Tut mir leid, dass ich erst jetzt antworte. Viel zutun vor Weihnachten
Also ja ich habe die Fehler behoben die mir Malwarebytes angezeigt hatte. Es gab keine Veränderung. Es ist mittlerweile auch schon so weit dass ich kaum ins Internet komme weil auch Seiten nicht geladen werden.
Hier nochmal die LOG-Files:
GMER-Log Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-12-20 17:01:00
Windows 6.1.7600 x64 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T0L0-1 SAMSUNG_HD502IJ rev.1AA01113 465,76GB
Running: i0ceusog.exe; Driver: C:\Users\Game\AppData\Local\Temp\pxtdqpow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!EngSetLastError + 624 fffff96000124834 8 bytes [44, 94, 0D, 04, 80, F8, FF, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000153900 7 bytes [00, AE, F3, FF, 01, B8, F0]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000153908 3 bytes [C0, 06, 02]
.text ... * 107
.text C:\Windows\System32\win32k.sys!EngGetProcessHandle + 400 fffff96000211928 1 byte [24]
.text C:\Windows\System32\win32k.sys!EngGetProcessHandle + 402 fffff9600021192a 12 bytes [0D, 04, 80, F8, FF, FF, FF, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\wininit.exe[960] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\services.exe[160] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\winlogon.exe[280] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\lsass.exe[292] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\svchost.exe[680] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[824] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[820] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Windows\system32\svchost.exe[868] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\System32\svchost.exe[984] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\System32\svchost.exe[896] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1044] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1264] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1292] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1464] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[1472] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\Explorer.EXE[1856] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files (x86)\WinZipper\winzipersvc.exe[1928] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\ProgramData\eSafe\eGdpSvc.exe[1996] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\ProgramData\eSafe\eGdpSvc.exe[1996] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\ProgramData\eSafe\eGdpSvc.exe[1996] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Windows\system32\taskhost.exe[1512] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2744] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3040] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1576] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1564] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1564] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1564] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Users\Game\AppData\Local\Facebook\Update\FacebookUpdate.exe[2880] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Users\Game\AppData\Local\Facebook\Update\FacebookUpdate.exe[2880] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Users\Game\AppData\Local\Facebook\Update\FacebookUpdate.exe[2880] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe[3068] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files\Logitech\SetPoint II\SetPointII.exe[2984] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[3076] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[3076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[3076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3140] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3148] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3156] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE[3240] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Users\Game\AppData\Roaming\PTS\run.exe[3380] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Users\Game\AppData\Roaming\PTS\run.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Users\Game\AppData\Roaming\PTS\run.exe[3380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Windows\system32\conhost.exe[3388] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\System32\spoolsv.exe[3868] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\svchost.exe[3904] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[3984] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[3984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe[3984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[4028] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[4060] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[4060] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[4060] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe[3696] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe[3652] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2208] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4124] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000073731a22 2 bytes [73, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000073731ad0 2 bytes [73, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000073731b08 2 bytes [73, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000073731bba 2 bytes [73, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000073731bda 2 bytes [73, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075041465 2 bytes [04, 75]
.text C:\Windows\SysWOW64\PnkBstrA.exe[4304] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750414bb 2 bytes [04, 75]
.text ... * 2
.text C:\Windows\system32\svchost.exe[4384] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[4424] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4980] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\conhost.exe[4988] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\SearchIndexer.exe[5200] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5988] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\svchost.exe[6032] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\SearchProtocolHost.exe[6564] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\System32\svchost.exe[6944] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\AUDIODG.EXE[4208] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Windows\system32\taskhost.exe[7640] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 00000000770df1fd 1 byte [62]
.text C:\Users\Game\Downloads\i0ceusog.exe[8008] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 0000000076e0b0c5 1 byte [62]
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x19 0x69 0x55 0x5B ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3B 0x67 0x5D 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x59 0x26 0x4A 0x8F ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x22 0xB6 0x37 0xC2 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x19 0x69 0x55 0x5B ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x3B 0x67 0x5D 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x59 0x26 0x4A 0x8F ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x22 0xB6 0x37 0xC2 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.A1wish\UserChoice@Progid RapidSolution.Audials.A1wish
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\OpenWithProgids@iTunes.pls
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\OpenWithProgids@RapidSolution.Radiotracker.pls
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice@Progid RapidSolution.Audials.pls
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.RTstn\UserChoice@Progid RapidSolution.Audials.RTstn
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.RTwsh\UserChoice@Progid RapidSolution.Audials.RTwsh
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scs\OpenWithList@a WinRAR.exe
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scs\OpenWithList@MRUList a
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sfk\OpenWithList@a wmplayer.exe
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sfk\OpenWithList@MRUList a
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vlt\OpenWithList@a WinRAR.exe
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vlt\OpenWithList@MRUList ba
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vlt\OpenWithList@b vlc.exe
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdseml\UserChoice@Progid ThunderbirdEML
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{19C9D718-2788-AE16-08C3-D4C986934916}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{19C9D718-2788-AE16-08C3-D4C986934916}@hanankbkafhhbbnl 0x6A 0x61 0x61 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{19C9D718-2788-AE16-08C3-D4C986934916}@iahplpnnagbojnnfob 0x63 0x61 0x67 0x6E ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{19C9D718-2788-AE16-08C3-D4C986934916}@ialadlefdmkcckfpld 0x6A 0x61 0x61 0x70 ...
---- EOF - GMER 2.1 ---- FRST-Log
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-12-2013 02
Ran by Game (administrator) on GAME-PC on 20-12-2013 17:03:33
Running from C:\Users\Game\Downloads
Windows 7 Ultimate (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Taiwan Shui Mu Chih Ching Technology Limited.) C:\Program Files (x86)\WinZipper\winzipersvc.exe
(Wsys Co., Ltd.) C:\ProgramData\eSafe\eGdpSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Facebook Inc.) C:\Users\Game\AppData\Local\Facebook\Update\FacebookUpdate.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint II\SetPointII.exe
(Ask) C:\Program Files (x86)\Ask.com\Updater\Updater.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
() C:\Users\Game\AppData\Roaming\PTS\run.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.Exe [130576 2009-06-17] (Logitech, Inc.)
HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Facebook Update] - C:\Users\Game\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.)
HKCU\...\Run: [EPSON SX218 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGDE.EXE /FU "C:\Windows\TEMP\E_S11CC.tmp" /EF "HKCU"
HKCU\...\Run: [Google Update] - C:\Users\Game\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-09-05] (Google Inc.)
HKCU\...\Run: [PTS Software] - C:\Users\Game\AppData\Roaming\PTS\PTS.exe [135680 2013-11-23] ()
HKCU\...\Policies\Explorer: [HideSCAHealth] 1
MountPoints2: I - I:\Autorun.exe
MountPoints2: {226e0497-3afb-11e3-81a8-806e6f6e6963} - M:\Autorun.exe
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ApnUpdater] - C:\Program Files (x86)\Ask.com\Updater\Updater.exe [1648264 2013-04-25] (Ask)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-18] (AVAST Software)
HKLM-x32\...\Run: [TrojanScanner] - C:\Program Files (x86)\Trojan Remover\Trjscan.exe [1658640 2013-11-11] (Simply Super Software)
HKU\Administrator\...\Run: [Connectify] - C:\Program Files (x86)\Connectify\Connectify.exe [2967368 2011-09-29] (Connectify)
HKU\Administrator\...\Run: [Desura] - C:\Program Files (x86)\Desura\desura.exe [2529096 2012-05-10] (Desura Pty Ltd)
HKU\Administrator\...\Run: [EPSON SX218 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGDE.EXE /FU "C:\Windows\TEMP\E_SFFB.tmp" /EF "HKCU"
HKU\Administrator\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-05] (DT Soft Ltd)
HKU\Administrator\...\Run: [Facebook Update] - C:\Users\Game\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.)
HKU\Administrator\...\Run: [RDReminder] - [x]
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-11-14] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~1\LUCIDL~1\VIRTU\x86\APPINI~1.DLL,C:\Windows\SysWOW64\nvinit.dll [141336 2013-11-14] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=DE&userid=242d611b-ab33-4ad2-924d-3bc2b6cd7f1a&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x116CFCAB8E3DCC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=DE&userid=242d611b-ab33-4ad2-924d-3bc2b6cd7f1a&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=7536725
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=7536725
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=7536725
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=DE&userid=242d611b-ab33-4ad2-924d-3bc2b6cd7f1a&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=7536725
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=DE&userid=242d611b-ab33-4ad2-924d-3bc2b6cd7f1a&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=DE&userid=242d611b-ab33-4ad2-924d-3bc2b6cd7f1a&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=7536725
SearchScopes: HKCU - {633AFB9E-1B2E-4338-A203-11E9E99A3093} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=IMB&o=15785&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=HQ&apn_dtid=YYYYYYYYDE&apn_uid=361451fd-25d6-4c6d-8814-a0a9df34b892&apn_sauid=D6B8CEB9-4198-47A3-B9B0-F867D449E7F5
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = hxxp://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {074C1DC5-9320-4A9A-947D-C042949C6216} - No File
BHO-x32: SmartView VisualBookmark - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files (x86)\DeviceVM\SmartView\SmartView.dll (DeviceVM, Inc.)
BHO-x32: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: PriceGong - Price Comparison - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.6.11\PriceGongIE.dll (PriceGong)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM-x32 - No Name - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - No File
Toolbar: HKLM-x32 - QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Winsock: Catalog9 01 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 02 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 03 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 04 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 05 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 06 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 07 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 08 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 09 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 10 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Winsock: Catalog9 21 D:\PROGRA~1\SPEEDB~1\sblsp.dll [251488] (Speedbit Ltd.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default
FF user.js: detected! => C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\user.js
FF NewTab: hxxp://www.delta-homes.com/newtab/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=nt&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1380358493
FF DefaultSearchEngine: delta-homes
FF SearchEngineOrder.1: delta-homes
FF SelectedSearchEngine: delta-homes
FF Homepage: hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
FF NetworkProxy: "autoconfig_url", "file:///C:/Users/Game/AppData/Local/RapidSolution/Videoraptor/WebRip/profile/rrproxy_ffox_4f679b34.pac"
FF NetworkProxy: "backup.ftp", ""
FF NetworkProxy: "backup.ftp_port", 0
FF NetworkProxy: "backup.socks", ""
FF NetworkProxy: "backup.socks_port", 0
FF NetworkProxy: "backup.ssl", ""
FF NetworkProxy: "backup.ssl_port", 0
FF NetworkProxy: "ftp", "www-proxy.t-online.de"
FF NetworkProxy: "ftp_port", 80
FF NetworkProxy: "http", "www-proxy.t-online.de"
FF NetworkProxy: "http_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "www-proxy.t-online.de"
FF NetworkProxy: "socks_port", 80
FF NetworkProxy: "ssl", "www-proxy.t-online.de"
FF NetworkProxy: "ssl_port", 80
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=1.122.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @idsoftware.com/QuakeLive - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - D:\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Game\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Game\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Game\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Game\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Game\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Game\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF SearchPlugin: C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\searchplugins\daemon-search.xml
FF SearchPlugin: C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\delta-homes.xml
FF Extension: DAEMON Tools Toolbar - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\DTToolbar@toolbarnet.com
FF Extension: Better Battlelog (BBLog) - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack
FF Extension: Ask Toolbar - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\toolbar@ask.com
FF Extension: ObviousIdea Addon - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\toolbarbutton@obviousidea.us
FF Extension: PriceGong - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
FF Extension: SaveFrom.net helper - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\helper@savefrom.net.xpi
FF Extension: Telekom YouTube Turbo - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\info@maltegoetz.de.xpi
FF Extension: Adblock Plus - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Adblock Edge - C:\Users\Game\AppData\Roaming\Mozilla\Firefox\Profiles\yaoraz5s.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
FF Extension: QuickStores-Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de
FF HKLM-x32\...\Firefox\Extensions: [{184AA5E6-741D-464a-820E-94B3ABC2F3B4}] - C:\Users\Game\AppData\Roaming\9001
FF Extension: Java String Helper - C:\Users\Game\AppData\Roaming\9001
FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - E:\Adobe Creative Suite 5 Master Collection\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF HKCU\...\Firefox\Extensions: [{184AA5E6-741D-464a-820E-94B3ABC2F3B4}] - C:\Users\Game\AppData\Roaming\9001
FF Extension: Java String Helper - C:\Users\Game\AppData\Roaming\9001
FF StartMenuInternet: FIREFOX.EXE - C:\Users\Game\AppData\Local\Mozilla Firefox\firefox.exe hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1373040620
Chrome:
=======
CHR HomePage: hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1377244790
CHR RestoreOnStartup: "hxxp://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1377244790"
CHR DefaultSearchKeyword: delta-homes
CHR DefaultSearchProvider: delta-homes
CHR DefaultSearchURL: hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=SAMSUNGXHD502IJ_S13TJ90Q888977&ts=1377244790&type=default&q={searchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Game\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Game\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Game\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Game\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (VLC Web Plugin) - D:\VLC\npvlc.dll (VideoLAN)
CHR Extension: (Google Docs) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (PriceGong) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.6.11_0
CHR Extension: (YouTube) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (ObviousIdea) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnefekibahpibgnllfjpckodgobkpije\2.0_0
CHR Extension: (AdBlock) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (ProxMate - Proxy on steroids!) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\3.0.9_0
CHR Extension: (Lightning Newtab) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.1.8.4_0
CHR Extension: (Google Wallet) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Battlefield 3) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\pagmklehiaheilihklokljahmoihkjni\1_1
CHR Extension: (Gmail) - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [bkomkajifikmkfnjgphkjcfeepbnojok] - C:\Program Files (x86)\PriceGong\2.6.11\pricegong.crx
CHR HKLM-x32\...\Chrome\Extension: [fnefekibahpibgnllfjpckodgobkpije] - C:\Users\Game\AppData\Local\ObviousIdea\extension.crx
CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Game\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
==================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-18] (AVAST Software)
S4 cFosSpeedS; C:\Program Files\ASRock\XFast LAN\spd.exe [395136 2011-07-04] (cFos Software GmbH)
S4 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [69632 2011-09-29] ()
S4 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe [153600 2010-09-17] (Firebird Project)
S4 FirebirdServerDefaultInstance; C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe [5624320 2010-09-17] (Firebird Project)
R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [275752 2008-01-22] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-11-29] ()
S4 SmartViewService; C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [125216 2010-09-02] (DeviceVM, Inc.)
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
S4 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2027840 2011-09-01] (TuneUp Software)
S4 VideoAcceleratorService; D:\Program Files (x86)\SpeedBit Video Accelerator\VideoAcceleratorService.exe [300656 2012-02-19] (Speedbit Ltd.)
S4 WCUService; C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [456976 2010-09-02] (DeviceVM, Inc.)
R2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [424104 2013-06-20] (Taiwan Shui Mu Chih Ching Technology Limited.)
R2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [303680 2013-08-22] (Wsys Co., Ltd.)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2013-12-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2013-12-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2013-12-18] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2013-12-20] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-10-31] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-18] ()
R1 cnnctfy2; C:\Windows\System32\DRIVERS\cnnctfy2.sys [31344 2012-04-06] (Connectify)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2012-01-14] (DT Soft Ltd)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWow64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2011-07-08] (FNet Co., Ltd.)
R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [54848 2010-07-22] (FSPro Labs)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation)
S3 SaiH075C; C:\Windows\System32\DRIVERS\SaiH075C.sys [326784 2006-07-27] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [22792 2010-08-10] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [50056 2010-08-10] (Saitek)
R3 TotRec8; C:\Windows\system32\drivers\TotRec8.sys [121424 2010-10-14] (High Criteria inc.)
S3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2011-07-07] (TuneUp Software)
S3 ALSysIO; \??\C:\Users\Game\AppData\Local\Temp\ALSysIO64.sys [x]
S3 EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
S4 sptd; \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [x]
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 X6va007; \??\C:\Users\Game\AppData\Local\Temp\0078BEA.tmp [x]
U3 pxtdqpow; \??\C:\Users\Game\AppData\Local\Temp\pxtdqpow.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-20 17:01 - 2013-12-20 17:01 - 00027460 _____ C:\Users\Game\Desktop\Gmer.log
2013-12-20 16:46 - 2013-12-20 17:03 - 00003697 _____ C:\Users\Game\Downloads\FRST.txt
2013-12-20 16:46 - 2013-12-20 16:46 - 00047043 _____ C:\Users\Game\Downloads\Addition.txt
2013-12-20 16:45 - 2013-12-20 16:45 - 02193141 _____ (Farbar) C:\Users\Game\Downloads\FRST64.exe
2013-12-20 16:45 - 2013-12-20 16:45 - 00000000 ____D C:\FRST
2013-12-20 16:44 - 2013-12-20 16:44 - 00000592 _____ C:\Users\Game\Downloads\defogger_disable.log
2013-12-20 16:44 - 2013-12-20 16:44 - 00000168 _____ C:\Users\Game\defogger_reenable
2013-12-20 16:43 - 2013-12-20 16:43 - 00050477 _____ C:\Users\Game\Downloads\Defogger.exe
2013-12-20 16:42 - 2013-12-20 16:42 - 00377856 _____ C:\Users\Game\Downloads\i0ceusog.exe
2013-12-20 16:33 - 2013-12-20 16:33 - 00142744 _____ C:\Users\Game\Downloads\vtuploader2.2.exe
2013-12-20 16:33 - 2013-12-20 16:33 - 00002090 _____ C:\Users\Game\Desktop\VirusTotal Uploader 2.2.lnk
2013-12-20 16:33 - 2013-12-20 16:33 - 00002090 _____ C:\Users\Administrator\Desktop\VirusTotal Uploader 2.2.lnk
2013-12-20 16:33 - 2013-12-20 16:33 - 00000000 ____D C:\Users\Game\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.2
2013-12-20 16:33 - 2013-12-20 16:33 - 00000000 ____D C:\Program Files (x86)\VirusTotalUploader2
2013-12-20 14:33 - 2013-12-20 14:33 - 00000000 ____D C:\Users\Game\AppData\Roaming\Simply Super Software
2013-12-20 13:58 - 2013-12-20 16:30 - 00000000 ____D C:\Program Files (x86)\Trojan Remover
2013-12-20 13:58 - 2013-12-20 13:58 - 00001154 _____ C:\Users\Public\Desktop\Trojan Remover.lnk
2013-12-20 13:58 - 2013-12-20 13:58 - 00001154 _____ C:\ProgramData\Desktop\Trojan Remover.lnk
2013-12-20 13:58 - 2013-12-20 13:58 - 00000000 ___DC C:\ProgramData\Simply Super Software
2013-12-20 13:58 - 2013-12-20 13:58 - 00000000 ____D C:\Users\Game\Documents\Simply Super Software
2013-12-20 13:42 - 2013-12-20 13:42 - 00001872 _____ C:\Users\Administrator\Desktop\UseNeXT by Tangysoft.lnk
2013-12-20 13:33 - 2013-12-20 13:33 - 00000000 ____D C:\Users\Administrator\AppData\Local\Apple
2013-12-20 13:25 - 2013-12-20 13:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVAST Software
2013-12-20 13:25 - 2013-12-20 13:25 - 00000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA Corporation
2013-12-20 13:24 - 2013-12-20 13:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA
2013-12-18 20:32 - 2013-12-18 20:32 - 00155176 _____ C:\Users\Game\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-18 19:02 - 2013-12-20 16:32 - 00001344 _____ C:\Windows\setupact.log
2013-12-18 19:02 - 2013-12-20 16:30 - 00001270 _____ C:\Windows\PFRO.log
2013-12-18 19:02 - 2013-12-18 19:02 - 05069208 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-18 19:02 - 2013-12-18 19:02 - 00000000 _____ C:\Windows\setuperr.log
2013-12-18 18:29 - 2013-12-18 18:29 - 00000000 ____D C:\Users\Game\AppData\Roaming\AVAST Software
2013-12-18 17:45 - 2013-11-20 10:13 - 03166600 _____ (AVAST Software) C:\Windows\system32\HTMLayout.dll
2013-12-18 17:41 - 2013-12-18 17:41 - 01388246 _____ C:\Users\Game\Downloads\htmlayout.zip
2013-12-18 17:16 - 2013-12-18 17:16 - 00000000 ____D C:\Users\Game\AppData\Roaming\PioneerLog
2013-12-18 17:16 - 2013-12-18 17:16 - 00000000 ____D C:\Users\Game\AppData\Roaming\Pioneer
2013-12-18 17:05 - 2013-12-18 17:05 - 00000892 _____ C:\Users\Game\Desktop\rekordbox 2.2.0.lnk
2013-12-18 17:05 - 2013-12-18 17:05 - 00000000 ____D C:\Users\Game\rekordbox 2.2.0
2013-12-18 17:05 - 2013-12-18 17:05 - 00000000 ____D C:\Users\Game\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pioneer
2013-12-18 16:56 - 2013-12-18 17:02 - 38990526 _____ (Pioneer) C:\Users\Game\Downloads\Install_rekordbox_2.2.0.20_3.exe
2013-12-18 15:33 - 2013-12-18 15:33 - 00001981 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-18 15:33 - 2013-12-18 15:33 - 00001981 _____ C:\ProgramData\Desktop\avast! Free Antivirus.lnk
2013-12-18 15:32 - 2013-12-20 15:33 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-18 15:25 - 2013-12-20 13:58 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-12-18 15:25 - 2013-12-18 15:32 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-18 15:25 - 2013-12-18 15:32 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-12-18 15:23 - 2013-12-18 15:23 - 00000000 ____D C:\Users\Game\AppData\Roaming\PTS
2013-12-17 18:33 - 2013-12-17 18:34 - 00000000 ____D C:\Users\Game\Desktop\Neuer Ordner (4)
2013-12-15 22:04 - 2013-12-15 22:04 - 04334528 _____ C:\Users\Game\Desktop\Microsoft Word-Dokument (neu).psd
2013-12-11 22:32 - 2013-12-11 22:32 - 02163529 _____ C:\Users\Game\Downloads\toasted_photoshop_actions_by_elestrial-d36yw97.zip
2013-12-11 22:32 - 2011-01-07 13:28 - 00040496 _____ C:\Users\Game\Desktop\Toasted.atn
2013-12-11 22:26 - 2013-12-11 22:28 - 00000000 ____D C:\Users\Game\Desktop\Neuer Ordner
2013-12-11 15:07 - 2013-12-11 15:07 - 00021904 _____ C:\Users\Game\Downloads\770_12_2013 (3).xlsx
2013-12-09 16:40 - 2013-12-09 16:40 - 00021904 _____ C:\Users\Game\Downloads\770_12_2013 (2).xlsx
2013-12-08 18:51 - 2013-12-08 18:51 - 00266051 _____ C:\Users\Game\Downloads\skse_1_06_16_installer (1).exe
2013-12-08 14:53 - 2013-12-08 18:51 - 00001076 _____ C:\Users\Game\Desktop\Skyrim (SKSE).lnk
2013-12-08 14:53 - 2013-12-08 18:51 - 00001076 _____ C:\Users\Administrator\Desktop\Skyrim (SKSE).lnk
2013-12-08 14:53 - 2013-12-08 14:53 - 00266051 _____ C:\Users\Game\Downloads\skse_1_06_16_installer.exe
2013-12-08 14:39 - 2013-12-08 14:39 - 00546166 _____ C:\Users\Game\Desktop\Real Vision ENB Data Files.zip
2013-12-08 14:38 - 2013-12-08 14:38 - 00000000 ____D C:\Users\Game\Desktop\enbseries_skyrim_v0239 (1)
2013-12-08 14:37 - 2013-12-08 14:37 - 02302256 _____ C:\Users\Game\Downloads\enbseries_skyrim_v0239.zip
2013-12-08 14:37 - 2013-12-08 14:37 - 02302256 _____ C:\Users\Game\Desktop\enbseries_skyrim_v0239 (1).zip
2013-12-08 13:26 - 2013-12-08 14:40 - 00000000 ____D C:\Users\Game\Desktop\RealVisionENB_V2.0a.239_FULL
2013-12-08 13:26 - 2013-12-08 13:26 - 01157327 _____ C:\Users\Game\Downloads\Option A - FULL - V2_0a_239 - CoT - RLO - SweetFX Lumasharpen - SMAA-30936-2-0a-239.zip
2013-12-08 13:08 - 2013-12-08 18:43 - 00000000 ____D C:\Users\Game\AppData\Local\Skyrim
2013-12-08 13:07 - 2013-12-08 13:08 - 00000201 _____ C:\Users\Game\Desktop\The Elder Scrolls V Skyrim.url
2013-12-08 13:04 - 2013-12-08 13:04 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2013-12-08 13:04 - 2013-12-08 13:04 - 00000607 _____ C:\ProgramData\Desktop\Nexus Mod Manager.lnk
2013-12-08 13:04 - 2013-12-08 13:04 - 00000000 ____D C:\Users\Game\Documents\Nexus Mod Manager
2013-12-08 13:04 - 2013-12-08 13:04 - 00000000 ____D C:\Users\Game\AppData\Local\Black_Tree_Gaming
2013-12-08 13:00 - 2013-12-08 13:01 - 04136616 _____ (Black Tree Gaming ) C:\Users\Game\Downloads\Nexus Mod Manager-0.46.0.exe
2013-12-08 12:46 - 2013-12-08 23:26 - 00000184 _____ C:\Users\Game\Desktop\Neues Textdokument.txt
2013-12-05 21:21 - 2013-12-05 21:34 - 1501608416 _____ C:\Users\Game\Desktop\walking.s04.e06.x264-IND (1).avi
2013-12-05 21:09 - 2013-12-05 21:21 - 1501608416 _____ C:\Users\Game\Desktop\wakin.dead.s04.e05.5.1.1080-pret.avi
2013-12-05 21:04 - 2013-12-05 21:05 - 00000000 ___DC C:\ProgramData\Freemake
2013-12-05 21:04 - 2013-12-05 21:05 - 00000000 ____D C:\Users\Game\Documents\Freemake
2013-12-05 21:04 - 2013-12-05 21:04 - 00001335 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk
2013-12-05 21:04 - 2013-12-05 21:04 - 00001335 _____ C:\ProgramData\Desktop\Freemake Video Converter.lnk
2013-12-05 21:04 - 2013-12-05 21:04 - 00000000 ____D C:\Users\Game\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2013-12-05 21:04 - 2013-12-05 21:04 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-12-05 21:03 - 2013-12-05 21:03 - 01271904 _____ (Ellora Assets Corporation ) C:\Users\Game\Downloads\Freemake4115VideoConverterSetup.exe
2013-12-05 20:55 - 2013-11-29 22:49 - 706658304 _____ C:\Users\Game\Desktop\wakin.dead.s04.e07.5.1.xvi-pret.avi
2013-12-05 20:55 - 2013-11-15 23:01 - 1935346394 _____ C:\Users\Game\Desktop\walking.s04.e06.x264-IND.avi
2013-12-04 21:12 - 2013-11-08 22:54 - 706783232 _____ C:\Users\Game\Desktop\wakin.dead.s04.e04.5.1.xvi-pret.avi
2013-12-04 21:12 - 2013-11-01 22:59 - 704763904 _____ C:\Users\Game\Desktop\wakin.dead.s04.e03.5.1.xvi-pret.avi
2013-12-04 17:15 - 2013-12-04 17:15 - 00031067 _____ C:\Users\Game\Downloads\770_01_2014.xlsx
2013-12-04 17:09 - 2013-12-04 17:09 - 00032296 _____ C:\Users\Game\Downloads\770_12_2013 (1).xlsx
2013-12-04 15:42 - 2013-12-04 15:42 - 00000000 ____D C:\Users\Game\AppData\Local\NVIDIA Corporation
2013-12-04 15:41 - 2013-10-30 18:03 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2013-12-04 15:41 - 2013-10-30 18:02 - 00032544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2013-12-03 16:54 - 2013-12-03 16:54 - 02095104 _____ C:\Users\Game\Downloads\QuakeLiveNP_520.msi
2013-12-03 16:54 - 2013-12-03 16:54 - 00000000 ___DC C:\ProgramData\id Software
2013-11-30 01:45 - 2013-11-29 17:56 - 01096480 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-30 01:45 - 2013-11-29 17:56 - 00979744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-30 01:41 - 2013-11-14 12:57 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 30361888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 22951200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 18208624 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 15862272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 12613408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-11-30 01:41 - 2013-11-14 12:56 - 11600432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 11514624 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 09691888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 09619872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433182.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433182.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00707360 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00657184 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00609568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00562464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00357152 _____ C:\Windows\system32\NvIFROpenGL.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00314656 _____ C:\Windows\SysWOW64\NvIFROpenGL.dll
2013-11-30 01:41 - 2013-11-14 12:56 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-11-30 01:41 - 2013-10-30 18:02 - 00035104 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2013-11-30 01:36 - 2013-11-30 01:39 - 255488144 _____ (NVIDIA Corporation) C:\Users\Game\Downloads\331.82-desktop-win8-win7-winvista-64bit-international-whql.exe
2013-11-30 01:34 - 2013-11-30 01:34 - 00000000 ___DC C:\ProgramData\Oracle
2013-11-30 01:33 - 2013-11-30 01:33 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-30 01:33 - 2013-11-30 01:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-30 01:33 - 2013-11-30 01:33 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-30 01:33 - 2013-11-30 01:33 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-30 01:31 - 2013-11-30 01:31 - 00915368 _____ (Oracle Corporation) C:\Users\Game\Downloads\chromeinstall-7u45.exe
2013-11-30 01:28 - 2013-11-30 01:28 - 03821064 _____ C:\Users\Game\Downloads\battlelog-web-plugins_2.3.2_130 (1).exe
2013-11-29 15:08 - 2013-11-29 15:08 - 03821064 _____ C:\Users\Game\Downloads\battlelog-web-plugins_2.3.2_130.exe
2013-11-27 21:25 - 2013-11-27 21:25 - 00008715 _____ C:\Users\Game\Downloads\spiderman.zip
2013-11-27 21:17 - 2013-11-27 21:17 - 00028016 _____ C:\Users\Game\Downloads\shaun-of-the-dead.zip
2013-11-25 20:10 - 2013-11-25 20:10 - 13079688 _____ (Microsoft Corporation) C:\Users\Game\Downloads\Silverlight_x64.exe
==================== One Month Modified Files and Folders =======
2013-12-20 17:03 - 2013-12-20 16:46 - 00003697 _____ C:\Users\Game\Downloads\FRST.txt
2013-12-20 17:03 - 2013-06-02 12:29 - 00000000 ____D C:\Program Files (x86)\WinZipper
2013-12-20 17:01 - 2013-12-20 17:01 - 00027460 _____ C:\Users\Game\Desktop\Gmer.log
2013-12-20 16:53 - 2012-02-01 14:56 - 00000000 ____D C:\Users\Game\AppData\Local\CrashDumps
2013-12-20 16:46 - 2013-12-20 16:46 - 00047043 _____ C:\Users\Game\Downloads\Addition.txt
2013-12-20 16:46 - 2012-09-05 19:07 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-20 16:45 - 2013-12-20 16:45 - 02193141 _____ (Farbar) C:\Users\Game\Downloads\FRST64.exe
2013-12-20 16:45 - 2013-12-20 16:45 - 00000000 ____D C:\FRST
2013-12-20 16:44 - 2013-12-20 16:44 - 00000592 _____ C:\Users\Game\Downloads\defogger_disable.log
2013-12-20 16:44 - 2013-12-20 16:44 - 00000168 _____ C:\Users\Game\defogger_reenable
2013-12-20 16:44 - 2011-07-08 17:07 - 00000000 ____D C:\Users\Game
2013-12-20 16:43 - 2013-12-20 16:43 - 00050477 _____ C:\Users\Game\Downloads\Defogger.exe
2013-12-20 16:42 - 2013-12-20 16:42 - 00377856 _____ C:\Users\Game\Downloads\i0ceusog.exe
2013-12-20 16:38 - 2012-12-20 14:48 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-997625092-1080858520-3280811444-1000UA.job
2013-12-20 16:37 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-20 16:37 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-20 16:35 - 2013-06-22 11:25 - 00812811 _____ C:\Windows\WindowsUpdate.log
2013-12-20 16:33 - 2013-12-20 16:33 - 00142744 _____ C:\Users\Game\Downloads\vtuploader2.2.exe
2013-12-20 16:33 - 2013-12-20 16:33 - 00002090 _____ C:\Users\Game\Desktop\VirusTotal Uploader 2.2.lnk
2013-12-20 16:33 - 2013-12-20 16:33 - 00002090 _____ C:\Users\Administrator\Desktop\VirusTotal Uploader 2.2.lnk
2013-12-20 16:33 - 2013-12-20 16:33 - 00000000 ____D C:\Users\Game\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.2
2013-12-20 16:33 - 2013-12-20 16:33 - 00000000 ____D C:\Program Files (x86)\VirusTotalUploader2
2013-12-20 16:32 - 2013-12-18 19:02 - 00001344 _____ C:\Windows\setupact.log
2013-12-20 16:30 - 2013-12-20 13:58 - 00000000 ____D C:\Program Files (x86)\Trojan Remover
2013-12-20 16:30 - 2013-12-18 19:02 - 00001270 _____ C:\Windows\PFRO.log
2013-12-20 16:30 - 2012-09-05 19:07 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-20 16:30 - 2012-01-15 00:03 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-20 16:30 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-20 16:17 - 2013-03-20 15:14 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-20 15:33 - 2013-12-18 15:32 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-20 14:33 - 2013-12-20 14:33 - 00000000 ____D C:\Users\Game\AppData\Roaming\Simply Super Software
2013-12-20 14:28 - 2011-07-08 17:12 - 00007607 _____ C:\Users\Game\AppData\Local\resmon.resmoncfg
2013-12-20 13:58 - 2013-12-20 13:58 - 00001154 _____ C:\Users\Public\Desktop\Trojan Remover.lnk
2013-12-20 13:58 - 2013-12-20 13:58 - 00001154 _____ C:\ProgramData\Desktop\Trojan Remover.lnk
2013-12-20 13:58 - 2013-12-20 13:58 - 00000000 ___DC C:\ProgramData\Simply Super Software
2013-12-20 13:58 - 2013-12-20 13:58 - 00000000 ____D C:\Users\Game\Documents\Simply Super Software
2013-12-20 13:58 - 2013-12-18 15:25 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-12-20 13:58 - 2013-02-10 22:20 - 00000000 ___DC C:\ProgramData\Licenses
2013-12-20 13:47 - 2012-05-25 12:16 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\UseNeXT
2013-12-20 13:42 - 2013-12-20 13:42 - 00001872 _____ C:\Users\Administrator\Desktop\UseNeXT by Tangysoft.lnk
2013-12-20 13:42 - 2012-05-25 12:16 - 00000000 ____D C:\Users\Administrator\Documents\UseNeXT
2013-12-20 13:42 - 2012-01-17 16:04 - 00000000 ____D C:\Program Files (x86)\UseNeXT
2013-12-20 13:33 - 2013-12-20 13:33 - 00000000 ____D C:\Users\Administrator\AppData\Local\Apple
2013-12-20 13:25 - 2013-12-20 13:25 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVAST Software
2013-12-20 13:25 - 2013-12-20 13:25 - 00000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA Corporation
2013-12-20 13:25 - 2012-05-25 12:16 - 00155176 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-20 13:24 - 2013-12-20 13:24 - 00000000 ____D C:\Users\Administrator\AppData\Local\NVIDIA
2013-12-19 21:52 - 2012-01-14 17:41 - 00000000 ____D C:\Users\Game\AppData\Roaming\UseNeXT
2013-12-19 20:38 - 2012-12-20 14:48 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-997625092-1080858520-3280811444-1000Core.job
2013-12-19 16:15 - 2012-03-18 12:43 - 00000000 ___RD C:\Users\Game\Desktop\D-J
2013-12-18 20:32 - 2013-12-18 20:32 - 00155176 _____ C:\Users\Game\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-18 19:43 - 2013-05-30 18:53 - 00000000 ___DC C:\ProgramData\eSafe
2013-12-18 19:02 - 2013-12-18 19:02 - 05069208 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-18 19:02 - 2013-12-18 19:02 - 00000000 _____ C:\Windows\setuperr.log
2013-12-18 18:48 - 2013-10-06 21:17 - 00000000 ____D C:\Users\Game\AppData\Roaming\TS3Client
2013-12-18 18:48 - 2012-01-14 17:58 - 00000000 ____D C:\Users\Game\AppData\Roaming\DAEMON Tools Lite
2013-12-18 18:29 - 2013-12-18 18:29 - 00000000 ____D C:\Users\Game\AppData\Roaming\AVAST Software
2013-12-18 17:41 - 2013-12-18 17:41 - 01388246 _____ C:\Users\Game\Downloads\htmlayout.zip
2013-12-18 17:16 - 2013-12-18 17:16 - 00000000 ____D C:\Users\Game\AppData\Roaming\PioneerLog
2013-12-18 17:16 - 2013-12-18 17:16 - 00000000 ____D C:\Users\Game\AppData\Roaming\Pioneer
2013-12-18 17:05 - 2013-12-18 17:05 - 00000892 _____ C:\Users\Game\Desktop\rekordbox 2.2.0.lnk
2013-12-18 17:05 - 2013-12-18 17:05 - 00000000 ____D C:\Users\Game\rekordbox 2.2.0
2013-12-18 17:05 - 2013-12-18 17:05 - 00000000 ____D C:\Users\Game\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pioneer
2013-12-18 17:02 - 2013-12-18 16:56 - 38990526 _____ (Pioneer) C:\Users\Game\Downloads\Install_rekordbox_2.2.0.20_3.exe
2013-12-18 15:33 - 2013-12-18 15:33 - 00001981 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-18 15:33 - 2013-12-18 15:33 - 00001981 _____ C:\ProgramData\Desktop\avast! Free Antivirus.lnk
2013-12-18 15:32 - 2013-12-18 15:25 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-18 15:32 - 2013-12-18 15:25 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-12-18 15:32 - 2012-07-03 22:05 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-12-18 15:32 - 2012-07-03 22:05 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-12-18 15:32 - 2012-07-03 22:04 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-18 15:32 - 2012-07-03 22:04 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-18 15:32 - 2012-07-03 22:04 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-18 15:32 - 2012-07-03 22:04 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-18 15:26 - 2012-07-03 22:04 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-18 15:25 - 2012-07-03 22:04 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-12-18 15:23 - 2013-12-18 15:23 - 00000000 ____D C:\Users\Game\AppData\Roaming\PTS
2013-12-17 20:23 - 2012-12-02 20:07 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-12-17 18:46 - 2012-04-17 14:12 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-17 18:34 - 2013-12-17 18:33 - 00000000 ____D C:\Users\Game\Desktop\Neuer Ordner (4)
2013-12-17 16:36 - 2012-01-14 21:02 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-12-15 22:04 - 2013-12-15 22:04 - 04334528 _____ C:\Users\Game\Desktop\Microsoft Word-Dokument (neu).psd
2013-12-15 22:04 - 2012-07-03 21:11 - 00000000 ___RD C:\Users\Game\Desktop\Wichtig
2013-12-13 15:16 - 2012-12-19 11:15 - 00000000 ____D C:\steam
2013-12-11 22:32 - 2013-12-11 22:32 - 02163529 _____ C:\Users\Game\Downloads\toasted_photoshop_actions_by_elestrial-d36yw97.zip
2013-12-11 22:28 - 2013-12-11 22:26 - 00000000 ____D C:\Users\Game\Desktop\Neuer Ordner
2013-12-11 15:07 - 2013-12-11 15:07 - 00021904 _____ C:\Users\Game\Downloads\770_12_2013 (3).xlsx
2013-12-10 21:17 - 2013-09-22 19:17 - 09293192 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-12-10 21:17 - 2013-03-20 15:14 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 21:17 - 2013-03-20 15:14 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 21:17 - 2011-07-08 17:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-09 16:40 - 2013-12-09 16:40 - 00021904 _____ C:\Users\Game\Downloads\770_12_2013 (2).xlsx
2013-12-08 23:26 - 2013-12-08 12:46 - 00000184 _____ C:\Users\Game\Desktop\Neues Textdokument.txt
2013-12-08 18:51 - 2013-12-08 18:51 - 00266051 _____ C:\Users\Game\Downloads\skse_1_06_16_installer (1).exe
2013-12-08 18:51 - 2013-12-08 14:53 - 00001076 _____ C:\Users\Game\Desktop\Skyrim (SKSE).lnk
2013-12-08 18:51 - 2013-12-08 14:53 - 00001076 _____ C:\Users\Administrator\Desktop\Skyrim (SKSE).lnk
2013-12-08 18:43 - 2013-12-08 13:08 - 00000000 ____D C:\Users\Game\AppData\Local\Skyrim
2013-12-08 14:53 - 2013-12-08 14:53 - 00266051 _____ C:\Users\Game\Downloads\skse_1_06_16_installer.exe
2013-12-08 14:40 - 2013-12-08 13:26 - 00000000 ____D C:\Users\Game\Desktop\RealVisionENB_V2.0a.239_FULL
2013-12-08 14:39 - 2013-12-08 14:39 - 00546166 _____ C:\Users\Game\Desktop\Real Vision ENB Data Files.zip
2013-12-08 14:38 - 2013-12-08 14:38 - 00000000 ____D C:\Users\Game\Desktop\enbseries_skyrim_v0239 (1)
2013-12-08 14:37 - 2013-12-08 14:37 - 02302256 _____ C:\Users\Game\Downloads\enbseries_skyrim_v0239.zip
2013-12-08 14:37 - 2013-12-08 14:37 - 02302256 _____ C:\Users\Game\Desktop\enbseries_skyrim_v0239 (1).zip
2013-12-08 13:26 - 2013-12-08 13:26 - 01157327 _____ C:\Users\Game\Downloads\Option A - FULL - V2_0a_239 - CoT - RLO - SweetFX Lumasharpen - SMAA-30936-2-0a-239.zip
2013-12-08 13:08 - 2013-12-08 13:07 - 00000201 _____ C:\Users\Game\Desktop\The Elder Scrolls V Skyrim.url
2013-12-08 13:08 - 2012-03-10 17:29 - 00000000 ____D C:\Users\Game\Documents\My Games
2013-12-08 13:04 - 2013-12-08 13:04 - 00000607 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2013-12-08 13:04 - 2013-12-08 13:04 - 00000607 _____ C:\ProgramData\Desktop\Nexus Mod Manager.lnk
2013-12-08 13:04 - 2013-12-08 13:04 - 00000000 ____D C:\Users\Game\Documents\Nexus Mod Manager
2013-12-08 13:04 - 2013-12-08 13:04 - 00000000 ____D C:\Users\Game\AppData\Local\Black_Tree_Gaming
2013-12-08 13:01 - 2013-12-08 13:00 - 04136616 _____ (Black Tree Gaming ) C:\Users\Game\Downloads\Nexus Mod Manager-0.46.0.exe
2013-12-05 22:58 - 2012-02-24 12:18 - 00000000 ____D C:\Users\Game\AppData\Roaming\vlc
2013-12-05 21:34 - 2013-12-05 21:21 - 1501608416 _____ C:\Users\Game\Desktop\walking.s04.e06.x264-IND (1).avi
2013-12-05 21:21 - 2013-12-05 21:09 - 1501608416 _____ C:\Users\Game\Desktop\wakin.dead.s04.e05.5.1.1080-pret.avi
2013-12-05 21:05 - 2013-12-05 21:04 - 00000000 ___DC C:\ProgramData\Freemake
2013-12-05 21:05 - 2013-12-05 21:04 - 00000000 ____D C:\Users\Game\Documents\Freemake
2013-12-05 21:04 - 2013-12-05 21:04 - 00001335 _____ C:\Users\Public\Desktop\Freemake Video Converter.lnk
2013-12-05 21:04 - 2013-12-05 21:04 - 00001335 _____ C:\ProgramData\Desktop\Freemake Video Converter.lnk
2013-12-05 21:04 - 2013-12-05 21:04 - 00000000 ____D C:\Users\Game\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2013-12-05 21:04 - 2013-12-05 21:04 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-12-05 21:03 - 2013-12-05 21:03 - 01271904 _____ (Ellora Assets Corporation ) C:\Users\Game\Downloads\Freemake4115VideoConverterSetup.exe
2013-12-05 18:39 - 2013-10-03 17:25 - 00000000 ____D C:\Users\Game\Desktop\Neuer Ordner (3)
2013-12-04 17:15 - 2013-12-04 17:15 - 00031067 _____ C:\Users\Game\Downloads\770_01_2014.xlsx
2013-12-04 17:09 - 2013-12-04 17:09 - 00032296 _____ C:\Users\Game\Downloads\770_12_2013 (1).xlsx
2013-12-04 15:43 - 2013-06-20 15:07 - 00000000 ____D C:\Users\Game\AppData\Local\NVIDIA
2013-12-04 15:42 - 2013-12-04 15:42 - 00000000 ____D C:\Users\Game\AppData\Local\NVIDIA Corporation
2013-12-04 15:42 - 2012-01-15 00:03 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-12-04 15:41 - 2012-01-15 00:03 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-12-04 15:41 - 2012-01-15 00:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-12-03 16:54 - 2013-12-03 16:54 - 02095104 _____ C:\Users\Game\Downloads\QuakeLiveNP_520.msi
2013-12-03 16:54 - 2013-12-03 16:54 - 00000000 ___DC C:\ProgramData\id Software
2013-12-02 20:33 - 2012-12-20 14:48 - 00004084 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-997625092-1080858520-3280811444-1000UA
2013-12-02 20:33 - 2012-12-20 14:48 - 00003688 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-997625092-1080858520-3280811444-1000Core
2013-12-02 20:17 - 2012-01-15 09:22 - 00000000 ____D C:\Windows\Minidump
2013-12-01 20:52 - 2013-10-06 21:16 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2013-12-01 20:41 - 2012-04-17 14:12 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-01 20:41 - 2012-04-17 14:12 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-01 18:56 - 2012-01-27 16:14 - 00000000 ___RD C:\Users\Game\Desktop\Schreiben
2013-11-30 21:23 - 2012-01-27 16:11 - 00000000 ___RD C:\Users\Game\Desktop\Spiele
2013-11-30 20:29 - 2012-01-15 08:53 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-11-30 01:39 - 2013-11-30 01:36 - 255488144 _____ (NVIDIA Corporation) C:\Users\Game\Downloads\331.82-desktop-win8-win7-winvista-64bit-international-whql.exe
2013-11-30 01:34 - 2013-11-30 01:34 - 00000000 ___DC C:\ProgramData\Oracle
2013-11-30 01:33 - 2013-11-30 01:33 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-30 01:33 - 2013-11-30 01:33 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-30 01:33 - 2013-11-30 01:33 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-30 01:33 - 2013-11-30 01:33 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-30 01:31 - 2013-11-30 01:31 - 00915368 _____ (Oracle Corporation) C:\Users\Game\Downloads\chromeinstall-7u45.exe
2013-11-30 01:28 - 2013-11-30 01:28 - 03821064 _____ C:\Users\Game\Downloads\battlelog-web-plugins_2.3.2_130 (1).exe
2013-11-29 22:49 - 2013-12-05 20:55 - 706658304 _____ C:\Users\Game\Desktop\wakin.dead.s04.e07.5.1.xvi-pret.avi
2013-11-29 17:56 - 2013-11-30 01:45 - 01096480 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2013-11-29 17:56 - 2013-11-30 01:45 - 00979744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2013-11-29 15:08 - 2013-11-29 15:08 - 03821064 _____ C:\Users\Game\Downloads\battlelog-web-plugins_2.3.2_130.exe
2013-11-29 15:06 - 2012-12-02 20:07 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-11-27 21:25 - 2013-11-27 21:25 - 00008715 _____ C:\Users\Game\Downloads\spiderman.zip
2013-11-27 21:17 - 2013-11-27 21:17 - 00028016 _____ C:\Users\Game\Downloads\shaun-of-the-dead.zip
2013-11-26 20:54 - 2012-01-22 13:17 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-11-26 20:54 - 2012-01-22 13:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-11-25 20:10 - 2013-11-25 20:10 - 13079688 _____ (Microsoft Corporation) C:\Users\Game\Downloads\Silverlight_x64.exe
2013-11-24 23:23 - 2013-01-10 20:25 - 00000000 ____D C:\Users\Game\AppData\Roaming\Audacity
2013-11-24 20:00 - 2009-07-14 18:58 - 00774626 _____ C:\Windows\system32\perfh007.dat
2013-11-24 20:00 - 2009-07-14 18:58 - 00175852 _____ C:\Windows\system32\perfc007.dat
2013-11-24 20:00 - 2009-07-14 06:13 - 01818242 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-20 10:13 - 2013-12-18 17:45 - 03166600 _____ (AVAST Software) C:\Windows\system32\HTMLayout.dll
Files to move or delete:
====================
C:\ProgramData\00etadpu.pad
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\cz7orvjd.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-11 16:46
==================== End Of Log ============================ --- --- ---
--- --- --- |