Malware - Logfileauswertung - Rechner stürzt ab oder friert ein Hallo zusammen,
habe auf meinem Rechner Windows 8.1 installiert. Es kommt zeitweise dazu das der Rechner einfriert oder abstürzt. Habe hier diverse Logfiles erstellt und bitte um Hilfe bei der Auswertung. Vielen Dank im voraus.
Logfile OTL: Code:
OTL logfile created on: 14.05.2015 20:53:05 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kay\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17801)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
5,96 Gb Total Physical Memory | 3,09 Gb Available Physical Memory | 51,90% Memory free
14,94 Gb Paging File | 11,62 Gb Available in Paging File | 77,78% Paging File free
Paging file location(s): c:\pagefile.sys 9198 9198 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918,27 Gb Total Space | 751,24 Gb Free Space | 81,81% Space Free | Partition Type: NTFS
Drive D: | 10,98 Gb Total Space | 1,29 Gb Free Space | 11,74% Space Free | Partition Type: NTFS
Computer Name: KSIN | User Name: Kay | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2015.05.13 03:53:28 | 001,894,064 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
PRC - [2015.05.08 21:47:35 | 000,376,944 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2015.05.08 00:03:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Kay\Downloads\otl.exe
PRC - [2015.04.24 07:19:02 | 004,481,824 | ---- | M] (FlashPeak Inc.) -- C:\Program Files (x86)\SlimBrowser\sbframe.exe
PRC - [2015.04.24 07:19:02 | 000,999,200 | ---- | M] (FlashPeak Inc.) -- C:\Program Files (x86)\SlimBrowser\SBRender.exe
PRC - [2015.04.20 18:33:52 | 003,391,712 | ---- | M] (Mister Group) -- C:\Program Files (x86)\System Explorer\SystemExplorer.exe
PRC - [2015.04.17 10:01:26 | 000,888,440 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\launcher.exe
PRC - [2015.04.15 13:21:40 | 003,438,032 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
PRC - [2015.04.15 13:17:20 | 003,745,232 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgui.exe
PRC - [2015.04.15 13:16:38 | 001,517,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
PRC - [2015.04.15 13:10:56 | 000,311,792 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
PRC - [2015.04.14 09:36:30 | 001,080,120 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2015.04.14 09:36:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2015.04.14 09:36:20 | 006,212,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2015.03.10 19:58:49 | 000,620,056 | ---- | M] () -- C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
PRC - [2015.03.08 16:30:28 | 001,740,776 | ---- | M] (Evaer Technology) -- C:\Program Files (x86)\Evaer\videochannel.exe
PRC - [2014.11.26 14:44:54 | 000,153,384 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe
PRC - [2014.11.26 14:42:12 | 001,167,656 | ---- | M] (Sophos Limited) -- C:\Program Files (x86)\Sophos\Sophos Virus Removal Tool\SVRTgui.exe
PRC - [2014.07.14 19:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014.07.14 19:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
========== Modules (No Company Name) ==========
MOD - [2015.05.13 03:53:28 | 016,867,504 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll
MOD - [2015.03.02 13:00:23 | 001,718,808 | ---- | M] () -- C:\Program Files (x86)\AVG Web TuneUp\TBAPI.dll
MOD - [2012.05.17 06:26:32 | 000,088,496 | ---- | M] () -- C:\Program Files (x86)\SlimBrowser\easyhook32.dll
========== Services (SafeList) ==========
SRV:64bit: - [2015.05.06 19:44:49 | 001,429,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:64bit: - [2015.03.10 22:28:53 | 000,229,888 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2015.02.21 01:49:18 | 000,780,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2014.11.21 10:17:35 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014.11.21 06:05:46 | 000,154,112 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2014.11.21 06:05:36 | 001,668,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:64bit: - [2014.11.21 06:04:47 | 000,562,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2014.11.21 06:04:42 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2014.11.21 06:04:41 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2014.11.21 06:04:35 | 000,374,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2014.11.21 06:04:34 | 000,550,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2014.11.21 06:04:31 | 000,166,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2014.11.21 06:04:20 | 003,460,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2014.11.21 06:04:17 | 001,639,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2014.11.21 06:04:17 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2014.11.21 06:04:16 | 000,041,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2014.11.21 06:04:14 | 000,260,608 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2014.11.21 06:04:14 | 000,131,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2014.11.21 06:04:12 | 000,521,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2014.11.21 06:04:08 | 000,407,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2014.11.21 06:04:08 | 000,270,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2014.11.21 06:04:07 | 000,262,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2014.11.21 06:04:07 | 000,206,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2014.11.21 06:04:02 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2014.11.21 06:04:01 | 000,294,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2014.11.21 06:04:01 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2014.11.21 06:04:01 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2014.11.21 06:03:56 | 001,348,096 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2014.11.21 06:03:50 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2014.11.21 06:03:50 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2014.11.21 06:03:50 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2014.11.21 06:03:50 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2014.11.21 06:03:50 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2014.11.21 06:03:50 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2014.11.21 06:03:50 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2014.11.21 06:03:34 | 000,838,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2014.11.21 06:03:34 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2014.11.21 06:03:30 | 002,987,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2014.11.21 06:03:29 | 000,324,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
SRV:64bit: - [2014.11.21 04:12:40 | 000,244,736 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2014.07.02 10:08:33 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2015.05.13 03:53:28 | 000,268,464 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015.05.08 21:47:48 | 000,148,080 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015.04.15 13:21:40 | 003,438,032 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2015.04.15 13:16:38 | 001,517,480 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2015\avgfws.exe -- (avgfws)
SRV - [2015.04.15 13:10:56 | 000,311,792 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe -- (avgwd)
SRV - [2015.04.14 09:36:30 | 001,080,120 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2015.04.14 09:36:28 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2015.04.01 18:48:32 | 005,540,424 | ---- | M] (COMODO) [Auto | Running] -- C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe -- (CmdAgent)
SRV - [2015.04.01 18:44:06 | 002,265,816 | ---- | M] (COMODO) [On_Demand | Stopped] -- C:\Programme\COMODO\COMODO Internet Security\cmdvirth.exe -- (cmdvirth)
SRV - [2015.03.28 12:58:42 | 000,089,840 | ---- | M] (Hewlett-Packard Company) [Disabled | Stopped] -- C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
SRV - [2015.03.26 08:41:16 | 002,306,248 | ---- | M] (Comodo) [Disabled | Stopped] -- C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe -- (ChromodoUpdater)
SRV - [2015.03.10 22:21:35 | 000,475,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2015.03.10 22:21:33 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2015.03.10 19:58:49 | 000,620,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe -- (WtuSystemSupport)
SRV - [2015.02.25 10:24:58 | 002,604,856 | ---- | M] (AVG Technologies) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc)
SRV - [2015.02.18 19:11:32 | 000,315,488 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014.12.20 12:00:00 | 000,820,960 | ---- | M] (Mister Group) [On_Demand | Running] -- C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe -- (SystemExplorerHelpService)
SRV - [2014.12.03 08:31:16 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014.11.26 14:44:54 | 000,153,384 | ---- | M] (Sophos Limited) [On_Demand | Running] -- C:\Program Files (x86)\Sophos\Sophos Virus Removal Tool\SVRTservice.exe -- (SophosVirusRemovalTool)
SRV - [2014.11.21 06:05:11 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2014.11.21 06:03:35 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2014.11.21 06:03:35 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2014.11.21 06:03:30 | 002,987,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014.10.10 10:37:18 | 000,409,376 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2014.10.10 10:37:16 | 000,158,496 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2014.08.21 21:42:40 | 000,093,184 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe -- (HP Support Assistant Service)
SRV - [2014.07.14 19:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014.07.14 19:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014.07.02 10:10:55 | 000,066,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\w3logsvc.dll -- (w3logsvc)
SRV - [2013.12.19 10:07:52 | 001,821,384 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Comodo\IceDragon\icedragon_updater.exe -- (IceDragonUpdater)
SRV - [2013.11.20 11:43:20 | 000,339,456 | ---- | M] (IDT, Inc.) [Disabled | Stopped] -- C:\Programme\IDT\WDM\stacsv64.exe -- (STacSV)
SRV - [2013.08.27 15:32:30 | 000,828,376 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Programme\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV - [2013.08.27 15:32:14 | 000,747,520 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Programme\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2015.05.14 20:39:16 | 000,136,408 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2015.04.15 13:06:02 | 000,256,992 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2015.04.14 09:38:00 | 000,064,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2015.04.14 09:37:46 | 000,107,736 | ---- | M] (Malwarebytes Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV:64bit: - [2015.04.14 09:37:42 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2015.04.09 14:11:14 | 000,284,128 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2015.04.07 12:39:26 | 000,293,856 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgwfpa.sys -- (Avgwfpa)
DRV:64bit: - [2015.04.03 09:34:12 | 000,137,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2015.04.01 18:50:10 | 000,020,696 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd)
DRV:64bit: - [2015.03.27 08:40:48 | 000,021,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\avgboota.sys -- (Avgboota)
DRV:64bit: - [2015.03.21 18:30:05 | 000,016,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SWDUMon.sys -- (SWDUMon)
DRV:64bit: - [2015.03.20 12:20:42 | 000,067,040 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)
DRV:64bit: - [2015.03.20 12:18:18 | 000,040,928 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2015.03.20 04:31:18 | 000,131,384 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ctxusbm.sys -- (ctxusbm)
DRV:64bit: - [2015.03.20 03:56:10 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2015.03.17 19:26:06 | 000,467,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2015.03.14 10:06:49 | 000,157,944 | ---- | M] (Ray Hinchliffe) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SIVX64.sys -- (SIVDriver)
DRV:64bit: - [2015.03.13 06:03:31 | 000,239,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2015.03.11 12:16:06 | 000,162,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2015.03.11 12:13:36 | 000,344,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2015.03.11 12:13:28 | 000,213,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2015.03.10 22:27:12 | 000,264,000 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2015.03.10 22:27:12 | 000,114,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2015.03.10 22:27:12 | 000,044,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2015.03.09 04:02:51 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2015.03.04 12:25:11 | 000,377,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2015.01.06 18:03:02 | 000,413,960 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tixhci.sys -- (tixhci)
DRV:64bit: - [2014.12.29 22:38:17 | 000,034,512 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\debutfilterx64.sys -- (debutfilter)
DRV:64bit: - [2014.12.04 21:44:34 | 000,033,520 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Smb_driver_Intel.sys -- (SmbDrvI)
DRV:64bit: - [2014.11.21 06:06:04 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:64bit: - [2014.11.21 06:05:51 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2014.11.21 06:05:47 | 000,054,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2014.11.21 06:04:34 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2014.11.21 06:04:31 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2014.11.21 06:04:30 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2014.11.21 06:04:28 | 000,921,920 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2014.11.21 06:04:12 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2014.11.21 06:03:31 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2014.11.21 06:03:29 | 000,415,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2014.11.21 06:03:29 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2014.11.21 06:03:29 | 000,069,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2014.11.21 06:03:28 | 000,324,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2014.11.21 06:03:28 | 000,189,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2014.11.21 05:42:09 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2014.11.21 05:41:53 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2014.11.21 05:41:52 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2014.11.21 05:41:51 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2014.11.21 05:41:51 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2014.11.21 05:13:11 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2014.11.21 04:40:00 | 018,959,360 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2014.11.21 04:08:54 | 000,589,312 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2014.11.19 11:29:16 | 000,876,760 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2014.11.10 20:06:59 | 000,136,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2014.11.04 21:33:40 | 000,058,176 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2014.10.17 06:56:23 | 000,039,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2014.10.17 05:35:04 | 000,086,336 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2014.10.10 10:37:16 | 000,129,312 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
DRV:64bit: - [2014.03.11 16:20:04 | 000,222,720 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdWB6.sys -- (AtiHDAudioService)
DRV:64bit: - [2014.01.13 23:50:42 | 000,023,608 | ---- | M] (Christian Gulden) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pimou.sys -- (pimou)
DRV:64bit: - [2013.12.18 12:34:38 | 000,888,536 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2013.11.21 09:31:28 | 000,632,168 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2013.11.20 11:43:22 | 000,551,936 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2013.08.22 15:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013.08.22 15:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013.08.22 14:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013.08.22 14:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013.08.22 14:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013.08.22 14:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013.08.22 14:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013.08.22 14:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013.08.22 14:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013.08.22 14:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013.08.22 14:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013.08.22 14:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013.08.22 14:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013.08.22 14:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013.08.22 14:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013.08.22 14:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013.08.22 14:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013.08.22 14:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013.08.22 14:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013.08.22 14:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013.08.22 14:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013.08.22 14:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013.08.22 14:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013.08.22 14:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013.08.22 14:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013.08.22 14:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013.08.22 14:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013.08.22 13:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013.08.22 13:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013.08.22 13:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013.08.22 13:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013.08.22 13:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013.08.22 13:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013.08.22 13:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013.08.22 13:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013.08.22 13:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013.08.22 13:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013.08.22 13:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013.08.22 13:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013.08.22 13:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013.08.22 13:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013.08.22 13:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013.08.22 10:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013.08.13 01:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013.08.10 02:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013.07.30 20:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013.07.25 21:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013.07.18 15:00:04 | 000,083,224 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:64bit: - [2012.09.23 01:17:24 | 000,021,160 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdkmafd.sys -- (amdkmafd)
DRV:64bit: - [2012.05.17 12:57:06 | 000,026,136 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ICCWDT.sys -- (ICCWDT)
DRV:64bit: - [2009.06.18 13:54:10 | 000,006,144 | ---- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\6044.tmp -- (MEMSWEEP2)
DRV - [2015.03.12 05:30:10 | 000,021,712 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\DrvAgent64.SYS -- (DrvAgent64)
DRV - [2015.01.13 12:26:10 | 000,014,112 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = hxxp://www.google.com/search?q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{BA667243-1B10-47C5-AD89-F7D3CE8B219D}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = hxxp://www.google.com/search?q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{BA667243-1B10-47C5-AD89-F7D3CE8B219D}: "URL" = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
IE - HKLM\..\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}: "URL" = https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\..\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}: "URL" = https://www.google.com/search?trackid=sp-006&q={searchTerms}
IE - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.countryCode: "DE"
FF - prefs.js..browser.search.defaultengine: "Google (avast)"
FF - prefs.js..browser.search.defaultthis.engineName: "Google (avast)"
FF - prefs.js..browser.search.defaulturl: "https://www.google.com/search/?trackid=sp-006"
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..browser.search.order.1: "Google (avast)"
FF - prefs.js..browser.search.region: "DE"
FF - prefs.js..browser.search.searchengine.desc: "this is my first firefox searchEngine"
FF - prefs.js..browser.search.searchengine.ptid: "cvs"
FF - prefs.js..browser.search.searchengine.uid: "WDCXWD10EZEX-60ZF5A0_WD-WCC1S098102481024"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "yahoo.de"
FF - prefs.js..extensions.enabledAddons: support%40free-hideip.com:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:38.0
FF - prefs.js..keyword.URL: "https://www.google.com/search/?trackid=sp-006"
FF - prefs.js..network.proxy.gopher: ""
FF - prefs.js..network.proxy.gopher_port: 0
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.45.2: C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2: C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1218158.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Citrix.com/npican: C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.45.2: C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2: C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\hp.com/HPDetect: C:\Users\Kay\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll (HP)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 38.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2015.04.15 22:49:55 | 000,000,000 | ---D | M]
[2014.12.10 20:47:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kay\AppData\Roaming\mozilla\Extensions
[2015.04.13 21:55:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kay\AppData\Roaming\mozilla\Firefox\Profiles\732yhgy9.default-1418351222236\extensions
[2015.04.13 21:55:30 | 000,004,548 | ---- | M] () (No name found) -- C:\Users\Kay\AppData\Roaming\mozilla\firefox\profiles\732yhgy9.default-1418351222236\extensions\support@free-hideip.com.xpi
[2015.03.22 23:16:12 | 000,002,428 | ---- | M] () -- C:\Users\Kay\AppData\Roaming\mozilla\firefox\profiles\732yhgy9.default-1418351222236\searchplugins\google-avast.xml
[2015.03.02 22:44:30 | 000,000,663 | ---- | M] () -- C:\Users\Kay\AppData\Roaming\mozilla\firefox\profiles\732yhgy9.default-1418351222236\searchplugins\google-images.xml
[2015.03.02 22:44:30 | 000,002,307 | ---- | M] () -- C:\Users\Kay\AppData\Roaming\mozilla\firefox\profiles\732yhgy9.default-1418351222236\searchplugins\google-maps.xml
[2015.03.10 20:02:14 | 000,008,039 | ---- | M] () -- C:\Users\Kay\AppData\Roaming\mozilla\firefox\profiles\732yhgy9.default-1418351222236\searchplugins\Google.xml
[2015.05.13 03:54:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2015.05.13 03:54:52 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik\2.2015.506.11355_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.2_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
CHR - Extension: No name found = C:\Users\Kay\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
O1 HOSTS File: ([2013.08.22 15:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.8.0_45\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre1.8.0_45\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Programme\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2015\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup File not found
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [SystemExplorerAutoStart] C:\Program Files (x86)\System Explorer\SystemExplorer.exe (Mister Group)
O4 - HKU\S-1-5-21-4150589384-1404209100-33404022-1001..\Run: [avichannel] C:\Program Files (x86)\Evaer\videochannel.exe (Evaer Technology)
O4 - HKU\S-1-5-21-4150589384-1404209100-33404022-1001..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKLM..\RunOnce\Setup: [Registering MS MPEG4 ActiveX filter...] C:\Windows\SysWOW64\MPG4ds32.ax (Microcrap Corporation)
O4 - Startup: C:\Users\Kay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2015.03.12 20:49:04 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-4150589384-1404209100-33404022-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BCF39CDF-2E39-4AE3-8CD8-AB6F3A508737}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\ica - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27:64bit: - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27:64bit: - HKLM IFEO\adobe air application installer.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27:64bit: - HKLM IFEO\chromodo.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27:64bit: - HKLM IFEO\icedragon.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27:64bit: - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27:64bit: - HKLM IFEO\wordview.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27 - HKLM IFEO\AcroRd32.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27 - HKLM IFEO\adobe air application installer.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27 - HKLM IFEO\chromodo.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27 - HKLM IFEO\icedragon.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27 - HKLM IFEO\uninstall.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O27 - HKLM IFEO\wordview.exe: Debugger - C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe (AVG Technologies)
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (sdnclean64.exe)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015.05.14 20:39:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2015.05.14 20:36:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
[2015.05.14 20:21:10 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Software
[2015.05.14 20:10:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group
[2015.05.14 20:10:07 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2015.05.13 03:24:32 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2015.05.13 03:24:32 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2015.05.13 03:19:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2015.05.13 03:18:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2015.05.13 03:18:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2015.05.12 20:33:57 | 001,441,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\lsasrv.dll
[2015.05.12 20:33:57 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\certcli.dll
[2015.05.12 20:33:57 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\certcli.dll
[2015.05.12 20:33:56 | 001,996,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DWrite.dll
[2015.05.12 20:33:56 | 000,410,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\services.exe
[2015.05.12 20:33:53 | 006,025,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015.05.12 20:33:52 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2015.05.12 20:33:52 | 000,664,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2015.05.12 20:33:52 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2015.05.12 20:33:51 | 002,125,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2015.05.12 20:33:51 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2015.05.12 20:33:51 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2015.05.12 20:33:51 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2015.05.12 20:33:51 | 000,720,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2015.05.12 20:33:51 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2015.05.12 20:33:51 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2015.05.12 20:33:51 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2015.05.12 20:33:51 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2015.05.12 20:33:51 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2015.05.12 20:33:51 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2015.05.12 20:33:51 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2015.05.12 20:33:51 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2015.05.12 20:33:51 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2015.05.12 20:33:51 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2015.05.08 01:45:12 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\Comodo
[2015.05.08 01:44:40 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc71.dll
[2015.05.07 23:45:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysWow64\Adobe
[2015.05.07 23:35:48 | 000,027,400 | ---- | C] (COMODO CA Limited) -- C:\WINDOWS\SysNative\certsentry.dll
[2015.05.07 23:35:48 | 000,024,328 | ---- | C] (COMODO CA Limited) -- C:\WINDOWS\SysWow64\certsentry.dll
[2015.05.07 23:35:48 | 000,024,296 | ---- | C] (COMODO CA Limited) -- C:\WINDOWS\SysNative\certsentry.exe
[2015.05.07 23:35:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Comodo
[2015.05.07 23:09:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2015.05.07 23:07:23 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\TrojanHunter
[2015.05.07 22:52:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
[2015.05.07 22:52:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TrojanHunter 5.6
[2015.05.07 22:52:18 | 000,000,000 | ---D | C] -- C:\ProgramData\TrojanHunter
[2015.05.07 22:36:52 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\AVG2015
[2015.05.07 22:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2015.05.07 22:35:43 | 000,000,000 | -H-D | C] -- C:\$AVG
[2015.05.07 22:35:43 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2015
[2015.05.07 22:30:21 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Local\Avg2015
[2015.05.07 21:25:35 | 000,000,000 | -H-D | C] -- C:\VTRoot
[2015.05.07 21:23:36 | 000,023,608 | ---- | C] (Christian Gulden) -- C:\WINDOWS\SysNative\drivers\pimou.sys
[2015.05.07 21:21:56 | 000,413,960 | ---- | C] (Texas Instruments Incorporated) -- C:\WINDOWS\SysNative\drivers\tixhci.sys
[2015.05.07 21:04:36 | 002,378,448 | ---- | C] (COMODO Security Solutions) -- C:\bsm_chrome.exe
[2015.05.07 21:04:36 | 001,238,744 | ---- | C] (COMODO) -- C:\cmdstat.dll
[2015.05.07 21:04:36 | 000,281,816 | ---- | C] (Igor Pavlov) -- C:\7za.dll
[2015.05.07 21:04:36 | 000,000,000 | ---D | C] -- C:\translations
[2015.05.07 21:04:35 | 004,479,704 | ---- | C] (COMODO) -- C:\cmdinstall.exe
[2015.05.07 21:04:35 | 003,454,680 | ---- | C] (Terra Informatica Software, Inc.) -- C:\cmdhtml.dll
[2015.05.07 21:04:35 | 000,000,000 | ---D | C] -- C:\cis
[2015.05.07 21:02:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2015.05.07 20:47:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Shared Space
[2015.05.07 20:45:57 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2015.05.07 20:45:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2015.05.07 20:45:49 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Local\Comodo
[2015.05.07 20:36:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2015.05.06 23:35:55 | 000,000,000 | ---D | C] -- C:\Snort
[2015.05.06 22:53:42 | 000,000,000 | ---D | C] -- C:\Users\Kay\.zenmap
[2015.05.06 22:52:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nmap
[2015.05.06 22:37:12 | 000,000,000 | ---D | C] -- C:\ProgramData\SystemExplorer
[2015.05.06 22:37:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer
[2015.05.06 22:37:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\System Explorer
[2015.05.06 22:33:28 | 000,000,000 | ---D | C] -- C:\Users\Kay\Desktop\filme
[2015.05.06 22:32:26 | 000,285,208 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\SysNative\drivers\tmcomm.sys
[2015.05.06 22:18:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved
[2015.05.06 22:17:26 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\Raptr
[2015.05.06 21:40:22 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015.05.06 20:48:08 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\Nico Mak Computing
[2015.05.06 19:45:25 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UtcResources.dll
[2015.05.06 00:28:48 | 002,256,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2015.05.06 00:28:47 | 001,943,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2015.05.06 00:08:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2015.05.06 00:06:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
[2015.05.05 23:51:03 | 000,000,000 | ---D | C] -- C:\Users\Kay\Desktop\Neuer Ordner (3)
[2015.04.30 01:37:56 | 000,000,000 | ---D | C] -- C:\Users\Kay\Desktop\Neuer Ordner (2)
[2015.04.29 19:54:01 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sdbinst.exe
[2015.04.29 19:54:01 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\sdbinst.exe
[2015.04.29 19:54:00 | 004,417,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbgeng.dll
[2015.04.29 19:54:00 | 002,985,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbgeng.dll
[2015.04.29 19:54:00 | 001,491,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dbghelp.dll
[2015.04.29 19:54:00 | 001,207,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dbghelp.dll
[2015.04.29 19:54:00 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\ahcache.sys
[2015.04.28 04:39:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2015.04.28 03:17:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Shark007
[2015.04.28 03:16:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Advanced
[2015.04.28 02:42:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2015.04.23 23:06:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Hewlett-Packard
[2015.04.23 10:14:42 | 002,819,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SettingsHandlers.dll
[2015.04.23 10:14:42 | 000,467,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2015.04.23 10:14:42 | 000,172,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Input.Inking.dll
[2015.04.23 10:14:42 | 000,141,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Input.Inking.dll
[2015.04.23 10:14:42 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\bthhfenum.sys
[2015.04.23 10:14:12 | 002,162,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SRH.dll
[2015.04.23 10:14:12 | 001,812,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SRH.dll
[2015.04.23 10:14:11 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PhotoMetadataHandler.dll
[2015.04.23 10:14:11 | 000,364,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PhotoMetadataHandler.dll
[2015.04.23 10:14:11 | 000,239,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\sdbus.sys
[2015.04.23 10:14:11 | 000,154,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\dumpsd.sys
[2015.04.23 10:14:07 | 002,067,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wpdshext.dll
[2015.04.23 10:14:07 | 000,186,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dpapisrv.dll
[2015.04.23 10:14:06 | 001,429,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagtrack.dll
[2015.04.23 00:31:57 | 000,000,000 | ---D | C] -- C:\Program Files\UltraDefrag
[2015.04.19 15:00:14 | 000,089,600 | ---- | C] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\udefrag.exe
[2015.04.19 15:00:10 | 000,013,312 | ---- | C] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\hibernate4win.exe
[2015.04.19 15:00:08 | 000,012,288 | ---- | C] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\bootexctrl.exe
[2015.04.19 15:00:04 | 000,033,792 | ---- | C] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\wgx.dll
[2015.04.19 14:59:40 | 000,394,752 | ---- | C] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\defrag_native.exe
[2015.04.19 14:59:22 | 000,055,808 | ---- | C] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\udefrag.dll
[2015.04.19 14:59:14 | 000,337,920 | ---- | C] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\zenwinx.dll
[2015.04.15 22:49:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2015.04.15 22:17:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2015.04.15 22:17:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2015.04.15 22:17:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2015.04.15 22:07:37 | 000,000,000 | ---D | C] -- C:\ProgramData\AmUStor
[2015.04.15 22:07:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AmUStor
[2015.04.15 22:07:19 | 000,876,760 | ---- | C] (Realtek ) -- C:\WINDOWS\SysNative\drivers\Rt630x64.sys
[2015.04.15 22:07:19 | 000,073,800 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\SysNative\RtNicProp64.dll
[2015.04.15 21:52:43 | 000,000,000 | ---D | C] -- C:\Users\Kay\AppData\Roaming\Easeware
[2015.04.15 21:52:37 | 000,000,000 | ---D | C] -- C:\Program Files\Easeware
[2015.04.15 21:00:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Citrix
[2015.04.15 15:36:57 | 000,185,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rascfg.dll
[2015.04.15 15:36:57 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\rascfg.dll
[2015.04.15 13:06:02 | 000,256,992 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\SysNative\drivers\avgldx64.sys
[2015.04.15 12:52:59 | 007,476,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2015.04.15 12:52:58 | 001,733,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2015.04.15 12:52:57 | 000,950,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tdh.dll
[2015.04.15 12:52:57 | 000,749,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tdh.dll
[2015.04.15 12:52:56 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\tracerpt.exe
[2015.04.15 12:52:56 | 000,369,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\tracerpt.exe
[2015.04.15 12:52:56 | 000,360,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\sechost.dll
[2015.04.15 12:52:56 | 000,285,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wow64.dll
[2015.04.15 12:52:56 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\microsoft-windows-system-events.dll
[2015.04.15 12:52:55 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wow64cpu.dll
[2015.04.15 12:52:01 | 000,377,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\clfs.sys
[2015.04.15 12:52:01 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\clfsw32.dll
[2015.04.15 12:52:01 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\clfsw32.dll
[5 C:\WINDOWS\SysNative\*.tmp files -> C:\WINDOWS\SysNative\*.tmp -> ]
[1 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015.05.14 20:58:39 | 000,016,448 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\sfi.dat
[2015.05.14 20:40:56 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2015.05.14 20:39:16 | 000,136,408 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2015.05.14 20:39:01 | 000,000,334 | ---- | M] () -- C:\WINDOWS\tasks\HPCeeScheduleForKay.job
[2015.05.14 20:38:55 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015.05.14 20:38:04 | 000,146,484 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\fvstore.dat
[2015.05.14 20:36:00 | 000,002,775 | ---- | M] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2015.05.14 20:23:02 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2015.05.14 20:10:07 | 000,001,282 | ---- | M] () -- C:\Users\Kay\Desktop\Revo Uninstaller.lnk
[2015.05.14 19:58:11 | 000,001,045 | ---- | M] () -- C:\Users\Public\Desktop\Free Hide IP.lnk
[2015.05.13 17:17:50 | 000,010,330 | ---- | M] () -- C:\KSIN.rtf
[2015.05.13 03:54:59 | 000,001,161 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2015.05.13 03:46:58 | 000,355,136 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2015.05.13 00:31:33 | 303,890,083 | ---- | M] () -- C:\Users\Kay\Desktop\sugarbaby1.mp4
[2015.05.12 23:39:35 | 000,069,352 | ---- | M] () -- C:\Users\Kay\Desktop\sassdaa.jpg
[2015.05.12 23:37:37 | 000,020,533 | ---- | M] () -- C:\Users\Kay\Desktop\41Sev2a-k7L.jpg
[2015.05.12 23:00:33 | 000,261,803 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_7296.JPG
[2015.05.12 23:00:02 | 000,259,247 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_6077.JPG
[2015.05.12 22:59:50 | 000,945,439 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_0709.PNG
[2015.05.12 22:59:35 | 000,274,295 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_6076.JPG
[2015.05.12 22:59:30 | 000,055,248 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_6510.JPG
[2015.05.12 22:41:55 | 001,552,070 | ---- | M] () -- C:\Users\Kay\Desktop\Picture 5.jpg
[2015.05.12 22:20:44 | 002,047,393 | ---- | M] () -- C:\Users\Kay\Desktop\Picture 3.jpg
[2015.05.11 04:17:23 | 171,822,746 | ---- | M] () -- C:\Users\Kay\Desktop\black angel.mp4
[2015.05.11 02:36:08 | 924,734,625 | ---- | M] () -- C:\Users\Kay\Desktop\blond jennifer.mp4
[2015.05.11 02:11:24 | 000,008,349 | ---- | M] () -- C:\Users\Kay\Desktop\black_tribal_tattoo.jpg
[2015.05.09 11:09:00 | 000,000,892 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player PPAPI Notifier.job
[2015.05.09 04:00:35 | 291,529,144 | ---- | M] () -- C:\Users\Kay\Desktop\hothot hot.mp4
[2015.05.08 19:19:17 | 359,372,269 | ---- | M] () -- C:\Users\Kay\Desktop\sasha.mp4
[2015.05.08 04:45:03 | 000,027,400 | ---- | M] (COMODO CA Limited) -- C:\WINDOWS\SysNative\certsentry.dll
[2015.05.08 04:45:03 | 000,024,328 | ---- | M] (COMODO CA Limited) -- C:\WINDOWS\SysWow64\certsentry.dll
[2015.05.08 04:45:03 | 000,024,296 | ---- | M] (COMODO CA Limited) -- C:\WINDOWS\SysNative\certsentry.exe
[2015.05.08 02:48:00 | 000,027,260 | ---- | M] () -- C:\Users\Kay\Desktop\My Snapshot56.jpg
[2015.05.08 01:49:13 | 000,027,040 | ---- | M] () -- C:\Users\Kay\Desktop\My Snapshot57.jpg
[2015.05.08 01:44:57 | 000,001,152 | ---- | M] () -- C:\Users\Public\Desktop\Comodo IceDragon.lnk
[2015.05.08 01:44:40 | 001,060,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc71.dll
[2015.05.07 23:37:06 | 000,001,133 | ---- | M] () -- C:\Users\Kay\Desktop\Internet (Chromodo).lnk
[2015.05.07 22:52:21 | 000,059,392 | R--- | M] () -- C:\WINDOWS\SysWow64\streamhlp.dll
[2015.05.07 22:52:20 | 000,001,099 | ---- | M] () -- C:\Users\Kay\Desktop\TrojanHunter.lnk
[2015.05.07 22:36:09 | 000,000,999 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2015.lnk
[2015.05.07 22:34:57 | 000,000,034 | ---- | M] () -- C:\WINDOWS\AvastEmUpdate.ini
[2015.05.07 21:16:33 | 000,000,558 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2015.05.07 21:07:24 | 000,002,030 | ---- | M] () -- C:\Users\Kay\Desktop\Spotify.lnk
[2015.05.07 21:07:24 | 000,001,464 | ---- | M] () -- C:\Users\Kay\Desktop\PatchMyPC - Verknüpfung.lnk
[2015.05.07 21:04:36 | 000,001,512 | RHS- | M] () -- C:\WINDOWS\SysWow64\{1606DC18-9578-4cbd-8312-8E9868F06A1D}.conf
[2015.05.07 21:04:36 | 000,000,642 | ---- | M] () -- C:\WINDOWS\SysWow64\{7995330B-E01F-4645-B702-53481E7CB778}.cmdfile
[2015.05.07 20:49:26 | 001,103,942 | ---- | M] () -- C:\WINDOWS\SysNative\perfh007.dat
[2015.05.07 20:49:26 | 000,278,380 | ---- | M] () -- C:\WINDOWS\SysNative\perfc007.dat
[2015.05.07 20:18:19 | 000,557,183 | ---- | M] () -- C:\Users\Kay\Desktop\bookmarks-2015-05-07.json
[2015.05.07 04:11:11 | 206,929,475 | ---- | M] () -- C:\Users\Kay\Desktop\sweet alice.mp4
[2015.05.07 02:26:02 | 000,030,410 | ---- | M] () -- C:\Users\Kay\Desktop\My Snapshot35.jpg
[2015.05.07 02:21:32 | 000,032,978 | ---- | M] () -- C:\Users\Kay\Desktop\My Snapshot34.jpg
[2015.05.06 23:03:46 | 000,000,218 | ---- | M] () -- C:\Users\Kay\AppData\Local\recently-used.xbel
[2015.05.06 22:39:20 | 000,425,490 | ---- | M] () -- C:\Users\Kay\AppData\Local\census.cache
[2015.05.06 22:39:15 | 000,190,976 | ---- | M] () -- C:\Users\Kay\AppData\Local\ars.cache
[2015.05.06 22:37:11 | 000,001,100 | ---- | M] () -- C:\Users\Public\Desktop\System Explorer.lnk
[2015.05.06 22:37:04 | 000,000,010 | ---- | M] () -- C:\Users\Kay\AppData\Local\sponge.last.runtime.cache
[2015.05.06 22:32:21 | 000,000,036 | ---- | M] () -- C:\Users\Kay\AppData\Local\housecall.guid.cache
[2015.05.06 19:44:49 | 001,429,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\diagtrack.dll
[2015.05.06 02:05:01 | 000,074,610 | ---- | M] () -- C:\Users\Kay\Desktop\byIw2Ar.jpg
[2015.05.05 20:54:15 | 000,114,745 | ---- | M] () -- C:\Users\Kay\Desktop\35038511_1427436033.jpg
[2015.05.05 20:51:37 | 000,043,176 | ---- | M] () -- C:\Users\Kay\Desktop\12066647_3169260_1430851837.jpg
[2015.05.05 19:59:54 | 000,792,568 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2015.05.05 19:59:54 | 000,178,168 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2015.05.04 22:10:45 | 001,210,680 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_0553.JPG
[2015.05.04 22:09:30 | 001,397,548 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_0597.JPG
[2015.05.04 22:07:37 | 001,082,736 | ---- | M] () -- C:\Users\Kay\Desktop\IMG_0513.JPG
[2015.05.03 23:49:31 | 000,112,288 | ---- | M] () -- C:\Users\Kay\Desktop\1adscd.jpg
[2015.05.03 23:48:47 | 000,217,685 | ---- | M] () -- C:\Users\Kay\Desktop\1adsc.jpg
[2015.05.03 23:47:35 | 000,136,828 | ---- | M] () -- C:\Users\Kay\Desktop\1ads.jpg
[2015.05.03 23:46:48 | 000,237,906 | ---- | M] () -- C:\Users\Kay\Desktop\1ad.jpg
[2015.05.03 23:45:47 | 000,121,245 | ---- | M] () -- C:\Users\Kay\Desktop\1a.jpg
[2015.04.30 22:35:31 | 000,124,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2015.04.30 22:35:19 | 000,102,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2015.04.30 08:19:36 | 000,088,786 | ---- | M] () -- C:\Users\Kay\Desktop\20584_1400044763644037_8996562729210117065_n.jpg
[2015.04.30 08:19:26 | 000,052,902 | ---- | M] () -- C:\Users\Kay\Desktop\11133760_1433575380290975_4430675554431884670_n.jpg
[2015.04.30 08:19:19 | 000,043,247 | ---- | M] () -- C:\Users\Kay\Desktop\11204940_1435453956769784_298465847266038884_n.jpg
[2015.04.28 16:52:53 | 000,000,836 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015.04.28 04:40:35 | 000,012,889 | -H-- | M] () -- C:\WINDOWS\SysWow64\BTImages.dat
[2015.04.25 13:02:42 | 001,984,420 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2015.04.25 13:02:42 | 000,787,792 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2015.04.25 13:02:42 | 000,161,550 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2015.04.24 23:32:10 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\UtcResources.dll
[2015.04.22 20:03:27 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015.04.21 18:50:12 | 000,584,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2015.04.21 18:50:03 | 000,417,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\html.iec
[2015.04.21 18:37:16 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2015.04.21 18:35:30 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2015.04.21 18:31:56 | 006,025,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015.04.21 18:13:03 | 000,107,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inseng.dll
[2015.04.21 18:09:57 | 000,341,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\html.iec
[2015.04.21 18:08:20 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2015.04.21 18:07:19 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2015.04.21 18:05:26 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2015.04.21 17:58:36 | 000,664,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2015.04.21 17:51:05 | 000,000,959 | ---- | M] () -- C:\Users\Kay\Desktop\Evaer.lnk
[2015.04.21 17:49:46 | 000,720,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2015.04.21 17:49:17 | 000,801,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2015.04.21 17:46:50 | 002,125,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2015.04.21 17:38:39 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2015.04.21 17:37:13 | 000,128,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2015.04.21 17:25:45 | 002,052,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2015.04.21 17:03:34 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2015.04.21 16:56:39 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2015.04.21 01:56:49 | 000,000,889 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2015.04.19 15:00:14 | 000,089,600 | ---- | M] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\udefrag.exe
[2015.04.19 15:00:10 | 000,013,312 | ---- | M] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\hibernate4win.exe
[2015.04.19 15:00:08 | 000,012,288 | ---- | M] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\bootexctrl.exe
[2015.04.19 15:00:04 | 000,033,792 | ---- | M] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\wgx.dll
[2015.04.19 14:59:50 | 000,132,608 | ---- | M] () -- C:\WINDOWS\SysNative\lua5.1a.dll
[2015.04.19 14:59:40 | 000,394,752 | ---- | M] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\defrag_native.exe
[2015.04.19 14:59:22 | 000,055,808 | ---- | M] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\udefrag.dll
[2015.04.19 14:59:14 | 000,337,920 | ---- | M] (UltraDefrag Development Team) -- C:\WINDOWS\SysNative\zenwinx.dll
[2015.04.15 22:49:55 | 000,002,041 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2015.04.15 21:57:22 | 000,111,016 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysNative\WindowsAccessBridge-64.dll
[2015.04.15 21:41:05 | 000,136,408 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\422D0373.sys
[2015.04.15 13:06:02 | 000,256,992 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\SysNative\drivers\avgldx64.sys
[5 C:\WINDOWS\SysNative\*.tmp files -> C:\WINDOWS\SysNative\*.tmp -> ]
[1 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015.05.14 20:36:00 | 000,002,775 | ---- | C] () -- C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
[2015.05.14 20:10:07 | 000,001,282 | ---- | C] () -- C:\Users\Kay\Desktop\Revo Uninstaller.lnk
[2015.05.13 00:12:37 | 303,890,083 | ---- | C] () -- C:\Users\Kay\Desktop\sugarbaby1.mp4
[2015.05.12 23:39:35 | 000,069,352 | ---- | C] () -- C:\Users\Kay\Desktop\sassdaa.jpg
[2015.05.12 23:37:37 | 000,020,533 | ---- | C] () -- C:\Users\Kay\Desktop\41Sev2a-k7L.jpg
[2015.05.12 23:00:39 | 000,261,803 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_7296.JPG
[2015.05.12 23:00:10 | 000,259,247 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_6077.JPG
[2015.05.12 23:00:06 | 000,945,439 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_0709.PNG
[2015.05.12 23:00:01 | 000,055,248 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_6510.JPG
[2015.05.12 22:59:56 | 000,274,295 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_6076.JPG
[2015.05.12 22:42:14 | 001,552,070 | ---- | C] () -- C:\Users\Kay\Desktop\Picture 5.jpg
[2015.05.12 22:21:29 | 002,047,393 | ---- | C] () -- C:\Users\Kay\Desktop\Picture 3.jpg
[2015.05.11 04:06:41 | 171,822,746 | ---- | C] () -- C:\Users\Kay\Desktop\black angel.mp4
[2015.05.11 02:11:23 | 000,008,349 | ---- | C] () -- C:\Users\Kay\Desktop\black_tribal_tattoo.jpg
[2015.05.11 01:38:30 | 924,734,625 | ---- | C] () -- C:\Users\Kay\Desktop\blond jennifer.mp4
[2015.05.09 03:42:26 | 291,529,144 | ---- | C] () -- C:\Users\Kay\Desktop\hothot hot.mp4
[2015.05.08 18:56:54 | 359,372,269 | ---- | C] () -- C:\Users\Kay\Desktop\sasha.mp4
[2015.05.08 17:07:26 | 000,001,045 | ---- | C] () -- C:\Users\Public\Desktop\Free Hide IP.lnk
[2015.05.08 02:48:04 | 000,027,260 | ---- | C] () -- C:\Users\Kay\Desktop\My Snapshot56.jpg
[2015.05.08 01:49:21 | 000,027,040 | ---- | C] () -- C:\Users\Kay\Desktop\My Snapshot57.jpg
[2015.05.08 01:44:57 | 000,001,152 | ---- | C] () -- C:\Users\Public\Desktop\Comodo IceDragon.lnk
[2015.05.07 23:35:53 | 000,001,133 | ---- | C] () -- C:\Users\Kay\Desktop\Internet (Chromodo).lnk
[2015.05.07 23:09:53 | 000,001,161 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2015.05.07 23:09:52 | 000,001,173 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2015.05.07 22:52:20 | 000,001,099 | ---- | C] () -- C:\Users\Kay\Desktop\TrojanHunter.lnk
[2015.05.07 22:52:18 | 000,059,392 | R--- | C] () -- C:\WINDOWS\SysWow64\streamhlp.dll
[2015.05.07 22:36:09 | 000,000,999 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2015.lnk
[2015.05.07 22:33:41 | 000,000,034 | ---- | C] () -- C:\WINDOWS\AvastEmUpdate.ini
[2015.05.07 21:25:33 | 000,146,484 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\fvstore.dat
[2015.05.07 21:02:27 | 000,001,512 | RHS- | C] () -- C:\WINDOWS\SysWow64\{1606DC18-9578-4cbd-8312-8E9868F06A1D}.conf
[2015.05.07 21:02:27 | 000,000,642 | ---- | C] () -- C:\WINDOWS\SysWow64\{7995330B-E01F-4645-B702-53481E7CB778}.cmdfile
[2015.05.07 20:49:19 | 000,016,448 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\sfi.dat
[2015.05.07 20:18:19 | 000,557,183 | ---- | C] () -- C:\Users\Kay\Desktop\bookmarks-2015-05-07.json
[2015.05.07 03:58:17 | 206,929,475 | ---- | C] () -- C:\Users\Kay\Desktop\sweet alice.mp4
[2015.05.07 02:26:11 | 000,030,410 | ---- | C] () -- C:\Users\Kay\Desktop\My Snapshot35.jpg
[2015.05.07 02:21:47 | 000,032,978 | ---- | C] () -- C:\Users\Kay\Desktop\My Snapshot34.jpg
[2015.05.06 23:04:04 | 001,667,584 | ---- | C] () -- C:\Users\Kay\Desktop\ncat.exe
[2015.05.06 23:03:46 | 000,000,218 | ---- | C] () -- C:\Users\Kay\AppData\Local\recently-used.xbel
[2015.05.06 22:39:20 | 000,425,490 | ---- | C] () -- C:\Users\Kay\AppData\Local\census.cache
[2015.05.06 22:39:15 | 000,190,976 | ---- | C] () -- C:\Users\Kay\AppData\Local\ars.cache
[2015.05.06 22:37:11 | 000,001,100 | ---- | C] () -- C:\Users\Public\Desktop\System Explorer.lnk
[2015.05.06 22:37:04 | 000,000,010 | ---- | C] () -- C:\Users\Kay\AppData\Local\sponge.last.runtime.cache
[2015.05.06 22:32:21 | 000,000,036 | ---- | C] () -- C:\Users\Kay\AppData\Local\housecall.guid.cache
[2015.05.06 22:26:09 | 000,006,069 | ---- | C] () -- C:\Users\Kay\Desktop\cports_lng.ini
[2015.05.06 02:05:01 | 000,074,610 | ---- | C] () -- C:\Users\Kay\Desktop\byIw2Ar.jpg
[2015.05.05 20:54:15 | 000,114,745 | ---- | C] () -- C:\Users\Kay\Desktop\35038511_1427436033.jpg
[2015.05.05 20:51:37 | 000,043,176 | ---- | C] () -- C:\Users\Kay\Desktop\12066647_3169260_1430851837.jpg
[2015.05.04 22:10:49 | 001,210,680 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_0553.JPG
[2015.05.04 22:09:46 | 001,397,548 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_0597.JPG
[2015.05.04 22:09:15 | 001,082,736 | ---- | C] () -- C:\Users\Kay\Desktop\IMG_0513.JPG
[2015.05.03 23:49:31 | 000,112,288 | ---- | C] () -- C:\Users\Kay\Desktop\1adscd.jpg
[2015.05.03 23:48:47 | 000,217,685 | ---- | C] () -- C:\Users\Kay\Desktop\1adsc.jpg
[2015.05.03 23:47:34 | 000,136,828 | ---- | C] () -- C:\Users\Kay\Desktop\1ads.jpg
[2015.05.03 23:46:48 | 000,237,906 | ---- | C] () -- C:\Users\Kay\Desktop\1ad.jpg
[2015.05.03 23:45:46 | 000,121,245 | ---- | C] () -- C:\Users\Kay\Desktop\1a.jpg
[2015.04.30 08:19:36 | 000,088,786 | ---- | C] () -- C:\Users\Kay\Desktop\20584_1400044763644037_8996562729210117065_n.jpg
[2015.04.30 08:19:26 | 000,052,902 | ---- | C] () -- C:\Users\Kay\Desktop\11133760_1433575380290975_4430675554431884670_n.jpg
[2015.04.30 08:19:19 | 000,043,247 | ---- | C] () -- C:\Users\Kay\Desktop\11204940_1435453956769784_298465847266038884_n.jpg
[2015.04.29 19:53:59 | 000,410,017 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2015.04.28 04:40:18 | 000,002,729 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk
[2015.04.28 03:19:47 | 001,679,360 | ---- | C] () -- C:\WINDOWS\SysWow64\ac3filter.acm.new
[2015.04.23 00:56:07 | 000,000,892 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player PPAPI Notifier.job
[2015.04.23 00:31:58 | 000,000,874 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraDefrag.lnk
[2015.04.21 17:42:35 | 422,283,349 | ---- | C] () -- C:\Users\Kay\Desktop\1997.06.28 - HR 3 Clubnight Spezial - Hessentag Korbach - Talla 2XLC, Mark Spoon, Sven Vath & Ulli Brenner.mp3
[2015.04.21 00:02:28 | 504,369,062 | ---- | C] () -- C:\Users\Kay\Desktop\1998.06.28 - HR 3 Clubnight Spezial - DJ Dag & Non Eric @ Katharinenkirche.mp3
[2015.04.19 14:59:50 | 000,132,608 | ---- | C] () -- C:\WINDOWS\SysNative\lua5.1a.dll
[2015.04.15 22:49:55 | 000,002,457 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2015.04.15 22:49:55 | 000,002,041 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2015.04.15 22:21:57 | 000,001,464 | ---- | C] () -- C:\Users\Kay\Desktop\PatchMyPC - Verknüpfung.lnk
[2015.04.15 22:00:46 | 000,010,330 | ---- | C] () -- C:\KSIN.rtf
[2015.04.15 21:01:31 | 000,001,624 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix Receiver.lnk
[2015.04.15 12:52:37 | 000,016,303 | ---- | C] () -- C:\WINDOWS\SysWow64\ieuinit.inf
[2015.04.15 12:52:37 | 000,016,303 | ---- | C] () -- C:\WINDOWS\SysNative\ieuinit.inf
[2015.03.22 17:23:50 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015.03.21 17:20:46 | 000,000,558 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2015.03.11 23:16:53 | 000,007,639 | ---- | C] () -- C:\Users\Kay\AppData\Local\Resmon.ResmonCfg
[2015.03.10 22:35:59 | 002,008,552 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2015.03.10 22:32:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2015.03.02 22:17:07 | 000,338,432 | ---- | C] () -- C:\WINDOWS\SysWow64\sqlite36_engine.dll
[2014.12.18 01:50:47 | 000,012,889 | -H-- | C] () -- C:\WINDOWS\SysWow64\BTImages.dat
[2014.11.21 06:05:31 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2014.11.21 06:03:37 | 000,107,008 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2014.11.21 05:42:28 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014.11.21 04:25:30 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2014.11.20 22:35:00 | 000,038,912 | ---- | C] () -- C:\WINDOWS\SysWow64\kdbsdk32.dll
[2014.07.21 23:04:58 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2014.07.21 23:04:58 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2014.07.21 23:04:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2014.07.21 23:04:04 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2014.07.21 23:04:04 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013.08.22 17:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013.08.22 17:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013.08.22 16:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013.08.22 09:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013.08.22 01:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013.08.22 01:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
========== ZeroAccess Check ==========
[2015.03.10 23:19:04 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015.03.10 22:23:42 | 022,291,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015.03.10 22:23:42 | 019,731,824 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014.11.21 06:03:53 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014.11.21 06:05:05 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014.11.21 06:03:52 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 26 bytes -> C:\Users\Kay\Desktop\sassdaa.jpg:$CmdZnID
@Alternate Data Stream - 26 bytes -> C:\Users\Kay\Desktop\black_tribal_tattoo.jpg:$CmdZnID
< End of report >
|