Hallo schrauber meine log datei: Code:
# AdwCleaner v3.005 - Bericht erstellt am 27/09/2013 um 19:29:21
# Updated 22/09/2013 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : engin - ERGÜN
# Gestartet von : C:\Users\engin\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Users\engin\AppData\Local\Babylon
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Babylon.xml
Datei Gelöscht : C:\Users\engin\AppData\Roaming\Mozilla\Firefox\Profiles\67mcx6lq.default\searchplugins\delta.xml
Datei Gelöscht : C:\Users\engin\AppData\Roaming\Mozilla\Firefox\Profiles\67mcx6lq.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\PIP
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16688
-\\ Mozilla Firefox v24.0 (de)
[ Datei : C:\Users\engin\AppData\Roaming\Mozilla\Firefox\Profiles\67mcx6lq.default\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://search.babylon.com/?affID=121562&babsrc=NT_ss&mntrId=7c1ab458000000000000000000000000");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Search the web (Babylon)");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Search the web (Babylon)");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=121562&babsrc=NT_ss&mntrId=7c1ab458000000000000000000000000");
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "en");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.id", "7c1ab458000000000000000000000000");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15738");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.10.0");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.10.020:16:18");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.10.0");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.babylon.com/?affID=121562&babsrc=KW_ss&mntrId=7c1ab458000000000000000000000000&q=");
*************************
AdwCleaner[R0].txt - [4725 octets] - [27/09/2013 19:23:48]
AdwCleaner[S0].txt - [4181 octets] - [27/09/2013 19:29:21]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4241 octets] ##########
Junkwire logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.3 (09.27.2013:1)
OS: Windows 8 x64
Ran by engin on 27.09.2013 at 19:59:37,96
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8218E8BC-E228-4079-8CE7-6EA6CCCEA191}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{8218E8BC-E228-4079-8CE7-6EA6CCCEA191}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{1DD3FC63-6A07-4A27-8A33-34A195FF941B}
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{340A0F1F-D9E5-4B4F-9315-9192868D5F3D}
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{3AC9173E-8EAD-412A-8C7F-8517E84FBA90}
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{68DFA1D3-B560-4E67-A014-49138589309B}
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{A824B19B-F37B-424C-A424-A92D8FDB37FE}
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{BE44EE3B-1C1E-4715-B06A-C268709121D8}
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{F89DAE0F-6E62-4D9D-A8D5-49C1039ECE54}
Successfully deleted: [Empty Folder] C:\Users\engin\appdata\local\{FBEA0A36-1288-40E1-9E49-4200066A2B66}
~~~ FireFox
Emptied folder: C:\Users\engin\AppData\Roaming\mozilla\firefox\profiles\67mcx6lq.default\minidumps [176 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.09.2013 at 20:04:01,78
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frst log:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2013
Ran by engin (administrator) on ERGÜN on 27-09-2013 20:10:56
Running from C:\Users\engin\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) c:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\windows\SysWOW64\PnkBstrA.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\Beats64.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BeatsOSDApp] - C:\Program Files\IDT\WDM\beats64.exe [37888 2012-09-19] (Hewlett-Packard )
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-09-19] (IDT, Inc.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1814440 2013-09-21] (Valve Corporation)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] - c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] - c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-02] (CyberLink Corp.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
Startup: C:\Users\engin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GpuTemp.lnk
ShortcutTarget: GpuTemp.lnk -> C:\Users\engin\AppData\Roaming\Microsoft\Installer\{0FFA85AB-D704-48A6-A009-25A0559152C3}\_1168EA9E829EB9D5F56A58.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.gametop.com/?utm_source=PoliceSupercarsRacing&utm_medium=start
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPDSK13/4
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS
SearchScopes: HKLM - {8218E8BC-E228-4079-8CE7-6EA6CCCEA191} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {140E4DF8-9E14-4A34-9577-C77561ED7883} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_client_4.5.13.0.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{87D4CFE8-D2D2-4ADF-86B4-1B860BF003F6}: [NameServer]62.109.121.2 62.109.121.1
FireFox:
========
FF ProfilePath: C:\Users\engin\AppData\Roaming\Mozilla\Firefox\Profiles\67mcx6lq.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw_1202122.dll No File
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\windows\system32\C2MP\npdivx32.dll No File
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.10.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\engin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: WOT - C:\Users\engin\AppData\Roaming\Mozilla\Firefox\Profiles\67mcx6lq.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF Extension: No Name - C:\Users\engin\AppData\Roaming\Mozilla\Firefox\Profiles\67mcx6lq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 HPConnectedRemote; c:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35232 2012-08-29] (Hewlett-Packard)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-06-16] ()
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP1\RpcAgentSrv.exe [68760 2008-12-27] (SiSoftware)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP1\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-01-07] (Duplex Secure Ltd.)
S3 CtClsFlt; \SystemRoot\system32\DRIVERS\CtClsFlt.sys [x]
S3 X6va012; \??\C:\windows\SysWOW64\Drivers\X6va012 [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-27 20:10 - 2013-09-27 20:10 - 01953854 _____ (Farbar) C:\Users\engin\Desktop\FRST64.exe
2013-09-27 20:04 - 2013-09-27 20:04 - 00001888 _____ C:\Users\engin\Desktop\JRT.txt
2013-09-27 19:59 - 2013-09-27 19:59 - 00000000 ____D C:\windows\ERUNT
2013-09-27 19:57 - 2013-09-27 19:57 - 01030305 _____ (Thisisu) C:\Users\engin\Desktop\JRT.exe
2013-09-27 19:32 - 2013-09-27 19:32 - 00004329 _____ C:\Users\engin\Desktop\AdwCleaner[S0].txt
2013-09-27 19:23 - 2013-09-27 19:33 - 00000000 ____D C:\AdwCleaner
2013-09-27 19:22 - 2013-09-27 19:22 - 01042066 _____ C:\Users\engin\Desktop\adwcleaner.exe
2013-09-26 21:59 - 2013-09-26 22:00 - 00024149 _____ C:\Users\engin\Desktop\Addition.txt
2013-09-26 21:58 - 2013-09-26 21:58 - 00000000 ____D C:\FRST
2013-09-26 18:46 - 2013-09-26 18:46 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-26 18:46 - 2013-09-26 18:46 - 00000000 ____D C:\Users\engin\AppData\Roaming\Malwarebytes
2013-09-26 18:46 - 2013-09-26 18:46 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-26 18:46 - 2013-09-26 18:46 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-26 18:46 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-09-18 12:14 - 2013-09-18 12:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-13 22:00 - 2013-09-13 22:00 - 00000000 ____D C:\windows\SysWOW64\xlive
2013-09-13 22:00 - 2013-09-13 22:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-09-13 21:59 - 2013-09-13 21:59 - 00000000 ____D C:\windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
2013-09-13 21:38 - 2013-09-13 21:38 - 00000000 ____D C:\windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2013-09-13 21:38 - 2013-09-13 21:38 - 00000000 ____D C:\Users\engin\AppData\Local\2K Games
2013-09-11 01:25 - 2013-09-11 01:25 - 00297352 _____ C:\windows\system32\FNTCACHE.DAT
2013-09-11 01:23 - 2013-08-07 07:15 - 00144896 _____ (Microsoft Corporation) C:\windows\system32\tssdisai.dll
2013-09-10 22:06 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\windows\system32\WSService.dll
2013-09-10 22:06 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\windows\system32\NotificationUI.exe
2013-09-10 22:06 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\windows\system32\sppsvc.exe
2013-09-10 22:06 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2013-09-10 22:06 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\windows\system32\sppobjs.dll
2013-09-10 22:06 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2013-09-10 22:06 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2013-09-10 22:05 - 2013-08-21 06:12 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-09-10 22:05 - 2013-08-21 06:12 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-09-10 22:05 - 2013-08-21 06:11 - 19246592 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 15404544 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 03959296 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\UXInit.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-09-10 22:05 - 2013-08-21 06:11 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-09-10 22:05 - 2013-08-21 04:34 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-09-10 22:05 - 2013-08-21 04:06 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-09-10 22:05 - 2013-08-21 04:06 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-09-10 22:05 - 2013-08-21 04:06 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 14332928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 02876928 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 02048000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-09-10 22:05 - 2013-08-21 04:05 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-09-10 22:05 - 2013-08-21 03:43 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-09-10 22:05 - 2013-08-21 01:52 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\uxtheme.dll
2013-09-10 22:05 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dam.sys
2013-09-10 22:05 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2013-09-10 22:05 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2013-09-10 22:05 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\windows\system32\sppwinob.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\windows\system32\WSClient.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\windows\system32\WSSync.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\windows\system32\sppc.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\setupcln.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2013-09-10 22:05 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSClient.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSSync.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00083968 _____ C:\windows\SysWOW64\OEMLicense.dll
2013-09-10 22:05 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2013-09-10 22:05 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2013-09-10 22:05 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\windows\SysWOW64\sppc.dll
2013-09-10 22:05 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\setupcln.dll
2013-09-10 22:05 - 2013-08-03 06:30 - 04038144 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-09-10 22:05 - 2013-07-09 10:04 - 00120144 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msgpioclx.sys
2013-09-10 22:05 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\windows\system32\WerFault.exe
2013-09-10 22:05 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFault.exe
2013-09-10 22:05 - 2013-07-09 05:57 - 00245760 _____ (Microsoft Corporation) C:\windows\SysWOW64\LocationApi.dll
2013-09-10 22:05 - 2013-07-09 00:46 - 00543744 _____ (Microsoft Corporation) C:\windows\system32\wwanmm.dll
2013-09-10 22:05 - 2013-07-09 00:46 - 00414208 _____ (Microsoft Corporation) C:\windows\system32\wwanconn.dll
2013-09-10 22:05 - 2013-07-09 00:46 - 00370688 _____ (Microsoft Corporation) C:\windows\system32\Wwanadvui.dll
2013-09-10 22:05 - 2013-07-09 00:45 - 00312832 _____ (Microsoft Corporation) C:\windows\system32\LocationApi.dll
2013-09-10 22:05 - 2013-07-06 02:16 - 01025024 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2013-09-10 22:05 - 2013-07-03 02:23 - 00778752 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2013-09-10 22:05 - 2013-07-03 02:23 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\Windows.Networking.BackgroundTransfer.dll
2013-09-10 22:05 - 2013-07-03 02:22 - 02839552 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2013-09-10 22:05 - 2013-07-03 02:22 - 01300480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2013-09-10 22:05 - 2013-07-03 02:11 - 00551424 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2013-09-10 22:05 - 2013-07-03 02:11 - 00268800 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-09-10 22:05 - 2013-07-03 02:10 - 02273792 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2013-09-10 22:05 - 2013-07-02 00:08 - 00387583 _____ C:\windows\system32\ApnDatabase.xml
2013-09-10 22:05 - 2013-07-01 00:30 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\openfiles.exe
2013-09-10 22:05 - 2013-07-01 00:29 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\openfiles.exe
2013-09-10 22:05 - 2013-06-29 08:15 - 00195416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2013-09-10 22:05 - 2013-06-29 08:15 - 00125784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2013-09-10 22:05 - 2013-06-29 07:43 - 00327512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Classpnp.sys
2013-09-10 22:05 - 2013-06-29 03:12 - 01022464 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2013-09-10 22:05 - 2013-06-26 05:01 - 00321536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\udfs.sys
2013-09-10 22:05 - 2013-06-26 04:59 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\Drivers\HdAudio.sys
2013-09-10 22:05 - 2013-06-25 00:54 - 00447488 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2013-09-10 22:05 - 2013-06-25 00:54 - 00263680 _____ (Microsoft Corporation) C:\windows\system32\wcmsvc.dll
2013-09-10 22:05 - 2013-06-25 00:54 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\wcmcsp.dll
2013-09-10 22:05 - 2013-06-19 07:36 - 00183808 _____ (Microsoft Corporation) C:\windows\system32\winmmbase.dll
2013-09-10 22:05 - 2013-06-19 07:36 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\winmm.dll
2013-09-10 22:05 - 2013-06-19 00:38 - 00160256 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmmbase.dll
2013-09-10 22:05 - 2013-06-19 00:38 - 00125440 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmm.dll
2013-09-10 22:05 - 2013-06-12 01:43 - 00154112 _____ (Microsoft Corporation) C:\windows\SysWOW64\WinSCard.dll
2013-09-10 22:05 - 2013-06-12 01:26 - 00230912 _____ (Microsoft Corporation) C:\windows\system32\WinSCard.dll
2013-09-10 22:05 - 2013-06-10 23:17 - 00096512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wfplwfs.sys
2013-09-10 22:05 - 2013-06-10 21:16 - 00888832 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2013-09-10 22:05 - 2013-06-10 21:15 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2013-09-10 22:05 - 2013-06-10 21:15 - 00723968 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL
2013-09-10 22:05 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2013-09-10 22:05 - 2013-06-10 21:10 - 00702464 _____ (Microsoft Corporation) C:\windows\SysWOW64\nshwfp.dll
2013-09-10 22:05 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\windows\SysWOW64\FWPUCLNT.DLL
2013-09-10 22:05 - 2013-06-06 10:03 - 00119040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2013-09-09 19:22 - 2013-09-09 22:49 - 00005120 _____ C:\Users\engin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-09 19:07 - 2013-09-09 22:48 - 00000000 ____D C:\Program Files (x86)\Sensible Vision
2013-09-09 19:03 - 2013-09-10 11:42 - 00000000 ____D C:\Users\engin\AppData\Roaming\Creative
2013-09-09 19:03 - 2013-09-09 19:19 - 00000000 ____D C:\ProgramData\Creative
2013-09-09 19:01 - 2013-09-09 19:01 - 00000086 _____ C:\Setup.log
2013-09-09 19:01 - 2010-12-29 09:51 - 00002931 _____ C:\windows\system32\V0700EQS.cfg
2013-09-09 19:01 - 2006-10-06 14:17 - 00053248 ____N (Creative Technology Ltd ) C:\windows\Ctregrun.exe
2013-09-09 19:01 - 2003-06-12 23:25 - 00007062 _____ C:\windows\SysWOW64\audiopid.vxd
2013-09-09 19:01 - 2000-05-22 16:58 - 00647872 ____N (Microsoft Corporation) C:\windows\SysWOW64\Mscomct2.ocx
2013-09-09 19:00 - 2013-09-10 11:45 - 00000000 ____D C:\windows\CtDrvInstall
2013-09-09 18:59 - 2013-09-10 11:45 - 00000000 ____D C:\Program Files (x86)\Creative
2013-09-09 18:59 - 2013-09-09 18:59 - 00000548 _____ C:\windows\NLSDownlevelMapping.log
2013-09-09 18:59 - 2006-09-19 13:56 - 00057656 ____N C:\windows\system32\Drivers\FilterPC.bmp
2013-09-03 12:21 - 2013-09-03 12:21 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-08-28 13:12 - 2013-08-28 13:12 - 00001387 _____ C:\Users\Public\Desktop\Adrenaline Action Benchmark Tool.lnk
2013-08-28 13:12 - 2013-08-28 13:12 - 00000000 ____D C:\Program Files (x86)\Adrenaline.com.br
2013-08-28 12:34 - 2013-08-28 12:34 - 00000222 _____ C:\Users\engin\Desktop\Sleeping Dogs Demo.url
==================== One Month Modified Files and Folders =======
2013-09-27 20:10 - 2013-09-27 20:10 - 01953854 _____ (Farbar) C:\Users\engin\Desktop\FRST64.exe
2013-09-27 20:04 - 2013-09-27 20:04 - 00001888 _____ C:\Users\engin\Desktop\JRT.txt
2013-09-27 20:02 - 2012-07-26 10:12 - 00000000 ____D C:\windows\system32\sru
2013-09-27 20:01 - 2013-01-12 17:58 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-09-27 19:59 - 2013-09-27 19:59 - 00000000 ____D C:\windows\ERUNT
2013-09-27 19:57 - 2013-09-27 19:57 - 01030305 _____ (Thisisu) C:\Users\engin\Desktop\JRT.exe
2013-09-27 19:41 - 2012-12-15 13:29 - 01875729 _____ C:\windows\WindowsUpdate.log
2013-09-27 19:36 - 2012-11-27 03:54 - 00745562 _____ C:\windows\system32\perfh007.dat
2013-09-27 19:36 - 2012-11-27 03:54 - 00169488 _____ C:\windows\system32\perfc007.dat
2013-09-27 19:36 - 2012-07-26 09:28 - 01752656 _____ C:\windows\system32\PerfStringBackup.INI
2013-09-27 19:33 - 2013-09-27 19:23 - 00000000 ____D C:\AdwCleaner
2013-09-27 19:32 - 2013-09-27 19:32 - 00004329 _____ C:\Users\engin\Desktop\AdwCleaner[S0].txt
2013-09-27 19:31 - 2013-06-10 13:14 - 00000000 ____D C:\Program Files (x86)\Steam
2013-09-27 19:31 - 2012-07-26 09:22 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-09-27 19:22 - 2013-09-27 19:22 - 01042066 _____ C:\Users\engin\Desktop\adwcleaner.exe
2013-09-27 12:05 - 2012-07-26 10:12 - 00000000 ____D C:\windows\AUInstallAgent
2013-09-26 23:01 - 2012-12-15 13:37 - 00003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2358368056-3233348350-3724359345-1001
2013-09-26 22:00 - 2013-09-26 21:59 - 00024149 _____ C:\Users\engin\Desktop\Addition.txt
2013-09-26 21:58 - 2013-09-26 21:58 - 00000000 ____D C:\FRST
2013-09-26 20:00 - 2013-01-13 12:40 - 00000344 _____ C:\windows\Tasks\HPCeeScheduleForengin.job
2013-09-26 20:00 - 2012-08-01 19:02 - 00165312 _____ C:\windows\PFRO.log
2013-09-26 19:59 - 2012-07-26 07:26 - 00262144 ___SH C:\windows\system32\config\BBI
2013-09-26 19:48 - 2013-01-13 12:40 - 00003158 _____ C:\windows\System32\Tasks\HPCeeScheduleForengin
2013-09-26 19:48 - 2012-12-15 13:29 - 00000000 ____D C:\Users\engin
2013-09-26 19:47 - 2012-12-23 14:03 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-09-26 19:47 - 2012-12-17 18:34 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2013-09-26 19:43 - 2012-12-15 14:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-26 18:46 - 2013-09-26 18:46 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-26 18:46 - 2013-09-26 18:46 - 00000000 ____D C:\Users\engin\AppData\Roaming\Malwarebytes
2013-09-26 18:46 - 2013-09-26 18:46 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-26 18:46 - 2013-09-26 18:46 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-24 22:58 - 2013-05-04 10:59 - 00000000 ____D C:\Users\engin\Desktop\pics
2013-09-19 18:39 - 2013-01-04 15:53 - 13131776 _____ C:\Users\engin\AppData\Roaming\Sandra.mdb
2013-09-19 14:26 - 2013-02-13 20:49 - 00003924 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-09-19 14:26 - 2013-02-13 20:49 - 00000000 _____ C:\windows\SysWOW64\config.nt
2013-09-19 01:26 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-09-19 01:26 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-18 12:14 - 2013-09-18 12:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-18 12:14 - 2012-12-15 14:30 - 00000000 ____D C:\Users\engin\AppData\Local\Mozilla
2013-09-17 20:23 - 2012-11-26 19:15 - 00271241 _____ C:\windows\DirectX.log
2013-09-13 23:49 - 2013-01-11 18:46 - 00000000 ____D C:\Users\engin\Documents\CAPCOM
2013-09-13 22:23 - 2012-12-18 21:24 - 00000000 ____D C:\Users\engin\AppData\Local\CAPCOM
2013-09-13 22:00 - 2013-09-13 22:00 - 00000000 ____D C:\windows\SysWOW64\xlive
2013-09-13 22:00 - 2013-09-13 22:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-09-13 21:59 - 2013-09-13 21:59 - 00000000 ____D C:\windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
2013-09-13 21:38 - 2013-09-13 21:38 - 00000000 ____D C:\windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2013-09-13 21:38 - 2013-09-13 21:38 - 00000000 ____D C:\Users\engin\AppData\Local\2K Games
2013-09-13 12:57 - 2012-07-26 10:12 - 00000000 ____D C:\windows\rescache
2013-09-11 01:25 - 2013-09-11 01:25 - 00297352 _____ C:\windows\system32\FNTCACHE.DAT
2013-09-11 01:15 - 2012-07-26 10:12 - 00000000 ____D C:\windows\WinStore
2013-09-11 01:15 - 2012-07-26 10:12 - 00000000 ____D C:\windows\PolicyDefinitions
2013-09-11 01:15 - 2012-07-26 07:38 - 00000000 ____D C:\windows\system32\oobe
2013-09-11 00:14 - 2013-07-09 22:46 - 00000000 ____D C:\windows\system32\MRT
2013-09-11 00:13 - 2012-12-15 19:00 - 79143768 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-09-10 22:01 - 2013-01-12 17:58 - 00003772 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-09-10 11:45 - 2013-09-09 19:00 - 00000000 ____D C:\windows\CtDrvInstall
2013-09-10 11:45 - 2013-09-09 18:59 - 00000000 ____D C:\Program Files (x86)\Creative
2013-09-10 11:42 - 2013-09-09 19:03 - 00000000 ____D C:\Users\engin\AppData\Roaming\Creative
2013-09-10 11:42 - 2012-11-26 19:04 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-09 22:49 - 2013-09-09 19:22 - 00005120 _____ C:\Users\engin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-09 22:48 - 2013-09-09 19:07 - 00000000 ____D C:\Program Files (x86)\Sensible Vision
2013-09-09 20:36 - 2013-07-05 20:52 - 00000000 ____D C:\Users\engin\AppData\Roaming\Skype
2013-09-09 19:19 - 2013-09-09 19:03 - 00000000 ____D C:\ProgramData\Creative
2013-09-09 19:01 - 2013-09-09 19:01 - 00000086 _____ C:\Setup.log
2013-09-09 19:01 - 2012-07-26 09:21 - 00026841 _____ C:\windows\setupact.log
2013-09-09 18:59 - 2013-09-09 18:59 - 00000548 _____ C:\windows\NLSDownlevelMapping.log
2013-09-09 18:22 - 2013-06-16 17:51 - 00000000 ____D C:\Users\engin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst
2013-09-09 18:22 - 2012-12-15 13:31 - 00000000 ___RD C:\Users\engin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-03 12:21 - 2013-09-03 12:21 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-08-30 09:48 - 2013-03-03 22:49 - 00204880 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-08-30 09:48 - 2013-03-03 22:49 - 00065336 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-08-30 09:48 - 2013-03-03 22:49 - 00064288 _____ (AVAST Software) C:\windows\system32\Drivers\aswTdi.sys
2013-08-30 09:48 - 2013-02-13 20:49 - 01030952 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-08-30 09:48 - 2013-02-13 20:49 - 00378944 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-08-30 09:48 - 2013-02-13 20:49 - 00080816 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-08-30 09:48 - 2013-02-13 20:49 - 00072016 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-08-30 09:48 - 2013-02-13 20:49 - 00033400 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-08-30 09:47 - 2013-02-13 20:49 - 00287840 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-08-30 09:47 - 2013-02-13 20:49 - 00041664 _____ (AVAST Software) C:\windows\avastSS.scr
2013-08-28 13:12 - 2013-08-28 13:12 - 00001387 _____ C:\Users\Public\Desktop\Adrenaline Action Benchmark Tool.lnk
2013-08-28 13:12 - 2013-08-28 13:12 - 00000000 ____D C:\Program Files (x86)\Adrenaline.com.br
2013-08-28 12:34 - 2013-08-28 12:34 - 00000222 _____ C:\Users\engin\Desktop\Sleeping Dogs Demo.url
Some content of TEMP:
====================
C:\Users\engin\AppData\Local\Temp\AskSLib.dll
C:\Users\engin\AppData\Local\Temp\AutoRun.exe
C:\Users\engin\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\engin\AppData\Local\Temp\drm_dyndata_7390006.dll
C:\Users\engin\AppData\Local\Temp\EAInstall.dll
C:\Users\engin\AppData\Local\Temp\eauninstall.exe
C:\Users\engin\AppData\Local\Temp\FAInstallV4.000.173.CR.exe
C:\Users\engin\AppData\Local\Temp\sfamcc00001.dll
C:\Users\engin\AppData\Local\Temp\sfamcc00002.dll
C:\Users\engin\AppData\Local\Temp\sfextra.dll
C:\Users\engin\AppData\Local\Temp\Shockwave_Installer_FF.exe
C:\Users\engin\AppData\Local\Temp\SkypeSetup.exe
C:\Users\engin\AppData\Local\Temp\uninst1.exe
C:\Users\engin\AppData\Local\Temp\_isE76.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-19 14:39
==================== End Of Log ============================ --- --- ---
--- --- ---
Hallo schrauber ich hoffe, dass ich bis jetzt alles richtig gemacht habe. |