|
Log-Analyse und Auswertung: Accountzugriffe aus TokyoWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.01.2014, 01:12 | #1 |
| Accountzugriffe aus Tokyo Hallo! Ich habe vor kurzem eine Email erhalten das sich jemand mit meinem Passwort in meinen GMail Account eingeloggt hat. Glücklicherweise wurde das von Google unterbunden und ich konnte mein Passwort ändern. Ich habe mir nichts weiter dabei gedacht, da nichts weiter vorgekommen ist. Soeben habe ich eine weitere Email bekommen das sich jemand mit meinem Passwort in ein MMORPG eingeloggt hat. Der Loginversuch in das GMail konto kam aus: Ningde, Fujian, China und der Loginversuch in das MMORPG kam aus Tokyo. Solangsam mache ich mir sorgen das ich mir was eingefangen habe. Der erste Vorfall war am 8. Januar. Scan mit FRST, FRST.txt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-01-2014 02 Ran by Daniel (administrator) on Daniel-PC on 27-01-2014 00:50:19 Running from C:\Users\Daniel\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Sandboxie Holdings, LLC) E:\Sandboxie\SbieSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Spotify Ltd) C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE (Nero AG) E:\HTC sync manager\HSMServiceEntry.exe (Sandboxie Holdings, LLC) E:\Sandboxie\SbieCtrl.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE (SteelSeries ApS) E:\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe () E:\puush\puush.exe () E:\HTC sync manager\HTC Sync\adb.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () D:\Leagueoflegends\RADS\system\rads_user_kernel.exe () D:\Leagueoflegends\RADS\projects\lol_launcher\releases\0.0.0.198\deploy\LoLLauncher.exe () D:\Leagueoflegends\RADS\projects\lol_air_client\releases\0.0.1.68\deploy\LolClient.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Spotify Ltd) C:\Users\Daniel\AppData\Roaming\Spotify\spotify.exe () C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13657304 2013-10-18] (Realtek Semiconductor) HKLM\...\Run: [MsmqIntCert] - regsvr32 /s mqrt.dll HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [Spotify] - C:\Users\Daniel\AppData\Roaming\Spotify\Spotify.exe [6118400 2014-01-17] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-17] (Spotify Ltd) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.) HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKCU\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe [35768 2013-12-09] (Overwolf) HKCU\...\Run: [SandboxieControl] - E:\Sandboxie\SbieCtrl.exe [759496 2013-10-16] (Sandboxie Holdings, LLC) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE [283232 2012-02-27] (SEIKO EPSON CORPORATION) HKCU\...\Run: [SteelSeries Engine] - E:\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [242688 2013-11-05] (SteelSeries ApS) HKCU\...\Run: [GoogleChromeAutoLaunch_5560E485902A34F6B1CF63ACD9274ABA] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [866584 2014-01-11] (Google Inc.) HKCU\...\Run: [puush] - E:\puush\puush.exe [567880 2013-12-22] () HKCU\...\Run: [EADM] - D:\Origin\Origin.exe [3598680 2014-01-23] (Electronic Arts) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4D3BFB3EDBCCCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKCU - DefaultScope {BC3ADBFF-A058-403F-98C3-7B6594437EEF} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=526426fd000000000000dc9c52072e08&r=413 SearchScopes: HKCU - {BC3ADBFF-A058-403F-98C3-7B6594437EEF} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=526426fd000000000000dc9c52072e08&r=413 BHO: No Name - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - No File BHO-x32: No Name - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Tcpip\Parameters: [DhcpNameServer] 192.168.188.1 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default FF user.js: detected! => C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - E:\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\searchplugins\softonic.xml FF Extension: iMacros for Firefox - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-01-06] FF Extension: Live HTTP Headers - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2013-11-25] FF Extension: SQLite Manager - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\SQLiteManager@mrinalkant.blogspot.com.xpi [2013-12-14] Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-19] CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-19] CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-19] CHR Extension: (Adblock Plus) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-13] CHR Extension: (Google-Suche) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-19] CHR Extension: (iMacros for Chrome) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp [2014-01-06] CHR Extension: (Foxtab Speed Dial) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchmpbaclbiioedakpcldenooikekokm [2014-01-22] CHR Extension: (FoxyProxy Standard) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcknhkkoolaabfmlnjonogaaifnjlfnp [2013-12-17] CHR Extension: (EXIF Viewer) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2014-01-16] CHR Extension: (EXIF Reader) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nchnjcdahncnilbicljpnbfobpnljnki [2014-01-16] CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-19] CHR Extension: (Google Mail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-19] CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-08-30] (Advanced Micro Devices, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-09] (Avira Operations GmbH & Co. KG) R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 HTCMonitorService; E:\HTC sync manager\HSMServiceEntry.exe [87368 2013-09-02] (Nero AG) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-21] (Microsoft Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-21] (Microsoft Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2014-01-15] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2014-01-15] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) R2 SbieSvc; E:\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-09] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-15] (Disc Soft Ltd) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation) R3 SbieDrv; E:\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-01-03] (Anchorfree Inc.) S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-27 00:50 - 2014-01-27 00:53 - 00017129 _____ C:\Users\Daniel\Downloads\FRST.txt 2014-01-27 00:50 - 2014-01-27 00:50 - 00000000 ____D C:\FRST 2014-01-27 00:49 - 2014-01-27 00:49 - 02078208 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe 2014-01-26 18:56 - 2014-01-26 18:57 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\JetBrains 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\SymbolSourceSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\RefSrcSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\JetBrains 2014-01-26 18:51 - 2014-01-26 18:53 - 29220864 _____ C:\Users\Daniel\Downloads\dotPeekSetup-1.1.1.33.msi 2014-01-26 18:46 - 2014-01-26 18:46 - 01467128 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE.exe 2014-01-26 18:38 - 2014-01-26 18:38 - 00157234 _____ C:\Users\Daniel\Downloads\RouterReconnect_1.3.zip 2014-01-26 18:38 - 2008-04-19 18:03 - 00335360 _____ (RPworld.de) C:\Users\Daniel\Desktop\RouterReconnect.exe 2014-01-26 18:37 - 2014-01-26 18:37 - 04689382 _____ C:\Users\Daniel\Downloads\curl-7.34.0.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 00094335 _____ C:\Users\Daniel\Downloads\Fritz!Box Reconnect.rar 2014-01-26 18:25 - 2014-01-26 18:29 - 00000000 _____ C:\Users\Daniel\Desktop\null 2014-01-26 18:24 - 2014-01-26 18:24 - 00041223 _____ C:\Users\Daniel\Downloads\Fritz_Box_reconnect.zip 2014-01-26 16:36 - 2014-01-26 16:49 - 00000000 ____D C:\Users\Daniel\Documents\Rezepte 2014-01-23 09:38 - 2014-01-23 09:38 - 42713738 _____ C:\Users\Daniel\Downloads\Devisual's Graphics Pack.rar 2014-01-17 12:16 - 2014-01-17 12:16 - 00092309 _____ C:\Users\Daniel\Downloads\MarkC_Windows_8.x+7_MouseFix.zip 2014-01-15 15:47 - 2014-01-15 15:47 - 00000749 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-15 15:46 - 2014-01-15 15:46 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 15:36 - 2014-01-15 15:38 - 08501736 _____ C:\Users\Daniel\Downloads\HSS-3.31-install-e-550-plain.exe 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2014-01-15 15:22 - 2014-01-15 15:22 - 00000530 _____ C:\Users\Public\Desktop\Origin.lnk 2014-01-15 15:20 - 2014-01-15 15:21 - 16952720 _____ (Electronic Arts, Inc.) C:\Users\Daniel\Downloads\OriginThinSetup.exe 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\EA Core 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Users\Daniel\AppData\Local\ESN 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2014-01-15 15:11 - 2014-01-15 15:11 - 03821064 _____ C:\Users\Daniel\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00012885 _____ C:\Users\Daniel\AppData\Local\recently-used.xbel 2014-01-15 09:23 - 2014-01-15 09:23 - 00004705 _____ C:\Users\Daniel\Downloads\First Person Camera Fix-6508-1.7z 2014-01-15 08:46 - 2014-01-15 08:46 - 00060838 _____ C:\Users\Daniel\Downloads\SafetyLoad 1_2-46465-1-2.zip 2014-01-15 08:06 - 2014-01-15 08:06 - 00003710 _____ C:\Users\Daniel\Downloads\High Prefs and inis ugrids 5 V27 ENB version-36146-v27.rar 2014-01-15 07:58 - 2014-01-15 07:58 - 12881617 _____ C:\Users\Daniel\Downloads\RealVision_ENB_245a-30936-245a.7z 2014-01-15 07:58 - 2014-01-15 07:58 - 02342720 _____ C:\Users\Daniel\Downloads\enbseries_skyrim_v0245.zip 2014-01-15 07:54 - 2014-01-15 07:54 - 01457128 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - Weather Patch-39799-15.rar 2014-01-15 07:53 - 2014-01-15 07:53 - 00020795 _____ C:\Users\Daniel\Downloads\Supreme Storms for Climates of Tamriel 3_1-27022-3-1.rar 2014-01-15 07:50 - 2014-01-15 07:51 - 14741439 _____ C:\Users\Daniel\Downloads\RSE High v1_4-836.7z 2014-01-15 07:50 - 2014-01-15 07:50 - 00762191 _____ C:\Users\Daniel\Downloads\Dust Effects v1_0-44201-1-0.7z 2014-01-15 07:49 - 2014-01-15 07:49 - 17953454 _____ C:\Users\Daniel\Downloads\Rocking Stones Parallax for ENB - 2k BROWNISH - best one imo-38004-4-4.7z 2014-01-15 07:47 - 2014-01-15 07:47 - 16731899 _____ C:\Users\Daniel\Downloads\SkyFalls - Dragonborn Edition-40564-1-2.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 04175336 _____ C:\Users\Daniel\Downloads\HD Ivy - Original Green-30971-2-00.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 01405354 _____ C:\Users\Daniel\Downloads\SkyFalls - Animated Distant Waterfalls-40564-1-9.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 00006543 _____ C:\Users\Daniel\Downloads\SkyFalls - Dawnguard Edition-40564-1-1.rar 2014-01-15 07:45 - 2014-01-15 07:46 - 28948920 _____ C:\Users\Daniel\Downloads\TreesHD_Skyrim_variation_HIGH_NEW-3812-1-6.rar 2014-01-15 07:43 - 2014-01-15 07:44 - 29112106 _____ C:\Users\Daniel\Downloads\Dragonborn addon v02-141-v0-2.7z 2014-01-15 07:43 - 2014-01-15 07:43 - 01807096 _____ C:\Users\Daniel\Downloads\Natural Grass Texture Floor-30164-1-0.zip 2014-01-15 07:30 - 2014-01-15 07:37 - 145113682 _____ C:\Users\Daniel\Downloads\Summer Edition v181-141-v1-81.7z 2014-01-15 07:27 - 2014-01-15 07:29 - 26777790 _____ C:\Users\Daniel\Downloads\Detailed_Rugs_v1-3-29608-1-3.7z 2014-01-15 07:15 - 2014-01-15 07:24 - 144349763 _____ C:\Users\Daniel\Downloads\Hectrol CAVES DELUXE HighRes Retex 4K-29145-1-0.7z 2014-01-15 07:12 - 2014-01-15 07:13 - 04941702 _____ C:\Users\Daniel\Downloads\Cinematic Fire FX 2-2692-2-3.zip 2014-01-15 07:11 - 2014-01-15 07:24 - 18920661 _____ C:\Users\Daniel\Downloads\Ruins_Clutter_Improved_v2-6-14227-2-6.7z 2014-01-14 23:09 - 2014-01-14 23:09 - 05713023 _____ C:\Users\Daniel\Downloads\Unofficial Dragonborn Patch-31083-2-0-0.7z 2014-01-14 04:34 - 2014-01-14 04:35 - 09511604 _____ C:\Users\Daniel\Downloads\Footprints v0_99-22745-0-99.7z 2014-01-14 04:34 - 2014-01-14 04:34 - 08922372 _____ C:\Users\Daniel\Downloads\0_Pure Waters 4-6 Legendary-1111-4-6.rar 2014-01-14 04:27 - 2014-01-14 04:27 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (2).7z 2014-01-14 04:20 - 2014-01-14 04:21 - 09113460 _____ C:\Users\Daniel\Downloads\UNP BASE Main body V1dot2-6709.7z 2014-01-14 04:16 - 2014-01-14 04:17 - 02178105 _____ C:\Users\Daniel\Downloads\Sharpshooter enb classic version-15105-V1.rar 2014-01-14 04:15 - 2014-01-14 04:29 - 235701929 _____ C:\Users\Daniel\Downloads\UNP Mashup Compilation v1-20415-1.rar 2014-01-14 03:29 - 2014-01-14 03:30 - 23759325 _____ C:\Users\Daniel\Downloads\Better Vampires 6-5-9717-6-5.zip 2014-01-14 03:25 - 2014-01-14 03:25 - 00023554 _____ C:\Users\Daniel\Downloads\NEW Temptress Vampire Compatibility Update-18717-.rar 2014-01-14 03:14 - 2014-01-14 03:14 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (1).7z 2014-01-14 00:57 - 2014-01-14 00:57 - 00000617 _____ C:\Users\Daniel\Downloads\More Dragon Loot-10050-R4.rar 2014-01-14 00:55 - 2014-01-14 00:55 - 00001935 _____ C:\Users\Daniel\Downloads\Version 2_1-1010-2-1.zip 2014-01-14 00:47 - 2014-01-14 00:47 - 00001144 _____ C:\Users\Daniel\Downloads\More Arrows-11613-1-0.rar 2014-01-14 00:45 - 2014-01-14 00:46 - 20135641 _____ C:\Users\Daniel\Downloads\Enhanced Character Edit-12951-1-2.7z 2014-01-14 00:39 - 2014-01-14 00:39 - 04869331 _____ C:\Users\Daniel\Downloads\The Joy of Perspective Female V0 9 3 -6002-v0-9-3.rar 2014-01-14 00:35 - 2014-01-14 00:35 - 00322469 _____ C:\Users\Daniel\Downloads\Realistic Force-601-1-9.rar 2014-01-14 00:34 - 2014-01-14 00:34 - 00887469 _____ C:\Users\Daniel\Downloads\XPMS 1-92 NMM-BAIN INSTALLER-26800-1-92.7z 2014-01-14 00:31 - 2014-01-14 00:31 - 00083125 _____ C:\Users\Daniel\Downloads\The Dance of Death 4-0 Beta - Ultimate Edition-10906-4-0.7z 2014-01-14 00:26 - 2014-01-14 00:26 - 01025219 _____ C:\Users\Daniel\Downloads\UNP Bouncing Boobs-10470-1-0.rar 2014-01-14 00:21 - 2014-01-14 00:21 - 03496349 _____ C:\Users\Daniel\Downloads\360WalkRunPlus_v3_1_2-34508-3-1-2.7z 2014-01-14 00:11 - 2014-01-14 00:15 - 72977814 _____ C:\Users\Daniel\Downloads\Unofficial Skyrim Patch-19-2-0-0a.7z 2014-01-14 00:10 - 2014-01-14 00:11 - 29040935 _____ C:\Users\Daniel\Downloads\Immersive Sounds - Aural Assortment-49084-1-0.zip 2014-01-14 00:10 - 2014-01-14 00:10 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6 (1).zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6.zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00002452 _____ C:\Users\Daniel\Downloads\0 Dragonborn-Dawnguard Compatibility Patch-60-.rar 2014-01-14 00:02 - 2014-01-14 00:02 - 00266051 _____ C:\Users\Daniel\Downloads\skse_1_06_16_installer.exe 2014-01-14 00:02 - 2014-01-14 00:02 - 00000649 _____ C:\Users\Daniel\Desktop\Skyrim (SKSE).lnk 2014-01-14 00:01 - 2014-01-14 00:06 - 43448187 _____ C:\Users\Daniel\Downloads\Enhanced Blood Textures 3_5d-60-3-5d.rar 2014-01-13 23:59 - 2014-01-14 00:00 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929.7z 2014-01-13 23:54 - 2014-01-14 00:18 - 151736579 _____ C:\Users\Daniel\Downloads\IA v6 BETA 2-19733-6-BETA-2.7z 2014-01-13 23:53 - 2014-01-13 23:53 - 02978304 _____ C:\Users\Daniel\Downloads\Realistic Lighting Overhaul 4_0_8_01 NMM-BAINWizard Installer-30450-4-0-8-01.7z 2014-01-13 23:52 - 2014-01-13 23:52 - 07592804 _____ C:\Users\Daniel\Downloads\Wars_in_Skyrim_-_Normal_Mode-6176-1-4-1.7z 2014-01-13 23:38 - 2014-01-13 23:49 - 119244137 _____ C:\Users\Daniel\Downloads\Temptress Complete v1_3-18717-1-3.rar 2014-01-13 23:30 - 2014-01-13 23:42 - 151991017 _____ C:\Users\Daniel\Downloads\ApachiiSkyHair_v_1_5_Full-10168-1-5-Full.7z 2014-01-13 23:18 - 2014-01-13 23:19 - 11624802 _____ C:\Users\Daniel\Downloads\No_More_Blocky_Faces-1_50-30-1-5.7z 2014-01-13 23:12 - 2014-01-13 23:12 - 00000313 _____ C:\Users\Daniel\Downloads\Proper Aiming 1_1-13652-1-1.rar 2014-01-13 23:06 - 2014-01-13 23:06 - 00230939 _____ C:\Users\Daniel\Downloads\Version 1_82 Quick Fix-18480-1-82.rar 2014-01-13 23:03 - 2014-01-13 23:04 - 11252501 _____ C:\Users\Daniel\Downloads\Version 1_82 BSA-18480-1-82.rar 2014-01-13 22:59 - 2014-01-13 23:34 - 554674254 _____ C:\Users\Daniel\Downloads\SMIM v1-61-8655-1-61.7z 2014-01-13 22:51 - 2014-01-13 22:56 - 107551867 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - V3-1-17802-3-1.zip 2014-01-13 22:42 - 2014-01-14 23:08 - 00000000 ____D C:\Users\Daniel\Documents\Nexus Mod Manager 2014-01-13 22:42 - 2014-01-13 22:42 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-01-13 22:42 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Black_Tree_Gaming 2014-01-13 22:35 - 2014-01-13 22:37 - 04136616 _____ (Black Tree Gaming ) C:\Users\Daniel\Downloads\Nexus Mod Manager-0.46.0.exe 2014-01-13 22:32 - 2014-01-13 22:32 - 01409134 _____ C:\Users\Daniel\Downloads\SkyUI_4_1-3863-4-1.7z 2014-01-13 22:29 - 2014-01-13 22:34 - 85038708 _____ C:\Users\Daniel\Downloads\Noiral_CBBE_Reloaded.zip 2014-01-13 20:02 - 2014-01-14 23:08 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2014-01-13 19:07 - 2014-01-13 19:07 - 00000640 _____ C:\Users\Daniel\Desktop\The Elder Scrolls V Skyrim - Legendary Edition (Launcher).lnk 2014-01-13 19:07 - 2014-01-13 19:07 - 00000606 _____ C:\Users\Daniel\Desktop\The Elder Scrolls V Skyrim - Legendary Edition.lnk 2014-01-11 10:20 - 1997-03-24 17:42 - 00314368 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe 2014-01-11 10:19 - 2014-01-11 10:19 - 00000000 ____D C:\Users\Daniel\Desktop\netxray 2014-01-11 10:13 - 2014-01-11 10:14 - 07679554 _____ C:\Users\Daniel\Downloads\netxray.zip 2014-01-11 09:54 - 2010-07-09 00:48 - 00000000 ____D C:\Users\Daniel\Desktop\IDAStealthRemote 2014-01-11 09:53 - 2014-01-11 09:53 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Hex-Rays 2014-01-11 09:51 - 2014-01-11 09:52 - 16374114 _____ (Hex-Rays SA ) C:\Users\Daniel\Downloads\idafree50.exe 2014-01-11 09:51 - 2014-01-11 09:52 - 01385454 _____ C:\Users\Daniel\Downloads\idastealth_complete.rar 2014-01-11 09:45 - 2014-01-11 09:45 - 00545804 _____ C:\Users\Daniel\Downloads\fdbg0024.zip 2014-01-11 09:41 - 2014-01-11 09:42 - 06965278 _____ C:\Users\Daniel\Downloads\odbg201.zip 2014-01-11 09:13 - 2014-01-11 09:13 - 01646243 _____ C:\Users\Daniel\Downloads\tsearch16b.rar 2014-01-10 20:56 - 2014-01-12 20:44 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Awesomium 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\Users\Daniel\Documents\Elder Scrolls Online 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\ProgramData\Elder Scrolls Online 2014-01-09 15:58 - 2014-01-09 15:58 - 00414569 _____ C:\Users\Daniel\Downloads\Raf Manager.zip 2014-01-08 06:59 - 2014-01-08 06:59 - 02653910 _____ C:\Users\Daniel\Downloads\9221.zip 2014-01-08 06:54 - 2014-01-08 06:55 - 24309760 _____ C:\Users\Daniel\Downloads\LauncherSetup.msi 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Local\SkinSoft 2014-01-07 19:02 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\Desktop\Crypto 2014-01-07 18:43 - 2014-01-07 18:49 - 17584706 _____ C:\Users\Daniel\Downloads\CryptoObfuscator.Enterprise.2012.R2.Build.130111.rar 2014-01-06 23:38 - 2014-01-06 23:38 - 00033323 _____ C:\Users\Daniel\Downloads\Prodiction.lua 2014-01-06 21:24 - 2014-01-06 21:24 - 01310829 _____ C:\Users\Daniel\Downloads\19913.zip 2014-01-06 21:24 - 2014-01-06 21:24 - 01304629 _____ C:\Users\Daniel\Downloads\6471.zip 2014-01-06 21:20 - 2014-01-06 21:21 - 01016952 _____ C:\Users\Daniel\Downloads\25273.zip 2014-01-06 20:41 - 2014-01-02 14:42 - 00025203 _____ C:\xPRiiME.properties 2014-01-06 17:42 - 2014-01-06 17:42 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5 (1).zip 2014-01-06 17:20 - 2014-01-06 17:20 - 00026395 _____ C:\Users\Daniel\Downloads\OpenPOP.zip 2014-01-06 17:05 - 2014-01-06 17:05 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5.zip 2014-01-06 16:57 - 2014-01-06 16:57 - 00027152 _____ C:\Users\Daniel\Downloads\ReadPop3EmailsASP.Net.zip 2014-01-06 16:14 - 2014-01-06 16:16 - 00000000 ____D C:\Users\Daniel\Documents\sliqemailconfirmerlite 2014-01-06 16:06 - 2014-01-06 16:06 - 00003165 _____ C:\Users\Daniel\Desktop\SliQ Link Clicker Lite.lnk 2014-01-06 16:06 - 2014-01-06 16:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SliQTools 2014-01-06 16:03 - 2014-01-06 16:03 - 06043285 _____ (SliQTools ) C:\Users\Daniel\Downloads\sliqlinkclickerlite.exe 2014-01-03 23:54 - 2014-01-03 23:54 - 00042184 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys 2014-01-03 22:52 - 2014-01-03 22:52 - 00008657 _____ C:\Users\Daniel\Downloads\DownloadSVN13.zip 2014-01-03 21:30 - 2014-01-03 21:30 - 00186054 _____ C:\Users\Daniel\Downloads\FsbExtractor13.07.23.rar 2014-01-03 21:17 - 2014-01-03 21:18 - 26578452 _____ C:\Users\Daniel\Downloads\Unreal Tournament Announcer Mod (LoL) V. 2.1.0.7.zip 2014-01-03 17:16 - 2014-01-03 17:16 - 00001172 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-01-03 17:16 - 2014-01-03 17:16 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-02 21:03 - 2014-01-02 21:03 - 01530695 _____ C:\Users\Daniel\Downloads\861.zip 2014-01-02 20:41 - 2014-01-02 20:41 - 00197483 _____ C:\Users\Daniel\Downloads\gimp-dds-win64-3.0.1.zip 2014-01-02 20:34 - 2014-01-02 20:34 - 00253076 _____ C:\Users\Daniel\Downloads\2093 (1).zip 2014-01-02 12:14 - 2014-01-02 12:16 - 33901910 _____ C:\Users\Daniel\Downloads\fmoddesigner44427win-installer.exe 2014-01-02 12:00 - 2014-01-02 12:00 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext (1).zip 2014-01-02 11:30 - 2014-01-02 11:30 - 02785220 _____ C:\Users\Daniel\Downloads\2622.zip 2014-01-02 10:28 - 2014-01-02 10:28 - 00272516 _____ C:\Users\Daniel\Downloads\yaybatch.zip 2014-01-02 10:22 - 2014-01-02 10:22 - 01923290 _____ C:\Users\Daniel\Downloads\cdex_151.zip 2014-01-02 09:14 - 2014-01-02 09:15 - 05015064 _____ C:\Users\Daniel\Downloads\MusicPlayerEx-Full-02-04-2013.7z 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32.zip 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32 (1).zip 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-01-02 07:05 - 2014-01-02 07:06 - 07598942 _____ C:\Users\Daniel\Downloads\npp.6.5.3.Installer.exe 2014-01-02 06:35 - 2014-01-12 00:42 - 00000000 ____D C:\Users\Daniel\Desktop\LoL Modding 2014-01-02 06:26 - 2014-01-02 06:27 - 06709836 _____ C:\Users\Daniel\Downloads\SIU 3.335-Lite.zip 2014-01-02 03:15 - 2014-01-02 03:17 - 53464955 _____ C:\Users\Daniel\Downloads\wintermint.rar 2014-01-02 01:35 - 2014-01-16 18:11 - 00000000 ____D C:\Users\Daniel\Documents\LOLReplay 2014-01-02 01:35 - 2014-01-02 01:35 - 01472106 _____ C:\Users\Daniel\Downloads\LOLReplay-0.8.5.2.exe 2014-01-02 01:35 - 2014-01-02 01:35 - 00000611 _____ C:\Users\Public\Desktop\LOL Recorder.lnk 2013-12-31 18:21 - 2014-01-22 12:26 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-12-31 06:52 - 2013-12-31 06:52 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00002076 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\ProgramData\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\Program Files (x86)\Avira 2013-12-31 06:51 - 2013-12-09 11:37 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-12-31 06:41 - 2013-12-31 06:48 - 129598176 _____ C:\Users\Daniel\Downloads\avira_free_antivirus_de.exe 2013-12-31 05:46 - 2013-12-31 05:47 - 00253076 _____ C:\Users\Daniel\Downloads\2093.zip 2013-12-31 05:13 - 2013-12-31 05:13 - 00860736 _____ C:\Users\Daniel\Downloads\hexedit602.zip 2013-12-31 05:01 - 2013-12-31 05:01 - 00253442 _____ C:\Users\Daniel\Downloads\1209303036_datexpl.rar 2013-12-31 04:58 - 2013-12-31 04:58 - 00018023 _____ C:\Users\Daniel\Downloads\FTL UnPacker 1.0.1.zip 2013-12-31 04:53 - 2013-12-31 04:54 - 11147144 _____ (Adobe Systems, Inc.) C:\Users\Daniel\Downloads\flashplayer_11_sa_debug.exe 2013-12-31 04:52 - 2013-12-31 04:53 - 02179506 _____ (StandaloneFlashPlayer.com ) C:\Users\Daniel\Downloads\standaloneflashplayer_setup.exe 2013-12-31 02:32 - 2013-12-31 02:32 - 10807547 _____ C:\Users\Daniel\Downloads\fmodsandbox43505win-installer.exe 2013-12-31 02:16 - 2014-01-02 12:11 - 00000000 ____D C:\Users\Daniel\AppData\Local\FMOD Studio 2013-12-31 02:09 - 2013-12-31 02:14 - 79700009 _____ C:\Users\Daniel\Downloads\fmodstudio10211win-installer.exe 2013-12-31 02:09 - 2013-12-31 02:09 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext.zip 2013-12-30 21:36 - 2014-01-26 19:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Wireshark 2013-12-30 21:28 - 2013-12-30 21:28 - 00000000 ____D C:\Program Files (x86)\WinPcap 2013-12-30 21:08 - 2013-12-30 21:10 - 27981224 _____ (Wireshark development team) C:\Users\Daniel\Downloads\Wireshark-win64-1.10.5.exe 2013-12-29 21:07 - 2013-12-29 21:22 - 00000000 ____D C:\Users\Daniel\AppData\Local\Gapotchenko 2013-12-29 21:07 - 2013-12-29 21:07 - 05001216 _____ C:\Users\Daniel\Downloads\Eazfuscator.NET 4.1 Setup.msi 2013-12-29 19:19 - 2013-12-29 19:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-29 19:13 - 2014-01-03 19:15 - 00010567 _____ C:\Users\Daniel\Documents\test.html ==================== One Month Modified Files and Folders ======= 2014-01-27 00:54 - 2013-10-20 07:28 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype 2014-01-27 00:53 - 2014-01-27 00:50 - 00017129 _____ C:\Users\Daniel\Downloads\FRST.txt 2014-01-27 00:52 - 2013-10-28 00:52 - 00000296 _____ C:\Windows\Tasks\UpdaterEX.job 2014-01-27 00:50 - 2014-01-27 00:50 - 00000000 ____D C:\FRST 2014-01-27 00:49 - 2014-01-27 00:49 - 02078208 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe 2014-01-27 00:39 - 2013-10-28 00:51 - 00000292 _____ C:\Windows\Tasks\FoxTab.job 2014-01-27 00:30 - 2013-10-19 18:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Spotify 2014-01-27 00:11 - 2013-10-19 15:56 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-26 21:11 - 2013-10-19 15:56 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-26 20:08 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2014-01-26 20:07 - 2013-11-20 01:46 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2014-01-26 19:38 - 2014-01-26 19:38 - 01104710 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE.zip 2014-01-26 19:26 - 2014-01-26 19:26 - 00000005 _____ C:\Users\Daniel\Downloads\Download 2014-01-26 19:06 - 2013-12-30 21:36 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Wireshark 2014-01-26 18:57 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\JetBrains 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\SymbolSourceSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\RefSrcSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\JetBrains 2014-01-26 18:53 - 2014-01-26 18:51 - 29220864 _____ C:\Users\Daniel\Downloads\dotPeekSetup-1.1.1.33.msi 2014-01-26 18:49 - 2014-01-26 18:49 - 01467128 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE (1).exe 2014-01-26 18:46 - 2014-01-26 18:46 - 01467128 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE.exe 2014-01-26 18:38 - 2014-01-26 18:38 - 00157234 _____ C:\Users\Daniel\Downloads\RouterReconnect_1.3.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 04689382 _____ C:\Users\Daniel\Downloads\curl-7.34.0.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 00094335 _____ C:\Users\Daniel\Downloads\Fritz!Box Reconnect.rar 2014-01-26 18:29 - 2014-01-26 18:25 - 00000000 _____ C:\Users\Daniel\Desktop\null 2014-01-26 18:24 - 2014-01-26 18:24 - 00041223 _____ C:\Users\Daniel\Downloads\Fritz_Box_reconnect.zip 2014-01-26 16:49 - 2014-01-26 16:36 - 00000000 ____D C:\Users\Daniel\Documents\Rezepte 2014-01-26 13:54 - 2013-10-19 15:12 - 01054453 _____ C:\Windows\WindowsUpdate.log 2014-01-26 07:16 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-26 07:16 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-26 07:10 - 2013-11-27 00:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Overwolf 2014-01-26 07:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\inetsrv 2014-01-26 07:07 - 2013-10-20 09:40 - 00000000 ____D C:\Users\Daniel\AppData\Local\HTC MediaHub 2014-01-26 07:06 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-26 07:06 - 2009-07-14 05:51 - 00042109 _____ C:\Windows\setupact.log 2014-01-25 19:14 - 2013-11-27 17:07 - 00000000 ____D C:\Users\Daniel\AppData\Local\Purplizer 2014-01-24 20:51 - 2010-11-21 04:47 - 00117556 _____ C:\Windows\PFRO.log 2014-01-23 09:38 - 2014-01-23 09:38 - 42713738 _____ C:\Users\Daniel\Downloads\Devisual's Graphics Pack.rar 2014-01-23 07:39 - 2013-12-19 13:51 - 00000107 _____ C:\Users\Daniel\AppData\Roaming\WB.CFG 2014-01-22 14:30 - 2014-01-22 14:30 - 00382935 _____ C:\Users\Daniel\Downloads\LLC_UPDATE.zip 2014-01-22 12:26 - 2013-12-31 18:21 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2014-01-22 01:39 - 2013-10-28 00:51 - 00003236 _____ C:\Windows\System32\Tasks\FoxTab 2014-01-21 08:14 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\TubeBox 2014-01-21 05:26 - 2011-04-12 08:43 - 00792924 _____ C:\Windows\system32\perfh007.dat 2014-01-21 05:26 - 2011-04-12 08:43 - 00183676 _____ C:\Windows\system32\perfc007.dat 2014-01-21 05:26 - 2009-07-14 06:13 - 01857894 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-20 16:37 - 2013-10-19 18:53 - 00000000 ____D C:\Users\Daniel\AppData\Local\Spotify 2014-01-17 12:16 - 2014-01-17 12:16 - 00092309 _____ C:\Users\Daniel\Downloads\MarkC_Windows_8.x+7_MouseFix.zip 2014-01-17 07:51 - 2013-11-15 19:46 - 00000607 _____ C:\Users\Daniel\Desktop\Battlefield 4 64bit.lnk 2014-01-17 00:15 - 2013-10-19 15:58 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-16 18:11 - 2014-01-02 01:35 - 00000000 ____D C:\Users\Daniel\Documents\LOLReplay 2014-01-16 16:30 - 2013-10-19 17:09 - 00000000 ____D C:\Users\Daniel\Documents\Visual Studio 2012 2014-01-15 15:47 - 2014-01-15 15:47 - 00000749 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-15 15:46 - 2014-01-15 15:46 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 15:46 - 2013-10-31 14:25 - 00135647 _____ C:\Windows\DirectX.log 2014-01-15 15:45 - 2013-10-31 11:23 - 00000000 ____D C:\ProgramData\Origin 2014-01-15 15:38 - 2014-01-15 15:36 - 08501736 _____ C:\Users\Daniel\Downloads\HSS-3.31-install-e-550-plain.exe 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2014-01-15 15:22 - 2014-01-15 15:22 - 00000530 _____ C:\Users\Public\Desktop\Origin.lnk 2014-01-15 15:21 - 2014-01-15 15:20 - 16952720 _____ (Electronic Arts, Inc.) C:\Users\Daniel\Downloads\OriginThinSetup.exe 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\EA Core 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Users\Daniel\AppData\Local\ESN 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2014-01-15 15:11 - 2014-01-15 15:11 - 03821064 _____ C:\Users\Daniel\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00012885 _____ C:\Users\Daniel\AppData\Local\recently-used.xbel 2014-01-15 14:04 - 2013-12-03 16:06 - 00000000 ____D C:\Users\Daniel\.gimp-2.8 2014-01-15 11:38 - 2014-01-15 11:38 - 01016952 _____ C:\Users\Daniel\Downloads\25273 (1).zip 2014-01-15 09:23 - 2014-01-15 09:23 - 00004705 _____ C:\Users\Daniel\Downloads\First Person Camera Fix-6508-1.7z 2014-01-15 08:46 - 2014-01-15 08:46 - 00060838 _____ C:\Users\Daniel\Downloads\SafetyLoad 1_2-46465-1-2.zip 2014-01-15 08:06 - 2014-01-15 08:06 - 00003710 _____ C:\Users\Daniel\Downloads\High Prefs and inis ugrids 5 V27 ENB version-36146-v27.rar 2014-01-15 07:58 - 2014-01-15 07:58 - 12881617 _____ C:\Users\Daniel\Downloads\RealVision_ENB_245a-30936-245a.7z 2014-01-15 07:58 - 2014-01-15 07:58 - 02342720 _____ C:\Users\Daniel\Downloads\enbseries_skyrim_v0245.zip 2014-01-15 07:54 - 2014-01-15 07:54 - 01457128 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - Weather Patch-39799-15.rar 2014-01-15 07:53 - 2014-01-15 07:53 - 00020795 _____ C:\Users\Daniel\Downloads\Supreme Storms for Climates of Tamriel 3_1-27022-3-1.rar 2014-01-15 07:51 - 2014-01-15 07:50 - 14741439 _____ C:\Users\Daniel\Downloads\RSE High v1_4-836.7z 2014-01-15 07:50 - 2014-01-15 07:50 - 00762191 _____ C:\Users\Daniel\Downloads\Dust Effects v1_0-44201-1-0.7z 2014-01-15 07:49 - 2014-01-15 07:49 - 17953454 _____ C:\Users\Daniel\Downloads\Rocking Stones Parallax for ENB - 2k BROWNISH - best one imo-38004-4-4.7z 2014-01-15 07:47 - 2014-01-15 07:47 - 16731899 _____ C:\Users\Daniel\Downloads\SkyFalls - Dragonborn Edition-40564-1-2.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 04175336 _____ C:\Users\Daniel\Downloads\HD Ivy - Original Green-30971-2-00.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 01405354 _____ C:\Users\Daniel\Downloads\SkyFalls - Animated Distant Waterfalls-40564-1-9.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 00006543 _____ C:\Users\Daniel\Downloads\SkyFalls - Dawnguard Edition-40564-1-1.rar 2014-01-15 07:46 - 2014-01-15 07:45 - 28948920 _____ C:\Users\Daniel\Downloads\TreesHD_Skyrim_variation_HIGH_NEW-3812-1-6.rar 2014-01-15 07:44 - 2014-01-15 07:43 - 29112106 _____ C:\Users\Daniel\Downloads\Dragonborn addon v02-141-v0-2.7z 2014-01-15 07:43 - 2014-01-15 07:43 - 01807096 _____ C:\Users\Daniel\Downloads\Natural Grass Texture Floor-30164-1-0.zip 2014-01-15 07:37 - 2014-01-15 07:30 - 145113682 _____ C:\Users\Daniel\Downloads\Summer Edition v181-141-v1-81.7z 2014-01-15 07:29 - 2014-01-15 07:27 - 26777790 _____ C:\Users\Daniel\Downloads\Detailed_Rugs_v1-3-29608-1-3.7z 2014-01-15 07:24 - 2014-01-15 07:15 - 144349763 _____ C:\Users\Daniel\Downloads\Hectrol CAVES DELUXE HighRes Retex 4K-29145-1-0.7z 2014-01-15 07:24 - 2014-01-15 07:11 - 18920661 _____ C:\Users\Daniel\Downloads\Ruins_Clutter_Improved_v2-6-14227-2-6.7z 2014-01-15 07:13 - 2014-01-15 07:12 - 04941702 _____ C:\Users\Daniel\Downloads\Cinematic Fire FX 2-2692-2-3.zip 2014-01-14 23:09 - 2014-01-14 23:09 - 05713023 _____ C:\Users\Daniel\Downloads\Unofficial Dragonborn Patch-31083-2-0-0.7z 2014-01-14 23:08 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\Documents\Nexus Mod Manager 2014-01-14 23:08 - 2014-01-13 20:02 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2014-01-14 04:35 - 2014-01-14 04:34 - 09511604 _____ C:\Users\Daniel\Downloads\Footprints v0_99-22745-0-99.7z 2014-01-14 04:34 - 2014-01-14 04:34 - 08922372 _____ C:\Users\Daniel\Downloads\0_Pure Waters 4-6 Legendary-1111-4-6.rar 2014-01-14 04:29 - 2014-01-14 04:15 - 235701929 _____ C:\Users\Daniel\Downloads\UNP Mashup Compilation v1-20415-1.rar 2014-01-14 04:27 - 2014-01-14 04:27 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (2).7z 2014-01-14 04:21 - 2014-01-14 04:20 - 09113460 _____ C:\Users\Daniel\Downloads\UNP BASE Main body V1dot2-6709.7z 2014-01-14 04:17 - 2014-01-14 04:16 - 02178105 _____ C:\Users\Daniel\Downloads\Sharpshooter enb classic version-15105-V1.rar 2014-01-14 03:30 - 2014-01-14 03:29 - 23759325 _____ C:\Users\Daniel\Downloads\Better Vampires 6-5-9717-6-5.zip 2014-01-14 03:25 - 2014-01-14 03:25 - 00023554 _____ C:\Users\Daniel\Downloads\NEW Temptress Vampire Compatibility Update-18717-.rar 2014-01-14 03:14 - 2014-01-14 03:14 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (1).7z 2014-01-14 00:57 - 2014-01-14 00:57 - 00000617 _____ C:\Users\Daniel\Downloads\More Dragon Loot-10050-R4.rar 2014-01-14 00:55 - 2014-01-14 00:55 - 00001935 _____ C:\Users\Daniel\Downloads\Version 2_1-1010-2-1.zip 2014-01-14 00:47 - 2014-01-14 00:47 - 00001144 _____ C:\Users\Daniel\Downloads\More Arrows-11613-1-0.rar 2014-01-14 00:46 - 2014-01-14 00:45 - 20135641 _____ C:\Users\Daniel\Downloads\Enhanced Character Edit-12951-1-2.7z 2014-01-14 00:39 - 2014-01-14 00:39 - 04869331 _____ C:\Users\Daniel\Downloads\The Joy of Perspective Female V0 9 3 -6002-v0-9-3.rar 2014-01-14 00:35 - 2014-01-14 00:35 - 00322469 _____ C:\Users\Daniel\Downloads\Realistic Force-601-1-9.rar 2014-01-14 00:34 - 2014-01-14 00:34 - 00887469 _____ C:\Users\Daniel\Downloads\XPMS 1-92 NMM-BAIN INSTALLER-26800-1-92.7z 2014-01-14 00:31 - 2014-01-14 00:31 - 00083125 _____ C:\Users\Daniel\Downloads\The Dance of Death 4-0 Beta - Ultimate Edition-10906-4-0.7z 2014-01-14 00:26 - 2014-01-14 00:26 - 01025219 _____ C:\Users\Daniel\Downloads\UNP Bouncing Boobs-10470-1-0.rar 2014-01-14 00:21 - 2014-01-14 00:21 - 03496349 _____ C:\Users\Daniel\Downloads\360WalkRunPlus_v3_1_2-34508-3-1-2.7z 2014-01-14 00:18 - 2014-01-13 23:54 - 151736579 _____ C:\Users\Daniel\Downloads\IA v6 BETA 2-19733-6-BETA-2.7z 2014-01-14 00:15 - 2014-01-14 00:11 - 72977814 _____ C:\Users\Daniel\Downloads\Unofficial Skyrim Patch-19-2-0-0a.7z 2014-01-14 00:11 - 2014-01-14 00:10 - 29040935 _____ C:\Users\Daniel\Downloads\Immersive Sounds - Aural Assortment-49084-1-0.zip 2014-01-14 00:10 - 2014-01-14 00:10 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6 (1).zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6.zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00002452 _____ C:\Users\Daniel\Downloads\0 Dragonborn-Dawnguard Compatibility Patch-60-.rar 2014-01-14 00:06 - 2014-01-14 00:01 - 43448187 _____ C:\Users\Daniel\Downloads\Enhanced Blood Textures 3_5d-60-3-5d.rar 2014-01-14 00:02 - 2014-01-14 00:02 - 00266051 _____ C:\Users\Daniel\Downloads\skse_1_06_16_installer.exe 2014-01-14 00:02 - 2014-01-14 00:02 - 00000649 _____ C:\Users\Daniel\Desktop\Skyrim (SKSE).lnk 2014-01-14 00:00 - 2014-01-13 23:59 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929.7z 2014-01-13 23:53 - 2014-01-13 23:53 - 02978304 _____ C:\Users\Daniel\Downloads\Realistic Lighting Overhaul 4_0_8_01 NMM-BAINWizard Installer-30450-4-0-8-01.7z 2014-01-13 23:52 - 2014-01-13 23:52 - 07592804 _____ C:\Users\Daniel\Downloads\Wars_in_Skyrim_-_Normal_Mode-6176-1-4-1.7z 2014-01-13 23:49 - 2014-01-13 23:38 - 119244137 _____ C:\Users\Daniel\Downloads\Temptress Complete v1_3-18717-1-3.rar 2014-01-13 23:42 - 2014-01-13 23:30 - 151991017 _____ C:\Users\Daniel\Downloads\ApachiiSkyHair_v_1_5_Full-10168-1-5-Full.7z 2014-01-13 23:34 - 2014-01-13 22:59 - 554674254 _____ C:\Users\Daniel\Downloads\SMIM v1-61-8655-1-61.7z 2014-01-13 23:19 - 2014-01-13 23:18 - 11624802 _____ C:\Users\Daniel\Downloads\No_More_Blocky_Faces-1_50-30-1-5.7z 2014-01-13 23:12 - 2014-01-13 23:12 - 00000313 _____ C:\Users\Daniel\Downloads\Proper Aiming 1_1-13652-1-1.rar 2014-01-13 23:06 - 2014-01-13 23:06 - 00230939 _____ C:\Users\Daniel\Downloads\Version 1_82 Quick Fix-18480-1-82.rar 2014-01-13 23:04 - 2014-01-13 23:03 - 11252501 _____ C:\Users\Daniel\Downloads\Version 1_82 BSA-18480-1-82.rar 2014-01-13 22:56 - 2014-01-13 22:51 - 107551867 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - V3-1-17802-3-1.zip 2014-01-13 22:42 - 2014-01-13 22:42 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-01-13 22:42 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Black_Tree_Gaming 2014-01-13 22:37 - 2014-01-13 22:35 - 04136616 _____ (Black Tree Gaming ) C:\Users\Daniel\Downloads\Nexus Mod Manager-0.46.0.exe 2014-01-13 22:34 - 2014-01-13 22:29 - 85038708 _____ C:\Users\Daniel\Downloads\Noiral_CBBE_Reloaded.zip 2014-01-13 22:32 - 2014-01-13 22:32 - 01409134 _____ C:\Users\Daniel\Downloads\SkyUI_4_1-3863-4-1.7z 2014-01-13 20:02 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\My Games 2014-01-12 20:44 - 2014-01-10 20:56 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Awesomium 2014-01-12 00:42 - 2014-01-02 06:35 - 00000000 ____D C:\Users\Daniel\Desktop\LoL Modding 2014-01-11 10:19 - 2014-01-11 10:19 - 00000000 ____D C:\Users\Daniel\Desktop\netxray 2014-01-11 10:14 - 2014-01-11 10:13 - 07679554 _____ C:\Users\Daniel\Downloads\netxray.zip 2014-01-11 09:53 - 2014-01-11 09:53 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Hex-Rays 2014-01-11 09:52 - 2014-01-11 09:51 - 16374114 _____ (Hex-Rays SA ) C:\Users\Daniel\Downloads\idafree50.exe 2014-01-11 09:52 - 2014-01-11 09:51 - 01385454 _____ C:\Users\Daniel\Downloads\idastealth_complete.rar 2014-01-11 09:45 - 2014-01-11 09:45 - 00545804 _____ C:\Users\Daniel\Downloads\fdbg0024.zip 2014-01-11 09:42 - 2014-01-11 09:41 - 06965278 _____ C:\Users\Daniel\Downloads\odbg201.zip 2014-01-11 09:13 - 2014-01-11 09:13 - 01646243 _____ C:\Users\Daniel\Downloads\tsearch16b.rar 2014-01-11 09:08 - 2013-10-19 15:23 - 00000000 ____D C:\Users\Daniel\AppData\Local\VirtualStore 2014-01-11 09:07 - 2014-01-11 09:07 - 00000000 ____D C:\Users\Daniel\Desktop\WPE 2014-01-11 09:06 - 2014-01-11 09:06 - 00411452 _____ C:\Users\Daniel\Downloads\wpepro09mod.zip 2014-01-11 07:45 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\My Cheat Tables 2014-01-11 07:38 - 2014-01-11 07:38 - 00000607 _____ C:\Users\Daniel\Desktop\Cheat Engine.lnk 2014-01-11 07:35 - 2014-01-11 07:34 - 08065840 _____ (Cheat Engine ) C:\Users\Daniel\Downloads\CheatEngine63.exe 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\Users\Daniel\Documents\Elder Scrolls Online 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\ProgramData\Elder Scrolls Online 2014-01-09 16:48 - 2014-01-09 16:38 - 190488919 _____ C:\Users\Daniel\Downloads\RusselZs League of Draven (3.10a Lucian).rar 2014-01-09 15:58 - 2014-01-09 15:58 - 00414569 _____ C:\Users\Daniel\Downloads\Raf Manager.zip 2014-01-08 06:59 - 2014-01-08 06:59 - 02653910 _____ C:\Users\Daniel\Downloads\9221.zip 2014-01-08 06:55 - 2014-01-08 06:54 - 24309760 _____ C:\Users\Daniel\Downloads\LauncherSetup.msi 2014-01-07 23:07 - 2013-11-27 01:02 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TS3Client 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Local\SkinSoft 2014-01-07 19:03 - 2014-01-07 19:02 - 00000000 ____D C:\Users\Daniel\Desktop\Crypto 2014-01-07 18:49 - 2014-01-07 18:43 - 17584706 _____ C:\Users\Daniel\Downloads\CryptoObfuscator.Enterprise.2012.R2.Build.130111.rar 2014-01-07 18:48 - 2013-10-20 09:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Apple Computer 2014-01-06 23:38 - 2014-01-06 23:38 - 00033323 _____ C:\Users\Daniel\Downloads\Prodiction.lua 2014-01-06 21:24 - 2014-01-06 21:24 - 01310829 _____ C:\Users\Daniel\Downloads\19913.zip 2014-01-06 21:24 - 2014-01-06 21:24 - 01304629 _____ C:\Users\Daniel\Downloads\6471.zip 2014-01-06 21:21 - 2014-01-06 21:20 - 01016952 _____ C:\Users\Daniel\Downloads\25273.zip 2014-01-06 18:16 - 2014-01-06 18:16 - 00001521 _____ C:\Users\Daniel\Downloads\UBot_Studio_Xing_Bot.ubot 2014-01-06 17:42 - 2014-01-06 17:42 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5 (1).zip 2014-01-06 17:20 - 2014-01-06 17:20 - 00026395 _____ C:\Users\Daniel\Downloads\OpenPOP.zip 2014-01-06 17:05 - 2014-01-06 17:05 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5.zip 2014-01-06 16:57 - 2014-01-06 16:57 - 00027152 _____ C:\Users\Daniel\Downloads\ReadPop3EmailsASP.Net.zip 2014-01-06 16:16 - 2014-01-06 16:14 - 00000000 ____D C:\Users\Daniel\Documents\sliqemailconfirmerlite 2014-01-06 16:06 - 2014-01-06 16:06 - 00003165 _____ C:\Users\Daniel\Desktop\SliQ Link Clicker Lite.lnk 2014-01-06 16:06 - 2014-01-06 16:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SliQTools 2014-01-06 16:05 - 2013-10-20 09:39 - 00000000 ____D C:\Users\Daniel\AppData\Local\Downloaded Installations 2014-01-06 16:03 - 2014-01-06 16:03 - 06043285 _____ (SliQTools ) C:\Users\Daniel\Downloads\sliqlinkclickerlite.exe 2014-01-06 03:23 - 2014-01-06 02:01 - 00010363 _____ C:\Users\Daniel\Documents\Emails.txt 2014-01-05 23:58 - 2013-11-14 22:45 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TeamViewer 2014-01-05 23:26 - 2013-10-19 17:09 - 00009843 _____ C:\Users\Daniel\Documents\index.html 2014-01-04 07:33 - 2009-07-14 05:45 - 00296048 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-03 23:54 - 2014-01-03 23:54 - 00042184 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys 2014-01-03 22:52 - 2014-01-03 22:52 - 00008657 _____ C:\Users\Daniel\Downloads\DownloadSVN13.zip 2014-01-03 21:30 - 2014-01-03 21:30 - 00186054 _____ C:\Users\Daniel\Downloads\FsbExtractor13.07.23.rar 2014-01-03 21:18 - 2014-01-03 21:17 - 26578452 _____ C:\Users\Daniel\Downloads\Unreal Tournament Announcer Mod (LoL) V. 2.1.0.7.zip 2014-01-03 19:15 - 2013-12-29 19:13 - 00010567 _____ C:\Users\Daniel\Documents\test.html 2014-01-03 17:59 - 2013-10-19 15:55 - 00064408 _____ C:\Users\Daniel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-03 17:16 - 2014-01-03 17:16 - 00001172 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-01-03 17:16 - 2014-01-03 17:16 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-03 16:34 - 2013-10-28 00:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-02 21:03 - 2014-01-02 21:03 - 01530695 _____ C:\Users\Daniel\Downloads\861.zip 2014-01-02 20:41 - 2014-01-02 20:41 - 00197483 _____ C:\Users\Daniel\Downloads\gimp-dds-win64-3.0.1.zip 2014-01-02 20:34 - 2014-01-02 20:34 - 00253076 _____ C:\Users\Daniel\Downloads\2093 (1).zip 2014-01-02 14:42 - 2014-01-06 20:41 - 00025203 _____ C:\xPRiiME.properties 2014-01-02 12:16 - 2014-01-02 12:14 - 33901910 _____ C:\Users\Daniel\Downloads\fmoddesigner44427win-installer.exe 2014-01-02 12:11 - 2013-12-31 02:16 - 00000000 ____D C:\Users\Daniel\AppData\Local\FMOD Studio 2014-01-02 12:00 - 2014-01-02 12:00 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext (1).zip 2014-01-02 11:30 - 2014-01-02 11:30 - 02785220 _____ C:\Users\Daniel\Downloads\2622.zip 2014-01-02 10:28 - 2014-01-02 10:28 - 00272516 _____ C:\Users\Daniel\Downloads\yaybatch.zip 2014-01-02 10:22 - 2014-01-02 10:22 - 01923290 _____ C:\Users\Daniel\Downloads\cdex_151.zip 2014-01-02 09:15 - 2014-01-02 09:14 - 05015064 _____ C:\Users\Daniel\Downloads\MusicPlayerEx-Full-02-04-2013.7z 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32.zip 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32 (1).zip 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:05 - 07598942 _____ C:\Users\Daniel\Downloads\npp.6.5.3.Installer.exe 2014-01-02 06:27 - 2014-01-02 06:26 - 06709836 _____ C:\Users\Daniel\Downloads\SIU 3.335-Lite.zip 2014-01-02 03:17 - 2014-01-02 03:15 - 53464955 _____ C:\Users\Daniel\Downloads\wintermint.rar 2014-01-02 01:35 - 2014-01-02 01:35 - 01472106 _____ C:\Users\Daniel\Downloads\LOLReplay-0.8.5.2.exe 2014-01-02 01:35 - 2014-01-02 01:35 - 00000611 _____ C:\Users\Public\Desktop\LOL Recorder.lnk 2013-12-31 17:12 - 2013-11-27 17:36 - 00001582 _____ C:\Windows\Sandboxie.ini 2013-12-31 06:52 - 2013-12-31 06:52 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00002076 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\ProgramData\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\Program Files (x86)\Avira 2013-12-31 06:48 - 2013-12-31 06:41 - 129598176 _____ C:\Users\Daniel\Downloads\avira_free_antivirus_de.exe 2013-12-31 06:33 - 2013-12-31 06:33 - 00735804 _____ C:\Users\Daniel\Downloads\UI RAF.rar 2013-12-31 05:47 - 2013-12-31 05:46 - 00253076 _____ C:\Users\Daniel\Downloads\2093.zip 2013-12-31 05:13 - 2013-12-31 05:13 - 00860736 _____ C:\Users\Daniel\Downloads\hexedit602.zip 2013-12-31 05:01 - 2013-12-31 05:01 - 00253442 _____ C:\Users\Daniel\Downloads\1209303036_datexpl.rar 2013-12-31 04:58 - 2013-12-31 04:58 - 00018023 _____ C:\Users\Daniel\Downloads\FTL UnPacker 1.0.1.zip 2013-12-31 04:54 - 2013-12-31 04:53 - 11147144 _____ (Adobe Systems, Inc.) C:\Users\Daniel\Downloads\flashplayer_11_sa_debug.exe 2013-12-31 04:53 - 2013-12-31 04:52 - 02179506 _____ (StandaloneFlashPlayer.com ) C:\Users\Daniel\Downloads\standaloneflashplayer_setup.exe 2013-12-31 02:32 - 2013-12-31 02:32 - 10807547 _____ C:\Users\Daniel\Downloads\fmodsandbox43505win-installer.exe 2013-12-31 02:14 - 2013-12-31 02:09 - 79700009 _____ C:\Users\Daniel\Downloads\fmodstudio10211win-installer.exe 2013-12-31 02:09 - 2013-12-31 02:09 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext.zip 2013-12-30 21:28 - 2013-12-30 21:28 - 00000000 ____D C:\Program Files (x86)\WinPcap 2013-12-30 21:10 - 2013-12-30 21:08 - 27981224 _____ (Wireshark development team) C:\Users\Daniel\Downloads\Wireshark-win64-1.10.5.exe 2013-12-29 21:22 - 2013-12-29 21:07 - 00000000 ____D C:\Users\Daniel\AppData\Local\Gapotchenko 2013-12-29 21:07 - 2013-12-29 21:07 - 05001216 _____ C:\Users\Daniel\Downloads\Eazfuscator.NET 4.1 Setup.msi 2013-12-29 19:19 - 2013-12-29 19:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-29 16:15 - 2013-10-19 15:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\Deployment Some content of TEMP: ==================== C:\Users\Daniel\AppData\Local\Temp\AskPIP_FF_.exe C:\Users\Daniel\AppData\Local\Temp\avgnt.exe C:\Users\Daniel\AppData\Local\Temp\secur7512.dll C:\Users\Daniel\AppData\Local\Temp\sonarinst.exe C:\Users\Daniel\AppData\Local\Temp\swt-win32-3349.dll C:\Users\Daniel\AppData\Local\Temp\tmp610.tmp.exe C:\Users\Daniel\AppData\Local\Temp\tmp6649.tmp.exe C:\Users\Daniel\AppData\Local\Temp\tmpAE8E.tmp.exe C:\Users\Daniel\AppData\Local\Temp\x2blapi.dll C:\Users\Daniel\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-20 13:54 ==================== End Of Log ============================ Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-01-2014 02 Ran by Daniel at 2014-01-27 00:54:24 Running from C:\Users\Daniel\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.15.100.30830 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 2.5.709.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.0830.1944.33589 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Fuel (Version: 2013.0830.1944.33589 - Ihr Firmenname) Hidden AMD Media Foundation Decoders (Version: 1.0.80830.1925 - Advanced Micro Devices, Inc.) Hidden AMD Steady Video Plug-In (Version: 2.06.0000 - AMD) Hidden Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira) Battlefield 3™ (x32 Version: 1.6.0.0 - Electronic Arts) Battlelog Web Plugins (x32 Version: 2.3.2 - EA Digital Illusions CE AB) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden Crypto Obfuscator For .Net 2012 R2 (x32 Version: - LogicNP Software) DAEMON Tools Lite (x32 Version: 4.48.1.0347 - Disc Soft Ltd) Dogs of War (x32 Version: - ) Eazfuscator.NET (x32 Version: 4.1.166 - Gapotchenko) Entity Framework Designer für Visual Studio 2012 - DEU (x32 Version: 11.1.20810.00 - Microsoft Corporation) EPSON Scan (x32 Version: - Seiko Epson Corporation) EPSON WF-2530 Series Printer Uninstall (Version: - SEIKO EPSON Corporation) Erforderliche Komponenten für SSDT (x32 Version: 11.0.2100.60 - Microsoft Corporation) ESN Sonar (x32 Version: 0.70.4 - ESN Social Software AB) Extended Update (HKCU Version: - ) FMOD Designer (x32 Version: - ) FMOD Sandbox (remove only) (x32 Version: - ) FormatFactory 3.2.1.0 (x32 Version: 3.2.1.0 - Free Time) Foxtab (x32 Version: - FoxTab) <==== ATTENTION GIMP 2.8.10 (Version: 2.8.10 - The GIMP Team) Google Chrome (x32 Version: 32.0.1700.76 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Hex-Editor MX (x32 Version: 6.0 - NEXT-Soft) HTC Driver Installer (x32 Version: 4.8.0.002 - HTC Corporation) HTC Sync Manager (x32 Version: 2.3.32.0 - HTC) IDA Pro Free v5.0 (x32 Version: - Hex-Rays SA) IPTInstaller (x32 Version: 4.0.8 - HTC) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JetBrains dotPeek 1.1 (x32 Version: 1.1.1.33 - JetBrains Inc) League of Legends (x32 Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden LOLReplay (x32 Version: 0.8.5.2 - www.leaguereplays.com) Marvell Miniport Driver (x32 Version: 11.45.3.3 - Marvell) Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5 Multi-Targeting Pack (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK - DEU Lang Pack (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (x32 Version: 4.5.50709 - Microsoft Corporation) Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727 - Microsoft Corporation) Microsoft Help Viewer 2.0 (x32 Version: 2.0.50727 - Microsoft Corporation) Hidden Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727 - Microsoft Corporation) Microsoft Help Viewer 2.0 Language Pack - DEU (x32 Version: 2.0.50727 - Microsoft Corporation) Hidden Microsoft NuGet - Visual Studio Express 2012 for Windows Desktop (x32 Version: 2.0.30717.9005 - Microsoft Corporation) Hidden Microsoft SQL Server 2012 Command Line Utilities (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x32 Version: 11.0.2316.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL Compiler Service (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL Language Service (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 DEU (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - DEU (11.1.20828.01) (x32 Version: 11.1.20828.01 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - DEU (11.1.20828.01) (x32 Version: 11.1.20828.01 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 32bit Compilers - DEU Resources (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Core Libraries (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (x32 Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86-x64 Compilers (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Express Prerequisites x64 - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell (Minimum) (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Shell-(Mindest)-Ressourcen (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012 Tools für SQL Server Compact 4.0 SP1 DEU (x32 Version: 4.0.8876.1 - Microsoft Corporation) Hidden Microsoft Visual Studio 2012-Vorbereitung (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Express 2012 for Windows Desktop (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Express 2012 für Windows Desktop - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Express 2012 für Windows Desktop - DEU (x32 Version: 11.0.50727.42 - Microsoft Corporation) Microsoft Visual Studio Team Foundation Server 2012 Object Model (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - DEU (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Team Explorer (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - DEU (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual Studio Ultimate 2012 XAML UI Designer deu Resources (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft-System-CLR-Typen für SQL Server 2012 (x32 Version: 11.0.2100.60 - Microsoft Corporation) Microsoft-System-CLR-Typen für SQL Server 2012 (x64) (Version: 11.0.2100.60 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 en-US) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) Nexus Mod Manager (Version: 0.46.0 - Black Tree Gaming) Notepad++ (x32 Version: 6.5.3 - Notepad++ Team) OpenOffice 4.0.1 (x32 Version: 4.01.9714 - Apache Software Foundation) Opera Mail 1.0 (HKCU Version: 1.0.1040 - Opera Software ASA) Origin (x32 Version: 9.3.11.2762 - Electronic Arts, Inc.) Overwolf (x32 Version: 0.47.284 - Overwolf) PunkBuster Services (x32 Version: 0.991 - Even Balance, Inc.) puush (x32 Version: 1.0.0.0 - Dean Herbert) Realtek High Definition Audio Driver (x32 Version: 6.0.1.7071 - Realtek Semiconductor Corp.) Sandboxie 4.06 (64-bit) (Version: 4.06 - Sandboxie Holdings, LLC) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) SliQ Link Clicker Lite (x32 Version: 1.06.0000 - SliQTools) Software Updater (x32 Version: 4.1.7 - SEIKO EPSON CORPORATION) Sony Mobile Update Service (x32 Version: 2.13.13.201311080941 - Sony Mobile Communications AB) Spotify (HKCU Version: 0.9.7.16.g4b197456 - Spotify AB) SteelSeries Engine (Version: 2.8.171.34768 - SteelSeries) SweetFX Configurator (HKCU Version: 1.3.3.32 - SweetFX Configurator) TeamSpeak 3 Client (x32 Version: 3.0.13 - TeamSpeak Systems GmbH) TeamViewer 9 (x32 Version: 9.0.24951 - TeamViewer) The Elder Scrolls Online Beta (x32 Version: 0.3.4 - ) TmNationsForever (x32 Version: - Nadeo) Update for (KB2504637) (x32 Version: 1 - Microsoft Corporation) Update for Foxtab (HKCU Version: - Update for Foxtab) <==== ATTENTION Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1 - Microsoft Corporation) VLC media player 2.1.1 (Version: 2.1.1 - VideoLAN) Windows Software Development Kit (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit DirectX x64 Remote (Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit DirectX x86 Remote (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps DirectX x64 Remote (Version: 8.59.25584 - Microsoft Corporation) Hidden Windows Software Development Kit for Windows Store Apps DirectX x86 Remote (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden WinPcap 4.1.3 (x32 Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 5.00 (64-Bit) (Version: 5.00.0 - win.rar GmbH) Wireshark 1.10.5 (64-bit) (x32 Version: 1.10.5 - The Wireshark developer community, hxxp://www.wireshark.org) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0870FFF3-0271-44E8-B611-EA5FECF1F5BD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19] (Google Inc.) Task: {797E3838-C955-4E62-AC4C-B35EDF2EE115} - System32\Tasks\FoxTab => C:\Users\Daniel\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-30] () <==== ATTENTION Task: {956F132C-EAC0-4CDE-80E2-4CE1B06EC871} - System32\Tasks\UpdaterEX => C:\Users\Daniel\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {D6633C07-45BF-449C-8901-9B1253F2BCE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19] (Google Inc.) Task: C:\Windows\Tasks\FoxTab.job => C:\Users\Daniel\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\Daniel\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () E:\Notepad++\NppShell_05.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00708096 _____ () E:\SteelSeries\SteelSeries Engine\SSEngineLib.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00175104 _____ () E:\SteelSeries\SteelSeries Engine\DBUtils.dll 2013-12-16 12:50 - 2013-12-16 12:50 - 00089915 _____ () C:\Users\Daniel\AppData\Local\Temp\10d2ca4a-28d7-4d81-8c1e-dc42bb6c83fc\CliSecureRT64.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00280064 _____ () E:\SteelSeries\SteelSeries Engine\DriverCommunication.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00139776 _____ () E:\SteelSeries\SteelSeries Engine\ISSPlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00148480 _____ () E:\SteelSeries\SteelSeries Engine\Localization.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00145408 _____ () E:\SteelSeries\SteelSeries Engine\Utilities.dll 2013-01-10 06:46 - 2013-01-10 06:46 - 00047616 _____ () E:\SteelSeries\SteelSeries Engine\SteelSeriesDrivers\x2api.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 09562112 _____ () E:\SteelSeries\SteelSeries Engine\SSEngineWinGui.dll 2013-01-10 06:46 - 2013-01-10 06:46 - 01102336 _____ () E:\SteelSeries\SteelSeries Engine\System.Data.SQLite.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00209408 _____ () E:\SteelSeries\SteelSeries Engine\CustomWPFColorPicker.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00349696 _____ () E:\SteelSeries\SteelSeries Engine\MousePlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00171008 _____ () E:\SteelSeries\SteelSeries Engine\D3MousePlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00173056 _____ () E:\SteelSeries\SteelSeries Engine\KKMousePlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00171008 _____ () E:\SteelSeries\SteelSeries Engine\SRawPlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00307200 _____ () E:\SteelSeries\SteelSeries Engine\MLGSenseiPlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00154624 _____ () E:\SteelSeries\SteelSeries Engine\WoWGoldPlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00170496 _____ () E:\SteelSeries\SteelSeries Engine\GW2MousePlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00169472 _____ () E:\SteelSeries\SteelSeries Engine\CSGOMousePlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00169984 _____ () E:\SteelSeries\SteelSeries Engine\DOTA2MousePlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00157184 _____ () E:\SteelSeries\SteelSeries Engine\WoWWirelessPlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00170496 _____ () E:\SteelSeries\SteelSeries Engine\CODMousePlugin.dll 2013-11-05 18:19 - 2013-11-05 18:19 - 00169984 _____ () E:\SteelSeries\SteelSeries Engine\WoTMousePlugin.dll 2013-12-31 06:51 - 2013-12-09 11:37 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-10-17 16:08 - 2013-10-17 16:08 - 00031080 _____ () E:\HTC sync manager\DbAccess.dll 2013-10-17 16:08 - 2013-10-17 16:08 - 00607376 _____ () E:\HTC sync manager\sqlite3.dll 2013-10-17 16:09 - 2013-10-17 16:09 - 00044392 _____ () E:\HTC sync manager\NAdvLog.dll 2013-10-17 16:09 - 2013-10-17 16:09 - 00036216 _____ () E:\HTC sync manager\NFileCacheDBAccess.dll 2013-10-17 16:09 - 2013-10-17 16:09 - 00080248 _____ () E:\HTC sync manager\ninstallerhelper.dll 2013-10-17 16:10 - 2013-10-17 16:10 - 00129376 _____ () E:\HTC sync manager\zlib1.dll 2013-10-17 16:10 - 2013-10-17 16:10 - 00223592 _____ () E:\HTC sync manager\DevConnMon.dll 2014-01-17 00:15 - 2014-01-11 11:28 - 00715544 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\libglesv2.dll 2014-01-17 00:15 - 2014-01-11 11:28 - 00100120 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\libegl.dll 2014-01-17 00:15 - 2014-01-11 11:29 - 04055320 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\pdf.dll 2014-01-17 00:15 - 2014-01-11 11:29 - 00399640 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll 2014-01-17 00:15 - 2014-01-11 11:28 - 01634584 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\ffmpegsumo.dll 2014-01-02 13:56 - 2014-01-17 07:50 - 00126816 _____ () D:\Leagueoflegends\RADS\projects\lol_launcher\releases\0.0.0.198\deploy\RiotLauncher.dll 2014-01-02 13:51 - 2013-10-19 18:53 - 04774248 _____ () D:\Leagueoflegends\RADS\projects\lol_air_client\releases\0.0.1.68\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll 2013-10-19 18:53 - 2014-01-17 10:23 - 36967424 _____ () C:\Users\Daniel\AppData\Roaming\Spotify\Data\libcef.dll 2013-10-28 00:57 - 2013-10-28 00:57 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll 2013-10-19 18:53 - 2014-01-17 10:23 - 00887808 _____ () C:\Users\Daniel\AppData\Roaming\Spotify\Data\libglesv2.dll 2013-10-19 18:53 - 2014-01-17 10:23 - 00109568 _____ () C:\Users\Daniel\AppData\Roaming\Spotify\Data\libegl.dll 2014-01-17 00:15 - 2014-01-11 11:29 - 13615896 _____ () C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: AMD High Definition Audio Device Description: AMD High Definition Audio Device Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318} Manufacturer: Advanced Micro Devices Service: AtiHDAudioService Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Standardtastatur (PS/2) Description: Standardtastatur (PS/2) Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318} Manufacturer: (Standardtastaturen) Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (01/26/2014 07:08:29 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/25/2014 07:09:12 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/24/2014 08:55:52 PM) (Source: MsiInstaller) (User: Daniel-PC) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011006}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/24/2014 08:53:41 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/23/2014 07:18:21 AM) (Source: MsiInstaller) (User: Daniel-PC) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011006}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/23/2014 07:16:39 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/22/2014 00:25:59 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: League of Legends.exe, Version: 4.1.0.171, Zeitstempel: 0x52d458f9 Name des fehlerhaften Moduls: League of Legends.exe, Version: 4.1.0.171, Zeitstempel: 0x52d458f9 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0042d7f0 ID des fehlerhaften Prozesses: 0x1958 Startzeit der fehlerhaften Anwendung: 0xLeague of Legends.exe0 Pfad der fehlerhaften Anwendung: League of Legends.exe1 Pfad des fehlerhaften Moduls: League of Legends.exe2 Berichtskennung: League of Legends.exe3 Error: (01/21/2014 05:26:53 AM) (Source: MsiInstaller) (User: Daniel-PC) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011006}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 Error: (01/21/2014 05:22:23 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/20/2014 05:01:04 PM) (Source: Application Hang) (User: ) Description: Programm rads_user_kernel.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 4c0 Startzeit: 01cf15f8aafc11b7 Endzeit: 3 Anwendungspfad: D:\Leagueoflegends\RADS\system\rads_user_kernel.exe Berichts-ID: 06fb6a5b-81ec-11e3-95e8-dc9c52072e08 System errors: ============= Error: (01/26/2014 07:09:07 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2014 07:09:07 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (01/26/2014 07:09:06 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2014 07:09:06 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (01/26/2014 07:09:07 AM) (Source: DCOM) (User: ) Description: 1053WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (01/26/2014 07:09:07 AM) (Source: DCOM) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (01/26/2014 07:07:50 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (01/25/2014 07:10:58 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (01/25/2014 07:10:23 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/25/2014 07:10:23 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Microsoft Office Sessions: ========================= Error: (01/26/2014 07:08:29 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/25/2014 07:09:12 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/24/2014 08:55:52 PM) (Source: MsiInstaller)(User: Daniel-PC) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011006}1625(NULL)(NULL)(NULL) Error: (01/24/2014 08:53:41 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/23/2014 07:18:21 AM) (Source: MsiInstaller)(User: Daniel-PC) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011006}1625(NULL)(NULL)(NULL) Error: (01/23/2014 07:16:39 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/22/2014 00:25:59 PM) (Source: Application Error)(User: ) Description: League of Legends.exe4.1.0.17152d458f9League of Legends.exe4.1.0.17152d458f9c00000050042d7f0195801cf17616d953516D:\Leagueoflegends\RADS\solutions\lol_game_client_sln\releases\0.0.1.6\deploy\League of Legends.exeD:\Leagueoflegends\RADS\solutions\lol_game_client_sln\releases\0.0.1.6\deploy\League of Legends.exef75667cd-8357-11e3-bd3a-dc9c52072e08 Error: (01/21/2014 05:26:53 AM) (Source: MsiInstaller)(User: Daniel-PC) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011006}1625(NULL)(NULL)(NULL) Error: (01/21/2014 05:22:23 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/20/2014 05:01:04 PM) (Source: Application Hang)(User: ) Description: rads_user_kernel.exe0.0.0.04c001cf15f8aafc11b73D:\Leagueoflegends\RADS\system\rads_user_kernel.exe06fb6a5b-81ec-11e3-95e8-dc9c52072e08 ==================== Memory info =========================== Percentage of memory in use: 52% Total physical RAM: 8183.84 MB Available physical RAM: 3927.57 MB Total Pagefile: 16365.85 MB Available Pagefile: 11023.88 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:63.48 GB) (Free:4.62 GB) NTFS Drive d: (Spiele) (Fixed) (Total:234.61 GB) (Free:52.9 GB) NTFS Drive e: (Prog's & Sonstiges) (Fixed) (Total:465.66 GB) (Free:432.57 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: 0E39AC72) Partition 1: (Not Active) - (Size=63 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=235 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 7C276BAF) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Ich danke euch! |
27.01.2014, 07:06 | #2 |
/// the machine /// TB-Ausbilder | Accountzugriffe aus Tokyo hi,
__________________Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ |
27.01.2014, 22:36 | #3 |
| Accountzugriffe aus Tokyo Malwarebytes fand sogar ein LOG-File auf meinem Rechner in dem sich ausspionierte Daten befanden!
__________________Hier ist das LOG-File vom ersten Scan: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1009 www.malwarebytes.org Database version: v2014.01.27.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 Daniel :: Daniel-PC [administrator] 27.01.2014 22:03:59 mbar-log-2014-01-27 (22-03-59).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 265927 Time elapsed: 19 minute(s), 18 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\SOFTWARE\DC3_FEXEC (Malware.Trace) -> Delete on reboot. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 1 C:\Users\Daniel\AppData\Roaming\dclogs (Stolen.Data) -> Delete on reboot. Files Detected: 10 C:\Users\Daniel\AppData\Local\Temp\tmp610.tmp.exe (Backdoor.Agent.MNOGen) -> Delete on reboot. C:\Users\Daniel\AppData\Local\Temp\tmp6649.tmp.exe (Backdoor.Agent.MNOGen) -> Delete on reboot. C:\Users\Daniel\AppData\Local\Temp\tmpAE8E.tmp.exe (Backdoor.Agent.MNOGen) -> Delete on reboot. C:\Users\Daniel\AppData\Local\Temp\temp_APkIeqDPFR\vbc.exe (Misused.Legit) -> Delete on reboot. C:\Users\Daniel\AppData\Local\Temp\temp_DgNkfBCmid\vbc.exe (Misused.Legit) -> Delete on reboot. C:\Users\Daniel\AppData\Local\Temp\temp_httoalWxlm\vbc.exe (Misused.Legit) -> Delete on reboot. C:\Users\Daniel\AppData\Local\Temp\temp_vTtsPKkkkb\vbc.exe (Misused.Legit) -> Delete on reboot. C:\Users\Daniel\Desktop\WPE\WPE PRO - modified.exe (HackTool.Sniffer.WpePro) -> Delete on reboot. C:\Users\Daniel\Desktop\WPE\WpeSpy.dll (HackTool.Sniffer.WpePro) -> Delete on reboot. C:\Users\Daniel\AppData\Roaming\dclogs\2013-12-31-3.dc (Stolen.Data) -> Delete on reboot. Physical Sectors Detected: 0 (No malicious items detected) (end) Vielen vielen Dank für die Hilfe! /E: Beim erstem Durchlauf fand Malwarebytes einen Trojaner mit dem Dateinamen NHC_COOP, beim zweiten Durchlauf fand er ihn nichtmehr. Jetzt, ein paar Minuten später fand Avira die selbe Datei aber in einem anderem Ordner. Geändert von PRiiME (27.01.2014 um 23:14 Uhr) |
28.01.2014, 15:42 | #4 | |
/// the machine /// TB-Ausbilder | Accountzugriffe aus Tokyo Logfile von Avira? MBAR nochmal scannen, frisches Log bitte. Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.01.2014, 17:16 | #5 |
| Accountzugriffe aus Tokyo Combofix Logfile: Code:
ATTFilter ComboFix 14-01-27.02 - Daniel 28.01.2014 16:26:50.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.8184.2206 [GMT 1:00] ausgeführt von:: c:\users\Daniel\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Daniel\AppData\Local\Temp\10d2ca4a-28d7-4d81-8c1e-dc42bb6c83fc\CliSecureRT64.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-28 bis 2014-01-28 )))))))))))))))))))))))))))))) . . 2014-01-28 15:43 . 2014-01-28 15:43 -------- d-----w- c:\users\DefaultAppPool\AppData\Local\temp 2014-01-28 15:43 . 2014-01-28 15:43 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-01-28 12:24 . 2014-01-28 12:24 -------- d-----w- c:\users\Daniel\AppData\Local\Cosa_Nostra 2014-01-28 10:59 . 2014-01-28 10:59 -------- d-----w- c:\users\Daniel\AppData\Local\Blizzard Entertainment 2014-01-28 10:59 . 2014-01-28 10:59 -------- d-----w- c:\users\Daniel\AppData\Local\Battle.net 2014-01-28 10:59 . 2014-01-28 10:59 -------- d-----w- c:\users\Daniel\AppData\Roaming\Battle.net 2014-01-28 10:58 . 2014-01-28 10:58 -------- d-----w- c:\programdata\Blizzard Entertainment 2014-01-28 10:58 . 2014-01-28 10:58 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment 2014-01-28 10:55 . 2014-01-28 10:55 -------- d-----w- c:\programdata\Battle.net 2014-01-28 03:27 . 2014-01-28 03:27 -------- d-----w- c:\program files (x86)\MySQL 2014-01-28 02:34 . 2014-01-28 05:31 -------- d-----w- c:\users\Daniel\AppData\Roaming\FileZilla 2014-01-27 22:07 . 2014-01-27 22:07 -------- d-----w- c:\program files (x86)\ESET 2014-01-27 22:01 . 2014-01-28 09:39 -------- d-----w- c:\users\Daniel\AppData\Roaming\QuickScan 2014-01-27 21:03 . 2014-01-27 21:03 -------- d-----w- c:\programdata\Malwarebytes 2014-01-27 21:03 . 2014-01-27 22:00 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2014-01-27 21:03 . 2014-01-27 21:36 119000 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-01-27 21:02 . 2014-01-27 21:33 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-01-26 23:50 . 2014-01-26 23:50 -------- d-----w- C:\FRST 2014-01-26 17:56 . 2014-01-26 17:56 -------- d-----w- c:\users\Daniel\AppData\Local\SymbolSourceSymbols 2014-01-26 17:56 . 2014-01-26 17:56 -------- d-----w- c:\users\Daniel\AppData\Local\RefSrcSymbols 2014-01-26 17:56 . 2014-01-26 17:57 -------- d-----w- c:\users\Daniel\AppData\Roaming\JetBrains 2014-01-26 17:56 . 2014-01-26 17:56 -------- d-----w- c:\users\Daniel\AppData\Local\JetBrains 2014-01-15 14:47 . 2014-01-15 14:47 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller 2014-01-15 14:46 . 2014-01-15 14:46 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2014-01-15 14:46 . 2014-01-15 14:46 189248 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2014-01-15 14:46 . 2014-01-15 14:46 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe 2014-01-15 14:25 . 2014-01-15 14:25 -------- d-----w- c:\users\Daniel\AppData\Local\Origin 2014-01-15 14:16 . 2014-01-15 14:16 -------- d-----w- c:\programdata\EA Core 2014-01-15 14:16 . 2014-01-15 14:50 -------- d-----w- c:\programdata\EA Logs 2014-01-15 14:16 . 2014-01-15 14:16 -------- d-----w- c:\programdata\Electronic Arts 2014-01-15 14:12 . 2014-01-15 14:12 -------- d-----w- c:\users\Daniel\AppData\Local\ESN 2014-01-15 14:12 . 2014-01-15 14:12 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins 2014-01-13 21:42 . 2014-01-13 21:42 -------- d-----w- c:\users\Daniel\AppData\Local\Black_Tree_Gaming 2014-01-13 19:02 . 2014-01-14 22:08 -------- d-----w- c:\users\Daniel\AppData\Local\Skyrim 2014-01-11 09:20 . 1997-03-24 16:42 314368 ----a-w- c:\windows\IsUninst.exe 2014-01-11 08:53 . 2014-01-11 08:53 -------- d-----w- c:\users\Daniel\AppData\Roaming\Hex-Rays 2014-01-10 19:56 . 2014-01-12 19:44 -------- d-----w- c:\users\Daniel\AppData\Roaming\Awesomium 2014-01-10 19:30 . 2014-01-10 19:30 -------- d-----w- c:\programdata\Elder Scrolls Online 2014-01-07 18:03 . 2014-01-07 18:03 -------- d-----w- c:\users\Daniel\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2 2014-01-07 18:03 . 2014-01-07 18:03 -------- d-----w- c:\users\Daniel\AppData\Local\SkinSoft 2014-01-06 15:06 . 2014-01-06 15:06 409600 ----a-r- c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{F149CF33-0074-4AF8-AC1C-AE51086D4E25}\SliQEmailLinkClick_F553E8ECFC61412F965137651E73CF0E.exe 2014-01-06 15:06 . 2014-01-06 15:06 409600 ----a-r- c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{F149CF33-0074-4AF8-AC1C-AE51086D4E25}\SliQEmailLinkClick_52AB910A415D44CBAEA63829349710C3.exe 2014-01-06 15:06 . 2014-01-06 15:06 409600 ----a-r- c:\users\Daniel\AppData\Roaming\Microsoft\Installer\{F149CF33-0074-4AF8-AC1C-AE51086D4E25}\ARPPRODUCTICON.exe 2014-01-03 22:54 . 2014-01-03 22:54 42184 ----a-w- c:\windows\system32\drivers\taphss6.sys 2014-01-03 16:16 . 2014-01-03 16:16 -------- d-----w- c:\program files (x86)\TeamViewer 2014-01-02 06:06 . 2014-01-02 06:06 -------- d-----w- c:\users\Daniel\AppData\Roaming\Notepad++ 2013-12-31 17:21 . 2014-01-27 22:15 -------- d-----w- c:\users\Daniel\AppData\Local\CrashDumps 2013-12-31 05:52 . 2013-12-31 05:52 -------- d-----w- c:\users\Daniel\AppData\Roaming\Avira 2013-12-31 05:51 . 2013-12-09 10:37 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-12-31 05:51 . 2013-12-09 10:37 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-12-31 05:51 . 2013-12-09 10:37 131576 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-12-31 05:51 . 2013-12-09 10:37 108440 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-12-31 05:51 . 2013-12-31 05:51 -------- d-----w- c:\programdata\Avira 2013-12-31 05:51 . 2013-12-31 05:51 -------- d-----w- c:\program files (x86)\Avira 2013-12-31 01:16 . 2014-01-02 11:11 -------- d-----w- c:\users\Daniel\AppData\Local\FMOD Studio 2013-12-30 20:36 . 2014-01-26 18:06 -------- d-----w- c:\users\Daniel\AppData\Roaming\Wireshark 2013-12-30 20:28 . 2013-12-30 20:28 -------- d-----w- c:\program files (x86)\WinPcap 2013-12-29 20:07 . 2013-12-29 20:22 -------- d-----w- c:\users\Daniel\AppData\Local\Gapotchenko . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-01-27 21:29 . 2013-12-01 21:39 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin 2013-11-23 13:52 . 2013-11-23 13:52 27760 ----a-w- c:\windows\system32\drivers\ggsemc.sys 2013-11-23 13:52 . 2013-11-23 13:52 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll 2013-11-23 13:52 . 2013-11-23 13:52 14448 ----a-w- c:\windows\system32\drivers\ggflt.sys 2013-11-18 17:53 . 2013-11-18 17:53 1089632 ----a-w- c:\programdata\Microsoft\WDExpress\11.0\1031\ResourceCache.dll 2013-11-15 18:19 . 2013-11-15 18:19 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2013-11-09 18:43 . 2013-11-09 18:43 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-11-09 18:43 . 2013-11-09 18:43 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-09 18:43 . 2013-11-09 18:43 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-11-09 18:43 . 2013-11-09 18:43 89600 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-09 18:43 . 2013-11-09 18:43 855552 ----a-w- c:\windows\system32\jscript.dll 2013-11-09 18:43 . 2013-11-09 18:43 81408 ----a-w- c:\windows\system32\icardie.dll 2013-11-09 18:43 . 2013-11-09 18:43 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-11-09 18:43 . 2013-11-09 18:43 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-11-09 18:43 . 2013-11-09 18:43 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-11-09 18:43 . 2013-11-09 18:43 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-09 18:43 . 2013-11-09 18:43 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-11-09 18:43 . 2013-11-09 18:43 67072 ----a-w- c:\windows\system32\iesetup.dll 2013-11-09 18:43 . 2013-11-09 18:43 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-11-09 18:43 . 2013-11-09 18:43 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-11-09 18:43 . 2013-11-09 18:43 61440 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-11-09 18:43 . 2013-11-09 18:43 603136 ----a-w- c:\windows\system32\msfeeds.dll 2013-11-09 18:43 . 2013-11-09 18:43 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-11-09 18:43 . 2013-11-09 18:43 53248 ----a-w- c:\windows\system32\jsproxy.dll 2013-11-09 18:43 . 2013-11-09 18:43 526336 ----a-w- c:\windows\system32\ieui.dll 2013-11-09 18:43 . 2013-11-09 18:43 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-11-09 18:43 . 2013-11-09 18:43 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-11-09 18:43 . 2013-11-09 18:43 51712 ----a-w- c:\windows\system32\ie4uinit.exe 2013-11-09 18:43 . 2013-11-09 18:43 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-11-09 18:43 . 2013-11-09 18:43 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-11-09 18:43 . 2013-11-09 18:43 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-09 18:43 . 2013-11-09 18:43 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-11-09 18:43 . 2013-11-09 18:43 441856 ----a-w- c:\windows\system32\html.iec 2013-11-09 18:43 . 2013-11-09 18:43 39936 ----a-w- c:\windows\system32\iernonce.dll 2013-11-09 18:43 . 2013-11-09 18:43 3959296 ----a-w- c:\windows\system32\jscript9.dll 2013-11-09 18:43 . 2013-11-09 18:43 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-11-09 18:43 . 2013-11-09 18:43 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-11-09 18:43 . 2013-11-09 18:43 2876928 ----a-w- c:\windows\SysWow64\jscript9.dll 2013-11-09 18:43 . 2013-11-09 18:43 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-11-09 18:43 . 2013-11-09 18:43 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-11-09 18:43 . 2013-11-09 18:43 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-11-09 18:43 . 2013-11-09 18:43 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb 2013-11-09 18:43 . 2013-11-09 18:43 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-11-09 18:43 . 2013-11-09 18:43 2647552 ----a-w- c:\windows\system32\iertutil.dll 2013-11-09 18:43 . 2013-11-09 18:43 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-11-09 18:43 . 2013-11-09 18:43 235008 ----a-w- c:\windows\system32\url.dll 2013-11-09 18:43 . 2013-11-09 18:43 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-11-09 18:43 . 2013-11-09 18:43 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-11-09 18:43 . 2013-11-09 18:43 2241024 ----a-w- c:\windows\system32\wininet.dll 2013-11-09 18:43 . 2013-11-09 18:43 216064 ----a-w- c:\windows\system32\msls31.dll 2013-11-09 18:43 . 2013-11-09 18:43 197120 ----a-w- c:\windows\system32\msrating.dll 2013-11-09 18:43 . 2013-11-09 18:43 19252224 ----a-w- c:\windows\system32\mshtml.dll 2013-11-09 18:43 . 2013-11-09 18:43 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-11-09 18:43 . 2013-11-09 18:43 1767936 ----a-w- c:\windows\SysWow64\wininet.dll 2013-11-09 18:43 . 2013-11-09 18:43 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-11-09 18:43 . 2013-11-09 18:43 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-11-09 18:43 . 2013-11-09 18:43 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-11-09 18:43 . 2013-11-09 18:43 15404544 ----a-w- c:\windows\system32\ieframe.dll 2013-11-09 18:43 . 2013-11-09 18:43 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-11-09 18:43 . 2013-11-09 18:43 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-11-09 18:43 . 2013-11-09 18:43 149504 ----a-w- c:\windows\system32\occache.dll 2013-11-09 18:43 . 2013-11-09 18:43 144896 ----a-w- c:\windows\system32\wextract.exe 2013-11-09 18:43 . 2013-11-09 18:43 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-11-09 18:43 . 2013-11-09 18:43 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-09 18:43 . 2013-11-09 18:43 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-11-09 18:43 . 2013-11-09 18:43 13824 ----a-w- c:\windows\system32\mshta.exe 2013-11-09 18:43 . 2013-11-09 18:43 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-11-09 18:43 . 2013-11-09 18:43 136704 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-09 18:43 . 2013-11-09 18:43 1365504 ----a-w- c:\windows\system32\urlmon.dll 2013-11-09 18:43 . 2013-11-09 18:43 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-11-09 18:43 . 2013-11-09 18:43 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-09 18:43 . 2013-11-09 18:43 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-11-09 18:43 . 2013-11-09 18:43 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-11-09 18:43 . 2013-11-09 18:43 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-11-09 18:43 . 2013-11-09 18:43 109056 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-11-09 18:43 . 2013-11-09 18:43 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-09 18:43 . 2013-11-09 18:43 102912 ----a-w- c:\windows\system32\inseng.dll 2013-11-09 18:40 . 2013-11-09 18:40 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-11-09 18:40 . 2013-11-09 18:40 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-11-09 18:40 . 2013-11-09 18:40 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-11-09 18:40 . 2013-11-09 18:40 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-11-09 18:40 . 2013-11-09 18:40 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-11-09 18:40 . 2013-11-09 18:40 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-11-09 18:40 . 2013-11-09 18:40 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-11-09 18:40 . 2013-11-09 18:40 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-11-09 18:40 . 2013-11-09 18:40 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-11-09 18:40 . 2013-11-09 18:40 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-11-09 18:40 . 2013-11-09 18:40 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-18 20587168] "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE" [2012-02-27 283232] "SteelSeries Engine"="e:\steelseries\SteelSeries Engine\SteelSeriesEngine.exe" [2013-11-05 242688] "puush"="e:\puush\puush.exe" [2013-12-22 567880] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-08-30 766208] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-12-09 684600] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x] S2 EPSON_PM_RPCV4_05;EPSON V3 Service4(05);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE [x] S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc64.exe;c:\windows\SYSNATIVE\EscSvc64.exe [x] S2 HTCMonitorService;HTCMonitorService;e:\htc sync manager\HSMServiceEntry.exe;e:\htc sync manager\HSMServiceEntry.exe [x] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x] S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x] S3 busenum;SteelBusSvc;c:\windows\system32\DRIVERS\SteelBus64.sys;c:\windows\SYSNATIVE\DRIVERS\SteelBus64.sys [x] S3 SAlphamHid;SteelHIDSvc;c:\windows\system32\DRIVERS\SAlpham64.sys;c:\windows\SYSNATIVE\DRIVERS\SAlpham64.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] S3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\drivers\WSDScan.sys;c:\windows\SYSNATIVE\drivers\WSDScan.sys [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] iissvcs REG_MULTI_SZ w3svc was apphost REG_MULTI_SZ apphostsvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-01-16 23:13 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.76\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19 14:56] . 2014-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19 14:56] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-10-18 13657304] "MsmqIntCert"="mqrt.dll" [2010-11-21 247808] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.188.1 FF - ProfilePath - c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\ FF - ExtSQL: 2013-12-14 14:42; SQLiteManager@mrinalkant.blogspot.com; c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\extensions\SQLiteManager@mrinalkant.blogspot.com.xpi FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=526426fd000000000000dc9c52072e08&q= FF - user.js: extensions.Softonic.id - 526426fd000000000000dc9c52072e08 FF - user.js: extensions.Softonic.appId - {7ABBFE1C-E485-44AA-8F36-353751B4124D} FF - user.js: extensions.Softonic.instlDay - 16024 FF - user.js: extensions.Softonic.vrsn - 1.8.21.14 FF - user.js: extensions.Softonic.vrsni - 1.8.21.14 FF - user.js: extensions.Softonic.vrsnTs - 1.8.21.1419:20 FF - user.js: extensions.Softonic.prtnrId - softonic FF - user.js: extensions.Softonic.prdct - Softonic FF - user.js: extensions.Softonic.aflt - OC FF - user.js: extensions.Softonic.smplGrp - none FF - user.js: extensions.Softonic.tlbrId - opencandy2013 FF - user.js: extensions.Softonic.instlRef - MOY00621 FF - user.js: extensions.Softonic.dfltLng - de FF - user.js: extensions.Softonic.excTlbr - false FF - user.js: extensions.Softonic.ffxUnstlRst - false FF - user.js: extensions.Softonic.admin - false FF - user.js: extensions.Softonic.autoRvrt - false FF - user.js: extensions.Softonic.rvrt - false FF - user.js: extensions.Softonic.hmpg - true FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=526426fd000000000000dc9c52072e08 FF - user.js: extensions.Softonic.dfltSrch - true FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic) FF - user.js: extensions.Softonic.dnsErr - true FF - user.js: extensions.Softonic.newTab - true FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=526426fd000000000000dc9c52072e08 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-UpdaterEX - c:\users\Daniel\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:09,cb,c2,5c,ae,1b,cf,01 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dd,4c,37,e9,30,df,87,4e,b2,b7,13,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dd,4c,37,e9,30,df,87,4e,b2,b7,13,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-01-28 17:12:39 ComboFix-quarantined-files.txt 2014-01-28 16:12 . Vor Suchlauf: 11 Verzeichnis(se), 10.199.166.976 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 10.043.396.096 Bytes frei . - - End Of File - - D808E57512C96D139F6D8A964D2AE805 5FB38429D5D77768867C76DCBDB35194 MBar Log (28.01.2014 / 17:29): Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1009 www.malwarebytes.org Database version: v2014.01.27.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 Dennis :: DANIEL-PC [administrator] 28.01.2014 17:16:12 mbar-log-2014-01-28 (17-16-12).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 263637 Time elapsed: 12 minute(s), 18 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Geändert von PRiiME (28.01.2014 um 17:30 Uhr) |
29.01.2014, 10:57 | #6 |
/// the machine /// TB-Ausbilder | Accountzugriffe aus Tokyo Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Accountzugriffe aus Tokyo |
29.01.2014, 11:41 | #7 |
| Accountzugriffe aus Tokyo JRT LOG: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Ultimate x64 Ran by Daniel on 29.01.2014 at 11:31:57,89 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1441510524-1933241039-3303874102-1000\Software\Microsoft\Internet Explorer\Main\\Start Page ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\caphyon Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup1_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup1_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BC3ADBFF-A058-403F-98C3-7B6594437EEF} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ FireFox Emptied folder: C:\Users\Daniel\AppData\Roaming\mozilla\firefox\profiles\j575yr6r.default\minidumps [6 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.01.2014 at 11:39:39,46 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.29.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 Daniel :: Daniel-PC [Administrator] Schutz: Aktiviert 29.01.2014 11:12:10 mbam-log-2014-01-29 (11-12-10).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 238487 Laufzeit: 6 Minute(n), 28 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 3 HKCU\SOFTWARE\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\InstallCore\1I1T1Q1S (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 1 HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0A1M1S1N1H2Q1H0B1O1O -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 9 C:\Users\Daniel\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\AppData\Roaming\OpenCandy\7BFC9651634C49B7B96C9426DD3BB90A (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive\Update (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive\Update\Log (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\AppData\Local\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\AppData\Local\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Program Files (x86)\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 9 C:\Users\Daniel\Downloads\camfrog.exe (PUP.Optional.Spigot.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\Downloads\ccleaner.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\Downloads\DTLite4481-0347.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\Downloads\Fritz_Box_reconnect.zip (PUP.Netcat) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\Downloads\onxyCrypter.rar (Backdoor.Agent.DCRSAGen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\Downloads\UI RAF.rar (Backdoor.Agent.MNOGen) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\Downloads\wpepro09mod.zip (HackTool.Sniffer.WpePro) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Daniel\AppData\Roaming\OpenCandy\7BFC9651634C49B7B96C9426DD3BB90A\Setupsft_chr_p1v7.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\BonanzaDealsLive\Update\Log\BonanzaDealsLive.log (PUP.Optional.BonanzaDeals.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) AdwCleaner LOG: Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 29/01/2014 um 11:26:44 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : Daniel - Daniel-PC # Gestartet von : C:\Users\Daniel\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files (x86)\BonanzaDeals Ordner Gelöscht : C:\Users\Daniel\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Daniel\AppData\Roaming\UpdaterEX Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\invalidprefs.js Datei Gelöscht : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\searchplugins\softonic.xml Datei Gelöscht : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKCU\Software\anchorfree Schlüssel Gelöscht : HKLM\Software\InstallCore ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v26.0 (en-US) [ Datei : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\prefs.js ] Zeile gelöscht : user_pref("extensions.Softonic.admin", false); Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC"); Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}"); Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true); Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true); Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false); Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false); Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true); Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=526426fd000000000000dc9c52072e08"); Zeile gelöscht : user_pref("extensions.Softonic.id", "526426fd000000000000dc9c52072e08"); Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16024"); Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621"); Zeile gelöscht : user_pref("extensions.Softonic.newTab", true); Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=526426fd000000000000dc9c52072e08"); Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic"); Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic"); Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=526426fd000000000000dc9c52072e08&q="); Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14"); Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1419:20:07"); Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14"); -\\ Google Chrome v32.0.1700.102 [ Datei : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [4385 octets] - [29/01/2014 11:25:40] AdwCleaner[S0].txt - [4259 octets] - [29/01/2014 11:26:44] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4319 octets] ########## FRST LOG: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 Ran by Daniel (administrator) on Daniel-PC on 29-01-2014 11:42:22 Running from C:\Users\Daniel\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Sandboxie Holdings, LLC) E:\Sandboxie\SbieSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE (Nero AG) E:\HTC sync manager\HSMServiceEntry.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE () E:\HTC sync manager\HTC Sync\adb.exe () E:\puush\puush.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13657304 2013-10-18] (Realtek Semiconductor) HKLM\...\Run: [MsmqIntCert] - regsvr32 /s mqrt.dll HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE [283232 2012-02-27] (SEIKO EPSON CORPORATION) HKCU\...\Run: [SteelSeries Engine] - E:\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [242688 2013-11-05] (SteelSeries ApS) HKCU\...\Run: [puush] - E:\puush\puush.exe [567880 2013-12-22] () HKCU\...\Run: [GoogleChromeAutoLaunch_5560E485902A34F6B1CF63ACD9274ABA] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [866584 2014-01-23] (Google Inc.) HKCU\...\Run: [AdobeBridge] - [x] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4D3BFB3EDBCCCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Tcpip\Parameters: [DhcpNameServer] 192.168.188.1 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - E:\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: iMacros for Firefox - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-01-06] FF Extension: Live HTTP Headers - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2013-11-25] FF Extension: SQLite Manager - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\SQLiteManager@mrinalkant.blogspot.com.xpi [2013-12-14] Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-19] CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-19] CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-19] CHR Extension: (Adblock Plus) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-13] CHR Extension: (Google-Suche) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-19] CHR Extension: (iMacros for Chrome) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp [2014-01-06] CHR Extension: (Foxtab Speed Dial) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchmpbaclbiioedakpcldenooikekokm [2014-01-22] CHR Extension: (FoxyProxy Standard) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcknhkkoolaabfmlnjonogaaifnjlfnp [2013-12-17] CHR Extension: (Live HTTP Headers) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaiioopjkcekapmldfgbebdclcnpgnlo [2014-01-28] CHR Extension: (EXIF Viewer) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2014-01-16] CHR Extension: (EXIF Reader) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nchnjcdahncnilbicljpnbfobpnljnki [2014-01-16] CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-19] CHR Extension: (Bitdefender QuickScan) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2014-01-27] CHR Extension: (Google Mail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-19] CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-08-30] (Advanced Micro Devices, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-09] (Avira Operations GmbH & Co. KG) R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 HTCMonitorService; E:\HTC sync manager\HSMServiceEntry.exe [87368 2013-09-02] (Nero AG) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-21] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-21] (Microsoft Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2014-01-15] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2014-01-15] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) R2 SbieSvc; E:\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-09] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-15] (Disc Soft Ltd) S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [91352 2014-01-28] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation) R3 SbieDrv; E:\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-01-03] (Anchorfree Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-29 11:42 - 2014-01-29 11:42 - 00000000 ____D C:\Users\Daniel\Downloads\FRST-OlderVersion 2014-01-29 11:39 - 2014-01-29 11:39 - 00002056 _____ C:\Users\Daniel\Desktop\JRT.txt 2014-01-29 11:31 - 2014-01-29 11:31 - 01037068 _____ (Thisisu) C:\Users\Daniel\Downloads\JRT.exe 2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\ERUNT 2014-01-29 11:25 - 2014-01-29 11:26 - 00000000 ____D C:\AdwCleaner 2014-01-29 11:25 - 2014-01-29 11:25 - 01166132 _____ C:\Users\Daniel\Downloads\adwcleaner.exe 2014-01-29 11:10 - 2014-01-29 11:10 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2014-01-29 11:09 - 2014-01-29 11:09 - 00001119 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-29 11:09 - 2014-01-29 11:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-29 11:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-29 11:08 - 2014-01-29 11:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Daniel\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-28 17:56 - 2014-01-28 17:56 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2014-01-28 17:53 - 2014-01-28 17:56 - 00000000 ____D C:\Program Files\Common Files\Adobe 2014-01-28 17:49 - 2014-01-28 17:49 - 00102932 ____H C:\Windows\SysWOW64\mlfcache.dat 2014-01-28 17:44 - 2014-01-29 11:20 - 00006154 _____ C:\Windows\PFRO.log 2014-01-28 17:13 - 2014-01-28 17:13 - 00026718 _____ C:\ComboFix.txt 2014-01-28 16:24 - 2014-01-28 17:14 - 00000000 ____D C:\Qoobox 2014-01-28 16:24 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-28 16:24 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-28 16:24 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-28 16:23 - 2014-01-28 17:07 - 00000000 ____D C:\Windows\erdnt 2014-01-28 16:23 - 2014-01-28 16:23 - 05175619 ____R (Swearware) C:\Users\Daniel\Downloads\ComboFix.exe 2014-01-28 14:37 - 2014-01-28 14:42 - 00169060 _____ C:\Users\Daniel\Documents\lordangelomails1.txt 2014-01-28 14:10 - 2013-08-31 07:42 - 00000000 ____D C:\Users\Daniel\Desktop\CryptoObfuscator.Enterprise.2012.R2.Build.130111 2014-01-28 14:01 - 2014-01-28 14:07 - 17584706 _____ C:\Users\Daniel\Downloads\CryptoObfuscator.Enterprise.2012.R2.Build.130111 (1).rar 2014-01-28 13:57 - 2014-01-28 13:57 - 00930440 _____ (CNET Download.com) C:\Users\Daniel\Downloads\cbsidlm-cbsi176-Crypto_Obfuscator_For_Net-ORG-10968597.exe 2014-01-28 13:24 - 2014-01-28 13:24 - 00000000 ____D C:\Users\Daniel\AppData\Local\Cosa_Nostra 2014-01-28 13:22 - 2014-01-28 13:23 - 00134947 _____ C:\Users\Daniel\Downloads\RgxTester10Exe.zip 2014-01-28 12:04 - 2014-01-28 12:04 - 00880069 _____ C:\Users\Daniel\Downloads\Reteewt v1.2.rar 2014-01-28 12:04 - 2014-01-28 12:04 - 00000000 ____D C:\Users\Daniel\Desktop\asdad 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Battle.net 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Blizzard Entertainment 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Battle.net 2014-01-28 11:58 - 2014-01-28 11:58 - 00000788 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-28 11:58 - 2014-01-28 11:58 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2014-01-28 11:55 - 2014-01-28 11:55 - 00000000 ____D C:\ProgramData\Battle.net 2014-01-28 11:54 - 2014-01-28 11:54 - 05748920 _____ (Blizzard Entertainment) C:\Users\Daniel\Downloads\Battle.net-Beta-Setup-deDE.exe 2014-01-28 07:29 - 2014-01-29 11:28 - 00000280 _____ C:\Windows\setupact.log 2014-01-28 07:29 - 2014-01-28 07:29 - 00000000 _____ C:\Windows\setuperr.log 2014-01-28 05:57 - 2014-01-28 10:04 - 00000000 ____D C:\Users\Daniel\Documents\botman 2014-01-28 05:19 - 2014-01-28 05:19 - 00003901 _____ C:\Users\Daniel\Downloads\smime.p7s 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Program Files (x86)\MySQL 2014-01-28 04:26 - 2014-01-28 04:26 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6 (1).zip 2014-01-28 04:22 - 2014-01-28 04:22 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6.zip 2014-01-28 03:34 - 2014-01-28 17:42 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\FileZilla 2014-01-28 03:29 - 2014-01-28 03:29 - 07241860 _____ C:\Users\Daniel\Downloads\FileZilla_3.7.3_win32.zip 2014-01-27 23:24 - 2014-01-27 23:24 - 00000000 ____D C:\Windows\pss 2014-01-27 23:09 - 2014-01-27 23:24 - 00002748 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-27 23:09 - 2014-01-27 23:09 - 00000568 _____ C:\Users\Daniel\Desktop\CCleaner.lnk 2014-01-27 23:09 - 2014-01-27 23:09 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-01-27 23:08 - 2014-01-27 23:08 - 04721920 _____ (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup410.exe 2014-01-27 23:07 - 2014-01-27 23:07 - 02347384 _____ (ESET) C:\Users\Daniel\Downloads\esetsmartinstaller_enu.exe 2014-01-27 23:07 - 2014-01-27 23:07 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-27 23:01 - 2014-01-28 10:39 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\QuickScan 2014-01-27 22:03 - 2014-01-27 22:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-27 22:02 - 2014-01-28 17:29 - 00000000 ____D C:\Users\Daniel\Desktop\mbar 2014-01-27 22:02 - 2014-01-28 17:16 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-27 22:02 - 2014-01-27 22:02 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Daniel\Downloads\mbar-1.07.0.1009.exe 2014-01-27 00:54 - 2014-01-27 00:54 - 00033821 _____ C:\Users\Daniel\Downloads\Addition.txt 2014-01-27 00:50 - 2014-01-29 11:42 - 00015087 _____ C:\Users\Daniel\Downloads\FRST.txt 2014-01-27 00:50 - 2014-01-29 11:42 - 00000000 ____D C:\FRST 2014-01-27 00:49 - 2014-01-29 11:42 - 02079744 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe 2014-01-26 19:38 - 2014-01-26 19:38 - 01104710 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE.zip 2014-01-26 19:26 - 2014-01-26 19:26 - 00000005 _____ C:\Users\Daniel\Downloads\Download 2014-01-26 18:56 - 2014-01-26 18:57 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\JetBrains 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\SymbolSourceSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\RefSrcSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\JetBrains 2014-01-26 18:51 - 2014-01-26 18:53 - 29220864 _____ C:\Users\Daniel\Downloads\dotPeekSetup-1.1.1.33.msi 2014-01-26 18:38 - 2014-01-26 18:38 - 00157234 _____ C:\Users\Daniel\Downloads\RouterReconnect_1.3.zip 2014-01-26 18:38 - 2008-04-19 18:03 - 00335360 _____ (RPworld.de) C:\Users\Daniel\Desktop\RouterReconnect.exe 2014-01-26 18:37 - 2014-01-26 18:37 - 04689382 _____ C:\Users\Daniel\Downloads\curl-7.34.0.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 00094335 _____ C:\Users\Daniel\Downloads\Fritz!Box Reconnect.rar 2014-01-26 17:50 - 2014-01-26 17:50 - 00001154 _____ C:\Users\Daniel\Documents\absolutechamp.txt 2014-01-26 16:36 - 2014-01-26 16:49 - 00000000 ____D C:\Users\Daniel\Documents\Rezepte 2014-01-23 17:07 - 2014-01-26 18:25 - 00000000 ____D C:\Users\Daniel\Documents\zorroslisten 2014-01-23 09:50 - 2014-01-23 09:51 - 12322963 _____ C:\Users\Daniel\Downloads\Thread_Design_2.zip 2014-01-23 09:41 - 2014-01-23 09:41 - 01398825 _____ C:\Users\Daniel\Downloads\wg_3d_banners_vol3.zip 2014-01-23 09:38 - 2014-01-23 09:38 - 42713738 _____ C:\Users\Daniel\Downloads\Devisual's Graphics Pack.rar 2014-01-22 14:41 - 2014-01-22 14:41 - 00000000 _____ C:\Users\Daniel\Desktop\KUHDO.txt 2014-01-22 14:31 - 2014-01-22 14:32 - 00000000 ____D C:\Users\Daniel\Desktop\Lobby checker 2014-01-17 12:16 - 2014-01-17 12:16 - 00092309 _____ C:\Users\Daniel\Downloads\MarkC_Windows_8.x+7_MouseFix.zip 2014-01-15 15:47 - 2014-01-15 15:47 - 00000749 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-15 15:46 - 2014-01-15 15:46 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 15:36 - 2014-01-15 15:38 - 08501736 _____ C:\Users\Daniel\Downloads\HSS-3.31-install-e-550-plain.exe 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2014-01-15 15:22 - 2014-01-15 15:22 - 00000530 _____ C:\Users\Public\Desktop\Origin.lnk 2014-01-15 15:20 - 2014-01-15 15:21 - 16952720 _____ (Electronic Arts, Inc.) C:\Users\Daniel\Downloads\OriginThinSetup.exe 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\EA Core 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Users\Daniel\AppData\Local\ESN 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2014-01-15 15:11 - 2014-01-15 15:11 - 03821064 _____ C:\Users\Daniel\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00012885 _____ C:\Users\Daniel\AppData\Local\recently-used.xbel 2014-01-15 11:38 - 2014-01-15 11:38 - 01016952 _____ C:\Users\Daniel\Downloads\25273 (1).zip 2014-01-15 09:23 - 2014-01-15 09:23 - 00004705 _____ C:\Users\Daniel\Downloads\First Person Camera Fix-6508-1.7z 2014-01-15 08:46 - 2014-01-15 08:46 - 00060838 _____ C:\Users\Daniel\Downloads\SafetyLoad 1_2-46465-1-2.zip 2014-01-15 08:06 - 2014-01-15 08:06 - 00003710 _____ C:\Users\Daniel\Downloads\High Prefs and inis ugrids 5 V27 ENB version-36146-v27.rar 2014-01-15 07:58 - 2014-01-15 07:58 - 12881617 _____ C:\Users\Daniel\Downloads\RealVision_ENB_245a-30936-245a.7z 2014-01-15 07:58 - 2014-01-15 07:58 - 02342720 _____ C:\Users\Daniel\Downloads\enbseries_skyrim_v0245.zip 2014-01-15 07:54 - 2014-01-15 07:54 - 01457128 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - Weather Patch-39799-15.rar 2014-01-15 07:53 - 2014-01-15 07:53 - 00020795 _____ C:\Users\Daniel\Downloads\Supreme Storms for Climates of Tamriel 3_1-27022-3-1.rar 2014-01-15 07:50 - 2014-01-15 07:51 - 14741439 _____ C:\Users\Daniel\Downloads\RSE High v1_4-836.7z 2014-01-15 07:50 - 2014-01-15 07:50 - 00762191 _____ C:\Users\Daniel\Downloads\Dust Effects v1_0-44201-1-0.7z 2014-01-15 07:49 - 2014-01-15 07:49 - 17953454 _____ C:\Users\Daniel\Downloads\Rocking Stones Parallax for ENB - 2k BROWNISH - best one imo-38004-4-4.7z 2014-01-15 07:47 - 2014-01-15 07:47 - 16731899 _____ C:\Users\Daniel\Downloads\SkyFalls - Dragonborn Edition-40564-1-2.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 04175336 _____ C:\Users\Daniel\Downloads\HD Ivy - Original Green-30971-2-00.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 01405354 _____ C:\Users\Daniel\Downloads\SkyFalls - Animated Distant Waterfalls-40564-1-9.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 00006543 _____ C:\Users\Daniel\Downloads\SkyFalls - Dawnguard Edition-40564-1-1.rar 2014-01-15 07:45 - 2014-01-15 07:46 - 28948920 _____ C:\Users\Daniel\Downloads\TreesHD_Skyrim_variation_HIGH_NEW-3812-1-6.rar 2014-01-15 07:43 - 2014-01-15 07:44 - 29112106 _____ C:\Users\Daniel\Downloads\Dragonborn addon v02-141-v0-2.7z 2014-01-15 07:43 - 2014-01-15 07:43 - 01807096 _____ C:\Users\Daniel\Downloads\Natural Grass Texture Floor-30164-1-0.zip 2014-01-15 07:30 - 2014-01-15 07:37 - 145113682 _____ C:\Users\Daniel\Downloads\Summer Edition v181-141-v1-81.7z 2014-01-15 07:27 - 2014-01-15 07:29 - 26777790 _____ C:\Users\Daniel\Downloads\Detailed_Rugs_v1-3-29608-1-3.7z 2014-01-15 07:15 - 2014-01-15 07:24 - 144349763 _____ C:\Users\Daniel\Downloads\Hectrol CAVES DELUXE HighRes Retex 4K-29145-1-0.7z 2014-01-15 07:12 - 2014-01-15 07:13 - 04941702 _____ C:\Users\Daniel\Downloads\Cinematic Fire FX 2-2692-2-3.zip 2014-01-15 07:11 - 2014-01-15 07:24 - 18920661 _____ C:\Users\Daniel\Downloads\Ruins_Clutter_Improved_v2-6-14227-2-6.7z 2014-01-14 23:09 - 2014-01-14 23:09 - 05713023 _____ C:\Users\Daniel\Downloads\Unofficial Dragonborn Patch-31083-2-0-0.7z 2014-01-14 04:34 - 2014-01-14 04:35 - 09511604 _____ C:\Users\Daniel\Downloads\Footprints v0_99-22745-0-99.7z 2014-01-14 04:34 - 2014-01-14 04:34 - 08922372 _____ C:\Users\Daniel\Downloads\0_Pure Waters 4-6 Legendary-1111-4-6.rar 2014-01-14 04:27 - 2014-01-14 04:27 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (2).7z 2014-01-14 04:20 - 2014-01-14 04:21 - 09113460 _____ C:\Users\Daniel\Downloads\UNP BASE Main body V1dot2-6709.7z 2014-01-14 04:16 - 2014-01-14 04:17 - 02178105 _____ C:\Users\Daniel\Downloads\Sharpshooter enb classic version-15105-V1.rar 2014-01-14 04:15 - 2014-01-14 04:29 - 235701929 _____ C:\Users\Daniel\Downloads\UNP Mashup Compilation v1-20415-1.rar 2014-01-14 03:29 - 2014-01-14 03:30 - 23759325 _____ C:\Users\Daniel\Downloads\Better Vampires 6-5-9717-6-5.zip 2014-01-14 03:25 - 2014-01-14 03:25 - 00023554 _____ C:\Users\Daniel\Downloads\NEW Temptress Vampire Compatibility Update-18717-.rar 2014-01-14 03:14 - 2014-01-14 03:14 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (1).7z 2014-01-14 00:57 - 2014-01-14 00:57 - 00000617 _____ C:\Users\Daniel\Downloads\More Dragon Loot-10050-R4.rar 2014-01-14 00:55 - 2014-01-14 00:55 - 00001935 _____ C:\Users\Daniel\Downloads\Version 2_1-1010-2-1.zip 2014-01-14 00:47 - 2014-01-14 00:47 - 00001144 _____ C:\Users\Daniel\Downloads\More Arrows-11613-1-0.rar 2014-01-14 00:45 - 2014-01-14 00:46 - 20135641 _____ C:\Users\Daniel\Downloads\Enhanced Character Edit-12951-1-2.7z 2014-01-14 00:39 - 2014-01-14 00:39 - 04869331 _____ C:\Users\Daniel\Downloads\The Joy of Perspective Female V0 9 3 -6002-v0-9-3.rar 2014-01-14 00:35 - 2014-01-14 00:35 - 00322469 _____ C:\Users\Daniel\Downloads\Realistic Force-601-1-9.rar 2014-01-14 00:34 - 2014-01-14 00:34 - 00887469 _____ C:\Users\Daniel\Downloads\XPMS 1-92 NMM-BAIN INSTALLER-26800-1-92.7z 2014-01-14 00:31 - 2014-01-14 00:31 - 00083125 _____ C:\Users\Daniel\Downloads\The Dance of Death 4-0 Beta - Ultimate Edition-10906-4-0.7z 2014-01-14 00:26 - 2014-01-14 00:26 - 01025219 _____ C:\Users\Daniel\Downloads\UNP Bouncing Boobs-10470-1-0.rar 2014-01-14 00:21 - 2014-01-14 00:21 - 03496349 _____ C:\Users\Daniel\Downloads\360WalkRunPlus_v3_1_2-34508-3-1-2.7z 2014-01-14 00:11 - 2014-01-14 00:15 - 72977814 _____ C:\Users\Daniel\Downloads\Unofficial Skyrim Patch-19-2-0-0a.7z 2014-01-14 00:10 - 2014-01-14 00:11 - 29040935 _____ C:\Users\Daniel\Downloads\Immersive Sounds - Aural Assortment-49084-1-0.zip 2014-01-14 00:10 - 2014-01-14 00:10 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6 (1).zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6.zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00002452 _____ C:\Users\Daniel\Downloads\0 Dragonborn-Dawnguard Compatibility Patch-60-.rar 2014-01-14 00:02 - 2014-01-14 00:02 - 00266051 _____ C:\Users\Daniel\Downloads\skse_1_06_16_installer.exe 2014-01-14 00:02 - 2014-01-14 00:02 - 00000649 _____ C:\Users\Daniel\Desktop\Skyrim (SKSE).lnk 2014-01-14 00:01 - 2014-01-14 00:06 - 43448187 _____ C:\Users\Daniel\Downloads\Enhanced Blood Textures 3_5d-60-3-5d.rar 2014-01-13 23:59 - 2014-01-14 00:00 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929.7z 2014-01-13 23:54 - 2014-01-14 00:18 - 151736579 _____ C:\Users\Daniel\Downloads\IA v6 BETA 2-19733-6-BETA-2.7z 2014-01-13 23:53 - 2014-01-13 23:53 - 02978304 _____ C:\Users\Daniel\Downloads\Realistic Lighting Overhaul 4_0_8_01 NMM-BAINWizard Installer-30450-4-0-8-01.7z 2014-01-13 23:52 - 2014-01-13 23:52 - 07592804 _____ C:\Users\Daniel\Downloads\Wars_in_Skyrim_-_Normal_Mode-6176-1-4-1.7z 2014-01-13 23:38 - 2014-01-13 23:49 - 119244137 _____ C:\Users\Daniel\Downloads\Temptress Complete v1_3-18717-1-3.rar 2014-01-13 23:30 - 2014-01-13 23:42 - 151991017 _____ C:\Users\Daniel\Downloads\ApachiiSkyHair_v_1_5_Full-10168-1-5-Full.7z 2014-01-13 23:18 - 2014-01-13 23:19 - 11624802 _____ C:\Users\Daniel\Downloads\No_More_Blocky_Faces-1_50-30-1-5.7z 2014-01-13 23:12 - 2014-01-13 23:12 - 00000313 _____ C:\Users\Daniel\Downloads\Proper Aiming 1_1-13652-1-1.rar 2014-01-13 23:06 - 2014-01-13 23:06 - 00230939 _____ C:\Users\Daniel\Downloads\Version 1_82 Quick Fix-18480-1-82.rar 2014-01-13 23:03 - 2014-01-13 23:04 - 11252501 _____ C:\Users\Daniel\Downloads\Version 1_82 BSA-18480-1-82.rar 2014-01-13 22:59 - 2014-01-13 23:34 - 554674254 _____ C:\Users\Daniel\Downloads\SMIM v1-61-8655-1-61.7z 2014-01-13 22:51 - 2014-01-13 22:56 - 107551867 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - V3-1-17802-3-1.zip 2014-01-13 22:42 - 2014-01-14 23:08 - 00000000 ____D C:\Users\Daniel\Documents\Nexus Mod Manager 2014-01-13 22:42 - 2014-01-13 22:42 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-01-13 22:42 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Black_Tree_Gaming 2014-01-13 22:35 - 2014-01-13 22:37 - 04136616 _____ (Black Tree Gaming ) C:\Users\Daniel\Downloads\Nexus Mod Manager-0.46.0.exe 2014-01-13 22:32 - 2014-01-13 22:32 - 01409134 _____ C:\Users\Daniel\Downloads\SkyUI_4_1-3863-4-1.7z 2014-01-13 22:29 - 2014-01-13 22:34 - 85038708 _____ C:\Users\Daniel\Downloads\Noiral_CBBE_Reloaded.zip 2014-01-13 20:02 - 2014-01-14 23:08 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2014-01-11 10:20 - 1997-03-24 17:42 - 00314368 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe 2014-01-11 10:13 - 2014-01-11 10:14 - 07679554 _____ C:\Users\Daniel\Downloads\netxray.zip 2014-01-11 09:53 - 2014-01-11 09:53 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Hex-Rays 2014-01-11 09:51 - 2014-01-11 09:52 - 16374114 _____ (Hex-Rays SA ) C:\Users\Daniel\Downloads\idafree50.exe 2014-01-11 09:51 - 2014-01-11 09:52 - 01385454 _____ C:\Users\Daniel\Downloads\idastealth_complete.rar 2014-01-11 09:45 - 2014-01-11 09:45 - 00545804 _____ C:\Users\Daniel\Downloads\fdbg0024.zip 2014-01-11 09:41 - 2014-01-11 09:42 - 06965278 _____ C:\Users\Daniel\Downloads\odbg201.zip 2014-01-11 09:14 - 2014-01-11 09:14 - 01935900 _____ C:\Users\Daniel\Downloads\OneHitKill.rar 2014-01-11 09:13 - 2014-01-11 09:13 - 01646243 _____ C:\Users\Daniel\Downloads\tsearch16b.rar 2014-01-11 09:09 - 2014-01-11 10:04 - 00000319 _____ C:\Windows\WPE PRO - modified.INI 2014-01-11 07:38 - 2014-01-11 07:38 - 00000607 _____ C:\Users\Daniel\Desktop\Cheat Engine.lnk 2014-01-11 07:34 - 2014-01-11 07:35 - 08065840 _____ (Cheat Engine ) C:\Users\Daniel\Downloads\CheatEngine63.exe 2014-01-10 20:56 - 2014-01-12 20:44 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Awesomium 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\Users\Daniel\Documents\Elder Scrolls Online 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\ProgramData\Elder Scrolls Online 2014-01-09 15:58 - 2014-01-09 15:58 - 00414569 _____ C:\Users\Daniel\Downloads\Raf Manager.zip 2014-01-08 06:59 - 2014-01-08 06:59 - 02653910 _____ C:\Users\Daniel\Downloads\9221.zip 2014-01-08 06:54 - 2014-01-08 06:55 - 24309760 _____ C:\Users\Daniel\Downloads\LauncherSetup.msi 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Local\SkinSoft 2014-01-07 18:43 - 2014-01-07 18:49 - 17584706 _____ C:\Users\Daniel\Downloads\CryptoObfuscator.Enterprise.2012.R2.Build.130111.rar 2014-01-07 17:59 - 2014-01-10 16:20 - 00000423 _____ C:\Users\Daniel\Desktop\TESO stresstest.txt 2014-01-06 23:38 - 2014-01-06 23:38 - 00033323 _____ C:\Users\Daniel\Downloads\Prodiction.lua 2014-01-06 21:24 - 2014-01-06 21:24 - 01310829 _____ C:\Users\Daniel\Downloads\19913.zip 2014-01-06 21:24 - 2014-01-06 21:24 - 01304629 _____ C:\Users\Daniel\Downloads\6471.zip 2014-01-06 21:20 - 2014-01-06 21:21 - 01016952 _____ C:\Users\Daniel\Downloads\25273.zip 2014-01-06 20:41 - 2014-01-02 14:42 - 00025203 _____ C:\xPRiiME.properties 2014-01-06 18:16 - 2014-01-06 18:16 - 00001521 _____ C:\Users\Daniel\Downloads\UBot_Studio_Xing_Bot.ubot 2014-01-06 17:42 - 2014-01-06 17:42 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5 (1).zip 2014-01-06 17:20 - 2014-01-06 17:20 - 00026395 _____ C:\Users\Daniel\Downloads\OpenPOP.zip 2014-01-06 17:05 - 2014-01-06 17:05 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5.zip 2014-01-06 16:57 - 2014-01-06 16:57 - 00027152 _____ C:\Users\Daniel\Downloads\ReadPop3EmailsASP.Net.zip 2014-01-06 16:14 - 2014-01-06 16:16 - 00000000 ____D C:\Users\Daniel\Documents\sliqemailconfirmerlite 2014-01-06 16:06 - 2014-01-06 16:06 - 00003165 _____ C:\Users\Daniel\Desktop\SliQ Link Clicker Lite.lnk 2014-01-06 16:06 - 2014-01-06 16:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SliQTools 2014-01-06 16:03 - 2014-01-06 16:03 - 06043285 _____ (SliQTools ) C:\Users\Daniel\Downloads\sliqlinkclickerlite.exe 2014-01-06 02:01 - 2014-01-06 03:23 - 00010363 _____ C:\Users\Daniel\Documents\Emails.txt 2014-01-03 23:54 - 2014-01-03 23:54 - 00042184 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys 2014-01-03 22:52 - 2014-01-03 22:52 - 00008657 _____ C:\Users\Daniel\Downloads\DownloadSVN13.zip 2014-01-03 21:30 - 2014-01-03 21:30 - 00186054 _____ C:\Users\Daniel\Downloads\FsbExtractor13.07.23.rar 2014-01-03 21:17 - 2014-01-03 21:18 - 26578452 _____ C:\Users\Daniel\Downloads\Unreal Tournament Announcer Mod (LoL) V. 2.1.0.7.zip 2014-01-03 17:16 - 2014-01-03 17:16 - 00001172 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-01-03 17:16 - 2014-01-03 17:16 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-02 21:03 - 2014-01-02 21:03 - 01530695 _____ C:\Users\Daniel\Downloads\861.zip 2014-01-02 20:41 - 2014-01-02 20:41 - 00197483 _____ C:\Users\Daniel\Downloads\gimp-dds-win64-3.0.1.zip 2014-01-02 20:34 - 2014-01-02 20:34 - 00253076 _____ C:\Users\Daniel\Downloads\2093 (1).zip 2014-01-02 12:14 - 2014-01-02 12:16 - 33901910 _____ C:\Users\Daniel\Downloads\fmoddesigner44427win-installer.exe 2014-01-02 12:00 - 2014-01-02 12:00 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext (1).zip 2014-01-02 11:30 - 2014-01-02 11:30 - 02785220 _____ C:\Users\Daniel\Downloads\2622.zip 2014-01-02 10:28 - 2014-01-02 10:28 - 00272516 _____ C:\Users\Daniel\Downloads\yaybatch.zip 2014-01-02 10:22 - 2014-01-02 10:22 - 01923290 _____ C:\Users\Daniel\Downloads\cdex_151.zip 2014-01-02 09:14 - 2014-01-02 09:15 - 05015064 _____ C:\Users\Daniel\Downloads\MusicPlayerEx-Full-02-04-2013.7z 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32.zip 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32 (1).zip 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-01-02 07:05 - 2014-01-02 07:06 - 07598942 _____ C:\Users\Daniel\Downloads\npp.6.5.3.Installer.exe 2014-01-02 06:26 - 2014-01-02 06:27 - 06709836 _____ C:\Users\Daniel\Downloads\SIU 3.335-Lite.zip 2014-01-02 03:15 - 2014-01-02 03:17 - 53464955 _____ C:\Users\Daniel\Downloads\wintermint.rar 2014-01-02 01:35 - 2014-01-16 18:11 - 00000000 ____D C:\Users\Daniel\Documents\LOLReplay 2014-01-02 01:35 - 2014-01-02 01:35 - 01472106 _____ C:\Users\Daniel\Downloads\LOLReplay-0.8.5.2.exe 2014-01-02 01:35 - 2014-01-02 01:35 - 00000611 _____ C:\Users\Public\Desktop\LOL Recorder.lnk 2013-12-31 18:21 - 2014-01-29 11:37 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-12-31 06:52 - 2013-12-31 06:52 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00002076 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\ProgramData\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\Program Files (x86)\Avira 2013-12-31 06:51 - 2013-12-09 11:37 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-12-31 06:41 - 2013-12-31 06:48 - 129598176 _____ C:\Users\Daniel\Downloads\avira_free_antivirus_de.exe 2013-12-31 05:53 - 2013-12-31 05:54 - 03030680 _____ (Softbyte Labs, Inc. ) C:\Users\Daniel\Downloads\BlackWidow_Setup.exe 2013-12-31 05:46 - 2013-12-31 05:47 - 00253076 _____ C:\Users\Daniel\Downloads\2093.zip 2013-12-31 05:13 - 2013-12-31 05:13 - 00860736 _____ C:\Users\Daniel\Downloads\hexedit602.zip 2013-12-31 05:01 - 2013-12-31 05:01 - 00253442 _____ C:\Users\Daniel\Downloads\1209303036_datexpl.rar 2013-12-31 04:58 - 2013-12-31 04:58 - 00018023 _____ C:\Users\Daniel\Downloads\FTL UnPacker 1.0.1.zip 2013-12-31 04:53 - 2013-12-31 04:54 - 11147144 _____ (Adobe Systems, Inc.) C:\Users\Daniel\Downloads\flashplayer_11_sa_debug.exe 2013-12-31 04:52 - 2013-12-31 04:53 - 02179506 _____ (StandaloneFlashPlayer.com ) C:\Users\Daniel\Downloads\standaloneflashplayer_setup.exe 2013-12-31 02:32 - 2013-12-31 02:32 - 10807547 _____ C:\Users\Daniel\Downloads\fmodsandbox43505win-installer.exe 2013-12-31 02:16 - 2014-01-02 12:11 - 00000000 ____D C:\Users\Daniel\AppData\Local\FMOD Studio 2013-12-31 02:09 - 2013-12-31 02:14 - 79700009 _____ C:\Users\Daniel\Downloads\fmodstudio10211win-installer.exe 2013-12-31 02:09 - 2013-12-31 02:09 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext.zip 2013-12-30 21:36 - 2014-01-26 19:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Wireshark 2013-12-30 21:28 - 2013-12-30 21:28 - 00000000 ____D C:\Program Files (x86)\WinPcap 2013-12-30 21:08 - 2013-12-30 21:10 - 27981224 _____ (Wireshark development team) C:\Users\Daniel\Downloads\Wireshark-win64-1.10.5.exe ==================== One Month Modified Files and Folders ======= 2014-01-29 11:42 - 2014-01-29 11:42 - 00000000 ____D C:\Users\Daniel\Downloads\FRST-OlderVersion 2014-01-29 11:42 - 2014-01-27 00:50 - 00015087 _____ C:\Users\Daniel\Downloads\FRST.txt 2014-01-29 11:42 - 2014-01-27 00:50 - 00000000 ____D C:\FRST 2014-01-29 11:42 - 2014-01-27 00:49 - 02079744 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe 2014-01-29 11:39 - 2014-01-29 11:39 - 00002056 _____ C:\Users\Daniel\Desktop\JRT.txt 2014-01-29 11:37 - 2013-12-31 18:21 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2014-01-29 11:37 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-29 11:37 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-29 11:33 - 2013-10-19 15:12 - 01162256 _____ C:\Windows\WindowsUpdate.log 2014-01-29 11:31 - 2014-01-29 11:31 - 01037068 _____ (Thisisu) C:\Users\Daniel\Downloads\JRT.exe 2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\ERUNT 2014-01-29 11:30 - 2013-10-20 07:28 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype 2014-01-29 11:30 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\inetsrv 2014-01-29 11:28 - 2014-01-28 07:29 - 00000280 _____ C:\Windows\setupact.log 2014-01-29 11:28 - 2013-10-20 09:40 - 00000000 ____D C:\Users\Daniel\AppData\Local\HTC MediaHub 2014-01-29 11:28 - 2013-10-19 15:56 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-29 11:28 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-29 11:28 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-29 11:26 - 2014-01-29 11:25 - 00000000 ____D C:\AdwCleaner 2014-01-29 11:25 - 2014-01-29 11:25 - 01166132 _____ C:\Users\Daniel\Downloads\adwcleaner.exe 2014-01-29 11:20 - 2014-01-28 17:44 - 00006154 _____ C:\Windows\PFRO.log 2014-01-29 11:11 - 2013-10-19 15:56 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-29 11:10 - 2014-01-29 11:10 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2014-01-29 11:09 - 2014-01-29 11:09 - 00001119 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-29 11:09 - 2014-01-29 11:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-29 11:08 - 2014-01-29 11:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Daniel\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-29 08:07 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2014-01-29 08:03 - 2013-10-28 00:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2014-01-29 08:03 - 2009-07-14 05:45 - 04920336 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-28 18:17 - 2013-10-19 15:58 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-28 17:59 - 2013-10-19 23:10 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Adobe 2014-01-28 17:59 - 2013-10-19 15:55 - 00064408 _____ C:\Users\Daniel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-28 17:56 - 2014-01-28 17:56 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2014-01-28 17:56 - 2014-01-28 17:53 - 00000000 ____D C:\Program Files\Common Files\Adobe 2014-01-28 17:56 - 2013-10-31 14:32 - 00000000 ____D C:\ProgramData\Adobe 2014-01-28 17:54 - 2013-10-31 14:32 - 00000000 ____D C:\Program Files (x86)\Adobe 2014-01-28 17:49 - 2014-01-28 17:49 - 00102932 ____H C:\Windows\SysWOW64\mlfcache.dat 2014-01-28 17:42 - 2014-01-28 03:34 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\FileZilla 2014-01-28 17:42 - 2011-04-12 08:43 - 00793392 _____ C:\Windows\system32\perfh007.dat 2014-01-28 17:42 - 2011-04-12 08:43 - 00183854 _____ C:\Windows\system32\perfc007.dat 2014-01-28 17:42 - 2009-07-14 06:13 - 01859440 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-28 17:29 - 2014-01-27 22:02 - 00000000 ____D C:\Users\Daniel\Desktop\mbar 2014-01-28 17:16 - 2014-01-27 22:02 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-28 17:14 - 2014-01-28 16:24 - 00000000 ____D C:\Qoobox 2014-01-28 17:14 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-28 17:13 - 2014-01-28 17:13 - 00026718 _____ C:\ComboFix.txt 2014-01-28 17:07 - 2014-01-28 16:23 - 00000000 ____D C:\Windows\erdnt 2014-01-28 16:45 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-28 16:23 - 2014-01-28 16:23 - 05175619 ____R (Swearware) C:\Users\Daniel\Downloads\ComboFix.exe 2014-01-28 14:42 - 2014-01-28 14:37 - 00169060 _____ C:\Users\Daniel\Documents\lordangelomails1.txt 2014-01-28 14:14 - 2013-10-19 17:09 - 00000000 ____D C:\Users\Daniel\Documents\Visual Studio 2012 2014-01-28 14:07 - 2014-01-28 14:01 - 17584706 _____ C:\Users\Daniel\Downloads\CryptoObfuscator.Enterprise.2012.R2.Build.130111 (1).rar 2014-01-28 13:57 - 2014-01-28 13:57 - 00930440 _____ (CNET Download.com) C:\Users\Daniel\Downloads\cbsidlm-cbsi176-Crypto_Obfuscator_For_Net-ORG-10968597.exe 2014-01-28 13:24 - 2014-01-28 13:24 - 00000000 ____D C:\Users\Daniel\AppData\Local\Cosa_Nostra 2014-01-28 13:23 - 2014-01-28 13:22 - 00134947 _____ C:\Users\Daniel\Downloads\RgxTester10Exe.zip 2014-01-28 12:04 - 2014-01-28 12:04 - 00880069 _____ C:\Users\Daniel\Downloads\Reteewt v1.2.rar 2014-01-28 12:04 - 2014-01-28 12:04 - 00000000 ____D C:\Users\Daniel\Desktop\asdad 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Battle.net 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Blizzard Entertainment 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Battle.net 2014-01-28 11:58 - 2014-01-28 11:58 - 00000788 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-28 11:58 - 2014-01-28 11:58 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2014-01-28 11:55 - 2014-01-28 11:55 - 00000000 ____D C:\ProgramData\Battle.net 2014-01-28 11:54 - 2014-01-28 11:54 - 05748920 _____ (Blizzard Entertainment) C:\Users\Daniel\Downloads\Battle.net-Beta-Setup-deDE.exe 2014-01-28 10:39 - 2014-01-27 23:01 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\QuickScan 2014-01-28 10:04 - 2014-01-28 05:57 - 00000000 ____D C:\Users\Daniel\Documents\botman 2014-01-28 07:29 - 2014-01-28 07:29 - 00000000 _____ C:\Windows\setuperr.log 2014-01-28 05:19 - 2014-01-28 05:19 - 00003901 _____ C:\Users\Daniel\Downloads\smime.p7s 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Program Files (x86)\MySQL 2014-01-28 04:27 - 2013-10-19 16:26 - 01886128 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-28 04:26 - 2014-01-28 04:26 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6 (1).zip 2014-01-28 04:22 - 2014-01-28 04:22 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6.zip 2014-01-28 03:29 - 2014-01-28 03:29 - 07241860 _____ C:\Users\Daniel\Downloads\FileZilla_3.7.3_win32.zip 2014-01-28 01:38 - 2014-01-28 01:38 - 00073065 _____ C:\Users\Daniel\Downloads\FancyAsFuckToasty.zip 2014-01-28 01:38 - 2013-11-20 01:46 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2014-01-27 23:46 - 2013-10-19 18:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Spotify 2014-01-27 23:24 - 2014-01-27 23:24 - 00000000 ____D C:\Windows\pss 2014-01-27 23:24 - 2014-01-27 23:09 - 00002748 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-27 23:21 - 2013-12-03 16:05 - 00000000 ____D C:\Program Files\GIMP 2 2014-01-27 23:15 - 2013-11-27 01:02 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TS3Client 2014-01-27 23:15 - 2013-11-15 19:18 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DAEMON Tools Lite 2014-01-27 23:15 - 2013-10-19 16:09 - 00000000 ____D C:\Windows\Panther 2014-01-27 23:09 - 2014-01-27 23:09 - 00000568 _____ C:\Users\Daniel\Desktop\CCleaner.lnk 2014-01-27 23:09 - 2014-01-27 23:09 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-01-27 23:08 - 2014-01-27 23:08 - 04721920 _____ (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup410.exe 2014-01-27 23:07 - 2014-01-27 23:07 - 02347384 _____ (ESET) C:\Users\Daniel\Downloads\esetsmartinstaller_enu.exe 2014-01-27 23:07 - 2014-01-27 23:07 - 00000000 ____D C:\Program Files (x86)\ESET 2014-01-27 22:34 - 2013-11-27 17:07 - 00000000 ____D C:\Users\Daniel\AppData\Local\Purplizer 2014-01-27 22:34 - 2013-11-27 00:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Overwolf 2014-01-27 22:28 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\addins 2014-01-27 22:03 - 2014-01-27 22:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-27 22:02 - 2014-01-27 22:02 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Daniel\Downloads\mbar-1.07.0.1009.exe 2014-01-27 00:54 - 2014-01-27 00:54 - 00033821 _____ C:\Users\Daniel\Downloads\Addition.txt 2014-01-26 19:38 - 2014-01-26 19:38 - 01104710 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE.zip 2014-01-26 19:26 - 2014-01-26 19:26 - 00000005 _____ C:\Users\Daniel\Downloads\Download 2014-01-26 19:06 - 2013-12-30 21:36 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Wireshark 2014-01-26 18:57 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\JetBrains 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\SymbolSourceSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\RefSrcSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\JetBrains 2014-01-26 18:53 - 2014-01-26 18:51 - 29220864 _____ C:\Users\Daniel\Downloads\dotPeekSetup-1.1.1.33.msi 2014-01-26 18:38 - 2014-01-26 18:38 - 00157234 _____ C:\Users\Daniel\Downloads\RouterReconnect_1.3.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 04689382 _____ C:\Users\Daniel\Downloads\curl-7.34.0.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 00094335 _____ C:\Users\Daniel\Downloads\Fritz!Box Reconnect.rar 2014-01-26 17:50 - 2014-01-26 17:50 - 00001154 _____ C:\Users\Daniel\Documents\absolutechamp.txt 2014-01-26 16:49 - 2014-01-26 16:36 - 00000000 ____D C:\Users\Daniel\Documents\Rezepte 2014-01-23 09:51 - 2014-01-23 09:50 - 12322963 _____ C:\Users\Daniel\Downloads\Thread_Design_2.zip 2014-01-23 09:41 - 2014-01-23 09:41 - 01398825 _____ C:\Users\Daniel\Downloads\wg_3d_banners_vol3.zip 2014-01-23 09:38 - 2014-01-23 09:38 - 42713738 _____ C:\Users\Daniel\Downloads\Devisual's Graphics Pack.rar 2014-01-23 07:39 - 2013-12-19 13:51 - 00000107 _____ C:\Users\Daniel\AppData\Roaming\WB.CFG 2014-01-22 14:32 - 2014-01-22 14:31 - 00000000 ____D C:\Users\Daniel\Desktop\Lobby checker 2014-01-21 08:14 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\TubeBox 2014-01-20 16:37 - 2013-10-19 18:53 - 00000000 ____D C:\Users\Daniel\AppData\Local\Spotify 2014-01-17 12:16 - 2014-01-17 12:16 - 00092309 _____ C:\Users\Daniel\Downloads\MarkC_Windows_8.x+7_MouseFix.zip 2014-01-16 18:11 - 2014-01-02 01:35 - 00000000 ____D C:\Users\Daniel\Documents\LOLReplay 2014-01-15 15:47 - 2014-01-15 15:47 - 00000749 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-15 15:46 - 2014-01-15 15:46 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 15:45 - 2013-10-31 11:23 - 00000000 ____D C:\ProgramData\Origin 2014-01-15 15:38 - 2014-01-15 15:36 - 08501736 _____ C:\Users\Daniel\Downloads\HSS-3.31-install-e-550-plain.exe 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2014-01-15 15:22 - 2014-01-15 15:22 - 00000530 _____ C:\Users\Public\Desktop\Origin.lnk 2014-01-15 15:21 - 2014-01-15 15:20 - 16952720 _____ (Electronic Arts, Inc.) C:\Users\Daniel\Downloads\OriginThinSetup.exe 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\EA Core 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Users\Daniel\AppData\Local\ESN 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2014-01-15 15:11 - 2014-01-15 15:11 - 03821064 _____ C:\Users\Daniel\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00012885 _____ C:\Users\Daniel\AppData\Local\recently-used.xbel 2014-01-15 14:04 - 2013-12-03 16:06 - 00000000 ____D C:\Users\Daniel\.gimp-2.8 2014-01-15 11:38 - 2014-01-15 11:38 - 01016952 _____ C:\Users\Daniel\Downloads\25273 (1).zip 2014-01-15 09:23 - 2014-01-15 09:23 - 00004705 _____ C:\Users\Daniel\Downloads\First Person Camera Fix-6508-1.7z 2014-01-15 08:46 - 2014-01-15 08:46 - 00060838 _____ C:\Users\Daniel\Downloads\SafetyLoad 1_2-46465-1-2.zip 2014-01-15 08:06 - 2014-01-15 08:06 - 00003710 _____ C:\Users\Daniel\Downloads\High Prefs and inis ugrids 5 V27 ENB version-36146-v27.rar 2014-01-15 07:58 - 2014-01-15 07:58 - 12881617 _____ C:\Users\Daniel\Downloads\RealVision_ENB_245a-30936-245a.7z 2014-01-15 07:58 - 2014-01-15 07:58 - 02342720 _____ C:\Users\Daniel\Downloads\enbseries_skyrim_v0245.zip 2014-01-15 07:54 - 2014-01-15 07:54 - 01457128 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - Weather Patch-39799-15.rar 2014-01-15 07:53 - 2014-01-15 07:53 - 00020795 _____ C:\Users\Daniel\Downloads\Supreme Storms for Climates of Tamriel 3_1-27022-3-1.rar 2014-01-15 07:51 - 2014-01-15 07:50 - 14741439 _____ C:\Users\Daniel\Downloads\RSE High v1_4-836.7z 2014-01-15 07:50 - 2014-01-15 07:50 - 00762191 _____ C:\Users\Daniel\Downloads\Dust Effects v1_0-44201-1-0.7z 2014-01-15 07:49 - 2014-01-15 07:49 - 17953454 _____ C:\Users\Daniel\Downloads\Rocking Stones Parallax for ENB - 2k BROWNISH - best one imo-38004-4-4.7z 2014-01-15 07:47 - 2014-01-15 07:47 - 16731899 _____ C:\Users\Daniel\Downloads\SkyFalls - Dragonborn Edition-40564-1-2.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 04175336 _____ C:\Users\Daniel\Downloads\HD Ivy - Original Green-30971-2-00.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 01405354 _____ C:\Users\Daniel\Downloads\SkyFalls - Animated Distant Waterfalls-40564-1-9.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 00006543 _____ C:\Users\Daniel\Downloads\SkyFalls - Dawnguard Edition-40564-1-1.rar 2014-01-15 07:46 - 2014-01-15 07:45 - 28948920 _____ C:\Users\Daniel\Downloads\TreesHD_Skyrim_variation_HIGH_NEW-3812-1-6.rar 2014-01-15 07:44 - 2014-01-15 07:43 - 29112106 _____ C:\Users\Daniel\Downloads\Dragonborn addon v02-141-v0-2.7z 2014-01-15 07:43 - 2014-01-15 07:43 - 01807096 _____ C:\Users\Daniel\Downloads\Natural Grass Texture Floor-30164-1-0.zip 2014-01-15 07:37 - 2014-01-15 07:30 - 145113682 _____ C:\Users\Daniel\Downloads\Summer Edition v181-141-v1-81.7z 2014-01-15 07:29 - 2014-01-15 07:27 - 26777790 _____ C:\Users\Daniel\Downloads\Detailed_Rugs_v1-3-29608-1-3.7z 2014-01-15 07:24 - 2014-01-15 07:15 - 144349763 _____ C:\Users\Daniel\Downloads\Hectrol CAVES DELUXE HighRes Retex 4K-29145-1-0.7z 2014-01-15 07:24 - 2014-01-15 07:11 - 18920661 _____ C:\Users\Daniel\Downloads\Ruins_Clutter_Improved_v2-6-14227-2-6.7z 2014-01-15 07:13 - 2014-01-15 07:12 - 04941702 _____ C:\Users\Daniel\Downloads\Cinematic Fire FX 2-2692-2-3.zip 2014-01-14 23:09 - 2014-01-14 23:09 - 05713023 _____ C:\Users\Daniel\Downloads\Unofficial Dragonborn Patch-31083-2-0-0.7z 2014-01-14 23:08 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\Documents\Nexus Mod Manager 2014-01-14 23:08 - 2014-01-13 20:02 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2014-01-14 04:35 - 2014-01-14 04:34 - 09511604 _____ C:\Users\Daniel\Downloads\Footprints v0_99-22745-0-99.7z 2014-01-14 04:34 - 2014-01-14 04:34 - 08922372 _____ C:\Users\Daniel\Downloads\0_Pure Waters 4-6 Legendary-1111-4-6.rar 2014-01-14 04:29 - 2014-01-14 04:15 - 235701929 _____ C:\Users\Daniel\Downloads\UNP Mashup Compilation v1-20415-1.rar 2014-01-14 04:27 - 2014-01-14 04:27 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (2).7z 2014-01-14 04:21 - 2014-01-14 04:20 - 09113460 _____ C:\Users\Daniel\Downloads\UNP BASE Main body V1dot2-6709.7z 2014-01-14 04:17 - 2014-01-14 04:16 - 02178105 _____ C:\Users\Daniel\Downloads\Sharpshooter enb classic version-15105-V1.rar 2014-01-14 03:30 - 2014-01-14 03:29 - 23759325 _____ C:\Users\Daniel\Downloads\Better Vampires 6-5-9717-6-5.zip 2014-01-14 03:25 - 2014-01-14 03:25 - 00023554 _____ C:\Users\Daniel\Downloads\NEW Temptress Vampire Compatibility Update-18717-.rar 2014-01-14 03:14 - 2014-01-14 03:14 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (1).7z 2014-01-14 00:57 - 2014-01-14 00:57 - 00000617 _____ C:\Users\Daniel\Downloads\More Dragon Loot-10050-R4.rar 2014-01-14 00:55 - 2014-01-14 00:55 - 00001935 _____ C:\Users\Daniel\Downloads\Version 2_1-1010-2-1.zip 2014-01-14 00:47 - 2014-01-14 00:47 - 00001144 _____ C:\Users\Daniel\Downloads\More Arrows-11613-1-0.rar 2014-01-14 00:46 - 2014-01-14 00:45 - 20135641 _____ C:\Users\Daniel\Downloads\Enhanced Character Edit-12951-1-2.7z 2014-01-14 00:39 - 2014-01-14 00:39 - 04869331 _____ C:\Users\Daniel\Downloads\The Joy of Perspective Female V0 9 3 -6002-v0-9-3.rar 2014-01-14 00:35 - 2014-01-14 00:35 - 00322469 _____ C:\Users\Daniel\Downloads\Realistic Force-601-1-9.rar 2014-01-14 00:34 - 2014-01-14 00:34 - 00887469 _____ C:\Users\Daniel\Downloads\XPMS 1-92 NMM-BAIN INSTALLER-26800-1-92.7z 2014-01-14 00:31 - 2014-01-14 00:31 - 00083125 _____ C:\Users\Daniel\Downloads\The Dance of Death 4-0 Beta - Ultimate Edition-10906-4-0.7z 2014-01-14 00:26 - 2014-01-14 00:26 - 01025219 _____ C:\Users\Daniel\Downloads\UNP Bouncing Boobs-10470-1-0.rar 2014-01-14 00:21 - 2014-01-14 00:21 - 03496349 _____ C:\Users\Daniel\Downloads\360WalkRunPlus_v3_1_2-34508-3-1-2.7z 2014-01-14 00:18 - 2014-01-13 23:54 - 151736579 _____ C:\Users\Daniel\Downloads\IA v6 BETA 2-19733-6-BETA-2.7z 2014-01-14 00:15 - 2014-01-14 00:11 - 72977814 _____ C:\Users\Daniel\Downloads\Unofficial Skyrim Patch-19-2-0-0a.7z 2014-01-14 00:11 - 2014-01-14 00:10 - 29040935 _____ C:\Users\Daniel\Downloads\Immersive Sounds - Aural Assortment-49084-1-0.zip 2014-01-14 00:10 - 2014-01-14 00:10 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6 (1).zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6.zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00002452 _____ C:\Users\Daniel\Downloads\0 Dragonborn-Dawnguard Compatibility Patch-60-.rar 2014-01-14 00:06 - 2014-01-14 00:01 - 43448187 _____ C:\Users\Daniel\Downloads\Enhanced Blood Textures 3_5d-60-3-5d.rar 2014-01-14 00:02 - 2014-01-14 00:02 - 00266051 _____ C:\Users\Daniel\Downloads\skse_1_06_16_installer.exe 2014-01-14 00:02 - 2014-01-14 00:02 - 00000649 _____ C:\Users\Daniel\Desktop\Skyrim (SKSE).lnk 2014-01-14 00:00 - 2014-01-13 23:59 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929.7z 2014-01-13 23:53 - 2014-01-13 23:53 - 02978304 _____ C:\Users\Daniel\Downloads\Realistic Lighting Overhaul 4_0_8_01 NMM-BAINWizard Installer-30450-4-0-8-01.7z 2014-01-13 23:52 - 2014-01-13 23:52 - 07592804 _____ C:\Users\Daniel\Downloads\Wars_in_Skyrim_-_Normal_Mode-6176-1-4-1.7z 2014-01-13 23:49 - 2014-01-13 23:38 - 119244137 _____ C:\Users\Daniel\Downloads\Temptress Complete v1_3-18717-1-3.rar 2014-01-13 23:42 - 2014-01-13 23:30 - 151991017 _____ C:\Users\Daniel\Downloads\ApachiiSkyHair_v_1_5_Full-10168-1-5-Full.7z 2014-01-13 23:34 - 2014-01-13 22:59 - 554674254 _____ C:\Users\Daniel\Downloads\SMIM v1-61-8655-1-61.7z 2014-01-13 23:19 - 2014-01-13 23:18 - 11624802 _____ C:\Users\Daniel\Downloads\No_More_Blocky_Faces-1_50-30-1-5.7z 2014-01-13 23:12 - 2014-01-13 23:12 - 00000313 _____ C:\Users\Daniel\Downloads\Proper Aiming 1_1-13652-1-1.rar 2014-01-13 23:06 - 2014-01-13 23:06 - 00230939 _____ C:\Users\Daniel\Downloads\Version 1_82 Quick Fix-18480-1-82.rar 2014-01-13 23:04 - 2014-01-13 23:03 - 11252501 _____ C:\Users\Daniel\Downloads\Version 1_82 BSA-18480-1-82.rar 2014-01-13 22:56 - 2014-01-13 22:51 - 107551867 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - V3-1-17802-3-1.zip 2014-01-13 22:42 - 2014-01-13 22:42 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-01-13 22:42 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Black_Tree_Gaming 2014-01-13 22:37 - 2014-01-13 22:35 - 04136616 _____ (Black Tree Gaming ) C:\Users\Daniel\Downloads\Nexus Mod Manager-0.46.0.exe 2014-01-13 22:34 - 2014-01-13 22:29 - 85038708 _____ C:\Users\Daniel\Downloads\Noiral_CBBE_Reloaded.zip 2014-01-13 22:32 - 2014-01-13 22:32 - 01409134 _____ C:\Users\Daniel\Downloads\SkyUI_4_1-3863-4-1.7z 2014-01-13 20:02 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\My Games 2014-01-12 20:44 - 2014-01-10 20:56 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Awesomium 2014-01-12 00:42 - 2014-01-02 06:35 - 00000000 ____D C:\Users\Daniel\Desktop\LoL Modding 2014-01-11 10:14 - 2014-01-11 10:13 - 07679554 _____ C:\Users\Daniel\Downloads\netxray.zip 2014-01-11 10:04 - 2014-01-11 09:09 - 00000319 _____ C:\Windows\WPE PRO - modified.INI 2014-01-11 09:53 - 2014-01-11 09:53 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Hex-Rays 2014-01-11 09:52 - 2014-01-11 09:51 - 16374114 _____ (Hex-Rays SA ) C:\Users\Daniel\Downloads\idafree50.exe 2014-01-11 09:52 - 2014-01-11 09:51 - 01385454 _____ C:\Users\Daniel\Downloads\idastealth_complete.rar 2014-01-11 09:45 - 2014-01-11 09:45 - 00545804 _____ C:\Users\Daniel\Downloads\fdbg0024.zip 2014-01-11 09:42 - 2014-01-11 09:41 - 06965278 _____ C:\Users\Daniel\Downloads\odbg201.zip 2014-01-11 09:14 - 2014-01-11 09:14 - 01935900 _____ C:\Users\Daniel\Downloads\OneHitKill.rar 2014-01-11 09:13 - 2014-01-11 09:13 - 01646243 _____ C:\Users\Daniel\Downloads\tsearch16b.rar 2014-01-11 09:08 - 2013-10-19 15:23 - 00000000 ____D C:\Users\Daniel\AppData\Local\VirtualStore 2014-01-11 07:45 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\My Cheat Tables 2014-01-11 07:38 - 2014-01-11 07:38 - 00000607 _____ C:\Users\Daniel\Desktop\Cheat Engine.lnk 2014-01-11 07:35 - 2014-01-11 07:34 - 08065840 _____ (Cheat Engine ) C:\Users\Daniel\Downloads\CheatEngine63.exe 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\Users\Daniel\Documents\Elder Scrolls Online 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\ProgramData\Elder Scrolls Online 2014-01-08 06:59 - 2014-01-08 06:59 - 02653910 _____ C:\Users\Daniel\Downloads\9221.zip 2014-01-08 06:55 - 2014-01-08 06:54 - 24309760 _____ C:\Users\Daniel\Downloads\LauncherSetup.msi 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Crypto Obfuscator For .Net v2012 R2 2014-01-07 19:03 - 2014-01-07 19:03 - 00000000 ____D C:\Users\Daniel\AppData\Local\SkinSoft 2014-01-07 18:49 - 2014-01-07 18:43 - 17584706 _____ C:\Users\Daniel\Downloads\CryptoObfuscator.Enterprise.2012.R2.Build.130111.rar 2014-01-07 18:48 - 2013-10-20 09:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Apple Computer 2014-01-06 23:38 - 2014-01-06 23:38 - 00033323 _____ C:\Users\Daniel\Downloads\Prodiction.lua 2014-01-06 21:24 - 2014-01-06 21:24 - 01310829 _____ C:\Users\Daniel\Downloads\19913.zip 2014-01-06 21:24 - 2014-01-06 21:24 - 01304629 _____ C:\Users\Daniel\Downloads\6471.zip 2014-01-06 21:21 - 2014-01-06 21:20 - 01016952 _____ C:\Users\Daniel\Downloads\25273.zip 2014-01-06 18:16 - 2014-01-06 18:16 - 00001521 _____ C:\Users\Daniel\Downloads\UBot_Studio_Xing_Bot.ubot 2014-01-06 17:42 - 2014-01-06 17:42 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5 (1).zip 2014-01-06 17:20 - 2014-01-06 17:20 - 00026395 _____ C:\Users\Daniel\Downloads\OpenPOP.zip 2014-01-06 17:05 - 2014-01-06 17:05 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5.zip 2014-01-06 16:57 - 2014-01-06 16:57 - 00027152 _____ C:\Users\Daniel\Downloads\ReadPop3EmailsASP.Net.zip 2014-01-06 16:16 - 2014-01-06 16:14 - 00000000 ____D C:\Users\Daniel\Documents\sliqemailconfirmerlite 2014-01-06 16:06 - 2014-01-06 16:06 - 00003165 _____ C:\Users\Daniel\Desktop\SliQ Link Clicker Lite.lnk 2014-01-06 16:06 - 2014-01-06 16:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SliQTools 2014-01-06 16:05 - 2013-10-20 09:39 - 00000000 ____D C:\Users\Daniel\AppData\Local\Downloaded Installations 2014-01-06 16:03 - 2014-01-06 16:03 - 06043285 _____ (SliQTools ) C:\Users\Daniel\Downloads\sliqlinkclickerlite.exe 2014-01-06 03:23 - 2014-01-06 02:01 - 00010363 _____ C:\Users\Daniel\Documents\Emails.txt 2014-01-06 01:46 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\iMacros 2014-01-05 23:58 - 2013-11-14 22:45 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TeamViewer 2014-01-05 23:26 - 2013-10-19 17:09 - 00009843 _____ C:\Users\Daniel\Documents\index.html 2014-01-03 23:54 - 2014-01-03 23:54 - 00042184 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys 2014-01-03 22:52 - 2014-01-03 22:52 - 00008657 _____ C:\Users\Daniel\Downloads\DownloadSVN13.zip 2014-01-03 21:30 - 2014-01-03 21:30 - 00186054 _____ C:\Users\Daniel\Downloads\FsbExtractor13.07.23.rar 2014-01-03 21:18 - 2014-01-03 21:17 - 26578452 _____ C:\Users\Daniel\Downloads\Unreal Tournament Announcer Mod (LoL) V. 2.1.0.7.zip 2014-01-03 19:15 - 2013-12-29 19:13 - 00010567 _____ C:\Users\Daniel\Documents\test.html 2014-01-03 17:16 - 2014-01-03 17:16 - 00001172 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-01-03 17:16 - 2014-01-03 17:16 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-03 16:34 - 2013-10-28 00:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-02 21:03 - 2014-01-02 21:03 - 01530695 _____ C:\Users\Daniel\Downloads\861.zip 2014-01-02 20:41 - 2014-01-02 20:41 - 00197483 _____ C:\Users\Daniel\Downloads\gimp-dds-win64-3.0.1.zip 2014-01-02 20:34 - 2014-01-02 20:34 - 00253076 _____ C:\Users\Daniel\Downloads\2093 (1).zip 2014-01-02 14:42 - 2014-01-06 20:41 - 00025203 _____ C:\xPRiiME.properties 2014-01-02 12:16 - 2014-01-02 12:14 - 33901910 _____ C:\Users\Daniel\Downloads\fmoddesigner44427win-installer.exe 2014-01-02 12:11 - 2013-12-31 02:16 - 00000000 ____D C:\Users\Daniel\AppData\Local\FMOD Studio 2014-01-02 12:00 - 2014-01-02 12:00 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext (1).zip 2014-01-02 11:30 - 2014-01-02 11:30 - 02785220 _____ C:\Users\Daniel\Downloads\2622.zip 2014-01-02 10:28 - 2014-01-02 10:28 - 00272516 _____ C:\Users\Daniel\Downloads\yaybatch.zip 2014-01-02 10:22 - 2014-01-02 10:22 - 01923290 _____ C:\Users\Daniel\Downloads\cdex_151.zip 2014-01-02 09:15 - 2014-01-02 09:14 - 05015064 _____ C:\Users\Daniel\Downloads\MusicPlayerEx-Full-02-04-2013.7z 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32.zip 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32 (1).zip 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:05 - 07598942 _____ C:\Users\Daniel\Downloads\npp.6.5.3.Installer.exe 2014-01-02 06:27 - 2014-01-02 06:26 - 06709836 _____ C:\Users\Daniel\Downloads\SIU 3.335-Lite.zip 2014-01-02 03:17 - 2014-01-02 03:15 - 53464955 _____ C:\Users\Daniel\Downloads\wintermint.rar 2014-01-02 01:35 - 2014-01-02 01:35 - 01472106 _____ C:\Users\Daniel\Downloads\LOLReplay-0.8.5.2.exe 2014-01-02 01:35 - 2014-01-02 01:35 - 00000611 _____ C:\Users\Public\Desktop\LOL Recorder.lnk 2013-12-31 17:12 - 2013-11-27 17:36 - 00001582 _____ C:\Windows\Sandboxie.ini 2013-12-31 06:52 - 2013-12-31 06:52 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00002076 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\ProgramData\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\Program Files (x86)\Avira 2013-12-31 06:48 - 2013-12-31 06:41 - 129598176 _____ C:\Users\Daniel\Downloads\avira_free_antivirus_de.exe 2013-12-31 05:54 - 2013-12-31 05:53 - 03030680 _____ (Softbyte Labs, Inc. ) C:\Users\Daniel\Downloads\BlackWidow_Setup.exe 2013-12-31 05:47 - 2013-12-31 05:46 - 00253076 _____ C:\Users\Daniel\Downloads\2093.zip 2013-12-31 05:13 - 2013-12-31 05:13 - 00860736 _____ C:\Users\Daniel\Downloads\hexedit602.zip 2013-12-31 05:01 - 2013-12-31 05:01 - 00253442 _____ C:\Users\Daniel\Downloads\1209303036_datexpl.rar 2013-12-31 04:58 - 2013-12-31 04:58 - 00018023 _____ C:\Users\Daniel\Downloads\FTL UnPacker 1.0.1.zip 2013-12-31 04:54 - 2013-12-31 04:53 - 11147144 _____ (Adobe Systems, Inc.) C:\Users\Daniel\Downloads\flashplayer_11_sa_debug.exe 2013-12-31 04:53 - 2013-12-31 04:52 - 02179506 _____ (StandaloneFlashPlayer.com ) C:\Users\Daniel\Downloads\standaloneflashplayer_setup.exe 2013-12-31 02:32 - 2013-12-31 02:32 - 10807547 _____ C:\Users\Daniel\Downloads\fmodsandbox43505win-installer.exe 2013-12-31 02:14 - 2013-12-31 02:09 - 79700009 _____ C:\Users\Daniel\Downloads\fmodstudio10211win-installer.exe 2013-12-31 02:09 - 2013-12-31 02:09 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext.zip 2013-12-30 21:28 - 2013-12-30 21:28 - 00000000 ____D C:\Program Files (x86)\WinPcap 2013-12-30 21:10 - 2013-12-30 21:08 - 27981224 _____ (Wireshark development team) C:\Users\Daniel\Downloads\Wireshark-win64-1.10.5.exe Some content of TEMP: ==================== C:\Users\Daniel\AppData\Local\Temp\avgnt.exe C:\Users\Daniel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-20 13:54 ==================== End Of Log ============================ Geändert von PRiiME (29.01.2014 um 11:48 Uhr) |
29.01.2014, 17:33 | #8 |
/// the machine /// TB-Ausbilder | Accountzugriffe aus TokyoESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.01.2014, 12:55 | #9 |
| Accountzugriffe aus Tokyo ESET Log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=8c1593fe616a7b41969a2d81f1608312 # engine=16862 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-30 11:37:17 # local_time=2014-01-30 12:37:17 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 94 17842 4499999 10615 0 # compatibility_mode=5893 16776574 100 94 1797050 142711687 0 0 # scanned=336527 # found=1 # cleaned=0 # scan_time=6111 sh=929ED6B7365F1350F0823BF01266AF4335A83440 ft=0 fh=0000000000000000 vn="Win32/Adware.Gator application" ac=I fn="C:\Users\Daniel\Documents\DopeWars.rar" SecurityCheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 45 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader XI Mozilla Firefox (26.0) Google Chrome 32.0.1700.102 Google Chrome 32.0.1700.76 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST LOG: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 Ran by Daniel (administrator) on Daniel-PC on 30-01-2014 12:56:25 Running from C:\Users\Daniel\Downloads Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Sandboxie Holdings, LLC) E:\Sandboxie\SbieSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE (Nero AG) E:\HTC sync manager\HSMServiceEntry.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe () E:\HTC sync manager\HTC Sync\adb.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE () E:\puush\puush.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Spotify Ltd) C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () D:\Leagueoflegends\RADS\system\rads_user_kernel.exe () D:\Leagueoflegends\RADS\projects\lol_launcher\releases\0.0.0.198\deploy\LoLLauncher.exe () D:\Leagueoflegends\RADS\projects\lol_air_client\releases\0.0.1.69\deploy\LolClient.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13657304 2013-10-18] (Realtek Semiconductor) HKLM\...\Run: [MsmqIntCert] - regsvr32 /s mqrt.dll HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20587168 2013-11-18] (Skype Technologies S.A.) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE [283232 2012-02-27] (SEIKO EPSON CORPORATION) HKCU\...\Run: [SteelSeries Engine] - E:\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [242688 2013-11-05] (SteelSeries ApS) HKCU\...\Run: [puush] - E:\puush\puush.exe [567880 2013-12-22] () HKCU\...\Run: [GoogleChromeAutoLaunch_5560E485902A34F6B1CF63ACD9274ABA] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [866584 2014-01-23] (Google Inc.) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [Spotify Web Helper] - C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-17] (Spotify Ltd) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4D3BFB3EDBCCCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Tcpip\Parameters: [DhcpNameServer] 192.168.188.1 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - E:\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @nsroblox.roblox.com/launcher - C:\Program Files (x86)\Roblox\Versions\version-2c68f7c30e1b4888\\NPRobloxProxy.dll ( ROBLOX Corporation) FF Extension: iMacros for Firefox - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-01-06] FF Extension: Live HTTP Headers - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2013-11-25] FF Extension: SQLite Manager - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\j575yr6r.default\Extensions\SQLiteManager@mrinalkant.blogspot.com.xpi [2013-12-14] Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-19] CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-19] CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-19] CHR Extension: (Adblock Plus) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-13] CHR Extension: (Google-Suche) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-19] CHR Extension: (iMacros for Chrome) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplklnmnlbnpmjogncfgfijoopmnlemp [2014-01-06] CHR Extension: (Foxtab Speed Dial) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchmpbaclbiioedakpcldenooikekokm [2014-01-22] CHR Extension: (FoxyProxy Standard) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcknhkkoolaabfmlnjonogaaifnjlfnp [2013-12-17] CHR Extension: (Live HTTP Headers) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaiioopjkcekapmldfgbebdclcnpgnlo [2014-01-28] CHR Extension: (EXIF Viewer) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck [2014-01-16] CHR Extension: (EXIF Reader) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nchnjcdahncnilbicljpnbfobpnljnki [2014-01-16] CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-19] CHR Extension: (Bitdefender QuickScan) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2014-01-27] CHR Extension: (Google Mail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-19] CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\Daniel\AppData\Local\foxtab_speeddial.crx [2013-10-28] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-08-30] (Advanced Micro Devices, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1011768 2013-12-09] (Avira Operations GmbH & Co. KG) R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 HTCMonitorService; E:\HTC sync manager\HSMServiceEntry.exe [87368 2013-09-02] (Nero AG) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-21] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-21] (Microsoft Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2014-01-15] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2014-01-15] () S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) R2 SbieSvc; E:\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [84720 2013-12-09] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-15] (Disc Soft Ltd) S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [91352 2014-01-28] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) R3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation) R3 SbieDrv; E:\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-01-03] (Anchorfree Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-30 12:51 - 2014-01-30 12:51 - 00987425 _____ C:\Users\Daniel\Downloads\SecurityCheck.exe 2014-01-30 10:52 - 2014-01-30 10:52 - 02347384 _____ (ESET) C:\Users\Daniel\Downloads\esetsmartinstaller_enu (1).exe 2014-01-29 22:44 - 2014-01-29 22:44 - 00000003 _____ C:\Users\Daniel\Documents\version.ini 2014-01-29 20:51 - 2014-01-29 20:51 - 00006691 _____ C:\Users\Daniel\Downloads\ZipLib.zip 2014-01-29 20:47 - 2014-01-29 20:47 - 00001050 _____ C:\archage.zip 2014-01-29 19:21 - 2014-01-29 19:21 - 00312170 _____ C:\Users\Daniel\Downloads\VBNetThemes (1).zip 2014-01-29 19:19 - 2014-01-29 19:19 - 00312170 _____ C:\Users\Daniel\Downloads\VBNetThemes.zip 2014-01-29 15:22 - 2014-01-29 15:22 - 00003278 _____ C:\Windows\iis7.log 2014-01-29 15:16 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-01-29 15:16 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-01-29 15:16 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-01-29 15:16 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-01-29 15:15 - 2013-10-25 07:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-29 15:15 - 2013-10-25 07:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-29 15:15 - 2013-10-25 07:19 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-29 15:15 - 2013-10-25 07:18 - 19271168 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-29 15:15 - 2013-10-25 07:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-29 15:15 - 2013-10-25 07:17 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-29 15:15 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-29 15:15 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-29 15:15 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-29 15:15 - 2013-10-25 05:43 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-29 15:15 - 2013-10-25 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-29 15:15 - 2013-10-25 04:41 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-29 15:15 - 2013-10-25 04:17 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-29 15:15 - 2013-10-25 03:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-29 15:14 - 2014-01-29 15:14 - 00441640 _____ C:\Windows\msxml4-KB973688-enu.LOG 2014-01-29 15:14 - 2014-01-29 15:14 - 00441342 _____ C:\Windows\msxml4-KB954430-enu.LOG 2014-01-29 15:09 - 2011-03-11 07:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys 2014-01-29 15:09 - 2011-03-11 07:41 - 00189824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-01-29 15:09 - 2011-03-11 07:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys 2014-01-29 15:09 - 2011-03-11 07:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys 2014-01-29 15:09 - 2011-03-11 07:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys 2014-01-29 15:09 - 2011-03-11 07:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys 2014-01-29 15:09 - 2011-03-11 07:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2014-01-29 15:09 - 2011-03-11 07:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe 2014-01-29 15:09 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2014-01-29 15:09 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe 2014-01-29 15:09 - 2011-03-11 05:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2014-01-29 15:08 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-29 15:08 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-29 15:08 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-29 15:08 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-29 15:08 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-29 15:08 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-29 15:08 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-29 15:08 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-29 15:08 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-29 15:08 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-01-29 15:08 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-01-29 15:08 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-01-29 15:08 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-01-29 15:08 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-01-29 15:08 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-01-29 15:08 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-01-29 15:08 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2014-01-29 15:08 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-01-29 15:08 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-01-29 15:08 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2014-01-29 15:08 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2014-01-29 15:08 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2014-01-29 15:08 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2014-01-29 15:08 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2014-01-29 15:08 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2014-01-29 15:08 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2014-01-29 15:08 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-01-29 15:08 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-01-29 15:08 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2014-01-29 15:08 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2014-01-29 15:08 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2014-01-29 15:08 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2014-01-29 15:08 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2014-01-29 15:08 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2014-01-29 15:08 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-01-29 15:08 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-01-29 15:08 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2014-01-29 15:08 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-01-29 15:08 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2014-01-29 15:08 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-01-29 15:08 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-01-29 15:08 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-01-29 15:08 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-01-29 15:08 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-01-29 15:08 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-01-29 15:08 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-01-29 15:08 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-01-29 15:08 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-01-29 15:08 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-01-29 15:08 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-01-29 15:08 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-01-29 15:08 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-01-29 15:08 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-01-29 15:08 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-01-29 15:08 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-01-29 15:08 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-01-29 15:08 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2014-01-29 15:08 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-01-29 15:08 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-01-29 15:08 - 2012-07-06 21:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2014-01-29 15:08 - 2012-06-01 06:39 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wamregps.dll 2014-01-29 15:08 - 2012-06-01 06:36 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\iisRtl.dll 2014-01-29 15:08 - 2012-06-01 06:36 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\iisrstap.dll 2014-01-29 15:08 - 2012-06-01 06:35 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ahadmin.dll 2014-01-29 15:08 - 2012-06-01 06:34 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\admwprox.dll 2014-01-29 15:08 - 2012-06-01 06:33 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\iisreset.exe 2014-01-29 15:08 - 2012-06-01 05:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wamregps.dll 2014-01-29 15:08 - 2012-06-01 05:37 - 00154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisRtl.dll 2014-01-29 15:08 - 2012-06-01 05:37 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisrstap.dll 2014-01-29 15:08 - 2012-06-01 05:35 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admwprox.dll 2014-01-29 15:08 - 2012-06-01 05:35 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ahadmin.dll 2014-01-29 15:08 - 2012-06-01 05:34 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisreset.exe 2014-01-29 15:08 - 2011-04-28 04:54 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS 2014-01-29 12:39 - 2014-01-29 12:41 - 00000000 ____D C:\Users\Daniel\AppData\Local\Roblox 2014-01-29 12:39 - 2014-01-29 12:39 - 00001325 _____ C:\Users\Daniel\Desktop\ROBLOX Player.lnk 2014-01-29 12:37 - 2014-01-29 12:39 - 00001144 _____ C:\Users\Daniel\Desktop\ROBLOX Studio 2013.lnk 2014-01-29 12:37 - 2014-01-29 12:37 - 00543088 _____ (ROBLOX Corporation) C:\Users\Daniel\Downloads\RobloxPlayerLauncher.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000000 ____D C:\ProgramData\Roblox 2014-01-29 12:37 - 2014-01-29 12:37 - 00000000 ____D C:\Program Files (x86)\Roblox 2014-01-29 11:42 - 2014-01-29 11:42 - 00000000 ____D C:\Users\Daniel\Downloads\FRST-OlderVersion 2014-01-29 11:39 - 2014-01-29 11:39 - 00002056 _____ C:\Users\Daniel\Desktop\JRT.txt 2014-01-29 11:31 - 2014-01-29 11:31 - 01037068 _____ (Thisisu) C:\Users\Daniel\Downloads\JRT.exe 2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\ERUNT 2014-01-29 11:25 - 2014-01-29 11:26 - 00000000 ____D C:\AdwCleaner 2014-01-29 11:25 - 2014-01-29 11:25 - 01166132 _____ C:\Users\Daniel\Downloads\adwcleaner.exe 2014-01-29 11:10 - 2014-01-29 11:10 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2014-01-29 11:09 - 2014-01-29 11:09 - 00001119 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-29 11:09 - 2014-01-29 11:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-29 11:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-29 11:08 - 2014-01-29 11:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Daniel\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-29 09:01 - 2014-01-29 09:02 - 24088418 _____ C:\Users\Daniel\Downloads\Web Server - Riot Decode.zip 2014-01-28 17:56 - 2014-01-28 17:56 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2014-01-28 17:53 - 2014-01-28 17:56 - 00000000 ____D C:\Program Files\Common Files\Adobe 2014-01-28 17:49 - 2014-01-28 17:49 - 00102932 ____H C:\Windows\SysWOW64\mlfcache.dat 2014-01-28 17:44 - 2014-01-29 11:20 - 00006154 _____ C:\Windows\PFRO.log 2014-01-28 17:13 - 2014-01-28 17:13 - 00026718 _____ C:\ComboFix.txt 2014-01-28 16:24 - 2014-01-28 17:14 - 00000000 ____D C:\Qoobox 2014-01-28 16:24 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-28 16:24 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-28 16:24 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-28 16:24 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-28 16:23 - 2014-01-28 17:07 - 00000000 ____D C:\Windows\erdnt 2014-01-28 16:23 - 2014-01-28 16:23 - 05175619 ____R (Swearware) C:\Users\Daniel\Downloads\ComboFix.exe 2014-01-28 13:24 - 2014-01-28 13:24 - 00000000 ____D C:\Users\Daniel\AppData\Local\Cosa_Nostra 2014-01-28 13:22 - 2014-01-28 13:23 - 00134947 _____ C:\Users\Daniel\Downloads\RgxTester10Exe.zip 2014-01-28 12:04 - 2014-01-28 12:04 - 00880069 _____ C:\Users\Daniel\Downloads\Reteewt v1.2.rar 2014-01-28 12:04 - 2014-01-28 12:04 - 00000000 ____D C:\Users\Daniel\Desktop\asdad 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Battle.net 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Blizzard Entertainment 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Battle.net 2014-01-28 11:58 - 2014-01-28 11:58 - 00000788 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-28 11:58 - 2014-01-28 11:58 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2014-01-28 11:55 - 2014-01-28 11:55 - 00000000 ____D C:\ProgramData\Battle.net 2014-01-28 11:54 - 2014-01-28 11:54 - 05748920 _____ (Blizzard Entertainment) C:\Users\Daniel\Downloads\Battle.net-Beta-Setup-deDE.exe 2014-01-28 07:29 - 2014-01-30 08:34 - 00000796 _____ C:\Windows\setupact.log 2014-01-28 07:29 - 2014-01-28 07:29 - 00000000 _____ C:\Windows\setuperr.log 2014-01-28 05:57 - 2014-01-29 23:10 - 00000000 ____D C:\Users\Daniel\Documents\botman 2014-01-28 05:19 - 2014-01-28 05:19 - 00003901 _____ C:\Users\Daniel\Downloads\smime.p7s 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Program Files (x86)\MySQL 2014-01-28 04:26 - 2014-01-28 04:26 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6 (1).zip 2014-01-28 04:22 - 2014-01-28 04:22 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6.zip 2014-01-28 03:34 - 2014-01-30 00:24 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\FileZilla 2014-01-28 03:29 - 2014-01-28 03:29 - 07241860 _____ C:\Users\Daniel\Downloads\FileZilla_3.7.3_win32.zip 2014-01-27 23:24 - 2014-01-27 23:24 - 00000000 ____D C:\Windows\pss 2014-01-27 23:09 - 2014-01-27 23:24 - 00002748 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-27 23:09 - 2014-01-27 23:09 - 00000568 _____ C:\Users\Daniel\Desktop\CCleaner.lnk 2014-01-27 23:09 - 2014-01-27 23:09 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-01-27 23:08 - 2014-01-27 23:08 - 04721920 _____ (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup410.exe 2014-01-27 23:07 - 2014-01-27 23:07 - 02347384 _____ (ESET) C:\Users\Daniel\Downloads\esetsmartinstaller_enu.exe 2014-01-27 23:01 - 2014-01-28 10:39 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\QuickScan 2014-01-27 22:03 - 2014-01-27 22:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-27 22:02 - 2014-01-28 17:29 - 00000000 ____D C:\Users\Daniel\Desktop\mbar 2014-01-27 22:02 - 2014-01-28 17:16 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-27 22:02 - 2014-01-27 22:02 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Daniel\Downloads\mbar-1.07.0.1009.exe 2014-01-27 00:54 - 2014-01-27 00:54 - 00033821 _____ C:\Users\Daniel\Downloads\Addition.txt 2014-01-27 00:50 - 2014-01-30 12:56 - 00016695 _____ C:\Users\Daniel\Downloads\FRST.txt 2014-01-27 00:50 - 2014-01-30 12:56 - 00000000 ____D C:\FRST 2014-01-27 00:49 - 2014-01-29 11:42 - 02079744 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe 2014-01-26 19:38 - 2014-01-26 19:38 - 01104710 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE.zip 2014-01-26 19:27 - 2014-01-26 19:27 - 02097134 _____ C:\Users\Daniel\Downloads\systemsurveydummyfile (6).exe 2014-01-26 19:26 - 2014-01-26 19:26 - 00000005 _____ C:\Users\Daniel\Downloads\Download 2014-01-26 18:56 - 2014-01-26 18:57 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\JetBrains 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\SymbolSourceSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\RefSrcSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\JetBrains 2014-01-26 18:51 - 2014-01-26 18:53 - 29220864 _____ C:\Users\Daniel\Downloads\dotPeekSetup-1.1.1.33.msi 2014-01-26 18:38 - 2014-01-26 18:38 - 00157234 _____ C:\Users\Daniel\Downloads\RouterReconnect_1.3.zip 2014-01-26 18:38 - 2008-04-19 18:03 - 00335360 _____ (RPworld.de) C:\Users\Daniel\Desktop\RouterReconnect.exe 2014-01-26 18:37 - 2014-01-26 18:37 - 04689382 _____ C:\Users\Daniel\Downloads\curl-7.34.0.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 00094335 _____ C:\Users\Daniel\Downloads\Fritz!Box Reconnect.rar 2014-01-26 17:50 - 2014-01-26 17:50 - 00001154 _____ C:\Users\Daniel\Documents\absolutechamp.txt 2014-01-26 16:36 - 2014-01-26 16:49 - 00000000 ____D C:\Users\Daniel\Documents\Rezepte 2014-01-23 17:07 - 2014-01-29 23:38 - 00000000 ____D C:\Users\Daniel\Documents\zorroslisten 2014-01-23 09:41 - 2014-01-23 09:41 - 01398825 _____ C:\Users\Daniel\Downloads\wg_3d_banners_vol3.zip 2014-01-23 09:38 - 2014-01-23 09:38 - 42713738 _____ C:\Users\Daniel\Downloads\Devisual's Graphics Pack.rar 2014-01-22 14:41 - 2014-01-22 14:41 - 00000000 _____ C:\Users\Daniel\Desktop\KUHDO.txt 2014-01-22 14:31 - 2014-01-22 14:32 - 00000000 ____D C:\Users\Daniel\Desktop\Lobby checker 2014-01-17 12:16 - 2014-01-17 12:16 - 00092309 _____ C:\Users\Daniel\Downloads\MarkC_Windows_8.x+7_MouseFix.zip 2014-01-15 15:47 - 2014-01-15 15:47 - 00000749 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-15 15:46 - 2014-01-15 15:46 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 15:36 - 2014-01-15 15:38 - 08501736 _____ C:\Users\Daniel\Downloads\HSS-3.31-install-e-550-plain.exe 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2014-01-15 15:22 - 2014-01-15 15:22 - 00000530 _____ C:\Users\Public\Desktop\Origin.lnk 2014-01-15 15:20 - 2014-01-15 15:21 - 16952720 _____ (Electronic Arts, Inc.) C:\Users\Daniel\Downloads\OriginThinSetup.exe 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\EA Core 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Users\Daniel\AppData\Local\ESN 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2014-01-15 15:11 - 2014-01-15 15:11 - 03821064 _____ C:\Users\Daniel\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00012885 _____ C:\Users\Daniel\AppData\Local\recently-used.xbel 2014-01-15 11:38 - 2014-01-15 11:38 - 01016952 _____ C:\Users\Daniel\Downloads\25273 (1).zip 2014-01-15 09:23 - 2014-01-15 09:23 - 00004705 _____ C:\Users\Daniel\Downloads\First Person Camera Fix-6508-1.7z 2014-01-15 08:46 - 2014-01-15 08:46 - 00060838 _____ C:\Users\Daniel\Downloads\SafetyLoad 1_2-46465-1-2.zip 2014-01-15 08:06 - 2014-01-15 08:06 - 00003710 _____ C:\Users\Daniel\Downloads\High Prefs and inis ugrids 5 V27 ENB version-36146-v27.rar 2014-01-15 07:58 - 2014-01-15 07:58 - 12881617 _____ C:\Users\Daniel\Downloads\RealVision_ENB_245a-30936-245a.7z 2014-01-15 07:58 - 2014-01-15 07:58 - 02342720 _____ C:\Users\Daniel\Downloads\enbseries_skyrim_v0245.zip 2014-01-15 07:54 - 2014-01-15 07:54 - 01457128 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - Weather Patch-39799-15.rar 2014-01-15 07:53 - 2014-01-15 07:53 - 00020795 _____ C:\Users\Daniel\Downloads\Supreme Storms for Climates of Tamriel 3_1-27022-3-1.rar 2014-01-15 07:50 - 2014-01-15 07:51 - 14741439 _____ C:\Users\Daniel\Downloads\RSE High v1_4-836.7z 2014-01-15 07:50 - 2014-01-15 07:50 - 00762191 _____ C:\Users\Daniel\Downloads\Dust Effects v1_0-44201-1-0.7z 2014-01-15 07:49 - 2014-01-15 07:49 - 17953454 _____ C:\Users\Daniel\Downloads\Rocking Stones Parallax for ENB - 2k BROWNISH - best one imo-38004-4-4.7z 2014-01-15 07:47 - 2014-01-15 07:47 - 16731899 _____ C:\Users\Daniel\Downloads\SkyFalls - Dragonborn Edition-40564-1-2.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 04175336 _____ C:\Users\Daniel\Downloads\HD Ivy - Original Green-30971-2-00.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 01405354 _____ C:\Users\Daniel\Downloads\SkyFalls - Animated Distant Waterfalls-40564-1-9.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 00006543 _____ C:\Users\Daniel\Downloads\SkyFalls - Dawnguard Edition-40564-1-1.rar 2014-01-15 07:45 - 2014-01-15 07:46 - 28948920 _____ C:\Users\Daniel\Downloads\TreesHD_Skyrim_variation_HIGH_NEW-3812-1-6.rar 2014-01-15 07:43 - 2014-01-15 07:44 - 29112106 _____ C:\Users\Daniel\Downloads\Dragonborn addon v02-141-v0-2.7z 2014-01-15 07:43 - 2014-01-15 07:43 - 01807096 _____ C:\Users\Daniel\Downloads\Natural Grass Texture Floor-30164-1-0.zip 2014-01-15 07:30 - 2014-01-15 07:37 - 145113682 _____ C:\Users\Daniel\Downloads\Summer Edition v181-141-v1-81.7z 2014-01-15 07:27 - 2014-01-15 07:29 - 26777790 _____ C:\Users\Daniel\Downloads\Detailed_Rugs_v1-3-29608-1-3.7z 2014-01-15 07:15 - 2014-01-15 07:24 - 144349763 _____ C:\Users\Daniel\Downloads\Hectrol CAVES DELUXE HighRes Retex 4K-29145-1-0.7z 2014-01-15 07:12 - 2014-01-15 07:13 - 04941702 _____ C:\Users\Daniel\Downloads\Cinematic Fire FX 2-2692-2-3.zip 2014-01-15 07:11 - 2014-01-15 07:24 - 18920661 _____ C:\Users\Daniel\Downloads\Ruins_Clutter_Improved_v2-6-14227-2-6.7z 2014-01-14 23:09 - 2014-01-14 23:09 - 05713023 _____ C:\Users\Daniel\Downloads\Unofficial Dragonborn Patch-31083-2-0-0.7z 2014-01-14 04:34 - 2014-01-14 04:35 - 09511604 _____ C:\Users\Daniel\Downloads\Footprints v0_99-22745-0-99.7z 2014-01-14 04:34 - 2014-01-14 04:34 - 08922372 _____ C:\Users\Daniel\Downloads\0_Pure Waters 4-6 Legendary-1111-4-6.rar 2014-01-14 04:27 - 2014-01-14 04:27 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (2).7z 2014-01-14 04:20 - 2014-01-14 04:21 - 09113460 _____ C:\Users\Daniel\Downloads\UNP BASE Main body V1dot2-6709.7z 2014-01-14 04:16 - 2014-01-14 04:17 - 02178105 _____ C:\Users\Daniel\Downloads\Sharpshooter enb classic version-15105-V1.rar 2014-01-14 04:15 - 2014-01-14 04:29 - 235701929 _____ C:\Users\Daniel\Downloads\UNP Mashup Compilation v1-20415-1.rar 2014-01-14 03:29 - 2014-01-14 03:30 - 23759325 _____ C:\Users\Daniel\Downloads\Better Vampires 6-5-9717-6-5.zip 2014-01-14 03:25 - 2014-01-14 03:25 - 00023554 _____ C:\Users\Daniel\Downloads\NEW Temptress Vampire Compatibility Update-18717-.rar 2014-01-14 03:14 - 2014-01-14 03:14 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (1).7z 2014-01-14 00:57 - 2014-01-14 00:57 - 00000617 _____ C:\Users\Daniel\Downloads\More Dragon Loot-10050-R4.rar 2014-01-14 00:55 - 2014-01-14 00:55 - 00001935 _____ C:\Users\Daniel\Downloads\Version 2_1-1010-2-1.zip 2014-01-14 00:47 - 2014-01-14 00:47 - 00001144 _____ C:\Users\Daniel\Downloads\More Arrows-11613-1-0.rar 2014-01-14 00:45 - 2014-01-14 00:46 - 20135641 _____ C:\Users\Daniel\Downloads\Enhanced Character Edit-12951-1-2.7z 2014-01-14 00:39 - 2014-01-14 00:39 - 04869331 _____ C:\Users\Daniel\Downloads\The Joy of Perspective Female V0 9 3 -6002-v0-9-3.rar 2014-01-14 00:35 - 2014-01-14 00:35 - 00322469 _____ C:\Users\Daniel\Downloads\Realistic Force-601-1-9.rar 2014-01-14 00:34 - 2014-01-14 00:34 - 00887469 _____ C:\Users\Daniel\Downloads\XPMS 1-92 NMM-BAIN INSTALLER-26800-1-92.7z 2014-01-14 00:31 - 2014-01-14 00:31 - 00083125 _____ C:\Users\Daniel\Downloads\The Dance of Death 4-0 Beta - Ultimate Edition-10906-4-0.7z 2014-01-14 00:26 - 2014-01-14 00:26 - 01025219 _____ C:\Users\Daniel\Downloads\UNP Bouncing Boobs-10470-1-0.rar 2014-01-14 00:21 - 2014-01-14 00:21 - 03496349 _____ C:\Users\Daniel\Downloads\360WalkRunPlus_v3_1_2-34508-3-1-2.7z 2014-01-14 00:11 - 2014-01-14 00:15 - 72977814 _____ C:\Users\Daniel\Downloads\Unofficial Skyrim Patch-19-2-0-0a.7z 2014-01-14 00:10 - 2014-01-14 00:11 - 29040935 _____ C:\Users\Daniel\Downloads\Immersive Sounds - Aural Assortment-49084-1-0.zip 2014-01-14 00:10 - 2014-01-14 00:10 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6 (1).zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6.zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00002452 _____ C:\Users\Daniel\Downloads\0 Dragonborn-Dawnguard Compatibility Patch-60-.rar 2014-01-14 00:02 - 2014-01-14 00:02 - 00266051 _____ C:\Users\Daniel\Downloads\skse_1_06_16_installer.exe 2014-01-14 00:02 - 2014-01-14 00:02 - 00000649 _____ C:\Users\Daniel\Desktop\Skyrim (SKSE).lnk 2014-01-14 00:01 - 2014-01-14 00:06 - 43448187 _____ C:\Users\Daniel\Downloads\Enhanced Blood Textures 3_5d-60-3-5d.rar 2014-01-13 23:59 - 2014-01-14 00:00 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929.7z 2014-01-13 23:54 - 2014-01-14 00:18 - 151736579 _____ C:\Users\Daniel\Downloads\IA v6 BETA 2-19733-6-BETA-2.7z 2014-01-13 23:53 - 2014-01-13 23:53 - 02978304 _____ C:\Users\Daniel\Downloads\Realistic Lighting Overhaul 4_0_8_01 NMM-BAINWizard Installer-30450-4-0-8-01.7z 2014-01-13 23:52 - 2014-01-13 23:52 - 07592804 _____ C:\Users\Daniel\Downloads\Wars_in_Skyrim_-_Normal_Mode-6176-1-4-1.7z 2014-01-13 23:38 - 2014-01-13 23:49 - 119244137 _____ C:\Users\Daniel\Downloads\Temptress Complete v1_3-18717-1-3.rar 2014-01-13 23:30 - 2014-01-13 23:42 - 151991017 _____ C:\Users\Daniel\Downloads\ApachiiSkyHair_v_1_5_Full-10168-1-5-Full.7z 2014-01-13 23:18 - 2014-01-13 23:19 - 11624802 _____ C:\Users\Daniel\Downloads\No_More_Blocky_Faces-1_50-30-1-5.7z 2014-01-13 23:12 - 2014-01-13 23:12 - 00000313 _____ C:\Users\Daniel\Downloads\Proper Aiming 1_1-13652-1-1.rar 2014-01-13 23:06 - 2014-01-13 23:06 - 00230939 _____ C:\Users\Daniel\Downloads\Version 1_82 Quick Fix-18480-1-82.rar 2014-01-13 23:03 - 2014-01-13 23:04 - 11252501 _____ C:\Users\Daniel\Downloads\Version 1_82 BSA-18480-1-82.rar 2014-01-13 22:59 - 2014-01-13 23:34 - 554674254 _____ C:\Users\Daniel\Downloads\SMIM v1-61-8655-1-61.7z 2014-01-13 22:51 - 2014-01-13 22:56 - 107551867 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - V3-1-17802-3-1.zip 2014-01-13 22:42 - 2014-01-14 23:08 - 00000000 ____D C:\Users\Daniel\Documents\Nexus Mod Manager 2014-01-13 22:42 - 2014-01-13 22:42 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-01-13 22:42 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Black_Tree_Gaming 2014-01-13 22:35 - 2014-01-13 22:37 - 04136616 _____ (Black Tree Gaming ) C:\Users\Daniel\Downloads\Nexus Mod Manager-0.46.0.exe 2014-01-13 22:32 - 2014-01-13 22:32 - 01409134 _____ C:\Users\Daniel\Downloads\SkyUI_4_1-3863-4-1.7z 2014-01-13 22:29 - 2014-01-13 22:34 - 85038708 _____ C:\Users\Daniel\Downloads\Noiral_CBBE_Reloaded.zip 2014-01-13 20:02 - 2014-01-14 23:08 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2014-01-11 14:39 - 2014-01-11 14:39 - 00000650 _____ C:\Users\Daniel\Downloads\Split Second Velocity.ct 2014-01-11 10:20 - 1997-03-24 17:42 - 00314368 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe 2014-01-11 10:13 - 2014-01-11 10:14 - 07679554 _____ C:\Users\Daniel\Downloads\netxray.zip 2014-01-11 09:53 - 2014-01-11 09:53 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Hex-Rays 2014-01-11 09:51 - 2014-01-11 09:52 - 16374114 _____ (Hex-Rays SA ) C:\Users\Daniel\Downloads\idafree50.exe 2014-01-11 09:51 - 2014-01-11 09:52 - 01385454 _____ C:\Users\Daniel\Downloads\idastealth_complete.rar 2014-01-11 09:45 - 2014-01-11 09:45 - 00545804 _____ C:\Users\Daniel\Downloads\fdbg0024.zip 2014-01-11 09:41 - 2014-01-11 09:42 - 06965278 _____ C:\Users\Daniel\Downloads\odbg201.zip 2014-01-11 09:14 - 2014-01-11 09:14 - 01935900 _____ C:\Users\Daniel\Downloads\OneHitKill.rar 2014-01-11 09:13 - 2014-01-11 09:13 - 01646243 _____ C:\Users\Daniel\Downloads\tsearch16b.rar 2014-01-11 09:09 - 2014-01-11 10:04 - 00000319 _____ C:\Windows\WPE PRO - modified.INI 2014-01-11 07:38 - 2014-01-11 07:38 - 00000607 _____ C:\Users\Daniel\Desktop\Cheat Engine.lnk 2014-01-11 07:34 - 2014-01-11 07:35 - 08065840 _____ (Cheat Engine ) C:\Users\Daniel\Downloads\CheatEngine63.exe 2014-01-10 20:56 - 2014-01-12 20:44 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Awesomium 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\Users\Daniel\Documents\Elder Scrolls Online 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\ProgramData\Elder Scrolls Online 2014-01-09 16:38 - 2014-01-09 16:48 - 190488919 _____ C:\Users\Daniel\Downloads\RusselZs League of Draven (3.10a Lucian).rar 2014-01-09 15:58 - 2014-01-09 15:58 - 00414569 _____ C:\Users\Daniel\Downloads\Raf Manager.zip 2014-01-08 06:59 - 2014-01-08 06:59 - 02653910 _____ C:\Users\Daniel\Downloads\9221.zip 2014-01-08 06:54 - 2014-01-08 06:55 - 24309760 _____ C:\Users\Daniel\Downloads\LauncherSetup.msi 2014-01-06 23:38 - 2014-01-06 23:38 - 00033323 _____ C:\Users\Daniel\Downloads\Prodiction.lua 2014-01-06 21:24 - 2014-01-06 21:24 - 01310829 _____ C:\Users\Daniel\Downloads\19913.zip 2014-01-06 21:24 - 2014-01-06 21:24 - 01304629 _____ C:\Users\Daniel\Downloads\6471.zip 2014-01-06 21:20 - 2014-01-06 21:21 - 01016952 _____ C:\Users\Daniel\Downloads\25273.zip 2014-01-06 20:41 - 2014-01-02 14:42 - 00025203 _____ C:\xPRiiME.properties 2014-01-06 18:16 - 2014-01-06 18:16 - 00001521 _____ C:\Users\Daniel\Downloads\UBot_Studio_Xing_Bot.ubot 2014-01-06 17:20 - 2014-01-06 17:20 - 00026395 _____ C:\Users\Daniel\Downloads\OpenPOP.zip 2014-01-06 17:05 - 2014-01-06 17:05 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5.zip 2014-01-06 16:57 - 2014-01-06 16:57 - 00027152 _____ C:\Users\Daniel\Downloads\ReadPop3EmailsASP.Net.zip 2014-01-06 16:14 - 2014-01-06 16:16 - 00000000 ____D C:\Users\Daniel\Documents\sliqemailconfirmerlite 2014-01-06 16:06 - 2014-01-06 16:06 - 00003165 _____ C:\Users\Daniel\Desktop\SliQ Link Clicker Lite.lnk 2014-01-06 16:06 - 2014-01-06 16:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SliQTools 2014-01-06 16:03 - 2014-01-06 16:03 - 06043285 _____ (SliQTools ) C:\Users\Daniel\Downloads\sliqlinkclickerlite.exe 2014-01-06 02:01 - 2014-01-06 03:23 - 00010363 _____ C:\Users\Daniel\Documents\Emails.txt 2014-01-03 23:54 - 2014-01-03 23:54 - 00042184 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys 2014-01-03 22:52 - 2014-01-03 22:52 - 00008657 _____ C:\Users\Daniel\Downloads\DownloadSVN13.zip 2014-01-03 21:30 - 2014-01-03 21:30 - 00186054 _____ C:\Users\Daniel\Downloads\FsbExtractor13.07.23.rar 2014-01-03 21:17 - 2014-01-03 21:18 - 26578452 _____ C:\Users\Daniel\Downloads\Unreal Tournament Announcer Mod (LoL) V. 2.1.0.7.zip 2014-01-03 17:16 - 2014-01-03 17:16 - 00001172 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-01-03 17:16 - 2014-01-03 17:16 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-02 21:03 - 2014-01-02 21:03 - 01530695 _____ C:\Users\Daniel\Downloads\861.zip 2014-01-02 20:41 - 2014-01-02 20:41 - 00197483 _____ C:\Users\Daniel\Downloads\gimp-dds-win64-3.0.1.zip 2014-01-02 20:34 - 2014-01-02 20:34 - 00253076 _____ C:\Users\Daniel\Downloads\2093 (1).zip 2014-01-02 12:14 - 2014-01-02 12:16 - 33901910 _____ C:\Users\Daniel\Downloads\fmoddesigner44427win-installer.exe 2014-01-02 12:00 - 2014-01-02 12:00 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext (1).zip 2014-01-02 11:30 - 2014-01-02 11:30 - 02785220 _____ C:\Users\Daniel\Downloads\2622.zip 2014-01-02 10:28 - 2014-01-02 10:28 - 00272516 _____ C:\Users\Daniel\Downloads\yaybatch.zip 2014-01-02 10:22 - 2014-01-02 10:22 - 01923290 _____ C:\Users\Daniel\Downloads\cdex_151.zip 2014-01-02 09:14 - 2014-01-02 09:15 - 05015064 _____ C:\Users\Daniel\Downloads\MusicPlayerEx-Full-02-04-2013.7z 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32.zip 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32 (1).zip 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-01-02 07:05 - 2014-01-02 07:06 - 07598942 _____ C:\Users\Daniel\Downloads\npp.6.5.3.Installer.exe 2014-01-02 06:35 - 2014-01-12 00:42 - 00000000 ____D C:\Users\Daniel\Desktop\LoL Modding 2014-01-02 06:26 - 2014-01-02 06:27 - 06709836 _____ C:\Users\Daniel\Downloads\SIU 3.335-Lite.zip 2014-01-02 03:15 - 2014-01-02 03:17 - 53464955 _____ C:\Users\Daniel\Downloads\wintermint.rar 2014-01-02 01:35 - 2014-01-16 18:11 - 00000000 ____D C:\Users\Daniel\Documents\LOLReplay 2014-01-02 01:35 - 2014-01-02 01:35 - 01472106 _____ C:\Users\Daniel\Downloads\LOLReplay-0.8.5.2.exe 2014-01-02 01:35 - 2014-01-02 01:35 - 00000611 _____ C:\Users\Public\Desktop\LOL Recorder.lnk 2013-12-31 18:21 - 2014-01-30 12:52 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-12-31 06:52 - 2013-12-31 06:52 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00002076 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\ProgramData\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\Program Files (x86)\Avira 2013-12-31 06:51 - 2013-12-09 11:37 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-12-31 06:51 - 2013-12-09 11:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-12-31 06:41 - 2013-12-31 06:48 - 129598176 _____ C:\Users\Daniel\Downloads\avira_free_antivirus_de.exe 2013-12-31 05:53 - 2013-12-31 05:54 - 03030680 _____ (Softbyte Labs, Inc. ) C:\Users\Daniel\Downloads\BlackWidow_Setup.exe 2013-12-31 05:46 - 2013-12-31 05:47 - 00253076 _____ C:\Users\Daniel\Downloads\2093.zip 2013-12-31 05:13 - 2013-12-31 05:13 - 00860736 _____ C:\Users\Daniel\Downloads\hexedit602.zip 2013-12-31 05:01 - 2013-12-31 05:01 - 00253442 _____ C:\Users\Daniel\Downloads\1209303036_datexpl.rar 2013-12-31 04:58 - 2013-12-31 04:58 - 00018023 _____ C:\Users\Daniel\Downloads\FTL UnPacker 1.0.1.zip 2013-12-31 04:53 - 2013-12-31 04:54 - 11147144 _____ (Adobe Systems, Inc.) C:\Users\Daniel\Downloads\flashplayer_11_sa_debug.exe 2013-12-31 04:52 - 2013-12-31 04:53 - 02179506 _____ (StandaloneFlashPlayer.com ) C:\Users\Daniel\Downloads\standaloneflashplayer_setup.exe 2013-12-31 02:32 - 2013-12-31 02:32 - 10807547 _____ C:\Users\Daniel\Downloads\fmodsandbox43505win-installer.exe 2013-12-31 02:16 - 2014-01-02 12:11 - 00000000 ____D C:\Users\Daniel\AppData\Local\FMOD Studio 2013-12-31 02:09 - 2013-12-31 02:14 - 79700009 _____ C:\Users\Daniel\Downloads\fmodstudio10211win-installer.exe 2013-12-31 02:09 - 2013-12-31 02:09 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext.zip ==================== One Month Modified Files and Folders ======= 2014-01-30 12:56 - 2014-01-27 00:50 - 00016695 _____ C:\Users\Daniel\Downloads\FRST.txt 2014-01-30 12:56 - 2014-01-27 00:50 - 00000000 ____D C:\FRST 2014-01-30 12:52 - 2013-12-31 18:21 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2014-01-30 12:52 - 2013-10-20 07:28 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype 2014-01-30 12:51 - 2014-01-30 12:51 - 00987425 _____ C:\Users\Daniel\Downloads\SecurityCheck.exe 2014-01-30 12:11 - 2013-10-19 15:56 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-30 11:49 - 2013-10-19 15:12 - 01574595 _____ C:\Windows\WindowsUpdate.log 2014-01-30 10:52 - 2014-01-30 10:52 - 02347384 _____ (ESET) C:\Users\Daniel\Downloads\esetsmartinstaller_enu (1).exe 2014-01-30 08:43 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-30 08:43 - 2009-07-14 05:45 - 00021248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-30 08:37 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2014-01-30 08:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\inetsrv 2014-01-30 08:34 - 2014-01-28 07:29 - 00000796 _____ C:\Windows\setupact.log 2014-01-30 08:34 - 2013-10-20 09:40 - 00000000 ____D C:\Users\Daniel\AppData\Local\HTC MediaHub 2014-01-30 08:34 - 2013-10-19 15:56 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-30 08:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-30 00:24 - 2014-01-28 03:34 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\FileZilla 2014-01-29 22:53 - 2013-10-19 17:09 - 00000000 ____D C:\Users\Daniel\Documents\Visual Studio 2012 2014-01-29 20:47 - 2014-01-29 20:47 - 00001050 _____ C:\archage.zip 2014-01-29 19:48 - 2013-10-19 17:09 - 00000000 ____D C:\Users\Daniel\Documents\Arma 3 Alpha Lite 2014-01-29 19:21 - 2014-01-29 19:21 - 00312170 _____ C:\Users\Daniel\Downloads\VBNetThemes (1).zip 2014-01-29 15:25 - 2011-04-12 08:43 - 00775688 _____ C:\Windows\system32\perfh007.dat 2014-01-29 15:25 - 2011-04-12 08:43 - 00176366 _____ C:\Windows\system32\perfc007.dat 2014-01-29 15:25 - 2009-07-14 06:13 - 01812468 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-29 15:23 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2014-01-29 15:22 - 2014-01-29 15:22 - 00003278 _____ C:\Windows\iis7.log 2014-01-29 15:22 - 2013-10-19 16:09 - 00000000 ____D C:\Windows\Panther 2014-01-29 15:20 - 2009-07-14 05:45 - 04920336 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-29 15:18 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\inetsrv 2014-01-29 15:14 - 2014-01-29 15:14 - 00441640 _____ C:\Windows\msxml4-KB973688-enu.LOG 2014-01-29 15:14 - 2014-01-29 15:14 - 00441342 _____ C:\Windows\msxml4-KB954430-enu.LOG 2014-01-29 15:14 - 2013-10-19 16:26 - 01785812 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-29 15:13 - 2013-11-08 19:40 - 00000000 ____D C:\Windows\system32\MRT 2014-01-29 14:49 - 2013-10-19 18:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Spotify 2014-01-29 14:00 - 2013-10-19 18:53 - 00000000 ____D C:\Users\Daniel\AppData\Local\Spotify 2014-01-29 12:52 - 2013-10-19 15:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\Apps\2.0 2014-01-29 12:41 - 2014-01-29 12:39 - 00000000 ____D C:\Users\Daniel\AppData\Local\Roblox 2014-01-29 12:39 - 2014-01-29 12:39 - 00001325 _____ C:\Users\Daniel\Desktop\ROBLOX Player.lnk 2014-01-29 12:39 - 2014-01-29 12:37 - 00001144 _____ C:\Users\Daniel\Desktop\ROBLOX Studio 2013.lnk 2014-01-29 12:39 - 2009-07-14 03:34 - 00000430 _____ C:\Windows\win.ini 2014-01-29 12:37 - 2014-01-29 12:37 - 00543088 _____ (ROBLOX Corporation) C:\Users\Daniel\Downloads\RobloxPlayerLauncher.exe 2014-01-29 12:37 - 2014-01-29 12:37 - 00000000 ____D C:\ProgramData\Roblox 2014-01-29 12:37 - 2014-01-29 12:37 - 00000000 ____D C:\Program Files (x86)\Roblox 2014-01-29 11:42 - 2014-01-29 11:42 - 00000000 ____D C:\Users\Daniel\Downloads\FRST-OlderVersion 2014-01-29 11:42 - 2014-01-27 00:49 - 02079744 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe 2014-01-29 11:39 - 2014-01-29 11:39 - 00002056 _____ C:\Users\Daniel\Desktop\JRT.txt 2014-01-29 11:31 - 2014-01-29 11:31 - 01037068 _____ (Thisisu) C:\Users\Daniel\Downloads\JRT.exe 2014-01-29 11:31 - 2014-01-29 11:31 - 00000000 ____D C:\Windows\ERUNT 2014-01-29 11:28 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-29 11:26 - 2014-01-29 11:25 - 00000000 ____D C:\AdwCleaner 2014-01-29 11:25 - 2014-01-29 11:25 - 01166132 _____ C:\Users\Daniel\Downloads\adwcleaner.exe 2014-01-29 11:20 - 2014-01-28 17:44 - 00006154 _____ C:\Windows\PFRO.log 2014-01-29 11:10 - 2014-01-29 11:10 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2014-01-29 11:09 - 2014-01-29 11:09 - 00001119 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-29 11:09 - 2014-01-29 11:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-29 11:08 - 2014-01-29 11:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Daniel\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-29 09:02 - 2014-01-29 09:01 - 24088418 _____ C:\Users\Daniel\Downloads\Web Server - Riot Decode.zip 2014-01-29 08:03 - 2013-10-28 00:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2014-01-28 18:17 - 2013-10-19 15:58 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-28 17:59 - 2013-10-19 23:10 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Adobe 2014-01-28 17:59 - 2013-10-19 15:55 - 00064408 _____ C:\Users\Daniel\AppData\Local\GDIPFONTCACHEV1.DAT 2014-01-28 17:56 - 2014-01-28 17:56 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2014-01-28 17:56 - 2014-01-28 17:53 - 00000000 ____D C:\Program Files\Common Files\Adobe 2014-01-28 17:56 - 2013-10-31 14:32 - 00000000 ____D C:\ProgramData\Adobe 2014-01-28 17:54 - 2013-10-31 14:32 - 00000000 ____D C:\Program Files (x86)\Adobe 2014-01-28 17:49 - 2014-01-28 17:49 - 00102932 ____H C:\Windows\SysWOW64\mlfcache.dat 2014-01-28 17:29 - 2014-01-27 22:02 - 00000000 ____D C:\Users\Daniel\Desktop\mbar 2014-01-28 17:16 - 2014-01-27 22:02 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-28 17:14 - 2014-01-28 16:24 - 00000000 ____D C:\Qoobox 2014-01-28 17:14 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-28 17:13 - 2014-01-28 17:13 - 00026718 _____ C:\ComboFix.txt 2014-01-28 17:07 - 2014-01-28 16:23 - 00000000 ____D C:\Windows\erdnt 2014-01-28 16:45 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-28 16:23 - 2014-01-28 16:23 - 05175619 ____R (Swearware) C:\Users\Daniel\Downloads\ComboFix.exe 2014-01-28 14:42 - 2014-01-28 14:37 - 00169060 _____ C:\Users\Daniel\Documents\lordangelomails1.txt 2014-01-28 13:24 - 2014-01-28 13:24 - 00000000 ____D C:\Users\Daniel\AppData\Local\Cosa_Nostra 2014-01-28 13:23 - 2014-01-28 13:22 - 00134947 _____ C:\Users\Daniel\Downloads\RgxTester10Exe.zip 2014-01-28 12:04 - 2014-01-28 12:04 - 00880069 _____ C:\Users\Daniel\Downloads\Reteewt v1.2.rar 2014-01-28 12:04 - 2014-01-28 12:04 - 00000000 ____D C:\Users\Daniel\Desktop\asdad 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Battle.net 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Blizzard Entertainment 2014-01-28 11:59 - 2014-01-28 11:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Battle.net 2014-01-28 11:58 - 2014-01-28 11:58 - 00000788 _____ C:\Users\Public\Desktop\Battle.net.lnk 2014-01-28 11:58 - 2014-01-28 11:58 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2014-01-28 11:55 - 2014-01-28 11:55 - 00000000 ____D C:\ProgramData\Battle.net 2014-01-28 11:54 - 2014-01-28 11:54 - 05748920 _____ (Blizzard Entertainment) C:\Users\Daniel\Downloads\Battle.net-Beta-Setup-deDE.exe 2014-01-28 10:39 - 2014-01-27 23:01 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\QuickScan 2014-01-28 07:29 - 2014-01-28 07:29 - 00000000 _____ C:\Windows\setuperr.log 2014-01-28 05:19 - 2014-01-28 05:19 - 00003901 _____ C:\Users\Daniel\Downloads\smime.p7s 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MySQL 2014-01-28 04:27 - 2014-01-28 04:27 - 00000000 ____D C:\Program Files (x86)\MySQL 2014-01-28 04:26 - 2014-01-28 04:26 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6 (1).zip 2014-01-28 04:22 - 2014-01-28 04:22 - 03505809 _____ C:\Users\Daniel\Downloads\mysql-connector-net-5.2.6.zip 2014-01-28 03:29 - 2014-01-28 03:29 - 07241860 _____ C:\Users\Daniel\Downloads\FileZilla_3.7.3_win32.zip 2014-01-28 01:38 - 2014-01-28 01:38 - 00073065 _____ C:\Users\Daniel\Downloads\FancyAsFuckToasty.zip 2014-01-28 01:38 - 2013-11-20 01:46 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2014-01-27 23:24 - 2014-01-27 23:24 - 00000000 ____D C:\Windows\pss 2014-01-27 23:24 - 2014-01-27 23:09 - 00002748 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-27 23:21 - 2013-12-03 16:05 - 00000000 ____D C:\Program Files\GIMP 2 2014-01-27 23:15 - 2013-11-27 01:02 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TS3Client 2014-01-27 23:15 - 2013-11-15 19:18 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DAEMON Tools Lite 2014-01-27 23:09 - 2014-01-27 23:09 - 00000568 _____ C:\Users\Daniel\Desktop\CCleaner.lnk 2014-01-27 23:09 - 2014-01-27 23:09 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-01-27 23:08 - 2014-01-27 23:08 - 04721920 _____ (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup410.exe 2014-01-27 23:07 - 2014-01-27 23:07 - 02347384 _____ (ESET) C:\Users\Daniel\Downloads\esetsmartinstaller_enu.exe 2014-01-27 22:34 - 2013-11-27 17:07 - 00000000 ____D C:\Users\Daniel\AppData\Local\Purplizer 2014-01-27 22:34 - 2013-11-27 00:59 - 00000000 ____D C:\Users\Daniel\AppData\Local\Overwolf 2014-01-27 22:28 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\addins 2014-01-27 22:03 - 2014-01-27 22:03 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-27 22:02 - 2014-01-27 22:02 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Daniel\Downloads\mbar-1.07.0.1009.exe 2014-01-27 00:54 - 2014-01-27 00:54 - 00033821 _____ C:\Users\Daniel\Downloads\Addition.txt 2014-01-26 19:38 - 2014-01-26 19:38 - 01104710 _____ C:\Users\Daniel\Downloads\SystemCheck_deDE.zip 2014-01-26 19:27 - 2014-01-26 19:27 - 02097134 _____ C:\Users\Daniel\Downloads\systemsurveydummyfile (6).exe 2014-01-26 19:26 - 2014-01-26 19:26 - 00000005 _____ C:\Users\Daniel\Downloads\Download 2014-01-26 19:06 - 2013-12-30 21:36 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Wireshark 2014-01-26 18:57 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\JetBrains 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\SymbolSourceSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\RefSrcSymbols 2014-01-26 18:56 - 2014-01-26 18:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\JetBrains 2014-01-26 18:53 - 2014-01-26 18:51 - 29220864 _____ C:\Users\Daniel\Downloads\dotPeekSetup-1.1.1.33.msi 2014-01-26 18:38 - 2014-01-26 18:38 - 00157234 _____ C:\Users\Daniel\Downloads\RouterReconnect_1.3.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 04689382 _____ C:\Users\Daniel\Downloads\curl-7.34.0.zip 2014-01-26 18:37 - 2014-01-26 18:37 - 00094335 _____ C:\Users\Daniel\Downloads\Fritz!Box Reconnect.rar 2014-01-26 16:49 - 2014-01-26 16:36 - 00000000 ____D C:\Users\Daniel\Documents\Rezepte 2014-01-23 09:51 - 2014-01-23 09:50 - 12322963 _____ C:\Users\Daniel\Downloads\Thread_Design_2.zip 2014-01-23 09:41 - 2014-01-23 09:41 - 01398825 _____ C:\Users\Daniel\Downloads\wg_3d_banners_vol3.zip 2014-01-23 09:38 - 2014-01-23 09:38 - 42713738 _____ C:\Users\Daniel\Downloads\Devisual's Graphics Pack.rar 2014-01-23 07:39 - 2013-12-19 13:51 - 00000107 _____ C:\Users\Daniel\AppData\Roaming\WB.CFG 2014-01-22 14:41 - 2014-01-22 14:41 - 00000000 _____ C:\Users\Daniel\Desktop\KUHDO.txt 2014-01-22 14:32 - 2014-01-22 14:31 - 00000000 ____D C:\Users\Daniel\Desktop\Lobby checker 2014-01-21 08:14 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\TubeBox 2014-01-17 12:16 - 2014-01-17 12:16 - 00092309 _____ C:\Users\Daniel\Downloads\MarkC_Windows_8.x+7_MouseFix.zip 2014-01-17 01:32 - 2014-01-17 01:32 - 00000109 _____ C:\Users\Daniel\Desktop\sentencelol.txt 2014-01-15 15:47 - 2014-01-15 15:47 - 00000749 _____ C:\Users\Public\Desktop\Battlefield 3.lnk 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2014-01-15 15:46 - 2014-01-15 15:46 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2014-01-15 15:46 - 2014-01-15 15:46 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2014-01-15 15:45 - 2013-10-31 11:23 - 00000000 ____D C:\ProgramData\Origin 2014-01-15 15:38 - 2014-01-15 15:36 - 08501736 _____ C:\Users\Daniel\Downloads\HSS-3.31-install-e-550-plain.exe 2014-01-15 15:25 - 2014-01-15 15:25 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2014-01-15 15:22 - 2014-01-15 15:22 - 00000530 _____ C:\Users\Public\Desktop\Origin.lnk 2014-01-15 15:21 - 2014-01-15 15:20 - 16952720 _____ (Electronic Arts, Inc.) C:\Users\Daniel\Downloads\OriginThinSetup.exe 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\Electronic Arts 2014-01-15 15:16 - 2014-01-15 15:16 - 00000000 ____D C:\ProgramData\EA Core 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Users\Daniel\AppData\Local\ESN 2014-01-15 15:12 - 2014-01-15 15:12 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2014-01-15 15:11 - 2014-01-15 15:11 - 03821064 _____ C:\Users\Daniel\Downloads\battlelog-web-plugins_2.3.2_130.exe 2014-01-15 14:04 - 2014-01-15 14:04 - 00012885 _____ C:\Users\Daniel\AppData\Local\recently-used.xbel 2014-01-15 14:04 - 2013-12-03 16:06 - 00000000 ____D C:\Users\Daniel\.gimp-2.8 2014-01-15 11:38 - 2014-01-15 11:38 - 01016952 _____ C:\Users\Daniel\Downloads\25273 (1).zip 2014-01-15 09:23 - 2014-01-15 09:23 - 00004705 _____ C:\Users\Daniel\Downloads\First Person Camera Fix-6508-1.7z 2014-01-15 08:46 - 2014-01-15 08:46 - 00060838 _____ C:\Users\Daniel\Downloads\SafetyLoad 1_2-46465-1-2.zip 2014-01-15 08:06 - 2014-01-15 08:06 - 00003710 _____ C:\Users\Daniel\Downloads\High Prefs and inis ugrids 5 V27 ENB version-36146-v27.rar 2014-01-15 07:58 - 2014-01-15 07:58 - 12881617 _____ C:\Users\Daniel\Downloads\RealVision_ENB_245a-30936-245a.7z 2014-01-15 07:58 - 2014-01-15 07:58 - 02342720 _____ C:\Users\Daniel\Downloads\enbseries_skyrim_v0245.zip 2014-01-15 07:54 - 2014-01-15 07:54 - 01457128 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - Weather Patch-39799-15.rar 2014-01-15 07:53 - 2014-01-15 07:53 - 00020795 _____ C:\Users\Daniel\Downloads\Supreme Storms for Climates of Tamriel 3_1-27022-3-1.rar 2014-01-15 07:51 - 2014-01-15 07:50 - 14741439 _____ C:\Users\Daniel\Downloads\RSE High v1_4-836.7z 2014-01-15 07:50 - 2014-01-15 07:50 - 00762191 _____ C:\Users\Daniel\Downloads\Dust Effects v1_0-44201-1-0.7z 2014-01-15 07:49 - 2014-01-15 07:49 - 17953454 _____ C:\Users\Daniel\Downloads\Rocking Stones Parallax for ENB - 2k BROWNISH - best one imo-38004-4-4.7z 2014-01-15 07:47 - 2014-01-15 07:47 - 16731899 _____ C:\Users\Daniel\Downloads\SkyFalls - Dragonborn Edition-40564-1-2.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 04175336 _____ C:\Users\Daniel\Downloads\HD Ivy - Original Green-30971-2-00.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 01405354 _____ C:\Users\Daniel\Downloads\SkyFalls - Animated Distant Waterfalls-40564-1-9.rar 2014-01-15 07:46 - 2014-01-15 07:46 - 00006543 _____ C:\Users\Daniel\Downloads\SkyFalls - Dawnguard Edition-40564-1-1.rar 2014-01-15 07:46 - 2014-01-15 07:45 - 28948920 _____ C:\Users\Daniel\Downloads\TreesHD_Skyrim_variation_HIGH_NEW-3812-1-6.rar 2014-01-15 07:44 - 2014-01-15 07:43 - 29112106 _____ C:\Users\Daniel\Downloads\Dragonborn addon v02-141-v0-2.7z 2014-01-15 07:43 - 2014-01-15 07:43 - 01807096 _____ C:\Users\Daniel\Downloads\Natural Grass Texture Floor-30164-1-0.zip 2014-01-15 07:37 - 2014-01-15 07:30 - 145113682 _____ C:\Users\Daniel\Downloads\Summer Edition v181-141-v1-81.7z 2014-01-15 07:29 - 2014-01-15 07:27 - 26777790 _____ C:\Users\Daniel\Downloads\Detailed_Rugs_v1-3-29608-1-3.7z 2014-01-15 07:24 - 2014-01-15 07:15 - 144349763 _____ C:\Users\Daniel\Downloads\Hectrol CAVES DELUXE HighRes Retex 4K-29145-1-0.7z 2014-01-15 07:24 - 2014-01-15 07:11 - 18920661 _____ C:\Users\Daniel\Downloads\Ruins_Clutter_Improved_v2-6-14227-2-6.7z 2014-01-15 07:13 - 2014-01-15 07:12 - 04941702 _____ C:\Users\Daniel\Downloads\Cinematic Fire FX 2-2692-2-3.zip 2014-01-14 23:09 - 2014-01-14 23:09 - 05713023 _____ C:\Users\Daniel\Downloads\Unofficial Dragonborn Patch-31083-2-0-0.7z 2014-01-14 23:08 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\Documents\Nexus Mod Manager 2014-01-14 23:08 - 2014-01-13 20:02 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2014-01-14 04:35 - 2014-01-14 04:34 - 09511604 _____ C:\Users\Daniel\Downloads\Footprints v0_99-22745-0-99.7z 2014-01-14 04:34 - 2014-01-14 04:34 - 08922372 _____ C:\Users\Daniel\Downloads\0_Pure Waters 4-6 Legendary-1111-4-6.rar 2014-01-14 04:29 - 2014-01-14 04:15 - 235701929 _____ C:\Users\Daniel\Downloads\UNP Mashup Compilation v1-20415-1.rar 2014-01-14 04:27 - 2014-01-14 04:27 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (2).7z 2014-01-14 04:21 - 2014-01-14 04:20 - 09113460 _____ C:\Users\Daniel\Downloads\UNP BASE Main body V1dot2-6709.7z 2014-01-14 04:17 - 2014-01-14 04:16 - 02178105 _____ C:\Users\Daniel\Downloads\Sharpshooter enb classic version-15105-V1.rar 2014-01-14 03:30 - 2014-01-14 03:29 - 23759325 _____ C:\Users\Daniel\Downloads\Better Vampires 6-5-9717-6-5.zip 2014-01-14 03:25 - 2014-01-14 03:25 - 00023554 _____ C:\Users\Daniel\Downloads\NEW Temptress Vampire Compatibility Update-18717-.rar 2014-01-14 03:14 - 2014-01-14 03:14 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929 (1).7z 2014-01-14 00:57 - 2014-01-14 00:57 - 00000617 _____ C:\Users\Daniel\Downloads\More Dragon Loot-10050-R4.rar 2014-01-14 00:55 - 2014-01-14 00:55 - 00001935 _____ C:\Users\Daniel\Downloads\Version 2_1-1010-2-1.zip 2014-01-14 00:47 - 2014-01-14 00:47 - 00001144 _____ C:\Users\Daniel\Downloads\More Arrows-11613-1-0.rar 2014-01-14 00:46 - 2014-01-14 00:45 - 20135641 _____ C:\Users\Daniel\Downloads\Enhanced Character Edit-12951-1-2.7z 2014-01-14 00:39 - 2014-01-14 00:39 - 04869331 _____ C:\Users\Daniel\Downloads\The Joy of Perspective Female V0 9 3 -6002-v0-9-3.rar 2014-01-14 00:35 - 2014-01-14 00:35 - 00322469 _____ C:\Users\Daniel\Downloads\Realistic Force-601-1-9.rar 2014-01-14 00:34 - 2014-01-14 00:34 - 00887469 _____ C:\Users\Daniel\Downloads\XPMS 1-92 NMM-BAIN INSTALLER-26800-1-92.7z 2014-01-14 00:31 - 2014-01-14 00:31 - 00083125 _____ C:\Users\Daniel\Downloads\The Dance of Death 4-0 Beta - Ultimate Edition-10906-4-0.7z 2014-01-14 00:26 - 2014-01-14 00:26 - 01025219 _____ C:\Users\Daniel\Downloads\UNP Bouncing Boobs-10470-1-0.rar 2014-01-14 00:21 - 2014-01-14 00:21 - 03496349 _____ C:\Users\Daniel\Downloads\360WalkRunPlus_v3_1_2-34508-3-1-2.7z 2014-01-14 00:18 - 2014-01-13 23:54 - 151736579 _____ C:\Users\Daniel\Downloads\IA v6 BETA 2-19733-6-BETA-2.7z 2014-01-14 00:15 - 2014-01-14 00:11 - 72977814 _____ C:\Users\Daniel\Downloads\Unofficial Skyrim Patch-19-2-0-0a.7z 2014-01-14 00:11 - 2014-01-14 00:10 - 29040935 _____ C:\Users\Daniel\Downloads\Immersive Sounds - Aural Assortment-49084-1-0.zip 2014-01-14 00:10 - 2014-01-14 00:10 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6 (1).zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00130583 _____ C:\Users\Daniel\Downloads\First Person 1_6-49036-1-6.zip 2014-01-14 00:08 - 2014-01-14 00:08 - 00002452 _____ C:\Users\Daniel\Downloads\0 Dragonborn-Dawnguard Compatibility Patch-60-.rar 2014-01-14 00:06 - 2014-01-14 00:01 - 43448187 _____ C:\Users\Daniel\Downloads\Enhanced Blood Textures 3_5d-60-3-5d.rar 2014-01-14 00:02 - 2014-01-14 00:02 - 00266051 _____ C:\Users\Daniel\Downloads\skse_1_06_16_installer.exe 2014-01-14 00:02 - 2014-01-14 00:02 - 00000649 _____ C:\Users\Daniel\Desktop\Skyrim (SKSE).lnk 2014-01-14 00:00 - 2014-01-13 23:59 - 07021047 _____ C:\Users\Daniel\Downloads\A Quality World Map Installer-4929.7z 2014-01-13 23:53 - 2014-01-13 23:53 - 02978304 _____ C:\Users\Daniel\Downloads\Realistic Lighting Overhaul 4_0_8_01 NMM-BAINWizard Installer-30450-4-0-8-01.7z 2014-01-13 23:52 - 2014-01-13 23:52 - 07592804 _____ C:\Users\Daniel\Downloads\Wars_in_Skyrim_-_Normal_Mode-6176-1-4-1.7z 2014-01-13 23:49 - 2014-01-13 23:38 - 119244137 _____ C:\Users\Daniel\Downloads\Temptress Complete v1_3-18717-1-3.rar 2014-01-13 23:42 - 2014-01-13 23:30 - 151991017 _____ C:\Users\Daniel\Downloads\ApachiiSkyHair_v_1_5_Full-10168-1-5-Full.7z 2014-01-13 23:34 - 2014-01-13 22:59 - 554674254 _____ C:\Users\Daniel\Downloads\SMIM v1-61-8655-1-61.7z 2014-01-13 23:19 - 2014-01-13 23:18 - 11624802 _____ C:\Users\Daniel\Downloads\No_More_Blocky_Faces-1_50-30-1-5.7z 2014-01-13 23:12 - 2014-01-13 23:12 - 00000313 _____ C:\Users\Daniel\Downloads\Proper Aiming 1_1-13652-1-1.rar 2014-01-13 23:06 - 2014-01-13 23:06 - 00230939 _____ C:\Users\Daniel\Downloads\Version 1_82 Quick Fix-18480-1-82.rar 2014-01-13 23:04 - 2014-01-13 23:03 - 11252501 _____ C:\Users\Daniel\Downloads\Version 1_82 BSA-18480-1-82.rar 2014-01-13 22:56 - 2014-01-13 22:51 - 107551867 _____ C:\Users\Daniel\Downloads\Climates Of Tamriel - V3-1-17802-3-1.zip 2014-01-13 22:42 - 2014-01-13 22:42 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk 2014-01-13 22:42 - 2014-01-13 22:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Black_Tree_Gaming 2014-01-13 22:37 - 2014-01-13 22:35 - 04136616 _____ (Black Tree Gaming ) C:\Users\Daniel\Downloads\Nexus Mod Manager-0.46.0.exe 2014-01-13 22:34 - 2014-01-13 22:29 - 85038708 _____ C:\Users\Daniel\Downloads\Noiral_CBBE_Reloaded.zip 2014-01-13 22:32 - 2014-01-13 22:32 - 01409134 _____ C:\Users\Daniel\Downloads\SkyUI_4_1-3863-4-1.7z 2014-01-13 20:02 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\My Games 2014-01-12 20:44 - 2014-01-10 20:56 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Awesomium 2014-01-12 00:42 - 2014-01-02 06:35 - 00000000 ____D C:\Users\Daniel\Desktop\LoL Modding 2014-01-11 14:39 - 2014-01-11 14:39 - 00000650 _____ C:\Users\Daniel\Downloads\Split Second Velocity.ct 2014-01-11 10:14 - 2014-01-11 10:13 - 07679554 _____ C:\Users\Daniel\Downloads\netxray.zip 2014-01-11 10:04 - 2014-01-11 09:09 - 00000319 _____ C:\Windows\WPE PRO - modified.INI 2014-01-11 09:53 - 2014-01-11 09:53 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Hex-Rays 2014-01-11 09:52 - 2014-01-11 09:51 - 16374114 _____ (Hex-Rays SA ) C:\Users\Daniel\Downloads\idafree50.exe 2014-01-11 09:52 - 2014-01-11 09:51 - 01385454 _____ C:\Users\Daniel\Downloads\idastealth_complete.rar 2014-01-11 09:45 - 2014-01-11 09:45 - 00545804 _____ C:\Users\Daniel\Downloads\fdbg0024.zip 2014-01-11 09:42 - 2014-01-11 09:41 - 06965278 _____ C:\Users\Daniel\Downloads\odbg201.zip 2014-01-11 09:14 - 2014-01-11 09:14 - 01935900 _____ C:\Users\Daniel\Downloads\OneHitKill.rar 2014-01-11 09:13 - 2014-01-11 09:13 - 01646243 _____ C:\Users\Daniel\Downloads\tsearch16b.rar 2014-01-11 09:08 - 2013-10-19 15:23 - 00000000 ____D C:\Users\Daniel\AppData\Local\VirtualStore 2014-01-11 07:45 - 2013-10-19 17:07 - 00000000 ____D C:\Users\Daniel\Documents\My Cheat Tables 2014-01-11 07:38 - 2014-01-11 07:38 - 00000607 _____ C:\Users\Daniel\Desktop\Cheat Engine.lnk 2014-01-11 07:35 - 2014-01-11 07:34 - 08065840 _____ (Cheat Engine ) C:\Users\Daniel\Downloads\CheatEngine63.exe 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\Users\Daniel\Documents\Elder Scrolls Online 2014-01-10 20:30 - 2014-01-10 20:30 - 00000000 ____D C:\ProgramData\Elder Scrolls Online 2014-01-09 16:48 - 2014-01-09 16:38 - 190488919 _____ C:\Users\Daniel\Downloads\RusselZs League of Draven (3.10a Lucian).rar 2014-01-09 15:58 - 2014-01-09 15:58 - 00414569 _____ C:\Users\Daniel\Downloads\Raf Manager.zip 2014-01-08 06:59 - 2014-01-08 06:59 - 02653910 _____ C:\Users\Daniel\Downloads\9221.zip 2014-01-08 06:55 - 2014-01-08 06:54 - 24309760 _____ C:\Users\Daniel\Downloads\LauncherSetup.msi 2014-01-07 18:48 - 2013-10-20 09:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Apple Computer 2014-01-06 23:38 - 2014-01-06 23:38 - 00033323 _____ C:\Users\Daniel\Downloads\Prodiction.lua 2014-01-06 21:24 - 2014-01-06 21:24 - 01310829 _____ C:\Users\Daniel\Downloads\19913.zip 2014-01-06 21:24 - 2014-01-06 21:24 - 01304629 _____ C:\Users\Daniel\Downloads\6471.zip 2014-01-06 21:21 - 2014-01-06 21:20 - 01016952 _____ C:\Users\Daniel\Downloads\25273.zip 2014-01-06 18:16 - 2014-01-06 18:16 - 00001521 _____ C:\Users\Daniel\Downloads\UBot_Studio_Xing_Bot.ubot 2014-01-06 17:42 - 2014-01-06 17:42 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5 (1).zip 2014-01-06 17:20 - 2014-01-06 17:20 - 00026395 _____ C:\Users\Daniel\Downloads\OpenPOP.zip 2014-01-06 17:05 - 2014-01-06 17:05 - 01117042 _____ C:\Users\Daniel\Downloads\OpenPop.NET 2.0.5.zip 2014-01-06 16:57 - 2014-01-06 16:57 - 00027152 _____ C:\Users\Daniel\Downloads\ReadPop3EmailsASP.Net.zip 2014-01-06 16:20 - 2013-11-08 19:40 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-06 16:16 - 2014-01-06 16:14 - 00000000 ____D C:\Users\Daniel\Documents\sliqemailconfirmerlite 2014-01-06 16:06 - 2014-01-06 16:06 - 00003165 _____ C:\Users\Daniel\Desktop\SliQ Link Clicker Lite.lnk 2014-01-06 16:06 - 2014-01-06 16:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SliQTools 2014-01-06 16:05 - 2013-10-20 09:39 - 00000000 ____D C:\Users\Daniel\AppData\Local\Downloaded Installations 2014-01-06 16:03 - 2014-01-06 16:03 - 06043285 _____ (SliQTools ) C:\Users\Daniel\Downloads\sliqlinkclickerlite.exe 2014-01-05 23:58 - 2013-11-14 22:45 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\TeamViewer 2014-01-05 23:26 - 2013-10-19 17:09 - 00009843 _____ C:\Users\Daniel\Documents\index.html 2014-01-03 23:54 - 2014-01-03 23:54 - 00042184 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys 2014-01-03 22:52 - 2014-01-03 22:52 - 00008657 _____ C:\Users\Daniel\Downloads\DownloadSVN13.zip 2014-01-03 21:30 - 2014-01-03 21:30 - 00186054 _____ C:\Users\Daniel\Downloads\FsbExtractor13.07.23.rar 2014-01-03 21:18 - 2014-01-03 21:17 - 26578452 _____ C:\Users\Daniel\Downloads\Unreal Tournament Announcer Mod (LoL) V. 2.1.0.7.zip 2014-01-03 19:15 - 2013-12-29 19:13 - 00010567 _____ C:\Users\Daniel\Documents\test.html 2014-01-03 17:16 - 2014-01-03 17:16 - 00001172 _____ C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-01-03 17:16 - 2014-01-03 17:16 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2014-01-03 16:34 - 2013-10-28 00:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-02 21:03 - 2014-01-02 21:03 - 01530695 _____ C:\Users\Daniel\Downloads\861.zip 2014-01-02 20:41 - 2014-01-02 20:41 - 00197483 _____ C:\Users\Daniel\Downloads\gimp-dds-win64-3.0.1.zip 2014-01-02 20:34 - 2014-01-02 20:34 - 00253076 _____ C:\Users\Daniel\Downloads\2093 (1).zip 2014-01-02 14:42 - 2014-01-06 20:41 - 00025203 _____ C:\xPRiiME.properties 2014-01-02 12:16 - 2014-01-02 12:14 - 33901910 _____ C:\Users\Daniel\Downloads\fmoddesigner44427win-installer.exe 2014-01-02 12:11 - 2013-12-31 02:16 - 00000000 ____D C:\Users\Daniel\AppData\Local\FMOD Studio 2014-01-02 12:00 - 2014-01-02 12:00 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext (1).zip 2014-01-02 11:30 - 2014-01-02 11:30 - 02785220 _____ C:\Users\Daniel\Downloads\2622.zip 2014-01-02 10:28 - 2014-01-02 10:28 - 00272516 _____ C:\Users\Daniel\Downloads\yaybatch.zip 2014-01-02 10:22 - 2014-01-02 10:22 - 01923290 _____ C:\Users\Daniel\Downloads\cdex_151.zip 2014-01-02 09:15 - 2014-01-02 09:14 - 05015064 _____ C:\Users\Daniel\Downloads\MusicPlayerEx-Full-02-04-2013.7z 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32.zip 2014-01-02 08:58 - 2014-01-02 08:58 - 00377883 _____ C:\Users\Daniel\Downloads\celt011-win32 (1).zip 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:06 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ 2014-01-02 07:06 - 2014-01-02 07:05 - 07598942 _____ C:\Users\Daniel\Downloads\npp.6.5.3.Installer.exe 2014-01-02 06:27 - 2014-01-02 06:26 - 06709836 _____ C:\Users\Daniel\Downloads\SIU 3.335-Lite.zip 2014-01-02 03:17 - 2014-01-02 03:15 - 53464955 _____ C:\Users\Daniel\Downloads\wintermint.rar 2014-01-02 01:35 - 2014-01-02 01:35 - 01472106 _____ C:\Users\Daniel\Downloads\LOLReplay-0.8.5.2.exe 2014-01-02 01:35 - 2014-01-02 01:35 - 00000611 _____ C:\Users\Public\Desktop\LOL Recorder.lnk 2013-12-31 17:12 - 2013-11-27 17:36 - 00001582 _____ C:\Windows\Sandboxie.ini 2013-12-31 06:52 - 2013-12-31 06:52 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00002076 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\ProgramData\Avira 2013-12-31 06:51 - 2013-12-31 06:51 - 00000000 ____D C:\Program Files (x86)\Avira 2013-12-31 06:48 - 2013-12-31 06:41 - 129598176 _____ C:\Users\Daniel\Downloads\avira_free_antivirus_de.exe 2013-12-31 05:54 - 2013-12-31 05:53 - 03030680 _____ (Softbyte Labs, Inc. ) C:\Users\Daniel\Downloads\BlackWidow_Setup.exe 2013-12-31 05:47 - 2013-12-31 05:46 - 00253076 _____ C:\Users\Daniel\Downloads\2093.zip 2013-12-31 05:13 - 2013-12-31 05:13 - 00860736 _____ C:\Users\Daniel\Downloads\hexedit602.zip 2013-12-31 05:01 - 2013-12-31 05:01 - 00253442 _____ C:\Users\Daniel\Downloads\1209303036_datexpl.rar 2013-12-31 04:58 - 2013-12-31 04:58 - 00018023 _____ C:\Users\Daniel\Downloads\FTL UnPacker 1.0.1.zip 2013-12-31 04:54 - 2013-12-31 04:53 - 11147144 _____ (Adobe Systems, Inc.) C:\Users\Daniel\Downloads\flashplayer_11_sa_debug.exe 2013-12-31 04:53 - 2013-12-31 04:52 - 02179506 _____ (StandaloneFlashPlayer.com ) C:\Users\Daniel\Downloads\standaloneflashplayer_setup.exe 2013-12-31 02:32 - 2013-12-31 02:32 - 10807547 _____ C:\Users\Daniel\Downloads\fmodsandbox43505win-installer.exe 2013-12-31 02:14 - 2013-12-31 02:09 - 79700009 _____ C:\Users\Daniel\Downloads\fmodstudio10211win-installer.exe 2013-12-31 02:09 - 2013-12-31 02:09 - 00055201 _____ C:\Users\Daniel\Downloads\fsbext.zip Some content of TEMP: ==================== C:\Users\Daniel\AppData\Local\Temp\avgnt.exe C:\Users\Daniel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-30 08:54 ==================== End Of Log ============================ Ich möchte mich an dieser Stelle nochmal ganz herzlich bei Dir bedanken! Ich fühle mich wieder um einiges sicherer! Geändert von PRiiME (30.01.2014 um 13:01 Uhr) |
31.01.2014, 08:44 | #10 |
/// the machine /// TB-Ausbilder | Accountzugriffe aus Tokyo Java updaten. Den einen Fund von ESET manuell löschen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.02.2014, 16:35 | #11 |
| Accountzugriffe aus Tokyo Alles erledigt. An dieser Stelle noch einmal vielen vielen Dank ! |
03.02.2014, 16:10 | #12 |
/// the machine /// TB-Ausbilder | Accountzugriffe aus Tokyo Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |