Nightowl | 15.11.2013 00:24 | Antivirenprogramm meldet unerwünschte Software Guten Abend,
als ich heute mein Pc gestartet hab kamen im Antivirenprogramm mehrer unerwünschte programme,weiss leider nicht woher,hatte als letztes ein windowsupdate:P konnte mich auf eine
schwache Internetverbindung erinnern ,könnte Jemand mal nachsehen??
FRST file: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2013
Ran by k (administrator) on K-PC on 14-11-2013 23:56:59
Running from E:\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
(Conduit) C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
(DeviceVM, Inc.) C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe
(TorchMedia Inc.) C:\Users\k\AppData\Local\Torch\Update\TorchCrashHandler.exe
() C:\Program Files (x86)\Lizardlink\updateLizardlink.exe
() C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe
(DeviceVM, Inc.) C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Conduit) C:\Users\k\AppData\Roaming\SearchProtect\bin\cltmng.exe
(Valve Corporation) E:\Program Files (x86)\Steam\Steam.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(FNet Co., Ltd.) C:\Program Files (x86)\XFastUSB\XFastUsb.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe
() C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWlan.exe
(Microsoft Corporation) C:\Windows\sysWOW64\wbem\wmiprvse.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPop3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\klwtblfs.exe
(Microsoft Corporation) C:\Windows\SysWOW64\NOTEPAD.EXE
(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Wsys Co., Ltd.) C:\ProgramData\eSafe\eGdpSvc.exe
() C:\Program Files (x86)\OpenIt\Open It!\openit.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
() C:\Program Files (x86)\OpenIt\Open It!\openit.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM-x32\...\Runonce: [Del24458226] - cmd.exe /Q /D /c del "C:\Users\k\AppData\Local\Temp\0.del" [x]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [ASRockXTU] - [x]
HKCU\...\Run: [zASRockInstantBoot] - [x]
HKCU\...\Run: [SearchProtect] - C:\Users\k\AppData\Roaming\SearchProtect\bin\cltmng.exe [3470624 2013-09-22] (Conduit)
HKCU\...\Run: [Steam] - E:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\k\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKCU\...\Runonce: [Del24458211] - cmd.exe /Q /D /c del "C:\Users\k\AppData\Local\Temp\0.del"
MountPoints2: {14a9beca-25f9-11e3-8974-806e6f6e6963} - D:\deathrow.exe
MountPoints2: {7ea085cf-25f4-11e3-b180-806e6f6e6963} - D:\ASRSetup.exe
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [218880 2012-05-31] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation)
HKLM-x32\...\Run: [XFastUSB] - C:\Program Files (x86)\XFastUSB\XFastUsb.exe [5019360 2013-09-26] (FNet Co., Ltd.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [34672 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [THX TruStudio NB Settings] - C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] - C:\Windows\Updreg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [SmartViewAgent] - C:\Program Files (x86)\DeviceVM\SmartView\SmartViewAgent.exe [948504 2010-09-02] ()
HKLM-x32\...\Run: [SearchProtectAll] - C:\Program Files (x86)\SearchProtect\bin\cltmng.exe [3470624 2013-09-22] (Conduit)
HKLM-x32\...\Run: [Arc] - C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcLauncher.exe [129384 2013-10-10] (Perfect World Entertainment)
Startup: C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3312331&octid=CT3312331&SearchSource=61&CUI=UN31541596952505889&UM=2&UP=SPA83B3BB0-962C-44F8-B230-2081E8B4BDCE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFE7B791F90BACE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://aartemis.com/?type=hp&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://aartemis.com/?type=hp&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://aartemis.com/?type=hp&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://aartemis.com/?type=hp&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://aartemis.com/?type=hp&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
URLSearchHook: HKLM-x32 - appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.)
URLSearchHook: HKCU - SearchHook Class - {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\DeviceVM\SmartView\AddressBarSearch.dll (DeviceVM, Inc.)
URLSearchHook: HKCU - appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://aartemis.com/?type=sc&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
SearchScopes: HKCU - {15B6CF8A-A704-41E0-8A7C-2B894E9EB8FF} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3312331&CUI=UN31541596952505889&UM=2
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382&q={searchTerms}
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: SmartView VisualBookmark - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files (x86)\DeviceVM\SmartView\SmartView.dll (DeviceVM, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: ArcPluginIEBHO Class - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
BHO-x32: Zula Games - {A9337080-7CBF-4E3E-80C1-3867BEDD88E0} - C:\Program Files (x86)\Zula Games\ScriptHost.dll (ZulaGames.com)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Lizardlink - {eb9e4cdf-b007-450c-b0af-b66467c3d6e0} - C:\Program Files (x86)\Lizardlink\LizardlinkBHO.dll (Lizardlink)
BHO-x32: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll (BonanzaDeals)
Toolbar: HKLM-x32 - appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR HomePage: hxxp://aartemis.com/?type=hp&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
CHR RestoreOnStartup: "hxxp://aartemis.com/?type=hp&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Extension: (Google Docs) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Extended Protection) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0
CHR Extension: (Google Search) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Kaspersky URL Advisor) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.0.3370_0
CHR Extension: (BonanzaDeals) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0
CHR Extension: (Lightning Newtab) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.1.7.9_0
CHR Extension: (Virtual Keyboard) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.0.3370_0
CHR Extension: (Google Wallet) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [gflandjopdloblmlcoiidmncpinmmacn] - C:\Users\k\AppData\Roaming\zulagames\zulagames.crx
CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\k\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [jainjonnknhmbbkibcbmhihbopigapdm] - C:\Program Files (x86)\Lizardlink\jainjonnknhmbbkibcbmhihbopigapdm.crx
CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\k\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://aartemis.com/?type=sc&ts=1384469598&from=cor&uid=SanDiskXSDSSDP064G_123916401382
==================== Services (Whitelisted) =================
S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88424 2013-10-10] (Perfect World Entertainment Inc)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [218880 2012-05-31] (Kaspersky Lab ZAO)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-14] (BonanzaDeals)
S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-11-14] (BonanzaDeals)
R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe [97056 2013-05-08] (Conduit)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-04] ()
R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek)
R2 SmartViewService; C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [125216 2010-09-02] (DeviceVM, Inc.)
R2 TorchCrashHandler; C:\Users\k\AppData\Local\Torch\Update\TorchCrashHandler.exe [1210720 2013-09-24] (TorchMedia Inc.)
R2 Update Lizardlink; C:\Program Files (x86)\Lizardlink\updateLizardlink.exe [66336 2013-11-08] ()
R2 Util Lizardlink; C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe [66336 2013-11-08] ()
R2 WCUService; C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [456976 2010-09-02] (DeviceVM, Inc.)
R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [1706136 2013-11-14] (Wsys Co., Ltd.)
==================== Drivers (Whitelisted) ====================
R0 AsrRamDisk; C:\Windows\System32\DRIVERS\AsrRamDisk.sys [31016 2012-01-13] (ASRock Inc.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-09-26] (FNet Co., Ltd.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458544 2012-04-13] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [640344 2012-05-29] (Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [30000 2012-03-27] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-05-25] (Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [27992 2012-05-25] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54064 2012-05-12] (Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [172888 2012-05-24] (Kaspersky Lab)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-11-14] ()
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [85336 2012-05-29] (Kaspersky Lab)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-14 23:56 - 2013-11-14 23:56 - 00000000 ____D C:\FRST
2013-11-14 23:53 - 2013-11-14 23:56 - 00001110 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-11-14 23:53 - 2013-11-14 23:53 - 00003912 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA
2013-11-14 23:53 - 2013-11-14 23:53 - 00003660 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore
2013-11-14 23:53 - 2013-11-14 23:53 - 00003378 _____ C:\Windows\System32\Tasks\BonanzaDealsUpdate
2013-11-14 23:53 - 2013-11-14 23:53 - 00003200 _____ C:\Windows\System32\Tasks\DigitalSite
2013-11-14 23:53 - 2013-11-14 23:53 - 00001087 _____ C:\Users\k\Desktop\MyPC Backup.lnk
2013-11-14 23:53 - 2013-11-14 23:53 - 00000916 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
2013-11-14 23:53 - 2013-11-14 23:53 - 00000912 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
2013-11-14 23:53 - 2013-11-14 23:53 - 00000276 _____ C:\Windows\Tasks\DigitalSite.job
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\DigitalSite
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\aartemis
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\0D0S1L2Z1P1B
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Local\BonanzaDealsLive
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\ProgramData\eSafe
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-11-13 22:45 - 2013-11-13 22:45 - 00000000 ____D C:\ProgramData\EA Core
2013-11-13 22:43 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2013-11-13 22:42 - 2013-11-13 22:45 - 00000000 ____D C:\Users\k\Documents\FUSSBALL MANAGER 12
2013-11-13 22:30 - 2013-11-14 17:05 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-11-13 22:28 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-13 22:28 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-13 22:28 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-13 22:28 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-13 22:28 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-13 22:28 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-13 22:28 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-13 22:28 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-13 22:28 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-13 22:28 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-13 22:28 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 22:28 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-13 20:50 - 2013-11-13 20:50 - 00000000 ____D C:\Users\k\AppData\Local\Blizzard Entertainment
2013-11-13 16:57 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-13 16:57 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 16:57 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 16:57 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-13 16:57 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 16:57 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-13 16:57 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-13 16:57 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 16:57 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-13 16:57 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-13 16:57 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-13 16:57 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-13 16:57 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-13 16:57 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 16:57 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-13 16:57 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-13 16:57 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 16:57 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 16:57 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-13 16:57 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-13 16:57 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-13 16:57 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 16:57 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-13 16:57 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-13 16:57 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-13 16:57 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-13 16:57 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-13 16:57 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-13 16:57 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-13 16:57 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-12 22:14 - 2013-11-12 22:14 - 00000907 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
2013-11-12 22:14 - 2013-11-12 22:14 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2013-11-12 22:13 - 2013-11-12 22:13 - 00000000 ____D C:\ProgramData\Battle.net
2013-11-09 11:19 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-11-09 11:19 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2013-11-09 11:19 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2013-11-09 11:19 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-11-09 11:19 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-11-09 11:19 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-11-09 11:19 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2013-11-09 11:19 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-11-09 11:19 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2013-11-09 11:19 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2013-11-09 11:19 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-11-09 11:19 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-11-09 11:19 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2013-11-09 11:19 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-11-09 11:19 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2013-11-09 11:19 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-11-09 11:19 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2013-11-09 11:19 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-11-09 11:19 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-11-09 11:19 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2013-11-09 11:19 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-11-09 11:19 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2013-11-09 11:19 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-11-09 11:19 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2013-11-09 11:19 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-11-09 11:19 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2013-11-09 11:19 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2013-11-09 11:19 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-11-09 11:19 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-11-09 11:19 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2013-11-09 11:19 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-11-09 11:19 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2013-11-09 11:19 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2013-11-09 11:19 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-11-09 11:19 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-11-09 11:19 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2013-11-09 11:19 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-11-09 11:19 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-11-09 11:19 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2013-11-09 11:19 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2013-11-09 11:19 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-11-09 11:19 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-11-09 11:19 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2013-11-09 11:19 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2013-11-09 11:19 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-11-09 11:19 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-11-09 11:19 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2013-11-09 11:19 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-11-09 11:19 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2013-11-09 11:19 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-11-09 11:19 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2013-11-09 11:19 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-11-09 11:19 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2013-11-09 11:19 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2013-11-09 11:19 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-11-09 11:19 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-11-09 11:19 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2013-11-09 11:19 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-11-09 11:19 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2013-11-09 11:19 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-11-09 11:19 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2013-11-09 11:19 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-11-09 11:19 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2013-11-09 11:19 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-11-09 11:19 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2013-11-09 11:19 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-11-09 11:19 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2013-11-09 11:19 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-11-09 11:19 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2013-11-09 11:18 - 2013-11-09 11:18 - 00001854 _____ C:\Users\Public\Desktop\Path of Exile.lnk
2013-11-09 11:18 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2013-11-09 11:18 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2013-11-09 11:18 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-11-09 11:18 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2013-11-09 11:18 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-11-09 11:18 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2013-11-09 11:18 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-11-09 11:18 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2013-11-09 11:18 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-11-09 11:18 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2013-11-09 11:18 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-11-09 11:18 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2013-11-09 11:18 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-11-09 11:18 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2013-11-09 11:18 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-11-09 11:18 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2013-11-09 11:18 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-11-09 11:18 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2013-11-09 11:18 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-11-09 11:18 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2013-11-09 11:18 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-11-09 11:18 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2013-11-09 11:18 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-11-09 11:18 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2013-11-09 11:18 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2013-11-09 11:18 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-11-09 11:18 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2013-11-09 11:18 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-11-09 11:18 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2013-11-09 11:18 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-11-09 11:18 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2013-11-09 11:18 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-11-09 11:18 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2013-11-09 11:18 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-11-09 11:18 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2013-11-09 11:18 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2013-11-09 11:18 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-11-09 11:18 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-11-09 11:18 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2013-11-09 11:18 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-11-09 11:18 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2013-11-09 11:18 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-11-09 11:18 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2013-11-09 11:18 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2013-11-09 11:18 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-11-09 11:18 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-11-09 11:18 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-11-09 11:18 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2013-11-09 11:18 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2013-11-09 11:18 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2013-11-09 11:18 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-11-09 11:18 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-11-09 11:18 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2013-11-09 11:18 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-11-09 11:18 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2013-11-09 11:18 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-11-09 11:18 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2013-11-09 11:18 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-11-09 11:18 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2013-11-09 11:18 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-11-09 11:18 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2013-11-09 11:18 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-11-09 11:18 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2013-11-09 11:18 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-11-09 11:18 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2013-11-09 11:18 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-11-09 11:18 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2013-11-09 11:18 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-11-09 11:18 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2013-11-09 11:18 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-11-09 11:18 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2013-11-09 11:18 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-11-09 11:18 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2013-11-09 11:14 - 2013-11-09 11:14 - 00001842 _____ C:\Users\Public\Desktop\Arc.lnk
2013-11-09 11:14 - 2013-11-09 11:14 - 00000000 ____D C:\Program Files (x86)\Perfect World Entertainment
2013-11-06 18:14 - 2013-11-09 01:49 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2013-11-06 18:14 - 2013-11-09 01:49 - 00000776 _____ C:\Windows\LkmdfCoInst.log
2013-11-06 18:14 - 2013-11-06 18:14 - 00000000 ____D C:\Users\k\AppData\Local\Logitech
2013-11-06 18:14 - 2013-11-06 18:14 - 00000000 ____D C:\ProgramData\LogiShrd
2013-11-06 18:13 - 2013-11-06 18:14 - 00000000 ____D C:\Program Files\Logitech Gaming Software
2013-11-06 18:13 - 2013-11-06 18:13 - 00000000 ____D C:\Users\k\AppData\Roaming\Logitech
2013-11-06 18:13 - 2013-11-06 18:13 - 00000000 ____D C:\Users\k\AppData\Roaming\Logishrd
2013-10-24 08:12 - 2013-11-09 11:18 - 00000000 ____D C:\Users\k\Documents\My Games
2013-10-24 08:12 - 2013-10-24 08:12 - 00000000 ____D C:\Users\k\AppData\Local\My Games
2013-10-24 06:30 - 2013-10-24 06:30 - 00000220 _____ C:\Users\k\Desktop\Sid Meier's Civilization V.url
2013-10-23 20:58 - 2013-10-23 20:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-23 20:58 - 2013-10-23 20:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-20 17:02 - 2013-10-20 17:02 - 00000000 ____D C:\SearchProtect
2013-10-19 21:31 - 2013-10-19 21:31 - 00000000 ____D C:\Users\k\Documents\TacticalIntervention
2013-10-19 21:30 - 2013-10-19 21:30 - 00000219 _____ C:\Users\k\Desktop\Counter-Strike Global Offensive.url
2013-10-18 20:38 - 2013-10-18 20:38 - 00000000 ____D C:\Users\k\Documents\EA Games
2013-10-18 20:38 - 2013-10-18 20:38 - 00000000 ____D C:\Users\k\AppData\Local\EA Games
2013-10-18 20:29 - 2013-10-18 20:29 - 00000747 _____ C:\Users\Public\Desktop\Crysis 3.lnk
2013-10-18 20:28 - 2013-10-18 20:28 - 00000871 _____ C:\Users\Public\Desktop\Dead Space 3.lnk
2013-10-18 15:47 - 2013-10-18 15:47 - 00000000 ____D C:\Users\k\AppData\Local\Nexway
==================== One Month Modified Files and Folders =======
2013-11-14 23:56 - 2013-11-14 23:56 - 00000000 ____D C:\FRST
2013-11-14 23:56 - 2013-11-14 23:53 - 00001110 _____ C:\Users\Public\Desktop\Open It!.lnk
2013-11-14 23:53 - 2013-11-14 23:53 - 00003912 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA
2013-11-14 23:53 - 2013-11-14 23:53 - 00003660 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore
2013-11-14 23:53 - 2013-11-14 23:53 - 00003378 _____ C:\Windows\System32\Tasks\BonanzaDealsUpdate
2013-11-14 23:53 - 2013-11-14 23:53 - 00003200 _____ C:\Windows\System32\Tasks\DigitalSite
2013-11-14 23:53 - 2013-11-14 23:53 - 00001087 _____ C:\Users\k\Desktop\MyPC Backup.lnk
2013-11-14 23:53 - 2013-11-14 23:53 - 00000916 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
2013-11-14 23:53 - 2013-11-14 23:53 - 00000912 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
2013-11-14 23:53 - 2013-11-14 23:53 - 00000276 _____ C:\Windows\Tasks\DigitalSite.job
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\DigitalSite
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\aartemis
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Roaming\0D0S1L2Z1P1B
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Users\k\AppData\Local\BonanzaDealsLive
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\ProgramData\eSafe
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\OpenIt
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-11-14 23:53 - 2013-11-14 23:53 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-11-14 23:53 - 2013-09-26 11:10 - 00002359 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-14 23:53 - 2013-09-25 16:18 - 00001609 _____ C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-14 23:53 - 2013-09-25 16:18 - 00000000 ___RD C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-14 23:33 - 2013-09-25 16:13 - 01239364 _____ C:\Windows\WindowsUpdate.log
2013-11-14 23:26 - 2013-09-25 16:27 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-11-14 23:21 - 2013-09-26 11:10 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-14 20:21 - 2013-09-26 11:10 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-14 20:05 - 2013-10-02 19:02 - 00000000 ____D C:\ProgramData\TorchCrashHandler
2013-11-14 20:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-14 17:14 - 2009-07-14 05:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-14 17:14 - 2009-07-14 05:45 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-14 17:12 - 2009-07-14 18:58 - 00653928 _____ C:\Windows\system32\perfh007.dat
2013-11-14 17:12 - 2009-07-14 18:58 - 00129800 _____ C:\Windows\system32\perfc007.dat
2013-11-14 17:12 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-14 17:05 - 2013-11-13 22:30 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-11-14 17:05 - 2013-10-02 18:58 - 00000000 ____D C:\Users\k\AppData\Local\iLivid
2013-11-14 17:05 - 2013-09-26 11:46 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-14 17:05 - 2013-09-26 09:42 - 00001404 _____ C:\Users\k\Desktop\Games.lnk
2013-11-14 17:05 - 2013-09-26 09:42 - 00001404 _____ C:\Users\k\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk
2013-11-14 17:05 - 2013-09-26 09:38 - 00460262 _____ C:\Windows\PFRO.log
2013-11-14 17:05 - 2013-09-26 09:37 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2013-11-14 17:05 - 2013-09-26 09:34 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-11-14 17:05 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-14 17:05 - 2009-07-14 05:51 - 00010340 _____ C:\Windows\setupact.log
2013-11-13 23:45 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-11-13 22:45 - 2013-11-13 22:45 - 00000000 ____D C:\ProgramData\EA Core
2013-11-13 22:45 - 2013-11-13 22:42 - 00000000 ____D C:\Users\k\Documents\FUSSBALL MANAGER 12
2013-11-13 22:45 - 2013-09-25 16:18 - 00000000 ____D C:\Users\k\AppData\Local\VirtualStore
2013-11-13 22:28 - 2013-09-26 14:30 - 00000000 ____D C:\Windows\system32\MRT
2013-11-13 22:27 - 2013-09-26 14:30 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 20:50 - 2013-11-13 20:50 - 00000000 ____D C:\Users\k\AppData\Local\Blizzard Entertainment
2013-11-12 22:14 - 2013-11-12 22:14 - 00000907 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
2013-11-12 22:14 - 2013-11-12 22:14 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2013-11-12 22:13 - 2013-11-12 22:13 - 00000000 ____D C:\ProgramData\Battle.net
2013-11-10 21:06 - 2013-10-08 16:26 - 00000000 ____D C:\Users\k\AppData\Roaming\NVIDIA
2013-11-09 11:19 - 2013-09-26 12:05 - 00148115 _____ C:\Windows\DirectX.log
2013-11-09 11:18 - 2013-11-09 11:18 - 00001854 _____ C:\Users\Public\Desktop\Path of Exile.lnk
2013-11-09 11:18 - 2013-10-24 08:12 - 00000000 ____D C:\Users\k\Documents\My Games
2013-11-09 11:14 - 2013-11-09 11:14 - 00001842 _____ C:\Users\Public\Desktop\Arc.lnk
2013-11-09 11:14 - 2013-11-09 11:14 - 00000000 ____D C:\Program Files (x86)\Perfect World Entertainment
2013-11-09 11:14 - 2013-09-25 16:40 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-09 11:14 - 2013-09-25 16:18 - 00000000 ____D C:\Users\k
2013-11-09 01:49 - 2013-11-06 18:14 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2013-11-09 01:49 - 2013-11-06 18:14 - 00000776 _____ C:\Windows\LkmdfCoInst.log
2013-11-06 18:14 - 2013-11-06 18:14 - 00000000 ____D C:\Users\k\AppData\Local\Logitech
2013-11-06 18:14 - 2013-11-06 18:14 - 00000000 ____D C:\ProgramData\LogiShrd
2013-11-06 18:14 - 2013-11-06 18:13 - 00000000 ____D C:\Program Files\Logitech Gaming Software
2013-11-06 18:13 - 2013-11-06 18:13 - 00000000 ____D C:\Users\k\AppData\Roaming\Logitech
2013-11-06 18:13 - 2013-11-06 18:13 - 00000000 ____D C:\Users\k\AppData\Roaming\Logishrd
2013-11-02 17:16 - 2013-10-05 12:28 - 00000000 ____D C:\Users\k\AppData\Local\CrashDumps
2013-10-31 15:34 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-24 08:12 - 2013-10-24 08:12 - 00000000 ____D C:\Users\k\AppData\Local\My Games
2013-10-24 06:30 - 2013-10-24 06:30 - 00000220 _____ C:\Users\k\Desktop\Sid Meier's Civilization V.url
2013-10-23 20:58 - 2013-10-23 20:58 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-23 20:58 - 2013-10-23 20:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-20 17:02 - 2013-10-20 17:02 - 00000000 ____D C:\SearchProtect
2013-10-19 21:31 - 2013-10-19 21:31 - 00000000 ____D C:\Users\k\Documents\TacticalIntervention
2013-10-19 21:30 - 2013-10-19 21:30 - 00000219 _____ C:\Users\k\Desktop\Counter-Strike Global Offensive.url
2013-10-18 20:38 - 2013-10-18 20:38 - 00000000 ____D C:\Users\k\Documents\EA Games
2013-10-18 20:38 - 2013-10-18 20:38 - 00000000 ____D C:\Users\k\AppData\Local\EA Games
2013-10-18 20:29 - 2013-10-18 20:29 - 00000747 _____ C:\Users\Public\Desktop\Crysis 3.lnk
2013-10-18 20:28 - 2013-10-18 20:28 - 00000871 _____ C:\Users\Public\Desktop\Dead Space 3.lnk
2013-10-18 15:47 - 2013-10-18 15:47 - 00000000 ____D C:\Users\k\AppData\Local\Nexway
Some content of TEMP:
====================
C:\Users\k\AppData\Local\Temp\BackupSetup.exe
C:\Users\k\AppData\Local\Temp\bitool.dll
C:\Users\k\AppData\Local\Temp\Gw2.exe
C:\Users\k\AppData\Local\Temp\nscCBE9.exe
C:\Users\k\AppData\Local\Temp\nssF9FE.exe
C:\Users\k\AppData\Local\Temp\SecondStepInstaller.exe
C:\Users\k\AppData\Local\Temp\sonarinst.exe
C:\Users\k\AppData\Local\Temp\SPStub.exe
C:\Users\k\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-10 17:17
==================== End Of Log ============================ addition file: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2013
Ran by k at 2013-11-14 23:57:26
Running from E:\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Kaspersky Anti-Virus (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Anti-Virus (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
aartemis Browser Protecter (x32)
Acrobat.com (x32 Version: 0.0.0)
Acrobat.com (x32 Version: 1.1.377)
Adobe AIR (x32 Version: 1.0.4990)
Adobe AIR (x32 Version: 1.0.8.4990)
Adobe Reader 9 (x32 Version: 9.0.0)
Amazon MP3-Downloader 1.0.18 (HKCU Version: 1.0.18)
appbarioDE Toolbar for IE (x32 Version: 6.16.2.2)
Arc (x32 Version: 1.0.0.5510)
ASRock eXtreme Tuner v0.1.248 (x32)
ASRock InstantBoot v1.29 (x32)
ASRock XFast RAM v2.0.9
Battlefield 4™ Beta (x32 Version: 1.0.0.0)
Battlelog Web Plugins (x32 Version: 2.3.0)
Bonanza Deals (remove only) (x32 Version: 5.0.1.0)
Cisco EAP-FAST Module (x32 Version: 2.2.14)
Cisco LEAP Module (x32 Version: 1.0.19)
Cisco PEAP Module (x32 Version: 1.1.6)
Counter-Strike: Global Offensive (x32)
Counter-Strike: Source (x32)
Crysis®3 (x32 Version: 1.0.0.0)
Dead Space™ 3 (x32 Version: 1.0.0.0)
Empire: Total War (x32)
ESN Sonar (x32 Version: 0.70.4)
FUSSBALL MANAGER 12 (x32 Version: 1.0.0.0)
Google Chrome (x32 Version: 30.0.1599.101)
Google Update Helper (x32 Version: 1.3.21.165)
Guild Wars 2 (x32)
iLivid (x32 Version: 5.0.0.4002)
Intel(R) Control Center (x32 Version: 1.2.1.1008)
Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342)
Intel(R) Management Engine Components (x32 Version: 8.0.3.1427)
Intel(R) OpenCL CPU Runtime (x32)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2761)
Intel(R) Rapid Storage Technology (x32 Version: 11.2.0.1006)
Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.4.220)
Intel® Trusted Connect Service Client (Version: 1.23.605.1)
Kaspersky Anti-Virus 2013 (x32 Version: 13.0.0.3370)
Lizardlink 1.0.0 (Version: 1.0.0)
Logitech Gaming Software (Version: 8.45.88)
Logitech Gaming Software 8.50 (Version: 8.50.281)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610)
MyPC Backup (Version: )
NVIDIA 3D Vision Controller-Treiber 326.01 (Version: 326.01)
NVIDIA 3D Vision Treiber 327.23 (Version: 327.23)
NVIDIA Grafiktreiber 327.23 (Version: 327.23)
NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4)
NVIDIA Install Application (Version: 2.1002.133.902)
NVIDIA PhysX (x32 Version: 9.13.0725)
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2723)
NVIDIA Systemsteuerung 327.23 (Version: 327.23)
Open It! (x32 Version: 1.1.1)
Origin (x32 Version: 9.3.7.2735)
Path of Exile (x32 Version: 1.0.0.29375)
PunkBuster Services (x32 Version: 0.993)
Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6482)
REALTEK Wireless LAN Driver (x32 Version: 1.00.0154)
REALTEK Wireless LAN Driver and Utility (x32 Version: 1.00.0187)
Search Protect by conduit (x32 Version: 1.7.0.72)
Sid Meier's Civilization V (x32)
SmartView for IE (x32 Version: 1.0.4.1)
SmartView Software Updater (x32 Version: 1.0.4.1)
Star Wars: The Old Republic (x32 Version: 1.00)
Steam (x32 Version: 1.0.0.0)
Tactical Intervention (x32)
THX TruStudio (x32 Version: 1.00.01)
Torch (HKCU Version: 25.0.0.4508)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Zip Extractor (HKCU)
Video Performer (x32)
World of Tanks (x32)
World of Warcraft (x32)
Wsys Control 10.2.1.2652 (x32 Version: 10.2.1.2652)
XFastUSB (x32 Version: 3.02.30)
Zip Extractor Packages (HKCU)
Zula Games (x32 Version: 1.0.0.5)
==================== Restore Points =========================
10-11-2013 18:00:07 Windows-Sicherung
12-11-2013 15:20:23 Windows Update
13-11-2013 21:27:31 Windows Update
13-11-2013 21:42:58 DirectX wurde installiert
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {03604CE4-0313-41FA-994B-217D2EDE07E2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-26] (Google Inc.)
Task: {0A53A887-6E8D-4256-9048-3D9B965405E9} - System32\Tasks\BonanzaDealsUpdate => C:\Program
Task: {0AA5DBD6-B20E-474B-B5B4-AB98522728C0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-26] (Google Inc.)
Task: {30AB8FBD-8D89-414B-8A8B-BBC858F3E8F6} - System32\Tasks\DigitalSite => C:\Users\k\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe [2013-04-12] ()
Task: {C149CB7D-2709-493B-A6AF-53A301041882} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {CF0E3E88-8046-490A-BF87-DD61D54BB3B2} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {D4225602-8315-4909-BB21-6AE56DC3B2BC} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {F0B5F51F-A1A8-405F-B3CB-3AAE3FDFB168} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-14] (BonanzaDeals)
Task: {FBFFC90A-108F-4B13-A859-E85763423099} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-11-14] (BonanzaDeals)
Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe
Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe
Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\k\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
==================== Loaded Modules (whitelisted) =============
2013-09-25 16:36 - 2012-05-21 03:38 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-09-26 09:40 - 2011-05-19 08:58 - 00246784 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL
2013-09-19 23:37 - 2013-09-19 23:37 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll
2013-09-19 23:32 - 2013-09-19 23:32 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
2012-05-31 17:57 - 2012-05-31 17:57 - 01305016 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\kpcengine.2.2.dll
2013-08-21 13:18 - 2013-10-24 18:45 - 00691200 _____ () E:\Program Files (x86)\Steam\SDL2.dll
2013-09-21 09:35 - 2013-10-30 20:25 - 01123240 _____ () E:\Program Files (x86)\Steam\bin\chromehtml.DLL
2013-09-10 13:20 - 2013-10-23 21:07 - 20625832 _____ () E:\Program Files (x86)\Steam\bin\libcef.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 01100800 _____ () E:\Program Files (x86)\Steam\bin\avcodec-53.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 00124416 _____ () E:\Program Files (x86)\Steam\bin\avutil-51.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 00192000 _____ () E:\Program Files (x86)\Steam\bin\avformat-53.dll
2013-09-26 09:40 - 2011-05-04 15:32 - 00094208 ____N () C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\de-DE\THXAudNB.resources.dll
2010-09-02 15:54 - 2010-09-02 15:54 - 00503202 _____ () C:\Program Files (x86)\DeviceVM\SmartView\sqlite3.dll
2013-09-27 07:52 - 2009-12-09 20:20 - 00126976 _____ () C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\EnumDevLib.dll
2013-09-28 19:14 - 2013-09-28 19:14 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\d5fbd408c39e0de3296b93ac03a5c147\IsdiInterop.ni.dll
2013-09-25 16:41 - 2012-05-30 12:55 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-09-26 09:34 - 2012-02-21 11:09 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-03-27 22:50 - 2013-03-27 22:50 - 00020480 _____ () C:\Program Files (x86)\OpenIt\Open It!\libgcc_s_dw2-1.dll
2011-12-02 01:30 - 2011-12-02 01:30 - 00979982 _____ () C:\Program Files (x86)\OpenIt\Open It!\libstdc++-6.dll
2013-03-27 22:50 - 2013-03-27 22:50 - 00009826 _____ () C:\Program Files (x86)\OpenIt\Open It!\mingwm10.dll
2013-10-19 01:24 - 2013-10-09 01:01 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll
2013-10-19 01:24 - 2013-10-09 01:01 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll
2013-10-19 01:24 - 2013-10-09 01:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll
2013-10-19 01:24 - 2013-10-09 01:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll
2013-10-19 01:24 - 2013-10-09 01:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll
2013-10-19 01:24 - 2013-10-09 01:02 - 13584336 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/14/2013 11:53:28 PM) (Source: MsiInstaller) (User: k-PC)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\GoogleUpdateHelper.msi
Error: (11/14/2013 07:54:06 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (11/14/2013 05:05:49 PM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/14/2013 04:58:16 PM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/14/2013 05:46:10 AM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 10:38:24 PM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 10:30:38 PM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 04:53:07 PM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 00:40:46 AM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/12/2013 09:44:09 PM) (Source: ISCT Agent) (User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
System errors:
=============
Error: (11/14/2013 05:03:54 PM) (Source: DCOM) (User: )
Description: C:\Windows\SysWOW64\DllHost.exe /Processid:{06622D85-6856-4460-8DE1-A81921B41C4B}5{06622D85-6856-4460-8DE1-A81921B41C4B}
Error: (11/14/2013 05:46:09 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 14.11.2013 um 00:49:46 unerwartet heruntergefahren.
Error: (11/13/2013 10:38:22 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 13.11.2013 um 22:37:30 unerwartet heruntergefahren.
Error: (11/13/2013 10:27:50 PM) (Source: DCOM) (User: )
Description: {FE9617F6-E606-42AA-BECC-0E9CDA246D63}
Error: (11/12/2013 07:45:50 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 12.11.2013 um 19:44:48 unerwartet heruntergefahren.
Error: (10/31/2013 03:35:30 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/31/2013 03:35:30 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.
Error: (10/27/2013 04:07:41 PM) (Source: cdrom) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (10/10/2013 01:26:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/10/2013 01:26:19 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.
Microsoft Office Sessions:
=========================
Error: (11/14/2013 11:53:28 PM) (Source: MsiInstaller)(User: k-PC)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (11/14/2013 07:54:06 PM) (Source: SideBySide)(User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3
Error: (11/14/2013 05:05:49 PM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/14/2013 04:58:16 PM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/14/2013 05:46:10 AM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 10:38:24 PM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 10:30:38 PM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 04:53:07 PM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/13/2013 00:40:46 AM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
Error: (11/12/2013 09:44:09 PM) (Source: ISCT Agent)(User: )
Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2
==================== Memory info ===========================
Percentage of memory in use: 32%
Total physical RAM: 8087.01 MB
Available physical RAM: 5433.24 MB
Total Pagefile: 16172.2 MB
Available Pagefile: 12785.74 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:59.53 GB) (Free:17.08 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (All Eyez On Me) (CDROM) (Total:0.67 GB) (Free:0 GB) CDFS
Drive e: () (Fixed) (Total:931.51 GB) (Free:678.58 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 60 GB) (Disk ID: 44E96EA7)
Partition 1: (Active) - (Size=60 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 653126D5)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)
==================== End Of Log ============================ gmer file: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-11-15 00:03:38
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SanDisk_ rev.2.0. 59,63GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\k\AppData\Local\Temp\pxldqpog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800031a2000 45 bytes [00, 00, 40, 02, 49, 72, 70, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800031a202f 17 bytes [00, 30, C8, B3, 15, 80, FA, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe[1748] C:\Windows\SysWOW64\ntdll.dll!NtQueryValueKey 00000000777ffaa8 5 bytes JMP 00000001749d139f
.text C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe[1748] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077800038 5 bytes JMP 00000001749d19ed
.text C:\Windows\SysWOW64\PnkBstrA.exe[1140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000072261a22 2 bytes [26, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000072261ad0 2 bytes [26, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000072261b08 2 bytes [26, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000072261bba 2 bytes [26, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000072261bda 2 bytes [26, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075311465 2 bytes [31, 75]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753114bb 2 bytes [31, 75]
.text ... * 2
.text C:\Users\k\AppData\Local\Torch\Update\TorchCrashHandler.exe[2104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075311465 2 bytes [31, 75]
.text C:\Users\k\AppData\Local\Torch\Update\TorchCrashHandler.exe[2104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753114bb 2 bytes [31, 75]
.text ... * 2
.text C:\Users\k\AppData\Roaming\SearchProtect\bin\cltmng.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075311465 2 bytes [31, 75]
.text C:\Users\k\AppData\Roaming\SearchProtect\bin\cltmng.exe[3544] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753114bb 2 bytes [31, 75]
.text ... * 2
.text E:\Program Files (x86)\Steam\Steam.exe[3556] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate 0000000075fb549c 5 bytes JMP 00000001000f0800
? C:\Windows\system32\mssprxy.dll [3504] entry point in ".rdata" section 00000000649d71e6
.text C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe[4752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075311465 2 bytes [31, 75]
.text C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe[4752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753114bb 2 bytes [31, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5308] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate 0000000075fb549c 5 bytes JMP 0000000100110800
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5308] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075311465 2 bytes [31, 75]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5308] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000753114bb 2 bytes [31, 75]
.text ... * 2
.text C:\ProgramData\eSafe\eGdpSvc.exe[6052] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075311465 2 bytes [31, 75]
.text C:\ProgramData\eSafe\eGdpSvc.exe[6052] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753114bb 2 bytes [31, 75]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5884:5392] 000007fefb832a7c
---- EOF - GMER 2.1 ---- Mfg
Nightowl |