Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Alles rund um Windows (https://www.trojaner-board.de/alles-rund-um-windows/)
-   -   PC meldet sich nach Anmeldung automatisch wieder ab 2014 (https://www.trojaner-board.de/150588-pc-meldet-anmeldung-automatisch-ab-2014-a.html)

Drancer 04.03.2014 21:36

Zitat:

Zitat von mort (Beitrag 1262610)
edit

Hab ich was falsch gemacht ?

Undertaker 04.03.2014 22:19

moin,

Zitat:

Zitat von Drancer
wie meinen ? / Hab ich was falsch gemacht ?

ich will hier nicht reinpfuschen, aber die Logdatei legt den Verdacht nahe, dass Software illegal genutzt wird.

Code:

2014-02-11 02:07 - 2014-01-03 01:25 - 00000000 ____D () C:\Users\PC\AppData\Local\SKIDROW
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\SKIDROW

Zitat:

SKiDROW is one of the prominent warez groups in software.
Lesestoff: Cracks und Keygens Den Kopierschutz von Software zu umgehen ist nach geltendem Recht illegal. Die Logfiles deuten stark darauf hin, dass du nicht legal erworbene Software einsetzt. Zudem sind Cracks und Patches aus dubioser Quelle sehr oft mit Schädlingen versehen, womit man sich also fast vorsätzlich infiziert. Wir haben uns hier auf dem Board darauf geeinigt, dass wir an dieser Stelle nicht weiter bereinigen, da wir ein solches Vorgehen nicht unterstützen. Hinzu kommt, dass wir dich in unserer Anleitung und auch in diesem Wichtig-Thema unmissverständlich darauf hingewiesen haben, wie wir damit umgehen werden. Saubere, gute Software hat seinen Preis und die Softwarefirmen leben von diesen Einnahmen. Unsere Hilfe beschränkt sich daher nur auf das Neuaufsetzen und Absichern deines Systems. Fragen dazu beantworten wir dir aber weiterhin gerne und zwar in unserem Forum.

Drancer 04.03.2014 22:42

Zitat:

Zitat von Undertaker (Beitrag 1262676)
moin,



ich will hier nicht reinpfuschen, aber die Logdatei legt den Verdacht nahe, dass Software illegal genutzt wird.

Code:

2014-02-11 02:07 - 2014-01-03 01:25 - 00000000 ____D () C:\Users\PC\AppData\Local\SKIDROW
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\SKIDROW

Lesestoff: Cracks und Keygens Den Kopierschutz von Software zu umgehen ist nach geltendem Recht illegal. Die Logfiles deuten stark darauf hin, dass du nicht legal erworbene Software einsetzt. Zudem sind Cracks und Patches aus dubioser Quelle sehr oft mit Schädlingen versehen, womit man sich also fast vorsätzlich infiziert. Wir haben uns hier auf dem Board darauf geeinigt, dass wir an dieser Stelle nicht weiter bereinigen, da wir ein solches Vorgehen nicht unterstützen. Hinzu kommt, dass wir dich in unserer Anleitung und auch in diesem Wichtig-Thema unmissverständlich darauf hingewiesen haben, wie wir damit umgehen werden. Saubere, gute Software hat seinen Preis und die Softwarefirmen leben von diesen Einnahmen. Unsere Hilfe beschränkt sich daher nur auf das Neuaufsetzen und Absichern deines Systems. Fragen dazu beantworten wir dir aber weiterhin gerne und zwar in unserem Forum.

Wow wie hilfreich... Das ist ein spiel das ich schon lang nicht mehr in meinem rechner habe, ich hab denn installer vom Kolleg bekommen, mal ehrlich wisst ihr nicht wie man das problem löst, oder wollt irh wirklich nur wegen das jetzt nicht mehr weiterhelfen...

Undertaker 04.03.2014 23:53

Zitat:

Zitat von Drancer (Beitrag 1262687)
Das ist ein spiel das ich schon lang nicht mehr in meinem rechner habe

Willst du mich verarschen?

Code:

==================== One Month Created Files and Folders ========

2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\SKIDROW
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Arma 3 Alpha

Das sind zwei Wochen.

Hier gibt es Regeln.
Bereinige deinen Rechner von illegaler Software und dann sehen wir weiter.

Drancer 05.03.2014 00:30

Ich hatte es doch gelöscht why hab ich es immer noch auf dem rechner ?

Zitat:

Zitat von Undertaker (Beitrag 1262707)
Willst du mich verarschen?

Code:

==================== One Month Created Files and Folders ========

2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\SKIDROW
2014-02-18 03:01 - 2014-02-18 03:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Arma 3 Alpha

Das sind zwei Wochen.

Hier gibt es Regeln.
Bereinige deinen Rechner von illegaler Software und dann sehen wir weiter.

Ich hab gelesen das es mit der userinit zu tun haben soll, jedenfalls mit der regristry. Haste dafür eine lösung.
Ahja ich habe Avira, anti-virus (oder sowas ), adw cleaner, ccleaner, search bot, malewarebyte,laufen lassen und alles entfernt.

WICHTIGE FRAGE.
malewarebyte hat windows datei in der quarantäne ,könnte es damit was zu tun haben ?

mort 05.03.2014 00:52

Zitat:

könnte es damit was zu tun haben ?
Wenn du uns das Log geben könntest, können wir es genauer feststellen :)

Drancer 05.03.2014 01:25

So hier:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-03-2014
Ran by Administrator (administrator) on PC-PC on 05-03-2014 01:22:37
Running from C:\Users\Administrator\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

() C:\Program Files (x86)\WinArchiver\WAService.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Doctor Web, Ltd.) C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\TrafInsp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(SMART-SOFT) C:\Program Files (x86)\TrafInsp\ASP.NET\bin\TIASPNETHostServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7198424 2013-08-28] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime Alternative\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-11-09] (RealNetworks, Inc.)
HKLM-x32\...\Run: [WAHELPER.EXE] - C:\Program Files (x86)\WinArchiver\WAHELPER.EXE [480792 2013-11-10] (Power Software Ltd)
HKU\S-1-5-21-2263356855-1520679738-450664524-500\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2011-01-12] (AMD)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0D7BFBE9F903CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-AT
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: No Name - {74D271A4-00A7-0F5C-560A-2412C0CFD357} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: No Name - {8984B388-A5BB-4DF7-B274-77B879E179DB} -  No File
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.66.2.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\eddz111h.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mailru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ozonru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\priceru.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-slovari.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex.xml
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-09]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchURL: hxxp://www.google.com/search?q={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-30]
CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-30]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-30]
CHR Extension: (Google-Suche) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-30]
CHR Extension: (RealDownloader) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-02-24]
CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-30]
CHR Extension: (Google Mail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-30]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [68096 2012-06-21] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 DrWebEngine; C:\Program Files (x86)\TrafInsp\plugins\DwAV\Engine\dwengine.exe [1667416 2012-06-28] (Doctor Web, Ltd.)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5148240 2013-07-23] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-12-31] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 TrafInspSrv; C:\Program Files (x86)\TrafInsp\TrafInsp.exe [4475392 2012-06-08] (SMART-SOFT)
R2 WinArchiver Service; C:\Program Files (x86)\WinArchiver\WAService.exe [202264 2013-11-10] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] ()
R1 TICAPDRV; C:\Windows\System32\DRIVERS\ticap.sys [265880 2012-01-20] (SMART-SOFT)
R0 waemu; C:\Windows\System32\Drivers\waemu.sys [140184 2013-11-10] (Power Software Ltd)
S2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S3 cpuz136; \??\C:\Users\ADMINI~1\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S2 NEWDRIVER; \??\C:\Windows\SysWow64\WinVDEdrv6.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-05 01:22 - 2014-03-05 01:22 - 00016276 _____ () C:\Users\Administrator\Desktop\FRST.txt
2014-03-05 01:21 - 2014-03-05 01:21 - 00000000 ____D () C:\Program Files (x86)\Rockstars
2014-03-04 23:59 - 2014-03-04 23:59 - 00001098 _____ () C:\Users\Administrator\Desktop\Netcode Fix v2.zip
2014-03-04 23:59 - 2013-01-21 23:44 - 00000382 _____ () C:\Users\Administrator\Desktop\START.bat
2014-03-04 23:59 - 2013-01-21 23:44 - 00000378 _____ () C:\Users\Administrator\Desktop\STOP.bat
2014-03-04 22:53 - 2014-03-04 22:53 - 00000908 _____ () C:\Windows\PFRO.log
2014-03-04 22:32 - 2014-03-04 22:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\WMTools Downloaded Files
2014-03-04 22:27 - 2014-03-04 22:31 - 142602520 _____ (Microsoft Corporation) C:\Users\Administrator\Downloads\wlsetup-all_16.4.3508.0205.exe
2014-03-04 20:46 - 2014-03-04 21:18 - 255544475 _____ () C:\Users\Administrator\Desktop\Mackpro 2014-03-01 22-18-10-149.wmv
2014-03-04 19:20 - 2014-03-04 19:33 - 00000000 ___RD () C:\Users\Administrator\Dropbox
2014-03-04 19:20 - 2014-03-04 19:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Adobe
2014-03-04 18:37 - 2014-03-04 18:37 - 02156544 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2014-03-04 15:20 - 2014-03-04 15:20 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 15:08 - 2014-03-04 15:16 - 562072450 ____R () C:\Users\Administrator\Desktop\Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi
2014-03-04 14:29 - 2014-03-04 15:24 - 1582391058 ____R () C:\Users\Administrator\Desktop\KVN.2014.1.igra.hdtvrip.avi
2014-03-04 14:09 - 2014-03-04 14:09 - 00013068 _____ () C:\Users\Administrator\Downloads\[rutor.org]Новый_Comedy_Club.torrent
2014-03-04 14:07 - 2014-03-04 14:07 - 00011261 _____ () C:\Users\Administrator\Downloads\[rutor.org]Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi_.torrent
2014-03-04 14:06 - 2014-03-04 14:06 - 00015603 _____ () C:\Users\Administrator\Downloads\[rutor.org]KVN.2014.1.igra.hdtvrip.avi.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00017937 _____ () C:\Users\Administrator\Downloads\[rutor.org]Splin-Rezonans,_chast_1.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00013062 _____ () C:\Users\Administrator\Downloads\[rutor.org]Ляпис_Трубецкой-Матрёшка.torrent
2014-03-04 14:03 - 2014-03-04 15:11 - 00000000 ____D () C:\Users\Administrator\Desktop\Top Gear 21х01-04.720p
2014-03-04 14:03 - 2014-03-04 14:03 - 00012263 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.01.TVRip.avi.torrent
2014-03-04 14:03 - 2014-03-04 14:03 - 00011783 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.02.TVRip.avi.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00019388 _____ () C:\Users\Administrator\Downloads\[rutor.org]Top_Gear_21х01-04.720p.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\Administrator\Desktop\Discovery_Aliens mummies (2012) SATRip
2014-03-04 14:01 - 2014-03-04 14:01 - 00012821 _____ () C:\Users\Administrator\Downloads\[rutor.org]Discovery_Aliens_mummies_(2012)_SATRip.torrent
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-03-04 13:55 - 2014-03-04 16:07 - 1467863040 ____R () C:\Users\Administrator\Desktop\The.Hungover.Games.Unrated Edition.2014.D.WEB-DLRip.1400Mb.avi
2014-03-04 13:55 - 2014-03-04 13:55 - 00014538 _____ () C:\Users\Administrator\Downloads\[filmitorrent.org]The.Hungover.Games.Unrated_Edition.2014.D.WEB-D_0.torrent
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:57 - 2014-03-03 21:58 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 21:05 - 2014-03-04 22:58 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-03 21:05 - 2014-03-04 22:58 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-03 20:40 - 2014-03-05 01:22 - 00000000 ____D () C:\FRST
2014-03-03 20:26 - 2014-03-04 22:57 - 00000840 _____ () C:\Windows\setupact.log
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-01 20:21 - 2014-03-01 21:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:12 - 2014-03-02 19:27 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2014-03-01 20:01 - 2014-03-01 20:01 - 00016384 ___SH () C:\Users\PC\Thumbs.db
2014-03-01 19:45 - 2014-03-02 05:25 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:12 - 2014-03-01 07:19 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-03-01 06:47 - 2014-03-01 06:47 - 00070520 _____ () C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-28 07:10 - 2014-02-28 07:10 - 00015349 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Red.2.2013_HDRip__[scarabey.org].torrent
2014-02-27 14:12 - 2014-02-27 14:12 - 00015648 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Bilet.na.Vegas.2012.O.BDRip.745MB_[Youtracker]_.torrent
2014-02-27 14:11 - 2014-02-27 14:11 - 00015441 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Dubler.2013.O.BDRip.745MB_by_Yarmak23.avi.torrent
2014-02-27 14:07 - 2014-02-27 14:07 - 00014550 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Elki.3.2013.O.DVDRip.700MB.avi.torrent
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:54 - 2013-11-10 03:53 - 00140184 _____ (Power Software Ltd) C:\Windows\system32\Drivers\waemu.sys
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 14:01 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-26 14:01 - 2014-01-03 23:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 18:53 - 2014-02-26 19:50 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-25 13:50 - 2014-03-04 22:56 - 00315181 _____ () C:\Windows\WindowsUpdate.log
2014-02-25 13:48 - 2014-03-01 06:47 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 23:55 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-24 23:54 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-02-24 23:54 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-24 23:54 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-02-24 23:54 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-02-24 23:54 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-02-24 23:54 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-02-24 23:54 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-02-24 23:54 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-02-24 23:54 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-24 23:54 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-02-24 23:53 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-02-24 23:53 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-02-24 23:53 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys
2014-02-24 23:53 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-02-24 23:53 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-02-24 23:53 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-02-24 23:52 - 2013-09-25 03:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-02-24 23:52 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 17:03 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-23 22:53 - 2014-02-23 23:16 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2014-02-23 01:58 - 2014-02-23 01:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Realmware
2014-02-22 23:05 - 2014-03-03 20:25 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-02-22 23:05 - 2014-02-22 23:12 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 23:04 - 2014-02-23 00:10 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.comwatchv=OGnIS_a54ak
2014-02-21 15:51 - 2014-02-21 15:59 - 402748888 _____ () C:\Users\PC\Downloads\Горцы от ума - 4 . Полный фильм - Derbent.tv - Видео Дагестана, новости, приколы, клипы, концерты,свадьбы.flv
2014-02-21 07:39 - 2014-02-21 07:53 - 613726208 ____R () C:\Users\PC\Downloads\ТРИ РУБЛЯ (Дом Кино).mpg
2014-02-21 07:36 - 2014-02-21 07:53 - 616548352 ____R () C:\Users\PC\Downloads\Субботний вечер (Дом Кино).mpg
2014-02-20 00:08 - 2014-02-20 00:08 - 00000000 ____D () C:\Users\Administrator\AppData\Local\EMU
2014-02-20 00:00 - 2014-02-20 00:00 - 00000000 ____D () C:\Program Files (x86)\5
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-19 12:09 - 2014-03-04 22:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-17 18:28 - 2014-02-18 02:23 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-17 14:53 - 2014-02-25 14:27 - 00000000 ____D () C:\Users\PC\Downloads\Top Gear S21 E01-02
2014-02-14 03:45 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-14 03:45 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-14 03:44 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-14 03:44 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-14 03:44 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-14 03:44 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-14 03:44 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-14 03:44 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-14 03:44 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-14 03:44 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-14 03:44 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-14 03:44 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-14 03:44 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-14 03:44 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-14 03:44 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-14 03:44 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-14 03:44 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-14 03:44 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-14 03:44 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-14 03:44 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-14 03:44 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-14 03:44 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-14 03:44 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-14 03:44 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-14 03:44 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-14 03:44 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-14 03:44 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-14 03:44 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-14 03:44 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-14 03:44 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-14 03:44 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-13 23:19 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-13 23:19 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-13 23:19 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-13 23:19 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-13 23:19 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 23:19 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-13 23:19 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-13 23:19 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-13 23:19 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-13 23:19 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-13 23:18 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-13 23:18 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-13 23:18 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-13 23:18 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:04 - 2014-02-26 23:22 - 00009678 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:53 - 2013-10-23 15:11 - 00129944 _____ (Power Software Ltd) C:\Windows\system32\Drivers\scdemu.sys
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:30 - 2014-02-12 20:30 - 00000000 ____D () C:\Users\PC\AppData\Local\Disc_Soft_Ltd
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra
2014-02-11 16:33 - 2014-02-24 16:19 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\New Technology Studio
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Local\New Technology Studio
2014-02-11 00:41 - 2014-02-11 00:54 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\www.gtavicecity.ru
2014-02-10 22:05 - 2014-02-10 22:05 - 00000000 ____D () C:\Users\PC\AppData\Local\EMU
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-10 21:11 - 2014-02-10 21:11 - 00000000 ____D () C:\Users\PC\AppData\Local\Chromium
2014-02-10 13:26 - 2014-02-10 13:26 - 00000000 __RHD () C:\Users\PC\AppData\Roaming\SecuROM
2014-02-08 16:15 - 2014-02-08 17:27 - 00000000 ____D () C:\Users\PC\AppData\Local\Mato_Technologies
2014-02-07 06:41 - 2014-02-08 15:53 - 00001782 _____ () C:\Users\PC\Desktop\PeerBlock.lnk
2014-02-07 06:28 - 2014-02-09 23:29 - 00000825 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk

==================== One Month Modified Files and Folders =======

2014-03-05 01:22 - 2014-03-05 01:22 - 00016276 _____ () C:\Users\Administrator\Desktop\FRST.txt
2014-03-05 01:22 - 2014-03-03 20:40 - 00000000 ____D () C:\FRST
2014-03-05 01:21 - 2014-03-05 01:21 - 00000000 ____D () C:\Program Files (x86)\Rockstars
2014-03-05 00:36 - 2012-04-02 15:23 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-05 00:32 - 2012-04-02 22:38 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-03-05 00:32 - 2012-04-02 19:19 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-05 00:27 - 2012-04-02 15:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-05 00:25 - 2012-04-02 19:19 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-03-04 23:59 - 2014-03-04 23:59 - 00001098 _____ () C:\Users\Administrator\Desktop\Netcode Fix v2.zip
2014-03-04 23:54 - 2013-02-16 19:35 - 00000000 ___RD () C:\Users\Administrator\Desktop\bewerbung
2014-03-04 23:39 - 2013-02-23 17:34 - 00000916 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003UA.job
2014-03-04 23:05 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-04 23:05 - 2009-07-14 05:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-04 23:01 - 2012-04-15 21:26 - 00000000 ____D () C:\ProgramData\Origin
2014-03-04 23:01 - 2012-04-15 21:25 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-03-04 22:58 - 2014-03-03 21:05 - 00003350 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-04 22:58 - 2014-03-03 21:05 - 00003232 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-500
2014-03-04 22:58 - 2012-04-02 15:23 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-04 22:57 - 2014-03-03 20:26 - 00000840 _____ () C:\Windows\setupact.log
2014-03-04 22:57 - 2013-11-24 17:04 - 00000442 ____H () C:\Windows\Tasks\SK.Enhancer-S-161304646.job
2014-03-04 22:57 - 2012-04-02 15:12 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2014-03-04 22:57 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-04 22:56 - 2014-02-25 13:50 - 00315181 _____ () C:\Windows\WindowsUpdate.log
2014-03-04 22:53 - 2014-03-04 22:53 - 00000908 _____ () C:\Windows\PFRO.log
2014-03-04 22:49 - 2014-02-19 12:09 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-03-04 22:48 - 2012-04-11 07:01 - 00000000 ____D () C:\Windows\Minidump
2014-03-04 22:32 - 2014-03-04 22:32 - 00000000 ____D () C:\Users\Administrator\AppData\Local\WMTools Downloaded Files
2014-03-04 22:31 - 2014-03-04 22:27 - 142602520 _____ (Microsoft Corporation) C:\Users\Administrator\Downloads\wlsetup-all_16.4.3508.0205.exe
2014-03-04 22:24 - 2012-04-27 19:42 - 00000069 _____ () C:\Windows\NeroDigital.ini
2014-03-04 21:18 - 2014-03-04 20:46 - 255544475 _____ () C:\Users\Administrator\Desktop\Mackpro 2014-03-01 22-18-10-149.wmv
2014-03-04 19:38 - 2013-10-26 19:41 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-04 19:33 - 2014-03-04 19:20 - 00000000 ___RD () C:\Users\Administrator\Dropbox
2014-03-04 19:20 - 2014-03-04 19:20 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Adobe
2014-03-04 19:20 - 2013-10-26 19:41 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-03-04 19:20 - 2013-10-26 19:40 - 00000000 ____D () C:\Users\Administrator
2014-03-04 18:39 - 2013-10-26 19:40 - 00000008 __RSH () C:\Users\Administrator\ntuser.pol
2014-03-04 18:39 - 2013-06-14 16:23 - 00000322 __RSH () C:\Users\PC\ntuser.pol
2014-03-04 18:39 - 2012-04-02 14:26 - 00000000 ____D () C:\Users\PC
2014-03-04 18:38 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-04 18:37 - 2014-03-04 18:37 - 02156544 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe
2014-03-04 17:19 - 2013-08-12 15:04 - 00000000 ____D () C:\Program Files\PeerBlock
2014-03-04 16:41 - 2012-04-03 05:05 - 00000000 ___RD () C:\Users\PC\Desktop\PROGRAMME
2014-03-04 16:07 - 2014-03-04 13:55 - 1467863040 ____R () C:\Users\Administrator\Desktop\The.Hungover.Games.Unrated Edition.2014.D.WEB-DLRip.1400Mb.avi
2014-03-04 15:24 - 2014-03-04 14:29 - 1582391058 ____R () C:\Users\Administrator\Desktop\KVN.2014.1.igra.hdtvrip.avi
2014-03-04 15:20 - 2014-03-04 15:20 - 00001160 ____H () C:\Users\Administrator\Desktop\$$JetTHM$$.cache
2014-03-04 15:16 - 2014-03-04 15:08 - 562072450 ____R () C:\Users\Administrator\Desktop\Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi
2014-03-04 15:12 - 2014-03-04 15:12 - 00000000 ____D () C:\Users\Administrator\Documents\Freemake
2014-03-04 15:11 - 2014-03-04 14:03 - 00000000 ____D () C:\Users\Administrator\Desktop\Top Gear 21х01-04.720p
2014-03-04 15:10 - 2014-03-04 15:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\COWON
2014-03-04 15:05 - 2013-11-24 03:03 - 00000000 ____D () C:\Users\PC\Desktop\na more
2014-03-04 14:09 - 2014-03-04 14:09 - 00013068 _____ () C:\Users\Administrator\Downloads\[rutor.org]Новый_Comedy_Club.torrent
2014-03-04 14:07 - 2014-03-04 14:07 - 00011261 _____ () C:\Users\Administrator\Downloads\[rutor.org]Noviy.Comedy.Club.(efir.28.02.2014).WEBRip.avi_.torrent
2014-03-04 14:06 - 2014-03-04 14:06 - 00015603 _____ () C:\Users\Administrator\Downloads\[rutor.org]KVN.2014.1.igra.hdtvrip.avi.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00017937 _____ () C:\Users\Administrator\Downloads\[rutor.org]Splin-Rezonans,_chast_1.torrent
2014-03-04 14:05 - 2014-03-04 14:05 - 00013062 _____ () C:\Users\Administrator\Downloads\[rutor.org]Ляпис_Трубецкой-Матрёшка.torrent
2014-03-04 14:03 - 2014-03-04 14:03 - 00012263 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.01.TVRip.avi.torrent
2014-03-04 14:03 - 2014-03-04 14:03 - 00011783 _____ () C:\Users\Administrator\Downloads\[rutor.org]Kuhnja.3.02.TVRip.avi.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00019388 _____ () C:\Users\Administrator\Downloads\[rutor.org]Top_Gear_21х01-04.720p.torrent
2014-03-04 14:02 - 2014-03-04 14:02 - 00000000 ____D () C:\Users\Administrator\Desktop\Discovery_Aliens mummies (2012) SATRip
2014-03-04 14:01 - 2014-03-04 14:01 - 00012821 _____ () C:\Users\Administrator\Downloads\[rutor.org]Discovery_Aliens_mummies_(2012)_SATRip.torrent
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-03-04 13:56 - 2014-03-04 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-03-04 13:55 - 2014-03-04 13:55 - 00014538 _____ () C:\Users\Administrator\Downloads\[filmitorrent.org]The.Hungover.Games.Unrated_Edition.2014.D.WEB-D_0.torrent
2014-03-04 11:40 - 2012-06-27 13:08 - 00002139 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-04 02:34 - 2014-01-11 00:00 - 00000000 ____D () C:\AdwCleaner
2014-03-04 01:57 - 2014-03-04 01:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\LavasoftStatistics
2014-03-04 01:51 - 2014-03-04 01:51 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\DVDVideoSoft
2014-03-03 21:58 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Assassin's Creed Revelations
2014-03-03 21:57 - 2014-03-03 21:57 - 00000000 ____D () C:\Users\Administrator\Documents\Battlefield 3
2014-03-03 20:31 - 2012-03-07 00:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-03 20:25 - 2014-02-22 23:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PhotoScape
2014-03-03 20:25 - 2013-09-15 14:00 - 00000000 ____D () C:\Program Files (x86)\RusTV Player
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-03 20:25 - 2012-07-04 13:30 - 00000000 ___RD () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-03 20:25 - 2012-07-04 13:29 - 00000000 ____D () C:\Users\Gast
2014-03-03 20:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-03-03 20:24 - 2013-11-08 20:15 - 00000000 ____D () C:\Users\Administrator\AppData\Local\PunkBuster
2014-03-03 20:24 - 2012-04-03 04:54 - 00000000 ____D () C:\ProgramData\Real
2014-03-03 20:24 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-03-03 04:39 - 2013-11-08 20:08 - 00000000 ____D () C:\Users\Administrator\Desktop\dzhan
2014-03-02 19:27 - 2014-03-01 20:12 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2014-03-02 17:39 - 2013-02-23 17:34 - 00000894 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2263356855-1520679738-450664524-1003Core.job
2014-03-02 05:39 - 2014-03-02 05:39 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Auslogics
2014-03-02 05:26 - 2013-06-28 21:37 - 00000000 ____D () C:\Program Files\WinRAR
2014-03-02 05:25 - 2014-03-01 19:45 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
2014-03-02 05:25 - 2014-01-29 08:54 - 00000000 ____D () C:\Users\PC\Downloads\Neuer Ordner
2014-03-02 05:25 - 2013-10-03 18:31 - 00000000 ____D () C:\Program Files (x86)\Ss.Helper
2014-03-02 02:41 - 2014-03-02 02:41 - 00000000 ____D () C:\Program Files (x86)\SmartTweak Software
2014-03-02 02:11 - 2014-03-02 02:11 - 00002788 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-02 02:11 - 2012-04-03 05:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-01 23:41 - 2013-10-26 19:42 - 00000000 ___DC () C:\Users\Administrator\Desktop\Neuer Ordner
2014-03-01 21:21 - 2014-03-01 20:21 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PhotoScape
2014-03-01 20:39 - 2013-08-29 23:53 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DVDVideoSoft
2014-03-01 20:27 - 2013-11-10 18:01 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-01 20:27 - 2013-11-02 14:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DVDVideoSoft
2014-03-01 20:18 - 2014-03-01 20:18 - 00000000 ____D () C:\Windows\de
2014-03-01 20:17 - 2014-03-01 20:17 - 00000000 ____D () C:\Windows\en
2014-03-01 20:16 - 2014-03-01 20:16 - 00000000 ____D () C:\Windows\ru
2014-03-01 20:15 - 2012-04-02 16:35 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-03-01 20:01 - 2014-03-01 20:01 - 00016384 ___SH () C:\Users\PC\Thumbs.db
2014-03-01 13:21 - 2014-03-01 13:21 - 00021008 _____ () C:\Users\PC\Desktop\Mein Film bbbb.wlmp
2014-03-01 07:19 - 2014-03-01 07:12 - 377248555 _____ () C:\Users\PC\Desktop\Mein Film 1.mp4
2014-03-01 06:49 - 2012-04-02 14:43 - 00000000 ____D () C:\Users\PC\AppData\Roaming\uTorrent
2014-03-01 06:47 - 2014-03-01 06:47 - 00070520 _____ () C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-01 06:47 - 2014-02-25 13:48 - 00003188 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-03-01 06:47 - 2014-02-01 15:22 - 00003328 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-28 07:10 - 2014-02-28 07:10 - 00015349 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Red.2.2013_HDRip__[scarabey.org].torrent
2014-02-27 14:12 - 2014-02-27 14:12 - 00015648 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Bilet.na.Vegas.2012.O.BDRip.745MB_[Youtracker]_.torrent
2014-02-27 14:11 - 2014-02-27 14:11 - 00015441 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Dubler.2013.O.BDRip.745MB_by_Yarmak23.avi.torrent
2014-02-27 14:07 - 2014-02-27 14:07 - 00014550 _____ () C:\Users\PC\Downloads\[filmitorrent.org]Elki.3.2013.O.DVDRip.700MB.avi.torrent
2014-02-27 12:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-27 11:13 - 2014-02-27 11:13 - 00000088 _____ () C:\Users\PC\Desktop\Два ствола скачать торрент в хорошем качестве бесплатно dvdrip, hdrip.url
2014-02-27 10:52 - 2014-02-27 10:52 - 00000000 ____D () C:\Users\PC\Desktop\08951603108
2014-02-26 23:22 - 2014-02-13 22:04 - 00009678 _____ () C:\Windows\SysWOW64\ScriptHook.log
2014-02-26 21:09 - 2013-10-03 23:18 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\WinArchiver
2014-02-26 19:54 - 2014-02-26 19:54 - 00000000 ____D () C:\Program Files (x86)\WinArchiver
2014-02-26 19:53 - 2013-10-26 19:41 - 00070520 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-26 19:50 - 2014-02-25 18:53 - 00306000 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-26 19:49 - 2014-02-26 19:49 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-26 19:49 - 2014-02-26 19:49 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-26 19:48 - 2014-02-26 19:48 - 00000000 ____D () C:\Program Files\Java
2014-02-26 19:44 - 2014-02-26 19:44 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\PowerISO
2014-02-26 00:02 - 2014-02-26 00:02 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes
2014-02-25 14:27 - 2014-02-17 14:53 - 00000000 ____D () C:\Users\PC\Downloads\Top Gear S21 E01-02
2014-02-25 01:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-02-24 23:54 - 2012-04-03 15:38 - 00000000 ____D () C:\ProgramData\Skype
2014-02-24 23:54 - 2012-04-02 15:12 - 00010061 _____ () C:\Windows\system32\lvcoinst.log
2014-02-24 17:17 - 2012-11-25 00:19 - 00000000 ____D () C:\Program Files (x86)\rhv
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Malwarebytes
2014-02-24 17:03 - 2014-02-24 17:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-24 16:49 - 2012-04-03 13:33 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-24 16:19 - 2014-02-11 16:33 - 00003350 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-24 16:19 - 2013-12-12 18:48 - 00003210 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2263356855-1520679738-450664524-1003
2014-02-23 23:16 - 2014-02-23 22:53 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Electronic_Arts_Inc
2014-02-23 23:06 - 2014-02-23 23:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Need for Speed World
2014-02-23 02:16 - 2013-12-31 21:25 - 00000000 ____D () C:\Program Files\Realmware
2014-02-23 01:58 - 2014-02-23 01:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Realmware
2014-02-23 00:10 - 2014-02-22 23:04 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-02-22 23:12 - 2014-02-22 23:05 - 00008192 ____H () C:\Users\Administrator\Desktop\photothumb.db
2014-02-22 03:34 - 2012-05-03 07:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-22 01:08 - 2012-05-26 18:55 - 00000000 ____D () C:\Users\PC\AppData\Local\Electronic_Arts_Inc
2014-02-22 01:00 - 2014-02-22 01:00 - 00000000 ____D () C:\Users\PC\Desktop\login
2014-02-21 21:49 - 2012-04-04 16:15 - 00042496 _____ () C:\Users\PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-21 17:45 - 2014-02-21 17:45 - 00000000 ____D () C:\Users\PC\Desktop\httpwww.youtube.comwatchv=OGnIS_a54ak
2014-02-21 17:39 - 2014-01-15 18:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-21 15:59 - 2014-02-21 15:51 - 402748888 _____ () C:\Users\PC\Downloads\Горцы от ума - 4 . Полный фильм - Derbent.tv - Видео Дагестана, новости, приколы, клипы, концерты,свадьбы.flv
2014-02-21 07:53 - 2014-02-21 07:39 - 613726208 ____R () C:\Users\PC\Downloads\ТРИ РУБЛЯ (Дом Кино).mpg
2014-02-21 07:53 - 2014-02-21 07:36 - 616548352 ____R () C:\Users\PC\Downloads\Субботний вечер (Дом Кино).mpg
2014-02-21 07:27 - 2012-04-02 15:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-21 07:27 - 2012-04-02 15:23 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-21 07:27 - 2012-04-02 15:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-20 00:08 - 2014-02-20 00:08 - 00000000 ____D () C:\Users\Administrator\AppData\Local\EMU
2014-02-20 00:00 - 2014-02-20 00:00 - 00000000 ____D () C:\Program Files (x86)\5
2014-02-19 20:45 - 2014-02-19 20:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Theta
2014-02-19 20:28 - 2014-02-19 20:28 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-02-19 20:10 - 2014-02-19 20:10 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\BANDISOFT
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-02-19 12:18 - 2014-02-19 12:18 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-02-19 12:10 - 2014-02-19 12:10 - 00000836 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-19 12:07 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-02-18 03:23 - 2014-02-18 03:23 - 00000000 ____D () C:\Users\Administrator\Documents\Rockstar Games
2014-02-18 02:23 - 2014-02-17 18:28 - 00000000 ____D () C:\Users\Administrator\Documents\My Games
2014-02-18 02:18 - 2013-07-28 12:00 - 00000000 ____D () C:\Users\PC\Documents\My Games
2014-02-16 05:04 - 2013-11-24 15:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 05:00 - 2012-04-02 15:15 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-13 22:25 - 2014-02-13 22:25 - 00000000 ____D () C:\Users\PC\Documents\Rockstar Games
2014-02-13 22:14 - 2014-02-13 22:14 - 00003178 _____ () C:\Windows\System32\Tasks\{57E8181A-0929-418A-A72C-CE10D919BEE8}
2014-02-13 22:12 - 2014-02-13 22:12 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-02-13 22:03 - 2014-02-13 22:03 - 00336384 _____ () C:\Windows\SysWOW64\ScriptHook.dll
2014-02-13 18:31 - 2012-04-02 15:23 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-13 18:31 - 2012-04-02 15:23 - 00003846 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-13 03:16 - 2014-02-13 03:16 - 00000000 ____D () C:\Neuer Ordner
2014-02-12 22:16 - 2014-02-12 22:16 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-02-12 21:23 - 2014-02-12 21:23 - 00000000 ____D () C:\Program Files\PowerISO
2014-02-12 20:36 - 2014-02-12 20:36 - 00000000 ____D () C:\Users\PC\AppData\Roaming\PowerISO
2014-02-12 20:30 - 2014-02-12 20:30 - 00000000 ____D () C:\Users\PC\AppData\Local\Disc_Soft_Ltd
2014-02-12 20:28 - 2014-02-12 20:28 - 00000000 ____D () C:\Users\PC\AppData\Roaming\DAEMON Tools Ultra
2014-02-11 02:25 - 2014-02-11 02:25 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\New Technology Studio
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenIV
2014-02-11 01:10 - 2014-02-11 01:10 - 00000000 ____D () C:\Users\PC\AppData\Local\New Technology Studio
2014-02-11 00:54 - 2014-02-11 00:41 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\www.gtavicecity.ru
2014-02-10 22:05 - 2014-02-10 22:05 - 00000000 ____D () C:\Users\PC\AppData\Local\EMU
2014-02-10 21:57 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-10 21:12 - 2014-02-10 21:12 - 01199079 _____ () C:\Windows\unins000.exe
2014-02-10 21:12 - 2014-01-25 21:41 - 00080705 _____ () C:\Windows\unins000.dat
2014-02-10 21:11 - 2014-02-10 21:11 - 00000000 ____D () C:\Users\PC\AppData\Local\Chromium
2014-02-10 19:50 - 2014-01-03 01:25 - 00000000 ____D () C:\Users\PC\Documents\Arma 3 Alpha
2014-02-10 13:26 - 2014-02-10 13:26 - 00000000 __RHD () C:\Users\PC\AppData\Roaming\SecuROM
2014-02-09 23:29 - 2014-02-07 06:28 - 00000825 _____ () C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-02-08 17:27 - 2014-02-08 16:15 - 00000000 ____D () C:\Users\PC\AppData\Local\Mato_Technologies
2014-02-08 15:53 - 2014-02-07 06:41 - 00001782 _____ () C:\Users\PC\Desktop\PeerBlock.lnk
2014-02-06 14:24 - 2012-04-03 15:39 - 00000000 ____D () C:\Users\PC\AppData\Roaming\Skype
2014-02-06 13:16 - 2014-02-14 03:44 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-14 03:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-14 03:44 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-14 03:44 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-14 03:44 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-14 03:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-14 03:44 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-14 03:44 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-14 03:44 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-14 03:44 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-14 03:44 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-14 03:44 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-14 03:44 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-14 03:44 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-14 03:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-14 03:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-14 03:44 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-14 03:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-14 03:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-14 03:44 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-14 03:44 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-14 03:44 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-14 03:44 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-14 03:44 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-14 03:44 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-14 03:44 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-14 03:44 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-14 03:44 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-14 03:44 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-14 03:44 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-14 03:44 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-14 03:44 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-14 03:44 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-14 03:44 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-14 03:44 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-14 03:44 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-14 03:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-14 03:44 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-14 03:44 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-03 22:01 - 2014-01-31 22:15 - 00000000 ____D () C:\Users\PC\Documents\GTA San Andreas User Files
2014-02-03 21:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-03 19:09 - 2013-10-26 19:41 - 00001421 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

Files to move or delete:
====================
C:\Users\Gast\AppData\Roaming\CamLayout.ini
C:\Users\Gast\AppData\Roaming\CamShapes.ini
C:\Users\PC\AppData\Roaming\CamLayout.ini
C:\Users\PC\AppData\Roaming\CamShapes.ini
C:\ProgramData\qjaxlkio.dss


Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Administrator\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpotc8qp.dll
C:\Users\Gast\AppData\Local\Temp\AskSLib.dll
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
C:\Users\Gast\AppData\Local\Temp\install_flashplayer11x32axau_mssa_aaa_aih.exe
C:\Users\Gast\AppData\Local\Temp\kpinstaller.exe
C:\Users\Gast\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\PC\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-28 06:47

==================== End Of Log ============================

--- --- ---


Hoffe es passt !

mort 05.03.2014 01:29

Ich brauch das Log von Malwarebytes

Drancer 05.03.2014 02:22

Zitat:

Zitat von mort (Beitrag 1262722)
Ich brauch das Log von Malwarebytes

Verdammt ich finde denn Ordner nicht mehr wo ich Malware drin hab !
Was passiert mit denn ganzen viren wenn der order gelöscht wird wo malware drin ist.
Ich hoffe ich habs nicht gelöscht, andere möglichkeit malewarebytes zu finden ?
Denke aber ich habs gelöscht...
Und ein neuer scan bringt wohl nichts.
Kann mich erinnern das eine datei die irgendwas mit > Currentversion , in der quarantäne drin war.

was soll ich nur machen...:killpc:

mort 05.03.2014 02:26

Die Logs werden hier gelistet:
http://img.trojaner-board.de/alle-lo...-alle-logs.png

Drancer 05.03.2014 02:49

Zitat:

Zitat von mort (Beitrag 1262726)

Das weiß ich doch, aber ich finde das programm selber nicht, um es überhaupt zu öffnen.

Zitat:

Zitat von mort (Beitrag 1262726)

Hey ich hab es neu runtergeladen und es hatte die logs drin
Hab die reinkopiert die Viren gefunden haben

QUICK-SCAN:
Code:

Windows 7 x64 NTFS
Internet Explorer 11.0.9600.16518
Administrator :: PC-PC [administrator]

02.03.2014 02:05:31
mbam-log-2014-03-02 (02-05-31).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 567813
Time elapsed: 2 hour(s), 54 minute(s), 21 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{fe704bf8-384b-44e1-8cf2-8dbeb3637a8a} (PUP.Optional.ToolBar.WA) -> Data:  -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{fe704bf8-384b-44e1-8cf2-8dbeb3637a8a} (PUP.Optional.ToolBar.WA) -> Data: Поиск WebAlta -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 12
C:\Program Files (x86)\RusTV Player\RusTV Player.exe (PUP.Optional.InstallMonster) -> No action taken.
C:\Program Files (x86)\Ss.Helper\sprotector.dll (PUP.Optional.SProtect.A) -> Quarantined and deleted successfully.
C:\ProgramData\YTD Video Downloader\ytd_installer.exe (PUP.Optional.Spigot.A) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\File System\005\t\00\00000000 (PUP.Optional.OneClickDownloader.A) -> Quarantined and deleted successfully.
C:\Users\Administrator\Desktop\bewerbung\Games\EA GAMES\Need for Speed Rivals\Patch\nfs14.3dm.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Administrator\Desktop\bewerbung\Games\EA GAMES\Need for Speed Rivals\Patch\NFS14.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Administrator\Desktop\bewerbung\Games\GTA\Grand Theft Auto IV\LaunchGTAIV.exe (Packer.ModifiedUPX) -> Quarantined and deleted successfully.
C:\Users\PC\AppData\Local\New Technology Studio\Apps\OpenIV\uninstall.exe (PUP.Optional.InstallMonster) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\F reemakeVideoConverte.rar (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\FreemakeVideoConverterSetup.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\Game_Setup.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\gravitatsiya.exe (PUP.Optional.RuBar.A) -> Quarantined and deleted successfully.

(end)


Dann FULL -SCAN
Code:

Windows 7 x64 NTFS
Internet Explorer 11.0.9600.16518
Administrator :: PC-PC [administrator]

02.03.2014 02:05:31
mbam-log-2014-03-02 (02-05-31).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 567813
Time elapsed: 2 hour(s), 54 minute(s), 21 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{fe704bf8-384b-44e1-8cf2-8dbeb3637a8a} (PUP.Optional.ToolBar.WA) -> Data:  -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{fe704bf8-384b-44e1-8cf2-8dbeb3637a8a} (PUP.Optional.ToolBar.WA) -> Data: Поиск WebAlta -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 12
C:\Program Files (x86)\RusTV Player\RusTV Player.exe (PUP.Optional.InstallMonster) -> No action taken.
C:\Program Files (x86)\Ss.Helper\sprotector.dll (PUP.Optional.SProtect.A) -> Quarantined and deleted successfully.
C:\ProgramData\YTD Video Downloader\ytd_installer.exe (PUP.Optional.Spigot.A) -> Quarantined and deleted successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\File System\005\t\00\00000000 (PUP.Optional.OneClickDownloader.A) -> Quarantined and deleted successfully.
C:\Users\Administrator\Desktop\bewerbung\Games\EA GAMES\Need for Speed Rivals\Patch\nfs14.3dm.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Administrator\Desktop\bewerbung\Games\EA GAMES\Need for Speed Rivals\Patch\NFS14.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Administrator\Desktop\bewerbung\Games\GTA\Grand Theft Auto IV\LaunchGTAIV.exe (Packer.ModifiedUPX) -> Quarantined and deleted successfully.
C:\Users\PC\AppData\Local\New Technology Studio\Apps\OpenIV\uninstall.exe (PUP.Optional.InstallMonster) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\F reemakeVideoConverte.rar (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\FreemakeVideoConverterSetup.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\Game_Setup.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\PC\Downloads\Neuer Ordner\gravitatsiya.exe (PUP.Optional.RuBar.A) -> Quarantined and deleted successfully.

(end)

Noch ein FULL-Scan hier hat es ein Windows datei infiziert gemeldet
Code:

03.03.2014 17:27:18
mbam-log-2014-03-03 (17-27-18).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 557040
Time elapsed: 1 hour(s), 39 minute(s), 52 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A} (PUP.Optional.ToolBar.WA) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A} (PUP.Optional.ToolBar.WA) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Program Files (x86)\RusTV Player\RusTV Player.exe (PUP.Optional.InstallMonster) -> Quarantined and deleted successfully.

(end)


Drancer 05.03.2014 17:50

Zitat:

Zitat von mort (Beitrag 1262722)
Ich brauch das Log von Malwarebytes

Hast du gemerkt das ich die Logfiles gepostet habe ?
Hoffe es passt.

mort 06.03.2014 00:28

Sieht mir grade nicht nach einem Malware-Problem aus

Drancer 06.03.2014 01:03

Zitat:

Zitat von mort (Beitrag 1263416)
Sieht mir grade nicht nach einem Malware-Problem aus

Und was kann ich jetzt machen ? Eine Lösung muss es doch geben.
Wenn ich Formatiere und später herausfinde was das problem war werd ich es sicher bereuen.
Hoffe dir fällt was ein, und ich frag mich warum sonst niemand hier antwortet.

Zitat:

Zitat von mort (Beitrag 1263416)
Sieht mir grade nicht nach einem Malware-Problem aus

Hey mir ist was aufgefallen, also statt QUICK-SCAN hab ich ein FULL-SCAN rein gepostet beim ersten, also doppelt gepostet , die ersten 2 sind gleiche logs.
Hier der Quick Scan hat einiges gefunden.

Code:

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16518
Administrator :: PC-PC [administrator]

26.02.2014 00:33:53
mbam-log-2014-02-26 (00-33-53).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 300135
Time elapsed: 11 minute(s), 59 second(s)

Memory Processes Detected: 2
C:\Program Files (x86)\LPT\srptm.exe (PUP.Optional.Linkury.A) -> 1240 -> Delete on reboot.
C:\Program Files (x86)\LPT\srpts.exe (PUP.Optional.Linkury.A) -> 1940 -> Delete on reboot.

Memory Modules Detected: 16
C:\Program Files (x86)\LPT\Newtonsoft.Json.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Common.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Communication.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Communication.NamedPipe.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Infrastructure.Utilities.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Monetization.Proxy.ProxyService.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Personalization.Common.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\sppsm.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\spusm.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srbs.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srbu.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srpdm.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srpt.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srptc.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srut.dll (PUP.Optional.Linkury.A) -> Delete on reboot.

Registry Keys Detected: 4
HKCR\CLSID\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A} (PUP.Optional.ToolBar.WA) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A} (PUP.Optional.ToolBar.WA) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE704BF8-384B-44E1-8CF2-8DBEB3637A8A} (PUP.Optional.ToolBar.WA) -> Quarantined and deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\LPTSystemUpdater (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.

Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{fe704bf8-384b-44e1-8cf2-8dbeb3637a8a} (PUP.Optional.ToolBar.WA) -> Data:  -> Quarantined and deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\LPTSystemUpdater|ImagePath (PUP.Optional.Linkury.A) -> Data: "C:\Program Files (x86)\LPT\srpts.exe" -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 3
C:\Program Files (x86)\LPT (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Configs (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Resources (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.

Files Detected: 36
C:\Windows\Installer\de1398.msi (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Windows\Installer\de13a2.msi (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\PublisherSettings.xml (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\FiddlerCore.dll (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\HtmlAgilityPack.dll (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\linmsl.exe (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\LPTInstaller.msi (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Newtonsoft.Json.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Proxy.pac (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Smartbar.Common.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Communication.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Communication.NamedPipe.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Infrastructure.Utilities.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Monetization.Proxy.ProxyRemover.exe (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Smartbar.Monetization.Proxy.ProxyService.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Personalization.Common.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\sppsm.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\spusm.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srbs.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srbu.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\sreu.dll (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\srpdm.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srprl.dll (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\srpt.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srptc.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srptm.exe (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srptm.exe.config (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\srpts.exe (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\srut.dll (PUP.Optional.Linkury.A) -> Delete on reboot.
C:\Program Files (x86)\LPT\System.Data.SQLite.dll (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\UserSettings.xml (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Configs\BrowserSettings.xml (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Configs\LPTMapping.xml (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Configs\Timers.xml (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\LPT\Resources\LPT.xml (PUP.Optional.Linkury.A) -> Quarantined and deleted successfully.

(end)


Undertaker 06.03.2014 01:37

moin,

zwischen dem 26.02.2014 00:33:53 und dem 03.03.2014 17:27:18 liegen auch ein paar Tage.
Kein Wunder dass die Logdateien Unterschiede zeigen.

Dein Rechner scheint doch aber zu laufen, ohne Abschaltung, oder postest du von einer anderen Maschine?

Insofern scheint das Problem doch gelöst zu sein.


Gruß Undertaker


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:19 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130