Ca. pro Minute einmal. Teils kommt lange keine, und dann gleich mehrere aufs Mal, die IP (aus der Meldung), wechselt jedes mal.
http://i.pictr.com/ldnc0y2hy1.png
Soll ich mal mit den Sysinternals-Toos anhand des folgenden Videos versuchen?
hxxp://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA302
Oder hast du die Lösung griffbereit? (Bitte, bitte, bitte....)
UPDATE:
Die IP-Adressen wiederholen sich, der Pool dieser scheint aber recht gross zu sein.
Zusätzlich hat JRT wieder ein bösartiges Modul gefunden.
http://i.pictr.com/81sklgqitn.png
und dieses Mal scheint er auch etwas gemacht zu haben:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8.1 Pro x64
Ran by USERNAME on 17.12.2013 at 19:05:59,01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.12.2013 at 19:11:21,28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Die Meldungen erscheint aber weiterhin.
UPDATE:
Noch etwas ist mir aufgefallen, sobald ich den Resourcenmanager starte, erscheinen diese Meldungen nicht mehr.
gruss aguy
UPDATE:
Die Meldungen von der blockierten Verbindung erscheinen gar nicht mehr!
UND :)
Ich habe herausgefunden, dass Project64 -> das Programm welches ich herunterladen wollte, eine Spyware Toolbar enthält, welche man aber bei der Installation abwählen kann.
hxxp://atariage.com/forums/topic/216681-project64-without-spyware/
Bitte um entschuldigung, dass ich dies nicht schon früher gefunden habe. Es war aber trotzdem ganz gut, da ja doch noch etwas auf meinem Rechner war, welches nun weg zu sein
Mir ist aber noch etwas letztes aufgefallen:
Mein Festplatte hatte gerade eben in regelmässigen Abständen stark geratert. Als ich den Taskmanager öffnete, hat diese noch 2-3 Mal den Rhytmus fortgesetzt und ist seither wieder Stumm. Vielleicht relevant? Vielleicht Windows Search Index Aktualisierung? Wäre aber auch komisch, da das System auf einer SSD liegt, und dort eigentlich keine neuen Daten vorhanden sind.
aguy
das (hoffentlich letzte) dazugehörige FRST-log
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2013 02
Ran by USERNAME (administrator) on ANONYM-BOB13 on 17-12-2013 22:28:51
Running from C:\Users\USERNAME\Desktop
Windows 8.1 Pro (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
(Beepa P/L) C:\Fraps\fraps.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Beepa P/L) C:\Fraps\fraps64.dat
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Dropbox, Inc.) C:\Users\USERNAME\AppData\Roaming\Dropbox\bin\Dropbox.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Sysinternals - www.sysinternals.com) C:\SysinternalsSuite\Desktops.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\livecomm.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7156296 2013-03-05] (Realtek Semiconductor)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5618456 2013-09-12] (ESET)
HKLM\...\Run: [Greenshot] - C:\Program Files\Greenshot\Greenshot.exe [495616 2013-10-27] (Greenshot)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [Fences] - C:\Program Files (x86)\Stardock\Fences\Fences.exe [4013744 2013-07-11] (Stardock Corporation)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1823656 2013-12-11] (Valve Corporation)
HKCU\...\Run: [uTorrent] - C:\Users\USERNAME\AppData\Roaming\uTorrent\uTorrent.exe [1142864 2013-11-16] (BitTorrent Inc.)
HKCU\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [20203904 2013-12-06] (Google)
MountPoints2: {79334044-5d9f-11e3-8267-74d02b2b7ea4} - "F:\setup.exe"
HKLM-x32\...\Run: [RoccatKonePure] - C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.exe [561152 2013-06-10] (ROCCAT GmbH)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
Startup: C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\USERNAME\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fences.lnk
ShortcutTarget: Fences.lnk -> C:\Program Files (x86)\Stardock\Fences\Fences.exe (Stardock Corporation)
Startup: C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
ShortcutTarget: Stardock ObjectDock.lnk -> C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5C20E76453E1CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de-CH;q=0.8,de;q=0.6,fr-CH;q=0.4,fr;q=0.2
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: LastPass - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\support@lastpass.com
FF Extension: jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\jid0-9XfBwUWnvPx4wWsfBWMCm4Jj69E@jetpack.xpi
FF Extension: jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi
FF Extension: jid1-qQSMEVsYTOjgYA - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack.xpi
FF Extension: omnibar - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\omnibar@ajitk.com.xpi
FF Extension: s3google - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\s3google@translator.xpi
FF Extension: aios - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi
FF Extension: noscript - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\{ab4b5718-3998-4a2c-91ae-18a7c2db513e}.xpi
FF Extension: Adblock Plus - C:\Users\USERNAME\AppData\Roaming\Mozilla\Firefox\Profiles\66b1ckwl.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
CHR DefaultSearchKeyword: google.ch
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding}
CHR Extension: (Google Docs) - C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [927232 2012-10-29] ()
R2 CtHdaSvc; C:\Windows\sysWow64\CtHdaSvc.exe [103424 2013-02-14] (Creative Technology Ltd)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-11-02] (Microsoft Corporation)
R2 PnkBstrA; C:\WINDOWS\SysWow64\PnkBstrA.exe [76888 2013-11-14] ()
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2012-05-07] ()
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 cthda; C:\Windows\system32\drivers\cthda.sys [1044760 2013-02-14] (Creative Technology Ltd)
R3 cthdb; C:\Windows\system32\DRIVERS\cthdb.sys [28440 2013-02-14] (Creative Technology Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-07-26] (Intel Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr))
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
R3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2013-08-22] (Microsoft Corporation)
S4 nvpciflt; \SystemRoot\system32\DRIVERS\nvpciflt.sys [x]
S4 nvvad_WaveExtensible; \SystemRoot\system32\drivers\nvvad64v.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-17 19:37 - 2013-12-17 19:58 - 00007622 _____ C:\Users\USERNAME\AppData\Local\resmon.resmoncfg
2013-12-17 19:11 - 2013-12-17 19:27 - 00000755 _____ C:\Users\USERNAME\Desktop\JRT.txt
2013-12-16 23:59 - 2013-12-17 22:12 - 00000000 ____D C:\Users\USERNAME\Desktop\FRST-OlderVersion
2013-12-16 23:40 - 2013-12-16 23:40 - 00001126 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-16 23:40 - 2013-12-16 23:40 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Malwarebytes
2013-12-16 23:40 - 2013-12-16 23:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-16 23:40 - 2013-12-16 23:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-16 23:40 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-12-16 21:43 - 2013-12-16 21:43 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-16 21:43 - 2013-11-14 12:56 - 25257248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 22951200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 18208624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 17560352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 12613408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2013-12-16 21:43 - 2013-11-14 12:56 - 11600432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 11514624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 09691888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 09619872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 03132704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 03125024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 02947872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 02747680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433182.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433182.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 01242400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00707360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00657184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00609568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00562464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00479520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00405280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00357152 _____ C:\WINDOWS\system32\NvIFROpenGL.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00317472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00314656 _____ C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00266984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00168616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2013-12-16 21:43 - 2013-11-14 12:56 - 00141336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2013-12-16 21:42 - 2013-12-16 21:42 - 00000000 ____D C:\NVIDIA
2013-12-15 19:54 - 2013-12-15 19:54 - 00000583 _____ C:\Users\Public\Desktop\Call of Duty Ghosts.lnk
2013-12-15 17:56 - 2013-12-15 17:56 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\bizarre creations
2013-12-15 17:52 - 2013-12-15 17:52 - 00000917 _____ C:\Users\USERNAME\Desktop\Blur.lnk
2013-12-15 17:34 - 2013-12-15 19:56 - 00000000 ____D C:\ProgramData\Steam
2013-12-15 17:34 - 2013-12-15 17:34 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\MKKE
2013-12-15 17:11 - 2013-12-15 17:11 - 00000932 _____ C:\Users\Public\Desktop\Mortal Kombat Complete Edition.lnk
2013-12-15 17:10 - 2013-12-15 17:10 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
2013-12-15 16:09 - 2013-12-15 16:09 - 00006238 _____ C:\Users\USERNAME\Desktop\Splitscreen.xlsx
2013-12-15 13:48 - 2013-12-15 13:48 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2013-12-15 13:48 - 2013-12-15 13:48 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2013-12-15 13:41 - 2013-11-12 00:41 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-12-15 13:41 - 2013-11-12 00:40 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-12-15 13:41 - 2013-11-12 00:27 - 00701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-12-15 13:41 - 2013-11-12 00:24 - 00840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-12-15 13:41 - 2013-11-11 03:48 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-12-15 13:41 - 2013-11-09 12:55 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-12-15 13:41 - 2013-11-09 07:37 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2013-12-15 13:41 - 2013-11-09 06:56 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2013-12-15 13:41 - 2013-11-08 11:26 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2013-12-15 13:41 - 2013-11-08 06:23 - 00449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appmgr.dll
2013-12-15 13:41 - 2013-11-08 05:43 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2013-12-15 13:41 - 2013-11-08 05:42 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgr.dll
2013-12-15 13:41 - 2013-11-08 05:28 - 13177344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-12-15 13:41 - 2013-11-08 05:26 - 11674624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-12-15 13:41 - 2013-11-08 05:16 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2013-12-15 13:41 - 2013-11-08 05:15 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2013-12-15 13:41 - 2013-11-08 05:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2013-12-15 13:41 - 2013-11-08 04:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-12-15 13:41 - 2013-11-08 04:36 - 04105216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-12-15 13:41 - 2013-11-08 04:14 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-12-15 13:41 - 2013-11-05 15:19 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2013-12-15 13:41 - 2013-11-05 15:03 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2013-12-15 13:41 - 2013-11-05 14:57 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2013-12-15 13:41 - 2013-11-05 14:33 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2013-12-15 13:41 - 2013-11-05 14:32 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2013-12-15 13:41 - 2013-11-05 14:17 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2013-12-15 13:41 - 2013-11-04 18:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-12-15 13:41 - 2013-11-04 18:13 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-12-15 13:41 - 2013-11-04 14:07 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-12-15 13:41 - 2013-11-04 12:50 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-12-15 13:41 - 2013-11-04 11:32 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-12-15 13:41 - 2013-11-04 03:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-12-15 13:41 - 2013-11-04 02:30 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-12-15 13:41 - 2013-11-01 12:39 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2013-12-15 13:41 - 2013-11-01 07:08 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2013-12-15 13:41 - 2013-11-01 06:57 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2013-12-15 13:41 - 2013-10-31 01:58 - 00372568 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-12-15 13:41 - 2013-10-31 01:42 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-12-15 13:41 - 2013-10-31 01:33 - 01642016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2013-12-15 13:41 - 2013-10-31 01:33 - 01506680 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2013-12-15 13:41 - 2013-10-31 01:33 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2013-12-15 13:41 - 2013-10-31 01:33 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2013-12-15 13:41 - 2013-10-26 02:54 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys
2013-12-15 13:41 - 2013-10-24 10:31 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2013-12-15 13:41 - 2013-10-24 10:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2013-12-15 13:41 - 2013-10-17 12:21 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2013-12-15 13:41 - 2013-10-17 11:36 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2013-12-15 13:41 - 2013-10-05 15:21 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-12-15 13:41 - 2013-10-05 15:21 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-12-15 13:41 - 2013-10-05 13:05 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-12-15 13:41 - 2013-10-05 13:05 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2013-12-14 15:38 - 2013-12-14 15:38 - 00001069 _____ C:\Users\Public\Desktop\Start Sonic & All-Stars Racing Transformed.lnk
2013-12-14 15:38 - 2013-12-14 15:38 - 00001004 _____ C:\Users\Public\Desktop\Launcher Sonic & All-Stars Racing Transformed.lnk
2013-12-14 15:37 - 2013-12-14 15:37 - 00020727 _____ C:\Users\USERNAME\Desktop\FRST.zip
2013-12-14 15:31 - 2013-12-14 15:36 - 00031517 _____ C:\Users\USERNAME\Desktop\Addition.txt
2013-12-14 15:30 - 2013-12-17 22:28 - 00017777 _____ C:\Users\USERNAME\Desktop\FRST.txt
2013-12-14 15:30 - 2013-12-17 22:12 - 00000000 ____D C:\FRST
2013-12-13 21:11 - 2013-12-13 21:13 - 00000000 ____D C:\Program Files (x86)\Project64 1.6
2013-12-13 21:11 - 2013-12-13 21:11 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\project64 1.6
2013-12-13 20:40 - 2013-12-17 19:31 - 00002196 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-13 17:13 - 2013-12-17 22:12 - 01928214 _____ (Farbar) C:\Users\USERNAME\Desktop\FRST64.exe
2013-12-13 17:13 - 2013-12-13 17:13 - 00377856 _____ C:\Users\USERNAME\Desktop\gmer_2.1.19163.exe
2013-12-13 17:13 - 2013-12-13 17:13 - 00050477 _____ C:\Users\USERNAME\Desktop\Defogger.exe
2013-12-13 17:09 - 2013-12-13 17:09 - 00000269 _____ C:\Users\USERNAME\Desktop\Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten - Trojaner-Board.URL
2013-12-13 16:55 - 2013-12-13 16:55 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-13 16:52 - 2013-12-13 16:53 - 00000000 ____D C:\AdwCleaner
2013-12-13 16:51 - 2013-12-13 16:51 - 00891200 _____ C:\Users\USERNAME\Desktop\SecurityCheck.exe
2013-12-13 16:49 - 2013-12-13 16:49 - 01034531 _____ (Thisisu) C:\Users\USERNAME\Desktop\JRT.exe
2013-12-13 16:47 - 2013-12-13 16:47 - 01226802 _____ C:\Users\USERNAME\Desktop\adwcleaner.exe
2013-12-11 02:23 - 2013-10-19 09:53 - 00075360 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2013-12-11 02:23 - 2013-10-19 08:14 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2013-12-11 02:23 - 2013-10-15 09:54 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2013-12-11 02:23 - 2013-10-15 09:03 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2013-12-11 02:22 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-12-11 02:22 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-12-11 02:22 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-12-11 02:22 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-12-11 02:22 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-12-11 02:22 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-12-11 02:22 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-12-11 02:22 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-12-11 02:22 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-12-11 02:22 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-12-11 02:22 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-12-11 02:22 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-12-11 02:22 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-12-11 02:22 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2013-12-11 02:22 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2013-12-11 02:22 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-12-11 02:22 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-12-11 02:21 - 2013-11-08 08:21 - 04191744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-12-08 15:20 - 2013-12-08 21:23 - 00000000 ____D C:\Users\USERNAME\.freemind
2013-12-08 15:20 - 2013-12-08 15:20 - 00001132 _____ C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\FreeMind.lnk
2013-12-08 15:20 - 2013-12-08 15:20 - 00001108 _____ C:\Users\USERNAME\Desktop\FreeMind.lnk
2013-12-08 15:20 - 2013-12-08 15:20 - 00000000 ____D C:\Program Files (x86)\FreeMind
2013-12-08 14:36 - 2013-12-08 14:36 - 00002233 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-12-08 12:23 - 2013-12-08 12:23 - 62093799 _____ C:\Users\USERNAME\Desktop\Sphax PureBDcraft 256x MC17.zip
2013-12-08 10:52 - 2013-12-08 10:53 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\WINDOWS\PCHEALTH
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Users\USERNAME\AppData\Local\Microsoft Help
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-12-08 10:50 - 2013-12-08 10:50 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-12-08 10:43 - 2013-12-08 10:52 - 00000000 ____D C:\Program Files\Microsoft Office
2013-12-08 10:38 - 2013-12-13 16:27 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-12-08 10:31 - 2013-12-08 10:35 - 00000000 ____D C:\Program Files\office.tmp
2013-12-07 11:55 - 2013-12-07 11:38 - 604772257 _____ C:\Users\USERNAME\Desktop\Minecraft.zip
2013-12-07 11:33 - 2013-12-08 12:22 - 115988950 _____ C:\Users\USERNAME\Desktop\Sphax PureBDcraft 512x MC17.zip
2013-12-05 17:45 - 2013-12-05 17:45 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Might and Delight
2013-12-05 17:44 - 2013-12-05 17:44 - 00001271 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk
2013-12-05 17:44 - 2013-12-05 17:44 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-12-05 17:44 - 2013-12-05 17:15 - 639774576 _____ C:\Users\USERNAME\Desktop\wmt-shelter.bin
2013-12-05 17:44 - 2013-12-05 17:13 - 00000077 _____ C:\Users\USERNAME\Desktop\wmt-shelter.cue
2013-12-05 17:09 - 2013-12-05 17:09 - 00005112 _____ C:\Users\USERNAME\Desktop\shelter-walmart.nfo
2013-12-05 01:08 - 2013-12-05 01:08 - 00233984 _____ C:\Users\USERNAME\Desktop\VGABIOS.rom
2013-12-05 01:08 - 2013-07-03 06:34 - 00015648 _____ C:\WINDOWS\system32\Drivers\nvflash.sys
2013-12-05 01:02 - 2013-12-05 01:02 - 00000000 ____D C:\Users\USERNAME\Desktop\Setup32_ThunderMaster_NV_1_9h
2013-12-05 00:13 - 2013-12-05 00:13 - 00000283 _____ C:\Users\USERNAME\Desktop\[BF4] I have multiple fixes that make the game 90% improved, no more DX error's. Battlefield.URL
2013-11-22 13:22 - 2013-12-07 15:04 - 00257314 _____ C:\WINDOWS\DirectX.log
2013-11-22 13:18 - 2013-12-16 21:44 - 00002604 _____ C:\WINDOWS\setupact.log
2013-11-22 13:18 - 2013-11-22 13:18 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-22 13:17 - 2013-12-13 21:05 - 00002516 _____ C:\WINDOWS\PFRO.log
2013-11-21 22:33 - 2013-12-17 22:04 - 01478913 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-21 18:06 - 2013-12-13 01:19 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\vlc
2013-11-21 18:06 - 2013-11-21 18:06 - 00000888 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-21 18:06 - 2013-11-21 18:06 - 00000000 ____D C:\Program Files\VideoLAN
2013-11-20 21:22 - 2013-11-20 21:22 - 00001907 _____ C:\Users\Public\Desktop\IrfanView Thumbnails.lnk
2013-11-20 21:22 - 2013-11-20 21:22 - 00001015 _____ C:\Users\Public\Desktop\IrfanView.lnk
2013-11-20 21:22 - 2013-11-20 21:22 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\IrfanView
2013-11-20 21:22 - 2013-11-20 21:22 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-11-20 20:06 - 2013-11-25 21:40 - 00000000 ____D C:\Users\USERNAME\.MakeMKV
2013-11-17 15:14 - 2013-11-17 15:14 - 00000000 ____D C:\Users\USERNAME\AppData\Local\Stardock_Corporation
2013-11-17 15:13 - 2013-11-17 15:31 - 00000000 ____D C:\Program Files (x86)\Stardock
2013-11-17 15:13 - 2013-11-17 15:13 - 00002047 _____ C:\Users\USERNAME\Desktop\Customize Fences.lnk
2013-11-17 15:08 - 2013-11-17 15:08 - 00000966 _____ C:\Users\USERNAME\Desktop\eclipse.lnk
2013-11-17 15:07 - 2013-11-17 15:07 - 00000000 ____D C:\Program Files\eclipse
2013-11-17 15:05 - 2013-11-17 15:15 - 00000000 ____D C:\Users\USERNAME\.gimp-2.8
2013-11-17 15:05 - 2013-11-17 15:05 - 00000000 ____D C:\Users\USERNAME\AppData\Local\gegl-0.2
2013-11-17 14:57 - 2013-11-17 14:57 - 00000000 ____D C:\Program Files (x86)\FLAC
2013-11-17 14:29 - 2013-11-17 14:29 - 00000000 ____D C:\Program Files (x86)\Geeks3D
2013-11-17 13:59 - 2013-11-17 14:00 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Foxit Software
2013-11-17 13:59 - 2013-11-17 13:59 - 00002071 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-11-17 13:59 - 2013-11-17 13:59 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-11-17 13:59 - 2013-06-09 21:59 - 00216064 _____ C:\WINDOWS\SysWOW64\gcapi_dll.dll
2013-11-17 12:23 - 2013-11-17 12:23 - 00000000 ____D C:\ProgramData\ROCCAT
==================== One Month Modified Files and Folders =======
2013-12-17 22:28 - 2013-12-14 15:30 - 00017777 _____ C:\Users\USERNAME\Desktop\FRST.txt
2013-12-17 22:12 - 2013-12-16 23:59 - 00000000 ____D C:\Users\USERNAME\Desktop\FRST-OlderVersion
2013-12-17 22:12 - 2013-12-14 15:30 - 00000000 ____D C:\FRST
2013-12-17 22:12 - 2013-12-13 17:13 - 01928214 _____ (Farbar) C:\Users\USERNAME\Desktop\FRST64.exe
2013-12-17 22:04 - 2013-11-21 22:33 - 01478913 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-17 22:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2013-12-17 21:47 - 2013-11-16 19:36 - 00001136 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-17 20:53 - 2013-11-16 18:57 - 00005156 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for ANONYM-BOB13-USERNAME anonym-bob13
2013-12-17 20:37 - 2013-11-16 17:47 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-17 20:04 - 2013-11-14 17:10 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3419439862-1036738529-1644555537-1001
2013-12-17 19:58 - 2013-12-17 19:37 - 00007622 _____ C:\Users\USERNAME\AppData\Local\resmon.resmoncfg
2013-12-17 19:56 - 2013-11-16 20:08 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\ClassicShell
2013-12-17 19:53 - 2013-11-16 17:38 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\uTorrent
2013-12-17 19:47 - 2013-11-16 17:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-12-17 19:47 - 2013-11-16 17:49 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-17 19:47 - 2013-11-14 17:27 - 00000000 ____D C:\Program Files (x86)\Steam
2013-12-17 19:47 - 2013-11-14 16:54 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-12-17 19:47 - 2013-11-14 16:54 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-12-17 19:35 - 2013-09-30 05:14 - 01776918 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-17 19:35 - 2013-09-30 04:56 - 00764340 _____ C:\WINDOWS\system32\perfh007.dat
2013-12-17 19:35 - 2013-09-30 04:56 - 00159160 _____ C:\WINDOWS\system32\perfc007.dat
2013-12-17 19:31 - 2013-12-13 20:40 - 00002196 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-17 19:30 - 2013-11-16 20:02 - 00000000 ___RD C:\Users\USERNAME\Dropbox
2013-12-17 19:30 - 2013-11-16 19:36 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Dropbox
2013-12-17 19:30 - 2013-10-14 13:53 - 00000000 ___RD C:\Users\USERNAME\Google Drive
2013-12-17 19:29 - 2013-11-16 21:00 - 00003148 _____ C:\WINDOWS\System32\Tasks\FRAPS
2013-12-17 19:29 - 2013-11-16 19:36 - 00001132 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-17 19:29 - 2013-11-03 15:25 - 00000000 ____D C:\Fraps
2013-12-17 19:29 - 2013-09-02 17:37 - 00000000 __RDO C:\Users\USERNAME\SkyDrive
2013-12-17 19:29 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-17 19:28 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-12-17 19:27 - 2013-12-17 19:11 - 00000755 _____ C:\Users\USERNAME\Desktop\JRT.txt
2013-12-17 18:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-12-16 23:40 - 2013-12-16 23:40 - 00001126 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-16 23:40 - 2013-12-16 23:40 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Malwarebytes
2013-12-16 23:40 - 2013-12-16 23:40 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-16 23:40 - 2013-12-16 23:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-16 22:48 - 2013-11-14 17:28 - 00214392 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2013-12-16 21:47 - 2013-11-14 17:28 - 00214392 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2013-12-16 21:44 - 2013-11-22 13:18 - 00002604 _____ C:\WINDOWS\setupact.log
2013-12-16 21:43 - 2013-12-16 21:43 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-16 21:42 - 2013-12-16 21:42 - 00000000 ____D C:\NVIDIA
2013-12-16 21:24 - 2013-11-14 17:15 - 00000000 ____D C:\Program Files (x86)\Origin
2013-12-16 17:05 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2013-12-16 16:34 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData
2013-12-16 16:34 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-12-16 16:34 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\MediaViewer
2013-12-16 16:34 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\FileManager
2013-12-16 16:34 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Camera
2013-12-16 00:40 - 2013-11-16 16:53 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\foobar2000
2013-12-15 22:11 - 2013-11-16 20:12 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\.minecraft
2013-12-15 22:04 - 2013-11-16 20:37 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-12-15 19:56 - 2013-12-15 17:34 - 00000000 ____D C:\ProgramData\Steam
2013-12-15 19:54 - 2013-12-15 19:54 - 00000583 _____ C:\Users\Public\Desktop\Call of Duty Ghosts.lnk
2013-12-15 17:56 - 2013-12-15 17:56 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\bizarre creations
2013-12-15 17:52 - 2013-12-15 17:52 - 00000917 _____ C:\Users\USERNAME\Desktop\Blur.lnk
2013-12-15 17:34 - 2013-12-15 17:34 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\MKKE
2013-12-15 17:11 - 2013-12-15 17:11 - 00000932 _____ C:\Users\Public\Desktop\Mortal Kombat Complete Edition.lnk
2013-12-15 17:10 - 2013-12-15 17:10 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
2013-12-15 16:09 - 2013-12-15 16:09 - 00006238 _____ C:\Users\USERNAME\Desktop\Splitscreen.xlsx
2013-12-15 13:48 - 2013-12-15 13:48 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2013-12-15 13:48 - 2013-12-15 13:48 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2013-12-15 13:48 - 2013-11-16 19:37 - 00002059 _____ C:\Users\Public\Desktop\Google Slides.lnk
2013-12-15 13:48 - 2013-11-16 19:37 - 00002057 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2013-12-15 13:48 - 2013-11-16 19:37 - 00002047 _____ C:\Users\Public\Desktop\Google Docs.lnk
2013-12-15 13:47 - 2013-11-16 13:13 - 90708896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-12-15 13:47 - 2013-11-16 13:13 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-14 15:38 - 2013-12-14 15:38 - 00001069 _____ C:\Users\Public\Desktop\Start Sonic & All-Stars Racing Transformed.lnk
2013-12-14 15:38 - 2013-12-14 15:38 - 00001004 _____ C:\Users\Public\Desktop\Launcher Sonic & All-Stars Racing Transformed.lnk
2013-12-14 15:37 - 2013-12-14 15:37 - 00020727 _____ C:\Users\USERNAME\Desktop\FRST.zip
2013-12-14 15:36 - 2013-12-14 15:31 - 00031517 _____ C:\Users\USERNAME\Desktop\Addition.txt
2013-12-13 21:13 - 2013-12-13 21:11 - 00000000 ____D C:\Program Files (x86)\Project64 1.6
2013-12-13 21:11 - 2013-12-13 21:11 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\project64 1.6
2013-12-13 21:05 - 2013-11-22 13:17 - 00002516 _____ C:\WINDOWS\PFRO.log
2013-12-13 20:40 - 2013-11-16 19:36 - 00000000 ____D C:\Users\USERNAME\AppData\Local\Google
2013-12-13 20:40 - 2013-11-16 19:36 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-13 17:13 - 2013-12-13 17:13 - 00377856 _____ C:\Users\USERNAME\Desktop\gmer_2.1.19163.exe
2013-12-13 17:13 - 2013-12-13 17:13 - 00050477 _____ C:\Users\USERNAME\Desktop\Defogger.exe
2013-12-13 17:09 - 2013-12-13 17:09 - 00000269 _____ C:\Users\USERNAME\Desktop\Für alle Hilfesuchenden! Was muss ich vor der Eröffnung eines Themas beachten - Trojaner-Board.URL
2013-12-13 16:55 - 2013-12-13 16:55 - 00000000 ____D C:\WINDOWS\ERUNT
2013-12-13 16:53 - 2013-12-13 16:52 - 00000000 ____D C:\AdwCleaner
2013-12-13 16:51 - 2013-12-13 16:51 - 00891200 _____ C:\Users\USERNAME\Desktop\SecurityCheck.exe
2013-12-13 16:49 - 2013-12-13 16:49 - 01034531 _____ (Thisisu) C:\Users\USERNAME\Desktop\JRT.exe
2013-12-13 16:47 - 2013-12-13 16:47 - 01226802 _____ C:\Users\USERNAME\Desktop\adwcleaner.exe
2013-12-13 16:27 - 2013-12-08 10:38 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-12-13 16:15 - 2013-08-22 15:44 - 00473728 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-13 01:19 - 2013-11-21 18:06 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\vlc
2013-12-10 19:37 - 2013-11-16 17:47 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2013-12-08 21:23 - 2013-12-08 15:20 - 00000000 ____D C:\Users\USERNAME\.freemind
2013-12-08 15:20 - 2013-12-08 15:20 - 00001132 _____ C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\FreeMind.lnk
2013-12-08 15:20 - 2013-12-08 15:20 - 00001108 _____ C:\Users\USERNAME\Desktop\FreeMind.lnk
2013-12-08 15:20 - 2013-12-08 15:20 - 00000000 ____D C:\Program Files (x86)\FreeMind
2013-12-08 15:20 - 2013-11-14 17:00 - 00000000 ____D C:\Users\USERNAME
2013-12-08 14:36 - 2013-12-08 14:36 - 00002233 _____ C:\Users\Public\Desktop\Google Earth.lnk
2013-12-08 12:23 - 2013-12-08 12:23 - 62093799 _____ C:\Users\USERNAME\Desktop\Sphax PureBDcraft 256x MC17.zip
2013-12-08 12:22 - 2013-12-07 11:33 - 115988950 _____ C:\Users\USERNAME\Desktop\Sphax PureBDcraft 512x MC17.zip
2013-12-08 10:53 - 2013-12-08 10:52 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-08 10:53 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\WINDOWS\PCHEALTH
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Users\USERNAME\AppData\Local\Microsoft Help
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-12-08 10:52 - 2013-12-08 10:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-12-08 10:52 - 2013-12-08 10:43 - 00000000 ____D C:\Program Files\Microsoft Office
2013-12-08 10:50 - 2013-12-08 10:50 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-12-08 10:35 - 2013-12-08 10:31 - 00000000 ____D C:\Program Files\office.tmp
2013-12-07 15:04 - 2013-11-22 13:22 - 00257314 _____ C:\WINDOWS\DirectX.log
2013-12-07 11:38 - 2013-12-07 11:55 - 604772257 _____ C:\Users\USERNAME\Desktop\Minecraft.zip
2013-12-05 17:45 - 2013-12-05 17:45 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Might and Delight
2013-12-05 17:44 - 2013-12-05 17:44 - 00001271 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk
2013-12-05 17:44 - 2013-12-05 17:44 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-12-05 17:15 - 2013-12-05 17:44 - 639774576 _____ C:\Users\USERNAME\Desktop\wmt-shelter.bin
2013-12-05 17:13 - 2013-12-05 17:44 - 00000077 _____ C:\Users\USERNAME\Desktop\wmt-shelter.cue
2013-12-05 17:09 - 2013-12-05 17:09 - 00005112 _____ C:\Users\USERNAME\Desktop\shelter-walmart.nfo
2013-12-05 01:08 - 2013-12-05 01:08 - 00233984 _____ C:\Users\USERNAME\Desktop\VGABIOS.rom
2013-12-05 01:02 - 2013-12-05 01:02 - 00000000 ____D C:\Users\USERNAME\Desktop\Setup32_ThunderMaster_NV_1_9h
2013-12-05 00:13 - 2013-12-05 00:13 - 00000283 _____ C:\Users\USERNAME\Desktop\[BF4] I have multiple fixes that make the game 90% improved, no more DX error's. Battlefield.URL
2013-12-04 18:42 - 2013-11-16 19:36 - 00004108 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-04 18:42 - 2013-11-16 19:36 - 00003872 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-04 01:05 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-12-04 01:05 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-01 14:21 - 2013-11-16 20:03 - 00000000 ____D C:\ProgramData\ClassicShell
2013-11-30 16:22 - 2013-11-14 17:28 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-11-26 12:54 - 2013-12-11 02:22 - 23183360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-26 11:11 - 2013-12-11 02:22 - 17112576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-26 10:41 - 2013-12-11 02:22 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-26 09:57 - 2013-12-11 02:22 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-26 09:38 - 2013-12-11 02:22 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-26 09:35 - 2013-12-11 02:22 - 05769216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-26 09:16 - 2013-12-11 02:22 - 04243968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-26 09:02 - 2013-12-11 02:22 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-26 08:48 - 2013-12-11 02:22 - 12996608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-26 08:32 - 2013-12-11 02:22 - 01928192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-26 08:26 - 2013-12-11 02:22 - 11221504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-26 08:07 - 2013-12-11 02:22 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-26 07:40 - 2013-12-11 02:22 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-26 07:34 - 2013-12-11 02:22 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2013-11-26 07:34 - 2013-12-11 02:22 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2013-11-26 07:33 - 2013-12-11 02:22 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-26 07:27 - 2013-12-11 02:22 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-25 21:40 - 2013-11-20 20:06 - 00000000 ____D C:\Users\USERNAME\.MakeMKV
2013-11-22 13:18 - 2013-11-22 13:18 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-21 22:29 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-11-21 18:39 - 2013-11-14 17:04 - 00000000 ____D C:\Users\USERNAME\AppData\Local\Packages
2013-11-21 18:06 - 2013-11-21 18:06 - 00000888 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-21 18:06 - 2013-11-21 18:06 - 00000000 ____D C:\Program Files\VideoLAN
2013-11-21 02:06 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2013-11-20 21:22 - 2013-11-20 21:22 - 00001907 _____ C:\Users\Public\Desktop\IrfanView Thumbnails.lnk
2013-11-20 21:22 - 2013-11-20 21:22 - 00001015 _____ C:\Users\Public\Desktop\IrfanView.lnk
2013-11-20 21:22 - 2013-11-20 21:22 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\IrfanView
2013-11-20 21:22 - 2013-11-20 21:22 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-11-17 15:31 - 2013-11-17 15:13 - 00000000 ____D C:\Program Files (x86)\Stardock
2013-11-17 15:29 - 2013-11-16 20:39 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Stardock
2013-11-17 15:15 - 2013-11-17 15:05 - 00000000 ____D C:\Users\USERNAME\.gimp-2.8
2013-11-17 15:14 - 2013-11-17 15:14 - 00000000 ____D C:\Users\USERNAME\AppData\Local\Stardock_Corporation
2013-11-17 15:13 - 2013-11-17 15:13 - 00002047 _____ C:\Users\USERNAME\Desktop\Customize Fences.lnk
2013-11-17 15:13 - 2013-11-14 17:04 - 00000000 ___RD C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-17 15:08 - 2013-11-17 15:08 - 00000966 _____ C:\Users\USERNAME\Desktop\eclipse.lnk
2013-11-17 15:07 - 2013-11-17 15:07 - 00000000 ____D C:\Program Files\eclipse
2013-11-17 15:05 - 2013-11-17 15:05 - 00000000 ____D C:\Users\USERNAME\AppData\Local\gegl-0.2
2013-11-17 14:57 - 2013-11-17 14:57 - 00000000 ____D C:\Program Files (x86)\FLAC
2013-11-17 14:29 - 2013-11-17 14:29 - 00000000 ____D C:\Program Files (x86)\Geeks3D
2013-11-17 14:00 - 2013-11-17 13:59 - 00000000 ____D C:\Users\USERNAME\AppData\Roaming\Foxit Software
2013-11-17 13:59 - 2013-11-17 13:59 - 00002071 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2013-11-17 13:59 - 2013-11-17 13:59 - 00000000 ____D C:\Program Files (x86)\Foxit Software
2013-11-17 12:23 - 2013-11-17 12:23 - 00000000 ____D C:\ProgramData\ROCCAT
2013-11-17 12:23 - 2013-11-14 17:04 - 00000000 ____D C:\Users\USERNAME\AppData\Local\VirtualStore
Some content of TEMP:
====================
C:\Users\USERNAME\AppData\Local\Temp\Checkupdate.exe
C:\Users\USERNAME\AppData\Local\Temp\drm_dyndata_7380015.dll
C:\Users\USERNAME\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\USERNAME\AppData\Local\Temp\gcapi_dll.dll
C:\Users\USERNAME\AppData\Local\Temp\gtapi_signed.dll
C:\Users\USERNAME\AppData\Local\Temp\OfficeSetup.exe
C:\Users\USERNAME\AppData\Local\Temp\procexp64.exe
C:\Users\USERNAME\AppData\Local\Temp\Quarantine.exe
C:\Users\USERNAME\AppData\Local\Temp\sonarinst.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-10 19:54
==================== End Of Log ============================
--- --- ---
--- --- ---