![]() |
|
Netzwerk und Hardware: Adware/Trojaner Problem im Browser/SteamWindows 7 Hilfe zu Motherboards, CPUs, Lüfter, Raid-Controller, Digitalkameras, Treiber usw. Bitte alle relevanten Angaben zur Hardware machen. Welche Hardware habe ich? Themen zum Trojaner Entfernen oder Viren Beseitigung bitte in den Bereinigungsforen des Trojaner-Boards posten. |
![]() | #4 |
![]() | ![]() Adware/Trojaner Problem im Browser/Steam FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2014 01 Ran by Kevin (administrator) on DEKEV on 21-06-2014 23:16:16 Running from C:\Users\Kevin\AppData\Local\Microsoft\Windows\INetCache\IE\JG65OJ4A Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe () C:\Users\Kevin\AppData\Local\5ff3664609415b50c1185174b2c80442\ClipboardJRESprite.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Hewlett-Packard ) C:\Program Files\IDT\WDM\Beats64.exe (Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe () C:\Users\Kevin\AppData\Local\5ff3664609415b50c1185174b2c80442\DashboardLogRepository.exe (Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\main.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Eyeo GmbH) C:\Program Files\Adblock Plus for IE\AdblockPlusEngine.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2012-08-23] (Hewlett-Packard ) HKLM\...\Run: [ProfilerU] => C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek) HKLM\...\Run: [SaiMfd] => C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1179576 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-11-13] (IDT, Inc.) HKLM-x32\...\Run: [BrowserSafeguard] => "C:\Program Files (x86)\Browsersafeguard\BrowserSafeguard.exe" HKLM-x32\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-05-13] (LogMeIn Inc.) HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585048 2014-05-31] (Razer Inc.) HKLM-x32\...\Run: [RazerGameBooster] => C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe [61152 2014-02-25] (Razer Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-05-13] (Hewlett-Packard) HKU\S-1-5-21-914549682-461940930-3427488505-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21446272 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-914549682-461940930-3427488505-1001\...\Run: [ValueAppsTrayIcon] => C:\Users\Kevin\AppData\Local\ValueApps\ValueAppsTrayIcon.exe HKU\S-1-5-21-914549682-461940930-3427488505-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1754816 2014-05-29] (Valve Corporation) HKU\S-1-5-21-914549682-461940930-3427488505-1001\...\Run: [SPDriver] => C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.exe HKU\S-1-5-21-914549682-461940930-3427488505-1001\...\MountPoints2: {95a512eb-e6ae-11e3-bea1-78e3b5c4e414} - "F:\INSTALL.EXE" ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:11416 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {2ECE604F-97BB-4E9C-9F81-765824E936E7} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_ir_14_21_ff&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CzyyCtCyE0AtDtD0FtN0D0Tzu0SzzyByCtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtCtByBtDtD0DzztG0Azy0F0DtGtCzyzzzytG0ByDzytBtGyEyC0BtCyByByE0EtAtB0FtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0CzyzyyB0BzzzztGzyyD0F0CtGtB0BtC0CtGzzyByB0AtGyByBzz0D0F0E0F0EtDtByB0B2Q&cr=1166865410&ir= SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_ir_14_21_ff&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CzyyCtCyE0AtDtD0FtN0D0Tzu0SzzyByCtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtCtByBtDtD0DzztG0Azy0F0DtGtCzyzzzytG0ByDzytBtGyEyC0BtCyByByE0EtAtB0FtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0CzyzyyB0BzzzztGzyyD0F0CtGtB0BtC0CtGzzyByB0AtGyByBzz0D0F0E0F0EtDtByB0B2Q&cr=1166865410&ir= SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {2ECE604F-97BB-4E9C-9F81-765824E936E7} URL = SearchScopes: HKCU - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_ir_14_21_ff&cd=2XzuyEtN2Y1L1Qzu0AyE0D0BtAtDzz0CzyyCtCyE0AtDtD0FtN0D0Tzu0SzzyByCtN1L2XzutBtFtBtDtFtCyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyCtCtByBtDtD0DzztG0Azy0F0DtGtCzyzzzytG0ByDzytBtGyEyC0BtCyByByE0EtAtB0FtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0CzyzyyB0BzzzztGzyyD0F0CtGtB0BtC0CtGzzyByB0AtGyByBzz0D0F0E0F0EtDtByB0B2Q&cr=1166865410&ir= BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - No File BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) BHO-x32: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\7z8zak32.default-1402762235071 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @videolan.org/vlc,version=2.1.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 - C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\7z8zak32.default-1402762235071\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-15] FF HKLM-x32\...\Firefox\Extensions: [shortcutff@gmail.com] - C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\6pou63rw.default\extensions\shortcutff@gmail.com FF HKCU\...\Firefox\Extensions: [{39E25CE8-D83F-6BF5-3062-2EB9A568C8B3}] - C:\Program Files (x86)\Re-markit-soft\170.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll () CHR Plugin: (Battlelog Game Launcher) - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: ( "name": "",) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: ( "name": "",) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () CHR Extension: (Google Drive) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-02] CHR Extension: (YouTube) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-02] CHR Extension: (Adblock Plus) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-17] CHR Extension: (Google-Suche) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-02] CHR Extension: (Google Wallet) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-02] CHR Extension: (Google Mail) - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-02] CHR HKLM-x32\...\Chrome\Extension: [ainbkicbloikcngphmjfpjdemblcojdd] - C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\slidebar.crx [2014-06-13] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-06-21] () [File not signed] R2 CLHNServiceForPowerDVD12; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\CLHNServiceForPowerDVD12.exe [89864 2013-06-10] (CyberLink Corp.) R2 ClipboardJRESprite.exe; C:\Users\Kevin\AppData\Local\5ff3664609415b50c1185174b2c80442\ClipboardJRESprite.exe [110592 2014-06-03] () [File not signed] R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-06-10] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [294664 2013-06-10] (CyberLink) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129336 2013-01-31] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-01-31] (Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-04-15] (LogMeIn, Inc.) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2014-05-31] () R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.) R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2012-11-13] (IDT, Inc.) [File not signed] S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-03-14] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-05-19] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-05-19] (Microsoft Corporation) S2 ValueApps; C:\Users\Kevin\AppData\Local\ValueApps\ValueApps.exe [X] ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 bnzdpikm; C:\Windows\System32\Drivers\bnzdpikm.sys [423240 2014-06-01] (AVAST Software) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-15] (CyberLink) S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-02-26] (LogMeIn Inc.) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-03-14] (Microsoft Corporation) S3 kksqrtcb; C:\Windows\System32\Drivers\kksqrtcb.sys [423240 2014-05-25] (AVAST Software) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-02-28] (NetFilterSDK.com) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R2 ntk_PowerDVD12; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMP\CLHNServer\ntk_PowerDVD12_64.sys [84168 2013-03-12] (Cyberlink Corp.) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation) R3 RegFltrX64; C:\Users\Kevin\AppData\Local\5ff3664609415b50c1185174b2c80442\RegFltrX64.sys [18064 2014-06-03] () R3 rzendpt; C:\Windows\system32\DRIVERS\rzendpt.sys [39080 2014-05-19] (Razer Inc) S3 SaiK1705; C:\Windows\system32\DRIVERS\SaiK1705.sys [180584 2012-09-20] (Saitek) R3 SaiMini; C:\Windows\System32\drivers\SaiMini.sys [25120 2013-04-30] (Saitek) R3 SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek) S3 SaiU1705; C:\Windows\System32\drivers\SaiU1705.sys [47208 2012-09-20] (Saitek) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-03-14] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation) R3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-05-19] (Microsoft Corporation) R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation) S3 zmhtxwkn; C:\Windows\System32\Drivers\zmhtxwkn.sys [423240 2014-06-18] (AVAST Software) R1 {3f538614-b636-4023-9ec2-564ada4b07b3}w64; C:\Windows\System32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys [61112 2014-06-20] (StdLib) R1 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64; C:\Windows\System32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys [61112 2014-05-22] (StdLib) R1 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64; C:\Windows\System32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys [61112 2014-06-11] (StdLib) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S2 SPDRIVER_1.36.1.172; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1.36.1.172\jsdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-21 23:04 - 2014-06-21 23:16 - 00000000 ____D () C:\FRST 2014-06-21 23:02 - 2014-06-21 23:02 - 00073847 _____ () C:\Users\Kevin\Downloads\FRST64.exe 2014-06-21 22:58 - 2014-06-21 22:58 - 00000299 _____ () C:\WINDOWS\setupact.log 2014-06-21 22:58 - 2014-06-21 22:58 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-06-21 14:17 - 2014-06-21 14:17 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio 2014-06-21 13:10 - 2014-06-21 13:10 - 00262578 _____ (Thisisu) C:\Users\Kevin\Downloads\JRT.exe 2014-06-21 12:49 - 2014-06-21 12:59 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-06-21 12:49 - 2014-06-21 12:49 - 00001121 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-21 12:49 - 2014-06-21 12:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-21 12:49 - 2014-06-21 12:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-21 12:49 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-06-21 12:49 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2014-06-21 12:49 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-06-21 11:52 - 2014-06-21 11:52 - 00000000 ____D () C:\Program Files\Adblock Plus for IE 2014-06-21 09:56 - 2014-06-21 09:56 - 00004471 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_60-b19.log 2014-06-21 09:56 - 2014-06-21 09:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-06-21 08:36 - 2014-06-21 08:36 - 03250820 _____ () C:\Users\Kevin\Downloads\Persobuilder_v1.5.rar 2014-06-21 07:53 - 2014-06-21 07:53 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kevin\Downloads\AdwCleaner - CHIP-Installer (1).exe 2014-06-21 07:46 - 2014-06-21 13:12 - 00049132 _____ () C:\WINDOWS\PFRO.log 2014-06-21 07:19 - 2014-06-21 13:12 - 00000000 ____D () C:\AdwCleaner 2014-06-21 07:19 - 2014-06-21 07:19 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kevin\Downloads\AdwCleaner - CHIP-Installer.exe 2014-06-21 07:19 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll 2014-06-21 06:56 - 2014-06-20 15:28 - 00061112 _____ (StdLib) C:\WINDOWS\system32\Drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys 2014-06-19 16:44 - 2014-06-19 16:44 - 00000000 ____D () C:\Games 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\Users\Kevin\Documents\Nexus Mod Manager 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Black_Tree_Gaming 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\Program Files\Nexus Mod Manager 2014-06-19 16:41 - 2014-06-19 16:41 - 04258056 _____ (Black Tree Gaming ) C:\Users\Kevin\Downloads\Nexus Mod Manager-0.50.3.exe 2014-06-19 16:30 - 2014-06-19 16:59 - 00000000 ____D () C:\Users\Kevin\Desktop\Skyrim Mods 2014-06-18 19:10 - 2014-06-18 19:10 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Skyrim 2014-06-18 19:08 - 2014-06-18 19:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911 2014-06-18 19:05 - 2014-06-18 19:05 - 00018473 _____ () C:\WINDOWS\DirectX.log 2014-06-18 19:02 - 2014-06-20 21:34 - 00000000 ____D () C:\Program Files (x86)\The Elder Scrolls V Skyrim 2014-06-18 17:22 - 2014-06-18 17:22 - 00039256 _____ () C:\Users\Kevin\Documents\cc_20140618_172217.reg 2014-06-18 17:16 - 2014-06-21 22:58 - 00787646 _____ () C:\WINDOWS\WindowsUpdate.log 2014-06-18 17:11 - 2014-06-18 17:12 - 00000198 _____ () C:\Users\Kevin\Desktop\GoT.txt 2014-06-18 16:02 - 2014-06-18 16:02 - 00423240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\zmhtxwkn.sys 2014-06-16 16:03 - 2013-10-24 06:51 - 00765824 _____ (Razer USA Ltd) C:\WINDOWS\SysWOW64\RzMwApi.dll 2014-06-15 19:59 - 2014-06-15 19:59 - 00002951 _____ () C:\Users\Kevin\Desktop\Outcome.lnk 2014-06-15 19:59 - 2014-06-15 19:59 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outcome 2014-06-15 19:59 - 2014-06-15 19:59 - 00000000 ____D () C:\Program Files (x86)\Outcome 2014-06-14 12:57 - 2014-06-14 17:18 - 00000000 ____D () C:\ProgramData\5fc649bd8c3a8802 2014-06-13 09:49 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-06-13 09:49 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-06-13 09:49 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2014-06-13 09:49 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2014-06-13 09:49 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-06-13 09:49 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-06-13 09:49 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-06-13 09:49 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-06-13 09:49 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-06-13 09:49 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll 2014-06-13 09:49 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-06-13 09:49 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-06-13 09:49 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-06-13 09:49 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-06-13 09:49 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-06-13 09:49 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-06-13 09:49 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-06-13 09:49 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-06-13 09:49 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-06-13 09:49 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-06-13 09:49 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-06-13 09:49 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-06-13 09:49 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-06-13 09:49 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-06-13 09:49 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-06-13 09:49 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-06-13 09:49 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-06-13 09:49 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-06-13 09:49 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-06-13 09:49 - 2014-02-06 13:30 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll 2014-06-13 09:49 - 2014-02-06 13:07 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 2014-06-13 09:49 - 2014-02-06 13:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll 2014-06-13 09:49 - 2014-02-06 12:56 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 2014-06-13 09:49 - 2014-02-06 12:49 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe 2014-06-13 09:49 - 2014-02-06 12:48 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe 2014-06-13 09:49 - 2014-02-06 12:17 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll 2014-06-13 09:49 - 2014-02-06 12:00 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll 2014-06-13 09:49 - 2014-02-06 11:52 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2014-06-13 09:49 - 2014-02-06 11:52 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll 2014-06-13 09:49 - 2014-02-06 11:47 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe 2014-06-13 09:49 - 2014-02-06 11:25 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll 2014-06-13 09:48 - 2014-05-10 05:46 - 02151424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2014-06-13 09:48 - 2014-05-10 05:22 - 01312256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2014-06-13 09:48 - 2014-05-09 01:06 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys 2014-06-13 09:48 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2014-06-13 09:48 - 2014-05-03 09:14 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-06-13 09:48 - 2014-05-03 06:21 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-06-13 09:48 - 2014-05-03 06:07 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-06-13 09:48 - 2014-05-03 05:41 - 00921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-06-13 09:48 - 2014-05-03 05:38 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-06-13 09:48 - 2014-04-30 13:16 - 01336648 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2014-06-13 09:48 - 2014-04-30 05:51 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2014-06-13 09:48 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll 2014-06-13 09:48 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 2014-06-13 09:48 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll 2014-06-13 09:48 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll 2014-06-13 09:48 - 2014-04-18 11:32 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-06-13 09:48 - 2014-04-18 10:58 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-06-13 09:48 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll 2014-06-13 09:48 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2014-06-13 09:48 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2014-06-13 09:48 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2014-06-13 09:48 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2014-06-13 09:48 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 2014-06-13 09:48 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll 2014-06-13 09:48 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 2014-06-13 09:48 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll 2014-06-13 09:48 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll 2014-06-13 09:48 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys 2014-06-13 09:48 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll 2014-06-13 09:48 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll 2014-06-13 09:48 - 2014-04-09 06:35 - 01411584 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-06-13 09:48 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2014-06-13 09:48 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys 2014-06-13 09:48 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2014-06-13 09:48 - 2014-04-06 18:34 - 00275800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys 2014-06-13 09:48 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll 2014-06-13 09:48 - 2014-04-06 18:31 - 21268952 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2014-06-13 09:48 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2014-06-13 09:48 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys 2014-06-13 09:48 - 2014-04-06 18:20 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2014-06-13 09:48 - 2014-04-06 18:20 - 00233912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2014-06-13 09:48 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe 2014-06-13 09:48 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll 2014-06-13 09:48 - 2014-04-06 17:22 - 18755672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2014-06-13 09:48 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 02144984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2014-06-13 09:48 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2014-06-13 09:48 - 2014-04-06 16:10 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-06-13 09:48 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\srclient.dll 2014-06-13 09:48 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll 2014-06-13 09:48 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 2014-06-13 09:48 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rstrui.exe 2014-06-13 09:48 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srclient.dll 2014-06-13 09:48 - 2014-04-06 13:55 - 16872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2014-06-13 09:48 - 2014-04-06 13:54 - 12711424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-06-13 09:48 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll 2014-06-13 09:48 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2014-06-13 09:48 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2014-06-13 09:48 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2014-06-13 09:48 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2014-06-13 09:48 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2014-06-13 09:48 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2014-06-13 09:48 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 2014-06-13 09:48 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll 2014-06-13 09:48 - 2014-04-03 10:12 - 02124840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll 2014-06-13 09:48 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll 2014-06-13 09:48 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll 2014-06-13 09:48 - 2014-04-03 09:59 - 02518872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2014-06-13 09:48 - 2014-04-03 09:59 - 00428888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2014-06-13 09:48 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll 2014-06-13 09:48 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll 2014-06-13 09:48 - 2014-04-03 05:53 - 01797896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll 2014-06-13 09:48 - 2014-04-03 04:53 - 04269056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 2014-06-13 09:48 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2014-06-13 09:48 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll 2014-06-13 09:48 - 2014-04-03 04:23 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-06-13 09:48 - 2014-04-03 04:23 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2014-06-13 09:48 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tlscsp.dll 2014-06-13 09:48 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\tlscsp.dll 2014-06-13 09:48 - 2014-04-01 08:23 - 00384856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2014-06-13 09:48 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2014-06-13 09:48 - 2014-03-31 02:41 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll 2014-06-13 09:48 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll 2014-06-13 09:48 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll 2014-06-13 09:48 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll 2014-06-13 09:48 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 2014-06-13 09:48 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll 2014-06-13 09:48 - 2014-03-31 00:11 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll 2014-06-13 09:48 - 2014-03-30 23:47 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe 2014-06-13 09:48 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe 2014-06-13 09:48 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2014-06-13 09:48 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 2014-06-13 09:48 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2014-06-13 09:48 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll 2014-06-13 09:48 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2014-06-13 09:48 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll 2014-06-13 09:48 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll 2014-06-13 09:48 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe 2014-06-13 09:48 - 2014-03-25 00:58 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2014-06-13 09:48 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2014-06-13 09:48 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2014-06-13 09:48 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2014-06-13 09:48 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll 2014-06-13 09:48 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys 2014-06-13 09:48 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2014-06-13 09:48 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll 2014-06-13 09:48 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll 2014-06-13 09:48 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll 2014-06-13 09:48 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2014-06-13 09:48 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2014-06-13 09:48 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 2014-06-13 09:48 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2014-06-13 09:48 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll 2014-06-13 09:48 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll 2014-06-13 09:48 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll 2014-06-13 09:48 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll 2014-06-13 09:48 - 2014-03-18 10:19 - 00077312 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys 2014-06-13 09:48 - 2014-03-18 10:18 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xusb22.sys 2014-06-13 09:48 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2014-06-13 09:48 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2014-06-13 09:48 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll 2014-06-13 09:48 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll 2014-06-13 09:48 - 2014-03-17 05:01 - 00486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv 2014-06-13 09:48 - 2014-03-17 04:47 - 01025024 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll 2014-06-13 09:48 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv 2014-06-13 09:48 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll 2014-06-13 09:48 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll 2014-06-13 09:48 - 2014-03-06 14:42 - 00310616 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys 2014-06-13 09:46 - 2014-06-13 09:46 - 00000000 ____D () C:\Users\Kevin\AppData\Local\5ff3664609415b50c1185174b2c80442 2014-06-13 09:46 - 2014-06-11 15:36 - 00061112 _____ (StdLib) C:\WINDOWS\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys 2014-06-13 09:46 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvcfg.exe 2014-06-13 09:46 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe 2014-06-13 09:46 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvinst.exe 2014-06-13 09:46 - 2014-05-01 15:31 - 03048904 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2014-06-13 09:46 - 2014-05-01 15:31 - 00055328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys 2014-06-13 09:46 - 2014-05-01 09:14 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2014-06-13 09:46 - 2014-05-01 09:05 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll 2014-06-13 09:46 - 2014-05-01 08:51 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2014-06-13 09:46 - 2014-05-01 07:24 - 02834944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll 2014-06-13 09:46 - 2014-04-30 06:43 - 01975296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2014-06-13 09:46 - 2014-04-30 06:26 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2014-06-13 09:46 - 2014-04-30 05:47 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2014-06-13 09:45 - 2014-06-13 09:45 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2014-06-01 17:01 - 2014-06-01 17:01 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2014-06-01 17:01 - 2014-06-01 17:01 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Ubisoft Game Launcher 2014-06-01 17:01 - 2014-06-01 17:01 - 00000000 ____D () C:\Program Files (x86)\Ubisoft 2014-06-01 15:32 - 2014-06-01 15:32 - 00000000 ____D () C:\Users\Public\Documents\CyberLink 2014-06-01 14:33 - 2014-06-01 14:33 - 00000000 ____D () C:\Users\Kevin\AppData\Local\MFAData 2014-06-01 14:33 - 2014-06-01 14:33 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Avg2014 2014-06-01 14:33 - 2014-06-01 14:33 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-01 14:28 - 2014-06-01 14:28 - 00000000 ____D () C:\03a179c0f1e5814807fcad8a 2014-06-01 14:20 - 2014-06-01 14:20 - 00423240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\bnzdpikm.sys 2014-06-01 13:48 - 2014-06-01 13:48 - 00009756 _____ () C:\Users\Kevin\Documents\cc_20140601_134822.reg 2014-06-01 13:46 - 2014-06-01 13:46 - 00221426 _____ () C:\Users\Kevin\Documents\cc_20140601_134616.reg 2014-06-01 13:42 - 2014-06-01 13:42 - 00002772 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2014-06-01 13:42 - 2014-06-01 13:42 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-01 13:42 - 2014-06-01 13:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-06-01 13:41 - 2014-06-01 13:42 - 00000000 ____D () C:\Program Files\CCleaner 2014-06-01 13:29 - 2014-06-01 13:29 - 00000000 ____D () C:\Users\Kevin\Documents\watcherz 2014-06-01 01:06 - 2014-06-01 01:06 - 00000000 ____D () C:\Users\Kevin\Documents\WD 2014-06-01 00:58 - 2014-06-15 19:39 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Lollipop_05312258 2014-05-31 23:48 - 2014-05-31 23:48 - 00003500 _____ () C:\WINDOWS\System32\Tasks\Windows Updater 2014-05-29 20:16 - 2014-05-29 21:57 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Audacity 2014-05-29 20:16 - 2014-05-29 20:16 - 00001038 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk 2014-05-29 20:16 - 2014-05-29 20:16 - 00000000 ____D () C:\Program Files (x86)\Audacity 2014-05-29 16:44 - 2014-06-17 15:25 - 00000000 ____D () C:\Users\Kevin\Desktop\YT Stuff 2014-05-29 16:42 - 2014-05-29 16:42 - 00000000 ____D () C:\Users\Kevin\Documents\Easy h264 v0.6r 2014-05-29 16:41 - 2014-05-29 16:41 - 07965948 _____ () C:\Users\Kevin\Documents\Easy h264 v0.6r.zip 2014-05-29 14:56 - 2014-05-29 14:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H.264 Encoder 2014-05-29 14:56 - 2014-05-29 14:56 - 00000000 ____D () C:\Program Files (x86)\H.264 Encoder 2014-05-29 14:40 - 2014-05-29 14:40 - 00000000 ___RH () C:\Users\Kevin\AppData\Roaming\d7d6326212a996c14f44ad7a6216fd9e2 2014-05-29 13:59 - 2014-06-21 23:00 - 00000000 ____D () C:\Users\Kevin\AppData\Local\CrashDumps 2014-05-29 13:57 - 2014-05-29 13:57 - 00000000 ____D () C:\Users\Kevin\Documents\LoiLo 2014-05-29 13:56 - 2014-05-29 13:57 - 00000000 ____D () C:\Users\Kevin\AppData\Local\LoiLo 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLoScope 2 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLo Game Recorder 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\Program Files\LoiLo 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\Program Files (x86)\LoiLo 2014-05-29 13:55 - 2014-06-21 09:09 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Windows Live 2014-05-29 13:25 - 2014-05-29 13:25 - 00000000 ____D () C:\Users\Kevin\AppData\Local\TechSmith 2014-05-29 13:22 - 2014-05-29 13:51 - 00000000 ____D () C:\Users\Kevin\Documents\Camtasia Studio 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\TechSmith 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\ProgramData\regid.1995-08.com.techsmith 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\ProgramData\TechSmith 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\Program Files (x86)\TechSmith 2014-05-29 07:32 - 2014-05-29 07:32 - 00080384 _____ (Razer Inc) C:\WINDOWS\system32\RazerCoinstaller.dll 2014-05-29 02:47 - 2014-05-29 02:47 - 00000000 ____D () C:\Users\Kevin\Documents\IAmAlive 2014-05-29 02:14 - 2014-05-29 02:16 - 00000000 ____D () C:\Program Files (x86)\CheckPoint 2014-05-29 02:14 - 2014-05-29 02:14 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Check Point Software Technologies LTD 2014-05-29 02:14 - 2014-05-29 02:14 - 00000000 ____D () C:\ProgramData\CheckPoint 2014-05-29 02:14 - 2014-05-29 02:14 - 00000000 ____D () C:\Program Files (x86)\Check Point Software Technologies LTD 2014-05-29 02:13 - 2014-06-18 19:01 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\DAEMON Tools Lite 2014-05-29 02:12 - 2014-05-29 12:41 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2014-05-28 20:36 - 2014-05-28 20:36 - 00003154 _____ () C:\WINDOWS\System32\Tasks\UNELEVATE_12179 2014-05-26 17:21 - 2014-05-26 17:21 - 00000000 ____D () C:\Users\Kevin\Documents\Razer 2014-05-26 17:21 - 2014-05-26 17:21 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Razer_Inc 2014-05-26 17:20 - 2014-05-26 17:20 - 00002148 _____ () C:\Users\Public\Desktop\Razer Game Booster.lnk 2014-05-26 07:27 - 2014-05-22 18:26 - 00061112 _____ (StdLib) C:\WINDOWS\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys 2014-05-26 07:23 - 2014-05-28 20:19 - 00015981 _____ () C:\Users\Kevin\Documents\TombRaider.log 2014-05-25 23:48 - 2014-06-21 12:58 - 00000000 ____D () C:\Users\Kevin\AppData\Local\22482 2014-05-25 21:03 - 2014-05-25 21:03 - 00000000 ____D () C:\Users\Kevin\AppData\Local\WorldofTanks 2014-05-25 20:41 - 2014-05-25 20:44 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-05-25 20:41 - 2014-05-25 20:41 - 00423240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\kksqrtcb.sys 2014-05-25 20:06 - 2014-05-25 20:06 - 00000000 _____ () C:\autoexec.bat 2014-05-25 20:05 - 2014-05-25 21:00 - 00000000 ____D () C:\WINDOWS\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2014-05-25 20:05 - 2014-05-25 20:05 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-05-25 13:19 - 2014-05-25 13:20 - 00000000 ____D () C:\Program Files (x86)\MPP 2014-05-25 13:19 - 2014-05-25 13:19 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Genesis_05251119 2014-05-25 12:01 - 2014-05-25 12:01 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Realmware 2014-05-25 12:01 - 2014-05-25 12:01 - 00000000 ____D () C:\Program Files\Realmware 2014-05-25 11:11 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2014-05-25 11:11 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe 2014-05-25 11:11 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe 2014-05-25 11:11 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe 2014-05-24 04:33 - 2014-05-24 04:33 - 00864256 _____ (Razer Inc) C:\WINDOWS\SysWOW64\rzdevicedll.dll 2014-05-24 04:33 - 2014-05-24 04:33 - 00325120 _____ (Razer Inc) C:\WINDOWS\SysWOW64\rzaudiodll.dll 2014-05-24 00:23 - 2014-06-17 22:34 - 00290184 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2014-05-24 00:23 - 2014-05-31 12:19 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2014-05-23 23:21 - 2014-06-21 09:56 - 00000000 ____D () C:\Program Files (x86)\Java ==================== One Month Modified Files and Folders ======= 2014-06-21 23:16 - 2014-06-21 23:04 - 00000000 ____D () C:\FRST 2014-06-21 23:15 - 2014-04-30 19:56 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\uTorrent 2014-06-21 23:03 - 2014-03-02 01:43 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-914549682-461940930-3427488505-1001 2014-06-21 23:02 - 2014-06-21 23:02 - 00073847 _____ () C:\Users\Kevin\Downloads\FRST64.exe 2014-06-21 23:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-06-21 23:00 - 2014-05-29 13:59 - 00000000 ____D () C:\Users\Kevin\AppData\Local\CrashDumps 2014-06-21 23:00 - 2014-05-02 17:21 - 00003918 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D8B208A7-4413-4C1C-9D73-57E33F238ED8} 2014-06-21 22:58 - 2014-06-21 22:58 - 00000299 _____ () C:\WINDOWS\setupact.log 2014-06-21 22:58 - 2014-06-21 22:58 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-06-21 22:58 - 2014-06-18 17:16 - 00787646 _____ () C:\WINDOWS\WindowsUpdate.log 2014-06-21 22:58 - 2014-04-15 15:39 - 00000000 ___RD () C:\Users\Kevin\OneDrive 2014-06-21 22:58 - 2014-03-02 01:40 - 00001116 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-21 18:15 - 2014-03-02 01:41 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-06-21 18:14 - 2014-03-02 14:03 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Skype 2014-06-21 17:55 - 2014-03-02 01:40 - 00001120 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-21 17:50 - 2014-05-03 12:41 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-06-21 14:21 - 2014-05-01 12:47 - 00000000 ____D () C:\Users\Kevin\AppData\Local\ArmA 2 OA 2014-06-21 14:18 - 2014-05-01 12:47 - 00000000 ____D () C:\Users\Kevin\Documents\ArmA 2 2014-06-21 14:17 - 2014-06-21 14:17 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio 2014-06-21 13:38 - 2014-03-22 17:56 - 00000000 ____D () C:\Users\Kevin\AppData\Local\LogMeIn Hamachi 2014-06-21 13:12 - 2014-06-21 07:46 - 00049132 _____ () C:\WINDOWS\PFRO.log 2014-06-21 13:12 - 2014-06-21 07:19 - 00000000 ____D () C:\AdwCleaner 2014-06-21 13:12 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-06-21 13:10 - 2014-06-21 13:10 - 00262578 _____ (Thisisu) C:\Users\Kevin\Downloads\JRT.exe 2014-06-21 13:04 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Camera 2014-06-21 13:04 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-06-21 12:59 - 2014-06-21 12:49 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-06-21 12:58 - 2014-05-25 23:48 - 00000000 ____D () C:\Users\Kevin\AppData\Local\22482 2014-06-21 12:58 - 2014-04-28 16:07 - 00000000 ____D () C:\temp 2014-06-21 12:49 - 2014-06-21 12:49 - 00001121 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-21 12:49 - 2014-06-21 12:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-21 12:49 - 2014-06-21 12:49 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-21 11:52 - 2014-06-21 11:52 - 00000000 ____D () C:\Program Files\Adblock Plus for IE 2014-06-21 11:52 - 2013-04-03 17:09 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-21 09:56 - 2014-06-21 09:56 - 00004471 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_60-b19.log 2014-06-21 09:56 - 2014-06-21 09:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-06-21 09:56 - 2014-05-23 23:21 - 00000000 ____D () C:\Program Files (x86)\Java 2014-06-21 09:56 - 2014-03-02 09:15 - 00000000 ____D () C:\ProgramData\Oracle 2014-06-21 09:09 - 2014-05-29 13:55 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Windows Live 2014-06-21 08:36 - 2014-06-21 08:36 - 03250820 _____ () C:\Users\Kevin\Downloads\Persobuilder_v1.5.rar 2014-06-21 07:53 - 2014-06-21 07:53 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kevin\Downloads\AdwCleaner - CHIP-Installer (1).exe 2014-06-21 07:46 - 2014-05-03 12:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-21 07:46 - 2014-04-30 22:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-21 07:21 - 2014-05-02 17:47 - 00001381 _____ () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-06-21 07:20 - 2014-05-18 01:07 - 00000000 ____D () C:\Users\Kevin\Desktop\Ordner f. Ordner des Ordners 2014-06-21 07:20 - 2014-05-03 12:31 - 00001080 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-21 07:20 - 2014-03-14 21:59 - 00001014 _____ () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-06-21 07:20 - 2014-03-02 01:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-06-21 07:20 - 2013-08-22 15:25 - 00000194 _____ () C:\WINDOWS\win.ini 2014-06-21 07:19 - 2014-06-21 07:19 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kevin\Downloads\AdwCleaner - CHIP-Installer.exe 2014-06-20 21:34 - 2014-06-18 19:02 - 00000000 ____D () C:\Program Files (x86)\The Elder Scrolls V Skyrim 2014-06-20 19:03 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-06-20 19:00 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-06-20 15:40 - 2014-03-16 15:04 - 00003158 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForKevin 2014-06-20 15:40 - 2014-03-16 15:04 - 00000344 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForKevin.job 2014-06-20 15:28 - 2014-06-21 06:56 - 00061112 _____ (StdLib) C:\WINDOWS\system32\Drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys 2014-06-20 00:07 - 2014-03-14 21:47 - 00000000 ____D () C:\Users\Kevin 2014-06-19 16:59 - 2014-06-19 16:30 - 00000000 ____D () C:\Users\Kevin\Desktop\Skyrim Mods 2014-06-19 16:44 - 2014-06-19 16:44 - 00000000 ____D () C:\Games 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\Users\Kevin\Documents\Nexus Mod Manager 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Black_Tree_Gaming 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager 2014-06-19 16:42 - 2014-06-19 16:42 - 00000000 ____D () C:\Program Files\Nexus Mod Manager 2014-06-19 16:41 - 2014-06-19 16:41 - 04258056 _____ (Black Tree Gaming ) C:\Users\Kevin\Downloads\Nexus Mod Manager-0.50.3.exe 2014-06-19 16:05 - 2014-03-02 01:52 - 00000000 ____D () C:\ProgramData\Origin 2014-06-18 19:10 - 2014-06-18 19:10 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Skyrim 2014-06-18 19:10 - 2014-03-07 21:47 - 00000000 ____D () C:\Users\Kevin\Documents\My Games 2014-06-18 19:08 - 2014-06-18 19:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razor 1911 2014-06-18 19:05 - 2014-06-18 19:05 - 00018473 _____ () C:\WINDOWS\DirectX.log 2014-06-18 19:01 - 2014-05-29 02:13 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\DAEMON Tools Lite 2014-06-18 17:22 - 2014-06-18 17:22 - 00039256 _____ () C:\Users\Kevin\Documents\cc_20140618_172217.reg 2014-06-18 17:21 - 2014-03-29 19:35 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\TS3Client 2014-06-18 17:12 - 2014-06-18 17:11 - 00000198 _____ () C:\Users\Kevin\Desktop\GoT.txt 2014-06-18 16:02 - 2014-06-18 16:02 - 00423240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\zmhtxwkn.sys 2014-06-17 22:34 - 2014-05-24 00:23 - 00290184 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe 2014-06-17 22:34 - 2014-03-02 10:44 - 00290184 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.xtr 2014-06-17 22:33 - 2014-03-02 10:43 - 00280904 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0 2014-06-17 17:50 - 2014-05-17 07:07 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-06-17 15:25 - 2014-05-29 16:44 - 00000000 ____D () C:\Users\Kevin\Desktop\YT Stuff 2014-06-16 15:39 - 2014-03-03 11:15 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log 2014-06-16 15:39 - 2014-03-03 11:15 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-06-16 00:52 - 2014-03-02 01:48 - 00000000 ____D () C:\Users\Kevin\Desktop\Musik 2014-06-15 19:59 - 2014-06-15 19:59 - 00002951 _____ () C:\Users\Kevin\Desktop\Outcome.lnk 2014-06-15 19:59 - 2014-06-15 19:59 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Outcome 2014-06-15 19:59 - 2014-06-15 19:59 - 00000000 ____D () C:\Program Files (x86)\Outcome 2014-06-15 19:39 - 2014-06-01 00:58 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Lollipop_05312258 2014-06-15 12:35 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-06-14 17:18 - 2014-06-14 12:57 - 00000000 ____D () C:\ProgramData\5fc649bd8c3a8802 2014-06-13 11:41 - 2013-11-14 09:27 - 01980934 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-06-13 11:41 - 2013-11-14 09:11 - 00841326 _____ () C:\WINDOWS\system32\perfh007.dat 2014-06-13 11:41 - 2013-11-14 09:11 - 00191558 _____ () C:\WINDOWS\system32\perfc007.dat 2014-06-13 11:34 - 2013-08-22 16:44 - 00369528 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-06-13 11:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-06-13 11:31 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel 2014-06-13 11:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-06-13 11:31 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\oobe 2014-06-13 11:28 - 2014-03-03 12:06 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-06-13 11:27 - 2014-03-03 12:06 - 95414520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-06-13 09:46 - 2014-06-13 09:46 - 00000000 ____D () C:\Users\Kevin\AppData\Local\5ff3664609415b50c1185174b2c80442 2014-06-13 09:45 - 2014-06-13 09:45 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2014-06-11 15:36 - 2014-06-13 09:46 - 00061112 _____ (StdLib) C:\WINDOWS\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys 2014-06-01 17:01 - 2014-06-01 17:01 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2014-06-01 17:01 - 2014-06-01 17:01 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Ubisoft Game Launcher 2014-06-01 17:01 - 2014-06-01 17:01 - 00000000 ____D () C:\Program Files (x86)\Ubisoft 2014-06-01 15:32 - 2014-06-01 15:32 - 00000000 ____D () C:\Users\Public\Documents\CyberLink 2014-06-01 14:33 - 2014-06-01 14:33 - 00000000 ____D () C:\Users\Kevin\AppData\Local\MFAData 2014-06-01 14:33 - 2014-06-01 14:33 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Avg2014 2014-06-01 14:33 - 2014-06-01 14:33 - 00000000 ____D () C:\ProgramData\MFAData 2014-06-01 14:28 - 2014-06-01 14:28 - 00000000 ____D () C:\03a179c0f1e5814807fcad8a 2014-06-01 14:20 - 2014-06-01 14:20 - 00423240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\bnzdpikm.sys 2014-06-01 13:48 - 2014-06-01 13:48 - 00009756 _____ () C:\Users\Kevin\Documents\cc_20140601_134822.reg 2014-06-01 13:46 - 2014-06-01 13:46 - 00221426 _____ () C:\Users\Kevin\Documents\cc_20140601_134616.reg 2014-06-01 13:42 - 2014-06-01 13:42 - 00002772 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2014-06-01 13:42 - 2014-06-01 13:42 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-01 13:42 - 2014-06-01 13:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-06-01 13:42 - 2014-06-01 13:41 - 00000000 ____D () C:\Program Files\CCleaner 2014-06-01 13:42 - 2014-03-27 19:46 - 00000000 ____D () C:\WINDOWS\Minidump 2014-06-01 13:42 - 2014-03-14 21:41 - 00000000 ___DC () C:\WINDOWS\Panther 2014-06-01 13:29 - 2014-06-01 13:29 - 00000000 ____D () C:\Users\Kevin\Documents\watcherz 2014-06-01 01:06 - 2014-06-01 01:06 - 00000000 ____D () C:\Users\Kevin\Documents\WD 2014-05-31 23:48 - 2014-05-31 23:48 - 00003500 _____ () C:\WINDOWS\System32\Tasks\Windows Updater 2014-05-31 19:23 - 2014-05-18 00:31 - 00000000 ____D () C:\Program Files (x86)\Razer 2014-05-31 12:19 - 2014-05-24 00:23 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe 2014-05-31 07:13 - 2013-08-22 17:38 - 00703992 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-05-31 07:13 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-30 16:05 - 2013-10-20 07:13 - 00000000 ____D () C:\ProgramData\Temp 2014-05-30 12:21 - 2014-06-13 09:49 - 23414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-05-30 11:45 - 2014-06-13 09:49 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-05-30 11:28 - 2014-06-13 09:49 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2014-05-30 11:20 - 2014-06-13 09:49 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-13 09:49 - 17271296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-05-30 11:08 - 2014-06-13 09:49 - 05782528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-13 09:49 - 00452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-05-30 10:46 - 2014-06-13 09:49 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-13 09:49 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-13 09:49 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll 2014-05-30 10:38 - 2014-06-13 09:49 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-13 09:49 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-05-30 10:29 - 2014-06-13 09:49 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-05-30 10:27 - 2014-06-13 09:49 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-05-30 10:23 - 2014-06-13 09:49 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-13 09:49 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-05-30 10:04 - 2014-06-13 09:49 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-13 09:49 - 00242688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-13 09:49 - 04244992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-13 09:49 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-05-30 09:54 - 2014-06-13 09:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-05-30 09:49 - 2014-06-13 09:49 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-13 09:49 - 13522944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-13 09:49 - 11725312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-13 09:49 - 01398272 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-13 09:49 - 01790976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-13 09:49 - 01143296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-13 09:49 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-13 09:49 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-05-29 21:57 - 2014-05-29 20:16 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Audacity 2014-05-29 20:16 - 2014-05-29 20:16 - 00001038 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk 2014-05-29 20:16 - 2014-05-29 20:16 - 00000000 ____D () C:\Program Files (x86)\Audacity 2014-05-29 16:42 - 2014-05-29 16:42 - 00000000 ____D () C:\Users\Kevin\Documents\Easy h264 v0.6r 2014-05-29 16:41 - 2014-05-29 16:41 - 07965948 _____ () C:\Users\Kevin\Documents\Easy h264 v0.6r.zip 2014-05-29 14:56 - 2014-05-29 14:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H.264 Encoder 2014-05-29 14:56 - 2014-05-29 14:56 - 00000000 ____D () C:\Program Files (x86)\H.264 Encoder 2014-05-29 14:40 - 2014-05-29 14:40 - 00000000 ___RH () C:\Users\Kevin\AppData\Roaming\d7d6326212a996c14f44ad7a6216fd9e2 2014-05-29 13:57 - 2014-05-29 13:57 - 00000000 ____D () C:\Users\Kevin\Documents\LoiLo 2014-05-29 13:57 - 2014-05-29 13:56 - 00000000 ____D () C:\Users\Kevin\AppData\Local\LoiLo 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLoScope 2 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLo Game Recorder 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\Program Files\LoiLo 2014-05-29 13:56 - 2014-05-29 13:56 - 00000000 ____D () C:\Program Files (x86)\LoiLo 2014-05-29 13:51 - 2014-05-29 13:22 - 00000000 ____D () C:\Users\Kevin\Documents\Camtasia Studio 2014-05-29 13:25 - 2014-05-29 13:25 - 00000000 ____D () C:\Users\Kevin\AppData\Local\TechSmith 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\TechSmith 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\ProgramData\regid.1995-08.com.techsmith 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2014-05-29 13:22 - 2014-05-29 13:22 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\ProgramData\TechSmith 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\Program Files (x86)\TechSmith 2014-05-29 12:58 - 2014-04-16 01:50 - 00000000 ____D () C:\Users\Kevin\Documents\Bandicam 2014-05-29 12:41 - 2014-05-29 02:12 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2014-05-29 12:41 - 2013-10-20 07:18 - 00000000 ____D () C:\ProgramData\CyberLink 2014-05-29 10:59 - 2014-03-02 10:44 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-05-29 07:32 - 2014-05-29 07:32 - 00080384 _____ (Razer Inc) C:\WINDOWS\system32\RazerCoinstaller.dll 2014-05-29 02:47 - 2014-05-29 02:47 - 00000000 ____D () C:\Users\Kevin\Documents\IAmAlive 2014-05-29 02:16 - 2014-05-29 02:14 - 00000000 ____D () C:\Program Files (x86)\CheckPoint 2014-05-29 02:14 - 2014-05-29 02:14 - 00000000 ____D () C:\Users\Kevin\AppData\Roaming\Check Point Software Technologies LTD 2014-05-29 02:14 - 2014-05-29 02:14 - 00000000 ____D () C:\ProgramData\CheckPoint 2014-05-29 02:14 - 2014-05-29 02:14 - 00000000 ____D () C:\Program Files (x86)\Check Point Software Technologies LTD 2014-05-28 20:36 - 2014-05-28 20:36 - 00003154 _____ () C:\WINDOWS\System32\Tasks\UNELEVATE_12179 2014-05-28 20:19 - 2014-05-26 07:23 - 00015981 _____ () C:\Users\Kevin\Documents\TombRaider.log 2014-05-26 17:21 - 2014-05-26 17:21 - 00000000 ____D () C:\Users\Kevin\Documents\Razer 2014-05-26 17:21 - 2014-05-26 17:21 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Razer_Inc 2014-05-26 17:20 - 2014-05-26 17:20 - 00002148 _____ () C:\Users\Public\Desktop\Razer Game Booster.lnk 2014-05-26 17:20 - 2014-05-18 00:38 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Razer 2014-05-26 17:20 - 2014-05-18 00:31 - 00000000 ____D () C:\ProgramData\Razer 2014-05-26 17:20 - 2014-05-18 00:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2014-05-25 21:03 - 2014-05-25 21:03 - 00000000 ____D () C:\Users\Kevin\AppData\Local\WorldofTanks 2014-05-25 21:00 - 2014-05-25 20:05 - 00000000 ____D () C:\WINDOWS\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2014-05-25 20:57 - 2013-10-20 07:22 - 00000000 ____D () C:\ProgramData\Norton 2014-05-25 20:44 - 2014-05-25 20:41 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-05-25 20:41 - 2014-05-25 20:41 - 00423240 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\kksqrtcb.sys 2014-05-25 20:06 - 2014-05-25 20:06 - 00000000 _____ () C:\autoexec.bat 2014-05-25 20:05 - 2014-05-25 20:05 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-05-25 19:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-05-25 13:20 - 2014-05-25 13:19 - 00000000 ____D () C:\Program Files (x86)\MPP 2014-05-25 13:19 - 2014-05-25 13:19 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Genesis_05251119 2014-05-25 13:19 - 2014-05-02 17:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-05-25 12:01 - 2014-05-25 12:01 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Realmware 2014-05-25 12:01 - 2014-05-25 12:01 - 00000000 ____D () C:\Program Files\Realmware 2014-05-25 11:29 - 2014-03-14 21:43 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-05-25 11:20 - 2014-03-14 21:43 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-05-24 04:33 - 2014-05-24 04:33 - 00864256 _____ (Razer Inc) C:\WINDOWS\SysWOW64\rzdevicedll.dll 2014-05-24 04:33 - 2014-05-24 04:33 - 00325120 _____ (Razer Inc) C:\WINDOWS\SysWOW64\rzaudiodll.dll 2014-05-24 00:00 - 2014-03-02 02:48 - 00000000 ____D () C:\Users\Kevin\AppData\Local\Unity 2014-05-23 22:53 - 2014-03-02 14:03 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-05-23 22:52 - 2014-03-02 14:03 - 00000000 ____D () C:\ProgramData\Skype 2014-05-23 15:46 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-05-23 15:46 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-05-23 15:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2014-05-23 15:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-05-22 18:26 - 2014-05-26 07:27 - 00061112 _____ (StdLib) C:\WINDOWS\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys Some content of TEMP: ==================== C:\Users\Kevin\AppData\Local\Temp\4fpwfdtp.dll C:\Users\Kevin\AppData\Local\Temp\Bundle.exe C:\Users\Kevin\AppData\Local\Temp\downloader.dll C:\Users\Kevin\AppData\Local\Temp\Quarantine.exe C:\Users\Kevin\AppData\Local\Temp\tmp4035.tmp.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-21 18:15 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 22/06/2014 um 09:07:47 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Kevin - DEKEV # Gestartet von : C:\Users\Kevin\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\f8b34e3b5e6e337aa6491ee3f713f8f5\adwcleaner_3.212.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Kevin\AppData\Local\Temp\OCS Datei Gelöscht : C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Mozilla Firefox v30.0 (de) [ Datei : C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\7z8zak32.default-1402762235071\prefs.js ] [ Datei : C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ] -\\ Google Chrome v33.0.1750.117 [ Datei : C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [58378 octets] - [21/06/2014 07:19:41] AdwCleaner[R1].txt - [4240 octets] - [21/06/2014 07:54:07] AdwCleaner[R2].txt - [1804 octets] - [21/06/2014 13:11:10] AdwCleaner[R3].txt - [1951 octets] - [22/06/2014 09:07:25] AdwCleaner[S0].txt - [48407 octets] - [21/06/2014 07:20:35] AdwCleaner[S1].txt - [4029 octets] - [21/06/2014 07:54:46] AdwCleaner[S2].txt - [1819 octets] - [21/06/2014 13:11:57] AdwCleaner[S3].txt - [1826 octets] - [22/06/2014 09:07:47] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1886 octets] ########## Geändert von TheSeiker (21.06.2014 um 22:19 Uhr) |