Vielen Dank schrauber:-) für die super Unterstützung und den ausführlichen Anleitungen für die Viren Bekämpfung.
Wenn die Scanner durch sind, poste ich die Ergebnisse.
Gruß,
MasterOG
ESET ONLINE SCANNER LOG.FILE:
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=a3376586f51fe74ca55a85da28afab5c
# engine=20172
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-09-16 04:24:51
# local_time=2014-09-16 06:24:51 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 17843 15225012 0 0
# scanned=290869
# found=0
# cleaned=0
# scan_time=2270
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=a3376586f51fe74ca55a85da28afab5c
# engine=20172
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-09-16 08:01:51
# local_time=2014-09-16 10:01:51 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 30863 15238032 0 0
# scanned=400134
# found=12
# cleaned=0
# scan_time=10381
sh=9AA5E59F80A95BDFC48FBB4DC9F4B7212749E67D ft=1 fh=2fe225811afcde6b vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="C:\Users\RedSpider\Downloads\ccsetup416.exe"
sh=1DE5D70A411EBBF4441FD569E7427CC28A4D6B13 ft=1 fh=b572351b8a033ea9 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="C:\Users\RedSpider\Downloads\ccsetup417.exe"
sh=13DDFA1862B74BDBBC06FC8766B36B9B73B25760 ft=1 fh=891ef6f01345cc13 vn="a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application" ac=I fn="D:\Software\FOOBAR2000 AIMP3 Asus essence stx treiber\SetupImgBurn_2.5.7.0.exe"
sh=13DDFA1862B74BDBBC06FC8766B36B9B73B25760 ft=1 fh=891ef6f01345cc13 vn="a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application" ac=I fn="D:\Software\FOOBAR2000 AIMP3 Asus essence stx treiber\FLAC APE WAVEPACK CUE Brennen BIT EXACT\SetupImgBurn_2.5.7.0.exe"
sh=25CF9B7BB46B581ED8DE03DDC56E1574087CACAA ft=1 fh=10c5a1651be6049d vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="D:\Software\Windows Formate Programme\ccsetup326.exe"
sh=180C8ED7C81E3AE7B0507B26C927EA93584B017C ft=1 fh=b0b83453fcc7b480 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="D:\Software\Windows Formate Programme\ccsetup327.exe"
sh=C133DB147FA578119F34B675D45B477E110761B2 ft=1 fh=9272027fde077ca7 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="D:\Software\Windows Formate Programme\ccsetup412.exe"
sh=D9730C5400B014A430A5F608BE4AAF631122D10B ft=1 fh=973e8761a43b9766 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application" ac=I fn="D:\ZEKs HDD\video_deluxe_mx_201mb_d.exe"
sh=13DDFA1862B74BDBBC06FC8766B36B9B73B25760 ft=1 fh=891ef6f01345cc13 vn="a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application" ac=I fn="F:\New System Format Programme\Foobar Multimedia\FLAC APE WAVEPACK CUE Brennen BIT EXACT\SetupImgBurn_2.5.7.0.exe"
sh=5CA96A0C243390C378DEE1A629684EA261E2CFC4 ft=1 fh=a717dcd23690f0a7 vn="Win32/OpenCandy potentially unsafe application" ac=I fn="F:\WhatCD\What.CD Toolbox 6 for Windows\Burning\SetupImgBurn_2.5.8.0.exe"
sh=8FB67E7A05DABAEE976772182EFD265C708D0D0E ft=1 fh=27c2e5c2e2db566f vn="a variant of Win32/HackTool.Patcher.AD potentially unsafe application" ac=I fn="F:\WhatCD\What.CD Toolbox 6 for Windows\Content Analysis\Adobe Audition CC v6.0.732\adobe.photoshop.cc-patch-painter.exe"
sh=6CC66428B9C1E8C48055E342CF83906FB6F39E65 ft=1 fh=5f00dd68e7de5c54 vn="Win32/OpenCandy potentially unsafe application" ac=I fn="F:\WhatCD\What.CD Toolbox 6 for Windows\File Management\FreeFileSync_5.20_Windows_Setup.exe"
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internet# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=a3376586f51fe74ca55a85da28afab5c
# engine=20208
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-09-18 10:08:10
# local_time=2014-09-18 12:08:10 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 76209 15418411 0 0
# scanned=405044
# found=12
# cleaned=12
# scan_time=13822
sh=9AA5E59F80A95BDFC48FBB4DC9F4B7212749E67D ft=1 fh=2fe225811afcde6b vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\RedSpider\Downloads\ccsetup416.exe"
sh=1DE5D70A411EBBF4441FD569E7427CC28A4D6B13 ft=1 fh=b572351b8a033ea9 vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\RedSpider\Downloads\ccsetup417.exe"
sh=13DDFA1862B74BDBBC06FC8766B36B9B73B25760 ft=1 fh=891ef6f01345cc13 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="D:\Software\FOOBAR2000 AIMP3 Asus essence stx treiber\SetupImgBurn_2.5.7.0.exe"
sh=13DDFA1862B74BDBBC06FC8766B36B9B73B25760 ft=1 fh=891ef6f01345cc13 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="D:\Software\FOOBAR2000 AIMP3 Asus essence stx treiber\FLAC APE WAVEPACK CUE Brennen BIT EXACT\SetupImgBurn_2.5.7.0.exe"
sh=25CF9B7BB46B581ED8DE03DDC56E1574087CACAA ft=1 fh=10c5a1651be6049d vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="D:\Software\Windows Formate Programme\ccsetup326.exe"
sh=180C8ED7C81E3AE7B0507B26C927EA93584B017C ft=1 fh=b0b83453fcc7b480 vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="D:\Software\Windows Formate Programme\ccsetup327.exe"
sh=C133DB147FA578119F34B675D45B477E110761B2 ft=1 fh=9272027fde077ca7 vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="D:\Software\Windows Formate Programme\ccsetup412.exe"
sh=D9730C5400B014A430A5F608BE4AAF631122D10B ft=1 fh=973e8761a43b9766 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="D:\ZEKs HDD\video_deluxe_mx_201mb_d.exe"
sh=13DDFA1862B74BDBBC06FC8766B36B9B73B25760 ft=1 fh=891ef6f01345cc13 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="F:\New System Format Programme\Foobar Multimedia\FLAC APE WAVEPACK CUE Brennen BIT EXACT\SetupImgBurn_2.5.7.0.exe"
sh=5CA96A0C243390C378DEE1A629684EA261E2CFC4 ft=1 fh=a717dcd23690f0a7 vn="Win32/OpenCandy potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="F:\WhatCD\What.CD Toolbox 6 for Windows\Burning\SetupImgBurn_2.5.8.0.exe"
sh=8FB67E7A05DABAEE976772182EFD265C708D0D0E ft=1 fh=27c2e5c2e2db566f vn="Variante von Win32/HackTool.Patcher.AD potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="F:\WhatCD\What.CD Toolbox 6 for Windows\Content Analysis\Adobe Audition CC v6.0.732\adobe.photoshop.cc-patch-painter.exe"
sh=6CC66428B9C1E8C48055E342CF83906FB6F39E65 ft=1 fh=5f00dd68e7de5c54 vn="Win32/OpenCandy potenziell unsichere Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="F:\WhatCD\What.CD Toolbox 6 for Windows\File Management\FreeFileSync_5.20_Windows_Setup.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=a3376586f51fe74ca55a85da28afab5c
# engine=20217
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-09-18 08:22:42
# local_time=2014-09-18 10:22:42 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 34749 15455283 0 0
# scanned=403976
# found=3
# cleaned=0
# scan_time=14123
sh=5CA96A0C243390C378DEE1A629684EA261E2CFC4 ft=1 fh=a717dcd23690f0a7 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="F:\WhatCD\What.CD Toolbox 6 for Windows\Burning\SetupImgBurn_2.5.8.0.exe"
sh=8FB67E7A05DABAEE976772182EFD265C708D0D0E ft=1 fh=27c2e5c2e2db566f vn="Variante von Win32/HackTool.Patcher.AD potenziell unsichere Anwendung" ac=I fn="F:\WhatCD\What.CD Toolbox 6 for Windows\Content Analysis\Adobe Audition CC v6.0.732\adobe.photoshop.cc-patch-painter.exe"
sh=6CC66428B9C1E8C48055E342CF83906FB6F39E65 ft=1 fh=5f00dd68e7de5c54 vn="Win32/OpenCandy potenziell unsichere Anwendung" ac=I fn="F:\WhatCD\What.CD Toolbox 6 for Windows\File Management\FreeFileSync_5.20_Windows_Setup.exe"
SecurityCheck:
Results of screen317's Security Check version 0.99.87
x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Defender
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Java 8 Update 20
Java version out of Date!
Adobe Flash Player 15.0.0.152
Adobe Reader XI
Google Chrome 37.0.2062.120
````````Process Check: objlist.exe by Laurent````````
Windows Defender MSMpEng.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
FRST.txt X64 :
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by RedSpider (administrator) on REDSPIDER-PC on 18-09-2014 23:10:26
Running from C:\Users\RedSpider\Desktop\AntiVirus
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
() C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe
() C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Malwarebytes Corporation) C:\Users\Bootsektor\Downloads\mbam-setup\mbamscheduler.exe
(Malwarebytes Corporation) C:\Users\Bootsektor\Downloads\mbam-setup\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Users\Bootsektor\Downloads\mbam-setup\mbam.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe
(REALiX) C:\Program Files\HWiNFO64\HWiNFO64.EXE
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
() C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Unified Intents AB) C:\Program Files (x86)\Unified Remote\RemoteServer.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Piotr Pawlowski) C:\Program Files (x86)\foobar2000\foobar2000.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
() C:\Users\RedSpider\AppData\Roaming\foobar2000\user-components\foo_out_asio\ASIOhost64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-07-31] (Logitech, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1273448 2012-04-03] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\WINDOWS\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-976349099-1794730339-1012751642-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-976349099-1794730339-1012751642-1000\...\Run: [Unified Remote v2] => C:\Program Files (x86)\Unified Remote\RemoteServer.exe [333008 2014-06-03] (Unified Intents AB)
HKU\S-1-5-21-976349099-1794730339-1012751642-1000\...\Run: [GoogleChromeAutoLaunch_AA0546F6283AA107B5D07868E0E0FE05] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-09-04] (Google Inc.)
HKU\S-1-5-21-976349099-1794730339-1012751642-1000\...\MountPoints2: {4cd61f86-c877-11e3-8186-bcaec574c7fa} - "K:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-976349099-1794730339-1012751642-1000\...\MountPoints2: {75a9a0da-32ee-11e4-8206-bcaec574c7fa} - "K:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-976349099-1794730339-1012751642-1000\...\MountPoints2: {b952332c-e244-11e3-81a2-bcaec574c7fa} - "L:\HTC_Sync_Manager_PC.exe"
Startup: C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe (Samsung Electronics.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xBA2693E4A4FCCD01
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKCU - DefaultScope {9A01AA53-FAB4-4F9F-BB65-6D7F304B93BF} URL = https://de.search.yahoo.com/search?fr=mcafee&type=B010DE0D20140409&p={SearchTerms}
SearchScopes: HKCU - {9A01AA53-FAB4-4F9F-BB65-6D7F304B93BF} URL = https://de.search.yahoo.com/search?fr=mcafee&type=B010DE0D20140409&p={SearchTerms}
SearchScopes: HKCU - {BAB65997-01F0-41B0-B41D-937F60235DED} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=293224&p={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-04-22]
Chrome:
=======
CHR HomePage: Default -> hxxp://google.de/
CHR StartupUrls: Default -> "hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP&dt=071313", "hxxp://www.spiegel.de/", "hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5HtgW9e_DuX3ywRMXtYsMh4Qt7MrNn4G6p6l0_vvG0yzKBeLtzAX1tNx9sAd-Tzzf-AM7FrjsJ8AmkLsw0uaJ8Oz6JuSCrOF71LzuMDq6mejGFfUOUWpWy025XXteMtSPF6b8JZZwuwC2umSlDwRug,,"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (chessmail ~ Schach) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkgfhmdidjkcoflclddnmgacgeaahkk [2014-04-02]
CHR Extension: (HD for YouTube™) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\akjbfncbadcmnkopckegnmjgihagponf [2014-04-04]
CHR Extension: (Google Drive) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-02]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-12]
CHR Extension: (YouTube) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-02]
CHR Extension: (Webseiten-Screenshot - Webpage Screenshot) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki [2014-04-02]
CHR Extension: (The Thing 2011. TheThingMovie.net) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkcjahfmmfcnecceamibfaapiadafiim [2014-09-18]
CHR Extension: (AdBlock) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-02]
CHR Extension: (Stealthy) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieaebnkibonmpbhdaanjkmedikadnoje [2014-04-02]
CHR Extension: (Google Wallet) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-15]
CHR Extension: (Google Mail) - C:\Users\RedSpider\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-02]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe [1632256 2013-11-01] (ASUSTeK Computer Inc.) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160768 2011-05-27] (Intel Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
R2 MBAMScheduler; C:\Users\Bootsektor\Downloads\mbam-setup\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Users\Bootsektor\Downloads\mbam-setup\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 anvsnddrv; C:\Windows\system32\drivers\anvsnddrv.sys [33872 2011-11-28] (AnvSoft Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
S3 ASUSstpt; C:\Windows\System32\drivers\ASUSstpt.sys [25928 2012-08-20] (MCCI Corporation)
S3 ASUSumsc; C:\Windows\System32\drivers\ASUSumsc.sys [150344 2012-08-20] (MCCI Corporation)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2014-08-30] (Emsisoft GmbH)
S3 cmudaxp; C:\Windows\system32\drivers\cmudaxp.sys [2735616 2013-12-11] (C-Media Inc) [File not signed]
R3 DE_USBAUDIO; C:\Windows\system32\drivers\de_usbaudio.sys [144896 2013-05-20] (D&M Holdings Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-02-02] (DT Soft Ltd)
R3 e1cexpress; C:\Windows\system32\DRIVERS\e1c64x64.sys [468240 2013-08-21] (Intel Corporation)
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [27552 2014-09-13] (REALiX(tm))
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R1 pfmfs_7DB; C:\Windows\System32\Drivers\pfmfs_7DB.sys [258296 2013-02-19] (Pismo Technic Inc.)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.)
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13480 2014-06-10] ()
S3 SaiK0CFA; C:\Windows\system32\DRIVERS\SaiK0CFA.sys [180544 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\drivers\SaiMini.sys [24680 2012-10-15] (Saitek)
R3 SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [52200 2012-10-15] (Saitek)
S3 SaiU0CFA; C:\Windows\System32\drivers\SaiU0CFA.sys [47168 2012-09-20] (Saitek)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(???? | ????? ???? ?????.))
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
S3 xb1usb; C:\Windows\System32\drivers\xb1usb.sys [34016 2014-05-27] (Microsoft Corporation)
S1 ArcCtrl; system32\drivers\ArcCtrl.sys [X]
U3 idsvc; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-18 23:08 - 2014-09-18 23:08 - 00854417 _____ () C:\Users\RedSpider\Desktop\SecurityCheck.exe
2014-09-18 21:48 - 2014-09-18 21:48 - 00002308 _____ () C:\Users\RedSpider\AppData\Local\recently-used.xbel
2014-09-18 08:54 - 2014-09-18 22:59 - 00001142 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-18 08:54 - 2014-09-18 16:00 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-18 08:54 - 2014-09-18 15:58 - 00001138 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-18 08:54 - 2014-09-18 08:54 - 00004114 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-18 08:54 - 2014-09-18 08:54 - 00003878 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-18 08:54 - 2014-09-18 08:54 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\Deployment
2014-09-18 08:54 - 2014-09-18 08:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-18 08:22 - 2014-09-18 23:10 - 00000000 ____D () C:\Users\RedSpider\Desktop\AntiVirus
2014-09-18 07:40 - 2014-09-18 07:40 - 02347384 _____ (ESET) C:\Users\RedSpider\Desktop\esetsmartinstaller_deu.exe
2014-09-18 07:32 - 2014-09-18 07:32 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\VS Revo Group
2014-09-18 07:32 - 2014-09-18 07:32 - 00000000 ____D () C:\ProgramData\VS Revo Group
2014-09-18 07:32 - 2014-09-18 07:32 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-09-18 07:30 - 2014-09-18 07:30 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-17 22:04 - 2014-09-18 21:40 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-17 22:04 - 2014-09-17 22:04 - 00001206 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-17 22:04 - 2014-09-17 22:04 - 00000000 ____D () C:\Users\Bootsektor\Downloads\mbam-setup
2014-09-17 22:04 - 2014-09-17 22:04 - 00000000 ____D () C:\Users\Bootsektor
2014-09-17 22:04 - 2014-09-17 22:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-17 22:04 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-09-17 22:04 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-09-17 22:04 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-09-16 08:09 - 2014-09-16 08:09 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
2014-09-16 08:09 - 2014-09-16 08:09 - 00000000 ____D () C:\Program Files (x86)\Haali
2014-09-16 06:06 - 2014-09-18 23:10 - 00000000 ____D () C:\FRST
2014-09-15 06:50 - 2014-09-15 06:50 - 00000000 ____D () C:\Program Files\McAfee
2014-09-15 05:01 - 2014-09-15 05:01 - 00001778 _____ () C:\sc-cleaner.txt
2014-09-15 05:00 - 2014-09-15 05:00 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-09-14 19:02 - 2014-09-14 19:05 - 00073728 ___SH () C:\Users\RedSpider\Documents\Thumbs.db
2014-09-14 00:45 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-09-14 00:44 - 2014-09-18 08:11 - 00000000 ____D () C:\AdwCleaner
2014-09-13 22:33 - 2014-09-16 10:20 - 00000000 ____D () C:\Program Files (x86)\RivaTuner Statistics Server
2014-09-13 22:33 - 2014-09-13 22:33 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2014-09-13 22:00 - 2014-09-13 22:00 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\system32\Drivers\HWiNFO64A.SYS
2014-09-13 22:00 - 2014-09-13 22:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64
2014-09-13 22:00 - 2014-09-13 22:00 - 00000000 ____D () C:\Program Files\HWiNFO64
2014-09-13 21:57 - 2014-09-13 22:30 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\Micro-Star_Int'l_Co.,_Ltd
2014-09-11 16:22 - 2014-09-12 02:04 - 00000000 ____D () C:\Program Files\Microsoft Xbox One Controller for Windows
2014-09-11 03:46 - 2014-09-11 03:46 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\MKKE
2014-09-11 03:24 - 2014-09-11 03:24 - 00000222 _____ () C:\Users\RedSpider\Desktop\Mortal Kombat Komplete Edition.url
2014-09-11 03:00 - 2014-09-11 03:01 - 00458752 _____ () C:\WINDOWS\system32\Ikeext.etl
2014-09-10 23:50 - 2014-08-29 03:58 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2014-09-10 23:50 - 2014-08-29 03:32 - 02779136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-09-10 23:50 - 2014-08-29 02:59 - 03117568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-09-10 23:50 - 2014-08-29 01:56 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-09-10 23:50 - 2014-08-29 01:47 - 02321920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-09-10 23:50 - 2014-08-26 00:27 - 04148736 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-09-10 23:50 - 2014-08-23 09:48 - 02374784 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-09-10 23:50 - 2014-08-23 09:13 - 02084520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2014-09-10 23:50 - 2014-08-23 08:10 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-09-10 23:50 - 2014-08-23 07:32 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-09-10 23:50 - 2014-08-23 06:44 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-09-10 23:50 - 2014-08-23 06:34 - 13423104 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-09-10 23:50 - 2014-08-23 06:33 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-09-10 23:50 - 2014-08-23 06:31 - 01038336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-09-10 23:50 - 2014-08-23 06:20 - 11818496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-09-10 23:50 - 2014-08-16 06:08 - 21195616 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-09-10 23:50 - 2014-08-16 06:08 - 01507648 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-09-10 23:50 - 2014-08-16 06:01 - 01710184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-09-10 23:50 - 2014-08-16 05:58 - 01112512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-09-10 23:50 - 2014-08-16 05:57 - 02498880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-09-10 23:50 - 2014-08-16 05:57 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-09-10 23:50 - 2014-08-16 05:16 - 18722600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-09-10 23:50 - 2014-08-16 05:16 - 01205976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-09-10 23:50 - 2014-08-16 05:03 - 01467384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-09-10 23:50 - 2014-08-16 03:31 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-09-10 23:50 - 2014-08-16 03:04 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2014-09-10 23:50 - 2014-08-16 02:58 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-09-10 23:50 - 2014-08-16 02:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
2014-09-10 23:50 - 2014-08-16 02:46 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
2014-09-10 23:50 - 2014-08-16 02:45 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2014-09-10 23:50 - 2014-08-16 02:43 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2014-09-10 23:50 - 2014-08-16 02:43 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
2014-09-10 23:50 - 2014-08-16 02:31 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2014-09-10 23:50 - 2014-08-16 02:31 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2014-09-10 23:50 - 2014-08-16 02:29 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-10 23:50 - 2014-08-16 02:23 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-09-10 23:50 - 2014-08-16 02:22 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-09-10 23:50 - 2014-08-16 02:22 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-09-10 23:50 - 2014-08-16 02:20 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-09-10 23:50 - 2014-08-16 02:19 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-09-10 23:50 - 2014-08-16 02:18 - 04758528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-09-10 23:50 - 2014-08-16 02:17 - 08757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-09-10 23:50 - 2014-08-16 02:14 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-09-10 23:50 - 2014-08-16 02:13 - 06649344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-09-10 23:50 - 2014-08-16 02:13 - 05902848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-09-10 23:50 - 2014-08-16 02:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-09-10 23:50 - 2014-08-16 02:11 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-09-10 23:50 - 2014-08-16 02:11 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-09-10 23:50 - 2014-08-16 02:10 - 01120768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-09-10 23:50 - 2014-08-16 02:08 - 05777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-09-10 23:50 - 2014-08-16 02:07 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-09-10 23:50 - 2014-08-01 01:22 - 00388729 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-09-10 00:19 - 2014-08-16 04:40 - 23591424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-09-10 00:19 - 2014-08-16 04:04 - 17455104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-09-10 00:19 - 2014-08-16 04:00 - 05833728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-09-10 00:19 - 2014-08-16 04:00 - 02793984 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-09-10 00:19 - 2014-08-16 03:56 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-09-10 00:19 - 2014-08-16 03:54 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-09-10 00:19 - 2014-08-16 03:45 - 04232704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-09-10 00:19 - 2014-08-16 03:43 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-09-10 00:19 - 2014-08-16 03:32 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-09-10 00:19 - 2014-08-16 03:25 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-10 00:19 - 2014-08-16 03:22 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-09-10 00:19 - 2014-08-16 03:20 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-09-10 00:19 - 2014-08-16 03:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-09-10 00:19 - 2014-08-16 03:18 - 02185728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-09-10 00:19 - 2014-08-16 03:18 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-09-10 00:19 - 2014-08-16 03:11 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-09-10 00:19 - 2014-08-16 03:06 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-09-10 00:19 - 2014-08-16 03:05 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-09-10 00:19 - 2014-08-16 03:05 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-09-10 00:19 - 2014-08-16 03:03 - 02104832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-09-10 00:19 - 2014-08-16 03:03 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-09-10 00:19 - 2014-08-16 02:58 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-10 00:19 - 2014-08-16 02:56 - 02310656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-09-10 00:19 - 2014-08-16 02:53 - 13588480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-09-10 00:19 - 2014-08-16 02:53 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-09-10 00:19 - 2014-08-16 02:53 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-09-10 00:19 - 2014-08-16 02:51 - 11769856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-09-10 00:19 - 2014-08-16 02:45 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-09-10 00:19 - 2014-08-16 02:44 - 02014208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-09-10 00:19 - 2014-08-16 02:44 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-09-10 00:19 - 2014-08-16 02:34 - 01447424 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-09-10 00:19 - 2014-08-16 02:20 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-09-10 00:19 - 2014-08-16 02:18 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-09-10 00:19 - 2014-08-16 02:14 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-09-10 00:19 - 2014-08-16 02:12 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-09-09 23:49 - 2014-08-02 02:18 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2014-09-09 23:49 - 2014-07-24 05:20 - 00875688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2014-09-09 23:49 - 2014-07-24 05:20 - 00869544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-09 17:54 - 2014-09-09 17:54 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unified Remote
2014-09-09 17:54 - 2014-09-09 17:54 - 00000000 ____D () C:\Program Files (x86)\Unified Remote
2014-09-09 01:22 - 2014-09-09 01:22 - 00000000 ____D () C:\Users\RedSpider\Documents\WB Games
2014-09-09 01:22 - 2014-09-09 01:22 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-09-08 23:24 - 2014-09-08 23:24 - 00000975 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-09-07 21:06 - 2014-09-07 21:06 - 00001098 _____ () C:\Users\RedSpider\Desktop\MSI Afterburner.lnk
2014-09-07 19:44 - 2014-09-07 19:44 - 00298280 _____ () C:\WINDOWS\Minidump\090714-10765-01.dmp
2014-09-07 19:35 - 2014-09-07 19:35 - 00298096 _____ () C:\WINDOWS\Minidump\090714-11375-01.dmp
2014-09-07 19:32 - 2014-09-07 19:44 - 727950455 _____ () C:\WINDOWS\MEMORY.DMP
2014-09-07 19:32 - 2014-09-07 19:44 - 00000000 ____D () C:\WINDOWS\Minidump
2014-09-07 19:32 - 2014-09-07 19:32 - 00298264 _____ () C:\WINDOWS\Minidump\090714-11562-01.dmp
2014-09-07 19:30 - 2014-09-07 19:42 - 00000045 _____ () C:\WINDOWS\SysWOW64\initdebug.nfo
2014-09-07 19:30 - 2014-09-07 19:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
2014-09-05 20:52 - 2014-09-07 14:19 - 00000000 ____D () C:\Program Files\Recuva
2014-09-05 20:52 - 2014-09-05 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2014-09-03 00:13 - 2014-08-15 02:36 - 00146752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2014-09-03 00:13 - 2014-07-30 03:56 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2014-09-03 00:13 - 2014-07-29 07:22 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpmon.dll
2014-08-30 15:29 - 2014-08-30 15:29 - 00000755 _____ () C:\Users\RedSpider\Desktop\Start Emsisoft Emergency Kit.lnk
2014-08-30 15:04 - 2014-08-30 15:04 - 00003394 _____ () C:\WINDOWS\System32\Tasks\RunAsStdUser Task for VeohWebPlayer
2014-08-30 15:04 - 2014-08-30 15:04 - 00000000 ____D () C:\Program Files (x86)\Veoh Networks
2014-08-29 08:06 - 2014-08-29 08:06 - 00000692 _____ () C:\Users\RedSpider\Desktop\rutracker - Verknüpfung.lnk
2014-08-27 02:29 - 2014-08-27 02:32 - 00000000 ____D () C:\Users\RedSpider\Santana Samba Pa Ti
2014-08-27 02:10 - 2014-08-27 02:26 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\AccurateRip
2014-08-27 02:10 - 2014-08-27 02:10 - 00001082 _____ () C:\Users\Public\Desktop\Exact Audio Copy.lnk
2014-08-27 02:10 - 2014-08-27 02:10 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\EAC
2014-08-27 02:10 - 2014-08-27 02:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
2014-08-27 02:10 - 2014-08-27 02:10 - 00000000 ____D () C:\Program Files (x86)\Exact Audio Copy
2014-08-26 01:53 - 2014-08-26 01:53 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\EurekaLab s.a.s
2014-08-25 22:17 - 2014-09-14 18:43 - 00000000 ___HD () C:\ProgramData\CanonIJMIG
2014-08-25 22:16 - 2014-08-25 22:16 - 00002089 _____ () C:\Users\Public\Desktop\Canon My Image Garden.lnk
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\WorldofTanks
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\StormFall
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\GGEmpire441
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\WorldofTanks
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\StormFall
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\GGEmpire
2014-08-25 10:03 - 2014-09-16 08:57 - 00000000 ____D () C:\Users\RedSpider\Desktop\Pix MM
2014-08-20 05:13 - 2014-08-29 05:29 - 00001086 _____ () C:\Users\RedSpider\Desktop\Unreleased and RAR VINYLs - Verknüpfung.lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-18 23:10 - 2014-09-18 08:22 - 00000000 ____D () C:\Users\RedSpider\Desktop\AntiVirus
2014-09-18 23:10 - 2014-09-16 06:06 - 00000000 ____D () C:\FRST
2014-09-18 23:08 - 2014-09-18 23:08 - 00854417 _____ () C:\Users\RedSpider\Desktop\SecurityCheck.exe
2014-09-18 23:08 - 2013-02-01 02:44 - 09700352 ___SH () C:\Users\RedSpider\Desktop\Thumbs.db
2014-09-18 23:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-09-18 22:59 - 2014-09-18 08:54 - 00001142 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-18 22:44 - 2013-01-27 17:36 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-09-18 21:48 - 2014-09-18 21:48 - 00002308 _____ () C:\Users\RedSpider\AppData\Local\recently-used.xbel
2014-09-18 21:40 - 2014-09-17 22:04 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-18 19:15 - 2013-04-22 18:50 - 00003962 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{81665560-7A12-4689-97A0-7C5ADF10D3F3}
2014-09-18 18:29 - 2013-01-27 20:03 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\foobar2000
2014-09-18 16:18 - 2013-01-27 18:19 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-976349099-1794730339-1012751642-1000
2014-09-18 16:06 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-09-18 16:06 - 2013-09-30 05:56 - 00765378 _____ () C:\WINDOWS\system32\perfh007.dat
2014-09-18 16:06 - 2013-09-30 05:56 - 00159696 _____ () C:\WINDOWS\system32\perfc007.dat
2014-09-18 16:00 - 2014-09-18 08:54 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-18 15:58 - 2014-09-18 08:54 - 00001138 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-18 15:58 - 2013-10-17 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-18 15:58 - 2013-09-29 21:04 - 00537390 _____ () C:\WINDOWS\PFRO.log
2014-09-18 15:58 - 2013-08-22 16:46 - 00707317 _____ () C:\WINDOWS\setupact.log
2014-09-18 15:58 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-09-18 15:58 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-09-18 15:58 - 2013-07-03 04:08 - 00000375 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.ics
2014-09-18 15:57 - 2014-04-08 00:17 - 00003038 _____ () C:\WINDOWS\System32\Tasks\MSIAfterburner
2014-09-18 14:20 - 2013-10-17 14:52 - 01613888 _____ () C:\WINDOWS\WindowsUpdate.log
2014-09-18 08:54 - 2014-09-18 08:54 - 00004114 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-09-18 08:54 - 2014-09-18 08:54 - 00003878 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-09-18 08:54 - 2014-09-18 08:54 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\Deployment
2014-09-18 08:54 - 2014-09-18 08:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-18 08:54 - 2013-01-27 18:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-18 08:38 - 2014-06-03 19:54 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\vlc
2014-09-18 08:11 - 2014-09-14 00:44 - 00000000 ____D () C:\AdwCleaner
2014-09-18 07:40 - 2014-09-18 07:40 - 02347384 _____ (ESET) C:\Users\RedSpider\Desktop\esetsmartinstaller_deu.exe
2014-09-18 07:32 - 2014-09-18 07:32 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\VS Revo Group
2014-09-18 07:32 - 2014-09-18 07:32 - 00000000 ____D () C:\ProgramData\VS Revo Group
2014-09-18 07:32 - 2014-09-18 07:32 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-09-18 07:30 - 2014-09-18 07:30 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-18 07:03 - 2013-01-27 16:41 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\VirtualStore
2014-09-18 06:34 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-09-17 22:04 - 2014-09-17 22:04 - 00001206 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-17 22:04 - 2014-09-17 22:04 - 00000000 ____D () C:\Users\Bootsektor\Downloads\mbam-setup
2014-09-17 22:04 - 2014-09-17 22:04 - 00000000 ____D () C:\Users\Bootsektor
2014-09-17 22:04 - 2014-09-17 22:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-16 10:20 - 2014-09-13 22:33 - 00000000 ____D () C:\Program Files (x86)\RivaTuner Statistics Server
2014-09-16 10:20 - 2013-01-28 22:45 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2014-09-16 08:57 - 2014-08-25 10:03 - 00000000 ____D () C:\Users\RedSpider\Desktop\Pix MM
2014-09-16 08:09 - 2014-09-16 08:09 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
2014-09-16 08:09 - 2014-09-16 08:09 - 00000000 ____D () C:\Program Files (x86)\Haali
2014-09-16 08:07 - 2014-03-05 17:00 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-09-16 07:43 - 2013-07-19 18:11 - 00000000 _____ () C:\WINDOWS\Path.idx
2014-09-16 07:33 - 2013-03-06 04:37 - 00876960 _____ () C:\WINDOWS\PE_Rom.dll
2014-09-16 07:13 - 2013-03-05 06:14 - 00173568 _____ () C:\Users\RedSpider\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-16 07:11 - 2014-05-27 22:30 - 00000000 ____D () C:\EEK
2014-09-16 06:37 - 2013-11-10 03:12 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\deluge
2014-09-16 05:06 - 2013-03-25 01:01 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Skype
2014-09-15 07:15 - 2014-04-09 13:12 - 00000000 ____D () C:\ProgramData\McAfee
2014-09-15 06:54 - 2013-01-28 22:52 - 00000000 ____D () C:\Program Files\SmartTechnology
2014-09-15 06:53 - 2014-03-05 17:10 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-09-15 06:50 - 2014-09-15 06:50 - 00000000 ____D () C:\Program Files\McAfee
2014-09-15 06:49 - 2013-01-27 20:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft
2014-09-15 06:49 - 2013-01-27 20:43 - 00000000 ____D () C:\Program Files (x86)\AnvSoft
2014-09-15 05:01 - 2014-09-15 05:01 - 00001778 _____ () C:\sc-cleaner.txt
2014-09-15 05:00 - 2014-09-15 05:00 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-09-14 19:16 - 2013-02-14 06:18 - 03102720 ___SH () C:\Users\RedSpider\Downloads\Thumbs.db
2014-09-14 19:05 - 2014-09-14 19:02 - 00073728 ___SH () C:\Users\RedSpider\Documents\Thumbs.db
2014-09-14 18:43 - 2014-08-25 22:17 - 00000000 ___HD () C:\ProgramData\CanonIJMIG
2014-09-14 07:29 - 2013-10-17 14:54 - 00000000 ____D () C:\Users\RedSpider
2014-09-13 22:36 - 2013-11-01 13:51 - 00000000 ____D () C:\ProgramData\Origin
2014-09-13 22:36 - 2013-11-01 13:51 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-09-13 22:33 - 2014-09-13 22:33 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2014-09-13 22:33 - 2013-11-30 09:28 - 00000000 ____D () C:\WINDOWS\SysWOW64\directx
2014-09-13 22:30 - 2014-09-13 21:57 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\Micro-Star_Int'l_Co.,_Ltd
2014-09-13 22:00 - 2014-09-13 22:00 - 00027552 _____ (REALiX(tm)) C:\WINDOWS\system32\Drivers\HWiNFO64A.SYS
2014-09-13 22:00 - 2014-09-13 22:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64
2014-09-13 22:00 - 2014-09-13 22:00 - 00000000 ____D () C:\Program Files\HWiNFO64
2014-09-13 07:31 - 2013-02-19 01:28 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2
2014-09-12 02:04 - 2014-09-11 16:22 - 00000000 ____D () C:\Program Files\Microsoft Xbox One Controller for Windows
2014-09-11 05:30 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-09-11 03:46 - 2014-09-11 03:46 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\MKKE
2014-09-11 03:24 - 2014-09-11 03:24 - 00000222 _____ () C:\Users\RedSpider\Desktop\Mortal Kombat Komplete Edition.url
2014-09-11 03:01 - 2014-09-11 03:00 - 00458752 _____ () C:\WINDOWS\system32\Ikeext.etl
2014-09-11 03:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\tracing
2014-09-10 23:54 - 2013-08-22 16:44 - 00409280 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-09-10 23:53 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-09-10 23:53 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-09-10 23:50 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-09-10 23:46 - 2013-03-25 01:01 - 00000000 ____D () C:\ProgramData\Skype
2014-09-10 23:44 - 2013-01-27 17:36 - 00003796 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-09-10 23:38 - 2013-02-07 15:49 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\Adobe
2014-09-10 05:30 - 2013-12-08 05:52 - 00001911 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-09-10 05:30 - 2013-12-08 05:52 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-09-10 00:20 - 2013-02-09 17:38 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-10 00:19 - 2014-06-11 16:11 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-09-10 00:19 - 2014-06-11 16:11 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-09-10 00:19 - 2014-06-11 16:11 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-09-10 00:19 - 2014-06-11 16:11 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-09-10 00:19 - 2014-06-11 16:11 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-10 00:19 - 2014-05-03 20:57 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-09-10 00:19 - 2014-05-03 20:57 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-09-10 00:19 - 2013-07-10 14:36 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-09-10 00:17 - 2013-01-27 17:29 - 101694776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-09-09 17:54 - 2014-09-09 17:54 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unified Remote
2014-09-09 17:54 - 2014-09-09 17:54 - 00000000 ____D () C:\Program Files (x86)\Unified Remote
2014-09-09 13:44 - 2013-02-04 01:41 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\Windows Live
2014-09-09 01:22 - 2014-09-09 01:22 - 00000000 ____D () C:\Users\RedSpider\Documents\WB Games
2014-09-09 01:22 - 2014-09-09 01:22 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-09-08 23:43 - 2014-01-23 23:36 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\dvdcss
2014-09-08 23:24 - 2014-09-08 23:24 - 00000975 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-09-07 21:06 - 2014-09-07 21:06 - 00001098 _____ () C:\Users\RedSpider\Desktop\MSI Afterburner.lnk
2014-09-07 19:44 - 2014-09-07 19:44 - 00298280 _____ () C:\WINDOWS\Minidump\090714-10765-01.dmp
2014-09-07 19:44 - 2014-09-07 19:32 - 727950455 _____ () C:\WINDOWS\MEMORY.DMP
2014-09-07 19:44 - 2014-09-07 19:32 - 00000000 ____D () C:\WINDOWS\Minidump
2014-09-07 19:42 - 2014-09-07 19:30 - 00000045 _____ () C:\WINDOWS\SysWOW64\initdebug.nfo
2014-09-07 19:35 - 2014-09-07 19:35 - 00298096 _____ () C:\WINDOWS\Minidump\090714-11375-01.dmp
2014-09-07 19:32 - 2014-09-07 19:32 - 00298264 _____ () C:\WINDOWS\Minidump\090714-11562-01.dmp
2014-09-07 19:30 - 2014-09-07 19:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
2014-09-07 14:19 - 2014-09-05 20:52 - 00000000 ____D () C:\Program Files\Recuva
2014-09-05 20:52 - 2014-09-05 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2014-09-02 22:06 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-09-02 22:06 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-31 18:37 - 2014-07-21 02:55 - 00000000 ____D () C:\Users\RedSpider\Desktop\BR
2014-08-30 15:29 - 2014-08-30 15:29 - 00000755 _____ () C:\Users\RedSpider\Desktop\Start Emsisoft Emergency Kit.lnk
2014-08-30 15:21 - 2009-07-14 04:34 - 00000466 _____ () C:\WINDOWS\win.ini
2014-08-30 15:04 - 2014-08-30 15:04 - 00003394 _____ () C:\WINDOWS\System32\Tasks\RunAsStdUser Task for VeohWebPlayer
2014-08-30 15:04 - 2014-08-30 15:04 - 00000000 ____D () C:\Program Files (x86)\Veoh Networks
2014-08-29 08:06 - 2014-08-29 08:06 - 00000692 _____ () C:\Users\RedSpider\Desktop\rutracker - Verknüpfung.lnk
2014-08-29 05:29 - 2014-08-20 05:13 - 00001086 _____ () C:\Users\RedSpider\Desktop\Unreleased and RAR VINYLs - Verknüpfung.lnk
2014-08-29 03:58 - 2014-09-10 23:50 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2014-08-29 03:32 - 2014-09-10 23:50 - 02779136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-08-29 02:59 - 2014-09-10 23:50 - 03117568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-08-29 01:56 - 2014-09-10 23:50 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-08-29 01:47 - 2014-09-10 23:50 - 02321920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-08-27 02:39 - 2013-01-30 15:34 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-27 02:32 - 2014-08-27 02:29 - 00000000 ____D () C:\Users\RedSpider\Santana Samba Pa Ti
2014-08-27 02:26 - 2014-08-27 02:10 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\AccurateRip
2014-08-27 02:10 - 2014-08-27 02:10 - 00001082 _____ () C:\Users\Public\Desktop\Exact Audio Copy.lnk
2014-08-27 02:10 - 2014-08-27 02:10 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\EAC
2014-08-27 02:10 - 2014-08-27 02:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
2014-08-27 02:10 - 2014-08-27 02:10 - 00000000 ____D () C:\Program Files (x86)\Exact Audio Copy
2014-08-26 01:53 - 2014-08-26 01:53 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\EurekaLab s.a.s
2014-08-26 00:27 - 2014-09-10 23:50 - 04148736 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-25 22:16 - 2014-08-25 22:16 - 00002089 _____ () C:\Users\Public\Desktop\Canon My Image Garden.lnk
2014-08-25 22:16 - 2013-02-09 15:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\WorldofTanks
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\StormFall
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Roaming\GGEmpire441
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\WorldofTanks
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\StormFall
2014-08-25 22:15 - 2014-08-25 22:15 - 00000000 ____D () C:\Users\RedSpider\AppData\Local\GGEmpire
2014-08-24 13:21 - 2014-06-24 21:13 - 00000000 ____D () C:\Users\RedSpider\Documents\EMDB
2014-08-24 13:21 - 2014-06-24 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EMDB
2014-08-24 13:21 - 2014-06-24 21:13 - 00000000 ____D () C:\Program Files (x86)\EMDB
2014-08-23 09:48 - 2014-09-10 23:50 - 02374784 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2014-08-23 09:13 - 2014-09-10 23:50 - 02084520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2014-08-23 08:10 - 2014-09-10 23:50 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-08-23 07:32 - 2014-09-10 23:50 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-08-23 06:44 - 2014-09-10 23:50 - 02860032 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-08-23 06:34 - 2014-09-10 23:50 - 13423104 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-08-23 06:33 - 2014-09-10 23:50 - 00796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-08-23 06:31 - 2014-09-10 23:50 - 01038336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-08-23 06:20 - 2014-09-10 23:50 - 11818496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-08-20 05:44 - 2014-03-19 01:24 - 00319912 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-08-20 05:44 - 2014-03-19 01:24 - 00191400 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-08-20 05:44 - 2014-03-19 01:24 - 00190888 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-08-20 05:44 - 2014-03-19 01:24 - 00111016 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2014-08-20 05:44 - 2014-03-19 01:24 - 00000000 ____D () C:\Program Files\Java
2014-08-20 05:44 - 2013-10-17 14:09 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-20 05:44 - 2013-06-24 03:19 - 00272296 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-08-20 05:44 - 2013-06-24 03:19 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-08-20 05:44 - 2013-06-24 03:19 - 00176552 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-08-20 05:44 - 2013-06-24 03:19 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-08-20 05:44 - 2013-06-24 03:19 - 00000000 ____D () C:\Program Files (x86)\Java
Some content of TEMP:
====================
C:\Users\RedSpider\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-18 16:18
==================== End Of Log ============================
--- --- ---
--- --- ---