Siteshoot | 23.11.2013 09:21 | Log Malwarebytes: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.11.23.04
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16438
Siteshoot :: SITESHOOT [Administrator]
Schutz: Deaktiviert
23.11.2013 08:52:33
mbam-log-2013-11-23 (08-52-33).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 292627
Laufzeit: 3 Minute(n), 45 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 3
C:\Users\Siteshoot\AppData\Local\Temp\ct3288691 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Siteshoot\AppData\Local\Temp\ct3297265 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Siteshoot\AppData\Local\Temp\ct3297861 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 5
C:\Users\Siteshoot\AppData\Local\Temp\ct3288691\chromeid.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Siteshoot\AppData\Local\Temp\ct3288691\setup.ini.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Siteshoot\AppData\Local\Temp\ct3297265\ism.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Siteshoot\AppData\Local\Temp\ct3297861\chromeid.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Siteshoot\AppData\Local\Temp\ct3297861\setup.ini.txt (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) Log ADW: Code:
# AdwCleaner v3.012 - Bericht erstellt am 23/11/2013 um 08:59:09
# Updated 11/11/2013 von Xplode
# Betriebssystem : Windows 8.1 Pro (64 bits)
# Benutzername : Siteshoot - SITESHOOT
# Gestartet von : E:\download\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : splashtopremoteservice
Dienst Gelöscht : SSUService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\boost_interprocess
Ordner Gelöscht : C:\ProgramData\eSafe
Ordner Gelöscht : C:\ProgramData\Iminent
Ordner Gelöscht : C:\ProgramData\Splashtop
Ordner Gelöscht : C:\ProgramData\StarApp
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\ProgramData\savenshuaree
Ordner Gelöscht : C:\Program Files (x86)\Iminent
Ordner Gelöscht : C:\Program Files (x86)\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\Splashtop
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Umbrella
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Local\AskPartnerNetwork
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Local\eSupport.com
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Local\PutLockerDownloader
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Local\Splashtop
Ordner Gelöscht : C:\Users\Siteshoot\AppData\LocalLow\boost_interprocess
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Roaming\Iminent
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Roaming\iSafe
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PutLockerDownloader.com
Ordner Gelöscht : C:\Users\Siteshoot\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Siteshoot\AppData\Roaming\Mozilla\Firefox\Profiles\xp8syspi.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\Siteshoot\AppData\Roaming\Mozilla\Firefox\Profiles\xp8syspi.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Users\Siteshoot\AppData\Roaming\Mozilla\Firefox\Profiles\xp8syspi.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ocr@babylon.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PutLockerDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02C9C7B0-C7C8-4AAC-A9E4-55295BF60F8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0398B101-6DA7-473F-A290-17D2FBC88CC0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CC36196-8589-4B80-A771-D659411D7F90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{143D96F9-EB64-48B3-B192-91C2C41A1F43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{14F7D91F-F669-45C9-9F42-BACBFDB86EAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{187A6488-6E71-4A2A-B118-7BEFBFE58257}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2D065204-A024-4C39-8A38-EE7078EC7ACF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F5476C-677B-4DB0-B397-51F5BFD86840}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3223F2FB-D9B9-45FC-9D66-CD717FFA4EE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{351798B1-C1D2-45AB-92B4-4D6C2D6AB5AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AEA1BEF-6195-46F4-ACA2-0ED14F7EFA1B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D7F9AC3-BAC3-4E51-81D7-D121D79E550A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4498C5E9-93C6-4142-B6BE-F0C6DC48B77A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{492A108F-51D0-4BD8-899D-AD4AB2893064}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60893E02-2E5B-43F9-A93A-BAD60C2DF6EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6D39931F-451E-4BDD-BAF4-37FB96DBBA5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C684D2-C35D-4284-976A-D862F53ADB81}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{79EF3691-EC1A-4705-A01A-D2E36EC11758}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82F41418-8E64-47EB-A7F1-4702A974D289}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{85D920CE-63A7-46DC-8992-41D1D2E07FAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{895ED5E8-ABB4-40C3-A0CA-2571964268E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8AAC123A-1959-4A45-BFC5-E2D50783098A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A07956CD-81F8-4A03-B524-5D87E690DC83}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B5E3B26B-6E5C-4865-A63D-58D04B10E245}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B84D2DC5-42B2-4E5E-BF61-7B48152FF8EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89D5309-0367-4494-A92F-3D4C94F88307}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C014EBF8-8854-448B-B5A4-557C4090EDCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C31191DB-2F64-464C-B97C-6AC81ACB7AAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C342C7A7-F622-4EF3-8B7F-ABB9FBE73F14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C4765B07-BC2F-477B-925C-B2BF24887823}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD126DA6-FF5B-4181-AC13-54A62240D2FA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E812AE43-7799-4E67-8CF8-4104297A2D16}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F0BAAEC7-9AE0-49FF-9C4B-86E774FF397F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F92193FD-2243-4401-9ACC-49FF30885898}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD21B8A2-910B-45AC-9C10-45E6A8B84984}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{41564952-412D-5637-00A7-7A786E7484D7}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0BF91075-F457-4A8B-99EF-140B52D2F22A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{37425600-CB21-49A0-8659-476FBAB0F8E8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{431FB0E5-2CBB-4602-9FE6-F1D64488ADD7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5C9A230D-70A5-11D5-AFB0-0050DAC67890}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5F339F0B-716F-408F-A627-DEEB5DEB4020}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8911483C-C00A-4183-9FBC-6C9C00946C15}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{928FE5E7-D557-46B7-8AF6-17ACCE1FB4ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C3F058A9-407D-4CD1-8F66-B75605B54B69}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFDCAF05-D29C-4D4D-9836-8CDCD606A6B2}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\smartbar
Schlüssel Gelöscht : HKCU\Software\Splashtop Inc.
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\HappyLyrics
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Plus-HD-2.2
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\Splashtop Inc.
Schlüssel Gelöscht : HKLM\Software\SProtector
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{81FCC50B-950F-4063-8E4A-D99CAA4FBB1F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B7C5EA94-B96A-41F5-BE95-25D78B486678}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Splashtop Software Updater
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Splashtop Inc.
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\49AE5C7BA69B5F14EB59527DB8846687
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\B05CCF18F0593604E8A49DC9AAF4BBF1
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\49AE5C7BA69B5F14EB59527DB8846687
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\B05CCF18F0593604E8A49DC9AAF4BBF1
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16384
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
-\\ Mozilla Firefox v25.0.1 (de)
[ Datei : C:\Users\Siteshoot\AppData\Roaming\Mozilla\Firefox\Profiles\xp8syspi.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.AVIRA-V7.com.avira.dnt.rules", "\"{\\\"Version\\\":38,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Analytics\\\",\\\"category\\\[...]
Zeile gelöscht : user_pref("extensions.AVIRA-V7.domain", "\"avira.search.ask.com\"");
Zeile gelöscht : user_pref("extensions.crossrider.bic", "13f422129ba4886f46393334b5a1d867");
Zeile gelöscht : user_pref("extensions.dB_FI1qNC.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};(function(){try{if(window.opener&&window.self==window.top&&-1==document.cookie[...]
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.LastHiddenTime", 23046594);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", true);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true);
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "somoto");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "8e1c5efd-145a-a996-7914-d90719832a67");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "26/10/2013");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "somoto");
Zeile gelöscht : user_pref("extensions.umr_vlMI.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};new function(){var a=this;a.domain_storage=\"hxxp://xls.searchfun.in\";a.prefix[...]
Zeile gelöscht : user_pref("extensions.wajam.affiliate_id", "8752");
Zeile gelöscht : user_pref("extensions.wajam.firstrun", "false");
Zeile gelöscht : user_pref("extensions.wajam.log_send_info", "false");
Zeile gelöscht : user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21087\",\"update_interval\":1245,\"base_url\":\"hxxp:\\/\\/www.wajam.com\\/\",\"update_url\":\"hxxp:\\/\\/www.wajam.com\\/addon\\/[...]
Zeile gelöscht : user_pref("extensions.wajam.no_trace", "false");
Zeile gelöscht : user_pref("extensions.wajam.server_current_mapping_version", "0.21087");
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.amazon_product.priam_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam'[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.amazon_v2.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';wind[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.ebay_product.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';w[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.ebay_v2.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.encryptedgoogle.wajam_google_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'W[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.google.wajam_google_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.imdb.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';window['W[...]
Zeile gelöscht : user_pref("extensions.wajam.supported_sites.youtubesearch.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam';[...]
Zeile gelöscht : user_pref("extensions.wajam.trace_log", "1383337957198 - onFlagInfoReceived - No user current mapping version specified, set to '0'\n1383337957198 - onFlagInfoReceived - Unique ID saved\n");
Zeile gelöscht : user_pref("extensions.wajam.unique_id", "53FF82FA682AC689126DA7787EF139B1");
Zeile gelöscht : user_pref("extensions.wajam.user_current_mapping_version", "0");
Zeile gelöscht : user_pref("extensions.wajam.version", "1.26");
Zeile gelöscht : user_pref("extentions.webcake.defaultEnableAppsList", "layers,brain/features,newOffers/wc");
Zeile gelöscht : user_pref("extentions.webcake.installId", "5501e8c3-f4b3-4c55-9e21-d99555a5a3d4");
-\\ Google Chrome v
[ Datei : C:\Users\Siteshoot\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [20752 octets] - [23/11/2013 08:58:41]
AdwCleaner[S0].txt - [19770 octets] - [23/11/2013 08:59:09]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19831 octets] ########## Log JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 8.1 Pro x64
Ran by Siteshoot on 23.11.2013 at 9:03:06,44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311301136}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Siteshoot\appdata\local\{94E2CDE9-9307-41EC-8A70-E5861F40DAFD}
~~~ FireFox
Emptied folder: C:\Users\Siteshoot\AppData\Roaming\mozilla\firefox\profiles\xp8syspi.default\minidumps [19 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.11.2013 at 9:07:54,43
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2013
Ran by Siteshoot (administrator) on SITESHOOT on 23-11-2013 09:20:36
Running from C:\Users\Siteshoot\Downloads
Windows 8.1 Pro (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Bitdefender) E:\Program Files (x86)\Bitdefender\Bitdefender\vsserv.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(SUPERAntiSpyware.com) E:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Malwarebytes Corporation) E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Bitdefender) E:\Program Files (x86)\Bitdefender\Bitdefender\updatesrv.exe
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Bitdefender) E:\Program Files (x86)\Bitdefender\Bitdefender Safebox\safeboxservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\beats64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Bitdefender) E:\Program Files (x86)\Bitdefender\Bitdefender\bdagent.exe
(Bitdefender) E:\Program Files (x86)\Bitdefender\Bitdefender\pmbxag.exe
(Bitdefender) E:\Program Files (x86)\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Windows\WinStore\WSHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BeatsOSDApp] - C:\Program Files\IDT\WDM\beats64.exe [37888 2011-08-24] (Hewlett-Packard )
HKLM\...\Run: [hpsysdrv] - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-06-06] (IDT, Inc.)
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] - C:\ProgramData\cis4FC7.exe [4900568 2013-11-11] (COMODO)
HKLM\...\Run: [ShadowPlay] - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Bdagent] - E:\Program Files (x86)\Bitdefender\Bitdefender\bdagent.exe [1738968 2013-10-23] (Bitdefender)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2013-11-19] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKLM\...\Policies\Explorer: [NoCustomizeThisFolder] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKCU\...\Run: [EADM] - E:\Spiele\Origin\Origin.exe [3551576 2013-11-21] (Electronic Arts)
HKCU\...\Run: [Steam] - E:\Spiele\Steam\Steam.exe [1823656 2013-11-18] (Valve Corporation)
HKCU\...\Run: [Bitdefender-Geldbörse-Agent] - E:\Program Files (x86)\Bitdefender\Bitdefender\pmbxag.exe [564256 2013-10-28] (Bitdefender)
HKCU\...\Run: [Bitdefender-Geldbörse] - E:\Program Files (x86)\Bitdefender\Bitdefender\pwdmanui.exe [1004608 2013-10-23] (Bitdefender)
HKCU\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] - E:\Program Files (x86)\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [621448 2013-10-23] (Bitdefender)
HKCU\...\Policies\system: [DisableChangePassword] 0
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKCU\...\Policies\Explorer: [TaskbarNoNotification] 0
HKCU\...\Policies\Explorer: [NoViewContextMenu] 0
HKCU\...\Policies\Explorer: [NoFileMenu] 0
HKCU\...\Policies\Explorer: [NoChangeStartMenu] 0
HKCU\...\Policies\Explorer: [NoRecentDocsMenu] 0
HKCU\...\Policies\Explorer: [NoLogoff] 0
HKCU\...\Policies\Explorer: [NoWindowsUpdate] 0
HKCU\...\Policies\Explorer: [NoDeletePrinter] 1
HKCU\...\Policies\Explorer: [NoAddPrinter] 1
HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Razer Synapse] - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [442200 2013-10-17] (Razer Inc.)
HKLM-x32\...\Run: [ASUS Ai Charger] - C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [iTunesHelper] - E:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-23] (Apple Inc.)
HKU\Administrator\...\Policies\system: [LogonHoursAction] 2
HKU\Administrator\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\DefaultAppPool\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516608 2013-08-22] (Microsoft Corporation)
AppInit_DLLs: [ ] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {C6FE2517-D5D3-45BB-BC27-1E8D6058F25A} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-2/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - E:\Program Files (x86)\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender)
BHO: No Name - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - No File
BHO: No Name - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: No Name - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - No File
BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO-x32: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - E:\Program Files (x86)\Bitdefender\Bitdefender\antispam32\pmbxie.dll (Bitdefender)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - E:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Siteshoot\AppData\Roaming\Mozilla\Firefox\Profiles\xp8syspi.default
FF NewTab: about:blank
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: google.de
FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=ytff-comodo&p=
FF NetworkProxy: "http", "www-proxy.t-online.de"
FF NetworkProxy: "http_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - E:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.6 - e:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 - e:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll No File
FF Plugin-x32: @Bitdefender.com/PasswordManager;version=17.8 - E:\Program Files (x86)\Bitdefender\Bitdefender\Antispam32\pmbxnp.dll (Bitdefender)
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll No File
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin - e:\Spiele\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll No File
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Siteshoot\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Siteshoot\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Siteshoot\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Siteshoot\AppData\Roaming\Mozilla\Firefox\Profiles\xp8syspi.default\Extensions\youtubeunblocker@unblocker.yt
FF Extension: Adblock Plus - C:\Users\Siteshoot\AppData\Roaming\Mozilla\Firefox\Profiles\xp8syspi.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - E:\Program Files (x86)\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - E:\Program Files (x86)\Bitdefender\Bitdefender\bdtbext
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - E:\Program Files (x86)\Bitdefender\Bitdefender\Antispam32\ffpwdman\
FF Extension: Bitdefender Wallet - E:\Program Files (x86)\Bitdefender\Bitdefender\Antispam32\ffpwdman\
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - E:\Program Files (x86)\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - E:\Program Files (x86)\Bitdefender\Bitdefender\bdtbext
FF StartMenuInternet: FIREFOX.EXE - e:\Program Files (x86)\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR HomePage: hxxp://de.yahoo.com?fr=fpc-comodo
CHR RestoreOnStartup: "hxxp://de.yahoo.com?fr=fpc-comodo"
CHR DefaultSearchURL: (Google) - hxxp://www.google.com/search?q={searchTerms}
CHR DefaultSuggestURL: (Google) - "suggest_url": ""
CHR Plugin: (Shockwave Flash) - C:\Users\Siteshoot\AppData\Local\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Siteshoot\AppData\Local\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Siteshoot\AppData\Local\Google\Chrome\Application\29.0.1547.66\pdf.dll No File
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (Microsoft Office 2013) - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
CHR Plugin: (Unity Player) - C:\Users\Siteshoot\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
CHR Plugin: (Google Update) - C:\Users\Siteshoot\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\WINDOWS\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Microsoft Office 2010) - E:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL No File
CHR Plugin: (Microsoft Office 2010) - E:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL No File
CHR Plugin: (Uplay PC) - E:\Program Files (x86)\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
CHR Plugin: (iTunes Application Detector) - E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll No File
CHR Extension: (Adblock Plus) - C:\Users\SITESH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.5_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\SITESH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_1
CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - E:\Program Files (x86)\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx
==================== Services (Whitelisted) =================
R2 !SASCORE; e:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
S3 ArcService; e:\Spiele\Perfect World Entertainment\Arc\ArcService.exe [88424 2013-10-10] (Perfect World Entertainment Inc)
S4 BdDesktopParental; E:\Program Files (x86)\Bitdefender\Bitdefender\bdparentalservice.exe [77120 2013-10-15] (Bitdefender)
S3 Futuremark SystemInfo Service; E:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2013-10-15] (Futuremark)
R2 MBAMScheduler; e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25600 2013-10-19] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc)
R2 PnkBstrA; C:\WINDOWS\SysWow64\PnkBstrA.exe [76888 2013-11-02] ()
R2 RzMaelstromVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe [4241920 2013-09-18] (A-Volute)
R2 SafeBox; E:\Program Files (x86)\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender)
R2 UPDATESRV; E:\Program Files (x86)\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-10-07] (Bitdefender)
R2 VSSERV; E:\Program Files (x86)\Bitdefender\Bitdefender\vsserv.exe [1506736 2013-10-23] (Bitdefender)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-10-19] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [546304 2013-10-19] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [54160 2013-06-18] (Check Point Software Technologies, Ltd.)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-22] (ASUSTek Computer Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2013-10-27] ()
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-07-19] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261496 2013-07-17] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-07-19] (BitDefender)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-07-24] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\WINDOWS\system32\drivers\bdsandbox.sys [82824 2013-07-23] (BitDefender SRL)
R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
S3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2013-07-03] (LogMeIn Inc.)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-10-08] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S3 ks2avs; C:\Windows\System32\Drivers\ks2avs.sys [359784 2012-12-18] (Native Instruments GmbH)
S3 ks2usb_svc; C:\Windows\System32\Drivers\ks2usb.sys [83816 2012-12-18] (Native Instruments GmbH)
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.)
S3 libusb0; C:\Windows\system32\DRIVERS\libusb0.sys [52832 2013-10-27] (hxxp://libusb-win32.sourceforge.net)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2013-10-27] ()
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [173568 2013-10-19] (Microsoft Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-10-13] ()
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [47320 2013-07-29] (Realtek Microelectronics)
R3 RZMAELSTROMVADService; C:\Windows\system32\drivers\RzMaelstromVAD.sys [40696 2013-09-18] (Windows (R) Win 7 DDK provider)
R1 SASDIFSV; e:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; e:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 seehcri; C:\Windows\System32\drivers\seehcri.sys [34032 2013-08-10] (Sony Ericsson Mobile Communications)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146272 2013-08-22] (Microsoft Corporation)
R3 sthid; C:\Windows\System32\drivers\sthid.sys [21216 2013-06-26] (Splashtop Inc.)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
R3 tap0901t; C:\Windows\system32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-08-07] (BitDefender S.R.L.)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 cpuz136; \??\C:\WINDOWS\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 GPUZ; \??\C:\WINDOWS\TEMP\GPUZ.sys [x]
U3 idsvc;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-23 09:07 - 2013-11-23 09:07 - 00001160 _____ C:\Users\Siteshoot\Desktop\JRT.txt
2013-11-23 09:06 - 2013-11-23 09:07 - 00003588 _____ C:\WINDOWS\System32\Tasks\Bitdefender Auto-Scan
2013-11-23 09:06 - 2013-11-23 09:06 - 00596421 _____ C:\ProgramData\1385193710.bdinstall.bin
2013-11-23 09:06 - 2013-11-23 09:06 - 00001110 _____ C:\Users\Public\Desktop\Bitdefender Total Security.lnk
2013-11-23 09:06 - 2013-11-23 09:06 - 00000684 ____H C:\bdr-cf01
2013-11-23 09:06 - 2013-09-08 19:04 - 00023568 _____ (Bitdefender) C:\WINDOWS\system32\Drivers\bdelam.sys
2013-11-23 09:06 - 2013-07-30 17:41 - 00079192 _____ (BitDefender) C:\WINDOWS\system32\Drivers\bdvedisk.sys
2013-11-23 09:06 - 2013-07-24 17:19 - 00098768 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\bdfndisf6.sys
2013-11-23 09:06 - 2013-07-23 15:50 - 00082824 _____ (BitDefender SRL) C:\WINDOWS\system32\Drivers\bdsandbox.sys
2013-11-23 09:06 - 2013-07-19 17:08 - 00601360 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avckf.sys
2013-11-23 09:06 - 2013-07-19 17:04 - 00727592 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avc3.sys
2013-11-23 09:04 - 2013-11-23 09:07 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Bitdefender
2013-11-23 09:04 - 2013-11-23 09:06 - 00253404 ____H C:\bdr-ld01
2013-11-23 09:04 - 2013-11-23 09:06 - 00009216 ____H C:\bdr-ld01.mbr
2013-11-23 09:04 - 2013-09-24 15:38 - 46879860 ____H C:\bdr-im01.gz
2013-11-23 09:04 - 2013-08-13 12:38 - 03271472 ____H C:\bdr-bz01
2013-11-23 09:03 - 2013-11-23 09:03 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-23 09:02 - 2013-08-23 12:48 - 00150256 _____ (BitDefender LLC) C:\WINDOWS\system32\Drivers\gzflt.sys
2013-11-23 09:02 - 2013-08-07 12:46 - 00389240 _____ (BitDefender S.R.L.) C:\WINDOWS\system32\Drivers\trufos.sys
2013-11-23 08:58 - 2013-11-23 08:59 - 00000000 ____D C:\AdwCleaner
2013-11-23 08:56 - 2013-11-23 08:56 - 00062084 _____ C:\ProgramData\1385193393.bdinstall.bin
2013-11-23 08:55 - 2013-11-23 08:55 - 00253532 _____ C:\ProgramData\1385193187.bdinstall.bin
2013-11-23 06:59 - 2013-11-23 07:00 - 00040359 _____ C:\Users\Siteshoot\Downloads\Addition.txt
2013-11-23 06:48 - 2013-11-23 09:20 - 00026479 _____ C:\Users\Siteshoot\Downloads\FRST.txt
2013-11-23 06:48 - 2013-11-23 06:48 - 01957916 _____ (Farbar) C:\Users\Siteshoot\Downloads\FRST64.exe
2013-11-21 04:31 - 2013-11-21 04:34 - 00000000 ____D C:\Users\Siteshoot\Documents\Tongbu
2013-11-21 02:31 - 2013-11-21 02:31 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\kuaiyong
2013-11-21 01:58 - 2013-11-23 09:10 - 00000368 _____ C:\WINDOWS\Tasks\HPCeeScheduleForSiteshoot.job
2013-11-21 00:06 - 2013-11-14 12:57 - 01064224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2013-11-21 00:06 - 2013-11-14 12:57 - 00955168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2013-11-21 00:04 - 2013-11-21 00:06 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-11-21 00:03 - 2013-11-14 12:57 - 01510176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco64.dll
2013-11-21 00:03 - 2013-11-14 12:57 - 00039200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2013-11-21 00:03 - 2013-11-14 12:57 - 00028960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 25257248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 22951200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 18208624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 17560352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 15862272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 12613408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2013-11-21 00:03 - 2013-11-14 12:56 - 11600432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 11514624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 09691888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 09619872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 03132704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 03125024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 02947872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 02747680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433182.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433182.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 00707360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 00657184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 00609568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 00562464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 00317472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2013-11-21 00:03 - 2013-11-14 12:56 - 00266984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2013-11-21 00:02 - 2013-11-21 00:02 - 00000000 ____D C:\NVIDIA
2013-11-20 23:39 - 2013-11-11 15:58 - 04900568 _____ (COMODO) C:\ProgramData\cis4FC7.exe
2013-11-20 21:40 - 2013-11-20 21:40 - 00540304 _____ C:\ProgramData\1384979206.bdinstall.bin
2013-11-20 21:32 - 2013-11-20 21:32 - 00000385 _____ C:\Users\Siteshoot\AppData\Roaminguser_gensett.xml
2013-11-20 21:31 - 2013-11-20 21:31 - 00000385 _____ C:\WINDOWS\system32\user_gensett.xml
2013-11-20 21:31 - 2013-11-20 21:31 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2013-11-20 21:31 - 2013-11-20 21:31 - 00000000 ____D C:\ProgramData\BDLogging
2013-11-20 21:31 - 2013-07-17 18:31 - 00261496 _____ (BitDefender) C:\WINDOWS\system32\Drivers\avchv.sys
2013-11-20 21:31 - 2007-04-11 10:11 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\capicom.dll
2013-11-20 21:28 - 2013-11-20 21:28 - 00000000 _____ C:\ProgramData\1384979206.6916.bin
2013-11-20 21:26 - 2013-11-23 09:06 - 00000000 ____D C:\ProgramData\Bitdefender
2013-11-20 21:26 - 2013-11-23 09:02 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-11-20 21:26 - 2013-11-23 08:59 - 00000000 ____D C:\Program Files\Bitdefender
2013-11-20 21:26 - 2013-11-20 21:26 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\QuickScan
2013-11-20 21:25 - 2013-10-16 16:58 - 01943536 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2013-11-20 21:25 - 2013-10-16 14:54 - 01581968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2013-11-17 16:48 - 2013-11-17 16:48 - 00000000 ____D C:\FRST
2013-11-17 15:47 - 2013-11-17 15:47 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Malwarebytes
2013-11-17 15:46 - 2013-11-17 15:46 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-17 15:46 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-11-17 07:24 - 2013-11-20 16:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-17 02:21 - 2013-11-17 02:21 - 00000000 ____D C:\Users\Siteshoot\Documents\Egosoft
2013-11-17 00:58 - 2013-11-17 00:58 - 00003966 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B247946D-71D0-4A0C-BAF0-8DCC579DE8E0}
2013-11-17 00:57 - 2013-11-17 00:57 - 00003592 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3724801019-102522093-526387549-500
2013-11-17 00:56 - 2013-10-23 12:29 - 00044936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2013-11-17 00:56 - 2013-10-23 12:21 - 00155480 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2013-11-17 00:56 - 2013-10-23 12:13 - 00171864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kd_02_8086.dll
2013-11-17 00:56 - 2013-10-23 06:27 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-17 00:56 - 2013-10-23 06:09 - 04104704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-11-17 00:56 - 2013-10-23 06:04 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-17 00:56 - 2013-10-23 05:55 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-11-17 00:56 - 2013-10-23 05:46 - 00700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-11-17 00:56 - 2013-10-22 09:18 - 01287064 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2013-11-17 00:56 - 2013-10-22 09:18 - 00096088 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedapplauncher.exe
2013-11-17 00:56 - 2013-10-22 08:55 - 02328872 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-11-17 00:56 - 2013-10-22 07:03 - 02065448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-11-17 00:56 - 2013-10-22 06:15 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2013-11-17 00:56 - 2013-10-22 05:04 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2013-11-17 00:56 - 2013-10-22 05:02 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2013-11-17 00:56 - 2013-10-22 04:56 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2013-11-17 00:56 - 2013-10-22 04:44 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2013-11-17 00:56 - 2013-10-22 03:38 - 01362944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2013-11-17 00:56 - 2013-10-22 03:22 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-11-17 00:56 - 2013-10-22 03:13 - 01704448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-11-17 00:56 - 2013-10-22 03:07 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2013-11-17 00:56 - 2013-10-22 02:53 - 01584128 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2013-11-17 00:56 - 2013-10-22 02:47 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2013-11-17 00:56 - 2013-10-19 10:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-11-17 00:56 - 2013-10-19 09:51 - 00481392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2013-11-17 00:56 - 2013-10-19 09:08 - 23212544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-17 00:56 - 2013-10-19 08:12 - 00380656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2013-11-17 00:56 - 2013-10-19 07:37 - 17142784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-11-17 00:56 - 2013-10-19 07:24 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-11-17 00:56 - 2013-10-19 07:02 - 02764288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-17 00:56 - 2013-10-19 06:37 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2013-11-17 00:56 - 2013-10-19 06:19 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-17 00:56 - 2013-10-19 06:10 - 05765120 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-17 00:56 - 2013-10-19 05:52 - 02166272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-11-17 00:56 - 2013-10-19 05:48 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2013-11-17 00:56 - 2013-10-19 05:44 - 04240384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-11-17 00:56 - 2013-10-19 05:37 - 12995584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-17 00:56 - 2013-10-19 05:31 - 01993728 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-17 00:56 - 2013-10-19 05:03 - 00531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2013-11-17 00:56 - 2013-10-19 04:57 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-11-17 00:56 - 2013-10-19 04:56 - 11220992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-11-17 00:56 - 2013-10-19 04:55 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2013-11-17 00:56 - 2013-10-19 04:53 - 02332160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-17 00:56 - 2013-10-19 04:28 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-11-17 00:56 - 2013-10-19 04:26 - 01231360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2013-11-17 00:56 - 2013-10-19 04:23 - 01394176 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-11-17 00:56 - 2013-10-19 04:14 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2013-11-17 00:56 - 2013-10-19 04:09 - 01818112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-11-17 00:56 - 2013-10-19 04:02 - 01156608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-11-17 00:56 - 2013-10-17 16:42 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2013-11-17 00:56 - 2013-10-17 16:42 - 01373872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2013-11-17 00:56 - 2013-10-17 15:04 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2013-11-17 00:56 - 2013-10-16 10:34 - 00518656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2013-11-17 00:56 - 2013-10-16 10:33 - 00631296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2013-11-17 00:56 - 2013-10-13 04:06 - 00258904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2013-11-17 00:56 - 2013-10-13 03:43 - 00708616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2013-11-17 00:56 - 2013-10-11 16:11 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-11-17 00:56 - 2013-10-11 15:22 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-11-17 00:56 - 2013-10-11 14:24 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2013-11-17 00:56 - 2013-10-11 14:04 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-11-17 00:56 - 2013-10-11 14:03 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2013-11-17 00:56 - 2013-10-10 17:44 - 00031064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2013-11-17 00:56 - 2013-10-10 17:26 - 00317616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2013-11-17 00:56 - 2013-10-10 17:26 - 00104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2013-11-17 00:56 - 2013-10-10 17:23 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2013-11-17 00:56 - 2013-10-10 15:53 - 00235960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2013-11-17 00:56 - 2013-10-10 15:53 - 00088272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2013-11-17 00:56 - 2013-10-10 12:53 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2013-11-17 00:56 - 2013-10-10 12:38 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2013-11-17 00:56 - 2013-10-10 12:21 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2013-11-17 00:56 - 2013-10-10 11:40 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-11-17 00:56 - 2013-10-10 11:19 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-11-17 00:56 - 2013-10-09 06:40 - 00385528 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-11-17 00:56 - 2013-10-08 12:07 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-11-17 00:56 - 2013-10-08 11:28 - 00523096 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2013-11-17 00:56 - 2013-10-08 11:13 - 02551640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-11-17 00:56 - 2013-10-08 07:46 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shsetup.dll
2013-11-17 00:56 - 2013-10-08 06:58 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shsetup.dll
2013-11-17 00:56 - 2013-10-08 06:50 - 00656384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2013-11-17 00:56 - 2013-10-08 06:48 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2013-11-17 00:56 - 2013-10-08 06:15 - 00492544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2013-11-17 00:56 - 2013-10-08 06:09 - 01160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2013-11-17 00:56 - 2013-10-08 05:50 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2013-11-17 00:56 - 2013-10-08 05:50 - 00762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2013-11-17 00:56 - 2013-10-07 08:21 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-11-17 00:56 - 2013-10-07 08:21 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-11-17 00:56 - 2013-10-07 03:13 - 03532288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-11-17 00:56 - 2013-10-05 16:25 - 00371032 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-11-17 00:56 - 2013-10-05 16:25 - 00057176 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2013-11-17 00:56 - 2013-10-05 15:21 - 00699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2013-11-17 00:56 - 2013-10-05 13:05 - 00578952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2013-11-17 00:56 - 2013-10-05 12:01 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2013-11-17 00:56 - 2013-10-05 10:36 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2013-11-17 00:56 - 2013-10-05 10:18 - 01011712 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2013-11-17 00:56 - 2013-10-05 10:07 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-11-17 00:56 - 2013-10-05 09:56 - 01147904 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2013-11-17 00:56 - 2013-10-05 09:55 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\miutils.dll
2013-11-17 00:56 - 2013-10-05 09:40 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2013-11-17 00:56 - 2013-10-05 09:24 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\miutils.dll
2013-11-17 00:56 - 2013-10-05 09:21 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2013-11-17 00:56 - 2013-10-05 09:15 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2013-11-17 00:56 - 2013-10-05 08:43 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2013-11-17 00:56 - 2013-10-05 08:39 - 06639616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2013-11-17 00:56 - 2013-10-05 08:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-11-17 00:56 - 2013-10-05 08:32 - 05769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2013-11-17 00:56 - 2013-10-04 09:10 - 00533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2013-11-17 00:56 - 2013-09-19 06:04 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2013-11-17 00:56 - 2013-09-17 10:06 - 01067080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-11-17 00:56 - 2013-09-17 10:06 - 00465960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2013-11-17 00:56 - 2013-09-17 08:01 - 00270848 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2013-11-17 00:56 - 2013-09-17 07:31 - 00883184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-11-17 00:56 - 2013-09-17 07:31 - 00326024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2013-11-17 00:56 - 2013-09-17 05:37 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2013-11-17 00:56 - 2013-09-14 15:07 - 02134120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2013-11-17 00:56 - 2013-09-14 15:00 - 00391512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll
2013-11-17 00:56 - 2013-09-14 13:39 - 01799944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2013-11-17 00:56 - 2013-09-14 13:33 - 00345552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll
2013-11-17 00:56 - 2013-09-14 11:05 - 00338944 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2013-11-17 00:56 - 2013-09-14 10:11 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2013-11-17 00:56 - 2013-09-13 09:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ftp.exe
2013-11-17 00:56 - 2013-09-13 08:47 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ftp.exe
2013-11-17 00:56 - 2013-09-12 09:45 - 00101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2013-11-17 00:56 - 2013-09-12 09:08 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2013-11-17 00:56 - 2013-09-12 09:08 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2013-11-17 00:56 - 2013-09-12 09:02 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2013-11-17 00:56 - 2013-09-12 08:44 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2013-11-17 00:56 - 2013-09-12 08:37 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2013-11-17 00:56 - 2013-09-12 08:37 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2013-11-17 00:56 - 2013-09-12 08:21 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2013-11-17 00:56 - 2013-09-12 08:16 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2013-11-17 00:56 - 2013-09-12 08:01 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2013-11-17 00:56 - 2013-09-11 13:46 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-11-17 00:56 - 2013-09-10 06:26 - 04599808 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2013-11-17 00:56 - 2013-09-10 05:52 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\msched.dll
2013-11-17 00:56 - 2013-09-10 05:34 - 03934208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2013-11-17 00:51 - 2013-11-23 08:59 - 00025764 _____ C:\WINDOWS\PFRO.log
2013-11-17 00:41 - 2013-11-17 00:41 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-11-17 00:41 - 2013-11-05 21:21 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2013-11-17 00:41 - 2013-11-05 19:51 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2013-11-17 00:41 - 2013-11-05 17:20 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-17 00:41 - 2013-11-05 17:11 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-17 00:41 - 2013-11-05 15:30 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-11-17 00:41 - 2013-11-05 15:29 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-11-17 00:41 - 2013-10-13 03:48 - 00136536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-11-17 00:41 - 2013-10-12 22:48 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-11-17 00:41 - 2013-10-12 22:34 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-11-17 00:41 - 2013-10-10 12:26 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2013-11-17 00:41 - 2013-10-10 12:05 - 01019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2013-11-17 00:41 - 2013-10-10 11:34 - 01085952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2013-11-17 00:41 - 2013-10-10 11:27 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2013-11-17 00:41 - 2013-10-05 15:21 - 01341288 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-11-17 00:41 - 2013-10-05 09:39 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-11-17 00:40 - 2013-11-17 00:40 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2013-11-17 00:40 - 2013-11-17 00:40 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2013-11-17 00:40 - 2013-11-17 00:40 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-11-17 00:40 - 2013-11-17 00:40 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-11-17 00:39 - 2013-11-17 00:39 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-11-17 00:39 - 2013-11-17 00:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-11-17 00:38 - 2013-11-17 00:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-11-17 00:37 - 2013-11-23 09:06 - 00000793 _____ C:\WINDOWS\setupact.log
2013-11-17 00:37 - 2013-11-17 00:37 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-16 23:31 - 2013-11-16 23:34 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\download.am-data
2013-11-15 23:11 - 2013-11-15 23:11 - 00000000 ____D C:\Users\Siteshoot\Documents\Assassin's Creed IV Black Flag
2013-11-11 08:59 - 2013-11-11 08:59 - 00590112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2013-11-09 15:00 - 2013-11-09 15:00 - 00000000 ____D C:\Users\Siteshoot\apktool
2013-11-09 14:55 - 2013-11-09 14:55 - 00312744 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-11-09 14:55 - 2013-11-09 14:55 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-11-09 14:55 - 2013-11-09 14:55 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-11-09 14:55 - 2013-11-09 14:55 - 00108968 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2013-11-09 14:53 - 2013-11-09 14:53 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2013-11-09 14:53 - 2013-11-09 14:53 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2013-11-09 14:53 - 2013-11-09 14:53 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2013-11-09 14:53 - 2013-11-09 14:53 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2013-11-09 14:53 - 2013-11-09 14:53 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-09 14:35 - 2013-11-09 15:47 - 00000000 ____D C:\android
2013-11-09 01:10 - 2013-11-20 23:39 - 01474832 _____ C:\WINDOWS\system32\Drivers\sfi.dat
2013-11-02 19:30 - 2013-11-02 19:30 - 00000000 ____D C:\ProgramData\IObit
2013-11-02 04:46 - 2013-11-02 05:05 - 00000000 ____D C:\ProgramData\DriverGenius
2013-11-02 03:16 - 2013-11-02 03:16 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Arc
2013-11-02 03:08 - 2013-11-02 03:08 - 00000699 _____ C:\Users\Public\Desktop\Arc.lnk
2013-11-01 21:29 - 2013-10-23 12:01 - 00872840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2013-11-01 21:29 - 2013-10-23 09:59 - 00698232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2013-11-01 20:28 - 2013-11-01 20:28 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Sniper Elite Nazi Zombie Army 2
2013-11-01 20:28 - 2013-11-01 20:28 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\EMU
2013-11-01 20:06 - 2013-11-01 20:06 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\SUPERAntiSpyware.com
2013-11-01 20:06 - 2013-11-01 20:06 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-10-27 17:08 - 2013-10-27 17:08 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\libimobiledevice
2013-10-27 16:46 - 2013-10-27 16:46 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-27 16:46 - 2013-10-27 16:46 - 00000000 ____D C:\Program Files\iTunes
2013-10-27 16:46 - 2013-10-27 16:46 - 00000000 ____D C:\Program Files\iPod
2013-10-27 16:18 - 2013-10-27 16:18 - 00000000 ____D C:\Program Files (x86)\ASUS
2013-10-27 16:18 - 2012-03-22 16:10 - 00014848 _____ (ASUSTek Computer Inc.) C:\WINDOWS\SysWOW64\Drivers\AiCharger.sys
2013-10-27 12:11 - 2013-11-23 09:16 - 00000000 __RDO C:\Users\Siteshoot\SkyDrive
2013-10-27 10:55 - 2013-10-27 10:55 - 00000000 ____D C:\WINDOWS\PCHEALTH
2013-10-27 10:54 - 2013-10-27 10:54 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-10-27 10:54 - 2013-10-27 10:54 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-10-27 10:51 - 2013-11-09 14:55 - 00000000 ____D C:\ProgramData\Oracle
2013-10-27 10:49 - 2013-10-27 10:49 - 00004973 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-27 10:28 - 2013-10-27 10:28 - 00001160 _____ C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Badoo Desktop.lnk
2013-10-27 10:28 - 2013-10-27 10:28 - 00000000 ____D C:\ProgramData\Badoo
2013-10-27 05:12 - 2013-10-27 10:35 - 00003032 _____ C:\WINDOWS\System32\Tasks\MSIAfterburner
2013-10-27 04:47 - 2013-10-27 04:47 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Sniper Elite Nazi Zombie Army
2013-10-27 03:58 - 2013-10-27 04:10 - 00310984 _____ C:\WINDOWS\system32\Drivers\atksgt.sys
2013-10-27 03:58 - 2013-10-27 04:10 - 00042696 _____ C:\WINDOWS\system32\Drivers\lirsgt.sys
2013-10-27 00:54 - 2013-10-27 01:05 - 00000000 ____D C:\Users\Siteshoot\Heaven
2013-10-27 00:53 - 2013-10-27 01:02 - 01065984 _____ C:\Users\Siteshoot\AppData\Local\file__0.localstorage
2013-10-27 00:17 - 2013-10-27 00:17 - 00076384 _____ (hxxp://libusb-win32.sourceforge.net) C:\WINDOWS\system32\libusb0.dll
2013-10-27 00:17 - 2013-10-27 00:17 - 00052832 _____ (hxxp://libusb-win32.sourceforge.net) C:\WINDOWS\system32\Drivers\libusb0.sys
2013-10-27 00:15 - 2012-01-17 08:40 - 00067680 _____ (hxxp://libusb-win32.sourceforge.net) C:\WINDOWS\SysWOW64\libusb0.dll
2013-10-26 23:47 - 2013-10-27 10:35 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2013-10-26 23:29 - 2013-11-17 00:04 - 00000000 ____D C:\WINDOWS\Minidump
2013-10-26 22:50 - 2013-10-26 22:50 - 00000000 ____D C:\Intel
2013-10-26 21:32 - 2013-10-26 23:47 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2013-10-26 16:01 - 2013-10-26 16:01 - 00002389 _____ C:\Users\Siteshoot\Documents\Firefox-Wiederherstellungs-Schlüssel.html
2013-10-26 15:35 - 2013-10-26 15:35 - 00001448 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-26 15:35 - 2013-10-26 15:35 - 00000680 __RSH C:\Users\Administrator\ntuser.pol
2013-10-26 15:35 - 2013-10-26 15:35 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2013-10-26 15:30 - 2013-10-26 15:30 - 00000000 ____D C:\Users\Siteshoot\Documents\god.{ED7BA470-8E54-465E-825C-99712043E01C}
2013-10-26 15:22 - 2013-10-27 12:11 - 00000000 __RDO C:\Users\Siteshoot\SkyDrive.old
2013-10-26 15:03 - 2013-10-26 15:03 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-10-26 14:57 - 2013-11-01 21:31 - 00001174 _____ C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-10-26 14:52 - 2013-10-26 14:52 - 00000000 ____D C:\ProgramData\Advanced
2013-10-25 14:59 - 2013-11-14 12:56 - 00061216 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2013-10-25 14:59 - 2013-11-14 12:56 - 00053024 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2013-10-25 14:59 - 2013-11-11 16:02 - 06674208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2013-10-25 14:59 - 2013-11-11 16:02 - 03490080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2013-10-25 14:59 - 2013-11-11 16:01 - 03467927 _____ C:\WINDOWS\system32\nvcoproc.bin
2013-10-25 14:59 - 2013-11-11 16:01 - 02559776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2013-10-25 14:59 - 2013-11-11 16:01 - 00922912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2013-10-25 14:59 - 2013-11-11 16:01 - 00219424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2013-10-25 14:59 - 2013-11-11 16:01 - 00063776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 30361888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 18293608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 15218504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 03069608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 02697248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 01436528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 01242400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 00168616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 00141336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2013-10-25 14:58 - 2013-11-14 12:56 - 00023754 _____ C:\WINDOWS\system32\nvinfo.pb
2013-10-25 14:58 - 2013-10-16 01:48 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433158.dll
2013-10-25 14:58 - 2013-10-16 01:48 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433158.dll
2013-10-25 14:58 - 2013-06-16 13:38 - 00196384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2013-10-25 14:58 - 2013-06-16 13:38 - 00031520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2013-10-25 14:58 - 2013-01-29 09:35 - 01510176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
==================== One Month Modified Files and Folders =======
2013-11-23 09:21 - 2013-11-23 06:48 - 00026479 _____ C:\Users\Siteshoot\Downloads\FRST.txt
2013-11-23 09:21 - 2013-08-09 18:30 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3724801019-102522093-526387549-1000
2013-11-23 09:21 - 2013-02-28 18:46 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2013-11-23 09:20 - 2013-03-16 18:00 - 00000000 _____ C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-11-23 09:20 - 2013-02-28 18:43 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\HP Support Assistant
2013-11-23 09:20 - 2013-02-21 16:48 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\HpUpdate
2013-11-23 09:18 - 2013-02-20 16:57 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-11-23 09:16 - 2013-10-27 12:11 - 00000000 __RDO C:\Users\Siteshoot\SkyDrive
2013-11-23 09:16 - 2013-10-18 23:34 - 01671051 _____ C:\WINDOWS\WindowsUpdate.log
2013-11-23 09:16 - 2011-10-13 07:12 - 00000000 ____D C:\ProgramData\PDFC
2013-11-23 09:15 - 2013-10-18 23:34 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-23 09:15 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-11-23 09:14 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2013-11-23 09:10 - 2013-11-21 01:58 - 00000368 _____ C:\WINDOWS\Tasks\HPCeeScheduleForSiteshoot.job
2013-11-23 09:07 - 2013-11-23 09:07 - 00001160 _____ C:\Users\Siteshoot\Desktop\JRT.txt
2013-11-23 09:07 - 2013-11-23 09:06 - 00003588 _____ C:\WINDOWS\System32\Tasks\Bitdefender Auto-Scan
2013-11-23 09:07 - 2013-11-23 09:04 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Bitdefender
2013-11-23 09:06 - 2013-11-23 09:06 - 00596421 _____ C:\ProgramData\1385193710.bdinstall.bin
2013-11-23 09:06 - 2013-11-23 09:06 - 00001110 _____ C:\Users\Public\Desktop\Bitdefender Total Security.lnk
2013-11-23 09:06 - 2013-11-23 09:06 - 00000684 ____H C:\bdr-cf01
2013-11-23 09:06 - 2013-11-23 09:04 - 00253404 ____H C:\bdr-ld01
2013-11-23 09:06 - 2013-11-23 09:04 - 00009216 ____H C:\bdr-ld01.mbr
2013-11-23 09:06 - 2013-11-20 21:26 - 00000000 ____D C:\ProgramData\Bitdefender
2013-11-23 09:06 - 2013-11-17 00:37 - 00000793 _____ C:\WINDOWS\setupact.log
2013-11-23 09:05 - 2009-07-14 06:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2013-11-23 09:03 - 2013-11-23 09:03 - 00000000 ____D C:\WINDOWS\ERUNT
2013-11-23 09:02 - 2013-11-20 21:26 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-11-23 09:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-11-23 08:59 - 2013-11-23 08:58 - 00000000 ____D C:\AdwCleaner
2013-11-23 08:59 - 2013-11-20 21:26 - 00000000 ____D C:\Program Files\Bitdefender
2013-11-23 08:59 - 2013-11-17 00:51 - 00025764 _____ C:\WINDOWS\PFRO.log
2013-11-23 08:56 - 2013-11-23 08:56 - 00062084 _____ C:\ProgramData\1385193393.bdinstall.bin
2013-11-23 08:55 - 2013-11-23 08:55 - 00253532 _____ C:\ProgramData\1385193187.bdinstall.bin
2013-11-23 08:49 - 2013-02-20 16:39 - 00000000 ____D C:\Users\Siteshoot\Desktop\Programme
2013-11-23 08:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2013-11-23 07:00 - 2013-11-23 06:59 - 00040359 _____ C:\Users\Siteshoot\Downloads\Addition.txt
2013-11-23 06:48 - 2013-11-23 06:48 - 01957916 _____ (Farbar) C:\Users\Siteshoot\Downloads\FRST64.exe
2013-11-23 06:46 - 2013-10-18 23:34 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-11-21 07:13 - 2013-03-10 08:01 - 00000000 ____D C:\WINDOWS\Re-Aktivierung
2013-11-21 04:51 - 2013-10-20 07:21 - 00214392 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2013-11-21 04:34 - 2013-11-21 04:31 - 00000000 ____D C:\Users\Siteshoot\Documents\Tongbu
2013-11-21 02:36 - 2013-09-28 17:00 - 00000000 ____D C:\Users\Siteshoot\Documents\FIFA 14
2013-11-21 02:31 - 2013-11-21 02:31 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\kuaiyong
2013-11-21 01:58 - 2013-09-30 05:14 - 02072784 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-21 01:58 - 2013-09-30 04:56 - 00880462 _____ C:\WINDOWS\system32\perfh007.dat
2013-11-21 01:58 - 2013-09-30 04:56 - 00201996 _____ C:\WINDOWS\system32\perfc007.dat
2013-11-21 00:53 - 2013-02-28 19:01 - 00214392 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2013-11-21 00:06 - 2013-11-21 00:04 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-11-21 00:06 - 2013-10-18 23:34 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-11-21 00:06 - 2013-10-18 23:34 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-11-21 00:02 - 2013-11-21 00:02 - 00000000 ____D C:\NVIDIA
2013-11-20 23:39 - 2013-11-09 01:10 - 01474832 _____ C:\WINDOWS\system32\Drivers\sfi.dat
2013-11-20 23:39 - 2013-02-20 16:24 - 00000000 ____D C:\WINDOWS\System32\Tasks\COMODO
2013-11-20 21:42 - 2013-09-08 12:51 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins
2013-11-20 21:42 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2013-11-20 21:40 - 2013-11-20 21:40 - 00540304 _____ C:\ProgramData\1384979206.bdinstall.bin
2013-11-20 21:32 - 2013-11-20 21:32 - 00000385 _____ C:\Users\Siteshoot\AppData\Roaminguser_gensett.xml
2013-11-20 21:31 - 2013-11-20 21:31 - 00000385 _____ C:\WINDOWS\system32\user_gensett.xml
2013-11-20 21:31 - 2013-11-20 21:31 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2013-11-20 21:31 - 2013-11-20 21:31 - 00000000 ____D C:\ProgramData\BDLogging
2013-11-20 21:28 - 2013-11-20 21:28 - 00000000 _____ C:\ProgramData\1384979206.6916.bin
2013-11-20 21:26 - 2013-11-20 21:26 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\QuickScan
2013-11-20 19:38 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2013-11-20 17:48 - 2013-03-26 21:56 - 00000000 ____D C:\ProgramData\DivX
2013-11-20 17:48 - 2013-03-26 21:56 - 00000000 ____D C:\Program Files (x86)\DivX
2013-11-20 17:48 - 2013-03-13 14:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-20 17:47 - 2013-03-26 21:58 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\DivX
2013-11-20 17:47 - 2013-03-26 21:57 - 00000000 ____D C:\Program Files\DivX
2013-11-20 16:23 - 2013-11-17 07:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-17 16:48 - 2013-11-17 16:48 - 00000000 ____D C:\FRST
2013-11-17 16:00 - 2013-10-18 23:41 - 00000000 ____D C:\Users\Siteshoot
2013-11-17 15:47 - 2013-11-17 15:47 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Malwarebytes
2013-11-17 15:46 - 2013-11-17 15:46 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-17 02:27 - 2013-09-07 21:09 - 00000000 ____D C:\Users\Siteshoot\Desktop\Spiele
2013-11-17 02:21 - 2013-11-17 02:21 - 00000000 ____D C:\Users\Siteshoot\Documents\Egosoft
2013-11-17 01:03 - 2013-02-20 15:06 - 00000000 ___RD C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-17 01:03 - 2013-02-20 15:06 - 00000000 ___RD C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-17 01:02 - 2013-08-22 15:44 - 00509144 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-17 01:01 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData
2013-11-17 01:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-11-17 01:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\migwiz
2013-11-17 01:01 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-11-17 00:59 - 2013-07-28 07:42 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-11-17 00:58 - 2013-11-17 00:58 - 00003966 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B247946D-71D0-4A0C-BAF0-8DCC579DE8E0}
2013-11-17 00:57 - 2013-11-17 00:57 - 00003592 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3724801019-102522093-526387549-500
2013-11-17 00:57 - 2013-02-21 16:26 - 82896128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-11-17 00:42 - 2013-03-10 07:48 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-17 00:41 - 2013-11-17 00:41 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-11-17 00:41 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-17 00:40 - 2013-11-17 00:40 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2013-11-17 00:40 - 2013-11-17 00:40 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2013-11-17 00:40 - 2013-11-17 00:40 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-11-17 00:40 - 2013-11-17 00:40 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-11-17 00:39 - 2013-11-17 00:39 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-11-17 00:39 - 2013-11-17 00:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-11-17 00:39 - 2013-08-22 16:36 - 00000000 ____D C:\Program Files\Common Files\System
2013-11-17 00:39 - 2009-07-14 03:34 - 00000478 _____ C:\WINDOWS\win.ini
2013-11-17 00:38 - 2013-11-17 00:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-11-17 00:37 - 2013-11-17 00:37 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-11-17 00:13 - 2013-07-28 07:41 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Adobe
2013-11-17 00:12 - 2013-02-20 16:57 - 00003796 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2013-11-17 00:06 - 2013-06-25 23:28 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Razer
2013-11-17 00:06 - 2013-06-25 23:27 - 00000000 ____D C:\ProgramData\Razer
2013-11-17 00:05 - 2013-09-30 04:59 - 00000000 ____D C:\WINDOWS\ShellNew
2013-11-17 00:04 - 2013-10-26 23:29 - 00000000 ____D C:\WINDOWS\Minidump
2013-11-16 23:51 - 2011-10-13 07:02 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-16 23:34 - 2013-11-16 23:31 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\download.am-data
2013-11-16 19:53 - 2013-02-20 16:35 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\vlc
2013-11-16 19:42 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\tracing
2013-11-15 23:11 - 2013-11-15 23:11 - 00000000 ____D C:\Users\Siteshoot\Documents\Assassin's Creed IV Black Flag
2013-11-15 22:06 - 2013-04-20 08:11 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Audacity
2013-11-15 20:48 - 2013-04-20 17:26 - 00000178 _____ C:\Users\Siteshoot\Desktop\Uploaded.txt
2013-11-14 12:57 - 2013-11-21 00:06 - 01064224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2013-11-14 12:57 - 2013-11-21 00:06 - 00955168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2013-11-14 12:57 - 2013-11-21 00:03 - 01510176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco64.dll
2013-11-14 12:57 - 2013-11-21 00:03 - 00039200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2013-11-14 12:57 - 2013-11-21 00:03 - 00028960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2013-11-14 12:57 - 2013-10-03 21:38 - 00029984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 25257248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 22951200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 18208624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 17560352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 15862272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 12613408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2013-11-14 12:56 - 2013-11-21 00:03 - 11600432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 11514624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 09691888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 09619872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 03132704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 03125024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 02947872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 02747680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433182.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433182.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 00707360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 00657184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 00609568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 00562464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 00317472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2013-11-14 12:56 - 2013-11-21 00:03 - 00266984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2013-11-14 12:56 - 2013-10-25 14:59 - 00061216 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2013-11-14 12:56 - 2013-10-25 14:59 - 00053024 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 30361888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 18293608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 15218504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 03069608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 02697248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 01436528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 01242400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 00168616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 00141336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2013-11-14 12:56 - 2013-10-25 14:58 - 00023754 _____ C:\WINDOWS\system32\nvinfo.pb
2013-11-11 19:40 - 2013-08-09 18:24 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Packages
2013-11-11 16:02 - 2013-10-25 14:59 - 06674208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2013-11-11 16:02 - 2013-10-25 14:59 - 03490080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2013-11-11 16:01 - 2013-10-25 14:59 - 03467927 _____ C:\WINDOWS\system32\nvcoproc.bin
2013-11-11 16:01 - 2013-10-25 14:59 - 02559776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2013-11-11 16:01 - 2013-10-25 14:59 - 00922912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2013-11-11 16:01 - 2013-10-25 14:59 - 00219424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2013-11-11 16:01 - 2013-10-25 14:59 - 00063776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2013-11-11 15:58 - 2013-11-20 23:39 - 04900568 _____ (COMODO) C:\ProgramData\cis4FC7.exe
2013-11-11 08:59 - 2013-11-11 08:59 - 00590112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2013-11-09 15:47 - 2013-11-09 14:35 - 00000000 ____D C:\android
2013-11-09 15:00 - 2013-11-09 15:00 - 00000000 ____D C:\Users\Siteshoot\apktool
2013-11-09 14:55 - 2013-11-09 14:55 - 00312744 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2013-11-09 14:55 - 2013-11-09 14:55 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2013-11-09 14:55 - 2013-11-09 14:55 - 00189352 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2013-11-09 14:55 - 2013-11-09 14:55 - 00108968 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2013-11-09 14:55 - 2013-10-27 10:51 - 00000000 ____D C:\ProgramData\Oracle
2013-11-09 14:53 - 2013-11-09 14:53 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2013-11-09 14:53 - 2013-11-09 14:53 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2013-11-09 14:53 - 2013-11-09 14:53 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2013-11-09 14:53 - 2013-11-09 14:53 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2013-11-09 14:53 - 2013-11-09 14:53 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-09 01:10 - 2012-07-26 06:37 - 00000000 ____D C:\Users\Default.migrated
2013-11-06 00:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-11-06 00:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-05 21:21 - 2013-11-17 00:41 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2013-11-05 19:51 - 2013-11-17 00:41 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2013-11-05 17:20 - 2013-11-17 00:41 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2013-11-05 17:11 - 2013-11-17 00:41 - 18577408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2013-11-05 15:30 - 2013-11-17 00:41 - 11674112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-11-05 15:29 - 2013-11-17 00:41 - 13176320 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-11-03 11:35 - 2013-07-19 21:25 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Skype
2013-11-02 19:30 - 2013-11-02 19:30 - 00000000 ____D C:\ProgramData\IObit
2013-11-02 16:23 - 2013-10-20 07:21 - 00076888 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe
2013-11-02 05:05 - 2013-11-02 04:46 - 00000000 ____D C:\ProgramData\DriverGenius
2013-11-02 03:17 - 2013-03-02 16:06 - 00283032 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2013-11-02 03:16 - 2013-11-02 03:16 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Arc
2013-11-02 03:08 - 2013-11-02 03:08 - 00000699 _____ C:\Users\Public\Desktop\Arc.lnk
2013-11-01 21:31 - 2013-10-26 14:57 - 00001174 _____ C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-11-01 21:31 - 2013-10-18 23:57 - 00001452 _____ C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-01 20:28 - 2013-11-01 20:28 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Sniper Elite Nazi Zombie Army 2
2013-11-01 20:28 - 2013-11-01 20:28 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\EMU
2013-11-01 20:06 - 2013-11-01 20:06 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\SUPERAntiSpyware.com
2013-11-01 20:06 - 2013-11-01 20:06 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-10-31 16:59 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\ELAMBKUP
2013-10-27 17:08 - 2013-10-27 17:08 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\libimobiledevice
2013-10-27 16:46 - 2013-10-27 16:46 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-27 16:46 - 2013-10-27 16:46 - 00000000 ____D C:\Program Files\iTunes
2013-10-27 16:46 - 2013-10-27 16:46 - 00000000 ____D C:\Program Files\iPod
2013-10-27 16:18 - 2013-10-27 16:18 - 00000000 ____D C:\Program Files (x86)\ASUS
2013-10-27 13:18 - 2013-08-23 23:30 - 00000000 ____D C:\Program Files (x86)\Razer
2013-10-27 13:13 - 2013-10-18 23:57 - 00000680 __RSH C:\Users\Siteshoot\ntuser.pol
2013-10-27 12:11 - 2013-10-26 15:22 - 00000000 __RDO C:\Users\Siteshoot\SkyDrive.old
2013-10-27 11:00 - 2011-10-13 07:06 - 00000000 ____D C:\ProgramData\CyberLink
2013-10-27 10:55 - 2013-10-27 10:55 - 00000000 ____D C:\WINDOWS\PCHEALTH
2013-10-27 10:55 - 2013-05-05 02:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-10-27 10:54 - 2013-10-27 10:54 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-10-27 10:54 - 2013-10-27 10:54 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-10-27 10:49 - 2013-10-27 10:49 - 00004973 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-27 10:35 - 2013-10-27 05:12 - 00003032 _____ C:\WINDOWS\System32\Tasks\MSIAfterburner
2013-10-27 10:35 - 2013-10-26 23:47 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2013-10-27 10:33 - 2013-03-13 14:16 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-27 10:33 - 2013-03-13 14:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-27 10:28 - 2013-10-27 10:28 - 00001160 _____ C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Badoo Desktop.lnk
2013-10-27 10:28 - 2013-10-27 10:28 - 00000000 ____D C:\ProgramData\Badoo
2013-10-27 05:06 - 2013-07-19 21:25 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-27 05:06 - 2013-07-18 07:47 - 00000000 ____D C:\ProgramData\Skype
2013-10-27 05:01 - 2013-10-20 09:27 - 00000022 _____ C:\WINDOWS\GPU-Z.INI
2013-10-27 04:47 - 2013-10-27 04:47 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Sniper Elite Nazi Zombie Army
2013-10-27 04:10 - 2013-10-27 03:58 - 00310984 _____ C:\WINDOWS\system32\Drivers\atksgt.sys
2013-10-27 04:10 - 2013-10-27 03:58 - 00042696 _____ C:\WINDOWS\system32\Drivers\lirsgt.sys
2013-10-27 01:05 - 2013-10-27 00:54 - 00000000 ____D C:\Users\Siteshoot\Heaven
2013-10-27 01:02 - 2013-10-27 00:53 - 01065984 _____ C:\Users\Siteshoot\AppData\Local\file__0.localstorage
2013-10-27 00:17 - 2013-10-27 00:17 - 00076384 _____ (hxxp://libusb-win32.sourceforge.net) C:\WINDOWS\system32\libusb0.dll
2013-10-27 00:17 - 2013-10-27 00:17 - 00052832 _____ (hxxp://libusb-win32.sourceforge.net) C:\WINDOWS\system32\Drivers\libusb0.sys
2013-10-27 00:17 - 2013-10-18 23:57 - 00000600 __RSH C:\ProgramData\ntuser.pol
2013-10-26 23:47 - 2013-10-26 21:32 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2013-10-26 23:42 - 2013-03-02 14:16 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\NVIDIA
2013-10-26 22:50 - 2013-10-26 22:50 - 00000000 ____D C:\Intel
2013-10-26 22:50 - 2011-10-13 07:02 - 00000000 ____D C:\Program Files (x86)\Intel
2013-10-26 20:08 - 2013-04-20 22:37 - 00000000 ____D C:\Users\Siteshoot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2013-10-26 16:01 - 2013-10-26 16:01 - 00002389 _____ C:\Users\Siteshoot\Documents\Firefox-Wiederherstellungs-Schlüssel.html
2013-10-26 15:54 - 2013-04-23 20:35 - 00000000 ____D C:\Program Files\CCleaner
2013-10-26 15:36 - 2013-08-10 02:52 - 00000000 ____D C:\Users\Administrator\AppData\Local\Packages
2013-10-26 15:35 - 2013-10-26 15:35 - 00001448 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-26 15:35 - 2013-10-26 15:35 - 00000680 __RSH C:\Users\Administrator\ntuser.pol
2013-10-26 15:35 - 2013-10-26 15:35 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2013-10-26 15:35 - 2013-10-18 23:41 - 00000000 ____D C:\Users\Administrator
2013-10-26 15:35 - 2013-08-10 02:53 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-26 15:35 - 2013-08-10 02:53 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-26 15:30 - 2013-10-26 15:30 - 00000000 ____D C:\Users\Siteshoot\Documents\god.{ED7BA470-8E54-465E-825C-99712043E01C}
2013-10-26 15:20 - 2013-03-25 23:35 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\Downloaded Installations
2013-10-26 15:03 - 2013-10-26 15:03 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-10-26 14:53 - 2013-10-12 06:24 - 00000000 ____D C:\Users\Siteshoot\AppData\Local\AVG SafeGuard toolbar
2013-10-26 14:52 - 2013-10-26 14:52 - 00000000 ____D C:\ProgramData\Advanced
Files to move or delete:
====================
C:\ProgramData\cis4FC7.exe
Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Siteshoot\AppData\Local\Temp\ose00001.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2013-11-17 00:56] - [2013-10-22 08:55] - 2328872 ____A (Microsoft Corporation) 63DC38C3E4564B2405D562855643ABA2
C:\Windows\SysWOW64\explorer.exe
[2013-11-17 00:56] - [2013-10-22 07:03] - 2065448 ____A (Microsoft Corporation) 1A0BC9598E4A58FC84570FFF5A108E58
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll
[2013-11-17 00:56] - [2013-10-22 03:38] - 1362944 ____A (Microsoft Corporation) C72456BFFE941714CF05B0AA0BEE5B45
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-21 04:17
==================== End Of Log ============================ --- --- ---
--- --- --- |