Franky1993 | 28.08.2014 19:20 | mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.08.2014
Suchlauf-Zeit: 18:14:37
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.03.04.09
Rootkit Datenbank: v2014.02.20.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Franky
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 292071
Verstrichene Zeit: 11 Min, 12 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 9
Trojan.Banker, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C0F1636E-13A8-4C84-BB11-774BE45E1F83}, In Quarantäne, [2623ef10b1c93006840887c0e41eff01],
Trojan.Banker, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C0F1636E-13A8-4C84-BB11-774BE45E1F83}, In Quarantäne, [2623ef10b1c93006840887c0e41eff01],
Trojan.Banker, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C0F1636E-13A8-4C84-BB11-774BE45E1F83}, In Quarantäne, [2623ef10b1c93006840887c0e41eff01],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [68e146b9a1d91b1bb6f0e8ce5ea52fd1],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [57f2fc0397e38ea8971bc3fc1de642be],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [93b64bb44139b97d2d79e2d49073dd23],
PUP.Optional.Qone8, HKU\S-1-5-21-2521981952-1457118651-2954859535-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [81c8fa054c2e70c6456015a18a79a65a],
PUP.Optional.Qone8, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [1c2d6699f8821f17881dc4f256adbc44],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [24250cf3c9b176c01da0b3f845be35cb],
Registrierungswerte: 2
Trojan.Agent, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Userinit, C:\Users\Simon\AppData\Roaming\appConf32.exe, In Quarantäne, [a4a53cc3d1a9221444eb1cefe81b2ed2]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {EF32ACD6-DCE9-11E2-8248-871FE912F296}, In Quarantäne, [24250cf3c9b176c01da0b3f845be35cb]
Registrierungsdaten: 7
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878),Ersetzt,[42071de212682f07d3df8fa0768ea957]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[67e2ea151a602b0bd56e0728cd379a66]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878&q={searchTerms}),Ersetzt,[fd4c619e314942f411a075ba2dd75da3]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878),Ersetzt,[c980a95621590d290ea2200f34d0ad53]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878),Ersetzt,[8cbde41b1763b97d486a38f77a8afe02]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[1930649b601a88aeb68d9f909b6915eb]
Hijack.StartPage, HKU\S-1-5-21-2521981952-1457118651-2954859535-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.qvo6.com/?utm_source=b&utm_medium=mlv&from=mlv&uid=3219913727_132775_6A9C8794&ts=1372245310, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.qvo6.com/?utm_source=b&utm_medium=mlv&from=mlv&uid=3219913727_132775_6A9C8794&ts=1372245310),Ersetzt,[1039ba45b0caa5914b9a7ab44cb8817f]
Ordner: 0
(No malicious items detected)
Dateien: 17
PUP.Optional.Softonic.A, C:\Users\Franky\Downloads\SoftonicDownloader_for_spotify-mobile.exe, In Quarantäne, [f356a25def8b2b0b05fec0a27b865ea2],
PUP.Optional.Bandoo, C:\Users\Simon\Downloads\iLividSetup-r484-n-bc.exe, In Quarantäne, [88c19669f58559dd5d46eb6037caa759],
PUP.Optional.Bandoo, C:\Users\Simon\Downloads\iLividSetup-r484-n-bf.exe, In Quarantäne, [94b5d22d67136bcb861d67e45da441bf],
PUP.Optional.Softonic.A, C:\Users\Simon\Downloads\SoftonicDownloader_for_mcedit.exe, In Quarantäne, [2623996694e6f343b350a0c2b15010f0],
PUP.Optional.Softonic, C:\Users\Simon\Downloads\SoftonicDownloader_for_terraria.exe, In Quarantäne, [51f821de7efc7bbbdbc86ed81fe2d12f],
PUP.Optional.Softonic, C:\Users\Simon\Downloads\SoftonicDownloader_fuer_pflanzen-gegen-zombies.exe, In Quarantäne, [38117f80750554e2940f8db9bc45b14f],
PUP.Optional.Softonic, C:\Users\Simon\Downloads\SoftonicDownloader_fuer_terraria.exe, In Quarantäne, [de6bcc33a7d3b87e396a1d299d64b050],
PUP.Optional.Somoto, C:\Users\Simon\Downloads\MCPatcher_downloader_by_MCPatcher.exe, In Quarantäne, [0b3e77889bdf67cf62bcdb768084ec14],
PUP.BundleInstaller.VG, C:\Users\Simon\Downloads\video_downloader(1).exe, In Quarantäne, [8cbd76898bef87af5a969535b848768a],
HackTool.GamesCheat, C:\Users\Simon\Downloads\pvszv1201094+7trn.rar, In Quarantäne, [232649b6d8a2d2645cea7bc430d4768a],
PUP.BundleInstaller.VG, C:\Users\Simon\Downloads\video_downloader.exe, In Quarantäne, [410867984733c86e1fd1d4f6956beb15],
PUP.Optional.4Shared, C:\Users\Simon\Downloads\Terraria 1.1.2.exe, In Quarantäne, [d67355aa99e186b02b114e1e35cb58a8],
PUP.Optional.Somoto, C:\Users\Simon\Downloads\etypesetup(1).exe, In Quarantäne, [ea5fc03f7cfe6fc731eddd74d430a55b],
PUP.Optional.Somoto, C:\Users\Simon\Downloads\etypesetup.exe, In Quarantäne, [1a2fbd42453587af8b93e26fe024dd23],
PUP.Optional.RegCleanerPro, C:\Users\Simon\Downloads\rcpsetup_softonic_new_sd_new_enrest(1).exe, In Quarantäne, [b792f30ced8d52e40bd2de6edd24ef11],
PUP.Optional.RegCleanerPro, C:\Users\Simon\Downloads\rcpsetup_softonic_new_sd_new_enrest.exe, In Quarantäne, [3c0de619b9c1f04607d648049d64e51b],
PUP.Optional.SweetPage.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml, In Quarantäne, [9dacf609a1d963d3b001f6c9e221cf31],
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCkleaner[S0].txt Code:
# AdwCleaner v3.308 - Bericht erstellt am 28/08/2014 um 19:42:38
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Franky - FRANKY-PC
# Gestartet von : C:\Users\Franky\Desktop\adwcleaner_3.308.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Device
Ordner Gelöscht : C:\Users\Franky\AppData\Roaming\SendSpace
Ordner Gelöscht : C:\Users\Simon\AppData\Local\b1e
Ordner Gelöscht : C:\Users\Simon\AppData\Local\vghd
Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\B1Toolbar
Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\eIntaller
Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\otshot
Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\Smartbar
Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\CT3241949
Ordner Gelöscht : C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\faststartff@gmail.com
Ordner Gelöscht : C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\o_08@wwnrgdbya.edu
Ordner Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\Extensions\{78e516ef-11de-47a1-8364-a99b917ec5ee}
Ordner Gelöscht : C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajckffdklmhnklkigjoohdgjmkeehcah
Datei Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\searchplugins\fileconverter-13-customized-web-search.xml
Datei Gelöscht : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\user.js
Datei Gelöscht : C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Trymedia Systems
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17239
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.sweet-page.com/newtab/?type=nt&ts=1404564574&from=wld&uid=WDCXWD30EZRX-00DC0B0_WD-WCC1T101487814878");
[ Datei : C:\Users\Simon\AppData\Roaming\Mozilla\Firefox\Profiles\98aws5v5.default\prefs.js ]
Zeile gelöscht : user_pref("CT3241949.1000082.isDisplayHidden", "true");
Zeile gelöscht : user_pref("CT3241949.1000082.shrinkState", "shrinked");
Zeile gelöscht : user_pref("CT3241949.1000082.state", "{\"state\":\"stopped\",\"text\":\"NDR 2\",\"description\":\"NDR 2\",\"url\":\"hxxp://lsd.newmedia.tiscali-business.com/bb/redirect.lsc?content=live&media=ms&strea[...]
Zeile gelöscht : user_pref("CT3241949.1000234.TWC_TMP_city", "BERLIN");
Zeile gelöscht : user_pref("CT3241949.1000234.TWC_TMP_country", "DE");
Zeile gelöscht : user_pref("CT3241949.1000234.TWC_locId", "GMXX0007");
Zeile gelöscht : user_pref("CT3241949.1000234.TWC_location", "Berlin, Deutschland");
Zeile gelöscht : user_pref("CT3241949.1000234.TWC_region", "DE");
Zeile gelöscht : user_pref("CT3241949.1000234.TWC_temp_dis", "c");
Zeile gelöscht : user_pref("CT3241949.1000234.TWC_wind_dis", "kmh");
Zeile gelöscht : user_pref("CT3241949.1000234.weatherData", "{\"icon\":\"20.png\",\"temperature\":\"2°C\",\"temperatureClear\":\"2°C\",\"highTemperature\":\"2°C\",\"lowTemperature\":\"0°C\",\"feelsLike\":\"2°C\",\"con[...]
Zeile gelöscht : user_pref("CT3241949.1000515.APP_WIN_FEATURES", "%F8%EB%F9%EF%u0100%E7%E8%F2%EB%C3%B6%B2%EE%F9%E9%F8%F5%F2%F2%C3%B6%B2%FC%F9%E9%F8%F5%F2%F2%C3%B6%B2%FA%EF%FA%F2%EB%E8%E7%F8%C3%B7%B2%E9%F2%F5%F9%EB%E8%[...]
Zeile gelöscht : user_pref("CT3241949.1000515.FacebookLanguageByUser", "");
Zeile gelöscht : user_pref("CT3241949.1000515.Facebook_Last_Visit_Tab", "");
Zeile gelöscht : user_pref("CT3241949.3174054215061172570.bornDate", "{\"dataType\":\"string\",\"data\":\"{\\\"Response\\\":\\\"08\\\\/13\\\\/2013 18\\\"}\"}");
Zeile gelöscht : user_pref("CT3241949.CBOpenMAMSettings.enc", "MA==");
Zeile gelöscht : user_pref("CT3241949.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.Facebook_Mode", "%B8");
Zeile gelöscht : user_pref("CT3241949.Facebook_Mode.enc", "Mg==");
Zeile gelöscht : user_pref("CT3241949.Facebook_User_Locale", "%EA%EB");
Zeile gelöscht : user_pref("CT3241949.Facebook_User_Locale.enc", "ZGU=");
Zeile gelöscht : user_pref("CT3241949.FirstTime", "true");
Zeile gelöscht : user_pref("CT3241949.FirstTimeFF3", "true");
Zeile gelöscht : user_pref("CT3241949.LoginRevertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT3241949.RevertSettingsEnabled", true);
Zeile gelöscht : user_pref("CT3241949.SF_JUST_INSTALLED.enc", "RkFMU0U=");
Zeile gelöscht : user_pref("CT3241949.SF_STATUS.enc", "RU5BQkxFRA==");
Zeile gelöscht : user_pref("CT3241949.SF_USER_ID.enc", "Y2lkXzIyNDIwMTMxMTM4NTEzNDYyODAz");
Zeile gelöscht : user_pref("CT3241949.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241949&SearchSource=2&q=");
Zeile gelöscht : user_pref("CT3241949.UserID", "UN91888041744268743");
Zeile gelöscht : user_pref("CT3241949.addressBarTakeOverEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT3241949.browser.search.defaultthis.engineName", true);
Zeile gelöscht : user_pref("CT3241949.cb_experience_000.enc", "Mjg=");
Zeile gelöscht : user_pref("CT3241949.cb_firstuse0100.enc", "MQ==");
Zeile gelöscht : user_pref("CT3241949.cb_user_id_000.enc", "Q0I0NTAxMDU1MDY2OTNfMTM2NzI0NzIwNTYwMl9GaXJlZm94");
Zeile gelöscht : user_pref("CT3241949.cbcountry_001.enc", "REU=");
Zeile gelöscht : user_pref("CT3241949.cbfirsttime.enc", "V2VkIERlYyAxOSAyMDEyIDE0OjMxOjI3IEdNVCswMTAw");
Zeile gelöscht : user_pref("CT3241949.embeddedsData", "[{\"appId\":\"129887071061272563\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Zeile gelöscht : user_pref("CT3241949.enableAlerts", "always");
Zeile gelöscht : user_pref("CT3241949.event_data.enc", "JTVCJTVE");
Zeile gelöscht : user_pref("CT3241949.fired_events.enc", "AA==");
Zeile gelöscht : user_pref("CT3241949.firstTimeDialogOpened", "true");
Zeile gelöscht : user_pref("CT3241949.fixPageNotFoundErrorInHidden", "true");
Zeile gelöscht : user_pref("CT3241949.fixUrls", true);
Zeile gelöscht : user_pref("CT3241949.hxxp___facebook_conduitapps_com.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPTAsaHNjcm9sbD0wLHZzY3JvbGw9MCx0aXRsZWJhcj0xLGNsb3NlYnV0dG9uPTEsc2F2ZXJlc2l6ZWRzaXplPTAsb3BlbnBvc2l0aW9uPWFsaWd[...]
Zeile gelöscht : user_pref("CT3241949.installType", "Unknown");
Zeile gelöscht : user_pref("CT3241949.isCheckedStartAsHidden", true);
Zeile gelöscht : user_pref("CT3241949.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.isFirstTimeToolbarLoading", "false");
Zeile gelöscht : user_pref("CT3241949.isNewTabEnabled", true);
Zeile gelöscht : user_pref("CT3241949.isPerformedSmartBarTransition", "true");
Zeile gelöscht : user_pref("CT3241949.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT3241949.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.key_date.enc", "MTk=");
Zeile gelöscht : user_pref("CT3241949.keyword", true);
Zeile gelöscht : user_pref("CT3241949.mam_gk_appStateReportTime", "%B7%B9%BE%BA%B6%BE%B8%BD%B8%B8%BE%B9%BA");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appStateReportTime.enc", "MTM4NDA4MjcyMjgzNA==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_CouponBuddy.enc", "b24=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_Easytobook.enc", "b24=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_Easytobook_targeted.enc", "b24=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_PriceGong.enc", "b24=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appState_WindowShopper.enc", "b24=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appsConfig.enc", "eyJBcHBzQ29uZmlndXJhdGlvbiI6W3siaWQiOiJDbGFyaXR5X0FjdGl2ZSIsInVybCI6Imh0dHA6Ly9zdG9yYWdlLmNvbmR1aXQuY29tL21hbS8zcmRwYXJ0eWFwcHMvY2xhcml0eVJheS9jcl9hY3Rpdm[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_appsDefaultEnabled", "%F4%FB%F2%F2");
Zeile gelöscht : user_pref("CT3241949.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_calledSetupService.enc", "MQ==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_currentBadgeValue", "%BF%BB");
Zeile gelöscht : user_pref("CT3241949.mam_gk_currentBadgeValue.enc", "OTU=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_currentVersion", "%B7%B4%B7%B7%B4%BA%B4%B8");
Zeile gelöscht : user_pref("CT3241949.mam_gk_currentVersion.enc", "MS4xMS40LjI=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_eventsCache.enc", "eyI3YmYzYzQwNi0xMjc1LTQ0ZjItOWU3OS0zMjlmMjM4N2Q4NDAiOnsidG9waWMiOiJzZW5kVXNhZ2UiLCJkYXRhIjp7ImNhdGVnb3J5IjoiV2VsY29tZSIsImFjdGlvbiI6IlZpZXciLCJsYWJlbCI6I[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_existingUsersRecoveryDone.enc", "MQ==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_first_time", "%B7");
Zeile gelöscht : user_pref("CT3241949.mam_gk_first_time.enc", "MQ==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_gadgetOpen.enc", "bmV3QXBw");
Zeile gelöscht : user_pref("CT3241949.mam_gk_globalKeysMigratedToLocalStorage", "%B7");
Zeile gelöscht : user_pref("CT3241949.mam_gk_globalKeysMigratedToLocalStorage.enc", "MQ==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_lastLoginTime", "%B7%B9%BE%BA%B6%BE%B8%BD%B8%B9%BB%BA%B6");
Zeile gelöscht : user_pref("CT3241949.mam_gk_lastLoginTime.enc", "MTM4NDA4MjcyMzU0MA==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_localization", "%u0101%A8%ED%E7%EA%ED%EB%FA%C9%F5%F4%FA%EB%F4%FA%D6%F5%F2%EF%E9%FF%A8%C0%u0101%A8%DA%EB%FE%FA%A8%C0%A8%C9%F5%F4%FA%EB%F4%FA%B3%D8%EF%E9%EE%FA%F2%EF%F4%EF%EB[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50LVJpY2h0bGluaWUifSwiZ2FkZ2V0RGVzY3JpcHRpb25QcmltYXJ5Ijp7IlRleHQiOiJWYWx1ZSBBcHBzIGJlcmVpY2hlcnQgSWhy[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_newApps.enc", "W3siaWQiOiJDbGFyaXR5X0FjdGl2ZSIsIm5hbWUiOiJDbGFyaXR5IiwiZGVzY3JpcHRpb24iOm51bGwsImFkZGVkQXQiOiIxMzg0MDgyNzIyNzcxIn0seyJpZCI6ImVUb3JvIiwibmFtZSI6ImVUb3JvIiwiZ[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.10.2.5.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBl[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.10.4.0.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBl[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.11.4.2", "%u0101%A8%D9%FA%E7%FA%FB%F9%A8%C0%A8%F9%FB%E9%E9%EB%EB%EA%EB%EA%A8%B2%A8%CA%E7%FA%E7%A8%C0%u0101%A8%E9%FB%F8%F8%EB%F4%FA%CA%E7%FA%EB%A8%C0%A8%B8%B6%B7%B[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.11.4.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImN1cnJlbnREYXRlIjoiMjAxMzExMTAiLCJpbnRlcnZhbCI6MjQwLCJzdGFtcCI6IjQ2XzAiLCJpc1Rlc3QiOnRydWUsIlVzZXJDb3VudHJ5[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.6.0.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzA1XzAiLCJpc1Rlc3QiOnRydWUsImlzV2VsY29tZUV4cGVyaWVuY2VFbmFibGVkQnlEZWZhdWx0I[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.8.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBlc[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_settings1.9.0.4.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNDZfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiREUiLCJpc1dlbGNvbWVFeHBlc[...]
Zeile gelöscht : user_pref("CT3241949.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_showWelcomeGadget", "%EC%E7%F2%F9%EB");
Zeile gelöscht : user_pref("CT3241949.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
Zeile gelöscht : user_pref("CT3241949.mam_gk_stamp", "%BA%BC%E5%B6");
Zeile gelöscht : user_pref("CT3241949.mam_gk_stamp.enc", "NDZfMA==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_userId", "%EA%BD%E9%BC%BD%BA%EC%B6%B3%BB%BA%BC%B6%B3%BA%BD%E8%B9%B3%BF%BE%E9%B7%B3%BB%B8%B8%B7%B6%BF%EA%E9%BF%EB%EA%B9");
Zeile gelöscht : user_pref("CT3241949.mam_gk_userId.enc", "ZDdjNjc0ZjAtNTQ2MC00N2IzLTk4YzEtNTIyMTA5ZGM5ZWQz");
Zeile gelöscht : user_pref("CT3241949.mam_gk_user_approval_interacted", "%B7");
Zeile gelöscht : user_pref("CT3241949.mam_gk_user_approval_interacted.enc", "MQ==");
Zeile gelöscht : user_pref("CT3241949.mam_gk_welcomeDialogMode", "%B7");
Zeile gelöscht : user_pref("CT3241949.mam_gk_welcomeDialogMode.enc", "MQ==");
Zeile gelöscht : user_pref("CT3241949.migrateAppsAndComponents", true);
Zeile gelöscht : user_pref("CT3241949.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.amazon.de%2FMultifunktional-Adapter-MicroSDHC-MicroSDXC-schmaler%2Fdp%2FB00DYAZYF4%2Fref[...]
Zeile gelöscht : user_pref("CT3241949.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.personalApps", "{\"dataType\":\"object\",\"data\":\"[\\\"BROWSER_COMPONENT\\\"]\"}");
Zeile gelöscht : user_pref("CT3241949.price-gong.bornDate", "{\"dataType\":\"string\",\"data\":\"{\\\"Response\\\":\\\"09\\\\/25\\\\/2013 14\\\"}\"}");
Zeile gelöscht : user_pref("CT3241949.search.searchAppId", "129887071061272563");
Zeile gelöscht : user_pref("CT3241949.search.searchCount", "2");
Zeile gelöscht : user_pref("CT3241949.searchInNewTabEnabledInHidden", "true");
Zeile gelöscht : user_pref("CT3241949.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3241949\"}");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://FileConverter13.OurToolbar.com//xpi\"}");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"FileConverter 1.3\"}");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1383664203356");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_appsMetadata_lastUpdate", "1384086149492");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1383664203146");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_login_10.13.40.15_lastUpdate", "1398352391398");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_menu_769c590835a76d075fe33b9a87a87786_lastUpdate", "1384107152512");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_menu_d32f45618f5a02bd965c56155a643855_lastUpdate", "1384107152182");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1383664203166");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_searchAPI_lastUpdate", "1384107155909");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_serviceMap_lastUpdate", "1398352390782");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_toolbarContextMenu_lastUpdate", "1384107271862");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_toolbarSettings_lastUpdate", "1398352391127");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_translation_lastUpdate", "1398352391281");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_userApps7f5031f3-d548-4e84-b3af-0eadff483480_lastUpdate", "1384106925155");
Zeile gelöscht : user_pref("CT3241949.serviceLayer_services_userApps_lastUpdate", "1384106925176");
Zeile gelöscht : user_pref("CT3241949.settingsINI", true);
Zeile gelöscht : user_pref("CT3241949.smartbar.CTID", "CT3241949");
Zeile gelöscht : user_pref("CT3241949.smartbar.Uninstall", "0");
Zeile gelöscht : user_pref("CT3241949.smartbar.homepage", true);
Zeile gelöscht : user_pref("CT3241949.smartbar.isHidden", true);
Zeile gelöscht : user_pref("CT3241949.smartbar.toolbarName", "FileConverter 1.3 ");
Zeile gelöscht : user_pref("CT3241949.startPage", "userChanged");
Zeile gelöscht : user_pref("CT3241949.toolbarBornServerTime", "19-12-2012");
Zeile gelöscht : user_pref("CT3241949.toolbarCurrentServerTime", "24-4-2014");
Zeile gelöscht : user_pref("CT3241949.url_history0001.enc", "aHR0cDovL2ZvcnVtcy5mbHlmb3JoZXJvdjE1LmNvbS9zaG93dGhyZWFkLnBocD90PTI0OTE3Ojo6Y2xpY2toYW5kbGVyOjo6MTM4MDExMDI3MzIwMywsLGh0dHA6Ly9mb3J1bXMuZmx5Zm9yaGVyb3YxNS5j[...]
Zeile gelöscht : user_pref("CT3241949_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1399556081084,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Zeile gelöscht : user_pref("Smartbar.ConduitHomepagesList", "");
Zeile gelöscht : user_pref("Smartbar.ConduitSearchEngineList", "");
Zeile gelöscht : user_pref("Smartbar.ConduitSearchUrlList", "");
Zeile gelöscht : user_pref("Smartbar.keywordURLSelectedCTID", "CT3241949");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.qvo6.com/?utm_source=b&utm_medium=mlv&from=mlv&uid=3219913727_132775_6A9C8794&ts=1372245310");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241949&SearchSource=2&q=");
Zeile gelöscht : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3241949&SearchSource=13&CUI=SB_CUI");
Zeile gelöscht : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3241949&SearchSource=2&q=");
Zeile gelöscht : user_pref("smartbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
Zeile gelöscht : user_pref("smartbar.originalSearchAddressUrl", "");
Zeile gelöscht : user_pref("smartbar.originalSearchEngine", false);
-\\ Google Chrome v36.0.1985.143
[ Datei : C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo
Gelöscht [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg
Gelöscht [Extension] : hphibigbodkkohoglgfkddblldpfohjl
Gelöscht [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Gelöscht [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Gelöscht [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc
Gelöscht [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc
[ Datei : C:\Users\Simon\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : ajckffdklmhnklkigjoohdgjmkeehcah
*************************
AdwCleaner[R0].txt - [21220 octets] - [28/08/2014 19:02:05]
AdwCleaner[S0].txt - [20924 octets] - [28/08/2014 19:42:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [20985 octets] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Franky on 28.08.2014 at 19:49:24,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Franky\AppData\Roaming\mozilla\firefox\profiles\pmki85vq.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.08.2014 at 19:56:34,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ die neue FRST.txt
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2014 03
Ran by Franky (administrator) on FRANKY-PC on 28-08-2014 20:13:25
Running from C:\Users\Franky\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360rps.exe
(Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apache Software Foundation) C:\xampp\apache\bin\httpd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Windows\SysWOW64\ASGT.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apache Software Foundation) C:\xampp\apache\bin\httpd.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
() C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
(FileZilla Project) C:\xampp\FileZillaFTP\FileZillaServer.exe
() C:\xampp\mysql\bin\mysqld.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Tobias Süllhöfer Software) C:\Windows\System32\wtmcore.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUS) C:\Program Files (x86)\ASUS\GPU Tweak\Monitor.exe
(Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360sd.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe
(Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\360rp.exe
() C:\Program Files (x86)\puush\puush.exe
() C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe
(Dropbox, Inc.) C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Qihu 360 Software Co., Ltd.) C:\Program Files\360\360 Internet Security\safemon\360Tray.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor)
HKLM\...\Run: [Creative SB Monitoring Utility] => RunDll32 sbavmon.dll,SBAVMonitor
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Creative SB Monitoring Utility Launcher] => RunDll32 SBAVMonL.dll,SBAVMonitorLauncher
HKLM\...\Run: [360sd] => C:\Program Files\360\360 Internet Security\360sdrun.exe [287560 2014-04-16] (Qihu 360 Software Co., Ltd.)
HKLM-x32\...\Run: [Sound Blaster Recon3D SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3D\Sound Blaster Recon3D Control Panel v2\SBRecon.exe [1103872 2013-09-04] (Creative Technology Ltd)
HKLM\...\Winlogon: [Shell] explorer.exe,wtmcore.exe
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [ISUSPM Startup] => c:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2005-02-17] (InstallShield Software Corporation)
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7283072 2013-04-26] (Binary Fortress Software)
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2013-08-14] ()
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [Amazon Music] => C:\Users\Franky\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] ()
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\system32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DisableClock] 0
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoNetworkConnections] 0
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-2521981952-1457118651-2954859535-1000\...\Policies\Explorer: [NoCommonGroups] 0
Startup: C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Franky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0FB66E927017CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {8B7A2BC3-75E1-4f5d-AA53-26176AE0EFEF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV
SearchScopes: HKCU - {DD1A1D91-E60E-46d0-A1D0-A2823A9C2B12} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms}
SearchScopes: HKCU - {EE29A4DD-95C6-456c-A00A-C52454462FEF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH
BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files\360\360 Internet Security\safemon\safemon64.dll (Qihu 360 Software Co., Ltd.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default
FF Homepage: about:home
FF NetworkProxy: "ftp", "proxyus1.stealthy.co"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "http", "proxyus1.stealthy.co"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "proxyus1.stealthy.co"
FF NetworkProxy: "socks_port", 3128
FF NetworkProxy: "ssl", "proxyus1.stealthy.co"
FF NetworkProxy: "ssl_port", 3128
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Amazon-Icon - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\amazon-icon@giga.de [2014-07-05]
FF Extension: SearchNewTab - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\uuy0qpwgmv@t-oeua.org [2013-09-11]
FF Extension: ReloadEvery - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2013-04-16]
FF Extension: Adblock Plus - C:\Users\Franky\AppData\Roaming\Mozilla\Firefox\Profiles\pmki85vq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-07-14]
Chrome:
=======
CHR HomePage:
CHR RestoreOnStartup: ""
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Unity Player) - C:\Users\Franky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (podcast.de) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\bofligbealbmofkgodhlglkefkpegjnb [2013-09-11]
CHR Extension: (Adblock Plus) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-09-11]
CHR Extension: (Adblock for Youtube™) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-09-11]
CHR Extension: (9GAG Mini) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmkmihphgjhmeabggdcokmkjhbnmdml [2013-09-11]
CHR Extension: (WeatherBug) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco [2013-09-11]
CHR Extension: (Erweiterung \) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2013-09-11]
CHR Extension: (Chrome In-App Payments service) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-07]
CHR Extension: (360 WebShield Plug-in) - C:\Users\Franky\AppData\Local\Google\Chrome\User Data\Default\Extensions\pppagaglfkmlpgobnlenhknilehpmcbo [2014-08-22]
CHR HKLM-x32\...\Chrome\Extension: [pppagaglfkmlpgobnlenhknilehpmcbo] - C:\Program Files\360\360 Internet Security\safemon\360webshield.crx [2014-07-18]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
ATTENTION: => Could not perform signature verification. Cryptographic Service is not running.
R2 360rp; C:\Program Files\360\360 Internet Security\360rps.exe [310352 2014-04-16] (Qihu 360 Software Co., Ltd.)
R2 Apache2.4; C:\xampp\apache\bin\httpd.exe [22016 2012-08-18] (Apache Software Foundation)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] ()
S3 DAUpdaterSvc; G:\SteamLibrary\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [25832 2013-12-10] (BioWare)
R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [68136 2009-06-17] ()
R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1498000 2013-04-26] (Binary Fortress Software)
R2 FileZillaServer; C:\xampp\filezillaftp\filezillaserver.exe [632320 2012-05-11] (FileZilla Project)
S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
R2 mysql; C:\xampp\mysql\bin\mysqld.exe [8186368 2012-07-20] ()
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3975544 2012-05-09] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-30] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.)
S3 scan; C:\Program Files\360\360 Internet Security\scan.dll [423144 2013-02-20] (S.C. BitDefender S.R.L)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH)
R2 ZhuDongFangYu; C:\Program Files\360\360 Internet Security\deepscan\QHActiveDefense.exe [236360 2014-04-23] (Qihu 360 Software Co., Ltd.)
S4 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [97872 2014-04-21] (Qihu 360 Software Co., Ltd.)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [67664 2014-04-23] (Qihu 360 Software Co., Ltd.)
R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [305744 2014-04-29] (Qihu 360 Software Co., Ltd.)
S3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [41552 2014-04-29] (Qihu 360 Software Co., Ltd.)
R1 360fsflt; C:\Windows\System32\DRIVERS\360FsFlt.sys [304208 2014-05-07] (Qihu 360 Software Co., Ltd.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] ()
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310984 2013-02-02] ()
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [116480 2013-09-25] (AVM Berlin)
R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [180816 2014-04-18] (Qihu 360 Software Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-31] (DT Soft Ltd)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-02-24] ()
R3 GWHid; C:\Windows\System32\DRIVERS\GWHid.sys [22648 2010-06-13] (Microsoft Corporation)
S3 HH10Help.sys; C:\Windows\system32\drivers\HH10Help.sys [24088 2009-07-09] (H+H Software GmbH)
R3 IOMap; C:\Windows\system32\drivers\IOMap64.sys [24824 2013-02-19] (ASUSTeK Computer Inc.)
R3 ksaud; C:\Windows\System32\drivers\ksaud.sys [2033024 2013-08-05] (Creative Technology Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2013-02-02] ()
S1 mbmiodrvr; C:\Windows\syswow64\mbmiodrvr.sys [4608 2004-04-10] (cansoft@livewiredev.com)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation)
S3 PVUSB; C:\Windows\System32\DRIVERS\CESG64.sys [63808 2007-02-19] (CASIO COMPUTER CO.,LTD.)
S3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S1 vdrv1000; C:\Windows\System32\DRIVERS\vdrv1000.sys [223256 2011-04-19] (H+H Software GmbH)
R3 VL807; C:\Windows\System32\DRIVERS\VL807.sys [36728 2010-06-13] ()
R3 VL807; C:\Windows\SysWOW64\DRIVERS\VL807.sys [28920 2010-06-13] ()
R1 vmm; C:\Windows\system32\Treiber\vmm.sys [294232 2012-12-31] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 20:13 - 2014-08-28 20:13 - 00028011 _____ () C:\Users\Franky\Desktop\FRST.txt
2014-08-28 19:56 - 2014-08-28 19:56 - 00000758 _____ () C:\Users\Franky\Desktop\JRT.txt
2014-08-28 19:47 - 2014-08-28 19:47 - 00021074 _____ () C:\Users\Franky\Desktop\AdwCleaner[S0].txt
2014-08-28 19:01 - 2014-08-28 19:42 - 00000000 ____D () C:\AdwCleaner
2014-08-28 19:00 - 2014-08-28 19:00 - 01016261 _____ (Thisisu) C:\Users\Franky\Desktop\JRT(1).exe
2014-08-28 18:59 - 2014-08-28 19:00 - 01364531 _____ () C:\Users\Franky\Desktop\adwcleaner_3.308.exe
2014-08-28 18:13 - 2014-08-28 18:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-28 18:13 - 2014-08-28 18:13 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-28 18:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-28 18:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-28 18:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-28 18:11 - 2014-08-28 18:12 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Franky\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-28 18:09 - 2013-02-19 18:02 - 00024824 _____ (ASUSTeK Computer Inc.) C:\Windows\system32\Drivers\IOMap64.sys
2014-08-27 20:26 - 2014-08-27 20:26 - 00125611 _____ () C:\ComboFix.txt
2014-08-27 20:01 - 2014-08-27 20:27 - 00000000 ____D () C:\ComboFix
2014-08-27 20:01 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-27 20:01 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-27 20:01 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-27 20:01 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-27 20:01 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-27 20:01 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-27 20:01 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-27 20:01 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-27 19:47 - 2014-08-27 20:27 - 00000000 ____D () C:\Qoobox
2014-08-27 19:46 - 2014-08-27 20:20 - 00000000 ____D () C:\Windows\erdnt
2014-08-25 19:25 - 2014-08-25 19:26 - 00504236 _____ () C:\Users\Franky\Downloads\sh3-blackfranky-0b8881bb8de4a8b.rar
2014-08-25 19:15 - 2014-08-28 20:13 - 00000000 ____D () C:\FRST
2014-08-25 19:14 - 2014-08-25 19:14 - 02103296 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe
2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-24 00:02 - 2014-08-24 18:00 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger
2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3
2014-08-23 17:07 - 2014-08-23 21:33 - 00000000 ____D () C:\ProgramData\Firefly Studios
2014-08-23 17:05 - 2014-08-23 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
2014-08-23 17:05 - 2014-08-23 17:07 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends
2014-08-23 17:04 - 2014-08-23 17:21 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade
2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar
2014-08-16 00:04 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-16 00:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-16 00:04 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-16 00:04 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-16 00:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-16 00:04 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-16 00:03 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-16 00:03 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 22:11 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 22:11 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 22:11 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 22:11 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 22:11 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 22:11 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 22:11 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 22:11 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 22:11 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 22:11 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 22:11 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 22:11 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 22:11 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 22:11 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 22:11 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 22:11 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 22:11 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 22:11 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 22:11 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 22:11 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 22:11 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 22:11 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 22:11 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 22:11 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 22:11 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 22:11 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 22:11 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 22:11 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 22:11 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 22:11 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 22:11 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 22:11 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 22:11 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 22:11 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 22:11 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 22:11 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 22:11 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 22:11 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 22:11 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 22:11 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 22:11 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 22:11 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 22:11 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 22:11 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 22:11 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 22:11 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 22:11 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 22:11 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 22:11 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 22:11 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 22:11 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 22:11 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 22:11 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 22:11 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 22:11 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 22:11 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 22:11 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-13 22:11 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 22:11 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-13 22:11 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 22:11 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 22:11 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 22:11 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 22:11 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 22:11 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 22:11 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 22:11 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 22:11 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-13 22:11 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 22:11 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 22:11 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 22:11 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 22:11 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 22:11 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 22:11 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 22:11 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 22:11 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 22:09 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 22:09 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 22:09 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 22:09 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp
2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp
2014-08-13 18:00 - 2014-08-06 07:10 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi
2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip
2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk
2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk
2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet
2014-08-07 19:59 - 2014-08-07 20:06 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe
2014-08-05 22:41 - 2014-08-05 22:42 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 00:36 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-03 00:36 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-03 00:36 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-03 00:36 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-03 00:35 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-03 00:35 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-03 00:35 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-03 00:35 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-03 00:35 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-03 00:35 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-03 00:35 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-03 00:35 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-03 00:35 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-03 00:35 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment
2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment
2014-07-31 22:00 - 2014-08-01 19:36 - 00000000 ____D () C:\Users\Franky\Documents\Shiner
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-28 20:13 - 2014-08-28 20:13 - 00028011 _____ () C:\Users\Franky\Desktop\FRST.txt
2014-08-28 20:13 - 2014-08-25 19:15 - 00000000 ____D () C:\FRST
2014-08-28 20:08 - 2012-08-31 17:45 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-28 19:56 - 2014-08-28 19:56 - 00000758 _____ () C:\Users\Franky\Desktop\JRT.txt
2014-08-28 19:53 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-28 19:53 - 2009-07-14 06:45 - 00031072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-28 19:47 - 2014-08-28 19:47 - 00021074 _____ () C:\Users\Franky\Desktop\AdwCleaner[S0].txt
2014-08-28 19:47 - 2013-05-20 14:36 - 00000000 ___RD () C:\Users\Franky\Dropbox
2014-08-28 19:47 - 2013-05-20 14:34 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Dropbox
2014-08-28 19:45 - 2012-08-31 17:45 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-28 19:44 - 2014-06-09 09:34 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-28 19:44 - 2012-06-06 23:06 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2014-08-28 19:44 - 2010-11-21 05:47 - 00600706 _____ () C:\Windows\PFRO.log
2014-08-28 19:44 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-28 19:44 - 2009-07-14 06:51 - 00446170 _____ () C:\Windows\setupact.log
2014-08-28 19:43 - 2012-06-07 04:29 - 01144878 _____ () C:\Windows\WindowsUpdate.log
2014-08-28 19:42 - 2014-08-28 19:01 - 00000000 ____D () C:\AdwCleaner
2014-08-28 19:00 - 2014-08-28 19:00 - 01016261 _____ (Thisisu) C:\Users\Franky\Desktop\JRT(1).exe
2014-08-28 19:00 - 2014-08-28 18:59 - 01364531 _____ () C:\Users\Franky\Desktop\adwcleaner_3.308.exe
2014-08-28 19:00 - 2014-07-18 18:55 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\360safe
2014-08-28 18:58 - 2014-04-30 00:33 - 00000000 ____D () C:\Users\Franky\Desktop\SaveDon'tStarve
2014-08-28 18:57 - 2013-02-24 19:30 - 00000000 ____D () C:\Users\Franky\AppData\Local\TSVNCache
2014-08-28 18:55 - 2009-07-14 06:45 - 00380848 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 18:13 - 2014-08-28 18:13 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-28 18:13 - 2014-08-28 18:13 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-28 18:13 - 2014-08-28 18:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-28 18:12 - 2014-08-28 18:11 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Franky\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-27 21:26 - 2013-02-24 14:03 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-27 20:27 - 2014-08-27 20:01 - 00000000 ____D () C:\ComboFix
2014-08-27 20:27 - 2014-08-27 19:47 - 00000000 ____D () C:\Qoobox
2014-08-27 20:26 - 2014-08-27 20:26 - 00125611 _____ () C:\ComboFix.txt
2014-08-27 20:20 - 2014-08-27 19:46 - 00000000 ____D () C:\Windows\erdnt
2014-08-27 20:19 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-27 19:44 - 2014-06-30 22:17 - 00000000 ____D () C:\Users\Franky\Downloads\Verschiedene Dateien
2014-08-26 20:16 - 2012-06-06 23:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-25 19:26 - 2014-08-25 19:25 - 00504236 _____ () C:\Users\Franky\Downloads\sh3-blackfranky-0b8881bb8de4a8b.rar
2014-08-25 19:14 - 2014-08-25 19:14 - 02103296 _____ (Farbar) C:\Users\Franky\Desktop\FRST64.exe
2014-08-24 18:18 - 2014-08-24 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-24 18:00 - 2014-08-24 00:02 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\GameRanger
2014-08-24 16:49 - 2014-05-27 19:52 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Spotify
2014-08-24 11:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-24 01:50 - 2012-06-17 18:37 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Skype
2014-08-24 00:03 - 2012-06-09 00:29 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-08-23 21:33 - 2014-08-23 21:33 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold 3
2014-08-23 21:33 - 2014-08-23 17:07 - 00000000 ____D () C:\ProgramData\Firefly Studios
2014-08-23 21:32 - 2012-06-06 23:31 - 00260032 _____ () C:\Windows\DirectX.log
2014-08-23 20:29 - 2014-04-13 18:31 - 00000000 ____D () C:\Users\Franky\AppData\Local\JDownloader v2.0
2014-08-23 17:21 - 2014-08-23 17:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
2014-08-23 17:21 - 2014-08-23 17:04 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade
2014-08-23 17:07 - 2014-08-23 17:05 - 00000000 ____D () C:\Users\Franky\Documents\Stronghold Legends
2014-08-22 20:25 - 2012-08-01 02:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft
2014-08-22 20:05 - 2014-08-22 20:05 - 00506127 _____ () C:\Users\Franky\Downloads\ssz-blackfranky-f68e2038509c271.rar
2014-08-16 09:54 - 2014-07-08 18:43 - 00000000 ____D () C:\Windows\rescache
2014-08-16 08:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-16 00:23 - 2012-12-18 19:59 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-16 00:19 - 2013-07-15 10:41 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-16 00:11 - 2012-11-20 19:13 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-16 00:03 - 2014-06-15 16:20 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-15 19:20 - 2014-07-18 18:55 - 00000000 _RSHD () C:\360SANDBOX
2014-08-14 18:23 - 2013-05-20 14:35 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-13 18:33 - 2014-02-15 20:50 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\TEdit
2014-08-13 18:18 - 2013-12-14 10:48 - 00248832 ___SH () C:\Users\Franky\Documents\Thumbs.db
2014-08-13 18:17 - 2014-08-13 18:17 - 00660437 _____ () C:\Users\Franky\Documents\Sphere117.bmp
2014-08-13 18:15 - 2014-08-13 18:15 - 00635425 _____ () C:\Users\Franky\Documents\116.bmp
2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TEdit
2014-08-13 18:01 - 2014-02-15 20:50 - 00000000 ____D () C:\Program Files (x86)\TEdit
2014-08-13 17:58 - 2014-08-13 17:58 - 01260952 _____ () C:\Users\Franky\Downloads\TEdit3Installer_3.5.14218.23.zip
2014-08-12 19:18 - 2013-12-31 13:25 - 00000000 ____D () C:\Users\Franky\AppData\Local\Game Dev Tycoon - Steam
2014-08-09 14:21 - 2012-08-15 11:11 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\Audacity
2014-08-07 20:10 - 2014-08-07 20:10 - 00000707 _____ () C:\Users\Public\Desktop\PlatformBeta.lnk
2014-08-07 20:10 - 2014-08-07 20:10 - 00000633 _____ () C:\Users\Public\Desktop\ManiaPlanet.lnk
2014-08-07 20:10 - 2014-08-07 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ManiaPlanet
2014-08-07 20:06 - 2014-08-07 19:59 - 120122280 _____ (Nadeo ) C:\Users\Franky\Downloads\Maniaplanet_Setup_PlatformBeta@nadeolabs.exe
2014-08-07 04:06 - 2014-08-13 22:09 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-13 22:09 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-06 07:10 - 2014-08-13 18:00 - 00794624 _____ () C:\Users\Franky\Desktop\TEdit3Installer.msi
2014-08-05 22:42 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096bDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-05 22:41 - 2014-08-05 22:41 - 00000322 _____ () C:\Users\Franky\Downloads\BK_ROEG_000096aDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-04 20:49 - 2014-08-04 20:49 - 00000000 ____D () C:\Users\Franky\AppData\Roaming\com.radialgames.MonsterLovesYou
2014-08-04 16:53 - 2010-11-21 08:50 - 00701118 _____ () C:\Windows\system32\perfh007.dat
2014-08-04 16:53 - 2010-11-21 08:50 - 00150298 _____ () C:\Windows\system32\perfc007.dat
2014-08-04 16:53 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-04 16:47 - 2014-06-06 07:41 - 00000000 ____D () C:\Users\Franky\Desktop\Hörbucher
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032nDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032mDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032lDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032kDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000309 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032jDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-04 00:00 - 2014-08-04 00:00 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032iDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032hDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032gDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032fDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032eDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032dDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 23:58 - 2014-08-03 23:58 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032cDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 21:01 - 2014-08-03 21:01 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032bDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 20:59 - 2014-08-03 20:59 - 00000308 _____ () C:\Users\Franky\Downloads\BK_ROEG_000032aDE_mp332_A2C9LTVWCXI9AZ.adh
2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-03 00:29 - 2013-09-24 20:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-02 13:23 - 2013-09-24 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-08-01 19:36 - 2014-07-31 22:00 - 00000000 ____D () C:\Users\Franky\Documents\Shiner
2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\Documents\Robot Entertainment
2014-08-01 18:23 - 2014-08-01 18:23 - 00000000 ____D () C:\Users\Franky\AppData\Local\Robot Entertainment
2014-08-01 01:41 - 2014-08-13 22:11 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-01 01:16 - 2014-08-13 22:11 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
Files to move or delete:
====================
C:\Users\Franky\jagex_cl_runescape_LIVE.dat
C:\Users\Franky\random.dat
C:\Users\Simon\Dragonica_DE(1).exe
C:\Users\Simon\Dragonica_DE_Phoenix_20120720.exe
C:\Users\Simon\jagex_cl_runescape_LIVE.dat
C:\Users\Simon\random.dat
Some content of TEMP:
====================
C:\Users\Franky\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplrt7cy.dll
C:\Users\Franky\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-08-28 18:38
==================== End Of Log ============================ --- --- ---
--- --- --- |