Code:
# AdwCleaner v3.305 - Bericht erstellt am 15/08/2014 um 14:41:20
# Aktualisiert 14/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Lupus - LUPUS-PC
# Gestartet von : C:\Users\Lupus\Downloads\adwcleaner_3.305.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : globalUpdate
Dienst Gefunden : globalUpdatem
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Lupus\AppData\Roaming\Mozilla\Firefox\Profiles\5lodf5hy.default\searchplugins\trovi-search.xml
Ordner Gefunden : C:\Program Files (x86)\globalUpdate
Ordner Gefunden : C:\Program Files (x86)\HDCinemaPlus1.6
Ordner Gefunden : C:\Users\Lupus\AppData\Local\DownloadGuide
Ordner Gefunden : C:\Users\Lupus\AppData\Local\globalUpdate
Ordner Gefunden : C:\Users\Lupus\AppData\Local\Temp\OCS
***** [ Tasks ] *****
Task Gefunden : globalUpdateUpdateTaskMachineCore
Task Gefunden : globalUpdateUpdateTaskMachineUA
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\HDCinemaPlus1.6
Schlüssel Gefunden : HKCU\Software\GlobalUpdate
Schlüssel Gefunden : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\GlobalUpdate
Schlüssel Gefunden : [x64] HKCU\Software\InstalledBrowserExtensions
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622052248}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0060548.BHO
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0060548.BHO.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0060548.Sandbox
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CrossriderApp0060548.Sandbox.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655055548}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666056648}
Schlüssel Gefunden : HKLM\Software\GlobalUpdate
Schlüssel Gefunden : HKLM\Software\HDCinemaPlus1.6
Schlüssel Gefunden : HKLM\Software\InstalledBrowserExtensions
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622052248}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655055548}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666056648}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\Lupus\AppData\Roaming\Mozilla\Firefox\Profiles\5lodf5hy.default\prefs.js ]
Zeile gefunden : user_pref("extensions.crossrider.bic", "14749041147e3f3d0cec46781c135673");
*************************
AdwCleaner[R0].txt - [8250 octets] - [15/08/2014 14:41:20]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [8310 octets] ########## Code:
# AdwCleaner v3.305 - Bericht erstellt am 15/08/2014 um 14:42:15
# Aktualisiert 14/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Lupus - LUPUS-PC
# Gestartet von : C:\Users\Lupus\Downloads\adwcleaner_3.305.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : globalUpdate
[#] Dienst Gelöscht : globalUpdatem
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\HDCinemaPlus1.6
Ordner Gelöscht : C:\Users\Lupus\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Lupus\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Lupus\AppData\Local\Temp\OCS
Datei Gelöscht : C:\Users\Lupus\AppData\Roaming\Mozilla\Firefox\Profiles\5lodf5hy.default\searchplugins\trovi-search.xml
***** [ Tasks ] *****
Task Gelöscht : globalUpdateUpdateTaskMachineCore
Task Gelöscht : globalUpdateUpdateTaskMachineUA
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060548.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060548.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060548.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060548.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622052248}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655055548}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666056648}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622052248}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655055548}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666056648}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\HDCinemaPlus1.6
Schlüssel Gelöscht : HKLM\Software\GlobalUpdate
Schlüssel Gelöscht : HKLM\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\Software\HDCinemaPlus1.6
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7601.17514
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\Lupus\AppData\Roaming\Mozilla\Firefox\Profiles\5lodf5hy.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "14749041147e3f3d0cec46781c135673");
*************************
AdwCleaner[R0].txt - [8422 octets] - [15/08/2014 14:41:20]
AdwCleaner[S0].txt - [8043 octets] - [15/08/2014 14:42:15]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8103 octets] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.08.2014
Suchlauf-Zeit: 14:48:34
Logdatei:
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.15.05
Rootkit Datenbank: v2014.08.04.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Lupus
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 287004
Verstrichene Zeit: 7 Min, 48 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 5
PUP.Optional.HDCinemaPlus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HDCinemaPlus1.6, In Quarantäne, [9305f2d073086accfc9d0e34c143f808],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611051148}, In Quarantäne, [6d2b863c6714e452621104d3867ebb45],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611051148}, In Quarantäne, [6d2b863c6714e452621104d3867ebb45],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1814061760-1566638178-3755174951-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110611051148}, In Quarantäne, [6d2b863c6714e452621104d3867ebb45],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11111111-1111-1111-1111-110611051148}, In Quarantäne, [6d2b863c6714e452621104d3867ebb45],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 1
PUP.Optional.GlobalUpdate.A, C:\Users\Lupus\AppData\Local\Temp\comh.423778, In Quarantäne, [bbddf7cb691276c0f7896e6343bfc838],
Dateien: 17
PUP.Optional.OpenCandy, C:\Users\Lupus\Downloads\DAEMONToolsPro550-0388.exe, In Quarantäne, [a8f08042ee8d44f2ecaa3abcc143f60a],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-1, In Quarantäne, [0098883a89f26bcb230b657f6a9818e8],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-10, In Quarantäne, [8d0b2c96dba0d66087a706de36ccf907],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-11, In Quarantäne, [5543bd058dee62d430fe15cfb44e748c],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-2, In Quarantäne, [bade3d85314a8aac87a79351b052fe02],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-3, In Quarantäne, [9503932fcfac4beb57d7ad37fd05c13f],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-4, In Quarantäne, [d5c350729ddeee48bc72ab3971910cf4],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-5, In Quarantäne, [6e2a259d8bf0d462d658e7fdc53db54b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-5_user, In Quarantäne, [8a0e8e34205b3ef8b975a440a75b47b9],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-1.job, In Quarantäne, [5e3a5d652b5040f6e4c5330f60a47a86],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-10.job, In Quarantäne, [ff994a78700b43f35a4f4101699beb15],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-11.job, In Quarantäne, [f0a810b24a3148eed9d05ce6ae5652ae],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-2.job, In Quarantäne, [d4c431913546a5913871ae94ea1a6e92],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-3.job, In Quarantäne, [ceca348edc9f1b1b3f6aff4329db738d],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-4.job, In Quarantäne, [e5b3e2e075060c2a436683bf58ac7d83],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-5.job, In Quarantäne, [1c7c6f53334867cfaffaba88966e16ea],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\11af90c1-bfeb-47c4-a861-b5a0fe347702-5_user.job, In Quarantäne, [9afed5edbac1da5cf5b4de6449bb17e9],
Physische Sektoren: 0
(No malicious items detected)
(end)
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-08-2014
Ran by Lupus (administrator) on LUPUS-PC on 15-08-2014 15:03:50
Running from C:\Users\Lupus\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avanquest Software) C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(TeamSpeak Systems GmbH) C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671640 2014-04-10] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKU\S-1-5-21-1814061760-1566638178-3755174951-1000\...\Run: [uTorrent] => C:\Users\Lupus\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-07-17] (BitTorrent Inc.)
HKU\S-1-5-21-1814061760-1566638178-3755174951-1000\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466656 2014-05-23] (Sony)
HKU\S-1-5-21-1814061760-1566638178-3755174951-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3129560 2014-02-24] (Disc Soft Ltd)
HKU\S-1-5-21-1814061760-1566638178-3755174951-1000\...\MountPoints2: {0af1bdea-1a31-11e4-abda-94de8032ae0a} - E:\Startme.exe
HKU\S-1-5-21-1814061760-1566638178-3755174951-1000\...\MountPoints2: {e7ee520f-1e14-11e4-adb7-94de8032ae0a} - F:\Setup.exe
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xDFA71D02429CCF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {F7FC0F0A-EC95-44B7-8750-92B840848EB3} URL = https://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lupus\AppData\Roaming\Mozilla\Firefox\Profiles\5lodf5hy.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Lupus\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Lupus\AppData\Roaming\Mozilla\Firefox\Profiles\5lodf5hy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-07-09]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-09]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.) [File not signed]
S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2014-07-02] (Perfect World Entertainment Inc)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-09] (AVAST Software)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-07-17] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2014-07-17] ()
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-09] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-09] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-09] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-09] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-08-07] (Disc Soft Ltd)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-15 14:47 - 2014-08-15 15:02 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-15 14:47 - 2014-08-15 14:47 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-15 14:47 - 2014-08-15 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-15 14:47 - 2014-08-15 14:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-15 14:47 - 2014-08-15 14:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-15 14:47 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-15 14:47 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-15 14:47 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-15 14:46 - 2014-08-15 14:46 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lupus\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-15 14:40 - 2014-08-15 14:42 - 00000000 ____D () C:\AdwCleaner
2014-08-15 14:40 - 2014-08-15 14:40 - 01356107 _____ () C:\Users\Lupus\Downloads\adwcleaner_3.305.exe
2014-08-15 13:54 - 2014-08-15 15:03 - 00011189 _____ () C:\Users\Lupus\Downloads\FRST.txt
2014-08-15 13:54 - 2014-08-15 13:55 - 00033192 _____ () C:\Users\Lupus\Downloads\Addition.txt
2014-08-15 13:53 - 2014-08-15 15:03 - 00000000 ____D () C:\FRST
2014-08-15 13:53 - 2014-08-15 13:53 - 02100224 _____ (Farbar) C:\Users\Lupus\Downloads\FRST64.exe
2014-08-07 13:51 - 2014-08-07 13:51 - 00000000 ____D () C:\Users\Lupus\AppData\Local\SKIDROW
2014-08-07 13:48 - 2014-08-07 13:48 - 00002300 _____ () C:\Users\Public\Desktop\State of Decay - Lifeline.lnk
2014-08-07 13:48 - 2014-08-07 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Studios
2014-08-07 13:47 - 2014-08-07 13:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Studios
2014-08-07 13:46 - 2014-08-07 13:46 - 00001936 _____ () C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
2014-08-07 13:45 - 2014-08-07 13:46 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\DAEMON Tools Pro
2014-08-07 13:45 - 2014-08-07 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
2014-08-07 13:45 - 2014-08-07 13:45 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-08-07 13:45 - 2014-08-07 13:45 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Pro
2014-08-07 13:44 - 2014-08-07 13:46 - 00000000 ____D () C:\ProgramData\DAEMON Tools Pro
2014-08-07 12:55 - 2014-08-07 12:59 - 00000000 ____D () C:\Users\Lupus\Downloads\State.of.Decay.Lifeline-SKIDROW
2014-08-05 22:53 - 2014-08-05 22:53 - 00000222 _____ () C:\Users\Lupus\Desktop\Haegemonia The Solon Heritage.url
2014-08-05 22:53 - 2014-08-05 22:53 - 00000222 _____ () C:\Users\Lupus\Desktop\Haegemonia Legions of Iron.url
2014-08-03 12:42 - 2014-08-03 12:42 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-08-02 14:25 - 2014-08-02 14:25 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-08-02 14:25 - 2014-08-02 14:25 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2014-08-02 14:25 - 2014-08-02 14:25 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-08-02 14:24 - 2014-08-02 14:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2014-08-02 14:23 - 2014-08-02 14:23 - 00001190 _____ () C:\Users\Public\Desktop\aTube Catcher.lnk
2014-08-02 14:23 - 2014-08-02 14:23 - 00000049 _____ () C:\Windows\SysWOW64\ScrRecX.log
2014-08-02 14:23 - 2014-08-02 14:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
2014-08-02 14:23 - 2014-08-02 14:23 - 00000000 ____D () C:\Program Files (x86)\DsNET Corp
2014-08-02 14:23 - 2008-08-18 19:18 - 00077824 _____ (Fox Magic Software) C:\Windows\SysWOW64\fmcodec.DLL
2014-08-02 14:22 - 2014-08-02 14:22 - 16806776 _____ (DsNET Corp ) C:\Users\Lupus\Downloads\aTube7973_Catcher.exe
2014-08-02 13:45 - 2014-08-02 13:45 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-08-02 13:45 - 2014-08-02 13:45 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-08-02 13:35 - 2014-08-02 13:35 - 00000220 _____ () C:\Users\Lupus\Desktop\Uplink.url
2014-08-02 13:24 - 2014-08-02 13:31 - 00000000 ____D () C:\Users\Lupus\Desktop\Neuer Ordner
2014-08-02 13:24 - 2014-08-02 13:24 - 00000221 _____ () C:\Users\Lupus\Desktop\Hacker Evolution Duality.url
2014-08-02 13:23 - 2014-08-02 13:23 - 00000221 _____ () C:\Users\Lupus\Desktop\Hacker Evolution - Untold.url
2014-08-02 13:21 - 2014-08-02 13:25 - 00211996 _____ () C:\Windows\DPINST.LOG
2014-08-02 13:21 - 2014-08-02 13:21 - 00002102 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-08-02 13:21 - 2014-08-02 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-08-02 13:20 - 2014-08-02 13:20 - 00000221 _____ () C:\Users\Lupus\Desktop\Hacker Evolution.url
2014-08-02 13:20 - 2014-08-02 13:20 - 00000000 ____D () C:\ProgramData\Sony
2014-08-02 13:20 - 2014-08-02 13:20 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-07-30 17:16 - 2014-07-30 17:16 - 00000222 _____ () C:\Users\Lupus\Desktop\Beasts of Prey.url
2014-07-30 13:47 - 2014-07-30 13:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-28 16:20 - 2014-07-28 16:20 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler
2014-07-28 16:17 - 2014-07-28 16:17 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\TuneUp Software
2014-07-28 16:17 - 2014-07-28 16:17 - 00000000 ____D () C:\Users\Lupus\AppData\Local\TuneUp Software
2014-07-28 16:05 - 2014-07-28 16:20 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-07-28 16:04 - 2014-07-28 16:18 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-07-28 16:03 - 2014-07-28 16:04 - 28598072 _____ (TuneUp Software) C:\Users\Lupus\Downloads\TuneUpUtilities2014_de-DE.exe
2014-07-18 20:49 - 2014-07-18 20:49 - 00003190 _____ () C:\Windows\System32\Tasks\{72E1C06D-1628-447C-8783-F316868CCC07}
2014-07-18 16:30 - 2014-07-18 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-18 16:30 - 2014-07-11 03:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-18 16:30 - 2014-07-11 02:56 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-18 16:30 - 2014-07-11 02:56 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-18 16:30 - 2014-07-11 02:55 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-18 16:27 - 2014-07-18 16:30 - 00004220 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 16:26 - 2014-07-18 16:26 - 00918440 _____ (Oracle Corporation) C:\Users\Lupus\Downloads\jxpiinstall(1).exe
2014-07-18 13:51 - 2014-07-18 13:51 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\Nerd Kingdom
2014-07-18 13:35 - 2014-07-18 13:35 - 00000222 _____ () C:\Users\Lupus\Desktop\TUG.url
2014-07-18 12:46 - 2014-07-18 12:46 - 00000000 ____D () C:\Users\Lupus\Documents\TecmoKoei
2014-07-18 12:42 - 2014-07-18 12:42 - 00001707 _____ () C:\Users\Lupus\Desktop\Play Dynasty Warriors 8.lnk
2014-07-18 12:37 - 2014-07-18 12:42 - 00000000 ____D () C:\Games
2014-07-17 22:34 - 2014-07-17 23:26 - 00000000 ____D () C:\Users\Lupus\Downloads\Dynasty Warriors 8 Xtreme Legends PC game ^^nosTEAM^^
2014-07-17 22:31 - 2014-07-17 22:33 - 00000851 _____ () C:\Users\Lupus\Desktop\µTorrent.lnk
2014-07-17 22:31 - 2014-07-17 22:33 - 00000831 _____ () C:\Users\Lupus\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-07-17 22:29 - 2014-08-15 14:58 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\uTorrent
2014-07-17 14:45 - 2014-07-17 14:45 - 00000000 ____D () C:\Users\Lupus\Documents\My Games
2014-07-17 14:44 - 2014-07-17 14:44 - 02337865 _____ () C:\Windows\SysWOW64\pbsvc.exe
2014-07-17 14:44 - 2014-07-17 14:44 - 00107832 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-07-17 14:44 - 2014-07-17 14:44 - 00066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-07-17 12:45 - 2014-07-17 12:45 - 00000221 _____ () C:\Users\Lupus\Desktop\Tom Clancy's Rainbow Six Vegas 2.url
2014-07-16 00:13 - 2014-07-16 00:13 - 00000222 _____ () C:\Users\Lupus\Desktop\Robocraft.url
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-15 15:04 - 2014-08-15 13:54 - 00011189 _____ () C:\Users\Lupus\Downloads\FRST.txt
2014-08-15 15:03 - 2014-08-15 13:53 - 00000000 ____D () C:\FRST
2014-08-15 15:02 - 2014-08-15 14:47 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-15 15:02 - 2014-06-30 16:58 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-15 14:58 - 2014-07-17 22:29 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\uTorrent
2014-08-15 14:58 - 2014-06-30 16:48 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\TS3Client
2014-08-15 14:57 - 2010-11-21 05:47 - 00038912 _____ () C:\Windows\PFRO.log
2014-08-15 14:57 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\Performance
2014-08-15 14:57 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-15 14:57 - 2009-07-14 06:51 - 00028973 _____ () C:\Windows\setupact.log
2014-08-15 14:56 - 2014-06-30 15:54 - 00220607 _____ () C:\Windows\WindowsUpdate.log
2014-08-15 14:54 - 2014-06-30 16:18 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{B701F3FF-EBD0-4F52-B4BC-84CBFF403459}
2014-08-15 14:50 - 2009-07-14 06:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-15 14:50 - 2009-07-14 06:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-15 14:47 - 2014-08-15 14:47 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-15 14:47 - 2014-08-15 14:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-15 14:47 - 2014-08-15 14:47 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-15 14:47 - 2014-08-15 14:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-15 14:46 - 2014-08-15 14:46 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lupus\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-15 14:42 - 2014-08-15 14:40 - 00000000 ____D () C:\AdwCleaner
2014-08-15 14:40 - 2014-08-15 14:40 - 01356107 _____ () C:\Users\Lupus\Downloads\adwcleaner_3.305.exe
2014-08-15 14:19 - 2014-06-30 16:53 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-15 13:55 - 2014-08-15 13:54 - 00033192 _____ () C:\Users\Lupus\Downloads\Addition.txt
2014-08-15 13:53 - 2014-08-15 13:53 - 02100224 _____ (Farbar) C:\Users\Lupus\Downloads\FRST64.exe
2014-08-15 11:50 - 2011-04-12 09:43 - 00698688 _____ () C:\Windows\system32\perfh007.dat
2014-08-15 11:50 - 2011-04-12 09:43 - 00148828 _____ () C:\Windows\system32\perfc007.dat
2014-08-15 11:50 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-15 11:46 - 2014-07-09 16:36 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-14 17:18 - 2014-07-15 01:44 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\Skype
2014-08-07 13:51 - 2014-08-07 13:51 - 00000000 ____D () C:\Users\Lupus\AppData\Local\SKIDROW
2014-08-07 13:48 - 2014-08-07 13:48 - 00002300 _____ () C:\Users\Public\Desktop\State of Decay - Lifeline.lnk
2014-08-07 13:48 - 2014-08-07 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Studios
2014-08-07 13:47 - 2014-08-07 13:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Studios
2014-08-07 13:46 - 2014-08-07 13:46 - 00001936 _____ () C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
2014-08-07 13:46 - 2014-08-07 13:45 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\DAEMON Tools Pro
2014-08-07 13:46 - 2014-08-07 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
2014-08-07 13:46 - 2014-08-07 13:44 - 00000000 ____D () C:\ProgramData\DAEMON Tools Pro
2014-08-07 13:45 - 2014-08-07 13:45 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-08-07 13:45 - 2014-08-07 13:45 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Pro
2014-08-07 12:59 - 2014-08-07 12:55 - 00000000 ____D () C:\Users\Lupus\Downloads\State.of.Decay.Lifeline-SKIDROW
2014-08-07 11:57 - 2014-06-30 16:48 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client
2014-08-05 22:53 - 2014-08-05 22:53 - 00000222 _____ () C:\Users\Lupus\Desktop\Haegemonia The Solon Heritage.url
2014-08-05 22:53 - 2014-08-05 22:53 - 00000222 _____ () C:\Users\Lupus\Desktop\Haegemonia Legions of Iron.url
2014-08-03 12:42 - 2014-08-03 12:42 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-08-02 14:25 - 2014-08-02 14:25 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-08-02 14:25 - 2014-08-02 14:25 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2014-08-02 14:25 - 2014-08-02 14:25 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-08-02 14:25 - 2014-08-02 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2014-08-02 14:23 - 2014-08-02 14:23 - 00001190 _____ () C:\Users\Public\Desktop\aTube Catcher.lnk
2014-08-02 14:23 - 2014-08-02 14:23 - 00000049 _____ () C:\Windows\SysWOW64\ScrRecX.log
2014-08-02 14:23 - 2014-08-02 14:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
2014-08-02 14:23 - 2014-08-02 14:23 - 00000000 ____D () C:\Program Files (x86)\DsNET Corp
2014-08-02 14:22 - 2014-08-02 14:22 - 16806776 _____ (DsNET Corp ) C:\Users\Lupus\Downloads\aTube7973_Catcher.exe
2014-08-02 13:45 - 2014-08-02 13:45 - 00000000 ____D () C:\ProgramData\Sony Mobile
2014-08-02 13:45 - 2014-08-02 13:45 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-08-02 13:35 - 2014-08-02 13:35 - 00000220 _____ () C:\Users\Lupus\Desktop\Uplink.url
2014-08-02 13:31 - 2014-08-02 13:24 - 00000000 ____D () C:\Users\Lupus\Desktop\Neuer Ordner
2014-08-02 13:25 - 2014-08-02 13:21 - 00211996 _____ () C:\Windows\DPINST.LOG
2014-08-02 13:24 - 2014-08-02 13:24 - 00000221 _____ () C:\Users\Lupus\Desktop\Hacker Evolution Duality.url
2014-08-02 13:23 - 2014-08-02 13:23 - 00000221 _____ () C:\Users\Lupus\Desktop\Hacker Evolution - Untold.url
2014-08-02 13:21 - 2014-08-02 13:21 - 00002102 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-08-02 13:21 - 2014-08-02 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-08-02 13:20 - 2014-08-02 13:20 - 00000221 _____ () C:\Users\Lupus\Desktop\Hacker Evolution.url
2014-08-02 13:20 - 2014-08-02 13:20 - 00000000 ____D () C:\ProgramData\Sony
2014-08-02 13:20 - 2014-08-02 13:20 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-08-02 13:20 - 2014-06-30 16:12 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-31 21:22 - 2014-06-30 16:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-30 20:12 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-07-30 17:16 - 2014-07-30 17:16 - 00000222 _____ () C:\Users\Lupus\Desktop\Beasts of Prey.url
2014-07-30 13:47 - 2014-07-30 13:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-29 16:51 - 2014-06-30 15:57 - 00000000 ____D () C:\Users\Lupus\AppData\Local\VirtualStore
2014-07-28 23:09 - 2014-07-01 16:26 - 00000000 ____D () C:\Users\Lupus\AppData\Local\FirestormOS_x64
2014-07-28 16:20 - 2014-07-28 16:20 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler
2014-07-28 16:20 - 2014-07-28 16:05 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-07-28 16:18 - 2014-07-28 16:04 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-07-28 16:17 - 2014-07-28 16:17 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\TuneUp Software
2014-07-28 16:17 - 2014-07-28 16:17 - 00000000 ____D () C:\Users\Lupus\AppData\Local\TuneUp Software
2014-07-28 16:04 - 2014-07-28 16:03 - 28598072 _____ (TuneUp Software) C:\Users\Lupus\Downloads\TuneUpUtilities2014_de-DE.exe
2014-07-21 23:32 - 2014-07-10 18:57 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\Tunngle
2014-07-21 23:32 - 2014-07-10 18:57 - 00000000 ____D () C:\ProgramData\Tunngle
2014-07-18 20:49 - 2014-07-18 20:49 - 00003190 _____ () C:\Windows\System32\Tasks\{72E1C06D-1628-447C-8783-F316868CCC07}
2014-07-18 16:30 - 2014-07-18 16:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-18 16:30 - 2014-07-18 16:27 - 00004220 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 16:30 - 2014-06-30 17:56 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-18 16:30 - 2014-06-30 17:55 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-18 16:26 - 2014-07-18 16:26 - 00918440 _____ (Oracle Corporation) C:\Users\Lupus\Downloads\jxpiinstall(1).exe
2014-07-18 13:51 - 2014-07-18 13:51 - 00000000 ____D () C:\Users\Lupus\AppData\Roaming\Nerd Kingdom
2014-07-18 13:51 - 2014-06-30 16:34 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-18 13:35 - 2014-07-18 13:35 - 00000222 _____ () C:\Users\Lupus\Desktop\TUG.url
2014-07-18 12:46 - 2014-07-18 12:46 - 00000000 ____D () C:\Users\Lupus\Documents\TecmoKoei
2014-07-18 12:42 - 2014-07-18 12:42 - 00001707 _____ () C:\Users\Lupus\Desktop\Play Dynasty Warriors 8.lnk
2014-07-18 12:42 - 2014-07-18 12:37 - 00000000 ____D () C:\Games
2014-07-17 23:26 - 2014-07-17 22:34 - 00000000 ____D () C:\Users\Lupus\Downloads\Dynasty Warriors 8 Xtreme Legends PC game ^^nosTEAM^^
2014-07-17 22:34 - 2014-06-30 16:35 - 00000000 ____D () C:\Program Files (x86)\Raptr
2014-07-17 22:33 - 2014-07-17 22:31 - 00000851 _____ () C:\Users\Lupus\Desktop\µTorrent.lnk
2014-07-17 22:33 - 2014-07-17 22:31 - 00000831 _____ () C:\Users\Lupus\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-07-17 17:47 - 2014-07-01 14:30 - 00304562 _____ () C:\Windows\DirectX.log
2014-07-17 14:45 - 2014-07-17 14:45 - 00000000 ____D () C:\Users\Lupus\Documents\My Games
2014-07-17 14:44 - 2014-07-17 14:44 - 02337865 _____ () C:\Windows\SysWOW64\pbsvc.exe
2014-07-17 14:44 - 2014-07-17 14:44 - 00107832 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-07-17 14:44 - 2014-07-17 14:44 - 00066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-07-17 12:45 - 2014-07-17 12:45 - 00000221 _____ () C:\Users\Lupus\Desktop\Tom Clancy's Rainbow Six Vegas 2.url
2014-07-16 00:13 - 2014-07-16 00:13 - 00000222 _____ () C:\Users\Lupus\Desktop\Robocraft.url
Some content of TEMP:
====================
C:\Users\Lupus\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Lupus\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Lupus\AppData\Local\Temp\Quarantine.exe
C:\Users\Lupus\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Lupus\AppData\Local\Temp\SDShelEx-x64.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-15 12:16
==================== End Of Log ============================ --- --- --- |