furkan189 | 01.09.2014 15:33 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 01.09.2014 15:06:09, SYSTEM, FURKANLAPTOP, Protection, Malware Protection, Starting,
Protection, 01.09.2014 15:06:09, SYSTEM, FURKANLAPTOP, Protection, Malware Protection, Started,
Protection, 01.09.2014 15:06:09, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Starting,
Protection, 01.09.2014 15:06:10, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Started,
Update, 01.09.2014 15:06:13, SYSTEM, FURKANLAPTOP, Manual, Rootkit Database, 2014.2.20.1, 2014.8.21.1,
Update, 01.09.2014 15:06:22, SYSTEM, FURKANLAPTOP, Manual, Malware Database, 2014.3.4.9, 2014.9.1.1,
Protection, 01.09.2014 15:06:25, SYSTEM, FURKANLAPTOP, Protection, Refresh, Starting,
Protection, 01.09.2014 15:06:25, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Stopping,
Protection, 01.09.2014 15:06:26, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Stopped,
Protection, 01.09.2014 15:06:36, SYSTEM, FURKANLAPTOP, Protection, Refresh, Success,
Protection, 01.09.2014 15:06:36, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Starting,
Protection, 01.09.2014 15:06:36, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Started,
Protection, 01.09.2014 16:03:05, SYSTEM, FURKANLAPTOP, Protection, Malware Protection, Starting,
Protection, 01.09.2014 16:03:05, SYSTEM, FURKANLAPTOP, Protection, Malware Protection, Started,
Protection, 01.09.2014 16:03:05, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Starting,
Protection, 01.09.2014 16:03:53, SYSTEM, FURKANLAPTOP, Protection, Malicious Website Protection, Started,
(end) Code:
# AdwCleaner v3.308 - Bericht erstellt am 01/09/2014 um 16:12:08
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Furkan - FURKANLAPTOP
# Gestartet von : C:\Users\Ali\Downloads\adwcleaner_3.308.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Ali\AppData\Local\Temp\OCS
Datei Gelöscht : C:\Users\Ali\Favorites\Startfenster.lnk
Datei Gelöscht : C:\Users\Ali\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk
Datei Gelöscht : C:\Users\Ali\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk
Datei Gelöscht : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\foxydeal.sqlite
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17239
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.startfenster.de");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://www.sm.de/?q=");
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
[ Datei : C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [10177 octets] - [01/09/2014 16:09:42]
AdwCleaner[S0].txt - [4134 octets] - [01/09/2014 16:12:08]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4194 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Furkan on 01.09.2014 at 16:18:41,75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
~~~ FireFox
Emptied folder: C:\Users\Ali\AppData\Roaming\mozilla\firefox\profiles\gcte5nfi.default\minidumps [52 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.09.2014 at 16:23:59,62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02
Ran by Furkan (administrator) on FURKANLAPTOP on 01-09-2014 16:28:25
Running from C:\Users\Ali\Downloads
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe
() C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
() C:\Program Files (x86)\Acer Incorporated\HID Monitor\HIDMonitor.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMMsg.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files (x86)\ownCloud\owncloud.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\OUTLOOK.EXE
(Spotify Ltd) C:\Users\Ali\AppData\Roaming\Spotify\spotify.exe
() C:\Users\Ali\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Ali\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Ali\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
() C:\Users\Ali\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\Ali\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-10] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13449288 2013-03-26] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2994880 2012-08-15] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-06] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282632 2013-09-12] (CANON INC.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [161584 2014-08-04] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132224 2013-02-28] ( (Atheros Communications))
HKU\S-1-5-21-4093644379-2981368224-3405264002-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office 15\root\office15\lync.exe [18999456 2014-08-29] (Microsoft Corporation)
HKU\S-1-5-21-4093644379-2981368224-3405264002-1001\...\Run: [Spotify Web Helper] => C:\Users\Ali\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-08-30] (Spotify Ltd)
HKU\S-1-5-21-4093644379-2981368224-3405264002-1001\...\Run: [Rainlendar2] => C:\Program Files\Rainlendar2\Rainlendar2.exe
HKU\S-1-5-21-4093644379-2981368224-3405264002-1001\...\Run: [ownCloud] => C:\Program Files (x86)\ownCloud\owncloud.exe [17381826 2014-06-26] ()
HKU\S-1-5-21-4093644379-2981368224-3405264002-1001\...\MountPoints2: {53753c58-8568-11e3-be9b-0c84dc5dd78c} - "E:\Autorun.exe" {D2D77DC2-8299-11D1-8949-444553540000} 5.2066.1.9B05 PID_0083
Startup: C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SpotifyController.lnk
ShortcutTarget: SpotifyController.lnk -> C:\Users\Ali\AppData\Roaming\SpotifyController\server\spotifycontrollerservergui.jar ()
Startup: C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ali\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ali\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ali\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ali\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ali\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ali\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ali\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {35DAB87B-887F-4D05-AFBA-93C0344DB990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM - {CFB0ACDE-B5E3-45AB-8F0C-7593BBC03B02} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM-x32 - {35DAB87B-887F-4D05-AFBA-93C0344DB990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - {35DAB87B-887F-4D05-AFBA-93C0344DB990} URL =
SearchScopes: HKCU - {CFB0ACDE-B5E3-45AB-8F0C-7593BBC03B02} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default
FF DefaultSearchEngine: SuchMaschine
FF SearchEngineOrder.1: SuchMaschine
FF SelectedSearchEngine: SuchMaschine
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ali\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\Extensions\abs@avira.com [2014-08-28]
FF Extension: NoScript - C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-09-15]
FF Extension: Adblock Edge - C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\gcte5nfi.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-03-15]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-06] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-06] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227968 2013-02-28] (Qualcomm Atheros Commnucations)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [149296 2014-08-04] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2369720 2014-08-01] (Microsoft Corporation)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2013-02-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2013-02-18] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-03-15] (Acer Incorporate)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsDepSvc; C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [80472 2012-09-06] (Microsoft Corporation)
R2 MySQL; C:\Program Files\MySQL\MySQL Server 5.1\my.ini [8915 2014-05-18] () [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-03-03] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-09-30] (Avira Operations GmbH & Co. KG)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-02-28] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2014-07-21] (LogMeIn Inc.)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (EZB Systems, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-03-03] ()
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
S3 massfilter_hs; C:\Windows\System32\drivers\massfilter_hs.sys [18456 2011-08-15] (HandSet Incorporated)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-01] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [455240 2013-03-05] (RTS Corporation)
S3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
S3 zghsmdm; C:\Windows\system32\DRIVERS\zghsmdm.sys [129432 2011-08-15] (ZTE Incorporated)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-01 16:23 - 2014-09-01 16:23 - 00000934 _____ () C:\Users\Ali\Desktop\JRT.txt
2014-09-01 16:18 - 2014-09-01 16:18 - 01016261 _____ (Thisisu) C:\Users\Ali\Downloads\JRT.exe
2014-09-01 16:18 - 2014-09-01 16:18 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-09-01 16:17 - 2014-09-01 16:17 - 00004278 _____ () C:\Users\Ali\Desktop\AdwCleaner[S0].txt
2014-09-01 16:09 - 2014-09-01 16:13 - 00000000 ____D () C:\AdwCleaner
2014-09-01 16:07 - 2014-09-01 16:07 - 00001705 _____ () C:\Users\Ali\Desktop\1.txt
2014-09-01 15:23 - 2014-09-01 15:25 - 00052203 _____ () C:\Users\Ali\Downloads\Addition.txt
2014-09-01 15:19 - 2014-09-01 16:28 - 00021165 _____ () C:\Users\Ali\Downloads\FRST.txt
2014-09-01 15:19 - 2014-09-01 16:28 - 00000000 ____D () C:\FRST
2014-09-01 15:18 - 2014-09-01 15:19 - 02104832 _____ (Farbar) C:\Users\Ali\Downloads\FRST64.exe
2014-09-01 15:11 - 2014-09-01 15:11 - 01364531 _____ () C:\Users\Ali\Downloads\adwcleaner_3.308.exe
2014-09-01 15:05 - 2014-09-01 16:16 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-01 15:05 - 2014-09-01 15:05 - 00001122 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-01 15:05 - 2014-09-01 15:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-01 15:05 - 2014-09-01 15:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-01 15:05 - 2014-09-01 15:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-01 15:05 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-09-01 15:05 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-09-01 15:05 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-09-01 15:04 - 2014-09-01 15:04 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ali\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-01 15:04 - 2014-09-01 15:04 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ali\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-09-01 14:23 - 2014-09-01 14:23 - 00000000 ____D () C:\Users\Ali\Desktop\Spiele
2014-09-01 14:18 - 2014-09-01 14:18 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\vlc
2014-09-01 14:17 - 2014-09-01 14:17 - 00000891 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-09-01 14:17 - 2014-09-01 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-09-01 14:16 - 2014-09-01 14:16 - 00000000 ____D () C:\Program Files\VideoLAN
2014-08-31 21:51 - 2014-08-31 21:51 - 00000000 ____D () C:\Program Files\Common Files\VST2
2014-08-31 21:51 - 2014-08-31 21:51 - 00000000 ____D () C:\Program Files\Common Files\Propellerhead Software
2014-08-31 21:50 - 2014-09-01 14:21 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2014-08-31 21:50 - 2014-09-01 14:21 - 00000000 ____D () C:\Program Files\Image-Line
2014-08-31 21:50 - 2014-09-01 14:21 - 00000000 ____D () C:\Program Files (x86)\DSPRobotics
2014-08-31 21:50 - 2014-08-31 21:50 - 00000000 ____D () C:\Users\Ali\Documents\Image-Line
2014-08-31 21:50 - 2014-08-31 21:50 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\FlowStone
2014-08-31 21:46 - 2014-09-01 14:21 - 00000000 ____D () C:\Program Files (x86)\Image-Line
2014-08-28 17:58 - 2014-08-23 02:42 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-22 20:18 - 2014-08-22 20:18 - 00002268 _____ () C:\Users\Gast\Desktop\SWAT 4.lnk
2014-08-22 20:18 - 2014-08-22 20:18 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sierra
2014-08-22 20:18 - 2014-08-22 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
2014-08-22 20:03 - 2014-03-26 03:23 - 00000000 ____D () C:\Users\Ali\Downloads\SWAT4+NoCD-Crack&Serial (En+De)
2014-08-22 19:25 - 2014-08-22 20:04 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\BitTorrent
2014-08-21 14:16 - 2014-08-21 14:16 - 00000000 ____D () C:\Users\Ali\AppData\Local\My Games
2014-08-21 01:12 - 2014-08-21 01:12 - 00002496 _____ () C:\Users\Gast\Desktop\SWAT 4 Single Player Demo.lnk
2014-08-21 01:12 - 2014-08-21 01:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VUGames
2014-08-20 22:17 - 2014-08-20 22:27 - 00000000 ____D () C:\Users\Ali\AppData\Local\LogMeIn Hamachi
2014-08-20 22:17 - 2014-08-20 22:17 - 00000000 ____D () C:\Users\Ali\AppData\Local\LogMeIn
2014-08-20 22:17 - 2014-08-20 22:17 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-08-20 21:56 - 2014-08-21 14:16 - 00000000 ____D () C:\Users\Ali\Documents\My Games
2014-08-19 13:50 - 2014-08-19 14:02 - 00000000 ____D () C:\Users\Ali\Desktop\bilder
2014-08-19 13:49 - 2014-08-19 13:50 - 00000000 ____D () C:\Users\Ali\Desktop\Kamera
2014-08-19 13:48 - 2014-08-19 14:29 - 00000000 ____D () C:\Users\Ali\Desktop\musik
2014-08-18 18:00 - 2014-08-20 23:20 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\TS3Client
2014-08-18 17:59 - 2014-08-20 23:09 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-08-17 21:37 - 2014-08-17 21:37 - 00000000 ____D () C:\Users\Ali\Documents\Outlook-Dateien
2014-08-17 21:34 - 2014-08-17 21:35 - 00000000 ____D () C:\Users\Ali\Desktop\Frank2
2014-08-17 21:30 - 2014-08-17 21:30 - 00000000 ____D () C:\Users\Ali\AppData\Local\Adobe
2014-08-14 22:01 - 2014-08-02 02:17 - 00704480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-08-14 22:01 - 2014-08-02 02:17 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-14 10:54 - 2014-08-14 10:54 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\GolemLabs Laboratories
2014-08-14 10:18 - 2014-08-20 21:18 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-14 10:05 - 2014-08-21 14:23 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-14 10:05 - 2014-08-14 10:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-13 00:09 - 2014-07-24 17:28 - 00468288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2014-08-13 00:09 - 2014-07-24 17:28 - 00419648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2014-08-13 00:09 - 2014-07-24 17:28 - 00412992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2014-08-13 00:09 - 2014-07-24 17:28 - 00280384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2014-08-13 00:09 - 2014-07-24 17:28 - 00143680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2014-08-13 00:09 - 2014-07-24 17:25 - 00054752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-08-13 00:09 - 2014-07-24 17:23 - 01519488 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2014-08-13 00:09 - 2014-07-24 17:23 - 00125472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2014-08-13 00:09 - 2014-07-24 17:20 - 21266336 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-08-13 00:09 - 2014-07-24 17:20 - 00645592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2014-08-13 00:09 - 2014-07-24 17:20 - 00263400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2014-08-13 00:09 - 2014-07-24 17:16 - 02574208 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2014-08-13 00:09 - 2014-07-24 17:16 - 00211216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVol.exe
2014-08-13 00:09 - 2014-07-24 17:07 - 07424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-08-13 00:09 - 2014-07-24 17:07 - 02009920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-08-13 00:09 - 2014-07-24 17:05 - 01660048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2014-08-13 00:09 - 2014-07-24 17:05 - 01519560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2014-08-13 00:09 - 2014-07-24 17:05 - 01488008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2014-08-13 00:09 - 2014-07-24 17:05 - 01356840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2014-08-13 00:09 - 2014-07-24 17:03 - 02141920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-08-13 00:09 - 2014-07-24 17:03 - 00882136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2014-08-13 00:09 - 2014-07-24 17:03 - 00818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-08-13 00:09 - 2014-07-24 17:03 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2014-08-13 00:09 - 2014-07-24 17:03 - 00233888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2014-08-13 00:09 - 2014-07-24 17:03 - 00205512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2014-08-13 00:09 - 2014-07-24 16:57 - 02515264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-08-13 00:09 - 2014-07-24 16:57 - 00475968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2014-08-13 00:09 - 2014-07-24 15:50 - 00098048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2014-08-13 00:09 - 2014-07-24 15:48 - 02410976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2014-08-13 00:09 - 2014-07-24 15:48 - 00180208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVol.exe
2014-08-13 00:09 - 2014-07-24 15:46 - 18760328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-08-13 00:09 - 2014-07-24 15:46 - 00477200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2014-08-13 00:09 - 2014-07-24 15:36 - 02145472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-08-13 00:09 - 2014-07-24 15:36 - 00707536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2014-08-13 00:09 - 2014-07-24 15:36 - 00674512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-08-13 00:09 - 2014-07-24 15:36 - 00355800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2014-08-13 00:09 - 2014-07-24 15:36 - 00180720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2014-08-13 00:09 - 2014-07-24 13:51 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRUM.DLL
2014-08-13 00:09 - 2014-07-24 13:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDYAK.DLL
2014-08-13 00:09 - 2014-07-24 13:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDTT102.DLL
2014-08-13 00:09 - 2014-07-24 13:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDTAT.DLL
2014-08-13 00:09 - 2014-07-24 13:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRU1.DLL
2014-08-13 00:09 - 2014-07-24 13:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDBASH.DLL
2014-08-13 00:09 - 2014-07-24 13:51 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRU.DLL
2014-08-13 00:09 - 2014-07-24 13:47 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2014-08-13 00:09 - 2014-07-24 13:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
2014-08-13 00:09 - 2014-07-24 13:45 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2014-08-13 00:09 - 2014-07-24 13:44 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-08-13 00:09 - 2014-07-24 13:43 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2014-08-13 00:09 - 2014-07-24 13:42 - 01200640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2014-08-13 00:09 - 2014-07-24 13:42 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2014-08-13 00:09 - 2014-07-24 13:42 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NdisImPlatform.sys
2014-08-13 00:09 - 2014-07-24 13:41 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthpan.sys
2014-08-13 00:09 - 2014-07-24 13:41 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2014-08-13 00:09 - 2014-07-24 13:33 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-08-13 00:09 - 2014-07-24 13:33 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2014-08-13 00:09 - 2014-07-24 13:22 - 00308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2014-08-13 00:09 - 2014-07-24 13:06 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasnap.dll
2014-08-13 00:09 - 2014-07-24 13:05 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2014-08-13 00:09 - 2014-07-24 13:05 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2014-08-13 00:09 - 2014-07-24 12:52 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDYAK.DLL
2014-08-13 00:09 - 2014-07-24 12:52 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDTT102.DLL
2014-08-13 00:09 - 2014-07-24 12:52 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDTAT.DLL
2014-08-13 00:09 - 2014-07-24 12:51 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRUM.DLL
2014-08-13 00:09 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRU1.DLL
2014-08-13 00:09 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDBASH.DLL
2014-08-13 00:09 - 2014-07-24 12:51 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRU.DLL
2014-08-13 00:09 - 2014-07-24 12:49 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersGPExt.dll
2014-08-13 00:09 - 2014-07-24 12:33 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2014-08-13 00:09 - 2014-07-24 12:32 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.cpl
2014-08-13 00:09 - 2014-07-24 12:20 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2014-08-13 00:09 - 2014-07-24 12:18 - 01089024 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpedit.dll
2014-08-13 00:09 - 2014-07-24 12:12 - 00878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2014-08-13 00:09 - 2014-07-24 12:10 - 01844224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2014-08-13 00:09 - 2014-07-24 12:10 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2014-08-13 00:09 - 2014-07-24 12:10 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2014-08-13 00:09 - 2014-07-24 12:10 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasnap.dll
2014-08-13 00:09 - 2014-07-24 12:09 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll
2014-08-13 00:09 - 2014-07-24 12:06 - 00438272 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2014-08-13 00:09 - 2014-07-24 12:05 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2014-08-13 00:09 - 2014-07-24 11:53 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
2014-08-13 00:09 - 2014-07-24 11:52 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2014-08-13 00:09 - 2014-07-24 11:44 - 16874496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-08-13 00:09 - 2014-07-24 11:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.cpl
2014-08-13 00:09 - 2014-07-24 11:40 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2014-08-13 00:09 - 2014-07-24 11:39 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2014-08-13 00:09 - 2014-07-24 11:33 - 01741824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2014-08-13 00:09 - 2014-07-24 11:32 - 01048064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpedit.dll
2014-08-13 00:09 - 2014-07-24 11:27 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll
2014-08-13 00:09 - 2014-07-24 11:27 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2014-08-13 00:09 - 2014-07-24 11:25 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2014-08-13 00:09 - 2014-07-24 11:24 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2014-08-13 00:09 - 2014-07-24 11:23 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2014-08-13 00:09 - 2014-07-24 11:21 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2014-08-13 00:09 - 2014-07-24 11:18 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2014-08-13 00:09 - 2014-07-24 11:16 - 12730880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2014-08-13 00:09 - 2014-07-24 11:14 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2014-08-13 00:09 - 2014-07-24 11:13 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
2014-08-13 00:09 - 2014-07-24 11:12 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2014-08-13 00:09 - 2014-07-24 11:11 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe
2014-08-13 00:09 - 2014-07-24 11:11 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
2014-08-13 00:09 - 2014-07-24 11:10 - 00540672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2014-08-13 00:09 - 2014-07-24 11:09 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
2014-08-13 00:09 - 2014-07-24 11:04 - 00492032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2014-08-13 00:09 - 2014-07-24 11:04 - 00183808 _____ (Microsoft Corp.) C:\WINDOWS\system32\Defrag.exe
2014-08-13 00:09 - 2014-07-24 11:03 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2014-08-13 00:09 - 2014-07-24 11:02 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2014-08-13 00:09 - 2014-07-24 11:00 - 13292544 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-08-13 00:09 - 2014-07-24 10:58 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2014-08-13 00:09 - 2014-07-24 10:53 - 01261056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2014-08-13 00:09 - 2014-07-24 10:53 - 00449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2014-08-13 00:09 - 2014-07-24 10:52 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-08-13 00:09 - 2014-07-24 10:49 - 01361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2014-08-13 00:09 - 2014-07-24 10:49 - 01287680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-08-13 00:09 - 2014-07-24 10:49 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2014-08-13 00:09 - 2014-07-24 10:49 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
2014-08-13 00:09 - 2014-07-24 10:48 - 00659968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2014-08-13 00:09 - 2014-07-24 10:47 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2014-08-13 00:09 - 2014-07-24 10:43 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
2014-08-13 00:09 - 2014-07-24 10:40 - 11794944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-08-13 00:09 - 2014-07-24 10:39 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2014-08-13 00:09 - 2014-07-24 10:38 - 00371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2014-08-13 00:09 - 2014-07-24 10:36 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2014-08-13 00:09 - 2014-07-24 10:32 - 01532416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-08-13 00:09 - 2014-07-24 10:31 - 01038336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-08-13 00:09 - 2014-07-24 10:30 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2014-08-13 00:09 - 2014-07-24 10:30 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2014-08-13 00:09 - 2014-07-24 10:29 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-08-13 00:09 - 2014-07-24 10:29 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2014-08-13 00:09 - 2014-07-24 10:28 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2014-08-13 00:09 - 2014-07-24 10:27 - 00907776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2014-08-13 00:09 - 2014-07-24 10:24 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 00:09 - 2014-07-24 10:23 - 01404416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2014-08-13 00:09 - 2014-07-24 10:22 - 00487936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2014-08-13 00:09 - 2014-07-24 10:21 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2014-08-13 00:09 - 2014-07-24 10:21 - 00302080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2014-08-13 00:09 - 2014-07-24 10:20 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2014-08-13 00:09 - 2014-07-24 10:19 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-08-13 00:09 - 2014-07-24 10:18 - 01144320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2014-08-13 00:09 - 2014-07-24 10:18 - 00795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2014-08-13 00:09 - 2014-07-24 10:18 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-08-13 00:09 - 2014-07-24 10:16 - 00505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2014-08-13 00:09 - 2014-07-24 10:16 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2014-08-13 00:09 - 2014-07-24 10:15 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-08-13 00:09 - 2014-07-24 10:15 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2014-08-13 00:09 - 2014-07-24 10:15 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2014-08-13 00:09 - 2014-07-24 10:13 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2014-08-13 00:09 - 2014-07-24 10:12 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-13 00:09 - 2014-07-24 10:10 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-08-13 00:09 - 2014-07-24 10:10 - 00889344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2014-08-13 00:09 - 2014-07-24 10:10 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-08-13 00:09 - 2014-07-24 10:10 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2014-08-13 00:09 - 2014-07-24 10:08 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2014-08-13 00:09 - 2014-07-24 10:08 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2014-08-13 00:09 - 2014-07-24 10:07 - 01705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-08-13 00:09 - 2014-07-24 10:06 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-08-13 00:09 - 2014-07-24 10:05 - 00448000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll
2014-08-13 00:09 - 2014-07-24 10:04 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-08-13 00:09 - 2014-07-24 10:02 - 03465216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-08-13 00:09 - 2014-07-24 10:01 - 05833216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-08-13 00:09 - 2014-07-24 10:01 - 01992192 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2014-08-13 00:09 - 2014-07-24 10:01 - 01126912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-08-13 00:09 - 2014-07-24 10:00 - 02100736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2014-08-13 00:09 - 2014-07-24 09:58 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2014-08-13 00:09 - 2014-07-24 09:58 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2014-08-13 00:09 - 2014-07-24 09:54 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2014-08-13 00:09 - 2014-07-24 09:50 - 01182208 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.dll
2014-08-13 00:09 - 2014-07-24 09:50 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-08-13 00:09 - 2014-07-24 09:49 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2014-08-13 00:09 - 2014-07-24 09:47 - 00576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2014-08-13 00:09 - 2014-07-24 09:46 - 08652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-08-13 00:09 - 2014-07-24 09:44 - 01057792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.dll
2014-08-13 00:09 - 2014-07-24 09:43 - 02696704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-08-13 00:09 - 2014-07-24 09:43 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-08-13 00:09 - 2014-07-24 09:43 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2014-08-13 00:09 - 2014-07-24 09:41 - 00459264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2014-08-13 00:09 - 2014-07-24 09:39 - 02642944 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-08-13 00:09 - 2014-07-24 09:38 - 06649344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-08-13 00:09 - 2014-07-24 09:38 - 05777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-08-13 00:09 - 2014-07-24 09:33 - 03360768 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-08-13 00:09 - 2014-07-24 09:30 - 02318336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-08-13 00:09 - 2014-07-24 09:28 - 01600000 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2014-08-13 00:09 - 2014-07-24 06:11 - 00513544 _____ () C:\WINDOWS\SysWOW64\locale.nls
2014-08-13 00:09 - 2014-07-24 06:11 - 00513544 _____ () C:\WINDOWS\system32\locale.nls
2014-08-13 00:09 - 2014-07-12 07:55 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll
2014-08-13 00:09 - 2014-07-12 07:23 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-08-13 00:09 - 2014-07-12 06:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
2014-08-13 00:09 - 2014-07-12 06:33 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-08-13 00:09 - 2014-07-12 06:13 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-08-13 00:09 - 2014-07-10 01:19 - 00387391 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-08-13 00:09 - 2014-07-04 22:18 - 00149312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2014-08-13 00:09 - 2014-07-04 14:59 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2014-08-13 00:09 - 2014-07-04 12:29 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2014-08-13 00:09 - 2014-07-04 12:20 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2014-08-13 00:09 - 2014-07-04 12:06 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2014-08-13 00:09 - 2014-07-04 12:00 - 01351168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2014-08-13 00:09 - 2014-07-04 11:30 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2014-08-13 00:09 - 2014-07-04 11:27 - 00474112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2014-08-13 00:09 - 2014-06-27 08:22 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2014-08-13 00:09 - 2014-06-26 02:32 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2014-08-13 00:09 - 2014-06-26 02:29 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
2014-08-13 00:09 - 2014-06-20 03:48 - 01273184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2014-08-13 00:09 - 2014-06-20 01:52 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2014-08-13 00:09 - 2014-06-20 01:37 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-08-13 00:09 - 2014-06-19 04:13 - 00310080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-08-13 00:09 - 2014-06-14 08:03 - 02389504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2014-08-13 00:09 - 2014-06-14 07:46 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2014-08-13 00:09 - 2014-06-13 03:15 - 00517528 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2014-08-13 00:09 - 2014-06-13 03:14 - 01557848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-08-13 00:09 - 2014-06-13 02:10 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2014-08-13 00:09 - 2014-06-07 14:46 - 00216368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2014-08-13 00:09 - 2014-06-07 12:20 - 00189016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2014-08-13 00:09 - 2014-06-06 13:34 - 02133504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2014-08-13 00:09 - 2014-06-05 16:00 - 01118040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2014-08-13 00:09 - 2014-06-05 12:18 - 01018368 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2014-08-13 00:09 - 2014-06-05 11:42 - 00889856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2014-08-13 00:09 - 2014-05-31 07:00 - 01463808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2014-08-13 00:09 - 2014-05-31 06:18 - 01319936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2014-08-13 00:09 - 2014-05-29 08:23 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2014-08-13 00:09 - 2014-05-29 07:25 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2014-08-13 00:09 - 2014-05-29 07:20 - 00427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2014-08-13 00:09 - 2014-05-29 06:36 - 00344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2014-08-13 00:09 - 2014-05-26 09:26 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2014-08-13 00:09 - 2014-05-10 12:12 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2014-08-13 00:09 - 2014-05-10 10:46 - 00335680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2014-08-13 00:09 - 2014-05-06 06:41 - 00486744 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2014-08-13 00:09 - 2014-05-06 02:55 - 00391000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll
2014-08-13 00:09 - 2014-03-25 04:27 - 00160600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmmbase.dll
2014-08-13 00:09 - 2014-03-25 04:27 - 00123920 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmm.dll
2014-08-13 00:09 - 2014-03-25 03:20 - 00128568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmm.dll
2014-08-13 00:09 - 2014-03-25 03:20 - 00127544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmmbase.dll
2014-08-13 00:07 - 2014-08-06 02:48 - 02374816 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-08-13 00:07 - 2014-08-06 01:46 - 02088648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2014-08-13 00:02 - 2014-08-07 00:38 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-08-13 00:02 - 2014-08-02 07:44 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-08-13 00:02 - 2014-08-02 05:11 - 00918528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-08-13 00:02 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-08-13 00:02 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-08-13 00:02 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-08-13 00:02 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-08-13 00:02 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-08-13 00:02 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-08-13 00:02 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-08-13 00:02 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-08-13 00:02 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-08-13 00:02 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-08-13 00:02 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-08-13 00:02 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-08-13 00:02 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-08-13 00:02 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-08-13 00:02 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-08-13 00:02 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-08-13 00:02 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-08-13 00:02 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-08-13 00:02 - 2014-07-25 13:43 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-08-13 00:02 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 00:02 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-08-13 00:02 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-08-13 00:02 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-08-13 00:02 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-08-13 00:02 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-08-13 00:02 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-08-13 00:02 - 2014-07-25 13:09 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-08-13 00:02 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-08-13 00:02 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-08-13 00:02 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-08-13 00:02 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-08-13 00:02 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-08-13 00:02 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-08-13 00:02 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-08-13 00:02 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-08-13 00:02 - 2014-07-15 20:16 - 03048880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2014-08-13 00:02 - 2014-07-15 10:29 - 03118080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2014-08-13 00:02 - 2014-07-15 10:22 - 02861056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebSync.dll
2014-08-13 00:02 - 2014-07-15 10:03 - 02344448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2014-08-13 00:02 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2014-08-13 00:02 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2014-08-13 00:01 - 2014-08-07 04:12 - 01336624 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-08-13 00:01 - 2014-08-02 05:56 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-08-13 00:01 - 2014-07-12 06:17 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2014-08-13 00:01 - 2014-06-04 11:27 - 00114520 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-08-13 00:01 - 2014-06-04 07:31 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-08-13 00:01 - 2014-06-04 07:22 - 02790912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-08-13 00:01 - 2014-06-04 06:43 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-08-13 00:01 - 2014-06-04 06:38 - 03304448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-08-06 11:59 - 2014-08-06 11:59 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-08-06 11:59 - 2014-08-06 11:59 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-08-06 11:59 - 2014-08-06 11:59 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-08-06 11:59 - 2014-08-06 11:59 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-08-06 11:59 - 2014-08-06 11:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-06 11:53 - 2014-08-20 23:04 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-03 12:28 - 2014-06-16 08:01 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2014-08-03 12:28 - 2014-06-16 08:01 - 00110336 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudbus.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-01 16:28 - 2014-09-01 15:19 - 00021165 _____ () C:\Users\Ali\Downloads\FRST.txt
2014-09-01 16:28 - 2014-09-01 15:19 - 00000000 ____D () C:\FRST
2014-09-01 16:28 - 2013-09-14 17:10 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Spotify
2014-09-01 16:26 - 2013-10-18 06:31 - 00003950 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A1F31E70-265A-4835-A81F-B48EFB3A8031}
2014-09-01 16:25 - 2013-09-14 20:58 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4093644379-2981368224-3405264002-1001
2014-09-01 16:23 - 2014-09-01 16:23 - 00000934 _____ () C:\Users\Ali\Desktop\JRT.txt
2014-09-01 16:20 - 2013-09-14 21:27 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-09-01 16:18 - 2014-09-01 16:18 - 01016261 _____ (Thisisu) C:\Users\Ali\Downloads\JRT.exe
2014-09-01 16:18 - 2014-09-01 16:18 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-09-01 16:17 - 2014-09-01 16:17 - 00004278 _____ () C:\Users\Ali\Desktop\AdwCleaner[S0].txt
2014-09-01 16:16 - 2014-09-01 15:05 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-01 16:16 - 2013-10-17 19:38 - 00000000 __RDO () C:\Users\Ali\SkyDrive
2014-09-01 16:14 - 2013-09-29 21:04 - 00098912 _____ () C:\WINDOWS\PFRO.log
2014-09-01 16:14 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-09-01 16:13 - 2014-09-01 16:09 - 00000000 ____D () C:\AdwCleaner
2014-09-01 16:13 - 2013-08-22 15:25 - 01310720 ___SH () C:\WINDOWS\system32\config\BBI
2014-09-01 16:07 - 2014-09-01 16:07 - 00001705 _____ () C:\Users\Ali\Desktop\1.txt
2014-09-01 16:02 - 2013-08-22 16:44 - 00486424 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-09-01 15:59 - 2013-10-17 19:28 - 01789243 _____ () C:\WINDOWS\WindowsUpdate.log
2014-09-01 15:59 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-09-01 15:25 - 2014-09-01 15:23 - 00052203 _____ () C:\Users\Ali\Downloads\Addition.txt
2014-09-01 15:19 - 2014-09-01 15:18 - 02104832 _____ (Farbar) C:\Users\Ali\Downloads\FRST64.exe
2014-09-01 15:11 - 2014-09-01 15:11 - 01364531 _____ () C:\Users\Ali\Downloads\adwcleaner_3.308.exe
2014-09-01 15:05 - 2014-09-01 15:05 - 00001122 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-01 15:05 - 2014-09-01 15:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-01 15:05 - 2014-09-01 15:05 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-01 15:05 - 2014-09-01 15:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-01 15:04 - 2014-09-01 15:04 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ali\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-01 15:04 - 2014-09-01 15:04 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ali\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-09-01 15:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-09-01 14:38 - 2014-05-26 19:09 - 00000000 ____D () C:\Users\Ali\ownCloud
2014-09-01 14:28 - 2013-08-22 16:46 - 00325757 _____ () C:\WINDOWS\setupact.log
2014-09-01 14:23 - 2014-09-01 14:23 - 00000000 ____D () C:\Users\Ali\Desktop\Spiele
2014-09-01 14:21 - 2014-08-31 21:50 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2014-09-01 14:21 - 2014-08-31 21:50 - 00000000 ____D () C:\Program Files\Image-Line
2014-09-01 14:21 - 2014-08-31 21:50 - 00000000 ____D () C:\Program Files (x86)\DSPRobotics
2014-09-01 14:21 - 2014-08-31 21:46 - 00000000 ____D () C:\Program Files (x86)\Image-Line
2014-09-01 14:18 - 2014-09-01 14:18 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\vlc
2014-09-01 14:17 - 2014-09-01 14:17 - 00000891 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-09-01 14:17 - 2014-09-01 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-09-01 14:16 - 2014-09-01 14:16 - 00000000 ____D () C:\Program Files\VideoLAN
2014-09-01 14:10 - 2013-10-22 18:11 - 00800768 ___SH () C:\Users\Ali\Downloads\Thumbs.db
2014-08-31 21:51 - 2014-08-31 21:51 - 00000000 ____D () C:\Program Files\Common Files\VST2
2014-08-31 21:51 - 2014-08-31 21:51 - 00000000 ____D () C:\Program Files\Common Files\Propellerhead Software
2014-08-31 21:50 - 2014-08-31 21:50 - 00000000 ____D () C:\Users\Ali\Documents\Image-Line
2014-08-31 21:50 - 2014-08-31 21:50 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\FlowStone
2014-08-31 19:59 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-08-31 15:00 - 2013-09-14 16:29 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-08-30 20:39 - 2013-09-14 17:10 - 00000000 ____D () C:\Users\Ali\AppData\Local\Spotify
2014-08-30 20:22 - 2013-09-30 06:14 - 01814802 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-08-30 20:22 - 2013-09-30 05:56 - 00784836 _____ () C:\WINDOWS\system32\perfh007.dat
2014-08-30 20:22 - 2013-09-30 05:56 - 00165004 _____ () C:\WINDOWS\system32\perfc007.dat
2014-08-26 14:28 - 2014-05-11 20:27 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Telegram Win (Unofficial)
2014-08-25 15:55 - 2013-09-14 20:51 - 00000000 ____D () C:\Users\Ali\AppData\Local\Packages
2014-08-25 15:16 - 2014-05-06 19:48 - 00000600 _____ () C:\Users\Ali\AppData\Local\PUTTY.RND
2014-08-24 12:05 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-08-23 02:42 - 2014-08-28 17:58 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-23 01:09 - 2013-10-17 19:07 - 00000000 ____D () C:\Users\Ali
2014-08-22 20:20 - 2014-07-06 20:58 - 00000000 ____D () C:\Users\Gast
2014-08-22 20:19 - 2013-05-13 04:39 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-22 20:18 - 2014-08-22 20:18 - 00002268 _____ () C:\Users\Gast\Desktop\SWAT 4.lnk
2014-08-22 20:18 - 2014-08-22 20:18 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sierra
2014-08-22 20:18 - 2014-08-22 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
2014-08-22 20:12 - 2013-11-16 11:10 - 00000000 ____D () C:\Program Files (x86)\Sierra
2014-08-22 20:04 - 2014-08-22 19:25 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\BitTorrent
2014-08-21 14:44 - 2013-09-28 12:09 - 00000000 ____D () C:\Users\Ali\Documents\eclipse
2014-08-21 14:23 - 2014-08-14 10:05 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-21 14:16 - 2014-08-21 14:16 - 00000000 ____D () C:\Users\Ali\AppData\Local\My Games
2014-08-21 14:16 - 2014-08-20 21:56 - 00000000 ____D () C:\Users\Ali\Documents\My Games
2014-08-21 14:15 - 2014-03-03 15:13 - 00119355 _____ () C:\WINDOWS\DirectX.log
2014-08-21 01:12 - 2014-08-21 01:12 - 00002496 _____ () C:\Users\Gast\Desktop\SWAT 4 Single Player Demo.lnk
2014-08-21 01:12 - 2014-08-21 01:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VUGames
2014-08-20 23:20 - 2014-08-18 18:00 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\TS3Client
2014-08-20 23:12 - 2013-09-28 12:23 - 00000000 ____D () C:\Program Files\Java
2014-08-20 23:09 - 2014-08-18 17:59 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-08-20 23:04 - 2014-08-06 11:53 - 00001157 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-20 23:04 - 2014-05-18 20:09 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-20 23:04 - 2013-10-02 15:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-20 23:03 - 2013-09-14 17:10 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-20 22:27 - 2014-08-20 22:17 - 00000000 ____D () C:\Users\Ali\AppData\Local\LogMeIn Hamachi
2014-08-20 22:17 - 2014-08-20 22:17 - 00000000 ____D () C:\Users\Ali\AppData\Local\LogMeIn
2014-08-20 22:17 - 2014-08-20 22:17 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-08-20 21:18 - 2014-08-14 10:18 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-19 14:29 - 2014-08-19 13:48 - 00000000 ____D () C:\Users\Ali\Desktop\musik
2014-08-19 14:02 - 2014-08-19 13:50 - 00000000 ____D () C:\Users\Ali\Desktop\bilder
2014-08-19 13:50 - 2014-08-19 13:49 - 00000000 ____D () C:\Users\Ali\Desktop\Kamera
2014-08-17 21:53 - 2013-10-18 07:23 - 00000000 ____D () C:\Users\Ali\AppData\Local\Deployment
2014-08-17 21:37 - 2014-08-17 21:37 - 00000000 ____D () C:\Users\Ali\Documents\Outlook-Dateien
2014-08-17 21:35 - 2014-08-17 21:34 - 00000000 ____D () C:\Users\Ali\Desktop\Frank2
2014-08-17 21:30 - 2014-08-17 21:30 - 00000000 ____D () C:\Users\Ali\AppData\Local\Adobe
2014-08-16 21:29 - 2013-12-21 16:38 - 00001122 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-16 21:29 - 2013-12-21 16:38 - 00001110 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-16 16:08 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-08-16 13:46 - 2013-09-14 21:27 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-08-14 21:54 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-08-14 21:53 - 2014-07-15 16:17 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-08-14 21:53 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal
2014-08-14 21:53 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-08-14 21:53 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-08-14 21:53 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-14 21:53 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-14 21:53 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-08-14 21:53 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\setup
2014-08-14 21:53 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2014-08-14 21:53 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2014-08-14 21:52 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\InputMethod
2014-08-14 11:10 - 2014-06-09 19:16 - 00014681 _____ () C:\Users\Ali\Desktop\Tortenrechner.xlsx
2014-08-14 10:54 - 2014-08-14 10:54 - 00000000 ____D () C:\Users\Ali\AppData\Roaming\GolemLabs Laboratories
2014-08-14 10:05 - 2014-08-14 10:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-13 00:21 - 2013-09-14 19:22 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-08-13 00:19 - 2013-09-14 19:22 - 99218768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-08-09 14:28 - 2014-05-18 20:50 - 00000000 ____D () C:\Users\Ali\Documents\My Web Sites
2014-08-07 04:12 - 2014-08-13 00:01 - 01336624 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-08-07 00:38 - 2014-08-13 00:02 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-08-06 11:59 - 2014-08-06 11:59 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-08-06 11:59 - 2014-08-06 11:59 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-08-06 11:59 - 2014-08-06 11:59 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-08-06 11:59 - 2014-08-06 11:59 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-08-06 11:59 - 2014-08-06 11:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-06 11:59 - 2013-09-22 17:24 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-06 11:53 - 2013-09-14 17:10 - 00000000 ____D () C:\ProgramData\Avira
2014-08-06 02:48 - 2014-08-13 00:07 - 02374816 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-08-06 01:46 - 2014-08-13 00:07 - 02088648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2014-08-03 12:28 - 2014-03-01 12:42 - 00000000 ____D () C:\Program Files\SAMSUNG
2014-08-03 12:27 - 2013-12-28 23:15 - 00000000 ____D () C:\Users\Ali\Documents\SelfMV
2014-08-03 12:27 - 2013-10-04 23:49 - 00000000 ____D () C:\ProgramData\Samsung
2014-08-03 12:25 - 2013-09-22 18:50 - 00000000 ____D () C:\Program Files (x86)\Kalypso Media
2014-08-03 12:24 - 2013-05-13 04:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2014-08-03 12:24 - 2013-05-13 04:36 - 00000000 ____D () C:\Program Files (x86)\Acer
2014-08-02 11:15 - 2014-08-01 19:40 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-08-02 07:44 - 2014-08-13 00:02 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-08-02 05:56 - 2014-08-13 00:01 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-08-02 05:11 - 2014-08-13 00:02 - 00918528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-08-02 02:17 - 2014-08-14 22:01 - 00704480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-08-02 02:17 - 2014-08-14 22:01 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
Some content of TEMP:
====================
C:\Users\Ali\AppData\Local\Temp\appshat-distribution.exe
C:\Users\Ali\AppData\Local\Temp\AutoRun.exe
C:\Users\Ali\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Ali\AppData\Local\Temp\avgnt.exe
C:\Users\Ali\AppData\Local\Temp\CheatEngine63Clean.exe
C:\Users\Ali\AppData\Local\Temp\drm_dyndata_7260007.dll
C:\Users\Ali\AppData\Local\Temp\drm_dyndata_7400009.dll
C:\Users\Ali\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpagerl2.dll
C:\Users\Ali\AppData\Local\Temp\Execute2App.exe
C:\Users\Ali\AppData\Local\Temp\Installer.exe
C:\Users\Ali\AppData\Local\Temp\javagiac0.25017622973834386.dll
C:\Users\Ali\AppData\Local\Temp\javagiac0.2560649284939721.dll
C:\Users\Ali\AppData\Local\Temp\javagiac0.7138352146825591.dll
C:\Users\Ali\AppData\Local\Temp\javagiac0.7195746094452461.dll
C:\Users\Ali\AppData\Local\Temp\javagiac0.7525524535820622.dll
C:\Users\Ali\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Ali\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Ali\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Ali\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Ali\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Ali\AppData\Local\Temp\msvcp90.dll
C:\Users\Ali\AppData\Local\Temp\msvcr90.dll
C:\Users\Ali\AppData\Local\Temp\nsk5CC2.exe
C:\Users\Ali\AppData\Local\Temp\nsoD606.exe
C:\Users\Ali\AppData\Local\Temp\nss12E2.exe
C:\Users\Ali\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\Ali\AppData\Local\Temp\Quarantine.exe
C:\Users\Ali\AppData\Local\Temp\Shockwave_Installer_FF.exe
C:\Users\Ali\AppData\Local\Temp\sqlite3.exe
C:\Users\Ali\AppData\Local\Temp\SRLDetectionLibrary5465121850248568459.dll
C:\Users\Ali\AppData\Local\Temp\SRLDetectionLibrary9090806934770533994.dll
C:\Users\Ali\AppData\Local\Temp\tmp11EA.tmp.exe
C:\Users\Ali\AppData\Local\Temp\tmp4B98.tmp.exe
C:\Users\Ali\AppData\Local\Temp\tmp70DF.tmp.exe
C:\Users\Ali\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Ali\AppData\Local\Temp\utt95A4.tmp.exe
C:\Users\Ali\AppData\Local\Temp\_is2B28.exe
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-22 23:42
==================== End Of Log ============================ --- --- ---
--- --- --- |