AdwCleaner: Code:
# AdwCleaner v4.107 - Bericht erstellt am 11/01/2015 um 18:31:35
# Aktualisiert 07/01/2015 von Xplode
# Database : 2014-12-21.4 [Local]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzername : PhucTam - PHUCTAM-PC
# Gestartet von : C:\Users\PhucTam\Desktop\AdwCleaner_4.107.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Google Chrome v34.0.1847.116
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5EF15620-18B5-44BA-A22F-D0215438B06A&SearchSource=58&CUI=&UM=5&UP=SP34BD8D72-4674-41E3-BC57-41F1AAFB7661&q={searchTerms}&SSPV=
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5EF15620-18B5-44BA-A22F-D0215438B06A&SearchSource=58&CUI=&UM=5&UP=SP34BD8D72-4674-41E3-BC57-41F1AAFB7661&q={searchTerms}&SSPV=
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=705B00FF7220ECC3&affID=128750&tt=240414_41&tsp=5235
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1410089220&from=irs&uid=ST1000DM003-1CH162_Z1D7K813XXXXZ1D7K813&q={searchTerms}
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1410089220&from=irs&uid=ST1000DM003-1CH162_Z1D7K813XXXXZ1D7K813&q={searchTerms}
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://websearch.searc-hall.info/?l=1&q={searchTerms}&pid=1387&r=2014/11/04&hid=17219196511734920795&lg=EN&cc=DE&unqvl=65
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.delta-homes.com/web/?type=ds&ts=1418365265&from=wpm12123&uid=ST1000DM003-1CH162_Z1D7K813XXXXZ1D7K813&q={searchTerms}
-\\ Comodo Dragon v
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5EF15620-18B5-44BA-A22F-D0215438B06A&SearchSource=58&CUI=&UM=5&UP=SP34BD8D72-4674-41E3-BC57-41F1AAFB7661&q={searchTerms}&SSPV=
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5EF15620-18B5-44BA-A22F-D0215438B06A&SearchSource=58&CUI=&UM=5&UP=SP34BD8D72-4674-41E3-BC57-41F1AAFB7661&q={searchTerms}&SSPV=
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=705B00FF7220ECC3&affID=128750&tt=240414_41&tsp=5235
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1410089220&from=irs&uid=ST1000DM003-1CH162_Z1D7K813XXXXZ1D7K813&q={searchTerms}
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1410089220&from=irs&uid=ST1000DM003-1CH162_Z1D7K813XXXXZ1D7K813&q={searchTerms}
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://websearch.searc-hall.info/?l=1&q={searchTerms}&pid=1387&r=2014/11/04&hid=17219196511734920795&lg=EN&cc=DE&unqvl=65
[C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.delta-homes.com/web/?type=ds&ts=1418365265&from=wpm12123&uid=ST1000DM003-1CH162_Z1D7K813XXXXZ1D7K813&q={searchTerms}
*************************
AdwCleaner[R0].txt - [21920 octets] - [28/04/2014 13:58:05]
AdwCleaner[R1].txt - [19404 octets] - [10/01/2015 16:15:03]
AdwCleaner[R2].txt - [2842 octets] - [11/01/2015 18:29:41]
AdwCleaner[S0].txt - [19211 octets] - [28/04/2014 13:58:31]
AdwCleaner[S1].txt - [18776 octets] - [10/01/2015 16:19:31]
AdwCleaner[S2].txt - [4556 octets] - [11/01/2015 18:31:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [4616 octets] ########## MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 11.01.2015
Suchlauf-Zeit: 18:44:32
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.11.20.06
Rootkit Datenbank: v2014.11.18.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: PhucTam
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 333853
Verstrichene Zeit: 15 Min, 20 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [bd49e559bcc0ec4a367a18a3a35f17e9],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [9e68b6886d0f1521114e48768e749769],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [0402043a413b42f4f311764a7e84619f],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [7e88a39b3448171f322f4868bd477f81],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 4
PUP.Optional.AdPeak.A, C:\temp, In Quarantäne, [11f59ea078042b0b857894c3fb08ea16],
PUP.Optional.FreeWorldApp.A, C:\ProgramData\FreeWorldApp, In Quarantäne, [a75f9ca2ef8d85b1dacb64d0689b21df],
PUP.Optional.FreeWorldApp.A, C:\ProgramData\FreeWorldApp\GS_Booster, In Quarantäne, [a75f9ca2ef8d85b1dacb64d0689b21df],
PUP.Optional.FreeWorldApp.A, C:\ProgramData\FreeWorldApp\Setup, In Quarantäne, [a75f9ca2ef8d85b1dacb64d0689b21df],
Dateien: 8
PUP.Optional.InstalleRex.A, C:\ProgramData\InstallMate\{F6304B96-0189-48C3-AA28-49AB2DD36960}\Custom.dll, In Quarantäne, [ba4cd569c7b5c86ee38cf74cce3242be],
PUP.Optional.SnapDo.A, C:\Windows\Installer\26efdee.msi, In Quarantäne, [29dd1925e99395a14bf7cbd348b97090],
PUP.Optional.SmartBar, C:\Windows\Installer\26efdf3.msi, In Quarantäne, [fe0809358cf03303b2a0ec716997c937],
PUP.Optional.AdPeak.A, C:\temp\lsp2.log, In Quarantäne, [11f59ea078042b0b857894c3fb08ea16],
PUP.Optional.AdPeak.A, C:\temp\InstallFilter32.msi, In Quarantäne, [11f59ea078042b0b857894c3fb08ea16],
PUP.Optional.AdPeak.A, C:\temp\output.txt, In Quarantäne, [11f59ea078042b0b857894c3fb08ea16],
PUP.Optional.AdPeak.A, C:\temp\t.txt, In Quarantäne, [11f59ea078042b0b857894c3fb08ea16],
PUP.Optional.Conduit.A, C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.vaccint.com_0.localstorage, In Quarantäne, [4bbbfd41df9dcb6b691b2d312fd47090],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Ultimate x86
Ran by PhucTam on 11.01.2015 at 19:16:13,73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.01.2015 at 19:20:16,28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-01-2015
Ran by PhucTam (administrator) on PHUCTAM-PC on 11-01-2015 19:21:10
Running from C:\Users\PhucTam\Desktop
Loaded Profile: PhucTam (Available profiles: PhucTam)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Hi-Rez Studios) C:\Program Files\Hi-Rez Studios\HiPatchService.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\System32\PnkBstrA.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-Agent.exe
(Akamai Technologies, Inc.) C:\Users\PhucTam\AppData\Local\Akamai\netsession_win.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(Akamai Technologies, Inc.) C:\Users\PhucTam\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
() C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
(Adobe Systems, Inc.) C:\Users\PhucTam\Desktop\flashplayer_14_sa.exe
(Beepa P/L) C:\Fraps\fraps.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2015-01-11] (AVAST Software)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [2303256 2014-05-19] (Logitech, Inc.)
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [843480 2014-10-07] (BlueStack Systems, Inc.)
HKLM\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [3838800 2014-12-13] (LogMeIn Inc.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\Run: [Akamai NetSession Interface] => C:\Users\PhucTam\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [632328 2014-10-14] (Sandboxie Holdings, LLC)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-04-13] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3598937497-1326978013-658881309-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3598937497-1326978013-658881309-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3598937497-1326978013-658881309-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-3598937497-1326978013-658881309-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = https://de.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll No File
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-3598937497-1326978013-658881309-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\PhucTam\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-10-26]
FF HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\Firefox\Extensions: [{AFBBC1E8-F8FC-FEAA-B717-75C0969774E6}] - C:\Program Files\di7BlockAndSurf\175.xpi
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-21]
CHR Extension: (YouTube) - C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-21]
CHR Extension: (Google-Suche) - C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-21]
CHR Extension: (Google Wallet) - C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-10]
CHR Extension: (Google Mail) - C:\Users\PhucTam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-21]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-10]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-29] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [409304 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [782040 2014-10-07] (BlueStack Systems, Inc.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [915600 2014-12-13] (NVIDIA Corporation)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1895760 2014-12-13] (LogMeIn Inc.)
R2 HiPatchService; C:\Program Files\Hi-Rez Studios\HiPatchService.exe [9216 2015-01-06] (Hi-Rez Studios) [File not signed]
R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [411920 2014-12-02] (LogMeIn, Inc.)
S3 npggsvc; C:\Windows\system32\GameMon.des [3299328 2014-11-26] (INCA Internet Co., Ltd.)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18186896 2014-12-13] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [1903472 2014-12-22] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-12-23] ()
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [134664 2014-10-14] (Sandboxie Holdings, LLC)
S3 TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
R2 Verifies and fixes application compatibility issues; C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe [87208 2015-01-08] ()
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 ValueApps; C:\Users\PhucTam\AppData\Local\ValueApps\ValueApps.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-04-29] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-04-29] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-04-29] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-04-29] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [777488 2015-01-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [411680 2015-01-11] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [68312 2015-01-11] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180632 2014-04-29] ()
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [112344 2014-10-07] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-02] (Disc Soft Ltd)
R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [264704 2006-04-06] (AVM GmbH)
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 LEqdUsb; C:\Windows\System32\Drivers\LEqdUsb.Sys [42264 2014-03-19] (Logitech, Inc.)
R3 LHidEqd; C:\Windows\System32\Drivers\LHidEqd.Sys [10136 2014-03-19] (Logitech, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [32912 2014-11-22] (NVIDIA Corporation)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [22120 2014-06-13] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [45544 2014-06-13] (Saitek)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [161288 2014-10-14] (Sandboxie Holdings, LLC)
S3 scramby; C:\Windows\System32\drivers\scramby.sys [25896 2007-02-13] (RapidSolution Software AG)
S3 scramby_out; C:\Windows\System32\drivers\scramby_out.sys [23840 2007-08-08] (RapidSolution Software AG)
R3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2014-02-07] (Screaming Bee LLC)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [27136 2009-09-16] (Tunngle.net)
S3 _hid_0738_1710; C:\Windows\System32\DRIVERS\_hid_0738_1710.sys [144576 2014-06-13] (Saitek)
S3 _usb_0738_1710; C:\Windows\System32\DRIVERS\_usb_0738_1710.sys [40640 2014-06-13] (Saitek)
S3 catchme; \??\C:\Users\PhucTam\AppData\Local\Temp\catchme.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 XDva409; \??\C:\Windows\system32\XDva409.sys [X]
S3 XDva410; \??\C:\Windows\system32\XDva410.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-11 19:20 - 2015-01-11 19:20 - 00000693 _____ () C:\Users\PhucTam\Desktop\JRT.txt
2015-01-11 19:16 - 2015-01-11 19:16 - 00000000 ____D () C:\Windows\ERUNT
2015-01-11 19:14 - 2015-01-11 19:15 - 01707939 _____ (Thisisu) C:\Users\PhucTam\Downloads\JRT.exe
2015-01-11 19:06 - 2015-01-11 19:06 - 00003280 _____ () C:\Users\PhucTam\Desktop\mbam.txt
2015-01-11 18:42 - 2015-01-11 19:05 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-11 18:42 - 2015-01-11 18:42 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-11 18:42 - 2015-01-11 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-11 18:42 - 2015-01-11 18:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-11 18:42 - 2015-01-11 18:42 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-01-11 18:42 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-11 18:42 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-11 18:42 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-11 18:38 - 2015-01-11 18:40 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\PhucTam\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-11 00:39 - 2015-01-11 08:54 - 00000000 ____D () C:\Users\PhucTam\Desktop\bugfile
2015-01-11 00:22 - 2015-01-11 00:23 - 02052608 _____ (Entwell) C:\Users\PhucTam\Desktop\NostaleX.dat
2015-01-11 00:22 - 2015-01-11 00:23 - 01993728 _____ (Entwell) C:\Users\PhucTam\Desktop\Nostale.dat
2015-01-11 00:22 - 2015-01-11 00:23 - 00000010 _____ () C:\Users\PhucTam\Desktop\Update.dat
2015-01-11 00:22 - 2015-01-11 00:23 - 00000000 ____D () C:\Users\PhucTam\Desktop\NostaleData
2015-01-11 00:22 - 2015-01-11 00:22 - 01256960 _____ (ETW) C:\Users\PhucTam\Desktop\Nostale.exe.bak
2015-01-11 00:17 - 2011-06-06 18:35 - 01248768 _____ (ETW) C:\Users\PhucTam\Desktop\Nostale.exe
2015-01-11 00:08 - 2015-01-11 00:08 - 00001025 _____ () C:\Users\Public\Desktop\Gameforge Live.lnk
2015-01-11 00:08 - 2015-01-11 00:08 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\Gameforge4d
2015-01-11 00:00 - 2015-01-11 00:06 - 20227296 _____ (Gameforge ) C:\Users\PhucTam\Downloads\NosTale_GameforgeLiveSetup (2).exe
2015-01-10 17:16 - 2015-01-10 17:16 - 00041280 _____ () C:\ComboFix.txt
2015-01-10 16:58 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-01-10 16:58 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-01-10 16:58 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-01-10 16:58 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-01-10 16:58 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-01-10 16:58 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-01-10 16:58 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-01-10 16:58 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-01-10 16:56 - 2015-01-10 17:16 - 00000000 ____D () C:\Qoobox
2015-01-10 16:55 - 2015-01-10 17:15 - 00000000 ____D () C:\Windows\erdnt
2015-01-10 16:54 - 2015-01-10 16:55 - 05609736 ____R (Swearware) C:\Users\PhucTam\Desktop\ComboFix.exe
2015-01-10 16:29 - 2015-01-10 16:30 - 00031238 _____ () C:\Users\PhucTam\Desktop\Addition.txt
2015-01-10 16:27 - 2015-01-11 19:22 - 00018518 _____ () C:\Users\PhucTam\Desktop\FRST.txt
2015-01-10 16:27 - 2015-01-11 19:21 - 00000000 ____D () C:\FRST
2015-01-10 16:27 - 2015-01-10 16:27 - 01115648 _____ (Farbar) C:\Users\PhucTam\Desktop\FRST.exe
2015-01-10 16:13 - 2015-01-10 16:14 - 02191360 _____ () C:\Users\PhucTam\Desktop\AdwCleaner_4.107.exe
2015-01-10 12:14 - 2015-01-11 19:02 - 00004450 _____ () C:\Windows\PFRO.log
2015-01-09 23:16 - 2015-01-09 23:16 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2015-01-09 23:16 - 2015-01-09 23:16 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-01-09 23:16 - 2015-01-09 23:16 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2015-01-09 23:16 - 2015-01-09 23:16 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
2015-01-09 23:14 - 2015-01-10 11:57 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Compatibility Verifier
2015-01-09 23:14 - 2015-01-10 11:57 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Compatibility Verifier
2015-01-09 21:30 - 2015-01-11 19:07 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier
2015-01-09 06:51 - 2015-01-09 06:52 - 07563297 _____ () C:\Users\PhucTam\Downloads\DRB 32tel Finale __ Smoothie vs. MC Leon.mp4
2015-01-07 01:48 - 2015-01-07 01:48 - 00000003 _____ () C:\Windows\system32\HRUPPROG.TXT
2015-01-07 01:48 - 2015-01-07 01:48 - 00000003 _____ () C:\Windows\system32\HRUPPROG.EXIT
2015-01-05 16:53 - 2015-01-05 16:53 - 21574131 _____ () C:\Users\PhucTam\Downloads\Das Horn Music Video Featuring Hans Gretel.mp4
2015-01-05 15:59 - 2015-01-10 17:27 - 00002506 _____ () C:\Windows\Sandboxie.ini
2015-01-05 15:59 - 2015-01-10 03:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
2015-01-05 15:59 - 2015-01-05 15:59 - 00001067 _____ () C:\Users\PhucTam\Desktop\Sandboxed Web Browser.lnk
2015-01-05 15:58 - 2015-01-05 15:59 - 02734600 _____ (Sandboxie Holdings, LLC) C:\Users\PhucTam\Downloads\SandboxieInstall.exe
2015-01-03 18:33 - 2015-01-03 19:44 - 00007710 _____ () C:\Users\PhucTam\Desktop\protokoll nostale account.txt
2015-01-02 03:02 - 2015-01-02 03:07 - 64842875 _____ () C:\Users\PhucTam\Desktop\MCMBB vs Mairo Runde.mp4
2014-12-30 00:53 - 2015-01-02 03:54 - 00002371 _____ () C:\Users\PhucTam\Desktop\VS MAIRO.txt
2014-12-29 19:41 - 2014-12-29 19:41 - 00001888 _____ () C:\Users\PhucTam\Desktop\NosTale.lnk
2014-12-29 19:41 - 2014-12-29 19:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nostale(DE)
2014-12-29 17:57 - 2014-12-29 17:58 - 20227296 _____ (Gameforge ) C:\Users\PhucTam\Downloads\NosTale_GameforgeLiveSetup (1).exe
2014-12-29 14:05 - 2014-12-29 17:01 - 00000509 _____ () C:\Users\PhucTam\Desktop\VS DEVASTATIONMUSIC.txt
2014-12-29 13:45 - 2014-12-29 13:45 - 20227296 _____ (Gameforge ) C:\Users\PhucTam\Downloads\NosTale_GameforgeLiveSetup.exe
2014-12-29 03:12 - 2014-12-29 03:12 - 00001896 _____ () C:\Users\Public\Desktop\AION Free-to-Play.lnk
2014-12-29 03:12 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2014-12-28 23:58 - 2014-12-28 23:59 - 36719898 _____ () C:\Users\PhucTam\Downloads\Das Beer Boot Music Video Featuring Hans Gretel.mp4
2014-12-28 21:57 - 2014-12-28 21:57 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\SKIDROW
2014-12-28 21:55 - 2014-12-28 21:57 - 00000000 ____D () C:\Users\PhucTam\Desktop\TBOI
2014-12-28 20:09 - 2014-12-28 20:09 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\Awesomium
2014-12-28 19:53 - 2015-01-10 03:23 - 00000000 ____D () C:\Program Files\Hi-Rez Studios
2014-12-28 19:53 - 2014-12-28 19:53 - 00001979 _____ () C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
2014-12-28 19:53 - 2014-12-28 19:53 - 00001970 _____ () C:\Users\Public\Desktop\Smite.lnk
2014-12-28 19:53 - 2014-12-28 19:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
2014-12-28 19:53 - 2014-12-28 19:53 - 00000000 ____D () C:\ProgramData\Hi-Rez Studios
2014-12-28 19:50 - 2014-12-28 19:52 - 46655528 _____ (Hi-Rez Studios) C:\Users\PhucTam\Downloads\InstallSmite.exe
2014-12-26 22:31 - 2014-12-26 22:33 - 41035014 _____ () C:\Users\PhucTam\Desktop\famenpe.mp4
2014-12-26 18:14 - 2014-12-26 18:31 - 419038520 _____ () C:\Users\PhucTam\Downloads\JBB 2014 [KING FINALE 1_2] SpongeBOZZ vs. Gio (prod. by Digital Drama).mp4
2014-12-26 17:41 - 2014-12-26 18:05 - 227382692 _____ () C:\Users\PhucTam\Desktop\MC STEIN MEDLEY.mp4
2014-12-26 17:30 - 2014-12-26 17:31 - 34213196 _____ () C:\Users\PhucTam\Desktop\DARB 2014 [Halbfinale] Mc lp vs Kulster.mp4
2014-12-26 17:30 - 2014-12-26 17:30 - 03283634 _____ () C:\Users\PhucTam\Desktop\DARB 2014 [Qualifikation 8] MC LP Fan der Boss.mp4
2014-12-26 17:29 - 2014-12-26 17:29 - 03912066 _____ () C:\Users\PhucTam\Desktop\#26 Qualifikation von Smooth.mp4
2014-12-26 17:29 - 2014-12-26 17:29 - 01160576 _____ () C:\Users\PhucTam\Desktop\BLACK AND WHITE - - QUALIFIKATION #37 - BARSBATTLECONTEST.mp4
2014-12-26 03:01 - 2014-12-26 03:01 - 00000000 ____D () C:\Program Files\Microsoft ASP.NET
2014-12-25 16:13 - 2014-12-25 16:13 - 00003085 _____ () C:\Users\PhucTam\Downloads\realm-of-the-mad-god-cursor-.zip
2014-12-25 13:27 - 2015-01-11 19:02 - 00008223 _____ () C:\Windows\setupact.log
2014-12-25 13:27 - 2014-12-25 13:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-25 00:23 - 2014-12-25 00:23 - 00001217 _____ () C:\Users\PhucTam\Desktop\Battle.net.lnk
2014-12-24 22:37 - 2014-11-22 11:46 - 00032912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2014-12-24 13:25 - 2014-12-24 13:25 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\Apple Computer
2014-12-24 07:31 - 2014-12-24 07:31 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-12-24 07:31 - 2014-12-24 07:31 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\Apple
2014-12-24 07:31 - 2014-12-24 07:31 - 00000000 ____D () C:\ProgramData\Apple
2014-12-24 07:31 - 2014-12-24 07:31 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-12-24 07:31 - 2014-12-24 07:31 - 00000000 ____D () C:\Program Files\Apple Software Update
2014-12-23 20:38 - 2014-12-23 20:38 - 380932972 _____ () C:\Users\PhucTam\Desktop\DOD Content Addon (Oct 2014).zip
2014-12-23 20:28 - 2014-12-23 20:28 - 132745923 _____ () C:\Users\PhucTam\Desktop\DOD Maps Addon (Oct 2014).zip
2014-12-23 20:27 - 2014-12-23 20:27 - 120899692 _____ () C:\Users\PhucTam\Desktop\CSS Maps Addon (Oct 2014).zip
2014-12-23 19:51 - 2014-12-23 19:52 - 721122808 _____ () C:\Users\PhucTam\Desktop\CSS Content Addon (Oct 2014).zip
2014-12-23 16:14 - 2014-12-23 16:14 - 00000000 __RHD () C:\Users\PhucTam\AppData\Roaming\SecuROM
2014-12-23 16:14 - 2014-12-23 16:14 - 00000000 ____D () C:\Users\Public\Documents\EA Games
2014-12-23 16:14 - 2014-12-23 16:14 - 00000000 ____D () C:\Users\PhucTam\Documents\EA Games
2014-12-23 15:58 - 2014-12-23 16:03 - 00348928 _____ () C:\Windows\system32\PnkBstrB.xtr
2014-12-23 15:58 - 2014-12-23 15:58 - 00000000 ____D () C:\Users\PhucTam\Documents\Battlefield 3
2014-12-23 15:58 - 2014-12-23 15:58 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\PunkBuster
2014-12-23 15:58 - 2014-12-23 15:58 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\ESN
2014-12-23 15:57 - 2014-12-23 15:57 - 00000000 ____D () C:\Program Files\Battlelog Web Plugins
2014-12-23 15:56 - 2014-12-23 15:56 - 00000000 ____D () C:\ProgramData\EA Core
2014-12-23 12:35 - 2014-12-23 12:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimCity 2000 Special Edition
2014-12-23 12:33 - 2014-12-23 12:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 2 Ultimate Collection
2014-12-23 10:22 - 2014-12-23 10:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 3
2014-12-23 10:21 - 2014-12-23 16:03 - 00348928 _____ () C:\Windows\system32\PnkBstrB.exe
2014-12-23 10:21 - 2014-12-23 16:03 - 00139944 _____ () C:\Windows\system32\Drivers\PnkBstrK.sys
2014-12-23 10:21 - 2014-12-23 16:03 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe
2014-12-23 10:21 - 2014-12-23 15:58 - 00280904 _____ () C:\Windows\system32\PnkBstrB.ex0
2014-12-23 10:21 - 2014-12-23 10:21 - 00138056 _____ () C:\Users\PhucTam\AppData\Roaming\PnkBstrK.sys
2014-12-23 10:21 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-12-23 10:21 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2014-12-23 10:21 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-12-23 10:21 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2014-12-23 10:21 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2014-12-23 10:21 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2014-12-23 10:21 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2014-12-23 10:21 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2014-12-23 10:21 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2014-12-23 10:21 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2014-12-23 10:21 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2014-12-23 10:21 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2014-12-23 10:21 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-12-23 10:21 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-12-23 10:21 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-12-23 10:21 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2014-12-23 10:21 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2014-12-23 10:21 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2014-12-23 10:21 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2014-12-23 10:21 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2014-12-23 10:21 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2014-12-23 10:21 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2014-12-23 10:21 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2014-12-23 10:21 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2014-12-23 10:21 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2014-12-23 10:21 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2014-12-23 10:21 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2014-12-23 10:21 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2014-12-23 10:21 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2014-12-23 10:21 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2014-12-23 10:21 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2014-12-23 10:21 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2014-12-23 10:21 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2014-12-23 10:21 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2014-12-23 10:21 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2014-12-23 10:21 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2014-12-23 10:21 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2014-12-23 10:21 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2014-12-23 10:21 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2014-12-23 10:21 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2014-12-23 10:21 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2014-12-23 10:21 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2014-12-23 10:21 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2014-12-23 10:21 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2014-12-23 10:21 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2014-12-23 10:21 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2014-12-23 10:21 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2014-12-23 10:21 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2014-12-23 10:21 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2014-12-23 10:21 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2014-12-23 10:21 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2014-12-23 10:21 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2014-12-23 10:21 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2014-12-23 10:21 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2014-12-23 10:21 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2014-12-23 10:21 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2014-12-23 10:21 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2014-12-23 10:21 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2014-12-23 10:21 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2014-12-23 10:21 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2014-12-23 10:21 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2014-12-23 10:21 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2014-12-23 10:21 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2014-12-23 10:21 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2014-12-23 10:21 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2014-12-23 10:21 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-12-23 10:21 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2014-12-23 10:21 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2014-12-23 10:21 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2014-12-23 10:21 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2014-12-23 10:21 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2014-12-23 10:21 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2014-12-23 10:21 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2014-12-23 10:21 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2014-12-23 10:21 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2014-12-23 10:21 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2014-12-23 10:21 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2014-12-23 10:21 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2014-12-23 10:20 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2014-12-23 10:20 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2014-12-23 10:20 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2014-12-23 10:20 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2014-12-21 11:57 - 2014-12-21 11:57 - 00000000 ____D () C:\Users\PhucTam\Downloads\Smart Riot - Huma-Huma_data
2014-12-20 20:06 - 2009-07-13 14:39 - 49625595 _____ () C:\Users\PhucTam\Desktop\BP(D).ups
2014-12-20 20:05 - 2014-12-20 20:07 - 134217728 _____ () C:\Users\PhucTam\Desktop\3783 - Pokemon - Platin Edition (DE).nds
2014-12-18 06:04 - 2014-11-26 15:10 - 03299328 _____ (INCA Internet Co., Ltd.) C:\Windows\system32\GameMon.des
2014-12-18 06:03 - 2014-12-18 06:03 - 00000000 ____D () C:\Program Files\Common Files\INCA Shared
2014-12-18 06:03 - 2004-12-30 13:43 - 00004682 _____ (INCA Internet Co., Ltd.) C:\Windows\system32\npptNT2.sys
2014-12-18 06:03 - 2003-07-15 22:17 - 00005174 _____ () C:\Windows\system32\nppt9x.vxd
2014-12-18 05:37 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-15 14:26 - 2014-12-15 14:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-12-15 14:26 - 2014-12-15 14:26 - 00000000 ____D () C:\Program Files\LogMeIn Hamachi
2014-12-14 01:55 - 2014-12-14 01:56 - 20077203 _____ () C:\Users\PhucTam\Desktop\DARB 2014 [4tel 4_4] MC LP Fan der Boss vs BNB.mp4
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-11 19:14 - 2014-04-09 19:44 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\Skype
2015-01-11 19:10 - 2009-07-14 05:34 - 00020672 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-11 19:10 - 2009-07-14 05:34 - 00020672 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-11 19:06 - 2014-04-09 18:17 - 01558712 _____ () C:\Windows\WindowsUpdate.log
2015-01-11 19:03 - 2014-04-27 16:24 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\LogMeIn Hamachi
2015-01-11 19:02 - 2014-04-09 21:37 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-11 19:02 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-11 18:31 - 2014-04-28 13:58 - 00000000 ____D () C:\AdwCleaner
2015-01-11 18:18 - 2014-05-12 19:44 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\TS3Client
2015-01-11 17:26 - 2014-12-01 23:45 - 00000000 ____D () C:\Users\PhucTam\Downloads\Gameforge Live
2015-01-11 08:53 - 2014-04-29 13:32 - 00777488 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-01-11 08:53 - 2014-04-29 13:32 - 00411680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-01-11 08:53 - 2014-04-29 13:32 - 00068312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2015-01-11 00:08 - 2014-12-01 23:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gameforge Live
2015-01-11 00:08 - 2014-07-15 07:31 - 00000000 ____D () C:\Program Files\GameforgeLive
2015-01-10 17:24 - 2014-04-09 22:54 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\Battle.net
2015-01-10 17:16 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2015-01-10 17:16 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-01-10 17:12 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-01-10 16:24 - 2014-04-22 22:50 - 00001312 _____ () C:\Users\PhucTam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2015-01-10 16:20 - 2014-04-09 19:39 - 00001236 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-10 16:20 - 2014-04-09 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-10 16:20 - 2014-04-09 18:52 - 00001152 _____ () C:\Users\PhucTam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-10 12:11 - 2014-04-29 13:34 - 00002047 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2015-01-10 12:11 - 2014-04-29 13:32 - 00776976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1420962827284
2015-01-10 12:11 - 2014-04-29 13:32 - 00411552 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1420962827284
2015-01-10 03:26 - 2014-04-09 18:52 - 00000000 ____D () C:\Users\PhucTam
2015-01-10 03:23 - 2014-06-22 09:46 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\Akamai
2015-01-10 03:23 - 2014-05-02 01:27 - 00000000 ____D () C:\ProgramData\ZalmanInstaller_5372
2015-01-10 03:23 - 2014-04-29 13:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2015-01-10 03:23 - 2014-04-19 16:55 - 00000000 ____D () C:\Users\PhucTam\Desktop\Cubeworld
2015-01-10 03:23 - 2014-04-09 22:54 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\Battle.net
2015-01-10 03:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-01-10 03:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\registration
2015-01-10 03:23 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\AppCompat
2015-01-10 03:03 - 2009-07-14 09:56 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-01-06 20:51 - 2014-04-10 12:26 - 00000000 ____D () C:\Program Files\Steam
2015-01-06 04:36 - 2014-04-11 11:27 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 15:59 - 2014-12-04 17:01 - 00000000 ____D () C:\Program Files\Sandboxie
2015-01-02 06:12 - 2014-11-06 20:05 - 00000000 ____D () C:\Users\PhucTam\Desktop\Bilder, screens
2015-01-02 03:20 - 2014-04-22 05:24 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\Audacity
2014-12-31 03:28 - 2014-04-09 18:24 - 01618592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-29 00:33 - 2014-04-10 22:02 - 00000000 ____D () C:\Users\PhucTam\Documents\My Games
2014-12-28 19:53 - 2014-04-17 01:29 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-12-26 18:00 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-12-26 16:53 - 2014-04-09 20:08 - 00000000 ____D () C:\Users\PhucTam\AppData\Roaming\.minecraft
2014-12-25 00:44 - 2014-04-10 03:58 - 00000000 ____D () C:\Windows\Minidump
2014-12-25 00:38 - 2014-09-11 23:29 - 00000000 ____D () C:\Users\Public\Documents\Mad Catz
2014-12-25 00:38 - 2014-05-10 11:15 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-12-25 00:25 - 2014-07-12 16:30 - 00000000 ____D () C:\Users\PhucTam\Desktop\Musik ~98%
2014-12-23 15:56 - 2014-05-29 11:09 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-12-23 12:35 - 2009-07-14 05:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-23 12:33 - 2014-05-29 11:17 - 00000000 ____D () C:\Program Files\Origin Games
2014-12-23 10:21 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-12-22 22:34 - 2014-05-29 11:09 - 00000000 ____D () C:\ProgramData\Origin
2014-12-22 22:34 - 2014-05-29 11:09 - 00000000 ____D () C:\Program Files\Origin
2014-12-22 22:33 - 2014-04-09 19:44 - 00000000 ___RD () C:\Program Files\Skype
2014-12-22 22:33 - 2014-04-09 19:44 - 00000000 ____D () C:\ProgramData\Skype
2014-12-22 13:01 - 2014-05-29 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2014-12-20 14:01 - 2014-10-26 01:06 - 00016400 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2014-12-18 06:37 - 2014-06-29 09:57 - 00000000 ____D () C:\download
2014-12-17 23:25 - 2014-04-09 18:52 - 00000000 ____D () C:\Users\PhucTam\AppData\Local\VirtualStore
2014-12-13 01:12 - 2014-09-20 13:42 - 02210040 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap.dll
2014-12-13 01:12 - 2014-09-20 13:42 - 01291464 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge.dll
2014-12-12 04:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-12-12 03:17 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
Files to move or delete:
====================
C:\Users\PhucTam\jagex_cl_runescape_LIVE.dat
C:\Users\PhucTam\random.dat
Some content of TEMP:
====================
C:\Users\PhucTam\AppData\Local\Temp\Quarantine.exe
C:\Users\PhucTam\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-04 19:43
==================== End Of Log ============================ --- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 10-01-2015
Ran by PhucTam at 2015-01-11 19:23:28
Running from C:\Users\PhucTam\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
AION Free-to-Play (HKLM\...\{82E73E8D-E1E7-45A4-A311-6D31492AA913}_is1) (Version: - Gameforge)
Akamai NetSession Interface (HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\Akamai) (Version: - Akamai Technologies, Inc)
ANNO 2070 (HKLM\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
Apple Application Support (HKLM\...\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.0.5 (HKLM\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2018 - Avast Software)
Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment)
Battlefield 3™ (HKLM\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB)
BlueStacks Notification Center (HKLM\...\{152E0B21-19D5-4772-9EF8-8E76074B0C0A}) (Version: 0.9.4.4078 - BlueStack Systems, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.13 - Piriform)
Counter-Strike: Global Offensive (HKLM\...\Steam App 730) (Version: - Valve)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Diablo III (HKLM\...\Diablo III) (Version: - Blizzard Entertainment)
Fotogalerie (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fraps (remove only) (Version: - ) Hidden
Gameforge Live 2.0.5 (HKLM\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.5 - Gameforge)
Garry's Mod (HKLM\...\Steam App 4000) (Version: - Facepunch Studios)
Google Chrome (HKLM\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.)
Google Update Helper (Version: 1.3.23.9 - Google Inc.) Hidden
Hearthstone (HKLM\...\Hearthstone) (Version: - Blizzard Entertainment)
Hi-Rez Studios Authenticate and Update Service (HKLM\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
LAME v3.99.3 (for Windows) (HKLM\...\LAME_is1) (Version: - )
League of Legends (HKLM\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (Version: 3.0.1 - Riot Games ) Hidden
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
LogMeIn Hamachi (HKLM\...\LogMeIn Hamachi) (Version: 2.2.0.291 - LogMeIn, Inc.)
LogMeIn Hamachi (Version: 2.2.0.291 - LogMeIn, Inc.) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MorphVOX Pro (HKLM\...\{4bfc0d50-0417-46a0-ab1e-475fb1a90916}) (Version: 4.4.17.22603 - Screaming Bee)
MorphVOX Pro (Version: 4.4.17.22603 - Screaming Bee) Hidden
Movie Maker (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Nostale(DE) (HKLM\...\NosTale(DE)_is1) (Version: - Gameforge 4D GmbH)
Notepad++ (HKLM\...\Notepad++) (Version: 6.5.5 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 332.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 332.17 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 332.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 332.17 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Grafiktreiber 332.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.17 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.29.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.29.0 - NVIDIA Corporation)
NVIDIA PhysX (HKLM\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Origin (HKLM\...\Origin) (Version: 9.4.7.2799 - Electronic Arts, Inc.)
PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Realm of the Mad God (HKLM\...\Steam App 200210) (Version: - Wild Shadow Studios)
Rogue Legacy (HKLM\...\Steam App 241600) (Version: - Cellar Door Games)
Scribblenauts Unlimited (HKLM\...\Steam App 218680) (Version: - 5th Cell Media)
Serious Sam: The Random Encounter (HKLM\...\Steam App 201480) (Version: - Vlambeer)
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
Shopping Helper Smartbar (HKLM\...\{7DD65DA0-AD4F-4974-AAC6-5834DD7F6841}) (Version: 11.43.63.16271 - ReSoft Ltd.) <==== ATTENTION
Shopping Helper Smartbar Engine (HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\{f18039c1-5302-454f-adb0-fa2f0f2086fd}) (Version: 11.43.63.16271 - ReSoft Ltd.) <==== ATTENTION
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Smite (HKLM\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 1.0.2477.0 - Hi-Rez Studios)
Sonic Generations (HKLM\...\Steam App 71340) (Version: - Devil's Details)
Sony Vegas Pro Pre-Cracked By Exµs 11.0 (HKLM\...\Sony Vegas Pro Pre-Cracked By Exµs) (Version: 11.0 - TheMrExus)
Steam (HKLM\...\Steam) (Version: - Valve Corporation)
System Requirements Lab CYRI (HKLM\...\{F3FCB08B-E752-444D-86A0-0634A4F3B23D}) (Version: 6.0.8.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
Terraria (HKLM\...\Steam App 105600) (Version: - Re-Logic)
The Binding of Isaac (HKLM\...\Steam App 113200) (Version: - Edmund McMillen and Florian Himsl)
The Sims 2: Ultimate Collection (HKLM\...\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts)
Toribash (HKLM\...\Steam App 248570) (Version: - Nabi Studios)
Tunngle beta (HKLM\...\Tunngle beta_is1) (Version: - Tunngle.net GmbH)
Unity Web Player (HKU\S-1-5-21-3598937497-1326978013-658881309-1000\...\UnityWebPlayer) (Version: 4.5.1f3 - Unity Technologies ApS)
Uplay (HKLM\...\Uplay) (Version: 4.3 - Ubisoft)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
WinRAR 5.10 beta 2 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.2 - win.rar GmbH)
XSplit Broadcaster (HKLM\...\{19F00CA3-338D-497C-BA31-0507101F2BBB}) (Version: 1.3.1403.1202 - SplitmediaLabs)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3598937497-1326978013-658881309-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\PhucTam\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
==================== Restore Points =========================
03-01-2015 00:20:26 Windows Update
06-01-2015 10:33:02 Windows Update
09-01-2015 12:51:47 Windows Update
09-01-2015 21:31:01 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
09-01-2015 23:15:13 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
09-01-2015 23:36:05 avast! antivirus system restore point
10-01-2015 02:50:53 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
10-01-2015 03:05:40 avast! antivirus system restore point
10-01-2015 03:06:29 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
10-01-2015 03:07:48 Wiederherstellungsvorgang
10-01-2015 03:15:18 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
10-01-2015 03:18:14 Windows Update
10-01-2015 03:19:21 Wiederherstellungsvorgang
10-01-2015 03:24:30 avast! antivirus system restore point
10-01-2015 03:25:10 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
10-01-2015 11:39:41 avast! antivirus system restore point
10-01-2015 11:57:37 avast! antivirus system restore point
10-01-2015 12:10:30 avast! antivirus system restore point
10-01-2015 15:25:02 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
10-01-2015 17:31:54 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2015-01-10 17:12 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {119D7A20-226E-4037-8ECC-B97D1AF95B36} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-29] (AVAST Software)
Task: {BFA338DE-6156-494B-BC12-3A2580E5D8DA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Loaded Modules (whitelisted) =============
2014-04-09 21:36 - 2013-12-17 22:30 - 00107296 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2015-01-11 18:34 - 2015-01-11 18:34 - 02909696 _____ () C:\Program Files\AVAST Software\Avast\defs\15011101\algo.dll
2014-12-23 10:21 - 2014-12-23 16:03 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe
2015-01-10 03:25 - 2015-01-08 20:58 - 00087208 _____ () C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe
2015-01-09 23:39 - 2014-04-29 13:32 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-01-03 12:03 - 2014-01-03 12:03 - 07816192 _____ () C:\Program Files\SplitmediaLabs\XSplit\avcodec-54.dll
2014-01-03 12:03 - 2014-01-03 12:03 - 00188416 _____ () C:\Program Files\SplitmediaLabs\XSplit\avutil-52.dll
2014-01-03 12:03 - 2014-01-03 12:03 - 01425920 _____ () C:\Program Files\SplitmediaLabs\XSplit\avformat-54.dll
2014-01-03 12:03 - 2014-01-03 12:03 - 00336896 _____ () C:\Program Files\SplitmediaLabs\XSplit\swscale-2.dll
2014-01-03 12:03 - 2014-01-03 12:03 - 00096256 _____ () C:\Program Files\SplitmediaLabs\XSplit\swresample-0.dll
2015-01-10 03:25 - 2015-01-08 21:51 - 51252392 _____ () C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe
2015-01-10 03:25 - 2015-01-07 22:22 - 01360552 _____ () C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\libglesv2.dll
2015-01-10 03:25 - 2015-01-07 22:22 - 00214184 _____ () C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\libegl.dll
2015-01-10 03:25 - 2015-01-07 22:22 - 00985768 _____ () C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll
2015-01-10 03:25 - 2015-01-07 22:22 - 16827048 _____ () C:\Users\PhucTam\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll
2014-04-09 19:39 - 2014-04-02 02:57 - 00065352 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll
2014-04-09 19:39 - 2014-04-02 02:57 - 00674632 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\libglesv2.dll
2014-04-09 19:39 - 2014-04-02 02:57 - 00093000 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\libegl.dll
2014-04-09 19:39 - 2014-04-02 02:57 - 04081480 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\pdf.dll
2014-04-09 19:39 - 2014-04-02 02:58 - 00390472 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll
2014-04-09 19:39 - 2014-04-02 02:57 - 01647432 _____ () C:\Program Files\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-3598937497-1326978013-658881309-500 - Administrator - Disabled)
Gast (S-1-5-21-3598937497-1326978013-658881309-501 - Limited - Disabled)
PhucTam (S-1-5-21-3598937497-1326978013-658881309-1000 - Administrator - Enabled) => C:\Users\PhucTam
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Ethernet-Controller
Description: Ethernet-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: AMD FX(tm)-6300 Six-Core Processor
Percentage of memory in use: 69%
Total physical RAM: 3069.54 MB
Available physical RAM: 942.24 MB
Total Pagefile: 9211.82 MB
Available Pagefile: 6342.27 MB
Total Virtual: 2047.88 MB
Available Virtual: 1914.32 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.41 GB) (Free:713.17 GB) NTFS
Drive e: (DarkSiders.II) (CDROM) (Total:5.36 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6628B7BD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |