BKA Virus Windows zerschossen Hatte diesen BKA Virus auf dem Rechner welchen ich schnell mit Malewarebytes entfernen konnte aber nun macht Windows Probleme erst war der BootMGR gelöscht welchen ich mit der Windows CD wiederherstellen musste nun bekomm ich folgende Fehler
Beim Start kommt erstmal das mein Windows erneut aktiviert werden muss welches immer fehlschlägt habs mit mehreren Orginalen Keys versucht
Danach kommen 3 rundll .cpp Fehler
Desktop hat nach dem Neustart immer ein Schwarzes Hintergrundbild
OTL log: Code:
OTL logfile created on: 22.01.2015 14:42:14 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
15,96 Gb Total Physical Memory | 13,21 Gb Available Physical Memory | 82,78% Memory free
31,91 Gb Paging File | 28,91 Gb Available in Paging File | 90,59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,76 Gb Total Space | 68,69 Gb Free Space | 14,75% Space Free | Partition Type: NTFS
Drive D: | 372,61 Gb Total Space | 336,64 Gb Free Space | 90,35% Space Free | Partition Type: NTFS
Drive E: | 4,19 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 127,99 Gb Total Space | 77,46 Gb Free Space | 60,52% Space Free | Partition Type: NTFS
Drive G: | 338,75 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015.01.22 14:33:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Downloads\OTL.exe
PRC - [2015.01.22 14:28:36 | 000,070,239 | ---- | M] (hxxp://www.ruby-lang.org/) -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\rubyw.exe
PRC - [2015.01.22 14:28:31 | 000,070,239 | ---- | M] (hxxp://www.ruby-lang.org/) -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\bin\rubyw.exe
PRC - [2015.01.18 20:48:51 | 008,817,658 | ---- | M] () -- C:\Programme\pia_manager\pia_manager.exe
PRC - [2015.01.17 03:11:45 | 000,338,032 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2015.01.14 05:19:01 | 000,389,744 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
PRC - [2014.12.13 01:13:07 | 002,531,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014.12.13 01:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014.11.12 00:38:32 | 000,184,320 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\pia_tray.exe
PRC - [2014.10.27 17:37:08 | 003,095,840 | ---- | M] (Nota Inc.) -- C:\Program Files (x86)\Gyazo\GyStation.exe
PRC - [2014.09.13 21:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2014.06.23 12:35:12 | 000,436,720 | ---- | M] (QIP.ru) -- C:\Users\Admin\AppData\Roaming\QipGuard\QipGuard.exe
PRC - [2014.02.20 21:32:04 | 001,553,688 | ---- | M] (Comfort Software Group) -- C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe
PRC - [2013.10.17 15:27:02 | 000,166,912 | ---- | M] () -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2013.09.16 11:18:28 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2013.09.16 11:17:42 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2013.08.07 13:24:00 | 000,287,592 | ---- | M] (Intel Corporation) -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2012.05.20 17:26:26 | 000,291,648 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2009.10.19 12:47:30 | 000,210,400 | ---- | M] () -- C:\Program Files (x86)\WebMoney Agent\wmagent.exe
========== Modules (No Company Name) ==========
MOD - [2015.01.22 14:28:42 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
MOD - [2015.01.22 14:28:40 | 000,126,976 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
MOD - [2015.01.22 14:28:40 | 000,087,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
MOD - [2015.01.22 14:28:40 | 000,036,352 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so
MOD - [2015.01.22 14:28:40 | 000,023,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so
MOD - [2015.01.22 14:28:40 | 000,016,384 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
MOD - [2015.01.22 14:28:40 | 000,009,216 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so
MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so
MOD - [2015.01.22 14:28:40 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so
MOD - [2015.01.22 14:28:40 | 000,008,192 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so
MOD - [2015.01.22 14:28:38 | 000,275,968 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so
MOD - [2015.01.22 14:28:38 | 000,069,120 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so
MOD - [2015.01.22 14:28:38 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so
MOD - [2015.01.22 14:28:38 | 000,015,360 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so
MOD - [2015.01.22 14:28:36 | 000,127,316 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\libffi-6.dll
MOD - [2015.01.22 14:28:36 | 000,118,784 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so
MOD - [2015.01.22 14:28:36 | 000,095,744 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
MOD - [2015.01.22 14:28:36 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\src\rgloader\rgloader193.mswin.so
MOD - [2015.01.22 14:28:36 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
MOD - [2015.01.22 14:28:36 | 000,083,968 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\bin\zlib1.dll
MOD - [2015.01.22 14:28:36 | 000,026,624 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
MOD - [2015.01.22 14:28:36 | 000,014,848 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
MOD - [2015.01.22 14:28:36 | 000,013,312 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
MOD - [2015.01.22 14:28:36 | 000,012,800 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
MOD - [2015.01.22 14:28:36 | 000,009,728 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
MOD - [2015.01.22 14:28:36 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr92BD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
MOD - [2015.01.22 14:28:33 | 000,126,976 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
MOD - [2015.01.22 14:28:33 | 000,095,744 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
MOD - [2015.01.22 14:28:33 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
MOD - [2015.01.22 14:28:33 | 000,087,552 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
MOD - [2015.01.22 14:28:33 | 000,016,384 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
MOD - [2015.01.22 14:28:33 | 000,014,848 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
MOD - [2015.01.22 14:28:33 | 000,013,312 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
MOD - [2015.01.22 14:28:33 | 000,012,800 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
MOD - [2015.01.22 14:28:33 | 000,009,728 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
MOD - [2015.01.22 14:28:33 | 000,009,216 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
MOD - [2015.01.22 14:28:33 | 000,008,704 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
MOD - [2015.01.22 14:28:32 | 000,127,316 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\bin\libffi-6.dll
MOD - [2015.01.22 14:28:31 | 000,094,208 | ---- | M] () -- C:\Users\Admin\AppData\Local\Temp\ocr7FE8.tmp\src\rgloader\rgloader193.mswin.so
MOD - [2015.01.18 20:48:51 | 008,817,658 | ---- | M] () -- C:\Programme\pia_manager\pia_manager.exe
MOD - [2015.01.17 03:11:44 | 003,925,104 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2015.01.14 05:19:02 | 003,347,056 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
MOD - [2015.01.14 05:19:02 | 000,158,832 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
MOD - [2015.01.14 05:19:02 | 000,023,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
MOD - [2014.11.12 00:38:39 | 000,059,904 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\zlib1.dll
MOD - [2014.11.12 00:38:34 | 001,234,944 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\libxml2.dll
MOD - [2014.11.12 00:38:34 | 001,198,592 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoFoundation.dll
MOD - [2014.11.12 00:38:34 | 000,815,104 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\khost.dll
MOD - [2014.11.12 00:38:34 | 000,642,048 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoNet.dll
MOD - [2014.11.12 00:38:34 | 000,511,488 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoXML.dll
MOD - [2014.11.12 00:38:34 | 000,290,816 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoUtil.dll
MOD - [2014.11.12 00:38:33 | 000,745,472 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\runtime\1.2.0.RC6d\CFLite.dll
MOD - [2014.11.12 00:38:32 | 000,344,064 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiui\1.2.0.RC6d\tiuimodule.dll
MOD - [2014.11.12 00:38:32 | 000,217,088 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiprocess\1.2.0.RC6d\tiprocessmodule.dll
MOD - [2014.11.12 00:38:32 | 000,184,320 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\pia_tray.exe
MOD - [2014.11.12 00:38:31 | 000,368,640 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tinetwork\1.2.0.RC6d\tinetworkmodule.dll
MOD - [2014.11.12 00:38:31 | 000,200,704 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tiapp\1.2.0.RC6d\tiappmodule.dll
MOD - [2014.11.12 00:38:31 | 000,180,224 | ---- | M] () -- C:\Programme\pia_manager\pia_tray\modules\tifilesystem\1.2.0.RC6d\tifilesystemmodule.dll
MOD - [2014.09.29 22:25:43 | 001,203,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.WorkflowServ#\ad9facc364268611cc4ca65f77caeddd\System.WorkflowServices.ni.dll
MOD - [2014.09.29 22:25:23 | 001,127,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\dbf07cb14b4dcc210cdf8b5d90a12a56\System.ServiceModel.Discovery.ni.dll
MOD - [2014.09.29 22:25:23 | 000,365,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\76a5d670ce969c0c65a905b7303d4bbf\System.ServiceModel.Routing.ni.dll
MOD - [2014.09.29 22:25:22 | 000,082,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\c3831eb95ccf3904bab81a97a9b08ed3\System.ServiceModel.Channels.ni.dll
MOD - [2014.09.29 22:25:15 | 001,388,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\52481fccddb053768631c640d5059d4b\System.ServiceModel.Activities.ni.dll
MOD - [2014.09.29 22:25:14 | 001,065,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9eac876f58a3ebca8878b8654efdc817\System.IdentityModel.ni.dll
MOD - [2014.09.29 22:25:13 | 017,919,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\250b525aa8c17327216e102569c0d766\System.ServiceModel.ni.dll
MOD - [2014.09.29 22:25:05 | 001,046,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\51c60db370e050d9cdcac17060aaac53\System.ServiceModel.Web.ni.dll
MOD - [2014.09.29 22:24:11 | 002,625,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\e9f8a45b1063d6c6a62718c88a5623d1\System.Runtime.Serialization.ni.dll
MOD - [2014.09.29 22:24:11 | 001,011,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\f3989d3e9cb8904e4edf23ede5adb6c1\System.Runtime.DurableInstancing.ni.dll
MOD - [2014.09.29 22:24:11 | 000,142,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\4d2a51c03b27e615ff9f1c430f2014ba\SMDiagnostics.ni.dll
MOD - [2014.09.29 22:23:53 | 001,776,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6\System.Xaml.ni.dll
MOD - [2014.09.29 22:21:37 | 013,006,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\17e020ae92d7fab33bcc1c98b25019d0\System.Windows.Forms.ni.dll
MOD - [2014.09.29 22:21:32 | 001,651,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6\System.Drawing.ni.dll
MOD - [2014.09.29 22:21:04 | 005,571,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d\System.Xml.ni.dll
MOD - [2014.09.29 22:21:02 | 000,973,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ac18c2dcd06bd2a0589bac94ccae5716\System.Configuration.ni.dll
MOD - [2014.09.29 22:21:01 | 007,025,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85\System.Core.ni.dll
MOD - [2014.09.29 22:20:57 | 009,000,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3\System.ni.dll
MOD - [2014.09.29 22:20:54 | 014,415,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll
MOD - [2014.08.10 15:40:22 | 000,065,792 | ---- | M] () -- C:\Programme\TortoiseSVN\bin\TortoiseStub32.dll
MOD - [2014.08.10 15:40:10 | 000,071,936 | ---- | M] () -- C:\Programme\TortoiseSVN\bin\libsasl32.dll
MOD - [2014.06.23 12:35:12 | 000,378,864 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\QipGuard\chrome.dll
MOD - [2009.10.19 12:47:30 | 000,210,400 | ---- | M] () -- C:\Program Files (x86)\WebMoney Agent\wmagent.exe
========== Services (SafeList) ==========
SRV:64bit: - [2012.12.11 11:00:52 | 000,027,768 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\SysNative\ViakaraokeSrv.exe -- (VIAKaraokeService)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2015.01.17 03:11:44 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015.01.14 16:04:13 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.12.13 01:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014.12.13 01:13:04 | 001,148,560 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV - [2014.12.13 01:13:03 | 019,823,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV - [2014.12.11 10:30:48 | 000,315,496 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014.11.07 13:02:56 | 000,331,776 | ---- | M] () [Auto | Stopped] -- C:\ProgramData\4519DF80.dot -- (Winmgmt)
SRV - [2014.10.14 20:33:28 | 000,174,600 | ---- | M] (Sandboxie Holdings, LLC) [Auto | Running] -- C:\Programme\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV - [2014.09.13 21:12:58 | 000,411,968 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2013.10.17 15:27:02 | 000,166,912 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2013.09.16 11:18:28 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2013.09.16 11:17:42 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2013.08.27 13:32:30 | 000,828,376 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV - [2013.08.27 13:32:14 | 000,747,520 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV - [2013.08.07 13:24:00 | 000,015,720 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Programme\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010.03.18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.11.18 23:05:00 | 000,065,536 | ---- | M] (CodeGear) [Auto | Running] -- C:\Program Files (x86)\Embarcadero\RAD Studio\7.0\bin\BSQLServer.exe -- (BlackfishSQL)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014.11.22 11:46:30 | 000,038,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2014.11.05 05:49:12 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:64bit: - [2014.09.29 21:27:28 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014.09.17 05:51:20 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2013.12.16 09:46:34 | 000,690,864 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:64bit: - [2013.10.17 15:27:02 | 000,036,928 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\htcnprot.sys -- (htcnprot)
DRV:64bit: - [2013.09.16 11:17:42 | 000,099,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
DRV:64bit: - [2013.08.22 09:40:24 | 000,040,664 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2013.08.07 13:23:46 | 000,644,968 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2013.08.07 13:23:46 | 000,028,008 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:64bit: - [2013.07.18 06:54:52 | 000,129,224 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2013.01.03 02:31:20 | 000,301,256 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xhcdrv.sys -- (xhcdrv)
DRV:64bit: - [2013.01.03 02:31:18 | 000,231,112 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ViaHub3.sys -- (VUSB3HUB)
DRV:64bit: - [2012.05.20 17:25:32 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012.05.20 17:25:32 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012.05.20 17:25:32 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2010.03.09 04:08:36 | 000,121,800 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HtcVComV64.sys -- (HtcVCom32)
DRV:64bit: - [2009.11.02 18:16:50 | 000,033,736 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys -- (HTCAND64)
DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 01:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2014.12.13 01:13:03 | 000,019,600 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV - [2014.10.14 20:33:28 | 000,185,352 | ---- | M] (Sandboxie Holdings, LLC) [Kernel | On_Demand | Running] -- C:\Programme\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 6F AD F2 47 00 D0 01 [binary data]
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-508827818-3852767440-971368910-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B6AC85730-7D0F-4de0-B3FA-21142DD85326%7D:2.8
FF - prefs.js..extensions.enabledAddons: %7B9c51bd27-6ed8-4000-a2bf-36cb95c0c947%7D:11.0.1
FF - prefs.js..extensions.enabledAddons: foxyproxy%40eric.h.jung:4.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:35.0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 35.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2014.09.29 20:15:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions
[2014.09.29 20:25:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\f\extensions
[2015.01.18 20:39:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions
[2014.09.29 21:01:58 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2015.01.18 20:39:13 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\pjn4xhgx.default\extensions\foxyproxy@eric.h.jung
[2014.12.09 10:42:07 | 002,551,632 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\firebug@software.joehewitt.com.xpi
[2014.11.08 23:14:43 | 000,080,872 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi
[2015.01.15 14:12:06 | 000,985,112 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.09.11 16:15:07 | 000,002,438 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\englische-ergebnisse.xml
[2014.09.11 16:15:07 | 000,002,916 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\gmx-suche.xml
[2014.09.11 16:15:07 | 000,002,457 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\lastminute.xml
[2014.09.11 16:15:07 | 000,005,729 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\pjn4xhgx.default\searchplugins\webde-suche.xml
[2015.01.17 03:11:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2015.01.17 03:11:45 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2015.01.22 13:05:36 | 000,000,000 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (no name) - {2193d8fb-a459-4acc-b40d-5cefd11384dc} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (WebMoneyAdvisorBHO) - {E7D2CB77-6E2D-4C1F-B485-D50506B9FA6B} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces)
O3 - HKLM\..\Toolbar: (WebMoney Advisor) - {405DFEAE-1D2F-4649-BE08-C92313C3E1CE} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces)
O3 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..\Toolbar\WebBrowser: (WebMoney Advisor) - {405DFEAE-1D2F-4649-BE08-C92313C3E1CE} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4:64bit: - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [wmagent.exe] C:\Program Files (x86)\WebMoney Agent\wmagent.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [Ditto] C:\Programme\Ditto\Ditto.exe ()
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [FreeAC] C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe (Comfort Software Group)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe (Nota Inc.)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [QIP Internet Guardian] C:\Users\Admin\AppData\Roaming\QipGuard\QipGuard.exe (QIP.ru)
O4 - HKU\S-1-5-21-508827818-3852767440-971368910-1000..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (Sandboxie Holdings, LLC)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range1 ([https] in Trusted sites)
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range2 ([http] in Trusted sites)
O15 - HKU\S-1-5-21-508827818-3852767440-971368910-1000\..Trusted Ranges: Range2 ([https] in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEE1F8C0-6F4D-4476-8933-97871E5E3032}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20:64bit: - HKLM Winlogon: UserInit - (userinit.exe) - File not found
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found
O29 - HKLM SecurityProviders - (credssp.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.07.14 12:08:10 | 000,000,043 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{15ff45c5-481d-11e4-a4ce-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{15ff45c5-481d-11e4-a4ce-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe -- [2009.07.14 12:08:10 | 000,111,880 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\{21ccffb3-47f5-11e4-95c6-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{21ccffb3-47f5-11e4-95c6-806e6f6e6963}\Shell\AutoRun\command - "" = E:\setup.exe -- [2009.07.14 12:08:10 | 000,111,880 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015.01.22 14:23:35 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015.01.22 14:04:48 | 000,040,664 | ---- | C] (The OpenVPN Project) -- C:\Windows\SysNative\drivers\tap0901.sys
[2015.01.17 03:11:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015.01.14 05:18:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2015.01.10 11:35:17 | 000,000,000 | ---D | C] -- C:\Users\Admin\cminstaller
[2015.01.04 21:44:02 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS
[2015.01.04 13:22:58 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Gyazo
[2015.01.04 13:22:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
[2015.01.04 13:22:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gyazo
[2015.01.03 15:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
[2015.01.03 15:17:10 | 000,000,000 | ---D | C] -- C:\Program Files\Sony
[2015.01.03 15:17:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2014.12.26 16:46:19 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2014.12.25 21:20:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Runtime Software
[2014.12.25 21:20:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Runtime Software
[2014.12.25 19:48:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2014.12.25 19:48:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft
[2014.12.25 19:48:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft
[2014.12.25 19:46:27 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft
[2014.11.23 19:08:02 | 000,755,269 | ---- | C] (CheatHappens) -- C:\Users\Admin\coh2-Spike1338.exe
[2 C:\Users\Admin\AppData\Local\*.tmp files -> C:\Users\Admin\AppData\Local\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015.01.22 14:28:30 | 000,001,684 | ---- | M] () -- C:\Windows\tasks\MQJGALU.job
[2015.01.22 14:28:30 | 000,001,340 | ---- | M] () -- C:\Windows\tasks\SYKWCLB.job
[2015.01.22 14:28:30 | 000,001,338 | ---- | M] () -- C:\Windows\tasks\FRVOIK.job
[2015.01.22 14:28:30 | 000,001,336 | ---- | M] () -- C:\Windows\tasks\FWWLD.job
[2015.01.22 14:28:30 | 000,001,334 | ---- | M] () -- C:\Windows\tasks\MQBB.job
[2015.01.22 14:28:30 | 000,001,330 | ---- | M] () -- C:\Windows\tasks\WF.job
[2015.01.22 14:28:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.01.22 14:28:11 | 4261,040,126 | -HS- | M] () -- C:\hiberfil.sys
[2015.01.22 14:26:06 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015.01.22 14:26:06 | 000,020,368 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015.01.22 14:04:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015.01.22 13:25:50 | 000,001,780 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2015.01.22 13:19:11 | 000,002,008 | -H-- | M] () -- C:\Users\Admin\Documents\Default.rdp
[2015.01.22 13:05:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2015.01.10 14:54:51 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2015.01.05 09:41:49 | 001,025,097 | ---- | M] () -- C:\Users\Admin\IMAG0189.jpg
[2015.01.04 21:51:02 | 000,000,842 | ---- | M] () -- C:\Users\Admin\Desktop\uploads.html
[2015.01.04 13:22:42 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\Gyazo GIF.lnk
[2015.01.04 13:22:41 | 000,000,988 | ---- | M] () -- C:\Users\Public\Desktop\Gyazo.lnk
[2015.01.03 15:23:17 | 000,002,576 | ---- | M] () -- C:\Users\Admin\Documents\Vegas Pro registrieren.htm
[2014.12.29 00:20:24 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.12.27 23:13:26 | 000,092,530 | ---- | M] () -- C:\Users\Admin\click_link.jpg
[2014.12.27 10:42:50 | 000,004,744 | ---- | M] () -- C:\Users\Admin\toprlz.png
[2014.12.27 10:42:50 | 000,000,132 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2014.12.26 14:42:33 | 395,306,822 | ---- | M] () -- C:\Users\Admin\unbenannt.st3
[2014.12.25 21:21:04 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\GetDataBack for NTFS.lnk
[2014.12.25 21:20:12 | 000,000,621 | ---- | M] () -- C:\Users\Admin\Last session Admin.prj
[2014.12.25 21:20:05 | 000,001,994 | ---- | M] () -- C:\Users\Public\Desktop\GetDataBack for FAT.lnk
[2014.12.25 20:51:45 | 000,000,009 | RHS- | M] () -- C:\wedaolu
[2014.12.25 19:48:34 | 000,001,435 | ---- | M] () -- C:\Users\Public\Desktop\Free Audio CD Burner.lnk
[2014.12.25 19:48:34 | 000,001,247 | ---- | M] () -- C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
[2 C:\Users\Admin\AppData\Local\*.tmp files -> C:\Users\Admin\AppData\Local\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015.01.10 14:54:51 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01009.Wdf
[2015.01.05 09:44:32 | 001,025,097 | ---- | C] () -- C:\Users\Admin\IMAG0189.jpg
[2015.01.04 21:51:02 | 000,000,842 | ---- | C] () -- C:\Users\Admin\Desktop\uploads.html
[2015.01.04 13:22:42 | 000,000,988 | ---- | C] () -- C:\Users\Public\Desktop\Gyazo GIF.lnk
[2015.01.04 13:22:41 | 000,000,988 | ---- | C] () -- C:\Users\Public\Desktop\Gyazo.lnk
[2014.12.27 23:13:24 | 000,092,530 | ---- | C] () -- C:\Users\Admin\click_link.jpg
[2014.12.27 10:42:48 | 000,004,744 | ---- | C] () -- C:\Users\Admin\toprlz.png
[2014.12.26 14:40:02 | 395,306,822 | ---- | C] () -- C:\Users\Admin\unbenannt.st3
[2014.12.26 14:39:05 | 000,000,274 | ---- | C] () -- C:\Users\Admin\DE.reg.x64.reg
[2014.12.25 21:21:04 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\GetDataBack for NTFS.lnk
[2014.12.25 21:20:12 | 000,000,621 | ---- | C] () -- C:\Users\Admin\Last session Admin.prj
[2014.12.25 21:20:05 | 000,001,994 | ---- | C] () -- C:\Users\Public\Desktop\GetDataBack for FAT.lnk
[2014.12.25 20:51:45 | 000,000,009 | RHS- | C] () -- C:\wedaolu
[2014.12.25 19:48:34 | 000,001,435 | ---- | C] () -- C:\Users\Public\Desktop\Free Audio CD Burner.lnk
[2014.12.25 19:48:34 | 000,001,247 | ---- | C] () -- C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
[2014.12.20 12:25:57 | 000,959,853 | ---- | C] () -- C:\Users\Admin\IMAG0188.jpg
[2014.12.07 19:47:33 | 000,007,211 | ---- | C] () -- C:\Users\Admin\postmortem.nfo
[2014.11.17 13:56:11 | 000,607,800 | ---- | C] () -- C:\Users\Admin\fc4-Spike1338.exe
[2014.11.16 13:52:35 | 000,366,592 | ---- | C] () -- C:\Users\Admin\GamersGoMakers_CH.exe
[2014.11.13 21:41:19 | 000,074,488 | ---- | C] () -- C:\Users\Admin\VSa - Advanced Registration.xml
[2014.11.13 00:38:41 | 000,543,289 | ---- | C] () -- C:\Users\Admin\fa15-Spike1338.exe
[2014.11.12 09:38:11 | 000,002,903 | ---- | C] () -- C:\Users\Admin\ucms_update_entries.sql
[2014.11.12 09:38:11 | 000,002,269 | ---- | C] () -- C:\Users\Admin\ucms_update_partners.sql
[2014.11.12 09:38:11 | 000,000,504 | ---- | C] () -- C:\Users\Admin\ucms_update_entry_log.sql
[2014.11.12 09:23:21 | 000,018,613 | ---- | C] () -- C:\Users\Admin\ucms.sql
[2014.11.11 18:42:56 | 000,165,603 | ---- | C] () -- C:\Users\Admin\VSa_AFStats.xml
[2014.11.11 14:27:23 | 000,013,172 | ---- | C] () -- C:\Users\Admin\logo.png
[2014.11.11 14:23:56 | 000,000,326 | ---- | C] () -- C:\Users\Admin\primus-slate-fluid.xml
[2014.11.11 14:22:43 | 000,879,411 | ---- | C] () -- C:\Users\Admin\primus-slate-forum.xml
[2014.11.11 14:20:05 | 000,000,306 | ---- | C] () -- C:\Users\Admin\primus-blue-fluid.xml
[2014.11.11 12:28:32 | 000,221,639 | ---- | C] () -- C:\Users\Admin\TheBeaconDark - Red - Fixed.xml
[2014.11.11 12:28:32 | 000,221,635 | ---- | C] () -- C:\Users\Admin\TheBeaconDark - Red - Fluid.xml
[2014.11.10 22:52:23 | 000,028,925 | ---- | C] () -- C:\Users\Admin\functions.php
[2014.11.10 20:11:44 | 000,001,780 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2014.11.10 16:13:23 | 025,570,303 | ---- | C] () -- C:\Users\Admin\gezload_main-DB-11.1.08.sql
[2014.11.10 16:09:58 | 000,005,508 | ---- | C] () -- C:\Users\Admin\evo_beatz.sql
[2014.11.09 00:48:24 | 000,000,026 | ---- | C] () -- C:\Windows\Ditto.INI
[2014.11.07 13:02:56 | 000,331,776 | ---- | C] () -- C:\ProgramData\4519DF80.dot
[2014.11.05 06:37:59 | 000,000,612 | ---- | C] () -- C:\Users\Admin\index.html
[2014.11.03 22:31:53 | 000,000,132 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2014.10.25 10:20:53 | 002,594,031 | ---- | C] () -- C:\Users\Admin\WinRAR.rar
[2014.10.24 21:06:45 | 000,000,553 | ---- | C] () -- C:\Windows\eReg.dat
[2014.10.05 21:37:25 | 000,000,132 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\Adobe CS6-GIF-Format - Voreinstellungen
[2014.10.05 20:56:03 | 000,089,432 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2014.10.02 15:44:19 | 000,048,644 | ---- | C] () -- C:\Users\Admin\warezking.in_xml.xml
[2014.09.29 20:29:44 | 000,000,024 | ---- | C] () -- C:\Windows\SetupTemp.ini
[2014.09.29 20:28:48 | 001,186,161 | ---- | C] () -- C:\Windows\unins000.exe
[2014.09.29 20:28:48 | 000,001,134 | ---- | C] () -- C:\Windows\unins000.dat
[2014.09.29 20:24:08 | 001,591,716 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\WF
[2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\SYKWCLB
[2014.09.01 09:18:44 | 000,002,086 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\FWWLD
[2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\MQJGALU
[2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\MQBB
[2014.09.01 09:18:44 | 000,001,248 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\FRVOIK
[2013.11.16 13:39:18 | 000,063,852 | ---- | C] () -- C:\Users\Admin\index.php
[2013.08.27 13:00:08 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2013.03.21 05:10:16 | 000,042,880 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010.08.11 16:06:39 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010.08.11 16:06:39 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2015.01.22 13:19:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\.purple
[2014.11.07 10:53:53 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Affilorama
[2014.11.02 00:25:46 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\CodeGear
[2015.01.22 13:28:58 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite
[2014.12.25 19:48:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft
[2014.10.27 01:54:55 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\EasySetup
[2014.11.02 00:09:02 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Embarcadero
[2015.01.22 13:28:57 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FileZilla
[2015.01.04 13:25:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Gyazo
[2014.11.06 11:53:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\HTC
[2014.11.08 16:11:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MarketSamurai
[2014.11.08 16:11:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2014.11.10 12:18:40 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\MyImgur
[2014.10.03 11:02:19 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Notepad++
[2014.10.27 01:49:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Opera Software
[2014.10.05 21:25:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\PDAppFlex
[2014.11.16 16:39:36 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Publish Providers
[2014.10.02 13:49:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QIP
[2014.10.02 13:49:32 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QipGuard
[2014.12.21 13:42:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\QuickScan
[2015.01.03 15:16:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Sony
[2014.11.07 10:38:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Spiritsoft
[2014.09.30 13:01:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Steam
[2014.11.02 00:24:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Subversion
[2014.09.29 20:27:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Thunderbird
[2014.11.12 00:42:59 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Titanium
[2014.11.07 10:54:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Traffic Travis v4
[2014.11.05 16:02:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TrueCrypt
[2014.11.07 16:01:33 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\UBot Studio
[2015.01.22 13:06:28 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WebMoney
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A064CECC
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:41ADDB8A
< End of report > |