Hallo :)
AdwCleaner Code:
# AdwCleaner v3.210 - Bericht erstellt am 23/05/2014 um 20:37:22
# Aktualisiert 19/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : John-Nionto - JOHN-NIONTO-PC
# Gestartet von : C:\Users\John-Nionto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FB02GD1W\adwcleaner_3.210.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : bupService
[#] Dienst Gelöscht : CltMngSvc
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\MSR
Ordner Gelöscht : C:\Users\John-Nionto\AppData\LocalLow\SimplyTech
Datei Gelöscht : C:\Windows\System32\Tasks\Browser Updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Google Chrome v35.0.1916.114
[ Datei : C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [13218 octets] - [17/05/2014 16:00:25]
AdwCleaner[R1].txt - [6690 octets] - [20/05/2014 23:01:41]
AdwCleaner[R2].txt - [2092 octets] - [23/05/2014 20:36:25]
AdwCleaner[S0].txt - [9366 octets] - [17/05/2014 16:01:09]
AdwCleaner[S1].txt - [6586 octets] - [20/05/2014 23:02:31]
AdwCleaner[S2].txt - [2013 octets] - [23/05/2014 20:37:22]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2073 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by John-Nionto on 23.05.2014 at 20:42:41,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\simplytech
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\John-Nionto\appdata\locallow\simplytech"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.05.2014 at 20:52:29,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.05.2014
Suchlauf-Zeit: 21:02:53
Logdatei: mama.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.05.23.10
Rootkit Datenbank: v2014.05.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: John-Nionto
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 262505
Verstrichene Zeit: 9 Min, 51 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\updateSpadeCast.exe, 1688, Löschen bei Neustart, [ad29e86cec8fff376695620435cc4bb5]
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\utilSpadeCast.exe, 3056, Löschen bei Neustart, [c2143b194239f046b546590d19e8857b]
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\SpadeCast.BrowserAdapter.exe, 8388, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0]
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\SpadeCast.PurBrowse64.exe, 8236, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0]
Module: 1
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\{f64c1459-b911-4fd8-a74e-36a496bf26e3}.dll, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0],
Registrierungsschlüssel: 14
PUP.Optional.SpadeCast.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update SpadeCast, In Quarantäne, [ad29e86cec8fff376695620435cc4bb5],
PUP.Optional.SpadeCast.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util SpadeCast, In Quarantäne, [c2143b194239f046b546590d19e8857b],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ed381eb3-45e2-4e12-89eb-be974b15da44}, In Quarantäne, [82549eb6d4a7ef473b9306269c663cc4],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{ED381EB3-45E2-4E12-89EB-BE974B15DA44}, In Quarantäne, [82549eb6d4a7ef473b9306269c663cc4],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SpadeCast, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, HKLM\SOFTWARE\WOW6432NODE\SpadeCast, In Quarantäne, [8d4991c3df9cba7ce9f5fd9cd03242be],
PUP.Optional.SpadeCast.A, HKU\S-1-5-21-278123427-2378183310-4013628180-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SpadeCast, In Quarantäne, [c214213323583cfa29b4bcdd53af15eb],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[31a554000b70a88e27c4490c08fc07f9]
Ordner: 5
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\TEMP, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
Dateien: 42
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\updateSpadeCast.exe, Löschen bei Neustart, [ad29e86cec8fff376695620435cc4bb5],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\utilSpadeCast.exe, Löschen bei Neustart, [c2143b194239f046b546590d19e8857b],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\SpadeCastBHO.dll, In Quarantäne, [82549eb6d4a7ef473b9306269c663cc4],
PUP.Optional.AdPeak.A, C:\temp\t.msi, In Quarantäne, [ba1c371d5d1ebf77c6134208f4106d93],
PUP.Optional.InstallCore.A, C:\Users\John-Nionto\Downloads\SkypeSetup.exe, In Quarantäne, [16c0a5af87f4082e1749eb44de228080],
PUP.Optional.Breitschopp, C:\Users\John-Nionto\Downloads\soft32_Java Runtime Environment_1.0 (1).exe, In Quarantäne, [54821b391f5ce84e99448ab84bb943bd],
PUP.Optional.Breitschopp, C:\Users\John-Nionto\Downloads\soft32_Java Runtime Environment_1.0.exe, In Quarantäne, [dafc66ee3c3f2b0b7b62bf83b94b4cb4],
PUP.Optional.Softonic.A, C:\Users\John-Nionto\Downloads\SoftonicDownloader_fuer_moorhuhn-x.exe, In Quarantäne, [eceadd772d4e2d09ff7a52ce45bc9f61],
PUP.Optional.Jumpyapps, C:\Users\John-Nionto\Downloads\DownloadManagerSetup.exe, In Quarantäne, [686e2e26e09b3df96622f72b00046c94],
PUP.Optional.BundleInstaller.A, C:\Users\John-Nionto\Downloads\Java.exe, In Quarantäne, [efe76aeabebd1f17872bb377fa0af20e],
PUP.Optional.Outbrowse, C:\Users\John-Nionto\Downloads\setup (1).exe, In Quarantäne, [20b683d186f5d95d7d8287f62cd5ec14],
PUP.Optional.Outbrowse, C:\Users\John-Nionto\Downloads\setup (2).exe, In Quarantäne, [5086183c5922cd690bf44b3235cc40c0],
PUP.Optional.OptimumInstaller.A, C:\Users\John-Nionto\Downloads\Setup.exe, In Quarantäne, [08ceb1a3cbb0b77f96842e2023dedb25],
PUP.Optional.Amonetize.A, C:\Users\John-Nionto\AppData\Local\22736\a14600.exe, In Quarantäne, [9b3bd97b3744ba7c4a0fac979c6449b7],
PUP.Optional.Superfish.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [eaec2232a9d2a78fdf56e9a3f9099a66],
PUP.Optional.Superfish.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [63734e069ddea4920431dcb004fe04fc],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\SpadeCast.ico, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\7za.exe, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\SpadeCastUninstall.exe, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\updateSpadeCast.InstallState, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\7za.exe, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\BrowserAdapterS.7z, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\SpadeCast.BrowserAdapter.exe, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\SpadeCast.PurBrowse64.exe, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\SpadeCast.PurBrowseG.zip, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\SpadeCastBAApp.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\utilSpadeCast.InstallState, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\{f64c1459-b911-4fd8-a74e-36a496bf26e3}.dll, Löschen bei Neustart, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins\SpadeCast.Bromon.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins\SpadeCast.BroStats.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins\SpadeCast.BrowserAdapterS.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins\SpadeCast.CompatibilityChecker.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins\SpadeCast.FFUpdate.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins\SpadeCast.IEUpdate.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.SpadeCast.A, C:\Program Files (x86)\SpadeCast\bin\plugins\SpadeCast.PurBrowseG.dll, In Quarantäne, [f4e26ee665162c0ac4184b4e58aa20e0],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\000005.ldb, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\000006.log, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\CURRENT, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\LOCK, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\LOG, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\LOG.old, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
PUP.Optional.MySpeedDial.A, C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pflphaooapbgpeakohlggbpidpppgdff\MANIFEST-000004, In Quarantäne, [74628cc8b2c995a1abffd5add92958a8],
Physische Sektoren: 0
(No malicious items detected)
(end) Zoek Code:
Zoek.exe v5.0.0.0 Updated 22-05-2014
Tool run by John-Nionto on 23.05.2014 at 21:20:03,62.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\John-Nionto\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
23.05.2014 21:21:09 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-278123427-2378183310-4013628180-1000\Software\Microsoft\Internet Explorer\SearchScopes\{41EA33EC-049E-41D5-B44D-02E0337C3DD4} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\PROGRA~3\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted
C:\Users\John-Nionto\.android deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\John-Nionto\AppData\Local\cache deleted
C:\windows\SysNative\Tasks\SystemSockets deleted
C:\windows\SysNative\Tasks\Browser Updater deleted
C:\Users\John-Nionto\Downloads\FreeYouTubeToMP3Converter.exe deleted
C:\Users\John-Nionto\Downloads\FreeYouTubeToMP3Converter_3.12.32.327 (1).exe deleted
C:\Users\John-Nionto\AppData\LocalLow\SimplyTech deleted
C:\Windows\Launcher.exe deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [16.05.2014 16:35]
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bacmhbpcpggpejckjicbghlgdlhgelbc - C:\Program Files (x86)\ZappAddon\chrome\ZappAddon.crx[24.03.2014 06:31]
fheoggkfdfchfphceeifdbepaooicaho - No path found[]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{41EA33EC-049E-41D5-B44D-02E0337C3DD4}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{41EA33EC-049E-41D5-B44D-02E0337C3DD4}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
==== Reset Google Chrome ======================
C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyServer"="http=127.0.0.1:8118;https=127.0.0.1:8118"
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7dd964ce-bd82-4752-80e4-5ab17ee135bf}_is1 deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\John-Nionto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\John-Nionto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=199 folders=65 98015144 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\John-Nionto\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\JOHN-N~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 23.05.2014 at 21:30:28,39 ====================== FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-05-2014
Ran by John-Nionto (administrator) on JOHN-NIONTO-PC on 23-05-2014 21:37:57
Running from C:\Users\John-Nionto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DOVTFDF9
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(AVM Berlin) C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Drakonia Configurator\hid.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Game Inc.) C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(McAfee, Inc.) C:\Program Files\McAfee\MAT\McPvTray.exe
(Raptr, Inc) C:\Program Files (x86)\Raptr\raptr.exe
(Raptr, Inc) C:\Program Files (x86)\Raptr\raptr_im.exe
(Raptr Inc.) C:\Program Files (x86)\Raptr\raptr_ep64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM-x32\...\Run: [RUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [248832 2013-10-29] ()
HKLM-x32\...\Run: [GamingKeyboard] => C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe [1803264 2012-06-07] (Game Inc.)
HKU\S-1-5-21-278123427-2378183310-4013628180-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1775808 2014-05-21] (Valve Corporation)
HKU\S-1-5-21-278123427-2378183310-4013628180-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2013-10-16] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-278123427-2378183310-4013628180-1000\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2014-02-18] (Raptr, Inc)
HKU\S-1-5-21-278123427-2378183310-4013628180-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-11-22] (AMD)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldstr1202&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0E0A0C0A0BtCtD0Azz0BtN0D0Tzu0SyBtBtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=612540794&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldstr1202&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0E0A0C0A0BtCtD0Azz0BtN0D0Tzu0SyBtBtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=612540794&ir=
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Zapp - {f1abf166-ad38-4bcf-9844-c22b50874909} - C:\Program Files\ZappAddon\IE\ZappAddon.dll (Simply Tech LTD.)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Zapp - {f1abf166-ad38-4bcf-9844-c22b50874909} - C:\Program Files (x86)\ZappAddon\IE\ZappAddon.dll (Simply Tech LTD.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - Zapp - {f1abf166-ad38-4bcf-9844-c22b50874909} - C:\Program Files\ZappAddon\IE\ZappAddon.dll (Simply Tech LTD.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - Zapp - {f1abf166-ad38-4bcf-9844-c22b50874909} - C:\Program Files (x86)\ZappAddon\IE\ZappAddon.dll (Simply Tech LTD.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Winsock: Catalog5 07 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880] (AVM Berlin)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-10-31]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2013-10-31]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Google Wallet) - C:\Users\John-Nionto\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-23]
CHR HKLM-x32\...\Chrome\Extension: [bacmhbpcpggpejckjicbghlgdlhgelbc] - C:\Program Files (x86)\ZappAddon\chrome\ZappAddon.crx [2014-05-20]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 IGDCTRL; C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE [87344 2007-09-04] (AVM Berlin)
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\McAfee\MSC\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
S2 McOobeSv; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025712 2014-01-21] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-03-17] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [185792 2014-03-17] (McAfee, Inc.)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC)
S2 SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [X]
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70592 2014-03-17] (McAfee, Inc.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] ()
R3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH)
R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] ()
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R0 McPvDrv; C:\Windows\System32\drivers\McPvDrv.sys [74560 2013-09-09] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [180272 2014-03-17] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311600 2014-03-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [522360 2014-03-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [783864 2014-03-17] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [422712 2014-01-21] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96592 2014-01-21] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [345456 2014-03-17] (McAfee, Inc.)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2012-08-27] (Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [230280 2012-08-27] (Renesas Electronics Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC)
R1 {f64c1459-b911-4fd8-a74e-36a496bf26e3}Gw64; C:\Windows\System32\drivers\{f64c1459-b911-4fd8-a74e-36a496bf26e3}Gw64.sys [61112 2014-05-19] (StdLib)
S3 ALSysIO; \??\C:\Users\JOHN-N~1\AppData\Local\Temp\ALSysIO64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-23 21:35 - 2014-05-23 21:36 - 00008317 _____ () C:\Users\John-Nionto\Desktop\zoek.txt
2014-05-23 21:29 - 2014-05-23 21:19 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-23 21:20 - 2014-05-23 21:30 - 00008317 _____ () C:\zoek-results.log
2014-05-23 21:19 - 2014-05-23 21:28 - 00000000 ____D () C:\zoek_backup
2014-05-23 21:18 - 2014-05-23 21:18 - 01285120 _____ () C:\Users\John-Nionto\Desktop\zoek.exe
2014-05-23 21:13 - 2014-05-23 21:13 - 00011410 _____ () C:\Users\John-Nionto\Desktop\mama.txt
2014-05-23 21:00 - 2014-05-23 21:01 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-23 21:00 - 2014-05-23 21:00 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-23 21:00 - 2014-05-23 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-23 21:00 - 2014-05-23 21:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-23 21:00 - 2014-05-23 21:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-23 21:00 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-23 21:00 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-23 21:00 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-23 20:52 - 2014-05-23 20:52 - 00000983 _____ () C:\Users\John-Nionto\Desktop\JRT.txt
2014-05-23 20:42 - 2014-05-23 20:42 - 01016261 _____ (Thisisu) C:\Users\John-Nionto\Desktop\JRT.exe
2014-05-23 20:42 - 2014-05-23 20:42 - 00000000 ____D () C:\Windows\ERUNT
2014-05-23 20:40 - 2014-05-23 20:40 - 00002161 _____ () C:\Users\John-Nionto\Desktop\Adw.txt
2014-05-23 20:38 - 2014-05-23 21:30 - 00013112 _____ () C:\Windows\PFRO.log
2014-05-23 18:45 - 2014-05-23 21:30 - 00000224 _____ () C:\Windows\setupact.log
2014-05-23 18:45 - 2014-05-23 18:45 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-22 21:39 - 2014-05-22 21:39 - 00030052 _____ () C:\ComboFix.txt
2014-05-22 21:08 - 2014-05-22 21:39 - 00000000 ____D () C:\Qoobox
2014-05-22 21:08 - 2014-05-22 21:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-22 21:08 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-22 21:08 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-22 21:08 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-22 21:08 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-22 21:08 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-22 21:08 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-22 21:08 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-22 21:08 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-22 21:04 - 2014-05-22 21:04 - 05200426 ____R (Swearware) C:\Users\John-Nionto\Desktop\ComboFix.exe
2014-05-22 21:01 - 2014-05-22 21:02 - 05200426 _____ (Swearware) C:\Users\John-Nionto\Downloads\ComboFix.exe
2014-05-21 20:13 - 2014-05-21 20:14 - 00033958 _____ () C:\Users\John-Nionto\Downloads\Addition.txt
2014-05-21 20:12 - 2014-05-23 21:37 - 00000000 ____D () C:\FRST
2014-05-21 20:12 - 2014-05-21 20:14 - 00052458 _____ () C:\Users\John-Nionto\Downloads\FRST.txt
2014-05-21 20:12 - 2014-05-21 20:12 - 02067456 _____ (Farbar) C:\Users\John-Nionto\Downloads\FRST64.exe
2014-05-20 23:01 - 2014-05-20 23:01 - 01326389 _____ () C:\Users\John-Nionto\Downloads\adwcleaner_3.210.exe
2014-05-20 20:54 - 2014-05-20 20:54 - 00000000 ____D () C:\Users\John-Nionto\Downloads\Minecraft 1.6.4 by TeamExtremeMc.com
2014-05-20 20:50 - 2014-05-19 16:46 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{f64c1459-b911-4fd8-a74e-36a496bf26e3}Gw64.sys
2014-05-20 19:33 - 2014-04-14 20:14 - 00880040 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2014-05-20 19:33 - 2014-04-14 20:14 - 00802728 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2014-05-20 19:31 - 2014-05-20 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-05-20 19:30 - 2014-05-20 19:30 - 00000000 ____D () C:\Program Files\ZappAddon
2014-05-20 19:30 - 2014-05-20 19:30 - 00000000 ____D () C:\Program Files (x86)\ZappAddon
2014-05-20 19:30 - 2014-05-20 19:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-05-20 19:18 - 2014-05-20 19:18 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\Security System 2
2014-05-19 23:07 - 2014-05-19 23:07 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\LavasoftStatistics
2014-05-19 22:52 - 2014-05-19 22:52 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-05-19 22:48 - 2014-05-20 22:07 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2014-05-19 22:46 - 2014-05-19 22:46 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-05-19 22:09 - 2014-05-19 22:09 - 01727624 _____ () C:\Users\John-Nionto\Downloads\Adaware_Installer_11.1.5354.exe
2014-05-18 22:35 - 2014-05-18 22:35 - 00000000 _____ () C:\autoexec.bat
2014-05-18 22:34 - 2014-05-18 22:34 - 00003362 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
2014-05-18 22:34 - 2014-05-18 22:34 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-05-18 22:34 - 2014-05-18 22:34 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-05-18 22:34 - 2012-06-22 11:01 - 00022704 _____ () C:\Windows\system32\Drivers\EsgScanner.sys
2014-05-18 22:32 - 2014-05-18 22:32 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\John-Nionto\Downloads\SpyHunter-Installer.exe
2014-05-18 22:01 - 2014-05-18 22:01 - 00675988 _____ () C:\Users\John-Nionto\Downloads\Minecraft.exe
2014-05-18 00:33 - 2014-05-18 20:29 - 1926612148 _____ () C:\Users\John-Nionto\Downloads\The Amazing Spider-Man 2 Rendered 720p H264 AC3 by koz.mp4
2014-05-17 23:29 - 2014-05-20 19:13 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\.minecraft
2014-05-17 19:43 - 2014-05-18 00:06 - 00000000 ____D () C:\Users\John-Nionto\Downloads\Max.Payne.2.The.Fall.Of.Max.Payne.PC.Game(djDEVASTATE™)
2014-05-17 16:00 - 2014-05-23 20:37 - 00000000 ____D () C:\AdwCleaner
2014-05-17 16:00 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-17 15:54 - 2014-05-17 16:21 - 00000000 ____D () C:\Users\John-Nionto\Downloads\The Amazing Spiderman 2 2014 NEW CAM XviD-HELLRAZ0R
2014-05-17 15:34 - 2014-05-21 20:08 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\uTorrent
2014-05-17 15:33 - 2014-05-17 15:33 - 01670992 _____ (BitTorrent Inc.) C:\Users\John-Nionto\Downloads\uTorrent_3.4.1_31139.exe
2014-05-17 15:08 - 2014-05-23 21:13 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\22736
2014-05-17 15:08 - 2014-05-17 15:49 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\CrashDumps
2014-05-17 15:07 - 2014-05-17 15:07 - 00003282 _____ () C:\Windows\System32\Tasks\GPUpdate
2014-05-17 15:07 - 2014-05-17 15:07 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\wi_upd
2014-05-17 15:07 - 2014-05-17 15:07 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\GetPrivate
2014-05-15 22:35 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 22:35 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 22:35 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 22:35 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 22:35 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 22:35 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 17:56 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 17:56 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 17:56 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 17:56 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 17:55 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 17:55 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 17:55 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 17:55 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 17:55 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 17:55 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 17:55 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 17:55 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 17:55 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 17:55 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 17:55 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 17:55 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 17:55 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 17:55 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 17:55 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 17:55 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 17:55 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 17:55 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 17:55 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 17:55 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 17:55 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 17:55 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 17:55 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 17:55 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 17:55 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 17:55 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 17:55 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 17:55 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 17:55 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 17:55 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-14 22:43 - 2014-05-14 22:44 - 00000000 ____D () C:\Users\John-Nionto\Desktop\USB-
2014-05-13 22:12 - 2014-05-14 22:29 - 00000000 ____D () C:\Users\John-Nionto\Desktop\projekt
2014-05-13 22:10 - 2014-05-13 22:10 - 00087489 _____ () C:\Users\John-Nionto\Downloads\lol.zip
2014-05-07 22:36 - 2014-05-08 18:38 - 00002292 _____ () C:\Users\John-Nionto\Documents\profile.conf
2014-05-07 17:52 - 2014-05-07 17:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHARKOON Skiller
2014-05-07 17:52 - 2014-05-07 17:52 - 00000000 ____D () C:\Program Files (x86)\SHARKOON Skiller
2014-05-07 17:52 - 2012-05-11 15:24 - 00027648 _____ () C:\Windows\system32\Drivers\GameKB.sys
2014-05-07 17:51 - 2014-05-07 17:51 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\InstallShield
2014-05-07 17:49 - 2014-05-07 17:49 - 00018628 _____ () C:\Windows\unins000.dat
2014-05-07 17:49 - 2014-05-07 17:49 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\MingGuan
2014-05-07 17:49 - 2014-05-07 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drakonia Black
2014-05-07 17:49 - 2014-05-07 17:49 - 00000000 ____D () C:\Program Files (x86)\Drakonia Configurator
2014-05-07 17:49 - 2014-05-07 17:48 - 01192533 _____ () C:\Windows\unins000.exe
2014-05-05 21:54 - 2014-05-05 21:54 - 00146742 _____ () C:\Users\John-Nionto\Downloads\bogi Eq2.bmp
2014-05-05 21:54 - 2014-05-05 21:54 - 00146742 _____ () C:\Users\John-Nionto\Downloads\bogi Eq2 (1).bmp
2014-05-01 21:58 - 2014-05-05 22:19 - 00004608 _____ () C:\Users\John-Nionto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-05-01 21:56 - 2014-05-01 21:56 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\TechSmith
2014-05-01 21:54 - 2014-05-01 21:54 - 00000936 _____ () C:\Users\Public\Desktop\GPU Temp.lnk
2014-05-01 21:53 - 2014-05-01 21:53 - 00929416 _____ (CNET Download.com) C:\Users\John-Nionto\Downloads\cbsidlm-cbsi188-GPU_Temp-ORG-75593083.exe
2014-05-01 19:39 - 2014-05-05 22:21 - 00000000 ____D () C:\Users\John-Nionto\Documents\Camtasia Studio
2014-05-01 19:39 - 2014-05-01 19:39 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00001168 _____ () C:\Users\Public\Desktop\Camtasia Studio 8.lnk
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\ProgramData\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\ProgramData\regid.1995-08.com.techsmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\Program Files (x86)\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-01 19:32 - 2014-05-01 19:32 - 00188736 _____ () C:\Users\John-Nionto\Downloads\CoreTemp_64bit_0.99.5.27_PCMASTERS.DE.rar
2014-05-01 19:25 - 2014-05-01 19:33 - 251749736 _____ () C:\Users\John-Nionto\Downloads\camtasiade_8.1.2.exe
2014-04-30 23:25 - 2014-05-16 12:34 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-27 18:34 - 2014-04-27 18:34 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-27 18:34 - 2014-04-27 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-27 18:34 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-27 18:34 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-27 18:34 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-27 18:34 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-27 18:23 - 2014-04-27 18:23 - 00000000 ____D () C:\ProgramData\ATI
2014-04-26 23:49 - 2014-04-26 23:49 - 00061432 _____ () C:\Windows\SysWOW64\CCCInstall_201404262349070571.log
2014-04-26 23:49 - 2014-04-26 23:49 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-04-26 23:48 - 2014-04-26 23:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-04-26 23:28 - 2014-04-26 23:36 - 295347968 _____ (AMD Inc.) C:\Users\John-Nionto\Downloads\14-4-win7-win8-win8.1-64-dd-ccc-whql.exe
2014-04-23 17:45 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-04-23 17:11 - 2014-04-23 17:15 - 00000000 ____D () C:\Fraps
2014-04-23 17:11 - 2014-04-23 17:11 - 00000562 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-04-23 17:11 - 2014-04-23 17:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-04-23 17:11 - 2013-08-31 14:00 - 00000000 ____D () C:\Users\John-Nionto\Desktop\Fraps 3.5.99 by Elite48x
2014-04-23 16:59 - 2014-04-23 16:59 - 00000000 __SHD () C:\Users\John-Nionto\AppData\Local\EmieUserList
2014-04-23 16:59 - 2014-04-23 16:59 - 00000000 __SHD () C:\Users\John-Nionto\AppData\Local\EmieSiteList
2014-04-23 16:53 - 2014-04-23 16:53 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\Sony
2014-04-23 16:53 - 2014-04-23 16:53 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\Sony
2014-04-23 16:46 - 2014-04-23 16:46 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\Ashampoo
2014-04-23 16:41 - 2014-04-23 16:41 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-23 16:40 - 2014-04-23 16:41 - 10488072 _____ (Ashampoo GmbH & Co. KG ) C:\Users\John-Nionto\Downloads\ashampoo_media_sync_e1.0.2_sm.exe
==================== One Month Modified Files and Folders =======
2014-05-23 21:37 - 2014-05-21 20:12 - 00000000 ____D () C:\FRST
2014-05-23 21:37 - 2013-10-31 07:04 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-05-23 21:37 - 2013-10-31 07:04 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-05-23 21:37 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-23 21:37 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-23 21:37 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-23 21:36 - 2014-05-23 21:35 - 00008317 _____ () C:\Users\John-Nionto\Desktop\zoek.txt
2014-05-23 21:35 - 2013-12-01 18:29 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\Raptr
2014-05-23 21:34 - 2013-10-31 13:54 - 00001844 _____ () C:\Users\Public\Desktop\McAfee Total Protection.lnk
2014-05-23 21:34 - 2013-10-31 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-05-23 21:33 - 2013-10-30 15:16 - 01179820 _____ () C:\Windows\WindowsUpdate.log
2014-05-23 21:32 - 2013-10-31 13:54 - 00000000 __RSD () C:\Users\John-Nionto\Documents\McAfee-Tresore
2014-05-23 21:30 - 2014-05-23 21:20 - 00008317 _____ () C:\zoek-results.log
2014-05-23 21:30 - 2014-05-23 20:38 - 00013112 _____ () C:\Windows\PFRO.log
2014-05-23 21:30 - 2014-05-23 18:45 - 00000224 _____ () C:\Windows\setupact.log
2014-05-23 21:30 - 2013-10-31 14:43 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-23 21:30 - 2013-10-30 20:26 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-23 21:30 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-23 21:28 - 2014-05-23 21:19 - 00000000 ____D () C:\zoek_backup
2014-05-23 21:28 - 2013-10-30 15:16 - 00000000 ____D () C:\Users\John-Nionto
2014-05-23 21:19 - 2014-05-23 21:29 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-23 21:18 - 2014-05-23 21:18 - 01285120 _____ () C:\Users\John-Nionto\Desktop\zoek.exe
2014-05-23 21:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system
2014-05-23 21:13 - 2014-05-23 21:13 - 00011410 _____ () C:\Users\John-Nionto\Desktop\mama.txt
2014-05-23 21:13 - 2014-05-17 15:08 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\22736
2014-05-23 21:13 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini
2014-05-23 21:02 - 2013-10-30 20:26 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-23 21:01 - 2014-05-23 21:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-23 21:00 - 2014-05-23 21:00 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-23 21:00 - 2014-05-23 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-23 21:00 - 2014-05-23 21:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-23 21:00 - 2014-05-23 21:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-23 20:52 - 2014-05-23 20:52 - 00000983 _____ () C:\Users\John-Nionto\Desktop\JRT.txt
2014-05-23 20:42 - 2014-05-23 20:42 - 01016261 _____ (Thisisu) C:\Users\John-Nionto\Desktop\JRT.exe
2014-05-23 20:42 - 2014-05-23 20:42 - 00000000 ____D () C:\Windows\ERUNT
2014-05-23 20:40 - 2014-05-23 20:40 - 00002161 _____ () C:\Users\John-Nionto\Desktop\Adw.txt
2014-05-23 20:37 - 2014-05-17 16:00 - 00000000 ____D () C:\AdwCleaner
2014-05-23 19:38 - 2013-10-30 17:00 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\PMB Files
2014-05-23 18:47 - 2013-10-30 17:39 - 00000000 ____D () C:\Program Files (x86)\NosTale(DE)
2014-05-23 18:45 - 2014-05-23 18:45 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-23 18:45 - 2013-11-16 21:04 - 00001652 _____ () C:\Windows\Sandboxie.ini
2014-05-22 21:39 - 2014-05-22 21:39 - 00030052 _____ () C:\ComboFix.txt
2014-05-22 21:39 - 2014-05-22 21:08 - 00000000 ____D () C:\Qoobox
2014-05-22 21:38 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-22 21:37 - 2014-05-22 21:08 - 00000000 ____D () C:\Windows\erdnt
2014-05-22 21:36 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-22 21:15 - 2009-07-14 04:34 - 59768832 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-05-22 21:15 - 2009-07-14 04:34 - 25165824 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-05-22 21:15 - 2009-07-14 04:34 - 00786432 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-05-22 21:15 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-05-22 21:15 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-05-22 21:04 - 2014-05-22 21:04 - 05200426 ____R (Swearware) C:\Users\John-Nionto\Desktop\ComboFix.exe
2014-05-22 21:02 - 2014-05-22 21:01 - 05200426 _____ (Swearware) C:\Users\John-Nionto\Downloads\ComboFix.exe
2014-05-21 20:14 - 2014-05-21 20:13 - 00033958 _____ () C:\Users\John-Nionto\Downloads\Addition.txt
2014-05-21 20:14 - 2014-05-21 20:12 - 00052458 _____ () C:\Users\John-Nionto\Downloads\FRST.txt
2014-05-21 20:12 - 2014-05-21 20:12 - 02067456 _____ (Farbar) C:\Users\John-Nionto\Downloads\FRST64.exe
2014-05-21 20:08 - 2014-05-17 15:34 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\uTorrent
2014-05-20 23:01 - 2014-05-20 23:01 - 01326389 _____ () C:\Users\John-Nionto\Downloads\adwcleaner_3.210.exe
2014-05-20 22:07 - 2014-05-19 22:48 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2014-05-20 20:54 - 2014-05-20 20:54 - 00000000 ____D () C:\Users\John-Nionto\Downloads\Minecraft 1.6.4 by TeamExtremeMc.com
2014-05-20 19:32 - 2014-01-04 01:38 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-20 19:31 - 2014-05-20 19:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-05-20 19:30 - 2014-05-20 19:30 - 00000000 ____D () C:\Program Files\ZappAddon
2014-05-20 19:30 - 2014-05-20 19:30 - 00000000 ____D () C:\Program Files (x86)\ZappAddon
2014-05-20 19:30 - 2014-05-20 19:30 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-05-20 19:18 - 2014-05-20 19:18 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\Security System 2
2014-05-20 19:13 - 2014-05-17 23:29 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\.minecraft
2014-05-20 18:23 - 2013-10-30 17:00 - 00000000 ____D () C:\ProgramData\PMB Files
2014-05-19 23:07 - 2014-05-19 23:07 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\LavasoftStatistics
2014-05-19 22:52 - 2014-05-19 22:52 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-05-19 22:46 - 2014-05-19 22:46 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-05-19 22:09 - 2014-05-19 22:09 - 01727624 _____ () C:\Users\John-Nionto\Downloads\Adaware_Installer_11.1.5354.exe
2014-05-19 16:46 - 2014-05-20 20:50 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{f64c1459-b911-4fd8-a74e-36a496bf26e3}Gw64.sys
2014-05-18 22:35 - 2014-05-18 22:35 - 00000000 _____ () C:\autoexec.bat
2014-05-18 22:34 - 2014-05-18 22:34 - 00003362 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
2014-05-18 22:34 - 2014-05-18 22:34 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-05-18 22:34 - 2014-05-18 22:34 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-05-18 22:32 - 2014-05-18 22:32 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\John-Nionto\Downloads\SpyHunter-Installer.exe
2014-05-18 22:01 - 2014-05-18 22:01 - 00675988 _____ () C:\Users\John-Nionto\Downloads\Minecraft.exe
2014-05-18 20:29 - 2014-05-18 00:33 - 1926612148 _____ () C:\Users\John-Nionto\Downloads\The Amazing Spider-Man 2 Rendered 720p H264 AC3 by koz.mp4
2014-05-18 00:06 - 2014-05-17 19:43 - 00000000 ____D () C:\Users\John-Nionto\Downloads\Max.Payne.2.The.Fall.Of.Max.Payne.PC.Game(djDEVASTATE™)
2014-05-17 21:05 - 2014-03-12 23:13 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-05-17 16:21 - 2014-05-17 15:54 - 00000000 ____D () C:\Users\John-Nionto\Downloads\The Amazing Spiderman 2 2014 NEW CAM XviD-HELLRAZ0R
2014-05-17 16:20 - 2013-10-30 15:36 - 00001432 _____ () C:\Users\John-Nionto\Desktop\Google Chrome.lnk
2014-05-17 16:01 - 2013-10-30 20:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-05-17 16:01 - 2013-10-30 15:16 - 00001007 _____ () C:\Users\John-Nionto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-17 15:49 - 2014-05-17 15:08 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\CrashDumps
2014-05-17 15:33 - 2014-05-17 15:33 - 01670992 _____ (BitTorrent Inc.) C:\Users\John-Nionto\Downloads\uTorrent_3.4.1_31139.exe
2014-05-17 15:07 - 2014-05-17 15:07 - 00003282 _____ () C:\Windows\System32\Tasks\GPUpdate
2014-05-17 15:07 - 2014-05-17 15:07 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\wi_upd
2014-05-17 15:07 - 2014-05-17 15:07 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\GetPrivate
2014-05-16 16:36 - 2013-10-31 13:53 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-05-16 12:38 - 2013-10-30 15:16 - 00000000 ___RD () C:\Users\John-Nionto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 12:38 - 2013-10-30 15:16 - 00000000 ___RD () C:\Users\John-Nionto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 12:34 - 2014-04-30 23:25 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 12:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-15 22:34 - 2013-10-30 16:42 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-15 22:34 - 2013-10-30 16:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 22:53 - 2013-12-23 17:59 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\Skype
2014-05-14 22:44 - 2014-05-14 22:43 - 00000000 ____D () C:\Users\John-Nionto\Desktop\USB-
2014-05-14 22:29 - 2014-05-13 22:12 - 00000000 ____D () C:\Users\John-Nionto\Desktop\projekt
2014-05-13 22:10 - 2014-05-13 22:10 - 00087489 _____ () C:\Users\John-Nionto\Downloads\lol.zip
2014-05-12 07:26 - 2014-05-23 21:00 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-23 21:00 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-23 21:00 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 17:57 - 2013-10-30 20:26 - 00004116 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-10 17:57 - 2013-10-30 20:26 - 00003864 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-09 08:14 - 2014-05-15 17:56 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 17:56 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 18:38 - 2014-05-07 22:36 - 00002292 _____ () C:\Users\John-Nionto\Documents\profile.conf
2014-05-08 17:54 - 2009-07-14 06:45 - 00276608 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-07 17:53 - 2013-10-30 15:54 - 00058448 _____ () C:\Users\John-Nionto\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-07 17:52 - 2014-05-07 17:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHARKOON Skiller
2014-05-07 17:52 - 2014-05-07 17:52 - 00000000 ____D () C:\Program Files (x86)\SHARKOON Skiller
2014-05-07 17:52 - 2013-10-30 16:43 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-07 17:51 - 2014-05-07 17:51 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\InstallShield
2014-05-07 17:49 - 2014-05-07 17:49 - 00018628 _____ () C:\Windows\unins000.dat
2014-05-07 17:49 - 2014-05-07 17:49 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\MingGuan
2014-05-07 17:49 - 2014-05-07 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drakonia Black
2014-05-07 17:49 - 2014-05-07 17:49 - 00000000 ____D () C:\Program Files (x86)\Drakonia Configurator
2014-05-07 17:48 - 2014-05-07 17:49 - 01192533 _____ () C:\Windows\unins000.exe
2014-05-06 06:40 - 2014-05-15 22:35 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 22:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 22:35 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 22:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 22:35 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 22:35 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-05 22:21 - 2014-05-01 19:39 - 00000000 ____D () C:\Users\John-Nionto\Documents\Camtasia Studio
2014-05-05 22:19 - 2014-05-01 21:58 - 00004608 _____ () C:\Users\John-Nionto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-05-05 21:54 - 2014-05-05 21:54 - 00146742 _____ () C:\Users\John-Nionto\Downloads\bogi Eq2.bmp
2014-05-05 21:54 - 2014-05-05 21:54 - 00146742 _____ () C:\Users\John-Nionto\Downloads\bogi Eq2 (1).bmp
2014-05-01 21:56 - 2014-05-01 21:56 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\TechSmith
2014-05-01 21:54 - 2014-05-01 21:54 - 00000936 _____ () C:\Users\Public\Desktop\GPU Temp.lnk
2014-05-01 21:53 - 2014-05-01 21:53 - 00929416 _____ (CNET Download.com) C:\Users\John-Nionto\Downloads\cbsidlm-cbsi188-GPU_Temp-ORG-75593083.exe
2014-05-01 19:39 - 2014-05-01 19:39 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00001168 _____ () C:\Users\Public\Desktop\Camtasia Studio 8.lnk
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\ProgramData\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\ProgramData\regid.1995-08.com.techsmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\Program Files (x86)\TechSmith
2014-05-01 19:38 - 2014-05-01 19:38 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-01 19:33 - 2014-05-01 19:25 - 251749736 _____ () C:\Users\John-Nionto\Downloads\camtasiade_8.1.2.exe
2014-05-01 19:32 - 2014-05-01 19:32 - 00188736 _____ () C:\Users\John-Nionto\Downloads\CoreTemp_64bit_0.99.5.27_PCMASTERS.DE.rar
2014-04-27 18:43 - 2014-01-04 01:38 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-27 18:34 - 2014-04-27 18:34 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-27 18:34 - 2014-04-27 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-27 18:23 - 2014-04-27 18:23 - 00000000 ____D () C:\ProgramData\ATI
2014-04-26 23:49 - 2014-04-26 23:49 - 00061432 _____ () C:\Windows\SysWOW64\CCCInstall_201404262349070571.log
2014-04-26 23:49 - 2014-04-26 23:49 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-04-26 23:49 - 2013-10-30 16:05 - 00000000 ____D () C:\ProgramData\AMD
2014-04-26 23:48 - 2014-04-26 23:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-04-26 23:48 - 2013-10-30 16:01 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-04-26 23:44 - 2014-03-21 14:15 - 00000000 ____D () C:\AMD
2014-04-26 23:36 - 2014-04-26 23:28 - 295347968 _____ (AMD Inc.) C:\Users\John-Nionto\Downloads\14-4-win7-win8-win8.1-64-dd-ccc-whql.exe
2014-04-23 17:15 - 2014-04-23 17:11 - 00000000 ____D () C:\Fraps
2014-04-23 17:11 - 2014-04-23 17:11 - 00000562 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-04-23 17:11 - 2014-04-23 17:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-04-23 16:59 - 2014-04-23 16:59 - 00000000 __SHD () C:\Users\John-Nionto\AppData\Local\EmieUserList
2014-04-23 16:59 - 2014-04-23 16:59 - 00000000 __SHD () C:\Users\John-Nionto\AppData\Local\EmieSiteList
2014-04-23 16:53 - 2014-04-23 16:53 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\Sony
2014-04-23 16:53 - 2014-04-23 16:53 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\Sony
2014-04-23 16:51 - 2014-04-20 19:09 - 00000000 ____D () C:\Users\John-Nionto\AppData\Roaming\TS3Client
2014-04-23 16:46 - 2014-04-23 16:46 - 00000000 ____D () C:\Users\John-Nionto\AppData\Local\Ashampoo
2014-04-23 16:41 - 2014-04-23 16:41 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-04-23 16:41 - 2014-04-23 16:40 - 10488072 _____ (Ashampoo GmbH & Co. KG ) C:\Users\John-Nionto\Downloads\ashampoo_media_sync_e1.0.2_sm.exe
Some content of TEMP:
====================
C:\Users\John-Nionto\AppData\Local\Temp\GPUpd.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-15 18:30
==================== End Of Log ============================ --- --- ---
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-05-2014
Ran by John-Nionto at 2014-05-23 21:38:37
Running from C:\Users\John-Nionto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DOVTFDF9
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
==================== Installed Programs ======================
Aladdin (HKLM-x32\...\Aladdin) (Version: - )
AMD Accelerated Video Transcoding (Version: 13.30.100.40417 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{6119B3A6-3603-9695-0398-CDF2AF0A13F8}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden
AMD Media Foundation Decoders (Version: 1.0.81122.1054 - Advanced Micro Devices, Inc.) Hidden
AMD Steady Video Plug-In (Version: 2.07.0000 - AMD) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden
AVM FRITZ!DSL (HKLM-x32\...\{2457326B-C110-40C3-89B0-889CC913871A}) (Version: 2.04.02 - AVM Berlin)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: - AVM Berlin)
Camtasia Studio 8 (HKLM-x32\...\{F5C9BE9A-04C3-4A72-8CD0-BB67C722D608}) (Version: 8.1.2.1344 - TechSmith Corporation)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform)
Drakonia Black (HKLM-x32\...\{2EAD3327-2F92-455F-A675-E5CC4980B67A}}_is1) (Version: - )
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Free YouTube to MP3 Converter version 3.12.32.327 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.32.327 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
GPU Temp version 1.0 (HKLM-x32\...\{8C8711FD-0FC8-4801-B33E-ED19BB0350B1}_is1) (Version: 1.0 - gputemp.com)
HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.5.2 - www.leaguereplays.com)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
McAfee Total Protection (HKLM-x32\...\MSC) (Version: 12.8.957 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Moorhuhn Remake (HKLM-x32\...\{52210D57-0B1F-4681-90DD-8659DF4BCC40}) (Version: 1.00.0000 - )
Moorhuhn WE AYCS (HKLM-x32\...\{F92CDFEB-DB96-4589-B88C-BE181D153445}) (Version: - )
Nostale(DE) (HKLM-x32\...\NosTale(DE)_is1) (Version: - Gameforge 4D GmbH)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
Protegere (HKLM-x32\...\Protegere) (Version: - )
Raptr (HKLM-x32\...\Raptr) (Version: - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6959 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{17528CE4-C333-48FB-A9E4-D841E795CDCE}) (Version: 3.0.23.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 3.0.23.0 - Renesas Electronics Corporation) Hidden
Sandboxie 4.06 (64-bit) (HKLM\...\Sandboxie) (Version: 4.06 - Sandboxie Holdings, LLC)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SHARKOON Skiller (HKLM-x32\...\{91C25547-9534-41A5-823A-1E54BA16EA3F}) (Version: 1.00.0000 - )
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.018 - MSI)
System Update kb70007 (x32 Version: 1.0.0 - MSR) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WinRAR 5.00 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
==================== Restore Points =========================
07-05-2014 15:51:53 Installiert SHARKOON Skiller
07-05-2014 15:52:18 Gerätetreiber-Paketinstallation: Sharkoon Eingabegeräte (Human Interface Devices)
15-05-2014 20:33:00 Windows Update
18-05-2014 20:34:28 Installed SpyHunter
19-05-2014 20:47:01 AA11
19-05-2014 20:51:54 Removed SpyHunter
20-05-2014 17:32:36 Installed Java 7 Update 10
20-05-2014 17:34:31 Removed Java 7 Update 10
20-05-2014 20:05:56 AA11
22-05-2014 19:08:48 ComboFix created restore point
23-05-2014 19:20:53 zoek.exe restore point
==================== Hosts content: ==========================
2009-07-14 04:34 - 2014-05-22 21:36 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {4C51890B-70FB-4725-A20A-8C1EC924B94B} - \SystemSockets\SystemSockets No Task File <==== ATTENTION
Task: {55AAF4C6-CB07-482C-9922-0A9297A48F33} - \AmiUpdXp No Task File <==== ATTENTION
Task: {6239C1DA-95CE-4B31-BFC4-DC05EBF9E14C} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe
Task: {6826228D-444D-4E39-B345-F6DFE5611172} - \UpdaterEX No Task File <==== ATTENTION
Task: {6C637C2F-0D57-4B0B-8D93-B99C8E9EC86F} - \Browser Updater\Zapp Browser Updater No Task File <==== ATTENTION
Task: {A2F90510-6D8C-43E2-A24C-15EFA1A93F1A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-30] (Google Inc.)
Task: {A959EC32-568B-40F7-A9FF-BB3B4752E88F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd)
Task: {B2D93DDC-57E7-4D9D-9097-69EAE0D6A5CB} - System32\Tasks\GPUpdate => C:\Users\John-Nionto\AppData\Roaming\GetPrivate\gp_upd.exe [2014-05-17] ()
Task: {F8E9BEF1-F378-465B-A519-16CC716E47B6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-30] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-04-17 22:29 - 2014-04-17 22:29 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-05-07 17:49 - 2013-10-29 14:49 - 00248832 _____ () C:\Program Files (x86)\Drakonia Configurator\hid.exe
2014-05-07 17:49 - 2013-06-26 17:01 - 00240640 _____ () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
2014-04-17 22:29 - 2014-04-17 22:29 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-05-23 21:15 - 2014-04-30 02:08 - 01135104 _____ () C:\Program Files (x86)\Steam\libavcodec-55.dll
2014-04-23 15:45 - 2014-04-30 02:08 - 00471552 _____ () C:\Program Files (x86)\Steam\libavutil-53.dll
2014-05-23 21:15 - 2014-04-30 02:08 - 00404992 _____ () C:\Program Files (x86)\Steam\libavformat-55.dll
2014-01-09 19:47 - 2014-04-30 02:08 - 00340992 _____ () C:\Program Files (x86)\Steam\libavresample-1.dll
2013-10-24 10:45 - 2014-05-17 03:36 - 00756224 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2014-05-23 21:15 - 2014-04-29 02:37 - 02198720 _____ () C:\Program Files (x86)\Steam\video.dll
2014-05-23 21:15 - 2014-04-29 02:37 - 00519168 _____ () C:\Program Files (x86)\Steam\libswscale-2.dll
2013-10-30 12:25 - 2014-05-21 19:39 - 01145536 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2013-10-23 13:07 - 2014-05-02 01:35 - 20628160 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2013-06-14 16:49 - 2013-06-15 01:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll
2013-06-14 16:49 - 2013-06-15 01:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll
2013-06-14 16:49 - 2013-06-15 01:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll
2014-05-07 17:49 - 2013-01-15 17:06 - 00061952 _____ () C:\Program Files (x86)\Drakonia Configurator\HidDevice.dll
2014-05-07 17:49 - 2013-11-05 16:31 - 00249856 _____ () C:\Program Files (x86)\Drakonia Configurator\language.dll
2010-11-23 00:56 - 2010-11-23 00:56 - 00087040 _____ () C:\Program Files (x86)\Raptr\_ctypes.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00043008 _____ () C:\Program Files (x86)\Raptr\_socket.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00805376 _____ () C:\Program Files (x86)\Raptr\_ssl.pyd
2012-06-22 23:53 - 2012-06-22 23:53 - 05812736 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd
2012-06-22 23:24 - 2012-06-22 23:24 - 00067584 _____ () C:\Program Files (x86)\Raptr\sip.pyd
2012-06-22 23:39 - 2012-06-22 23:39 - 01662464 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtCore.pyd
2012-06-22 23:55 - 2012-06-22 23:55 - 00494592 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtNetwork.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00096256 _____ () C:\Program Files (x86)\Raptr\win32api.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00110592 _____ () C:\Program Files (x86)\Raptr\pywintypes26.dll
2010-11-23 00:56 - 2010-11-23 00:56 - 00324608 _____ () C:\Program Files (x86)\Raptr\PIL._imaging.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00356864 _____ () C:\Program Files (x86)\Raptr\_hashlib.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00036352 _____ () C:\Program Files (x86)\Raptr\win32process.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00111104 _____ () C:\Program Files (x86)\Raptr\win32file.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00124928 _____ () C:\Program Files (x86)\Raptr\_elementtree.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00127488 _____ () C:\Program Files (x86)\Raptr\pyexpat.pyd
2012-02-06 22:28 - 2012-02-06 22:28 - 00031744 _____ () C:\Program Files (x86)\Raptr\Crypto.Cipher.AES.pyd
2012-02-06 22:28 - 2012-02-06 22:28 - 00010752 _____ () C:\Program Files (x86)\Raptr\Crypto.Random.OSRNG.winrandom.pyd
2012-02-06 22:28 - 2012-02-06 22:28 - 00011264 _____ () C:\Program Files (x86)\Raptr\Crypto.Util._counter.pyd
2011-05-10 21:01 - 2011-05-10 21:01 - 00030208 _____ () C:\Program Files (x86)\Raptr\simplejson._speedups.pyd
2012-06-22 23:59 - 2012-06-22 23:59 - 00313856 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtWebKit.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00044544 _____ () C:\Program Files (x86)\Raptr\_sqlite3.pyd
2011-02-15 20:17 - 2011-02-15 20:17 - 00417501 _____ () C:\Program Files (x86)\Raptr\sqlite3.dll
2010-11-23 00:56 - 2010-11-23 00:56 - 00354304 _____ () C:\Program Files (x86)\Raptr\pythoncom26.dll
2010-11-23 00:57 - 2010-11-23 00:57 - 00016384 _____ () C:\Program Files (x86)\Raptr\win32trace.pyd
2010-11-23 00:57 - 2010-11-23 00:57 - 00167936 _____ () C:\Program Files (x86)\Raptr\win32gui.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00009216 _____ () C:\Program Files (x86)\Raptr\winsound.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00010240 _____ () C:\Program Files (x86)\Raptr\select.pyd
2010-11-23 00:56 - 2010-11-23 00:56 - 00583680 _____ () C:\Program Files (x86)\Raptr\unicodedata.pyd
2013-11-21 02:05 - 2013-11-21 02:05 - 00256000 _____ () C:\Program Files (x86)\Raptr\amd_ags.dll
2010-11-23 00:57 - 2010-11-23 00:57 - 00141312 _____ () C:\Program Files (x86)\Raptr\gobject._gobject.pyd
2012-10-27 09:53 - 2012-10-27 09:53 - 02717595 _____ () C:\Program Files (x86)\Raptr\heliotrope._purple.pyd
2011-02-15 20:17 - 2011-02-15 20:17 - 01213633 _____ () C:\Program Files (x86)\Raptr\libxml2-2.dll
2010-11-23 01:06 - 2010-11-23 01:06 - 00055808 _____ () C:\Program Files (x86)\Raptr\zlib1.dll
2013-05-10 01:52 - 2013-05-10 01:52 - 00495680 _____ () C:\Program Files (x86)\Raptr\plugins\libaim.dll
2013-05-10 01:52 - 2013-05-10 01:52 - 01183699 _____ () C:\Program Files (x86)\Raptr\liboscar.dll
2013-05-10 01:52 - 2013-05-10 01:52 - 00483306 _____ () C:\Program Files (x86)\Raptr\plugins\libicq.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00655356 _____ () C:\Program Files (x86)\Raptr\plugins\libirc.dll
2013-05-03 20:56 - 2013-05-03 20:56 - 01306387 _____ () C:\Program Files (x86)\Raptr\plugins\libmsn.dll
2013-05-03 20:56 - 2013-05-03 20:56 - 00565461 _____ () C:\Program Files (x86)\Raptr\plugins\libxmpp.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 01640221 _____ () C:\Program Files (x86)\Raptr\libjabber.dll
2013-05-03 20:56 - 2013-05-03 20:56 - 00506276 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoo.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 01053730 _____ () C:\Program Files (x86)\Raptr\libymsg.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00497782 _____ () C:\Program Files (x86)\Raptr\plugins\libyahoojp.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00603326 _____ () C:\Program Files (x86)\Raptr\plugins\ssl-nss.dll
2013-05-03 20:57 - 2013-05-03 20:57 - 00474199 _____ () C:\Program Files (x86)\Raptr\plugins\ssl.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/23/2014 09:32:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/23/2014 09:16:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17041 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 72c
Startzeit: 01cf76bb57b4f606
Endzeit: 31
Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe
Berichts-ID: c2241d08-e2ae-11e3-904b-bc05430e35eb
Error: (05/23/2014 09:16:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (05/23/2014 09:30:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (05/23/2014 09:30:53 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.
Error: (05/23/2014 09:30:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AODDriver4.3" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/23/2014 09:30:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AODDriver4.3" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/23/2014 09:30:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "SpyHunter 4 Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/23/2014 09:28:07 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (05/23/2014 09:28:06 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (05/23/2014 09:28:06 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (05/23/2014 09:28:05 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (05/23/2014 09:28:04 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Microsoft Office Sessions:
=========================
Error: (05/23/2014 09:32:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (05/23/2014 09:16:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.1704172c01cf76bb57b4f60631C:\Program Files\Internet Explorer\iexplore.exec2241d08-e2ae-11e3-904b-bc05430e35eb
Error: (05/23/2014 09:16:28 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
===================================
Date: 2014-05-22 21:14:24.428
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-05-22 21:14:24.397
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 27%
Total physical RAM: 8140.05 MB
Available physical RAM: 5886.9 MB
Total Pagefile: 16278.29 MB
Available Pagefile: 13763.66 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.41 GB) (Free:847.5 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: B198A783)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |