AdwCleaner Logfile: Code:
# AdwCleaner v3.006 - Bericht erstellt am 03/10/2013 um 11:11:08
# Updated 01/10/2013 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Creasy - CREASY-PC
# Gestartet von : C:\Users\Creasy\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : BackupStack
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\Trymedia
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Plasmoo
Ordner Gelöscht : C:\Users\Creasy\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Creasy\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Creasy\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Creasy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Ordner Gelöscht : C:\Users\Creasy\AppData\Roaming\Mozilla\Firefox\Profiles\o7f062yg.default\Conduit
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Creasy\Desktop\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Creasy\AppData\Roaming\Mozilla\Firefox\Profiles\o7f062yg.default\searchplugins\Conduit.xml
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AlxTB2.ToolBarProxy
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AlxTB2.ToolBarProxy.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C953EC4-8CFA-44FB-B32E-1249E5505091}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{0C58B7D1-D415-492B-A149-E976156BD3B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7C3B01BC-53A5-48A0-A43B-0C67731134B9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0ABE0FED-50E7-4E42-A125-57C0A11DBCDE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1A1BBE49-C6F1-40EA-9D2F-262F0AF6DDE3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2022154E-7E3E-4809-871E-1B45A6FC7058}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{292ECB89-350E-45D2-816F-52C15305B144}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{36CC2180-B6BF-4951-9578-6B0C40044AAA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{44A36944-22C6-4A08-BC7C-161F3E540DBF}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6247DD2C-8CF9-4041-A235-93691D71B8B4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{835BED79-DF7E-4096-B355-ED43FA2EA87B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8E863BD6-50DE-47D0-A6F1-3C1F6DB72451}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9DD36F1E-5111-41C5-ADED-A2A11A2FF3E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A2FB8217-E320-434E-BA79-513E357AD54F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A9CEBBF4-9129-479A-9231-E833ED3D3A8F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AFD4D1F9-167C-4884-95AE-B5A9797B0D16}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B3EAD50C-ECB0-459A-9EDA-F505AB99675B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C47788B1-9604-4D7A-A684-F4D450F2D7D2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{CA3B41D0-D4C1-4808-B248-75DA27238828}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D4A2FF6C-087F-4D40-8DFE-92AAD484BFB8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D88B9D5C-A9CF-4C69-906D-1CCA5D85A2EF}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F83AF01C-AA2F-469F-8BE7-D178FB15FD07}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16686
-\\ Mozilla Firefox v
[ Datei : C:\Users\Creasy\AppData\Roaming\Mozilla\Firefox\Profiles\o7f062yg.default\prefs.js ]
Zeile gelöscht : user_pref("CT2613550.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gelöscht : user_pref("CT2613550.CTID", "ct2613550");
Zeile gelöscht : user_pref("CT2613550.CurrentServerDate", "6-3-2011");
Zeile gelöscht : user_pref("CT2613550.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2613550.DownloadReferralCookieData", "");
Zeile gelöscht : user_pref("CT2613550.EMailNotifierPollDate", "Sun Mar 06 2011 21:23:07 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602533", "Sun Mar 06 2011 21:23:07 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602539", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602545", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602551", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602557", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602563", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602569", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602575", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602581", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602587", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602593", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602599", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602605", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602611", "Sun Mar 06 2011 21:23:09 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602617", "Sun Mar 06 2011 21:23:09 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602623", "Sun Mar 06 2011 21:23:09 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate129254982599602629", "Sun Mar 06 2011 21:23:09 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.FeedTTL129254982599602545", 5);
Zeile gelöscht : user_pref("CT2613550.FeedTTL129254982599602551", 5);
Zeile gelöscht : user_pref("CT2613550.FeedTTL129254982599602575", 2);
Zeile gelöscht : user_pref("CT2613550.FeedTTL129254982599602605", 5);
Zeile gelöscht : user_pref("CT2613550.FeedTTL129254982599602617", 30);
Zeile gelöscht : user_pref("CT2613550.FirstServerDate", "6-3-2011");
Zeile gelöscht : user_pref("CT2613550.FirstTime", true);
Zeile gelöscht : user_pref("CT2613550.FirstTimeFF3", true);
Zeile gelöscht : user_pref("CT2613550.FirstTimeSettingsDone", true);
Zeile gelöscht : user_pref("CT2613550.FixPageNotFoundErrors", true);
Zeile gelöscht : user_pref("CT2613550.GroupingServerCheckInterval", 1440);
Zeile gelöscht : user_pref("CT2613550.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gelöscht : user_pref("CT2613550.Initialize", true);
Zeile gelöscht : user_pref("CT2613550.InitializeCommonPrefs", true);
Zeile gelöscht : user_pref("CT2613550.InstallationAndCookieDataSentCount", 3);
Zeile gelöscht : user_pref("CT2613550.InstallationType", "UnknownIntegration");
Zeile gelöscht : user_pref("CT2613550.InstalledDate", "Sun Mar 06 2011 21:23:07 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.IsGrouping", false);
Zeile gelöscht : user_pref("CT2613550.IsMulticommunity", false);
Zeile gelöscht : user_pref("CT2613550.IsOpenThankYouPage", false);
Zeile gelöscht : user_pref("CT2613550.IsOpenUninstallPage", false);
Zeile gelöscht : user_pref("CT2613550.LanguagePackLastCheckTime", "Sun Mar 06 2011 21:23:09 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.LanguagePackReloadIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2613550.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gelöscht : user_pref("CT2613550.LastLogin_2.7.1.3", "Sun Mar 06 2011 21:23:09 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.LatestVersion", "2.7.1.3");
Zeile gelöscht : user_pref("CT2613550.Locale", "de-de");
Zeile gelöscht : user_pref("CT2613550.LoginCache", 4);
Zeile gelöscht : user_pref("CT2613550.MCDetectTooltipHeight", "83");
Zeile gelöscht : user_pref("CT2613550.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gelöscht : user_pref("CT2613550.MCDetectTooltipWidth", "295");
Zeile gelöscht : user_pref("CT2613550.RadioIsPodcast", false);
Zeile gelöscht : user_pref("CT2613550.RadioMediaID", "8546");
Zeile gelöscht : user_pref("CT2613550.RadioMediaType", "Media Player");
Zeile gelöscht : user_pref("CT2613550.RadioMenuSelectedID", "EBRadioMenu_CT26135508546");
Zeile gelöscht : user_pref("CT2613550.RadioStationName", "Radio%208");
Zeile gelöscht : user_pref("CT2613550.RadioStationURL", "hxxp://stream.radio8.de:8000/live.m3u");
Zeile gelöscht : user_pref("CT2613550.SavedHomepage", "www.google.de");
Zeile gelöscht : user_pref("CT2613550.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2613550&octid=EB_ORIGINAL_CTID&SearchSource=1");
Zeile gelöscht : user_pref("CT2613550.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("CT2613550.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2613550&q=");
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabLastCheckTime", "Sun Mar 06 2011 21:23:09 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2613550.SettingsCheckIntervalMin", 120);
Zeile gelöscht : user_pref("CT2613550.SettingsLastCheckTime", "Sun Mar 06 2011 21:23:06 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.SettingsLastUpdate", "1298419708");
Zeile gelöscht : user_pref("CT2613550.ThirdPartyComponentsInterval", 504);
Zeile gelöscht : user_pref("CT2613550.ThirdPartyComponentsLastCheck", "Sun Mar 06 2011 21:23:06 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.ThirdPartyComponentsLastUpdate", "1255348257");
Zeile gelöscht : user_pref("CT2613550.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2613550.UserID", "UN32616888102332549");
Zeile gelöscht : user_pref("CT2613550.WeatherNetwork", "");
Zeile gelöscht : user_pref("CT2613550.WeatherPollDate", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.WeatherUnit", "C");
Zeile gelöscht : user_pref("CT2613550.alertChannelId", "1006347");
Zeile gelöscht : user_pref("CT2613550.clientLogIsEnabled", true);
Zeile gelöscht : user_pref("CT2613550.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2613550.ct2613550.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2613550.ct2613550.FeedLastCount3082739963941193807", 418);
Zeile gelöscht : user_pref("CT2613550.ct2613550.FirstTimeSettingsDone", true);
Zeile gelöscht : user_pref("CT2613550.ct2613550.InvalidateCache", false);
Zeile gelöscht : user_pref("CT2613550.ct2613550.LanguagePackLastCheckTime", "Sun Mar 06 2011 21:23:10 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.ct2613550.Locale", "de-de");
Zeile gelöscht : user_pref("CT2613550.ct2613550.RadioLastCheckTime", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.ct2613550.RadioLastUpdateIPServer", "3");
Zeile gelöscht : user_pref("CT2613550.ct2613550.RadioLastUpdateServer", "0");
Zeile gelöscht : user_pref("CT2613550.ct2613550.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2613550&octid=EB_ORIGINAL_CTID&SearchSource=1");
Zeile gelöscht : user_pref("CT2613550.ct2613550.SettingsCheckIntervalMin", 120);
Zeile gelöscht : user_pref("CT2613550.ct2613550.SettingsLastCheckTime", "Sun Mar 06 2011 21:23:07 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.ct2613550.SettingsLastUpdate", "1298419708");
Zeile gelöscht : user_pref("CT2613550.ct2613550.ThirdPartyComponentsLastCheck", "Sun Mar 06 2011 21:23:07 GMT+0100");
Zeile gelöscht : user_pref("CT2613550.ct2613550.ThirdPartyComponentsLastUpdate", "1255348257");
Zeile gelöscht : user_pref("CT2613550.myStuffEnabled", true);
Zeile gelöscht : user_pref("CT2613550.myStuffPublihserMinWidth", 400);
Zeile gelöscht : user_pref("CT2613550.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2613550.myStuffServiceIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2613550.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gelöscht : user_pref("CT2613550.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2613550");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2613550");
Zeile gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Mar 06 2011 21:23:08 GMT+0100");
Zeile gelöscht : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2613550");
Zeile gelöscht : user_pref("browser.search.defaultthis.engineName", "ZoneAlarm-Sicherheit Customized Web Search");
Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2613550&SearchSource=3&q={searchTerms}");
*************************
AdwCleaner[R0].txt - [18812 octets] - [03/10/2013 11:08:30]
AdwCleaner[S0].txt - [18227 octets] - [03/10/2013 11:11:08]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18288 octets] ########## --- --- ---
[/CODE] Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.3 (09.27.2013:1)
OS: Windows 7 Ultimate x64
Ran by Creasy on 03.10.2013 at 11:20:31,32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Creasy\appdata\local\{23940773-9359-49C4-8D46-6B7A69B822AD}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.10.2013 at 11:31:39,10
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.10.03.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
Creasy :: CREASY-PC [Administrator]
03.10.2013 11:00:50
mbam-log-2013-10-03 (11-00-50).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 235301
Laufzeit: 4 Minute(n), 39 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 2
HKCR\CLSID\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\Distromatic\Toolbars (PUP.Optional.AlexaTB.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
Man kann dir gar nicht genug danken. :)
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by Creasy (administrator) on CREASY-PC on 03-10-2013 11:42:34
Running from C:\Users\Creasy\Downloads
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Logitech Inc.) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Logitech Inc.) C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
() C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
() C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_8_800_175_ActiveX.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Launch LGDCore] - C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe [1783296 2006-07-23] (Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [9577680 2012-11-08] (COMODO)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKCU\...\Run: [Logitech Vid] - C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe [5458704 2009-07-16] (Logitech Inc.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6581488 2013-08-15] (SUPERAntiSpyware)
HKLM-x32\...\Run: [ATICustomerCare] - C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [311296 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LogitechQuickCamRibbon] - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304 2009-10-14] ()
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [emsisoft anti-malware] - c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4329408 2013-09-30] (Emsisoft GmbH)
HKLM-x32\...\Run: [bdruninstaller] - C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setupdownloader.exe [747096 2013-05-15] (Bitdefender)
AppInit_DLLs: C:\Windows\System32\guard64.dll [390392 2012-11-08] (COMODO)
AppInit_DLLs-x32: C:\Windows\SysWOW64\guard32.dll [301264 2012-11-08] (COMODO)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x699374FDC5A5CB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: No Name - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPID.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 %SystemRoot%\System32\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Creasy\AppData\Roaming\Mozilla\Firefox\Profiles\o7f062yg.default
FF SearchEngineOrder.3: Bing
FF Homepage: google.de
FF Keyword.URL: hxxp://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=071413&q=
FF NetworkProxy: "ftp", "109.207.61.212"
FF NetworkProxy: "ftp_port", 8090
FF NetworkProxy: "http", "109.207.61.212"
FF NetworkProxy: "http_port", 8090
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "109.207.61.212"
FF NetworkProxy: "socks_port", 8090
FF NetworkProxy: "ssl", "109.207.61.212"
FF NetworkProxy: "ssl_port", 8090
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @idsoftware.com/QuakeLive - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.10.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Creasy\AppData\Roaming\Mozilla\Firefox\Profiles\o7f062yg.default\searchplugins\bingp.xml
FF Extension: Deutsches Wörterbuch - C:\Users\Creasy\AppData\Roaming\Mozilla\Firefox\Profiles\o7f062yg.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: stealthyextension - C:\Users\Creasy\AppData\Roaming\Mozilla\Firefox\Profiles\o7f062yg.default\Extensions\stealthyextension@gmail.com.xpi
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4153784 2013-09-30] (Emsisoft GmbH)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG)
S4 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2828408 2012-11-08] (COMODO)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [130976 2011-03-01] (Futuremark Corporation)
S2 libusbd; C:\Windows\SysWow64\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net)
S4 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-14] ()
S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [70960 2013-08-24] (Emsisoft GmbH)
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [70960 2013-08-24] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [17384 2013-03-28] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [17384 2013-03-28] (Emsisoft GmbH)
R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2012-07-23] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-19] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-08-19] (Emsisoft GmbH)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-08-19] (Emsisoft GmbH)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [584056 2012-11-08] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [38144 2012-11-08] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-22] (DT Soft Ltd)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [94288 2012-11-08] (COMODO)
S3 libusb0; C:\Windows\SysWow64\drivers\libusb0.sys [33792 2005-03-09] ()
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2012-07-23] ()
R3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-12-29] (Duplex Secure Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz130; \??\C:\Users\Creasy\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [x]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S3 libusb0; system32\drivers\libusb0.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-03 11:42 - 2013-10-03 11:42 - 01954124 _____ (Farbar) C:\Users\Creasy\Downloads\FRST64.exe
2013-10-03 11:31 - 2013-10-03 11:31 - 00000949 _____ C:\Users\Creasy\Desktop\JRT.txt
2013-10-03 11:20 - 2013-10-03 11:20 - 00000000 ____D C:\Windows\ERUNT
2013-10-03 11:07 - 2013-10-03 11:11 - 00000000 ____D C:\AdwCleaner
2013-10-03 10:59 - 2013-10-03 10:59 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Malwarebytes
2013-10-03 10:58 - 2013-10-03 10:58 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-03 10:58 - 2013-10-03 10:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-03 10:58 - 2013-10-03 10:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-03 10:58 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-03 10:57 - 2013-10-03 10:57 - 01030305 _____ (Thisisu) C:\Users\Creasy\Downloads\JRT.exe
2013-10-03 10:56 - 2013-10-03 10:56 - 01045226 _____ C:\Users\Creasy\Downloads\adwcleaner.exe
2013-10-03 10:56 - 2013-10-03 10:56 - 01045226 _____ C:\Users\Creasy\Downloads\adwcleaner (1).exe
2013-10-03 10:55 - 2013-10-03 10:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Creasy\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-02 10:21 - 2013-10-02 10:21 - 00024279 _____ C:\ComboFix.txt
2013-10-02 10:14 - 2013-10-03 11:33 - 00089320 _____ C:\Windows\WindowsUpdate.log
2013-10-02 10:09 - 2013-10-02 10:09 - 00000347 ____N C:\spyhunter.log
2013-10-02 09:59 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-10-02 09:59 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-10-02 09:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-10-02 09:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-10-02 09:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-10-02 09:59 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-10-02 09:59 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-10-02 09:59 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-10-02 09:58 - 2013-10-02 10:21 - 00000000 ____D C:\Qoobox
2013-10-02 09:58 - 2013-10-02 10:19 - 00000000 ____D C:\Windows\erdnt
2013-10-02 09:57 - 2013-10-02 09:58 - 05132885 ____R (Swearware) C:\Users\Creasy\Downloads\ComboFix.exe
2013-10-02 08:13 - 2013-10-02 08:13 - 00000000 _____ C:\autoexec.bat
2013-10-02 08:10 - 2013-10-02 08:10 - 00000126 _____ C:\sh4_service.log
2013-10-02 08:07 - 2013-10-02 08:07 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-10-02 08:06 - 2013-10-02 09:51 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-02 06:57 - 2013-10-02 06:57 - 00077312 _____ (Emsisoft GmbH) C:\Windows\system32\eamclean.exe
2013-10-02 06:57 - 2013-10-02 06:57 - 00006928 _____ C:\Users\Creasy\Desktop\a2scan_131001-214826.txt
2013-10-02 06:57 - 2013-10-02 06:57 - 00000212 _____ C:\Windows\system32\eamclean.dat
2013-10-01 21:31 - 2013-10-01 21:31 - 01037680 _____ C:\Users\Creasy\Desktop\gmer.txt
2013-10-01 21:10 - 2013-10-01 21:10 - 00057089 _____ C:\Users\Creasy\Desktop\FRST.txt
2013-10-01 21:10 - 2013-10-01 21:10 - 00032004 _____ C:\Users\Creasy\Desktop\Addition.txt
2013-10-01 21:09 - 2013-10-01 21:09 - 00000000 ____D C:\FRST
2013-10-01 20:57 - 2013-10-01 20:58 - 00000600 _____ C:\Users\Creasy\Desktop\defogger_disable.log
2013-10-01 20:57 - 2013-10-01 20:57 - 00050477 _____ C:\Users\Creasy\Desktop\Defogger.exe
2013-10-01 20:57 - 2013-10-01 20:57 - 00000020 _____ C:\Users\Creasy\defogger_reenable
2013-10-01 20:43 - 2013-10-01 20:43 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-10-01 20:40 - 2013-10-01 21:12 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\QuickScan
2013-10-01 20:38 - 2013-10-01 20:39 - 00000000 ___HD C:\Windows\AxInstSV
2013-10-01 20:28 - 2013-10-01 20:28 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-01 20:28 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-10-01 20:27 - 2013-10-02 06:58 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-01 20:27 - 2013-10-01 20:27 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-01 20:22 - 2013-10-03 11:41 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2013-10-01 20:22 - 2013-10-03 11:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-01 20:22 - 2013-10-01 20:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-01 20:22 - 2013-10-01 20:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-01 20:22 - 2013-10-01 20:22 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-01 20:22 - 2013-10-01 20:22 - 00001091 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-10-01 20:22 - 2013-10-01 20:22 - 00000000 ____D C:\Users\Creasy\Documents\Anti-Malware
2013-10-01 20:12 - 2013-10-01 20:12 - 00000820 _____ C:\Users\Public\Desktop\SmartPCFixer.lnk
2013-10-01 20:11 - 2013-10-01 20:12 - 00000000 ____D C:\Program Files\SmartPCFixer
2013-10-01 19:34 - 2013-10-01 19:34 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\SUPERAntiSpyware.com
2013-10-01 19:28 - 2013-10-01 19:48 - 00002208 _____ C:\Windows\system32\ASOROSet.bin
2013-10-01 19:28 - 2013-10-01 19:28 - 00000000 ____D C:\Windows\system32\config\RCCBakup
2013-10-01 19:24 - 2013-10-01 19:24 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\Avira
2013-10-01 19:23 - 2013-10-01 19:23 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.1428.dll
2013-10-01 19:19 - 2013-10-01 19:19 - 00064536 _____ C:\Users\CreasyX\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-01 19:19 - 2013-10-01 19:19 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\ATI
2013-10-01 19:19 - 2013-10-01 19:19 - 00000000 ____D C:\Users\CreasyX\AppData\Local\ATI
2013-10-01 19:19 - 2013-10-01 19:19 - 00000000 ____D C:\Users\CreasyX\AppData\Local\AMD
2013-10-01 19:18 - 2013-10-01 19:18 - 00001381 _____ C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ___RD C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ___RD C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\Logitech
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\Adobe
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Local\VirtualStore
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Local\Logitech
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Local\Adobe
2013-10-01 19:17 - 2013-10-02 06:57 - 00000000 ____D C:\Users\CreasyX
2013-10-01 19:17 - 2013-10-01 19:17 - 00000020 ___SH C:\Users\CreasyX\ntuser.ini
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Vorlagen
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Startmenü
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Netzwerkumgebung
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Lokale Einstellungen
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Eigene Dateien
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Druckumgebung
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Documents\Eigene Musik
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Documents\Eigene Bilder
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\AppData\Local\Verlauf
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\AppData\Local\Anwendungsdaten
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Anwendungsdaten
2013-10-01 19:17 - 2011-02-08 18:29 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\Macromedia
2013-10-01 19:17 - 2009-07-14 06:54 - 00000000 ___RD C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-10-01 19:17 - 2009-07-14 06:49 - 00000000 ___RD C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-10-01 18:41 - 2013-10-01 20:02 - 00000000 ____D C:\Users\Creasy\Desktop\backups
2013-10-01 18:35 - 2013-10-01 20:00 - 00008987 _____ C:\Users\Creasy\Desktop\hijackthis.log
2013-10-01 18:34 - 2013-10-01 18:34 - 00388608 _____ (Trend Micro Inc.) C:\Users\Creasy\Desktop\HijackThis.exe
2013-10-01 18:23 - 2013-10-01 18:23 - 00001768 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-10-01 18:23 - 2013-10-01 18:23 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\SUPERAntiSpyware.com
2013-10-01 18:23 - 2013-10-01 18:23 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-10-01 18:23 - 2013-10-01 18:23 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-10-01 18:21 - 2013-10-01 18:21 - 00377856 _____ C:\Users\Creasy\Desktop\gmer_2.1.19163.exe
2013-10-01 18:05 - 2013-10-01 18:05 - 00064536 _____ C:\Users\Creasy\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-01 18:02 - 2013-10-03 11:34 - 00011746 _____ C:\Windows\PFRO.log
2013-10-01 18:02 - 2013-10-03 11:34 - 00000672 _____ C:\Windows\setupact.log
2013-10-01 18:02 - 2013-10-01 18:03 - 04854640 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-01 18:02 - 2013-10-01 18:02 - 00000000 _____ C:\Windows\setuperr.log
2013-10-01 16:16 - 2013-10-01 16:21 - 00000000 __SHD C:\Users\Creasy\lbsan
2013-10-01 15:59 - 2013-10-01 15:59 - 00000000 ____D C:\Users\Creasy\Documents\FIFA 14
2013-09-30 15:58 - 2013-09-30 15:58 - 00000521 _____ C:\Users\Public\Desktop\µTorrent.lnk
2013-09-29 09:53 - 2013-09-29 09:53 - 00000940 _____ C:\Users\Creasy\Desktop\Heroes II Gold.lnk
2013-09-29 09:52 - 2013-09-29 09:52 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\3DO
2013-09-25 14:53 - 2013-09-25 15:13 - 00000000 ____D C:\Users\Creasy\Desktop\Neuer Ordner (3)
2013-09-19 17:00 - 2013-09-19 17:00 - 00000000 ____D C:\ProgramData\Age of Empires 3
2013-09-19 16:47 - 2013-09-19 16:47 - 00000202 _____ C:\Users\Creasy\Desktop\Age of Empires III Complete Collection.url
2013-09-16 19:06 - 2013-09-16 19:06 - 00000000 ____D C:\Users\Creasy\Documents\Ascaron Entertainment
2013-09-16 19:06 - 2013-09-16 19:06 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Ascaron Entertainment
2013-09-11 18:46 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 18:46 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 18:46 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 18:46 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 18:46 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 18:46 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 18:46 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 18:46 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-11 18:46 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 18:46 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-11 18:46 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 18:46 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-11 18:46 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-11 18:46 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-11 13:34 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 13:34 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-11 13:34 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-11 13:34 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-11 13:34 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-11 13:34 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-11 13:34 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-11 13:34 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-11 13:34 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-11 13:34 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-11 13:34 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-11 13:34 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-11 13:34 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-11 13:34 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-11 13:34 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-11 13:34 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-11 13:34 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-11 13:34 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-11 13:34 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-11 13:34 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-11 13:34 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-11 13:34 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 13:34 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-11 13:34 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-11 13:34 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-11 13:34 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-11 13:34 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
==================== One Month Modified Files and Folders =======
2013-10-03 11:42 - 2013-10-03 11:42 - 01954124 _____ (Farbar) C:\Users\Creasy\Downloads\FRST64.exe
2013-10-03 11:41 - 2013-10-01 20:22 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2013-10-03 11:40 - 2013-10-02 10:14 - 00089320 _____ C:\Windows\WindowsUpdate.log
2013-10-03 11:37 - 2011-01-16 17:14 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Skype
2013-10-03 11:34 - 2013-10-01 18:02 - 00011746 _____ C:\Windows\PFRO.log
2013-10-03 11:34 - 2013-10-01 18:02 - 00000672 _____ C:\Windows\setupact.log
2013-10-03 11:34 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-03 11:33 - 2009-07-14 06:45 - 00017488 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-03 11:33 - 2009-07-14 06:45 - 00017488 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-03 11:32 - 2013-10-01 20:22 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-03 11:31 - 2013-10-03 11:31 - 00000949 _____ C:\Users\Creasy\Desktop\JRT.txt
2013-10-03 11:20 - 2013-10-03 11:20 - 00000000 ____D C:\Windows\ERUNT
2013-10-03 11:11 - 2013-10-03 11:07 - 00000000 ____D C:\AdwCleaner
2013-10-03 10:59 - 2013-10-03 10:59 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Malwarebytes
2013-10-03 10:58 - 2013-10-03 10:58 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-03 10:58 - 2013-10-03 10:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-03 10:58 - 2013-10-03 10:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-03 10:57 - 2013-10-03 10:57 - 01030305 _____ (Thisisu) C:\Users\Creasy\Downloads\JRT.exe
2013-10-03 10:56 - 2013-10-03 10:56 - 01045226 _____ C:\Users\Creasy\Downloads\adwcleaner.exe
2013-10-03 10:56 - 2013-10-03 10:56 - 01045226 _____ C:\Users\Creasy\Downloads\adwcleaner (1).exe
2013-10-03 10:55 - 2013-10-03 10:55 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Creasy\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-03 09:04 - 2010-12-27 16:06 - 00000000 _____ C:\Windows\system32\Drivers\lvuvc.hs
2013-10-02 10:21 - 2013-10-02 10:21 - 00024279 _____ C:\ComboFix.txt
2013-10-02 10:21 - 2013-10-02 09:58 - 00000000 ____D C:\Qoobox
2013-10-02 10:19 - 2013-10-02 09:58 - 00000000 ____D C:\Windows\erdnt
2013-10-02 10:16 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-10-02 10:09 - 2013-10-02 10:09 - 00000347 ____N C:\spyhunter.log
2013-10-02 10:09 - 2010-12-27 14:50 - 00000000 ____D C:\Users\Creasy
2013-10-02 10:09 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system
2013-10-02 09:58 - 2013-10-02 09:57 - 05132885 ____R (Swearware) C:\Users\Creasy\Downloads\ComboFix.exe
2013-10-02 09:58 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-02 09:51 - 2013-10-02 08:06 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP
2013-10-02 08:13 - 2013-10-02 08:13 - 00000000 _____ C:\autoexec.bat
2013-10-02 08:10 - 2013-10-02 08:10 - 00000126 _____ C:\sh4_service.log
2013-10-02 08:07 - 2013-10-02 08:07 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-10-02 07:04 - 2011-05-22 19:42 - 00000000 ____D C:\Users\Creasy\AppData\Local\Google
2013-10-02 07:04 - 2011-05-22 19:42 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-02 06:58 - 2013-10-01 20:27 - 00000000 ____D C:\ProgramData\AVAST Software
2013-10-02 06:57 - 2013-10-02 06:57 - 00077312 _____ (Emsisoft GmbH) C:\Windows\system32\eamclean.exe
2013-10-02 06:57 - 2013-10-02 06:57 - 00006928 _____ C:\Users\Creasy\Desktop\a2scan_131001-214826.txt
2013-10-02 06:57 - 2013-10-02 06:57 - 00000212 _____ C:\Windows\system32\eamclean.dat
2013-10-02 06:57 - 2013-10-01 19:17 - 00000000 ____D C:\Users\CreasyX
2013-10-01 21:31 - 2013-10-01 21:31 - 01037680 _____ C:\Users\Creasy\Desktop\gmer.txt
2013-10-01 21:21 - 2012-02-24 09:09 - 00093209 _____ C:\Users\Creasy\Desktop\d1.txt
2013-10-01 21:12 - 2013-10-01 20:40 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\QuickScan
2013-10-01 21:10 - 2013-10-01 21:10 - 00057089 _____ C:\Users\Creasy\Desktop\FRST.txt
2013-10-01 21:10 - 2013-10-01 21:10 - 00032004 _____ C:\Users\Creasy\Desktop\Addition.txt
2013-10-01 21:09 - 2013-10-01 21:09 - 00000000 ____D C:\FRST
2013-10-01 20:58 - 2013-10-01 20:57 - 00000600 _____ C:\Users\Creasy\Desktop\defogger_disable.log
2013-10-01 20:57 - 2013-10-01 20:57 - 00050477 _____ C:\Users\Creasy\Desktop\Defogger.exe
2013-10-01 20:57 - 2013-10-01 20:57 - 00000020 _____ C:\Users\Creasy\defogger_reenable
2013-10-01 20:43 - 2013-10-01 20:43 - 00000000 ____D C:\Program Files\Common Files\Bitdefender
2013-10-01 20:39 - 2013-10-01 20:38 - 00000000 ___HD C:\Windows\AxInstSV
2013-10-01 20:28 - 2013-10-01 20:28 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-10-01 20:27 - 2013-10-01 20:27 - 00000000 ____D C:\Program Files\AVAST Software
2013-10-01 20:22 - 2013-10-01 20:22 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-01 20:22 - 2013-10-01 20:22 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-01 20:22 - 2013-10-01 20:22 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-01 20:22 - 2013-10-01 20:22 - 00001091 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-10-01 20:22 - 2013-10-01 20:22 - 00000000 ____D C:\Users\Creasy\Documents\Anti-Malware
2013-10-01 20:12 - 2013-10-01 20:12 - 00000820 _____ C:\Users\Public\Desktop\SmartPCFixer.lnk
2013-10-01 20:12 - 2013-10-01 20:11 - 00000000 ____D C:\Program Files\SmartPCFixer
2013-10-01 20:02 - 2013-10-01 18:41 - 00000000 ____D C:\Users\Creasy\Desktop\backups
2013-10-01 20:00 - 2013-10-01 18:35 - 00008987 _____ C:\Users\Creasy\Desktop\hijackthis.log
2013-10-01 19:49 - 2009-07-14 04:34 - 73138176 _____ C:\Windows\system32\config\SOFTWARE.bak
2013-10-01 19:49 - 2009-07-14 04:34 - 21757952 _____ C:\Windows\system32\config\SYSTEM.bak
2013-10-01 19:49 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak
2013-10-01 19:48 - 2013-10-01 19:28 - 00002208 _____ C:\Windows\system32\ASOROSet.bin
2013-10-01 19:45 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SAM.bak
2013-10-01 19:34 - 2013-10-01 19:34 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\SUPERAntiSpyware.com
2013-10-01 19:28 - 2013-10-01 19:28 - 00000000 ____D C:\Windows\system32\config\RCCBakup
2013-10-01 19:24 - 2013-10-01 19:24 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\Avira
2013-10-01 19:23 - 2013-10-01 19:23 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.1428.dll
2013-10-01 19:23 - 2010-12-27 14:50 - 00000000 ___RD C:\Users\Creasy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-01 19:19 - 2013-10-01 19:19 - 00064536 _____ C:\Users\CreasyX\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-01 19:19 - 2013-10-01 19:19 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\ATI
2013-10-01 19:19 - 2013-10-01 19:19 - 00000000 ____D C:\Users\CreasyX\AppData\Local\ATI
2013-10-01 19:19 - 2013-10-01 19:19 - 00000000 ____D C:\Users\CreasyX\AppData\Local\AMD
2013-10-01 19:18 - 2013-10-01 19:18 - 00001381 _____ C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ___RD C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ___RD C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\Logitech
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Roaming\Adobe
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Local\VirtualStore
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Local\Logitech
2013-10-01 19:18 - 2013-10-01 19:18 - 00000000 ____D C:\Users\CreasyX\AppData\Local\Adobe
2013-10-01 19:17 - 2013-10-01 19:17 - 00000020 ___SH C:\Users\CreasyX\ntuser.ini
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Vorlagen
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Startmenü
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Netzwerkumgebung
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Lokale Einstellungen
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Eigene Dateien
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Druckumgebung
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Documents\Eigene Musik
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Documents\Eigene Bilder
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\AppData\Local\Verlauf
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\AppData\Local\Anwendungsdaten
2013-10-01 19:17 - 2013-10-01 19:17 - 00000000 _SHDL C:\Users\CreasyX\Anwendungsdaten
2013-10-01 19:08 - 2010-12-27 15:15 - 00000000 ____D C:\Users\Creasy\AppData\Local\Mozilla
2013-10-01 18:54 - 2011-07-03 17:18 - 00000000 ____D C:\Program Files (x86)\ScummVM
2013-10-01 18:35 - 2010-12-27 14:50 - 00000000 ____D C:\Users\Creasy\AppData\Local\VirtualStore
2013-10-01 18:34 - 2013-10-01 18:34 - 00388608 _____ (Trend Micro Inc.) C:\Users\Creasy\Desktop\HijackThis.exe
2013-10-01 18:23 - 2013-10-01 18:23 - 00001768 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2013-10-01 18:23 - 2013-10-01 18:23 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\SUPERAntiSpyware.com
2013-10-01 18:23 - 2013-10-01 18:23 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2013-10-01 18:23 - 2013-10-01 18:23 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-10-01 18:21 - 2013-10-01 18:21 - 00377856 _____ C:\Users\Creasy\Desktop\gmer_2.1.19163.exe
2013-10-01 18:05 - 2013-10-01 18:05 - 00064536 _____ C:\Users\Creasy\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-01 18:04 - 2011-06-23 23:26 - 00000000 __SHD C:\Users\Creasy\AppData\Roaming\C51960
2013-10-01 18:03 - 2013-10-01 18:02 - 04854640 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-01 18:02 - 2013-10-01 18:02 - 00000000 _____ C:\Windows\setuperr.log
2013-10-01 18:00 - 2010-12-27 15:19 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Winamp
2013-10-01 17:49 - 2012-09-16 12:58 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\uTorrent
2013-10-01 17:49 - 2010-12-29 11:27 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\DAEMON Tools Lite
2013-10-01 17:48 - 2010-12-27 14:41 - 00000000 ____D C:\Windows\Panther
2013-10-01 16:21 - 2013-10-01 16:16 - 00000000 __SHD C:\Users\Creasy\lbsan
2013-10-01 15:59 - 2013-10-01 15:59 - 00000000 ____D C:\Users\Creasy\Documents\FIFA 14
2013-09-30 15:58 - 2013-09-30 15:58 - 00000521 _____ C:\Users\Public\Desktop\µTorrent.lnk
2013-09-29 09:53 - 2013-09-29 09:53 - 00000940 _____ C:\Users\Creasy\Desktop\Heroes II Gold.lnk
2013-09-29 09:53 - 2011-04-28 11:16 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-09-29 09:52 - 2013-09-29 09:52 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\3DO
2013-09-26 15:54 - 2010-12-27 16:04 - 00000000 ____D C:\Users\Creasy\Desktop\bilder
2013-09-25 15:24 - 2009-07-14 19:58 - 00696832 _____ C:\Windows\system32\perfh007.dat
2013-09-25 15:24 - 2009-07-14 19:58 - 00148128 _____ C:\Windows\system32\perfc007.dat
2013-09-25 15:24 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-25 15:19 - 2012-04-16 21:09 - 00000000 ____D C:\Users\Creasy\Desktop\Neuer Ordner
2013-09-25 15:13 - 2013-09-25 14:53 - 00000000 ____D C:\Users\Creasy\Desktop\Neuer Ordner (3)
2013-09-19 17:00 - 2013-09-19 17:00 - 00000000 ____D C:\ProgramData\Age of Empires 3
2013-09-19 17:00 - 2010-12-27 21:45 - 00000000 ____D C:\Users\Creasy\Documents\My Games
2013-09-19 16:47 - 2013-09-19 16:47 - 00000202 _____ C:\Users\Creasy\Desktop\Age of Empires III Complete Collection.url
2013-09-16 19:06 - 2013-09-16 19:06 - 00000000 ____D C:\Users\Creasy\Documents\Ascaron Entertainment
2013-09-16 19:06 - 2013-09-16 19:06 - 00000000 ____D C:\Users\Creasy\AppData\Roaming\Ascaron Entertainment
2013-09-15 17:32 - 2013-03-03 21:34 - 00000000 ____D C:\Users\Creasy\Desktop\SPIELE
2013-09-15 15:45 - 2013-07-17 20:03 - 00000000 ____D C:\Users\Creasy\Desktop\MP3 Download
2013-09-15 12:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-12 06:51 - 2010-12-27 14:50 - 00000000 ___RD C:\Users\Creasy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-11 18:46 - 2013-08-16 21:04 - 00000000 ____D C:\Windows\system32\MRT
2013-09-11 18:43 - 2011-01-29 11:25 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-11 18:42 - 2011-04-13 11:03 - 01590298 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-09-08 04:45 - 2012-10-20 08:34 - 00014848 _____ C:\Users\Creasy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-08 04:28 - 2012-12-08 16:20 - 00000000 ____D C:\Users\Creasy\Desktop\Wenke
2013-09-03 10:31 - 2013-08-19 16:36 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.1428.dll
Some content of TEMP:
====================
C:\Users\Creasy\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-02 01:12
==================== End Of Log ============================ --- --- ---
--- --- ---
[/CODE] |