Stage2009 | 14.09.2014 13:10 | So:
MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 14.09.2014
Suchlauf-Zeit: 13:47:33
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.14.03
Rootkit Datenbank: v2014.09.13.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Dennis
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 305168
Verstrichene Zeit: 4 Min, 36 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Service\ttsvc.exe, 2128, Löschen bei Neustart, [fa91e9044e2d20164383827cb54d7e82]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 17
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}\INPROCSERVER32, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{733413F4-5FB9-4EE9-8536-BF7AB1731A19}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3DD26F46-6B41-49B2-878E-1883411BBB59}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3DD26F46-6B41-49B2-878E-1883411BBB59}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{733413F4-5FB9-4EE9-8536-BF7AB1731A19}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-3656314769-1064978787-4233295665-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-3656314769-1064978787-4233295665-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\TermTutor, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ttsvc, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ttnfd, In Quarantäne, [99f21cd19eddff3736934cb2c63cee12],
PUP.Optional.SuperFish.A, HKU\S-1-5-21-3656314769-1064978787-4233295665-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [2f5cd41969122d09643b56b79a69b749],
Registrierungswerte: 2
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD|ImagePath, system32\drivers\ttnfd.sys, In Quarantäne, [503be706443778bedcee44ba37cb8878]
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTSVC|ImagePath, "C:\Program Files (x86)\TermTutor\Service\ttsvc.exe", In Quarantäne, [f3983fae631883b3eed938c68a78e41c]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 4
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor, Löschen bei Neustart, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\IE, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Service, Löschen bei Neustart, [fa91e9044e2d20164383827cb54d7e82],
Dateien: 12
PUP.Optional.TermTutor.A, C:\Program Files\TermTutor\IE\TermTutorClientIE.dll, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\IE\TermTutorClientIE.dll, In Quarantäne, [1a718667f68562d4821ba4deb54d35cb],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\terms-of-service.rtf, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Uninstall.exe, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\buildcrx-license.txt, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\Info-ZIP-license.txt, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\nsJSON-license.txt, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\UAC-license.txt, In Quarantäne, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Service\ttsvc.exe, Löschen bei Neustart, [fa91e9044e2d20164383827cb54d7e82],
PUP.Optional.TermTutor.A, C:\Windows\System32\drivers\ttnfd.sys, In Quarantäne, [99f21cd19eddff3736934cb2c63cee12],
PUP.Optional.Superfish.A, C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [bfcc37b6cead8fa7af9f6aaf55aec53b],
PUP.Optional.Superfish.A, C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [f9929f4e304b55e1b29c35e4a162e51b],
Physische Sektoren: 0
(No malicious items detected)
(end) ADW: Code:
# AdwCleaner v3.310 - Report created 14/09/2014 at 13:57:45
# Updated 12/09/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Dennis - DENNIS
# Running from : C:\Users\Dennis\Downloads\AdwCleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
File Deleted : C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\wla6vwqs.default\user.js
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16384
-\\ Mozilla Firefox v32.0.1 (x86 de)
[ File : C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\wla6vwqs.default\prefs.js ]
-\\ Google Chrome v
[ File : C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2375 octets] - [13/09/2014 11:54:54]
AdwCleaner[R1].txt - [1223 octets] - [14/09/2014 13:56:54]
AdwCleaner[S0].txt - [1883 octets] - [13/09/2014 11:55:45]
AdwCleaner[S1].txt - [1135 octets] - [14/09/2014 13:57:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1195 octets] ########## JWR: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Dennis on 14.09.2014 at 14:00:28,51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.09.2014 at 14:04:00,90
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frische FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Dennis (administrator) on DENNIS on 14-09-2014 14:07:46
Running from C:\Users\Dennis\Downloads
Platform: Windows 8.1 (X64) OS Language: Englisch (Vereinigte Staaten)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
() C:\Windows\SysWOW64\AsHookDevice.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe
(PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Lighting\ASUS_Manager_Lighting.exe
(Microsoft) C:\Program Files (x86)\ASUS\ASUS Launcher\Launcher.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Power Manager\Power Manager_background.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\NFC Express Desktops\DTNFCServer.exe
() C:\Program Files (x86)\ASUS\ASUS Manager\Application Update\ASUSUpdateChecker.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{9AF45D7C-34F1-4BA0-B799-825C8C04494C}\AiChargerDT.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\Built-in UPS\Built-in UPS.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
() C:\Program Files (x86)\ASUS\ASUS Manager\NFC Express Desktops\DT_NFCExpressDesktops.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Ai Charger II\Ai_ChargerII_TrayIcon(ASUS_Manager).exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\APRP\aprp.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Windows\WinStore\WSHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe
() C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSService.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7199448 2013-09-05] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-30] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-08] (Intel Corporation)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [280576 2013-09-26] (Realtek Semiconductor Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3216032 2014-01-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\ASUSWSLoader.exe [63296 2013-08-16] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-09] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [181208 2013-06-24] (cyberlink)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3656314769-1064978787-4233295665-1001\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-08-19] (AMD)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: !AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: !AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: !AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: StorageProviderError -> {0CA2640D-5B9C-4c59-A5FB-2DA61A7437CF} => C:\Windows\System32\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: StorageProviderSyncing -> {0A30F902-8398-4ee8-86F7-4CFB589F04D1} => C:\Windows\System32\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: StorageProviderError -> {0CA2640D-5B9C-4c59-A5FB-2DA61A7437CF} => C:\Windows\SysWOW64\shell32.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: StorageProviderSyncing -> {0A30F902-8398-4ee8-86F7-4CFB589F04D1} => C:\Windows\SysWOW64\shell32.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\wla6vwqs.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com ()
FF Plugin-x32: @kaspersky.com/online_banking -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\wla6vwqs.default\user.js
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Modul zum Sperren von gefährlichen Webseiten - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtuelle Tastatur - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: 卡巴斯基網址過濾 - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com [2014-09-12]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Sicherer Zahlungsverkehr - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2014-09-12]
Chrome:
=======
CHR HomePage: Default ->
CHR DefaultSearchKeyword: Default -> 2B68679307CD89AF5750DACE6795E086445A6566B3C48BF136781D3D4224E58B
CHR DefaultSearchProvider: Default -> F2811A452EEF687EB632B2F1CD69B5C6698073D99770A61B9B76F45E88097E7A
CHR DefaultSearchURL: Default -> 3A67F7884DAE179AC498699CE549676F9F99B74C93592DEF698E465D05E1A425
CHR Profile: C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-12]
CHR Extension: (Google Docs) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-12]
CHR Extension: (Google Drive) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-12]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-12]
CHR Extension: (YouTube) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-12]
CHR Extension: (Google-Suche) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-12]
CHR Extension: (Kaspersky Protection) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2014-09-12]
CHR Extension: (Google Wallet) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-12]
CHR Extension: (Google Mail) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-12]
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho []
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2013-08-28] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2013-05-15] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680 2013-08-16] (ASUS Cloud Corporation) [File not signed]
R2 AVP15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe [233552 2014-04-20] (Kaspersky Lab ZAO)
R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-05-07] (Realtek Semiconductor Corporation) [File not signed]
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [59392 2013-09-26] () [File not signed]
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [244696 2013-06-25] (CyberLink)
R2 Device Handle Service; C:\Windows\SysWOW64\AsHookDevice.exe [207160 2013-08-08] ()
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-24] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-08] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-19] (Intel Corporation)
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-01-13] (Microsoft Corporation)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2013-08-22] (Microsoft Corporation)
R2 postgresql-x64-9.3; C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe [89088 2014-07-22] (PostgreSQL Global Development Group) [File not signed]
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AiChargerDT; C:\Windows\SysWow64\drivers\AiChargerDT.sys [14880 2012-10-18] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.)
R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d64x64.sys [469264 2013-06-26] (Intel Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [457824 2014-02-20] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [141376 2014-09-12] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [243808 2014-04-10] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [769600 2014-09-12] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2014-02-25] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [28768 2014-03-28] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-08-08] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\system32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [67680 2014-03-19] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [179296 2014-03-26] (Kaspersky Lab ZAO)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-19] (Intel Corporation)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69264 2013-08-07] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [548056 2013-09-05] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2944216 2013-08-21] (Realtek Semiconductor Corporation )
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-14 14:04 - 2014-09-14 14:04 - 00000615 _____ () C:\Users\Dennis\Desktop\JRT.txt
2014-09-14 14:00 - 2014-09-14 14:00 - 00000000 ____D () C:\Windows\ERUNT
2014-09-14 13:58 - 2014-09-14 13:58 - 00001275 _____ () C:\Users\Dennis\Desktop\AdwCleaner[S1].txt
2014-09-14 13:55 - 2014-09-14 13:55 - 00006815 _____ () C:\Users\Dennis\Desktop\MBAM.txt
2014-09-14 13:52 - 2014-09-14 13:52 - 00002054 _____ () C:\Users\Dennis\Desktop\Anleitung.txt
2014-09-14 13:45 - 2014-09-14 13:53 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-14 13:45 - 2014-09-14 13:45 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-14 13:45 - 2014-09-14 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-14 13:45 - 2014-09-14 13:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-14 13:45 - 2014-09-14 13:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-14 13:45 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-14 13:45 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-14 13:45 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-14 13:44 - 2014-09-14 13:44 - 01016261 _____ (Thisisu) C:\Users\Dennis\Downloads\JRT.exe
2014-09-14 13:43 - 2014-09-14 13:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dennis\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-14 13:43 - 2014-09-14 13:44 - 01373475 _____ () C:\Users\Dennis\Downloads\AdwCleaner_3.310(1).exe
2014-09-14 13:40 - 2014-09-14 13:40 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 13:40 - 2014-08-29 13:01 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-14 13:40 - 2014-01-04 22:50 - 01462216 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-09-14 13:40 - 2014-01-04 21:22 - 01202888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-09-14 13:40 - 2014-01-04 16:30 - 13209088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-09-14 13:40 - 2014-01-04 16:23 - 11702272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-09-14 13:40 - 2014-01-04 16:03 - 00919040 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-09-14 13:40 - 2014-01-04 15:47 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2014-09-14 13:40 - 2014-01-04 15:42 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-09-14 13:40 - 2014-01-04 15:40 - 07416832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-09-14 13:40 - 2014-01-04 15:36 - 00830976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-09-14 13:40 - 2014-01-04 15:28 - 04961792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-09-14 13:40 - 2013-12-21 04:10 - 00009701 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms
2014-09-14 13:40 - 2013-12-21 04:10 - 00009701 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms
2014-09-14 13:39 - 2014-04-19 13:15 - 21186352 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-09-14 13:39 - 2014-04-19 08:49 - 18644072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-09-14 13:36 - 2014-02-22 14:16 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-09-14 13:36 - 2014-02-22 13:24 - 00124416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-09-14 13:36 - 2014-02-11 05:04 - 04189184 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-09-14 13:36 - 2014-02-11 04:43 - 00488448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-09-14 13:36 - 2014-02-11 04:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-09-14 13:36 - 2014-01-07 09:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe
2014-09-14 13:36 - 2014-01-07 07:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe
2014-09-14 13:36 - 2013-12-09 04:57 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-14 13:36 - 2013-12-09 03:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-14 13:35 - 2013-12-09 02:15 - 00787968 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2014-09-14 13:35 - 2013-11-09 08:34 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2014-09-14 13:35 - 2013-11-09 08:34 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll
2014-09-14 13:35 - 2013-11-09 07:52 - 00240128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll
2014-09-14 13:35 - 2013-10-16 17:58 - 01943536 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-09-14 13:35 - 2013-10-16 15:54 - 01581968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-09-14 13:35 - 2013-10-15 10:54 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-09-14 13:35 - 2013-10-15 10:03 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-09-14 13:32 - 2014-09-14 13:32 - 00055843 _____ () C:\Users\Dennis\Desktop\FRST.txt
2014-09-14 13:32 - 2014-09-14 13:32 - 00037237 _____ () C:\Users\Dennis\Desktop\Addition.txt
2014-09-14 11:45 - 2014-09-14 11:45 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-14 11:45 - 2014-09-14 11:45 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-09-14 11:45 - 2014-09-14 11:45 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-09-14 11:44 - 2014-09-14 11:44 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Macromedia
2014-09-14 11:35 - 2014-09-14 11:35 - 00709564 _____ () C:\Users\Dennis\Downloads\delfix_10.8.exe
2014-09-14 11:24 - 2014-09-14 11:47 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Adobe
2014-09-14 11:09 - 2014-09-14 11:09 - 00001182 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-14 11:09 - 2014-09-14 11:09 - 00001170 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-14 11:09 - 2014-09-14 11:09 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Mozilla
2014-09-14 11:09 - 2014-09-14 11:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-14 11:09 - 2014-09-14 11:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-14 10:54 - 2014-09-14 10:55 - 13114824 _____ (ASUS Cloud Corporation) C:\Users\Dennis\Downloads\WebStorageSyncAgent 2.1.10.398.exe
2014-09-13 15:52 - 2014-09-13 15:52 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-09-13 15:52 - 2014-09-13 15:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-09-13 15:52 - 2014-09-13 15:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-09-13 15:52 - 2014-09-13 15:52 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-09-13 15:52 - 2014-09-13 15:52 - 00001319 _____ () C:\Users\Dennis\Desktop\Calculator.lnk
2014-09-13 15:52 - 2014-09-13 15:52 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HoldemResources
2014-09-13 15:52 - 2014-09-13 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-13 15:52 - 2014-09-13 15:52 - 00000000 ____D () C:\Program Files\Java
2014-09-13 15:50 - 2014-09-13 15:50 - 00000000 ____D () C:\Users\Dennis\AppData\Local\HoldemResources
2014-09-13 15:41 - 2014-09-13 15:44 - 74773785 _____ (HoldemResources) C:\Users\Dennis\Downloads\holdemresources_release_x86_64_win-setup.exe
2014-09-13 13:35 - 2014-09-14 13:58 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-13 13:35 - 2014-09-14 13:40 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-13 13:35 - 2014-09-13 13:35 - 00004096 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-13 13:35 - 2014-09-13 13:35 - 00003860 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-13 11:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-13 11:54 - 2014-09-14 13:57 - 00000000 ____D () C:\AdwCleaner
2014-09-13 11:54 - 2014-09-13 11:54 - 01373475 _____ () C:\Users\Dennis\Downloads\AdwCleaner_3.310.exe
2014-09-13 11:49 - 2014-09-13 11:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-09-13 02:04 - 2014-09-13 01:34 - 117931107 _____ () C:\Users\Dennis\Desktop\Back_up_12.09.zip
2014-09-13 01:41 - 2014-09-13 01:41 - 00000000 __SHD () C:\aws
2014-09-13 01:41 - 2014-09-13 01:41 - 00000000 ____D () C:\Asus WebStorage
2014-09-13 00:26 - 2014-09-13 00:26 - 00001097 _____ () C:\Users\Dennis\Desktop\PokerTracker 4.lnk
2014-09-13 00:26 - 2014-09-13 00:26 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerTracker 4
2014-09-13 00:24 - 2014-09-13 00:24 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\postgresql
2014-09-13 00:16 - 2014-09-13 00:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 9.3
2014-09-13 00:15 - 2014-09-13 00:15 - 00000000 ____D () C:\Program Files\PostgreSQL
2014-09-13 00:07 - 2014-09-13 00:09 - 56552816 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\Downloads\postgresql-9.3.5-1-windows-x64 (1).exe
2014-09-12 23:50 - 2014-09-12 23:51 - 51895176 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\Downloads\postgresql-9.0.18-1-windows-x64.exe
2014-09-12 23:38 - 2014-09-13 11:48 - 00002357 _____ () C:\Users\Dennis\Desktop\Sicherer Zahlungsverkehr.lnk
2014-09-12 23:38 - 2014-09-12 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-09-12 23:38 - 2014-09-12 23:37 - 00001219 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2014-09-12 23:37 - 2014-09-14 14:05 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-09-12 23:37 - 2014-09-12 23:49 - 00769600 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-09-12 23:37 - 2014-09-12 23:49 - 00141376 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-09-12 23:37 - 2014-09-12 23:37 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-09-12 23:37 - 2014-04-10 18:25 - 00243808 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys
2014-09-12 23:37 - 2013-05-06 10:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2014-09-12 23:31 - 2014-09-12 23:31 - 06501278 _____ () C:\Users\Dennis\Downloads\Nicht bestätigt 314320.crdownload
2014-09-12 23:28 - 2014-09-12 23:33 - 176561792 _____ () C:\Users\Dennis\Downloads\kis15.0.0.463de-de.exe
2014-09-12 23:14 - 2014-09-12 23:14 - 00247722 _____ () C:\Users\Dennis\Downloads\notes.o_S7ven_o.xml
2014-09-12 23:10 - 2014-09-12 23:11 - 56552816 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\postgresql_93.exe
2014-09-12 23:04 - 2014-09-12 23:05 - 56552816 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\Downloads\postgresql-9.3.5-1-windows-x64.exe
2014-09-12 22:52 - 2014-09-12 22:52 - 00000092 _____ () C:\Users\Dennis\Desktop\test.txt
2014-09-12 22:48 - 2014-09-12 22:48 - 00001291 _____ () C:\Users\Dennis\Desktop\Revo Uninstaller.lnk
2014-09-12 22:48 - 2014-09-12 22:48 - 00000068 _____ () C:\Users\Dennis\AppData\Roaming\WB.CFG
2014-09-12 22:48 - 2014-09-12 22:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-12 22:47 - 2014-09-12 22:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Dennis\Downloads\revosetup95.exe
2014-09-12 22:45 - 2014-09-14 13:32 - 00037237 _____ () C:\Users\Dennis\Downloads\Addition.txt
2014-09-12 22:44 - 2014-09-14 14:07 - 00024597 _____ () C:\Users\Dennis\Downloads\FRST.txt
2014-09-12 22:44 - 2014-09-14 14:07 - 00000000 ____D () C:\FRST
2014-09-12 22:43 - 2014-09-12 22:43 - 02105856 _____ (Farbar) C:\Users\Dennis\Downloads\FRST64.exe
2014-09-12 22:36 - 2014-09-12 22:42 - 63697776 _____ () C:\Users\Dennis\Downloads\PT-Install-v4.11.11.exe
2014-09-12 22:35 - 2014-09-12 22:35 - 00002392 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICMIZER.lnk
2014-09-12 22:35 - 2014-09-12 22:35 - 00002362 _____ () C:\Users\Dennis\Desktop\ICMIZER.lnk
2014-09-12 22:14 - 2014-09-13 13:36 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-12 22:14 - 2014-09-12 22:18 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Google
2014-09-12 22:14 - 2014-09-12 22:14 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Deployment
2014-09-12 22:14 - 2014-09-12 22:14 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Apps\2.0
2014-09-12 22:12 - 2014-09-13 01:27 - 00000000 ____D () C:\Users\Dennis\AppData\Local\PokerTracker 4
2014-09-12 22:12 - 2014-09-12 22:12 - 00005044 _____ () C:\ProgramData\flwjycbm.bab
2014-09-12 22:12 - 2014-09-12 22:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerTracker 4
2014-09-12 22:11 - 2014-09-14 11:14 - 00000000 ____D () C:\Program Files (x86)\PokerTracker 4
2014-09-12 22:08 - 2014-09-12 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-12 22:08 - 2014-09-12 22:08 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-09-12 22:08 - 2014-09-12 22:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-12 22:01 - 2014-09-14 11:18 - 00000000 ____D () C:\Users\Dennis\AppData\Local\PokerStars.EU
2014-09-12 22:01 - 2014-09-12 22:01 - 00002023 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\PokerStars.eu.lnk
2014-09-12 22:01 - 2014-09-12 22:01 - 00001999 _____ () C:\Users\Dennis\Desktop\PokerStars.eu.lnk
2014-09-12 22:01 - 2014-09-12 22:01 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.EU
2014-09-12 22:00 - 2014-09-13 12:13 - 00000000 ____D () C:\Program Files (x86)\PokerStars.EU
2014-09-12 21:56 - 2014-09-14 11:32 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\TableNinja.v2
2014-09-12 21:56 - 2014-09-13 21:59 - 00003063 _____ () C:\Users\Dennis\Desktop\TableNinja v2.lnk
2014-09-12 21:56 - 2014-09-13 21:59 - 00003023 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TableNinja v2.lnk
2014-09-12 21:56 - 2014-09-12 21:57 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\HoldemManager
2014-09-12 21:56 - 2014-09-12 21:56 - 00000000 ____D () C:\Program Files (x86)\PASG
2014-09-12 21:51 - 2014-09-12 21:51 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Mozilla
2014-09-12 21:50 - 2014-09-12 21:50 - 00000000 ____D () C:\ProgramData\Mozilla
2014-09-12 21:48 - 2014-09-12 21:48 - 00000000 ____D () C:\Program Files\TermTutor
2014-09-12 21:36 - 2014-09-12 21:36 - 00002071 _____ () C:\Users\Public\Desktop\AI Suite II.lnk
2014-09-12 21:30 - 2014-09-12 21:30 - 00000000 ___HD () C:\kleaner.tmp
2014-09-12 21:29 - 2014-09-12 21:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-09-12 21:18 - 2014-09-12 21:18 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Macromedia
2014-09-12 21:14 - 2014-09-14 14:06 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3656314769-1064978787-4233295665-1001
2014-09-12 21:13 - 2014-09-14 11:15 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0AD65E03-0F0B-4F68-8FB0-C71DE2348261}
2014-09-12 21:12 - 2014-09-14 14:01 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\WebStorage
2014-09-12 21:12 - 2014-09-12 21:12 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-09-12 21:11 - 2014-09-14 14:01 - 00000000 ___RD () C:\Users\Dennis\SkyDrive
2014-09-12 21:11 - 2012-04-16 06:00 - 00389120 _____ (CANON INC.) C:\Windows\system32\CNMLMBB.DLL
2014-09-12 21:10 - 2014-09-12 21:10 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Intel Corporation
2014-09-12 21:09 - 2014-09-12 21:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-09-12 21:09 - 2014-09-12 21:09 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\ATI
2014-09-12 21:09 - 2014-09-12 21:09 - 00000000 ____D () C:\Users\Dennis\AppData\Local\ATI
2014-09-12 21:08 - 2014-09-14 14:01 - 00031180 _____ () C:\Users\Dennis\AppData\Local\BTServer.log
2014-09-12 21:08 - 2014-09-14 11:24 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Adobe
2014-09-12 21:08 - 2014-09-12 23:02 - 00000000 ____D () C:\Users\Dennis\AppData\Local\ASUS
2014-09-12 21:08 - 2014-09-12 21:09 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Packages
2014-09-12 21:08 - 2014-09-12 21:08 - 00001453 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-12 21:08 - 2014-09-12 21:08 - 00000000 ____D () C:\Users\Dennis\Documents\My Bluetooth
2014-09-12 21:08 - 2014-09-12 21:08 - 00000000 ____D () C:\Users\Dennis\AppData\Local\VirtualStore
2014-09-12 21:07 - 2014-09-13 02:14 - 00000000 ____D () C:\Users\Dennis
2014-09-12 21:07 - 2014-09-12 21:07 - 00000020 ___SH () C:\Users\Dennis\ntuser.ini
2014-09-12 21:07 - 2014-01-13 12:44 - 00002114 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2014-09-12 21:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-09-12 21:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-09-12 21:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-09-12 21:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-14 14:08 - 2014-09-12 22:44 - 00024597 _____ () C:\Users\Dennis\Downloads\FRST.txt
2014-09-14 14:07 - 2014-09-12 22:44 - 00000000 ____D () C:\FRST
2014-09-14 14:06 - 2014-09-12 21:14 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3656314769-1064978787-4233295665-1001
2014-09-14 14:06 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-14 14:05 - 2014-09-12 23:37 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-09-14 14:04 - 2014-09-14 14:04 - 00000615 _____ () C:\Users\Dennis\Desktop\JRT.txt
2014-09-14 14:04 - 2014-01-13 12:03 - 08365588 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-14 14:04 - 2013-09-13 23:24 - 00450712 _____ () C:\Windows\system32\prfh0404.dat
2014-09-14 14:04 - 2013-09-13 23:24 - 00135868 _____ () C:\Windows\system32\prfc0404.dat
2014-09-14 14:04 - 2013-09-13 23:15 - 00436346 _____ () C:\Windows\system32\prfh0804.dat
2014-09-14 14:04 - 2013-09-13 23:15 - 00135868 _____ () C:\Windows\system32\prfc0804.dat
2014-09-14 14:04 - 2013-09-13 23:07 - 00789596 _____ () C:\Windows\system32\prfh0816.dat
2014-09-14 14:04 - 2013-09-13 23:07 - 00164166 _____ () C:\Windows\system32\prfc0816.dat
2014-09-14 14:04 - 2013-09-13 22:59 - 00798252 _____ () C:\Windows\system32\perfh013.dat
2014-09-14 14:04 - 2013-09-13 22:59 - 00162330 _____ () C:\Windows\system32\perfc013.dat
2014-09-14 14:04 - 2013-09-13 22:52 - 00794000 _____ () C:\Windows\system32\perfh010.dat
2014-09-14 14:04 - 2013-09-13 22:52 - 00156420 _____ () C:\Windows\system32\perfc010.dat
2014-09-14 14:04 - 2013-09-13 22:45 - 00802234 _____ () C:\Windows\system32\perfh00C.dat
2014-09-14 14:04 - 2013-09-13 22:45 - 00159184 _____ () C:\Windows\system32\perfc00C.dat
2014-09-14 14:04 - 2013-09-13 22:38 - 00800660 _____ () C:\Windows\system32\perfh00A.dat
2014-09-14 14:04 - 2013-09-13 22:38 - 00166550 _____ () C:\Windows\system32\perfc00A.dat
2014-09-14 14:04 - 2013-09-13 22:28 - 00542632 _____ () C:\Windows\system32\perfh008.dat
2014-09-14 14:04 - 2013-09-13 22:28 - 00089196 _____ () C:\Windows\system32\perfc008.dat
2014-09-14 14:04 - 2013-09-13 22:22 - 00763218 _____ () C:\Windows\system32\perfh007.dat
2014-09-14 14:04 - 2013-09-13 22:22 - 00159364 _____ () C:\Windows\system32\perfc007.dat
2014-09-14 14:01 - 2014-09-12 21:12 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\WebStorage
2014-09-14 14:01 - 2014-09-12 21:11 - 00000000 ___RD () C:\Users\Dennis\SkyDrive
2014-09-14 14:01 - 2014-09-12 21:08 - 00031180 _____ () C:\Users\Dennis\AppData\Local\BTServer.log
2014-09-14 14:00 - 2014-09-14 14:00 - 00000000 ____D () C:\Windows\ERUNT
2014-09-14 14:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-09-14 13:58 - 2014-09-14 13:58 - 00001275 _____ () C:\Users\Dennis\Desktop\AdwCleaner[S1].txt
2014-09-14 13:58 - 2014-09-13 13:35 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-14 13:58 - 2014-04-10 20:39 - 00000025 ___SH () C:\Windows\SysWOW64\ReadTag.ini
2014-09-14 13:58 - 2014-01-13 11:53 - 00029514 _____ () C:\Windows\PFRO.log
2014-09-14 13:58 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-14 13:57 - 2014-09-13 11:54 - 00000000 ____D () C:\AdwCleaner
2014-09-14 13:55 - 2014-09-14 13:55 - 00006815 _____ () C:\Users\Dennis\Desktop\MBAM.txt
2014-09-14 13:53 - 2014-09-14 13:45 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-14 13:53 - 2013-09-13 22:32 - 00000000 ____D () C:\Windows\en-GB
2014-09-14 13:53 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-09-14 13:53 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\SysWOW64\en-GB
2014-09-14 13:53 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\en-GB
2014-09-14 13:53 - 2013-08-22 16:44 - 00424056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-14 13:53 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-14 13:52 - 2014-09-14 13:52 - 00002054 _____ () C:\Users\Dennis\Desktop\Anleitung.txt
2014-09-14 13:52 - 2014-04-10 20:27 - 01389132 _____ () C:\Windows\WindowsUpdate.log
2014-09-14 13:45 - 2014-09-14 13:45 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-14 13:45 - 2014-09-14 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-14 13:45 - 2014-09-14 13:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-14 13:45 - 2014-09-14 13:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-14 13:44 - 2014-09-14 13:44 - 01016261 _____ (Thisisu) C:\Users\Dennis\Downloads\JRT.exe
2014-09-14 13:44 - 2014-09-14 13:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dennis\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-14 13:44 - 2014-09-14 13:43 - 01373475 _____ () C:\Users\Dennis\Downloads\AdwCleaner_3.310(1).exe
2014-09-14 13:41 - 2014-09-14 13:40 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 13:41 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-09-14 13:41 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-09-14 13:40 - 2014-09-13 13:35 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-14 13:40 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-14 13:32 - 2014-09-14 13:32 - 00055843 _____ () C:\Users\Dennis\Desktop\FRST.txt
2014-09-14 13:32 - 2014-09-14 13:32 - 00037237 _____ () C:\Users\Dennis\Desktop\Addition.txt
2014-09-14 13:32 - 2014-09-12 22:45 - 00037237 _____ () C:\Users\Dennis\Downloads\Addition.txt
2014-09-14 11:47 - 2014-09-14 11:24 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Adobe
2014-09-14 11:45 - 2014-09-14 11:45 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-14 11:45 - 2014-09-14 11:45 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-09-14 11:45 - 2014-09-14 11:45 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-09-14 11:45 - 2014-01-13 12:22 - 00000000 ____D () C:\ProgramData\Adobe
2014-09-14 11:44 - 2014-09-14 11:44 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Macromedia
2014-09-14 11:35 - 2014-09-14 11:35 - 00709564 _____ () C:\Users\Dennis\Downloads\delfix_10.8.exe
2014-09-14 11:32 - 2014-09-12 21:56 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\TableNinja.v2
2014-09-14 11:24 - 2014-09-12 21:08 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Adobe
2014-09-14 11:18 - 2014-09-12 22:01 - 00000000 ____D () C:\Users\Dennis\AppData\Local\PokerStars.EU
2014-09-14 11:15 - 2014-09-12 21:13 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0AD65E03-0F0B-4F68-8FB0-C71DE2348261}
2014-09-14 11:14 - 2014-09-12 22:11 - 00000000 ____D () C:\Program Files (x86)\PokerTracker 4
2014-09-14 11:09 - 2014-09-14 11:09 - 00001182 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-14 11:09 - 2014-09-14 11:09 - 00001170 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-14 11:09 - 2014-09-14 11:09 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Mozilla
2014-09-14 11:09 - 2014-09-14 11:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-14 11:09 - 2014-09-14 11:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-14 10:55 - 2014-09-14 10:54 - 13114824 _____ (ASUS Cloud Corporation) C:\Users\Dennis\Downloads\WebStorageSyncAgent 2.1.10.398.exe
2014-09-13 21:59 - 2014-09-12 21:56 - 00003063 _____ () C:\Users\Dennis\Desktop\TableNinja v2.lnk
2014-09-13 21:59 - 2014-09-12 21:56 - 00003023 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TableNinja v2.lnk
2014-09-13 18:38 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-09-13 15:52 - 2014-09-13 15:52 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-09-13 15:52 - 2014-09-13 15:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-09-13 15:52 - 2014-09-13 15:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-09-13 15:52 - 2014-09-13 15:52 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-09-13 15:52 - 2014-09-13 15:52 - 00001319 _____ () C:\Users\Dennis\Desktop\Calculator.lnk
2014-09-13 15:52 - 2014-09-13 15:52 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HoldemResources
2014-09-13 15:52 - 2014-09-13 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-09-13 15:52 - 2014-09-13 15:52 - 00000000 ____D () C:\Program Files\Java
2014-09-13 15:50 - 2014-09-13 15:50 - 00000000 ____D () C:\Users\Dennis\AppData\Local\HoldemResources
2014-09-13 15:44 - 2014-09-13 15:41 - 74773785 _____ (HoldemResources) C:\Users\Dennis\Downloads\holdemresources_release_x86_64_win-setup.exe
2014-09-13 13:36 - 2014-09-12 22:14 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-13 13:35 - 2014-09-13 13:35 - 00004096 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-13 13:35 - 2014-09-13 13:35 - 00003860 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-13 12:13 - 2014-09-12 22:00 - 00000000 ____D () C:\Program Files (x86)\PokerStars.EU
2014-09-13 11:54 - 2014-09-13 11:54 - 01373475 _____ () C:\Users\Dennis\Downloads\AdwCleaner_3.310.exe
2014-09-13 11:49 - 2014-09-13 11:49 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-09-13 11:49 - 2013-08-22 16:46 - 00014700 _____ () C:\Windows\setupact.log
2014-09-13 11:48 - 2014-09-12 23:38 - 00002357 _____ () C:\Users\Dennis\Desktop\Sicherer Zahlungsverkehr.lnk
2014-09-13 05:49 - 2014-01-13 11:53 - 00000000 ____D () C:\Windows\Panther
2014-09-13 02:14 - 2014-09-12 21:07 - 00000000 ____D () C:\Users\Dennis
2014-09-13 01:41 - 2014-09-13 01:41 - 00000000 __SHD () C:\aws
2014-09-13 01:41 - 2014-09-13 01:41 - 00000000 ____D () C:\Asus WebStorage
2014-09-13 01:34 - 2014-09-13 02:04 - 117931107 _____ () C:\Users\Dennis\Desktop\Back_up_12.09.zip
2014-09-13 01:27 - 2014-09-12 22:12 - 00000000 ____D () C:\Users\Dennis\AppData\Local\PokerTracker 4
2014-09-13 00:26 - 2014-09-13 00:26 - 00001097 _____ () C:\Users\Dennis\Desktop\PokerTracker 4.lnk
2014-09-13 00:26 - 2014-09-13 00:26 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerTracker 4
2014-09-13 00:24 - 2014-09-13 00:24 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\postgresql
2014-09-13 00:16 - 2014-09-13 00:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 9.3
2014-09-13 00:15 - 2014-09-13 00:15 - 00000000 ____D () C:\Program Files\PostgreSQL
2014-09-13 00:09 - 2014-09-13 00:07 - 56552816 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\Downloads\postgresql-9.3.5-1-windows-x64 (1).exe
2014-09-12 23:51 - 2014-09-12 23:50 - 51895176 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\Downloads\postgresql-9.0.18-1-windows-x64.exe
2014-09-12 23:49 - 2014-09-12 23:37 - 00769600 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-09-12 23:49 - 2014-09-12 23:37 - 00141376 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-09-12 23:42 - 2014-01-13 12:25 - 00000000 ____D () C:\ProgramData\McAfee
2014-09-12 23:42 - 2014-01-13 12:25 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-09-12 23:42 - 2014-01-13 12:25 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-09-12 23:38 - 2014-09-12 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-09-12 23:37 - 2014-09-12 23:38 - 00001219 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2014-09-12 23:37 - 2014-09-12 23:37 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-09-12 23:37 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-09-12 23:33 - 2014-09-12 23:28 - 176561792 _____ () C:\Users\Dennis\Downloads\kis15.0.0.463de-de.exe
2014-09-12 23:31 - 2014-09-12 23:31 - 06501278 _____ () C:\Users\Dennis\Downloads\Nicht bestätigt 314320.crdownload
2014-09-12 23:14 - 2014-09-12 23:14 - 00247722 _____ () C:\Users\Dennis\Downloads\notes.o_S7ven_o.xml
2014-09-12 23:11 - 2014-09-12 23:10 - 56552816 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\postgresql_93.exe
2014-09-12 23:05 - 2014-09-12 23:04 - 56552816 _____ (PostgreSQL Global Development Group) C:\Users\Dennis\Downloads\postgresql-9.3.5-1-windows-x64.exe
2014-09-12 23:02 - 2014-09-12 21:08 - 00000000 ____D () C:\Users\Dennis\AppData\Local\ASUS
2014-09-12 22:52 - 2014-09-12 22:52 - 00000092 _____ () C:\Users\Dennis\Desktop\test.txt
2014-09-12 22:48 - 2014-09-12 22:48 - 00001291 _____ () C:\Users\Dennis\Desktop\Revo Uninstaller.lnk
2014-09-12 22:48 - 2014-09-12 22:48 - 00000068 _____ () C:\Users\Dennis\AppData\Roaming\WB.CFG
2014-09-12 22:48 - 2014-09-12 22:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-12 22:48 - 2014-09-12 22:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Dennis\Downloads\revosetup95.exe
2014-09-12 22:43 - 2014-09-12 22:43 - 02105856 _____ (Farbar) C:\Users\Dennis\Downloads\FRST64.exe
2014-09-12 22:42 - 2014-09-12 22:36 - 63697776 _____ () C:\Users\Dennis\Downloads\PT-Install-v4.11.11.exe
2014-09-12 22:35 - 2014-09-12 22:35 - 00002392 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICMIZER.lnk
2014-09-12 22:35 - 2014-09-12 22:35 - 00002362 _____ () C:\Users\Dennis\Desktop\ICMIZER.lnk
2014-09-12 22:18 - 2014-09-12 22:14 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Google
2014-09-12 22:14 - 2014-09-12 22:14 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Deployment
2014-09-12 22:14 - 2014-09-12 22:14 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Apps\2.0
2014-09-12 22:12 - 2014-09-12 22:12 - 00005044 _____ () C:\ProgramData\flwjycbm.bab
2014-09-12 22:12 - 2014-09-12 22:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerTracker 4
2014-09-12 22:08 - 2014-09-12 22:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-12 22:08 - 2014-09-12 22:08 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-09-12 22:08 - 2014-09-12 22:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-12 22:06 - 2014-04-10 20:32 - 00000000 ____D () C:\Windows\System32\Tasks\ASUS
2014-09-12 22:01 - 2014-09-12 22:01 - 00002023 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\PokerStars.eu.lnk
2014-09-12 22:01 - 2014-09-12 22:01 - 00001999 _____ () C:\Users\Dennis\Desktop\PokerStars.eu.lnk
2014-09-12 22:01 - 2014-09-12 22:01 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStars.EU
2014-09-12 21:57 - 2014-09-12 21:56 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\HoldemManager
2014-09-12 21:56 - 2014-09-12 21:56 - 00000000 ____D () C:\Program Files (x86)\PASG
2014-09-12 21:51 - 2014-09-12 21:51 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Mozilla
2014-09-12 21:50 - 2014-09-12 21:50 - 00000000 ____D () C:\ProgramData\Mozilla
2014-09-12 21:48 - 2014-09-12 21:48 - 00000000 ____D () C:\Program Files\TermTutor
2014-09-12 21:36 - 2014-09-12 21:36 - 00002071 _____ () C:\Users\Public\Desktop\AI Suite II.lnk
2014-09-12 21:36 - 2014-01-13 12:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2014-09-12 21:36 - 2014-01-13 11:57 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-09-12 21:35 - 2014-04-10 20:32 - 00000000 ____D () C:\ProgramData\ASUS
2014-09-12 21:35 - 2014-01-13 12:19 - 00000000 ____D () C:\Program Files (x86)\ASUS
2014-09-12 21:30 - 2014-09-12 21:30 - 00000000 ___HD () C:\kleaner.tmp
2014-09-12 21:29 - 2014-09-12 21:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-09-12 21:18 - 2014-09-12 21:18 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Macromedia
2014-09-12 21:12 - 2014-09-12 21:12 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-09-12 21:12 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-09-12 21:10 - 2014-09-12 21:10 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\Intel Corporation
2014-09-12 21:09 - 2014-09-12 21:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-09-12 21:09 - 2014-09-12 21:09 - 00000000 ____D () C:\Users\Dennis\AppData\Roaming\ATI
2014-09-12 21:09 - 2014-09-12 21:09 - 00000000 ____D () C:\Users\Dennis\AppData\Local\ATI
2014-09-12 21:09 - 2014-09-12 21:08 - 00000000 ____D () C:\Users\Dennis\AppData\Local\Packages
2014-09-12 21:08 - 2014-09-12 21:08 - 00001453 _____ () C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-12 21:08 - 2014-09-12 21:08 - 00000000 ____D () C:\Users\Dennis\Documents\My Bluetooth
2014-09-12 21:08 - 2014-09-12 21:08 - 00000000 ____D () C:\Users\Dennis\AppData\Local\VirtualStore
2014-09-12 21:07 - 2014-09-12 21:07 - 00000020 ___SH () C:\Users\Dennis\ntuser.ini
2014-09-02 22:06 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-02 22:06 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-29 13:01 - 2014-09-14 13:40 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Files to move or delete:
====================
C:\Users\Dennis\postgresql_93.exe
Some content of TEMP:
====================
C:\Users\Dennis\AppData\Local\Temp\optprosetup.exe
C:\Users\Dennis\AppData\Local\Temp\Quarantine.exe
C:\Users\Dennis\AppData\Local\Temp\shutdown1410556665.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-01-13 11:53
==================== End Of Log ============================ --- --- --- |