acskater | 22.08.2014 00:43 | Hier alle Logs:
mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.08.2014
Suchlauf-Zeit: 00:54:51
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.03.04.09
Rootkit Datenbank: v2014.08.16.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
B?sartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Tim
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 321852
Verstrichene Zeit: 5 Min, 48 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschl?ssel: 31
PUP.Optional.Kozaka.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Kozaka, In Quarant?ne, [72d71ee14931f640c2c6c4c979882cd4],
PUP.Optional.Kozaka.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Kozaka, In Quarant?ne, [af9abc434b2fdb5b6523d1bc60a108f8],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarant?ne, [c485d9267604f244b54eadc79b67c23e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarant?ne, [c485d9267604f244b54eadc79b67c23e],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarant?ne, [84c50ff099e1e353fa291361f0121be5],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarant?ne, [84c50ff099e1e353fa291361f0121be5],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarant?ne, [dd6c966951290f27f4b7023d8e74e818],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarant?ne, [dd6c966951290f27f4b7023d8e74e818],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC}, In Quarant?ne, [d1787b84ceac1224696299a5b34fd32d],
PUP.Optional.Kozaka.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{a45e3fa8-5048-4372-94ad-c6661671f7fc}, In Quarant?ne, [1039fb04b9c147ef38ace65a56acd42c],
PUP.Optional.Kozaka.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A45E3FA8-5048-4372-94AD-C6661671F7FC}, In Quarant?ne, [1039fb04b9c147ef38ace65a56acd42c],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DEDAF650-12B8-48f5-A843-BBA100716106}, In Quarant?ne, [50f936c9a3d7be78048aa49d1ae8f10f],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarant?ne, [57f2ae51d8a26dc9d8aa201f758d05fb],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarant?ne, [57f2ae51d8a26dc9d8aa201f758d05fb],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarant?ne, [57f2ae51d8a26dc9d8aa201f758d05fb],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarant?ne, [57f2ae51d8a26dc9d8aa201f758d05fb],
PUP.Optional.Kozaka.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Kozaka, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\Updater By Sweetpacks, In Quarant?ne, [91b800ff95e555e1acb8fcb49073a060],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarant?ne, [d1787986e7933afc2284417558ab05fb],
PUP.Optional.Kozaka.A, HKLM\SOFTWARE\WOW6432NODE\Kozaka, In Quarant?ne, [c98005fac7b364d2aca18f26f0133ec2],
PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\WOW6432NODE\Updater By Sweetpacks, In Quarant?ne, [b7922ad5a6d4bd7900641c945da65ea2],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarant?ne, [3613a659cab0092d5b4bfabce71ce51b],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarant?ne, [bc8da659423859ddcef0e5c6a0631be5],
PUP.Optional.ConduitSearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarant?ne, [57f2be417505f442c8fd575040c324dc],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarant?ne, [5dec1fe02e4cd363abfbbaf034cf13ed],
PUP.Optional.Delta.A, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\delta LTD, In Quarant?ne, [8cbde81727530036da8bcddfa85b36ca],
PUP.Optional.Kozaka.A, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Kozaka, In Quarant?ne, [66e3926dcbaf0f2774da40756c979070],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarant?ne, [e0698c73f08af3438918e5a91be70ef2],
PUP.Optional.Qone8, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarant?ne, [71d8e916e199af871293dbdb43c0d030],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarant?ne, [87c2ed120773d0669726e9c282815aa6],
PUP.Optional.AdvancedSystemProtector.A, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\Advanced System Protector, In Quarant?ne, [83c653ac80fafe38a7e404acbc47c63a],
Registrierungswerte: 2
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 84316671843664557381350634965991054953, In Quarant?ne, [bc8da659423859ddcef0e5c6a0631be5]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 84316671843664557381350634965991054953, In Quarant?ne, [87c2ed120773d0669726e9c282815aa6]
Registrierungsdaten: 4
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[4efbb44be298de583e05d25d2cd8649c]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[d3760cf33a40280e8ab9fc336a9aa957]
PUP.Optional.Snapdo, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=ab85d63e-c4a3-4a94-a917-32f9b0326192&searchtype=ds&q={searchTerms}&installDate=02/07/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=ab85d63e-c4a3-4a94-a917-32f9b0326192&searchtype=ds&q={searchTerms}&installDate=02/07/2013),Ersetzt,[6fdaf80792e8082eb9fc1c125ea6f40c]
PUP.Optional.Snapdo, HKU\S-1-5-21-1944573492-1714721241-4137265928-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=ab85d63e-c4a3-4a94-a917-32f9b0326192&searchtype=ds&q={searchTerms}&installDate=02/07/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=DE&userid=ab85d63e-c4a3-4a94-a917-32f9b0326192&searchtype=ds&q={searchTerms}&installDate=02/07/2013),Ersetzt,[83c615ea73076acc00b6c46afa0a8e72]
Ordner: 20
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka, L?schen bei Neustart, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin\plugins, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.OpenCandy, C:\Users\Tim\AppData\Roaming\OpenCandy, In Quarant?ne, [b198ed12b9c1c0764546f98dff031ae6],
PUP.Optional.OpenCandy, C:\Users\Tim\AppData\Roaming\OpenCandy\12EFF042721E4414ADC1AE4670E47443, In Quarant?ne, [b198ed12b9c1c0764546f98dff031ae6],
PUP.Optional.OpenCandy, C:\Users\Tim\AppData\Roaming\OpenCandy\8CB86EB8B88646C1B4CD4C6E5751A769, In Quarant?ne, [b198ed12b9c1c0764546f98dff031ae6],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ch, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\chrome, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\chrome\content, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ie, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ch, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\chrome, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\chrome\content, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ie, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.Kozaka.A, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciekghplkkgcmofonmkmlomhkamochd, In Quarant?ne, [97b20df2e9918fa791f4acdd31d107f9],
PUP.Optional.Kozaka.A, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciekghplkkgcmofonmkmlomhkamochd\1.0.0_0, In Quarant?ne, [97b20df2e9918fa791f4acdd31d107f9],
Dateien: 39
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\updateKozaka.exe, In Quarant?ne, [72d71ee14931f640c2c6c4c979882cd4],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin\utilKozaka.exe, In Quarant?ne, [af9abc434b2fdb5b6523d1bc60a108f8],
PUP.Optional.Babylon.A, C:\Users\Tim\AppData\Roaming\OpenCandy\12EFF042721E4414ADC1AE4670E47443\DeltaTB.exe, In Quarant?ne, [c188af50b5c580b6fce1ff48c8398c74],
PUP.Optional.PriceGong.A, C:\Users\Tim\AppData\Local\DownloadGuide\Offers\pricegong.exe, In Quarant?ne, [2b1e0ef1a6d434029d67722f91704bb5],
PUP.Optional.QuickShare.A, C:\Users\Tim\AppData\Local\DownloadGuide\Offers\quickshare.exe, In Quarant?ne, [1039906f38429d99ea260963758b7e82],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarant?ne, [ec5d4db24337a09648cee6a88d75837d],
Trojan.Agent.Gen, C:\Users\Tim\AppData\Roaming\Tim-wchelper.dll, In Quarant?ne, [60e9ad52d2a836006f77deaa4bb88080],
PUP.Optional.CSBrowserAssistant.A, C:\Program Files (x86)\CSBrowserHelper\cs-browser-assistant.exe, In Quarant?ne, [89c0ef10cab0ac8a1a9a4a69ed169868],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\Kozaka.ico, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\KozakaUninstall.exe, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\mciekghplkkgcmofonmkmlomhkamochd.crx, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\sqlite3.exe, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\updateKozaka.InstallState, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin\sqlite3.dll, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin\utilKozaka.InstallState, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin\plugins\Kozaka.FFUpdate.dll, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin\plugins\Kozaka.GCUpdate.dll, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.Kozaka.A, C:\Program Files (x86)\Kozaka\bin\plugins\Kozaka.IEUpdate.dll, In Quarant?ne, [6ddc12ed81f9e551e16b06afd92a7c84],
PUP.Optional.OpenCandy, C:\Users\Tim\AppData\Roaming\OpenCandy\8CB86EB8B88646C1B4CD4C6E5751A769\TuneUpUtilities2013-2200217_de-DE.exe, In Quarant?ne, [b198ed12b9c1c0764546f98dff031ae6],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ch\Chrome.crx, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\BetterSurf.xpi, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\build.cmd, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\chrome.manifest, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\install.rdf, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\chrome\content\firefox.js, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\chrome\content\inject.js, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\BetterSurf\ff\chrome\content\overlay.xul, In Quarant?ne, [c386847bbcbef046955dd4b3f210ea16],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ch\Chrome.crx, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\Better-Surf.xpi, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\build.cmd, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\chrome.manifest, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\install.rdf, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\chrome\content\better-surf.js, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\chrome\content\firefox.js, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.BetterSurf, C:\Program Files (x86)\Better-Surf\ff\chrome\content\overlay.xul, In Quarant?ne, [094023dc0971b6802a10196ffa08d62a],
PUP.Optional.Kozaka.A, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciekghplkkgcmofonmkmlomhkamochd\1.0.0_0\background.js, In Quarant?ne, [97b20df2e9918fa791f4acdd31d107f9],
PUP.Optional.Kozaka.A, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciekghplkkgcmofonmkmlomhkamochd\1.0.0_0\content.js, In Quarant?ne, [97b20df2e9918fa791f4acdd31d107f9],
PUP.Optional.Kozaka.A, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciekghplkkgcmofonmkmlomhkamochd\1.0.0_0\icon.png, In Quarant?ne, [97b20df2e9918fa791f4acdd31d107f9],
PUP.Optional.Kozaka.A, C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciekghplkkgcmofonmkmlomhkamochd\1.0.0_0\manifest.json, In Quarant?ne, [97b20df2e9918fa791f4acdd31d107f9],
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v3.308 - Bericht erstellt am 22/08/2014 um 01:25:45
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Tim - TIM-PC
# Gestartet von : C:\Users\Tim\Desktop\adwcleaner_3.308.exe
# Option : L?schen
***** [ Dienste ] *****
[#] Dienst Gel?scht : SCBackService
***** [ Dateien / Ordner ] *****
Ordner Gel?scht : C:\ProgramData\Babylon
Ordner Gel?scht : C:\ProgramData\Systweak
Ordner Gel?scht : C:\Program Files (x86)\ASP
Ordner Gel?scht : C:\Program Files (x86)\CSBrowserHelper
Ordner Gel?scht : C:\Program Files (x86)\SimpleFiles
Ordner Gel?scht : C:\Program Files (x86)\VideoPlayerV3
Ordner Gel?scht : C:\Windows\SysWOW64\SearchProtect
Ordner Gel?scht : C:\Users\Tim\AppData\Local\DownloadGuide
Ordner Gel?scht : C:\Users\Tim\AppData\Local\SearchProtect
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\Advanced System Protector
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\Babylon
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\goforfiles
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\Systweak
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\webssearches
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\120
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\125
Ordner Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\128
Ordner Gel?scht : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\dedmngkbaffkenlfdcbganndoghblmap
Ordner Gel?scht : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Ordner Gel?scht : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\poheodfamflhhhdcmjfeggbgigeefaco
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
Datei Gel?scht : C:\Windows\System32\sasnative64.exe
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\foxydeal.sqlite
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\invalidprefs.js
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\searchplugins\Babylon.xml
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\searchplugins\BrowserDefender.xml
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\searchplugins\delta.xml
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\searchplugins\trovi-search.xml
Datei Gel?scht : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\searchplugins\Web Search.xml
Datei Gel?scht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml
Datei Gel?scht : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
Datei Gel?scht : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gel?scht : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Tasks ] *****
Task Gel?scht : Advanced System Protector
Task Gel?scht : Advanced System Protector_startup
Task Gel?scht : GoforFilesUpdate
Task Gel?scht : Update Service SimpleFiles
***** [ Verkn?pfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gel?scht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Wert Gel?scht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Wert Gel?scht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [12x3q@3244516.com]
Wert Gel?scht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Wert Gel?scht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [xz123@ya456.com]
Schl?ssel Gel?scht : HKLM\SOFTWARE\Google\Chrome\Extensions\dedmngkbaffkenlfdcbganndoghblmap
Schl?ssel Gel?scht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schl?ssel Gel?scht : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Schl?ssel Gel?scht : HKLM\SOFTWARE\Google\Chrome\Extensions\poheodfamflhhhdcmjfeggbgigeefaco
Schl?ssel Gel?scht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\Prod.cap
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.FBServiceAPPEventsSink
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.FBServiceAPPEventsSink.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.OptionMenu
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.OptionMenu.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.Protocol
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.Protocol.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.VisualBookmark
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.VisualBookmark.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.WebObject
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STC.WebObject.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STCHelper.BHOHelper
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STCHelper.BHOHelper.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STCHelper.FBServiceAPP
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STCHelper.FBServiceAPP.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STCHelper.Protocol
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\STCHelper.Protocol.1
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS
Schl?ssel Gel?scht : HKCU\Software\d57d8d9b66dbf43
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\AppID\{82A5CE4D-AF0C-45B6-8AF8-75625BE6A08D}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\AppID\{B2B7E0CD-E169-43B3-A233-E129610EE314}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{0DEC13F0-5C8C-4147-8329-6CDFAD9755B7}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{0E5680D1-BF44-4929-94AF-FD30D784AD1D}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{0F3DC9E0-C459-4A40-BCF8-747BD9322E10}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{5E97F0FA-3B44-4634-A87E-8B0D5CFD6365}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{951F5841-FD1E-4F1D-8607-67B174DBD753}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{D1CCB0CC-DA45-4797-93D3-DEE7A13F8177}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{DCE24E28-D8EF-49BE-BC01-A1DD3B58FCE3}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{E4F7F1A5-490E-4884-A9E3-CBD6A25749E1}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422182296}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\Interface\{462862BE-9A5C-49A5-9CBD-A649EAC63645}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\TypeLib\{4E8E0178-00EF-413D-9324-E7B3E31572E3}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\TypeLib\{A1A533A8-E106-422B-AE29-D0025269AF83}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Classes\TypeLib\{B1759D04-0EF9-472A-B5C3-C774997B5321}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E5680D1-BF44-4929-94AF-FD30D784AD1D}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E5680D1-BF44-4929-94AF-FD30D784AD1D}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E5680D1-BF44-4929-94AF-FD30D784AD1D}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6492E171-2427-4932-B414-33574A089F5E}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80ED3EBC-CC05-4336-ABCC-295798855718}
Schl?ssel Gel?scht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schl?ssel Gel?scht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Wert Gel?scht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gel?scht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Classes\Interface\{462862BE-9A5C-49A5-9CBD-A649EAC63645}
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Wert Gel?scht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
Schl?ssel Gel?scht : HKCU\Software\AVG Secure Search
Schl?ssel Gel?scht : HKCU\Software\BI
Schl?ssel Gel?scht : HKCU\Software\clicup
Schl?ssel Gel?scht : HKCU\Software\GoforFiles
Schl?ssel Gel?scht : HKCU\Software\lollipop
Schl?ssel Gel?scht : HKCU\Software\OCS
Schl?ssel Gel?scht : HKCU\Software\powerpack
Schl?ssel Gel?scht : HKCU\Software\Softonic
Schl?ssel Gel?scht : HKCU\Software\systweak
Schl?ssel Gel?scht : HKCU\Software\AppDataLow\Software\DynConIE
Schl?ssel Gel?scht : HKCU\Software\AppDataLow\Software\lyricsspeaker
Schl?ssel Gel?scht : HKLM\SOFTWARE\DataMngr
Schl?ssel Gel?scht : HKLM\SOFTWARE\GoforFiles
Schl?ssel Gel?scht : HKLM\SOFTWARE\systweak
Schl?ssel Gel?scht : HKLM\SOFTWARE\webssearchesSoftware
Schl?ssel Gel?scht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17239
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\prefs.js ]
Zeile gel?scht : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
Zeile gel?scht : user_pref("extensions.crossrider.bic", "141c263742fd2ffff1087ea59bc03147");
Zeile gel?scht : user_pref("extensions.delta.admin", false);
Zeile gel?scht : user_pref("extensions.delta.aflt", "babsst");
Zeile gel?scht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gel?scht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gel?scht : user_pref("extensions.delta.dfltLng", "de");
Zeile gel?scht : user_pref("extensions.delta.excTlbr", false);
Zeile gel?scht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gel?scht : user_pref("extensions.delta.id", "fa602ac2000000000000801f0244b0b7");
Zeile gel?scht : user_pref("extensions.delta.instlDay", "15902");
Zeile gel?scht : user_pref("extensions.delta.instlRef", "sst");
Zeile gel?scht : user_pref("extensions.delta.newTab", false);
Zeile gel?scht : user_pref("extensions.delta.prdct", "delta");
Zeile gel?scht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gel?scht : user_pref("extensions.delta.rvrt", "false");
Zeile gel?scht : user_pref("extensions.delta.smplGrp", "none");
Zeile gel?scht : user_pref("extensions.delta.tlbrId", "base");
Zeile gel?scht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gel?scht : user_pref("extensions.delta.vrsn", "1.8.21.5");
Zeile gel?scht : user_pref("extensions.delta.vrsnTs", "1.8.21.518:17:06");
Zeile gel?scht : user_pref("extensions.delta.vrsni", "1.8.21.5");
Zeile gel?scht : user_pref("extensions.delta_i.babExt", "");
Zeile gel?scht : user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4945");
Zeile gel?scht : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gel?scht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gel?scht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gel?scht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gel?scht : user_pref("extensions.helperbar.Visibility", false);
Zeile gel?scht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gel?scht : user_pref("extensions.helperbar.downloadprovider", "quickobrw");
Zeile gel?scht : user_pref("extensions.helperbar.installationid", "ab85d63e-c4a3-4a94-a917-32f9b0326192");
Zeile gel?scht : user_pref("extensions.helperbar.installdate", "02/07/2013");
Zeile gel?scht : user_pref("extensions.helperbar.publisher", "quickobrw");
Zeile gel?scht : user_pref("extensions.quick_start.enable_search1", false);
Zeile gel?scht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
Zeile gel?scht : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocationType=tb50-ff-aolsoftonic[...]
Zeile gel?scht : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_whiteList", "{\"search.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"searc[...]
Zeile gel?scht : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_product_name", "Updater By Sweetpacks");
-\\ Google Chrome v
[ Datei : C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gel?scht [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPC69F157A-485B-4345-81EE-45E2A1D6F0CF&q={searchTerms}&SSPV=
Gel?scht [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Gel?scht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M10217B56-E4B3-4A8F-AFC5-ABD92C4C8E96&SearchSource=58&CUI=&UM=6&UP=SP6B81003E-C349-4878-86C7-E830D76B6511&q={searchTerms}&SSPV=
Gel?scht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1406901417&from=exp&uid=WDCXWD10EARX-00N0YB0_WD-WMC0S036203962039&q={searchTerms}
Gel?scht [Startup_urls] : hxxp://istart.webssearches.com/?type=hp&ts=1406901417&from=exp&uid=WDCXWD10EARX-00N0YB0_WD-WMC0S036203962039
Gel?scht [Homepage] : hxxp://istart.webssearches.com/?type=hp&ts=1406901417&from=exp&uid=WDCXWD10EARX-00N0YB0_WD-WMC0S036203962039
Gel?scht [Extension] : dedmngkbaffkenlfdcbganndoghblmap
Gel?scht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gel?scht [Extension] : poheodfamflhhhdcmjfeggbgigeefaco
*************************
AdwCleaner[R0].txt - [19507 octets] - [22/08/2014 01:23:14]
AdwCleaner[S0].txt - [17585 octets] - [22/08/2014 01:25:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [17646 octets] ########## --- --- ---
[/CODE]
JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Lukas on 22.08.2014 at 1:31:21,34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] wcuservice_stc_ie
Successfully deleted: [Service] wcuservice_stc_ie
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1944573492-1714721241-4137265928-1000\Software\sweetim
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Lukas\AppData\Roaming\mozilla\firefox\profiles\tq0qfbtp.default\extensions\116
Successfully deleted: [Folder] C:\Users\Lukas\AppData\Roaming\mozilla\firefox\profiles\tq0qfbtp.default\extensions\122
Emptied folder: C:\Users\Lukas\AppData\Roaming\mozilla\firefox\profiles\tq0qfbtp.default\minidumps [215 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Lukas\appdata\local\Google\Chrome\User Data\Default\Extensions\dedmngkbaffkenlfdcbganndoghblmap
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.08.2014 at 1:34:58,87
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-08-2014
Ran by Tim (administrator) on TIM-PC on 22-08-2014 01:38:34
Running from C:\Users\Tim\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
() C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-1944573492-1714721241-4137265928-1000\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-1944573492-1714721241-4137265928-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll ()
ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll ()
ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: 178.219.241.114:3128
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x704A66C60A2CCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {3B88602C-2518-4ec4-A3BE-63E81FB15778} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms}
SearchScopes: HKCU - {454D3220-570C-453f-A9FB-688CD4A80D52} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{F3FD2A6E-8540-4939-A5C0-7EB156984D74}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
FireFox:
========
FF ProfilePath: C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default
FF Homepage: https://www.google.de/
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*'))%20%7B%20return%20'PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Tim\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Tim\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Die Siedler 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll (Ubisoft)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: HTTPS-Everywhere - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\https-everywhere@eff.org [2014-07-20]
FF Extension: Better Battlelog (BBLog) - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack [2014-07-16]
FF Extension: AutoCopy 2 - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\autocopy2@teo.pl.xpi [2014-08-01]
FF Extension: Easy Copy Paste - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\easycopypaste@everhelper.me.xpi [2014-08-01]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2014-08-21]
FF Extension: ProxTube - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-30]
FF Extension: Single Key Tab Switch - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\{a66191d8-898b-4a66-89be-d5b279477a54}.xpi [2014-08-01]
FF Extension: Adblock Plus - C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\tq0qfbtp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-02]
FF HKLM-x32\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}] - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}
FF Extension: Splashtop Connect Companion - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} [2013-08-08]
FF HKLM-x32\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}] - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}
FF Extension: Splashtop Connect - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} [2013-08-08]
FF HKLM-x32\...\Firefox\Extensions: [{d9284e50-81fc-11da-a72b-0800200c9a66}] - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66}
FF Extension: Yoono - C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66} [2013-08-08]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-05-20]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchKeyword: webssearches
CHR DefaultSearchProvider: webssearches
CHR DefaultSearchURL: hxxp://istart.webssearches.com/web/?type=ds&ts=1406901417&from=exp&uid=WDCXWD10EARX-00N0YB0_WD-WMC0S036203962039&q={searchTerms}
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Tim\AppData\Local\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Tim\AppData\Local\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Tim\AppData\Local\Google\Chrome\Application\35.0.1916.153\pdf.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Google Update) - C:\Users\Tim\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (ProxFlow) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2013-10-19]
CHR Extension: (Google Docs) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-17]
CHR Extension: (Google Drive) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-17]
CHR Extension: (Turn Off the Lights) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2013-10-19]
CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-17]
CHR Extension: (Adblock Plus) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-09-17]
CHR Extension: (CT Sobrio) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cogcpnmcioajbgpnmaeibpnjbepkbhec [2013-09-17]
CHR Extension: (Google-Suche) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-17]
CHR Extension: (AdBlock Premium) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj [2013-10-19]
CHR Extension: (Spotify Chrome Extension) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbjmlahipheaaghllkabfkpolljilkjb [2014-05-01]
CHR Extension: (SoundCloud) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipebkipbeggmmkjjljenoblnfaenambp [2013-11-18]
CHR Extension: (Better Battlelog (BBLog)) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjlfnjepjdmlppapoikepbaabbghofma [2014-05-01]
CHR Extension: (Google Mail-Checker) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2013-10-19]
CHR Extension: (My Cloud Player) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbfjhlpinelhnncgfpgfekddidnbnaab [2013-11-18]
CHR Extension: (Google Wallet) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-17]
CHR Extension: (No Name) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma [2014-08-01]
CHR Extension: (Google Mail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-17]
CHR Extension: (No Name) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\poheodfamflhhhdcmjfeggbgigeefaco [2013-11-25]
CHR HKLM-x32\...\Chrome\Extension: [mciekghplkkgcmofonmkmlomhkamochd] - C:\Program Files (x86)\Kozaka\mciekghplkkgcmofonmkmlomhkamochd.crx [2013-11-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-02-13] () [File not signed]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-07-16] (LogMeIn, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16941856 2014-02-05] (NVIDIA Corporation)
S4 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-20] ()
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
S4 UsbService; C:\Program Files\Eltima Software\USB Network Gate\UsbService64.exe [3865832 2013-09-11] (ELTIMA Software)
R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [14405200 2013-10-18] ()
S4 WCUService_STC_FF; C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [493384 2011-03-24] (Splashtop Inc.)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-17] (DT Soft Ltd)
S3 ElgatoGC658Y; C:\Windows\System32\Drivers\ElgatoGC658.sys [50288 2012-11-12] (UB658)
R3 ELTIMA_USB_HUB_FILTER; C:\Program Files\Eltima Software\USB Network Gate\drv\NT6x64\fusbhub.sys [86248 2013-09-11] (ELTIMA Software)
R3 eustub; C:\Windows\System32\DRIVERS\eusbstub.sys [17640 2013-09-11] (ELTIMA Software)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-08-17] (Duplex Secure Ltd.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [33872 2013-02-22] (VMware, Inc.)
R3 vuhub; C:\Windows\System32\DRIVERS\vuhub.sys [74984 2013-09-11] (ELTIMA Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-22 01:38 - 2014-08-22 01:38 - 00026248 _____ () C:\Users\Tim\Desktop\FRST.txt
2014-08-22 01:36 - 2014-08-22 01:36 - 00000000 ____D () C:\Users\Tim\Desktop\FRST-OlderVersion
2014-08-22 01:34 - 2014-08-22 01:34 - 00001521 _____ () C:\Users\Tim\Desktop\JRT.txt
2014-08-22 01:31 - 2014-08-22 01:31 - 00000000 ____D () C:\Windows\ERUNT
2014-08-22 01:30 - 2014-08-22 01:30 - 01016261 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2014-08-22 01:24 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-22 01:21 - 2014-08-22 01:25 - 00000000 ____D () C:\AdwCleaner
2014-08-22 00:57 - 2014-08-22 00:57 - 01364531 _____ () C:\Users\Tim\Desktop\adwcleaner_3.308.exe
2014-08-22 00:53 - 2014-08-22 01:12 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-22 00:53 - 2014-08-22 00:53 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-22 00:53 - 2014-08-22 00:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-22 00:53 - 2014-08-22 00:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-22 00:53 - 2014-08-22 00:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-22 00:53 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-22 00:53 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-22 00:53 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-21 11:34 - 2014-08-22 01:35 - 00001511 _____ () C:\Users\Tim\Desktop\Transformed.txt
2014-08-21 11:27 - 2014-08-21 11:36 - 00000000 ____D () C:\Users\Tim\AppData\Local\Temporary Projects
2014-08-21 11:20 - 2014-08-21 11:19 - 00021664 _____ () C:\Users\Tim\Desktop\ComboFix.txt
2014-08-21 11:19 - 2014-08-21 11:19 - 00021664 _____ () C:\ComboFix.txt
2014-08-20 17:41 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-20 17:41 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-20 17:41 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-20 17:41 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-20 17:40 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-20 17:40 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-20 17:40 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-20 17:40 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-20 15:53 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-20 15:53 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-20 15:53 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-20 15:53 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-20 15:53 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-20 15:53 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-20 15:53 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-20 15:53 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-20 15:53 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-20 15:53 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-20 15:53 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-20 15:53 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-20 15:53 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-20 15:53 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-20 15:53 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-20 15:53 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-20 15:53 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-20 15:53 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-20 15:53 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-20 15:53 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-20 15:53 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-20 15:53 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-20 15:53 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-20 15:53 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-20 15:53 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-20 15:53 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-20 15:53 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-20 15:53 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-20 15:53 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-20 15:53 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-20 15:53 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-20 15:53 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-20 15:53 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-20 15:53 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-20 15:53 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-20 15:53 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-20 15:53 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-20 15:53 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-20 15:53 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-20 15:53 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-20 15:53 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-20 15:53 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-20 15:53 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-20 15:53 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-20 15:53 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-20 15:53 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-20 15:53 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-20 15:53 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-20 15:53 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-20 15:53 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-20 15:53 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-20 15:53 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-20 15:53 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-20 15:53 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-20 15:53 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-20 15:53 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-20 15:27 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-20 15:27 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-20 15:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-20 15:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-20 15:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-20 15:27 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-20 15:27 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-20 15:27 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-20 15:26 - 2014-08-21 11:20 - 00000000 ____D () C:\Qoobox
2014-08-20 15:26 - 2014-08-20 15:50 - 00000000 ____D () C:\Windows\erdnt
2014-08-20 15:25 - 2014-08-20 15:26 - 05572251 ____R (Swearware) C:\Users\Tim\Desktop\ComboFix.exe
2014-08-20 15:24 - 2014-08-20 15:24 - 05006188 _____ () C:\Users\Tim\Desktop\p0sixspwn-v1.0.8-win.zip
2014-08-20 15:06 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-20 15:06 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-20 15:06 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-20 15:06 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-20 15:06 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-20 15:06 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-20 15:06 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-20 15:06 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-20 15:06 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-20 15:06 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-20 15:05 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-20 15:05 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-20 14:55 - 2014-08-20 14:55 - 00001268 _____ () C:\Users\Tim\Desktop\Revo Uninstaller.lnk
2014-08-20 14:55 - 2014-08-20 14:55 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-20 14:54 - 2014-08-20 14:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Tim\Desktop\revosetup95.exe
2014-08-02 19:03 - 2014-08-02 19:03 - 00005912 _____ () C:\Users\Tim\Desktop\LOL_OPGG_Observer_1603203456.bat
2014-08-02 18:43 - 2014-08-02 18:43 - 00000355 _____ () C:\Users\Tim\Desktop\Computer - Verknüpfung.lnk
2014-08-02 17:22 - 2014-08-02 17:22 - 00000000 ____D () C:\Users\Tim\Documents\Square Enix
2014-08-02 17:19 - 2014-08-02 17:22 - 00000000 ____D () C:\Program Files (x86)\Just Cause 2
2014-08-02 16:15 - 2014-08-02 16:15 - 00102908 ____H () C:\Windows\SysWOW64\mlfcache.dat
2014-08-02 14:18 - 2014-08-02 14:18 - 00001960 _____ () C:\Users\Tim\Desktop\ZombieHook - Verknüpfung.lnk
2014-08-02 14:18 - 2014-08-02 14:18 - 00001511 _____ () C:\Users\Tim\Desktop\Launcher - Verknüpfung.lnk
2014-08-02 14:14 - 2014-08-02 14:14 - 00000000 ____D () C:\Users\Tim\Desktop\sdad
2014-08-01 22:11 - 2014-08-01 22:12 - 00000000 ____D () C:\Users\Tim\Desktop\usb
2014-08-01 22:10 - 2014-08-01 22:10 - 00000000 ____D () C:\Users\Tim\Desktop\PS3
2014-08-01 21:31 - 2014-08-02 18:51 - 00000000 ____D () C:\Users\Tim\Desktop\Filme für Kati
2014-08-01 21:28 - 2014-08-01 21:28 - 00001324 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\Users\Tim\Documents\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\ProgramData\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\Program Files (x86)\Freemake
2014-08-01 20:49 - 2014-08-01 20:50 - 00032015 _____ () C:\Users\Tim\Desktop\Logfiles.zip
2014-08-01 19:30 - 2014-08-01 19:30 - 00380416 _____ () C:\Users\Tim\Desktop\Gmer-19357.exe
2014-08-01 19:28 - 2014-08-22 01:38 - 00000000 ____D () C:\FRST
2014-08-01 19:27 - 2014-08-22 01:36 - 02101760 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2014-08-01 19:23 - 2014-08-01 19:23 - 00050477 _____ () C:\Users\Tim\Desktop\Defogger.exe
2014-08-01 19:23 - 2014-08-01 19:23 - 00000020 _____ () C:\Users\Tim\defogger_reenable
2014-08-01 19:12 - 2014-08-01 19:12 - 00001382 _____ () C:\Users\Tim\Desktop\iTunes.lnk
2014-08-01 19:02 - 2014-08-01 19:02 - 00000722 _____ () C:\Users\Tim\Desktop\league of Legends.lnk
2014-08-01 15:56 - 2014-08-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\SimpleFiles
2014-08-01 15:56 - 2014-08-01 18:50 - 00000000 ____D () C:\Program Files (x86)\SimpleFilesUpdater
2014-08-01 14:53 - 2014-08-01 15:25 - 00001583 _____ () C:\Users\Tim\Desktop\weapon id die rise.txt
2014-08-01 02:50 - 2014-08-01 04:24 - 00001080 _____ () C:\Users\Tim\Desktop\weapon id alkatraz.txt
2014-08-01 02:37 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-01 02:37 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-01 02:37 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-01 02:37 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-01 02:37 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-01 02:37 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-01 02:37 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-01 02:37 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-01 02:37 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-01 02:37 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-01 02:37 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-01 02:37 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-01 02:37 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-01 02:37 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-01 00:35 - 2014-08-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net Tools
2014-08-01 00:35 - 2014-08-01 00:36 - 00000000 ____D () C:\Program Files (x86)\Net Tools
2014-08-01 00:35 - 2006-06-23 21:38 - 00809345 _____ () C:\Windows\SysWOW64\nmap-os-fingerprints
2014-08-01 00:35 - 2006-06-23 21:38 - 00557444 _____ () C:\Windows\SysWOW64\nmap-service-probes
2014-08-01 00:35 - 2006-06-23 21:38 - 00452096 _____ () C:\Windows\SysWOW64\nmap.exe
2014-08-01 00:35 - 2006-06-23 21:38 - 00225546 _____ () C:\Windows\SysWOW64\nmap-mac-prefixes
2014-08-01 00:35 - 2006-06-23 21:38 - 00192007 _____ () C:\Windows\SysWOW64\CHANGELOG
2014-08-01 00:35 - 2006-06-23 21:38 - 00108536 _____ () C:\Windows\SysWOW64\nmap-services
2014-08-01 00:35 - 2006-06-23 21:38 - 00025611 _____ () C:\Windows\SysWOW64\COPYING
2014-08-01 00:35 - 2006-06-23 21:38 - 00021552 _____ () C:\Windows\SysWOW64\nmap.xsl
2014-08-01 00:35 - 2006-06-23 21:38 - 00017955 _____ () C:\Windows\SysWOW64\nmap-rpc
2014-08-01 00:35 - 2006-06-23 21:38 - 00006318 _____ () C:\Windows\SysWOW64\nmap-protocols
2014-08-01 00:35 - 2006-06-23 21:38 - 00000192 _____ () C:\Windows\SysWOW64\nmap_performance.reg
2014-08-01 00:35 - 2004-08-04 04:21 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msado25.tlb
2014-08-01 00:35 - 2004-07-10 04:44 - 00608448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx
2014-08-01 00:35 - 2004-06-09 15:59 - 00939224 _____ (Macromedia, Inc.) C:\Windows\SysWOW64\Flash.ocx
2014-08-01 00:35 - 2004-03-01 20:55 - 00561179 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dao360.dll
2014-08-01 00:35 - 2004-02-27 00:00 - 00962612 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC42D.DLL
2014-08-01 00:35 - 2004-02-27 00:00 - 00061493 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCN42D.DLL
2014-08-01 00:35 - 2004-02-17 00:00 - 00434252 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVCRTD.DLL
2014-08-01 00:35 - 2003-03-19 02:03 - 00544768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71d.dll
2014-08-01 00:35 - 2003-01-29 17:50 - 00010348 _____ () C:\Windows\SysWOW64\SubclassingSink.tlb
2014-08-01 00:35 - 2002-11-20 19:53 - 00482123 _____ () C:\Windows\SysWOW64\nmapwin.chm
2014-08-01 00:35 - 2002-11-20 19:44 - 00077824 _____ (JVSoftware) C:\Windows\SysWOW64\nmapwin.exe
2014-08-01 00:35 - 2002-11-20 18:06 - 00290816 _____ () C:\Windows\SysWOW64\nmapserv.exe
2014-08-01 00:35 - 2002-08-15 15:09 - 00000687 _____ () C:\Windows\SysWOW64\nmapwin.exe.manifest
2014-08-01 00:35 - 2001-11-27 00:13 - 00114688 _____ (Open Source Telecom) C:\Windows\SysWOW64\CCGNU32.dll
2014-08-01 00:35 - 2001-09-07 14:00 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wbemdisp.tlb
2014-08-01 00:35 - 2001-09-07 13:00 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msado20.tlb
2014-08-01 00:35 - 2001-04-05 16:43 - 01009336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mschrt20.ocx
2014-08-01 00:35 - 2000-12-06 01:00 - 00209608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tabctl32.ocx
2014-08-01 00:35 - 2000-12-05 19:30 - 00109248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mswinsck.ocx
2014-08-01 00:35 - 2000-05-22 16:58 - 00647872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomct2.ocx
2014-08-01 00:35 - 2000-05-22 00:00 - 00203976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2014-08-01 00:35 - 2000-05-22 00:00 - 00115920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSINET.ocx
2014-08-01 00:35 - 2000-04-03 16:52 - 00164144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comct232.ocx
2014-08-01 00:35 - 1999-05-07 00:00 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Comdlg32.ocx
2014-08-01 00:35 - 1999-04-17 00:06 - 00010752 _____ (Almeida & Andrade Ltda) C:\Windows\SysWOW64\aamd532.dll
2014-08-01 00:35 - 1999-03-26 03:00 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6STKIT.DLL
2014-08-01 00:35 - 1998-06-24 00:00 - 00137000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSMAPI32.OCX
2014-08-01 00:35 - 1998-06-24 00:00 - 00103744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMM32.OCX
2014-08-01 00:35 - 1998-06-18 00:00 - 00299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDBRPTR.DLL
2014-08-01 00:35 - 1998-06-09 00:00 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDERUN.DLL
2014-07-31 22:33 - 2014-08-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VB Decompiler Lite
2014-07-31 22:33 - 2014-07-31 22:33 - 00000000 ____D () C:\Program Files (x86)\VB Decompiler Lite
2014-07-31 21:41 - 2014-07-31 21:41 - 01867776 _____ () C:\Users\Tim\Desktop\[www.OldSchoolHack.de]_s0ZNIzTrainer v8.0.exe
2014-07-31 11:52 - 2014-07-31 11:52 - 00000000 ____D () C:\Users\Tim\Desktop\bo2 origins easter egg
2014-07-31 11:15 - 2014-07-31 11:52 - 00000032 _____ () C:\Users\Tim\Desktop\Neues Textdokument.txt
2014-07-30 17:02 - 2014-07-31 10:58 - 00000000 ____D () C:\Users\Tim\Desktop\stuff
2014-07-30 16:59 - 2014-07-31 14:19 - 00000000 ____D () C:\Users\Tim\Desktop\NEW BO2
2014-07-30 16:52 - 2014-07-30 16:52 - 00718497 _____ () C:\Windows\unins001.exe
2014-07-30 16:44 - 2014-07-30 17:01 - 00000000 ____D () C:\Users\Tim\AppData\Local\Maxiget
2014-07-30 16:44 - 2014-07-30 16:44 - 00000000 ____D () C:\Users\Tim\AppData\Local\MaxiGet Download Manager
2014-07-30 16:43 - 2014-07-30 16:52 - 00353866 _____ () C:\Windows\unins001.dat
2014-07-30 16:33 - 2014-07-30 17:07 - 00000000 ____D () C:\Users\Tim\AppData\Local\Deployment
2014-07-30 16:33 - 2014-07-30 16:33 - 00000000 ____D () C:\Users\Tim\AppData\Local\Apps\2.0
2014-07-30 13:23 - 2014-07-30 13:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-27 10:30 - 2014-07-30 12:22 - 00000127 _____ () C:\Users\Tim\Desktop\origins.txt
2014-07-26 11:46 - 2014-07-26 11:46 - 00000000 ____D () C:\Users\Tim\Documents\PCSX2
2014-07-26 11:44 - 2014-08-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
2014-07-26 11:43 - 2014-07-26 11:47 - 00000000 ____D () C:\Users\Tim\Desktop\ps2
2014-07-26 11:43 - 2014-07-26 11:46 - 00000000 ____D () C:\Program Files (x86)\PCSX2 1.2.1
2014-07-23 14:07 - 2014-08-01 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-07-23 14:07 - 2014-07-23 14:07 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-22 01:39 - 2014-08-22 01:38 - 00026248 _____ () C:\Users\Tim\Desktop\FRST.txt
2014-08-22 01:38 - 2014-08-01 19:28 - 00000000 ____D () C:\FRST
2014-08-22 01:36 - 2014-08-22 01:36 - 00000000 ____D () C:\Users\Tim\Desktop\FRST-OlderVersion
2014-08-22 01:36 - 2014-08-01 19:27 - 02101760 _____ (Farbar) C:\Users\Tim\Desktop\FRST64.exe
2014-08-22 01:35 - 2014-08-21 11:34 - 00001511 _____ () C:\Users\Tim\Desktop\Transformed.txt
2014-08-22 01:35 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-22 01:35 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-22 01:34 - 2014-08-22 01:34 - 00001521 _____ () C:\Users\Tim\Desktop\JRT.txt
2014-08-22 01:31 - 2014-08-22 01:31 - 00000000 ____D () C:\Windows\ERUNT
2014-08-22 01:30 - 2014-08-22 01:30 - 01016261 _____ (Thisisu) C:\Users\Tim\Desktop\JRT.exe
2014-08-22 01:30 - 2013-03-29 00:38 - 02034714 _____ () C:\Windows\WindowsUpdate.log
2014-08-22 01:28 - 2013-03-30 16:23 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Skype
2014-08-22 01:27 - 2014-05-08 13:09 - 00000000 ____D () C:\ProgramData\VMware
2014-08-22 01:27 - 2013-03-29 16:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-22 01:27 - 2010-11-21 05:47 - 00078906 _____ () C:\Windows\PFRO.log
2014-08-22 01:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-22 01:27 - 2009-07-14 06:51 - 00132190 _____ () C:\Windows\setupact.log
2014-08-22 01:25 - 2014-08-22 01:21 - 00000000 ____D () C:\AdwCleaner
2014-08-22 01:21 - 2013-07-12 13:59 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\TS3Client
2014-08-22 01:12 - 2014-08-22 00:53 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-22 01:12 - 2013-04-03 12:54 - 00000000 ____D () C:\ProgramData\MFAData
2014-08-22 01:08 - 2014-03-08 19:26 - 00000000 ____D () C:\Users\Tim\AppData\Local\LogMeIn Hamachi
2014-08-22 01:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system
2014-08-22 00:57 - 2014-08-22 00:57 - 01364531 _____ () C:\Users\Tim\Desktop\adwcleaner_3.308.exe
2014-08-22 00:53 - 2014-08-22 00:53 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-22 00:53 - 2014-08-22 00:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-22 00:53 - 2014-08-22 00:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-22 00:53 - 2014-08-22 00:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-22 00:49 - 2013-08-19 03:32 - 00000000 ____D () C:\Users\Tim\AppData\Local\PMB Files
2014-08-22 00:49 - 2013-08-19 03:32 - 00000000 ____D () C:\ProgramData\PMB Files
2014-08-22 00:46 - 2013-09-17 18:50 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1944573492-1714721241-4137265928-1000UA.job
2014-08-22 00:42 - 2013-03-29 16:11 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-21 21:11 - 2013-06-04 21:13 - 00000000 ____D () C:\Users\Tim\AppData\Local\CrashDumps
2014-08-21 21:10 - 2013-04-26 17:23 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-21 15:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-21 11:36 - 2014-08-21 11:27 - 00000000 ____D () C:\Users\Tim\AppData\Local\Temporary Projects
2014-08-21 11:20 - 2014-08-20 15:26 - 00000000 ____D () C:\Qoobox
2014-08-21 11:19 - 2014-08-21 11:20 - 00021664 _____ () C:\Users\Tim\Desktop\ComboFix.txt
2014-08-21 11:19 - 2014-08-21 11:19 - 00021664 _____ () C:\ComboFix.txt
2014-08-21 11:14 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-21 10:59 - 2014-06-18 02:00 - 00000000 ____D () C:\Users\Tim\AppData\Local\Adobe
2014-08-20 19:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-20 17:51 - 2014-05-29 10:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-20 15:55 - 2013-05-07 18:50 - 00000000 ____D () C:\Users\Tim\Documents\Visual Studio 2012
2014-08-20 15:51 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-08-20 15:50 - 2014-08-20 15:26 - 00000000 ____D () C:\Windows\erdnt
2014-08-20 15:44 - 2009-07-14 04:34 - 21495808 _____ () C:\Windows\system32\config\system.bak
2014-08-20 15:44 - 2009-07-14 04:34 - 110886912 _____ () C:\Windows\system32\config\software.bak
2014-08-20 15:44 - 2009-07-14 04:34 - 05505024 _____ () C:\Windows\system32\config\default.bak
2014-08-20 15:44 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2014-08-20 15:44 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2014-08-20 15:37 - 2013-09-26 11:06 - 00000000 ____D () C:\ProgramData\TEMP
2014-08-20 15:26 - 2014-08-20 15:25 - 05572251 ____R (Swearware) C:\Users\Tim\Desktop\ComboFix.exe
2014-08-20 15:24 - 2014-08-20 15:24 - 05006188 _____ () C:\Users\Tim\Desktop\p0sixspwn-v1.0.8-win.zip
2014-08-20 14:55 - 2014-08-20 14:55 - 00001268 _____ () C:\Users\Tim\Desktop\Revo Uninstaller.lnk
2014-08-20 14:55 - 2014-08-20 14:55 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-20 14:54 - 2014-08-20 14:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Tim\Desktop\revosetup95.exe
2014-08-20 14:53 - 2013-07-12 12:50 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-08-02 19:03 - 2014-08-02 19:03 - 00005912 _____ () C:\Users\Tim\Desktop\LOL_OPGG_Observer_1603203456.bat
2014-08-02 18:51 - 2014-08-01 21:31 - 00000000 ____D () C:\Users\Tim\Desktop\Filme für Kati
2014-08-02 18:43 - 2014-08-02 18:43 - 00000355 _____ () C:\Users\Tim\Desktop\Computer - Verknüpfung.lnk
2014-08-02 17:22 - 2014-08-02 17:22 - 00000000 ____D () C:\Users\Tim\Documents\Square Enix
2014-08-02 17:22 - 2014-08-02 17:19 - 00000000 ____D () C:\Program Files (x86)\Just Cause 2
2014-08-02 17:15 - 2011-04-12 09:43 - 00702184 _____ () C:\Windows\system32\perfh007.dat
2014-08-02 17:15 - 2011-04-12 09:43 - 00150850 _____ () C:\Windows\system32\perfc007.dat
2014-08-02 17:15 - 2009-07-14 07:13 - 01629154 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-02 16:15 - 2014-08-02 16:15 - 00102908 ____H () C:\Windows\SysWOW64\mlfcache.dat
2014-08-02 14:18 - 2014-08-02 14:18 - 00001960 _____ () C:\Users\Tim\Desktop\ZombieHook - Verknüpfung.lnk
2014-08-02 14:18 - 2014-08-02 14:18 - 00001511 _____ () C:\Users\Tim\Desktop\Launcher - Verknüpfung.lnk
2014-08-02 14:14 - 2014-08-02 14:14 - 00000000 ____D () C:\Users\Tim\Desktop\sdad
2014-08-01 22:12 - 2014-08-01 22:11 - 00000000 ____D () C:\Users\Tim\Desktop\usb
2014-08-01 22:10 - 2014-08-01 22:10 - 00000000 ____D () C:\Users\Tim\Desktop\PS3
2014-08-01 21:28 - 2014-08-01 21:28 - 00001324 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\Users\Tim\Documents\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\ProgramData\Freemake
2014-08-01 21:28 - 2014-08-01 21:28 - 00000000 ____D () C:\Program Files (x86)\Freemake
2014-08-01 21:23 - 2013-04-11 17:15 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\DVDVideoSoft
2014-08-01 20:50 - 2014-08-01 20:49 - 00032015 _____ () C:\Users\Tim\Desktop\Logfiles.zip
2014-08-01 19:30 - 2014-08-01 19:30 - 00380416 _____ () C:\Users\Tim\Desktop\Gmer-19357.exe
2014-08-01 19:23 - 2014-08-01 19:23 - 00050477 _____ () C:\Users\Tim\Desktop\Defogger.exe
2014-08-01 19:23 - 2014-08-01 19:23 - 00000020 _____ () C:\Users\Tim\defogger_reenable
2014-08-01 19:23 - 2013-03-29 00:38 - 00000000 ____D () C:\Users\Tim
2014-08-01 19:12 - 2014-08-01 19:12 - 00001382 _____ () C:\Users\Tim\Desktop\iTunes.lnk
2014-08-01 19:02 - 2014-08-01 19:02 - 00000722 _____ () C:\Users\Tim\Desktop\league of Legends.lnk
2014-08-01 19:00 - 2013-04-03 12:59 - 00003246 _____ () C:\Windows\System32\Tasks\SidebarExecute
2014-08-01 18:50 - 2014-08-01 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\SimpleFiles
2014-08-01 18:50 - 2014-08-01 15:56 - 00000000 ____D () C:\Program Files (x86)\SimpleFilesUpdater
2014-08-01 18:50 - 2014-08-01 00:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net Tools
2014-08-01 18:50 - 2014-07-31 22:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VB Decompiler Lite
2014-08-01 18:50 - 2014-07-26 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
2014-08-01 18:50 - 2014-07-23 14:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-08-01 18:50 - 2014-07-11 22:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\osu!
2014-08-01 18:50 - 2014-05-30 03:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-08-01 18:50 - 2014-05-29 10:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-08-01 18:50 - 2014-04-10 15:41 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2014-08-01 18:50 - 2014-04-01 14:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-08-01 18:50 - 2014-03-21 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbiWord Word Processor
2014-08-01 18:50 - 2014-03-19 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-08-01 18:50 - 2014-02-13 15:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-01 18:50 - 2014-02-13 15:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-08-01 18:50 - 2014-01-01 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clownfish
2014-08-01 18:50 - 2013-12-25 17:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON
2014-08-01 18:50 - 2013-12-24 23:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cinema 4D R12
2014-08-01 18:50 - 2013-12-09 00:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Duty Black Ops 2
2014-08-01 18:50 - 2013-12-02 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IDA PRO Advanced Edition
2014-08-01 18:50 - 2013-12-02 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex Workshop v6.7
2014-08-01 18:50 - 2013-11-29 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express
2014-08-01 18:50 - 2013-10-04 11:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PS3 Media Server
2014-08-01 18:50 - 2013-09-26 11:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bruteforce Save Data
2014-08-01 18:50 - 2013-09-17 18:51 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-01 18:50 - 2013-09-14 11:09 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2014-08-01 18:50 - 2013-09-12 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-08-01 18:50 - 2013-08-24 16:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.2
2014-08-01 18:50 - 2013-08-19 17:14 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software
2014-08-01 18:50 - 2013-08-19 03:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-08-01 18:50 - 2013-08-17 09:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2014-08-01 18:50 - 2013-08-08 16:16 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-08-01 18:50 - 2013-08-08 16:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2014-08-01 18:50 - 2013-07-13 19:44 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-08-01 18:50 - 2013-07-12 12:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-08-01 18:50 - 2013-07-10 16:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sound Normalizer
2014-08-01 18:50 - 2013-07-10 15:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3Gain
2014-08-01 18:50 - 2013-06-04 20:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2014-08-01 18:50 - 2013-05-23 16:00 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-01 18:50 - 2013-05-21 17:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-08-01 18:50 - 2013-05-12 01:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2014-08-01 18:50 - 2013-05-11 00:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-08-01 18:50 - 2013-05-10 14:26 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-01 18:50 - 2013-05-10 14:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-01 18:50 - 2013-05-07 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK - Deutsch
2014-08-01 18:50 - 2013-05-07 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 4 SDK - Deutsch
2014-08-01 18:50 - 2013-05-07 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2012
2014-08-01 18:50 - 2013-04-26 17:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-01 18:50 - 2013-04-14 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskAid
2014-08-01 18:50 - 2013-04-11 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\i-Funbox DevTeam
2014-08-01 18:50 - 2013-04-11 17:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-08-01 18:50 - 2013-04-03 18:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dxtory2.0
2014-08-01 18:50 - 2013-03-29 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-08-01 18:50 - 2013-03-29 04:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-08-01 18:50 - 2013-03-29 01:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2014-08-01 18:50 - 2013-03-29 00:38 - 00000000 ___RD () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-08-01 18:50 - 2013-03-29 00:38 - 00000000 ___RD () C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-01 18:50 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-01 18:50 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-08-01 18:50 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-01 15:54 - 2013-05-09 16:47 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\uTorrent
2014-08-01 15:25 - 2014-08-01 14:53 - 00001583 _____ () C:\Users\Tim\Desktop\weapon id die rise.txt
2014-08-01 14:15 - 2013-03-29 01:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-01 04:24 - 2014-08-01 02:50 - 00001080 _____ () C:\Users\Tim\Desktop\weapon id alkatraz.txt
2014-08-01 03:46 - 2013-09-17 18:50 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1944573492-1714721241-4137265928-1000Core.job
2014-08-01 01:41 - 2014-08-20 15:53 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-01 01:16 - 2014-08-20 15:53 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-01 00:36 - 2014-08-01 00:35 - 00000000 ____D () C:\Program Files (x86)\Net Tools
2014-07-31 22:33 - 2014-07-31 22:33 - 00000000 ____D () C:\Program Files (x86)\VB Decompiler Lite
2014-07-31 21:41 - 2014-07-31 21:41 - 01867776 _____ () C:\Users\Tim\Desktop\[www.OldSchoolHack.de]_s0ZNIzTrainer v8.0.exe
2014-07-31 17:01 - 2013-04-03 13:10 - 00000000 ____D () C:\Users\Tim\Documents\My Cheat Tables
2014-07-31 14:23 - 2013-11-29 17:56 - 00000000 ____D () C:\Users\Tim\Documents\Visual Studio 2010
2014-07-31 14:19 - 2014-07-30 16:59 - 00000000 ____D () C:\Users\Tim\Desktop\NEW BO2
2014-07-31 11:52 - 2014-07-31 11:52 - 00000000 ____D () C:\Users\Tim\Desktop\bo2 origins easter egg
2014-07-31 11:52 - 2014-07-31 11:15 - 00000032 _____ () C:\Users\Tim\Desktop\Neues Textdokument.txt
2014-07-31 10:58 - 2014-07-30 17:02 - 00000000 ____D () C:\Users\Tim\Desktop\stuff
2014-07-31 09:48 - 2013-08-18 02:42 - 00000000 ____D () C:\Program Files (x86)\Activision
2014-07-30 21:18 - 2014-07-08 19:03 - 00000000 ____D () C:\Users\Tim\AppData\Roaming\BoL
2014-07-30 17:07 - 2014-07-30 16:33 - 00000000 ____D () C:\Users\Tim\AppData\Local\Deployment
2014-07-30 17:06 - 2014-02-12 14:34 - 00000000 ____D () C:\Program Files (x86)\Telerik
2014-07-30 17:01 - 2014-07-30 16:44 - 00000000 ____D () C:\Users\Tim\AppData\Local\Maxiget
2014-07-30 17:01 - 2014-03-04 03:01 - 00000000 ____D () C:\Games
2014-07-30 17:00 - 2013-12-10 15:27 - 00000000 ____D () C:\ProgramData\AVG2014
2014-07-30 16:52 - 2014-07-30 16:52 - 00718497 _____ () C:\Windows\unins001.exe
2014-07-30 16:52 - 2014-07-30 16:43 - 00353866 _____ () C:\Windows\unins001.dat
2014-07-30 16:44 - 2014-07-30 16:44 - 00000000 ____D () C:\Users\Tim\AppData\Local\MaxiGet Download Manager
2014-07-30 16:33 - 2014-07-30 16:33 - 00000000 ____D () C:\Users\Tim\AppData\Local\Apps\2.0
2014-07-30 13:23 - 2014-07-30 13:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-30 12:22 - 2014-07-27 10:30 - 00000127 _____ () C:\Users\Tim\Desktop\origins.txt
2014-07-28 16:34 - 2013-06-30 16:25 - 00000000 ____D () C:\Users\Tim\AppData\Local\Arma 3
2014-07-26 11:47 - 2014-07-26 11:43 - 00000000 ____D () C:\Users\Tim\Desktop\ps2
2014-07-26 11:46 - 2014-07-26 11:46 - 00000000 ____D () C:\Users\Tim\Documents\PCSX2
2014-07-26 11:46 - 2014-07-26 11:43 - 00000000 ____D () C:\Program Files (x86)\PCSX2 1.2.1
2014-07-26 11:46 - 2013-10-19 22:13 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-07-26 11:44 - 2013-04-29 00:03 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-25 16:52 - 2014-08-20 15:53 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-25 16:02 - 2014-08-20 15:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-25 16:01 - 2014-08-20 15:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-25 15:51 - 2014-08-20 15:53 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-25 15:30 - 2014-08-20 15:53 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-25 15:28 - 2014-08-20 15:53 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-25 15:28 - 2014-08-20 15:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-25 15:25 - 2014-08-20 15:53 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-25 15:25 - 2014-08-20 15:53 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-25 15:11 - 2014-08-20 15:53 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-25 15:10 - 2014-08-20 15:53 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-25 15:04 - 2014-08-20 15:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-25 15:03 - 2014-08-20 15:53 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-25 15:00 - 2014-08-20 15:53 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-25 15:00 - 2014-08-20 15:53 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-25 14:59 - 2014-08-20 15:53 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-25 14:47 - 2014-08-20 15:53 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-25 14:40 - 2014-08-20 15:53 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-25 14:34 - 2014-08-20 15:53 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-25 14:34 - 2014-08-20 15:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-25 14:33 - 2014-08-20 15:53 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-25 14:30 - 2014-08-20 15:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-25 14:28 - 2014-08-20 15:53 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-25 14:28 - 2014-08-20 15:53 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 14:21 - 2014-08-20 15:53 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-25 14:19 - 2014-08-20 15:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-25 14:18 - 2014-08-20 15:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-25 14:17 - 2014-08-20 15:53 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-25 14:17 - 2014-08-20 15:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-25 14:12 - 2014-08-20 15:53 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-25 14:10 - 2014-08-20 15:53 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-25 14:10 - 2014-08-20 15:53 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-25 14:08 - 2014-08-20 15:53 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-25 14:06 - 2014-08-20 15:53 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-25 13:52 - 2014-08-20 15:53 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-25 13:47 - 2014-08-20 15:53 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-25 13:43 - 2014-08-20 15:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-25 13:42 - 2014-08-20 15:53 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-25 13:39 - 2014-08-20 15:53 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-25 13:39 - 2014-08-20 15:53 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-25 13:36 - 2014-08-20 15:53 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-25 13:34 - 2014-08-20 15:53 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-25 13:29 - 2014-08-20 15:53 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-25 13:23 - 2014-08-20 15:53 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-25 13:14 - 2014-05-30 03:26 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-25 13:14 - 2014-05-30 03:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-25 13:13 - 2014-08-20 15:53 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-25 13:07 - 2014-08-20 15:53 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-25 13:07 - 2014-08-20 15:53 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-25 13:03 - 2014-08-20 15:53 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-25 12:52 - 2014-08-20 15:53 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-25 12:26 - 2014-08-20 15:53 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-25 12:17 - 2014-08-20 15:53 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-25 12:09 - 2014-08-20 15:53 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-25 12:05 - 2014-08-20 15:53 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-25 12:00 - 2014-08-20 15:53 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-24 16:56 - 2014-02-13 19:54 - 00000000 ____D () C:\Users\Tim\AppData\Local\DayZ
2014-07-23 14:07 - 2014-07-23 14:07 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
Some content of TEMP:
====================
C:\Users\Tim\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-20 17:29
==================== End Of Log ============================ --- --- --- |