsb] => C:\Program Files (x86)\XFastUsb\XFastUsb.exe [4942336 2012-01-08] (FNet Co., Ltd.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SSBkgdUpdate] => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-10] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-10] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort11reminder] => C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3888648 2014-05-31] (AVAST Software)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] - "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe" "C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware" [54072 2014-05-12] (Malwarebytes Corporation)
HKLM-x32\...\Winlogon: [Userinit] c:\windows\system32\userinit.exe,c:\program files (x86)\brother\controlcenter3\brctrcensrv.exe, [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2406318905-1240849825-252203313-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1754816 2014-05-29] (Valve Corporation)
HKU\S-1-5-21-2406318905-1240849825-252203313-1000\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-2406318905-1240849825-252203313-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2013-09-29] ()
HKU\S-1-5-21-2406318905-1240849825-252203313-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21445248 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-2406318905-1240849825-252203313-1000\...\Run: [Spotify] => C:\Users\user\AppData\Roaming\Spotify\spotify.exe [6170168 2014-05-15] (Spotify Ltd)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB4A034104DDECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {4CA0C149-4213-4B04-B3CA-76141F79093B} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
SearchScopes: HKCU - {6EC98539-C975-41B0-8D84-967EBD599058} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag=tonline-browser_toolbar3_search-21&index=blended&linkCode=ur2
SearchScopes: HKCU - {A31EAB68-FEA5-4C79-903F-9CB11BCA86E9} URL = hxxp://suche.t-online.de/fast-cgi/tsc?sr=twiki&q={searchTerms}&dia=tie8
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKCU - No Name - {2015C8D4-8534-48DB-B5FB-5C76291F080C} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4102exwr.default
FF NewTab: chrome://quick_start/content/index.html
FF NetworkProxy: "http", "localhost"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: wacom.com/WacomTabletPlugin - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll No File
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\user\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\user\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4102exwr.default\Extensions\staged [2014-05-25]
FF Extension: NoScript - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4102exwr.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-05-10]
FF Extension: Adblock Plus - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4102exwr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-05-24]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-05-12]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-10-06]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKCU\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\user\AppData\Local\CRE\ngnjhfpfhadncgafgbneeljaginimmmk.crx []
CHR HKLM-x32\...\Chrome\Extension: [neibkbfmjpkenkbjpajgfkedjaehefnc] - C:\ProgramData\DownloadnSave\neibkbfmjpkenkbjpajgfkedjaehefnc.crx []
CHR HKLM-x32\...\Chrome\Extension: [ngnjhfpfhadncgafgbneeljaginimmmk] - C:\Users\user\AppData\Local\CRE\ngnjhfpfhadncgafgbneeljaginimmmk.crx []
CHR StartMenuInternet: Google Chrome - C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-31] (AVAST Software)
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-20] (Microsoft Corporation)
R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4466688 2007-11-08] (Microsoft Corporation)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2404864 2011-03-24] (Deutsche Telekom AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
S2 Mikogo-Service; C:\Users\user\AppData\Roaming\Mikogo\Mikogo-Service.exe [X]
==================== Drivers (Whitelisted) ====================
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-31] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-31] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-31] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-31] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-31] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-31] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-31] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-31] ()
S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-01-08] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-01-08] (FNet Co., Ltd.)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [122584 2014-06-02] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation)
S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WacHidRouter; system32\DRIVERS\wachidrouter.sys [X]
S3 wacomrouterfilter; system32\DRIVERS\wacomrouterfilter.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-02 09:01 - 2014-06-02 09:04 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-02 09:01 - 2014-06-02 09:01 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-02 09:01 - 2014-06-02 09:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-02 09:01 - 2014-06-02 09:01 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-02 09:01 - 2014-06-02 09:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-02 09:01 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-02 09:01 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-02 09:01 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-02 08:59 - 2014-06-02 09:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-02 08:32 - 2014-06-02 08:32 - 00001208 _____ () C:\Windows\SysWOW64\collectionCache.bnk
2014-06-02 08:21 - 2014-06-02 08:21 - 00049703 _____ () C:\ComboFix.txt
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.007\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.006\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.005\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.004\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.003\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.002\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.000\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp
2014-06-02 08:04 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-02 08:04 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-02 08:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-02 08:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-02 08:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-02 08:04 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-02 08:04 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-02 08:04 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-02 08:03 - 2014-06-02 08:22 - 00000000 ____D () C:\Qoobox
2014-06-02 08:03 - 2014-06-02 08:20 - 00000000 ____D () C:\Windows\erdnt
2014-06-02 08:01 - 2014-06-02 08:01 - 05203398 ____R (Swearware) C:\Users\user\Desktop\ComboFix.exe
2014-06-02 08:00 - 2014-06-02 08:01 - 05203398 _____ (Swearware) C:\Users\user\Downloads\ComboFix.exe
2014-06-01 21:14 - 2014-06-02 09:29 - 00020532 _____ () C:\Users\user\Desktop\FRST.txt
2014-06-01 21:14 - 2014-06-01 21:15 - 00040504 _____ () C:\Users\user\Desktop\Addition.txt
2014-06-01 21:13 - 2014-06-02 09:29 - 00000000 ____D () C:\FRST
2014-06-01 21:11 - 2014-06-01 21:11 - 02067456 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2014-06-01 19:59 - 2014-06-01 19:59 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-06-01 19:59 - 2014-06-01 19:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-01 19:59 - 2014-06-01 19:59 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-01 19:33 - 2014-06-01 19:33 - 23681945 _____ () C:\Users\user\Desktop\UserLayoutOne.rar
2014-06-01 18:42 - 2014-06-01 18:42 - 00001208 _____ () C:\Windows\collectionCache.bnk
2014-06-01 18:07 - 2014-06-01 18:07 - 00002928 _____ () C:\Windows\System32\Tasks\{44DD2D46-375A-499B-8A4E-B6B9A604D303}
2014-05-31 19:22 - 2014-05-31 19:22 - 00003132 _____ () C:\Windows\System32\Tasks\{D6D44D57-77E6-4CEB-9E24-C0BFC2337A46}
2014-05-31 11:49 - 2014-05-31 11:49 - 00000000 ____D () C:\Users\user\AppData\Roaming\AVAST Software
2014-05-31 11:41 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-31 11:40 - 2014-05-31 11:43 - 00000000 ____D () C:\AdwCleaner
2014-05-31 11:36 - 2014-05-31 12:07 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-31 11:36 - 2014-05-31 11:36 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-31 11:36 - 2014-05-31 11:36 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-29 17:31 - 2014-05-29 17:31 - 00000000 _____ () C:\dfu.log
2014-05-27 13:48 - 2014-06-01 17:13 - 583307911 _____ () C:\Windows\MEMORY.DMP
2014-05-27 12:49 - 2014-06-02 08:16 - 00000000 ____D () C:\Users\Public\Documents\MSDCSC
2014-05-25 00:01 - 2014-05-25 00:01 - 81471565 _____ () C:\Users\user\Desktop\UserLayoutOne.DMP
2014-05-24 03:11 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32_backup_wti.dll
2014-05-24 03:11 - 2011-07-05 04:00 - 01857536 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame_backup_wti.dll
2014-05-24 03:11 - 2010-11-20 15:27 - 00898560 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr_backup_wti.dll
2014-05-24 02:24 - 2014-05-24 02:24 - 00000000 ____D () C:\Users\user\AppData\Local\mfbot.de
2014-05-23 20:09 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.006
2014-05-23 20:09 - 2014-05-23 20:09 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.007
2014-05-23 20:09 - 2013-12-14 02:23 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.007\AppData\Local\Google
2014-05-23 19:29 - 2014-05-23 19:29 - 00558464 _____ () C:\Windows\Minidump\052314-41823-01.dmp
2014-05-23 19:20 - 2014-05-23 19:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.005
2014-05-20 21:17 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-20 21:17 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-20 21:17 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-20 21:17 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-20 21:16 - 2014-05-20 21:17 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-18 02:45 - 2014-05-18 02:35 - 00000000 ____D () C:\images_gui
2014-05-18 01:43 - 2014-05-18 01:43 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.004
2014-05-18 01:43 - 2013-12-14 02:23 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.004\AppData\Local\Google
2014-05-18 01:42 - 2014-05-18 01:42 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.003
2014-05-17 23:03 - 2014-05-17 23:03 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft Corporation
2014-05-17 13:08 - 2013-04-30 19:18 - 00014136 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\hidkmdf.sys
2014-05-17 12:01 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-17 12:01 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-17 12:01 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-17 12:01 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-17 12:01 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-17 12:01 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 23:46 - 2014-06-01 19:14 - 00000000 ____D () C:\Users\user\Documents\Visual Studio 2010
2014-05-15 23:46 - 2014-05-19 00:37 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express
2014-05-15 13:04 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 13:04 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 13:03 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 13:03 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 13:03 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 13:03 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 13:03 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 13:03 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 13:03 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 13:03 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 13:03 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 13:03 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 13:03 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 13:03 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 13:03 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 13:03 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 13:03 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 13:03 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 13:03 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 13:03 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 13:03 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 13:03 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 13:03 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 13:03 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 13:03 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 13:03 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 13:03 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 13:03 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 13:03 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 13:03 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 13:03 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 13:03 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 23:29 - 2014-05-13 23:29 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-12 16:04 - 2014-05-12 16:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-06 16:02 - 2014-05-06 16:02 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA Corporation
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 ____D () C:\Users\Administrator
2014-05-06 16:02 - 2014-05-03 22:04 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-06 16:02 - 2013-12-14 02:23 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-05-06 16:02 - 2013-10-09 00:20 - 00000000 ____D () C:\Users\Administrator\Documents\Visual Studio 2010
2014-05-06 16:02 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-06 16:02 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-05-04 12:24 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-05-04 12:18 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-05-04 12:18 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-05-04 12:18 - 2014-03-04 16:35 - 00024544 _____ () C:\Windows\system32\nvinfo.pb
2014-05-04 12:18 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-05-04 12:18 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-05-04 12:11 - 2014-03-21 21:43 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-05-04 12:11 - 2014-03-21 21:43 - 00033568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-05-03 10:20 - 2014-05-03 10:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.002
2014-05-03 10:20 - 2014-05-03 10:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-03 10:20 - 2014-05-03 10:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001
==================== One Month Modified Files and Folders =======
2014-06-02 09:30 - 2014-06-01 21:14 - 00020532 _____ () C:\Users\user\Desktop\FRST.txt
2014-06-02 09:30 - 2012-01-08 00:36 - 00000000 ____D () C:\Users\user\AppData\Local\Temp
2014-06-02 09:29 - 2014-06-01 21:13 - 00000000 ____D () C:\FRST
2014-06-02 09:29 - 2012-01-16 14:09 - 00000000 ____D () C:\Users\user\AppData\Roaming\Skype
2014-06-02 09:28 - 2012-06-14 22:33 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-02 09:27 - 2014-02-25 16:22 - 00000000 ___HD () C:\ProgramData\YTD Video Downloader
2014-06-02 09:27 - 2013-06-28 23:08 - 00000000 ____D () C:\Windows\SysWOW64\DCSCMIN
2014-06-02 09:04 - 2014-06-02 09:01 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-02 09:01 - 2014-06-02 09:01 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-02 09:01 - 2014-06-02 09:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-02 09:01 - 2014-06-02 09:01 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-02 09:01 - 2014-06-02 09:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-02 09:00 - 2014-06-02 08:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-02 08:44 - 2012-01-16 15:24 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2406318905-1240849825-252203313-1000UA.job
2014-06-02 08:36 - 2012-01-08 00:38 - 01758778 _____ () C:\Windows\WindowsUpdate.log
2014-06-02 08:34 - 2012-06-03 19:56 - 00000000 ____D () C:\Users\user\AppData\Roaming\Spotify
2014-06-02 08:34 - 2012-03-05 19:21 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-02 08:32 - 2014-06-02 08:32 - 00001208 _____ () C:\Windows\SysWOW64\collectionCache.bnk
2014-06-02 08:30 - 2012-10-06 23:10 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-02 08:30 - 2012-03-02 21:25 - 00000433 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-06-02 08:30 - 2009-07-14 06:51 - 00150358 _____ () C:\Windows\setupact.log
2014-06-02 08:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\inetsrv
2014-06-02 08:28 - 2013-04-24 21:37 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-06-02 08:28 - 2012-03-05 19:21 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-02 08:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-02 08:26 - 2012-01-12 14:38 - 01782054 _____ () C:\Windows\PFRO.log
2014-06-02 08:26 - 2012-01-08 01:00 - 00000000 ___HD () C:\ProgramData\NVIDIA
2014-06-02 08:22 - 2014-06-02 08:03 - 00000000 ____D () C:\Qoobox
2014-06-02 08:21 - 2014-06-02 08:21 - 00049703 _____ () C:\ComboFix.txt
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.007\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.006\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.005\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.004\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.003\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.002\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.000\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-02 08:21 - 2014-06-02 08:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\temp
2014-06-02 08:21 - 2014-05-23 20:09 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.006
2014-06-02 08:20 - 2014-06-02 08:03 - 00000000 ____D () C:\Windows\erdnt
2014-06-02 08:19 - 2009-07-14 04:34 - 00000312 _____ () C:\Windows\system.ini
2014-06-02 08:16 - 2014-05-27 12:49 - 00000000 ____D () C:\Users\Public\Documents\MSDCSC
2014-06-02 08:16 - 2013-05-16 12:45 - 00000000 ___RD () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-02 08:16 - 2012-01-20 20:51 - 00000000 __SHD () C:\Users\user\Documents\MSDCSC
2014-06-02 08:01 - 2014-06-02 08:01 - 05203398 ____R (Swearware) C:\Users\user\Desktop\ComboFix.exe
2014-06-02 08:01 - 2014-06-02 08:00 - 05203398 _____ (Swearware) C:\Users\user\Downloads\ComboFix.exe
2014-06-02 07:23 - 2012-06-03 19:57 - 00000000 ____D () C:\Users\user\AppData\Local\Spotify
2014-06-01 23:44 - 2012-01-16 15:24 - 00001064 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2406318905-1240849825-252203313-1000Core.job
2014-06-01 21:15 - 2014-06-01 21:14 - 00040504 _____ () C:\Users\user\Desktop\Addition.txt
2014-06-01 21:11 - 2014-06-01 21:11 - 02067456 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2014-06-01 19:59 - 2014-06-01 19:59 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-06-01 19:59 - 2014-06-01 19:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-01 19:59 - 2014-06-01 19:59 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-01 19:58 - 2009-07-14 06:45 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-01 19:58 - 2009-07-14 06:45 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-01 19:55 - 2014-04-29 13:26 - 00000000 ____D () C:\Users\user\AppData\Roaming\WTablet
2014-06-01 19:33 - 2014-06-01 19:33 - 23681945 _____ () C:\Users\user\Desktop\UserLayoutOne.rar
2014-06-01 19:14 - 2014-05-15 23:46 - 00000000 ____D () C:\Users\user\Documents\Visual Studio 2010
2014-06-01 18:50 - 2014-04-25 22:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-06-01 18:42 - 2014-06-01 18:42 - 00001208 _____ () C:\Windows\collectionCache.bnk
2014-06-01 18:07 - 2014-06-01 18:07 - 00002928 _____ () C:\Windows\System32\Tasks\{44DD2D46-375A-499B-8A4E-B6B9A604D303}
2014-06-01 17:57 - 2013-10-07 20:57 - 00000000 ___RD () C:\Users\user\Desktop\GTA Mods
2014-06-01 17:54 - 2012-02-24 17:38 - 00000000 ___RD () C:\Users\user\Desktop\Stuff
2014-06-01 17:14 - 2013-06-07 21:53 - 00000000 ____D () C:\Windows\Minidump
2014-06-01 17:13 - 2014-05-27 13:48 - 583307911 _____ () C:\Windows\MEMORY.DMP
2014-06-01 17:02 - 2013-08-08 14:19 - 00000000 ____D () C:\Users\user\Documents\GTA San Andreas User Files
2014-05-31 20:08 - 2013-01-04 19:42 - 00000000 ____D () C:\Users\user\AppData\Local\Mato_Technologies
2014-05-31 19:22 - 2014-05-31 19:22 - 00003132 _____ () C:\Windows\System32\Tasks\{D6D44D57-77E6-4CEB-9E24-C0BFC2337A46}
2014-05-31 16:02 - 2012-10-28 23:20 - 00000000 ____D () C:\Users\user\AppData\Roaming\vlc
2014-05-31 12:22 - 2012-02-26 00:07 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2014-05-31 12:07 - 2014-05-31 11:36 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-31 12:07 - 2012-10-06 23:11 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-31 12:07 - 2012-10-06 23:11 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-31 11:49 - 2014-05-31 11:49 - 00000000 ____D () C:\Users\user\AppData\Roaming\AVAST Software
2014-05-31 11:43 - 2014-05-31 11:40 - 00000000 ____D () C:\AdwCleaner
2014-05-31 11:36 - 2014-05-31 11:36 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-31 11:36 - 2014-05-31 11:36 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-31 11:36 - 2013-03-10 17:07 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-05-31 11:36 - 2013-03-10 17:07 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-05-31 11:36 - 2012-10-06 23:11 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1401530828817
2014-05-31 11:36 - 2012-10-06 23:11 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1401530828817
2014-05-31 11:36 - 2012-10-06 23:11 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-05-31 11:36 - 2012-10-06 23:10 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-05-31 11:36 - 2012-10-06 23:10 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-05-31 11:31 - 2012-10-06 23:10 - 00000000 ___HD () C:\ProgramData\AVAST Software
2014-05-31 11:30 - 2012-10-06 23:10 - 00000000 _____ () C:\Windows\SysWOW64\config.nt
2014-05-31 11:27 - 2012-09-11 22:32 - 00000000 ____D () C:\Users\user\AppData\Local\Deployment
2014-05-31 10:08 - 2012-01-19 14:36 - 00000000 ____D () C:\Users\user\AppData\Roaming\DVDVideoSoft
2014-05-30 01:40 - 2012-01-26 14:48 - 88247296 ___SH () C:\Users\user\Desktop\Thumbs.db
2014-05-29 17:31 - 2014-05-29 17:31 - 00000000 _____ () C:\dfu.log
2014-05-29 16:56 - 2013-09-11 22:23 - 00000000 ____D () C:\Users\user\AppData\Local\fabi.me
2014-05-29 13:22 - 2013-09-25 16:27 - 00000000 ____D () C:\Users\user\Documents\Bewerbungszeug
2014-05-27 14:05 - 2012-02-24 17:59 - 00000000 ___HD () C:\ProgramData\MTA San Andreas All
2014-05-26 21:40 - 2013-04-11 13:37 - 00014336 ___SH () C:\Users\user\AppData\Roaming\Thumbs.db
2014-05-26 21:00 - 2013-03-01 16:41 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-05-26 21:00 - 2012-01-16 14:09 - 00000000 ___HD () C:\ProgramData\Skype
2014-05-25 00:01 - 2014-05-25 00:01 - 81471565 _____ () C:\Users\user\Desktop\UserLayoutOne.DMP
2014-05-24 03:12 - 2013-04-25 22:33 - 00925184 _____ () C:\Windows\expstart.exe
2014-05-24 03:11 - 2013-04-25 22:40 - 01566616 _____ () C:\Windows\UTP.exe
2014-05-24 02:24 - 2014-05-24 02:24 - 00000000 ____D () C:\Users\user\AppData\Local\mfbot.de
2014-05-23 20:09 - 2014-05-23 20:09 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.007
2014-05-23 19:29 - 2014-05-23 19:29 - 00558464 _____ () C:\Windows\Minidump\052314-41823-01.dmp
2014-05-23 19:20 - 2014-05-23 19:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.005
2014-05-22 22:48 - 2013-01-04 02:29 - 00000000 ____D () C:\Users\user\AppData\Roaming\TS3Client
2014-05-20 21:17 - 2014-05-20 21:16 - 00004161 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 21:17 - 2012-01-30 01:40 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-19 15:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-19 00:37 - 2014-05-15 23:46 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express
2014-05-18 02:35 - 2014-05-18 02:45 - 00000000 ____D () C:\images_gui
2014-05-18 01:43 - 2014-05-18 01:43 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.004
2014-05-18 01:42 - 2014-05-18 01:42 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.003
2014-05-18 00:12 - 2012-09-28 22:47 - 00000000 ___RD () C:\Users\user\Desktop\GFX Stuff
2014-05-17 23:03 - 2014-05-17 23:03 - 00000000 ____D () C:\Users\user\AppData\Roaming\Microsoft Corporation
2014-05-17 21:56 - 2013-10-08 00:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0
2014-05-17 18:56 - 2013-08-21 20:33 - 00000000 ____D () C:\Users\user\minecraft
2014-05-17 13:20 - 2012-01-08 00:37 - 00000000 ___RD () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-17 13:14 - 2013-10-04 22:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-17 13:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-17 11:58 - 2013-08-15 13:37 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-17 11:56 - 2009-10-14 07:12 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 14:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors
2014-05-14 14:38 - 2012-06-16 17:28 - 00000000 ____D () C:\Program Files (x86)\RocketDock
2014-05-13 23:29 - 2014-05-13 23:29 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 23:29 - 2012-06-14 22:33 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-13 23:29 - 2012-06-14 22:33 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 23:29 - 2012-01-16 14:37 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-12 16:04 - 2014-05-12 16:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-12 07:26 - 2014-06-02 09:01 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-02 09:01 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-02 09:01 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 10:26 - 2013-12-22 21:43 - 00000000 ____D () C:\Program Files (x86)\GameforgeLive
2014-05-07 13:29 - 2012-03-05 19:21 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-07 13:29 - 2012-03-05 19:21 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 16:02 - 2014-05-06 16:02 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Vorlagen
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Startmenü
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Lokale Einstellungen
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Eigene Dateien
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Anwendungsdaten
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 _SHDL () C:\Users\Administrator\Anwendungsdaten
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA Corporation
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA
2014-05-06 16:02 - 2014-05-06 16:02 - 00000000 ____D () C:\Users\Administrator
2014-05-06 06:40 - 2014-05-17 12:01 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-17 12:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-17 12:01 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-17 12:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-17 12:01 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-17 12:01 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 23:39 - 2012-01-16 15:24 - 00004088 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2406318905-1240849825-252203313-1000UA
2014-05-05 23:39 - 2012-01-16 15:24 - 00003692 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2406318905-1240849825-252203313-1000Core
2014-05-04 12:25 - 2012-10-06 17:11 - 00000000 ___HD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-05-04 12:25 - 2012-01-08 01:00 - 00000000 ___HD () C:\ProgramData\NVIDIA Corporation
2014-05-04 12:25 - 2012-01-08 01:00 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-05-04 12:13 - 2014-04-07 01:46 - 00000000 ____D () C:\Users\user\AppData\Local\NVIDIA Corporation
2014-05-03 22:07 - 2013-06-21 13:36 - 00001421 _____ () C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-03 22:04 - 2014-05-06 16:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-03 22:04 - 2012-01-11 20:25 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-03 22:04 - 2012-01-11 20:25 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-03 10:20 - 2014-05-03 10:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.002
2014-05-03 10:20 - 2014-05-03 10:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-03 10:20 - 2014-05-03 10:20 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001
ZeroAccess:
C:\Users\user\AppData\Local\{d07a4bff-1acc-ef4b-5437-0786ab909512}
C:\Users\user\AppData\Local\{d07a4bff-1acc-ef4b-5437-0786ab909512}\@
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe
[2012-01-16 15:08] - [2011-02-25 07:30] - 2616320 ____A (Microsoft Corporation) 697651F303443F98F7EC76D4DCAE6789
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-29 13:58
==================== End Of Log ============================ --- --- --- |