I have a small question/problem.
I actually never used any antivirus programm ( why should I? ) and since years never had any problems ( also I formatted my computer in this time alot)
But now i thought, I check myself ,and got Comodo Firewall and Avira Antivirus.
Comodo found a maybe harmfull .dll and avira found also something.
Now i want to know if I am really infected, if there is a method to check? or if I am clean etc, maybe some stuff I have to check to be sure withouth formatting my computer.
I never got hacked or something and I am very carefull ( thats why I dont use a antivir software)
I hope for help,
Sincerly,
Daisy.
Here are the logs.
If needed, i can provide the extras.txtOTL logfile created on: 27.07.2014 18:39:14 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\<myname>\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17207)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,94 Gb Total Physical Memory | 4,85 Gb Available Physical Memory | 61,12% Memory free
15,88 Gb Paging File | 12,12 Gb Available in Paging File | 76,32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 36,81 Gb Free Space | 3,95% Space Free | Partition Type: NTFS
Drive D: | 931,51 Gb Total Space | 147,00 Gb Free Space | 15,78% Space Free | Partition Type: NTFS
Computer Name: <myname>-PC | User Name: <myname> | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.07.27 18:39:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\<myname>\Downloads\OTL.exe
PRC - [2014.07.22 21:02:03 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Windows.old\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014.07.16 04:28:16 | 001,753,280 | ---- | M] (Valve Corporation) -- D:\SteamLibrary\Steam.exe
PRC - [2014.07.08 19:34:26 | 001,869,488 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
PRC - [2014.07.02 13:06:46 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2014.07.02 13:06:42 | 000,750,160 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2014.07.02 13:06:42 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2014.05.30 01:28:21 | 002,350,880 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014.05.30 01:23:57 | 001,631,008 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014.05.21 12:22:08 | 002,135,232 | ---- | M] () -- C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
PRC - [2014.05.12 22:07:49 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2014.05.02 18:00:09 | 000,211,968 | ---- | M] (My Digital Life Forums) -- C:\Windows\KMSServerService\KMS Server Service.exe
PRC - [2014.04.01 08:07:39 | 000,581,000 | ---- | M] (Autodesk Inc.) -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
PRC - [2014.02.27 12:30:46 | 000,070,352 | ---- | M] (Comodo Security Solutions, Inc.) -- C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
PRC - [2014.02.27 10:28:36 | 002,327,248 | ---- | M] (Comodo Security Solutions, Inc.) -- C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
PRC - [2013.10.24 00:39:14 | 001,017,224 | ---- | M] (Flux Software LLC) -- C:\Users\<myname>\AppData\Local\FluxSoftware\Flux\flux.exe
PRC - [2013.09.11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2013.03.08 09:54:00 | 000,017,760 | ---- | M] () -- C:\Program Files (x86)\HDD Health\HDDHealthService.exe
PRC - [2013.01.23 08:12:40 | 000,425,016 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
========== Modules (No Company Name) ==========
MOD - [2014.07.22 21:02:03 | 003,800,688 | ---- | M] () -- C:\Windows.old\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014.07.16 04:28:28 | 002,139,328 | ---- | M] () -- D:\SteamLibrary\video.dll
MOD - [2014.07.16 04:28:18 | 001,116,864 | ---- | M] () -- D:\SteamLibrary\bin\chromehtml.dll
MOD - [2014.07.12 02:53:26 | 001,116,672 | ---- | M] () -- D:\SteamLibrary\libavcodec-55.dll
MOD - [2014.07.12 02:53:26 | 000,438,784 | ---- | M] () -- D:\SteamLibrary\libavutil-53.dll
MOD - [2014.07.12 02:53:26 | 000,399,360 | ---- | M] () -- D:\SteamLibrary\libavformat-55.dll
MOD - [2014.07.12 02:53:26 | 000,331,264 | ---- | M] () -- D:\SteamLibrary\libavresample-1.dll
MOD - [2014.07.08 19:34:26 | 017,029,808 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll
MOD - [2014.06.27 00:40:28 | 000,764,416 | ---- | M] () -- D:\SteamLibrary\SDL2.dll
MOD - [2014.05.02 01:35:22 | 020,628,160 | ---- | M] () -- D:\SteamLibrary\bin\libcef.dll
MOD - [2014.04.29 02:37:22 | 000,519,168 | ---- | M] () -- D:\SteamLibrary\libswscale-2.dll
MOD - [2013.04.04 01:09:40 | 004,300,456 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2013.01.23 08:12:40 | 000,425,016 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
MOD - [2013.01.16 18:01:08 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
MOD - [2013.01.16 18:01:06 | 000,348,160 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
MOD - [2013.01.16 18:01:00 | 000,229,376 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTCore.dll
MOD - [2013.01.16 18:00:58 | 000,143,360 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTUI.dll
MOD - [2013.01.16 18:00:56 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTFC.dll
MOD - [2011.04.30 21:04:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTTSH.dll
========== Services (SafeList) ==========
SRV:64bit: - [2014.06.19 02:24:12 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014.07.22 21:02:03 | 000,119,408 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.07.14 01:10:20 | 000,049,152 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe -- (BEService)
SRV - [2014.07.08 19:34:29 | 000,262,320 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.07.02 13:06:46 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2014.07.02 13:06:42 | 000,430,160 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2014.05.30 01:23:57 | 001,631,008 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014.05.30 01:20:09 | 021,055,432 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV - [2014.05.21 12:22:08 | 002,135,232 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe -- (DragonUpdater)
SRV - [2014.05.12 22:07:49 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014.05.07 23:23:00 | 000,088,648 | ---- | M] (COMPANYVERS_NAME) [Disabled | Stopped] -- C:\PROGRA~2\RADIOR~1\bar\1.bin\4jbarsvc.exe -- (RadioRage_4jService)
SRV - [2014.05.06 00:50:48 | 001,357,104 | ---- | M] (Flexera Software LLC) [On_Demand | Stopped] -- C:\Programme\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe -- (FlexNet Licensing Service 64)
SRV - [2014.05.02 18:00:09 | 000,211,968 | ---- | M] (My Digital Life Forums) [Auto | Running] -- C:\Windows\KMSServerService\KMS Server Service.exe -- (KMSServerService)
SRV - [2014.04.25 11:56:12 | 005,024,576 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014.04.01 08:07:39 | 000,581,000 | ---- | M] (Autodesk Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe -- (AdAppMgrSvc)
SRV - [2014.03.25 20:22:40 | 006,812,400 | ---- | M] (COMODO) [Auto | Running] -- C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe -- (CmdAgent)
SRV - [2014.03.25 20:22:20 | 002,264,280 | ---- | M] (COMODO) [On_Demand | Stopped] -- C:\Programme\COMODO\COMODO Internet Security\cmdvirth.exe -- (cmdvirth)
SRV - [2014.02.27 12:30:46 | 000,070,352 | ---- | M] (Comodo Security Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe -- (CLPSLauncher)
SRV - [2014.02.27 10:28:36 | 002,327,248 | ---- | M] (Comodo Security Solutions, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe -- (GeekBuddyRSP)
SRV - [2013.11.06 00:11:42 | 004,797,064 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2013.10.23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.09.11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013.03.08 09:54:00 | 000,017,760 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\HDD Health\HDDHealthService.exe -- (HDDHealth)
SRV - [2013.03.01 03:48:58 | 000,118,520 | ---- | M] (Riverbed Technology, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2012.09.18 14:20:26 | 000,171,072 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)
SRV - [2012.07.25 18:58:26 | 000,126,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe -- (Te.Service)
SRV - [2012.07.25 18:13:16 | 000,139,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe -- (fussvc)
SRV - [2012.02.11 08:55:04 | 000,129,624 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2011.09.15 06:19:54 | 000,086,016 | ---- | M] () [Disabled | Stopped] -- C:\Programme\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe -- (mi-raysat_3dsmax2015_64)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010.01.09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014.07.20 14:23:30 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:64bit: - [2014.07.15 16:15:22 | 000,142,528 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2014.07.02 13:06:42 | 000,130,584 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2014.07.02 13:06:42 | 000,117,712 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2014.07.02 13:06:42 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2014.06.11 10:57:41 | 000,197,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2014.05.02 17:46:13 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014.04.11 10:39:22 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2014.04.11 10:39:22 | 000,110,336 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2014.03.31 18:42:44 | 000,040,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2014.03.25 20:22:50 | 000,023,168 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd)
DRV:64bit: - [2014.01.15 00:50:02 | 000,042,184 | ---- | M] (Anchorfree Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss6.sys -- (taphss6)
DRV:64bit: - [2013.10.07 07:17:38 | 000,014,888 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hmd.sys -- (HMD)
DRV:64bit: - [2013.08.13 16:02:10 | 000,046,568 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ISCTD64.sys -- (ISCT)
DRV:64bit: - [2013.08.13 16:02:10 | 000,029,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\INETMON.sys -- (INETMON)
DRV:64bit: - [2013.08.07 14:23:46 | 000,644,968 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:64bit: - [2013.08.07 14:23:46 | 000,028,008 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorF.sys -- (iaStorF)
DRV:64bit: - [2013.05.07 09:00:18 | 000,037,976 | ---- | M] (Windows ® Win 7 DDK provider) [File_System | System | Running] -- C:\Windows\SysNative\drivers\CFRMD.sys -- (CFRMD)
DRV:64bit: - [2013.04.04 11:33:50 | 000,051,496 | ---- | M] (Yamaha Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ymidusbx64.sys -- (YMIDUSBW)
DRV:64bit: - [2013.03.18 16:51:08 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2013.03.12 13:19:38 | 000,064,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2013.03.01 03:49:12 | 000,036,600 | ---- | M] (Riverbed Technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2013.02.01 16:46:44 | 000,819,784 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2012.11.08 12:41:34 | 000,418,632 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2012.11.08 12:41:34 | 000,139,592 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2012.05.12 12:31:00 | 000,121,416 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2012.03.01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011.12.07 19:42:28 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.20 13:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2009.12.30 11:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 18:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2014.07.09 14:03:10 | 000,019,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys -- (RivaTuner64)
DRV - [2014.05.30 01:20:09 | 000,020,256 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Programme\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV - [2014.05.01 00:11:15 | 000,022,280 | ---- | M] (ASRock Incorporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\AsrDrv101.sys -- (AsrDrv101)
DRV - [2013.01.23 08:12:38 | 000,013,368 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2012.07.26 14:38:00 | 000,070,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys -- (VSPerfDrv110)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-pag...q={searchTerms}
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-pag...q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-pag...q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-pag...q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 98 1E 9F AF CD 64 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;<local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 50.21.181.12:3128
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: 2.0%40disconnect.me:3.14.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.5.2: C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.5.2: C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.3.0: C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.4.0: C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@RadioRage_4j.com/Plugin: C:\Program Files (x86)\RadioRage_4j\bar\1.bin\NP4jStub.dll (Mindspark)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Windows.old\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Windows.old\Program Files (x86)\Mozilla Firefox\plugins [2014.07.22 21:02:01 | 000,000,000 | ---D | M]
[2014.05.01 01:43:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\<myname>\AppData\Roaming\mozilla\Extensions
[2014.07.24 17:14:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\<myname>\AppData\Roaming\mozilla\Firefox\Profiles\cwt0n2ts.default-1402129156548\extensions
[2014.07.20 19:14:24 | 000,000,000 | ---D | M] (Wörterbuch Deutsch (de-DE), Hunspell-unterstützt) -- C:\Users\<myname>\AppData\Roaming\mozilla\Firefox\Profiles\cwt0n2ts.default-1402129156548\extensions\[email protected]
[2014.07.20 19:16:12 | 000,000,000 | ---D | M] (German Dictionary) -- C:\Users\<myname>\AppData\Roaming\mozilla\Firefox\Profiles\cwt0n2ts.default-1402129156548\extensions\[email protected]
[2014.07.24 17:14:44 | 000,947,620 | ---- | M] () (No name found) -- C:\Users\<myname>\AppData\Roaming\mozilla\firefox\profiles\cwt0n2ts.default-1402129156548\extensions\[email protected]
[2014.07.22 16:16:18 | 003,621,870 | ---- | M] () (No name found) -- C:\Users\<myname>\AppData\Roaming\mozilla\firefox\profiles\cwt0n2ts.default-1402129156548\extensions\[email protected]
[2014.07.23 22:50:46 | 000,967,685 | ---- | M] () (No name found) -- C:\Users\<myname>\AppData\Roaming\mozilla\firefox\profiles\cwt0n2ts.default-1402129156548\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.07.24 17:14:44 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\<myname>\AppData\Roaming\mozilla\firefox\profiles\cwt0n2ts.default-1402129156548\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2014.05.07 23:23:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2014.05.03 14:05:42 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014.05.07 23:23:19 | 000,000,000 | ---D | M] (Hotspot Shield Extension) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\[email protected]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\<myname>\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Users\<myname>\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\<myname>\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\<myname>\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Users\<myname>\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Google Mail = C:\Users\<myname>\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre8\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Programme\COMODO\COMODO Internet Security\CisTray.exe (COMODO)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [tvncontrol] C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Comodo Security Solutions, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [f.lux] C:\Users\<myname>\AppData\Local\FluxSoftware\Flux\flux.exe (Flux Software LLC)
O4 - HKCU..\RunOnce: [AsrOMG_Day0] Reg Error: Invalid data type. File not found
O4 - HKCU..\RunOnce: [AsrOMG_Day1] Reg Error: Invalid data type. File not found
O4 - HKCU..\RunOnce: [AsrOMG_Day2] Reg Error: Invalid data type. File not found
O4 - HKCU..\RunOnce: [AsrOMG_Day3] Reg Error: Invalid data type. File not found
O4 - HKCU..\RunOnce: [AsrOMG_Day4] Reg Error: Invalid data type. File not found
O4 - HKCU..\RunOnce: [AsrOMG_Day5] Reg Error: Invalid data type. File not found
O4 - HKCU..\RunOnce: [AsrOMG_Day6] Reg Error: Invalid data type. File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.m...ash/swflash.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{86AC067A-5800-42EB-87C4-E50869808AA4}: DhcpNameServer = 192.168.0.1 192.168.0.2
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\Userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (bj.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Programme\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014.04.23 20:18:45 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O33 - MountPoints2\{a23c35c6-d1fe-11e3-bee4-d050991146ac}\Shell - "" = AutoRun
O33 - MountPoints2\{a23c35c6-d1fe-11e3-bee4-d050991146ac}\Shell\AutoRun\command - "" = E:\vs_ultimate.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.07.26 18:40:02 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\assembly
[2014.07.26 01:56:41 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Desktop\License
[2014.07.26 01:51:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskCheckup
[2014.07.26 01:51:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DiskCheckup
[2014.07.26 01:45:29 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\HDDHealth
[2014.07.26 01:45:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Health
[2014.07.26 01:45:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HDD Health
[2014.07.25 22:44:15 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Avira
[2014.07.25 22:43:50 | 000,042,040 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2014.07.25 22:42:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2014.07.25 22:42:18 | 000,130,584 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2014.07.25 22:42:18 | 000,117,712 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2014.07.25 22:42:18 | 000,028,600 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2014.07.25 22:42:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2014.07.25 22:42:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2014.07.25 21:57:00 | 000,000,000 | --SD | C] -- C:\ProgramData\Shared Space
[2014.07.25 21:56:40 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2014.07.25 21:56:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\COMODO
[2014.07.25 21:56:28 | 000,057,096 | ---- | C] (COMODO CA Limited) -- C:\Windows\SysNative\certsentry.dll
[2014.07.25 21:56:28 | 000,048,392 | ---- | C] (COMODO CA Limited) -- C:\Windows\SysWow64\certsentry.dll
[2014.07.25 21:54:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2014.07.25 21:54:16 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\Comodo
[2014.07.25 21:54:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Comodo
[2014.07.25 21:54:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2014.07.25 21:49:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2014.07.25 09:02:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Visual Studio
[2014.07.24 23:54:57 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\Red 5 Studios
[2014.07.24 23:54:52 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Firefall
[2014.07.24 23:54:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xiph.Org
[2014.07.24 23:54:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xiph.Org
[2014.07.24 23:29:21 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Visual Studio 2012
[2014.07.24 23:28:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014.07.24 23:27:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2014.07.24 23:27:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK - Deutsch
[2014.07.24 23:27:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 4 SDK - Deutsch
[2014.07.24 23:26:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2014.07.24 23:26:18 | 000,000,000 | ---D | C] -- C:\Program Files\Application Verifier
[2014.07.24 23:26:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Verifier
[2014.07.24 23:26:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows App Certification Kit
[2014.07.24 23:25:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
[2014.07.24 23:25:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft
[2014.07.24 23:25:31 | 000,000,000 | ---D | C] -- C:\ProgramData\PreEmptive Solutions
[2014.07.24 23:23:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2014.07.24 23:23:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Web Tools
[2014.07.24 23:23:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2014.07.24 23:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\IIS Express
[2014.07.24 23:23:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS Express
[2014.07.24 23:22:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NuGet
[2014.07.24 23:22:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft WCF Data Services
[2014.07.24 23:20:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Kits
[2014.07.24 23:17:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HTML Help Workshop
[2014.07.24 23:17:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Help Viewer
[2014.07.24 23:17:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1033
[2014.07.24 23:17:01 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1033
[2014.07.24 23:17:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\1031
[2014.07.24 23:16:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2014.07.24 23:16:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
[2014.07.24 23:14:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Merge Modules
[2014.07.24 23:13:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2012
[2014.07.24 23:13:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 11.0
[2014.07.24 23:13:45 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\1031
[2014.07.24 23:13:41 | 000,000,000 | ---D | C] -- C:\Windows\symbols
[2014.07.24 23:13:40 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 11.0
[2014.07.24 23:13:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SDKs
[2014.07.24 23:11:23 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1991-06.com.microsoft
[2014.07.24 22:23:33 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Desktop\MEGAPACK
[2014.07.20 21:49:37 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014.07.20 21:49:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014.07.20 21:49:10 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\http___www.julien-manici
[2014.07.20 15:49:27 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\TrueCrypt
[2014.07.20 14:31:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
[2014.07.20 14:31:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinPcap
[2014.07.20 14:31:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain
[2014.07.20 14:23:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueCrypt
[2014.07.20 14:23:30 | 000,231,376 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\SysNative\drivers\truecrypt.sys
[2014.07.20 14:23:14 | 000,000,000 | ---D | C] -- C:\Program Files\TrueCrypt
[2014.07.20 12:16:50 | 000,000,000 | ---D | C] -- C:\Users\<myname>\VirtualBox VMs
[2014.07.20 12:16:16 | 000,000,000 | ---D | C] -- C:\Users\<myname>\.VirtualBox
[2014.07.20 12:15:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
[2014.07.20 12:15:32 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2014.07.20 12:13:08 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\VMware
[2014.07.20 12:09:48 | 000,000,000 | ---D | C] -- C:\ProgramData\VMware
[2014.07.20 08:44:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014.07.19 22:30:26 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\NVIDIA
[2014.07.19 22:30:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2014.07.19 12:38:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2014.07.18 00:20:51 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Desktop\Website Safe Scanner
[2014.07.17 19:15:02 | 000,033,856 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\hamachi.sys
[2014.07.17 00:05:37 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Banished
[2014.07.16 00:58:54 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\RotMG.Production
[2014.07.15 16:28:58 | 000,000,000 | ---D | C] -- C:\ProgramData\SwiftKit
[2014.07.15 15:58:10 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2014.07.15 15:53:21 | 000,000,000 | ---D | C] -- C:\Windows\.jagex_cache_32
[2014.07.15 15:52:58 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape
[2014.07.14 00:26:24 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
[2014.07.14 00:26:22 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\FluxSoftware
[2014.07.13 15:24:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
[2014.07.13 15:23:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Diablo III
[2014.07.13 02:43:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
[2014.07.13 02:43:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TERA
[2014.07.12 15:08:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
[2014.07.12 15:06:45 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Vindictus EU
[2014.07.12 14:59:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2014.07.12 14:59:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BandiMPEG1
[2014.07.12 14:54:56 | 000,000,000 | ---D | C] -- C:\Nexon
[2014.07.12 14:28:01 | 000,000,000 | ---D | C] -- C:\ProgramData\NexonEU
[2014.07.11 23:34:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Arma III
[2014.07.11 21:10:56 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Bullet
[2014.07.11 21:09:56 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft AppLocale
[2014.07.09 21:16:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\WuShu_0.0.1.116
[2014.07.09 21:16:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AgeofWushu_download
[2014.07.09 14:06:53 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Mount&Blade Warband Savegames
[2014.07.09 14:05:37 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Mount&Blade Warband
[2014.07.09 14:05:37 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Mount&Blade Warband
[2014.07.09 14:02:38 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
[2014.07.09 14:02:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
[2014.07.09 11:31:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2014.07.09 11:31:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
[2014.07.09 11:09:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webzen
[2014.07.09 11:09:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Webzen
[2014.07.09 10:56:32 | 000,000,000 | ---D | C] -- C:\download
[2014.07.09 10:56:27 | 000,000,000 | ---D | C] -- C:\ProgramData\WEBZEN
[2014.07.06 00:56:17 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\LogMeIn Hamachi
[2014.07.06 00:56:17 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\LogMeIn
[2014.07.06 00:56:17 | 000,000,000 | ---D | C] -- C:\ProgramData\LogMeIn
[2014.07.04 21:42:00 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\VS Revo Group
[2014.07.04 21:41:57 | 000,031,800 | ---- | C] (VS Revo Group) -- C:\Windows\SysNative\drivers\revoflt.sys
[2014.07.04 21:41:57 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
[2014.07.04 21:41:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2014.07.04 21:41:56 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2014.07.03 21:04:23 | 000,000,000 | ---D | C] -- C:\ProgramData\pwd
[2014.07.03 20:26:23 | 000,000,000 | -H-D | C] -- C:\ArcTemp
[2014.07.03 19:18:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2
[2014.07.03 19:18:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Guild Wars 2
[2014.07.03 19:18:10 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Guild Wars 2
[2014.07.02 21:18:16 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\AnyTrans Export
[2014.07.02 21:14:36 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\Apple Computer
[2014.07.02 21:14:35 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\Apple Computer
[2014.07.02 21:14:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2014.07.02 21:14:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2014.07.02 21:14:02 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2014.07.02 21:12:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2014.07.02 21:11:18 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\iMobie_Inc
[2014.07.02 21:11:18 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\iMobie
[2014.06.30 18:49:55 | 000,000,000 | ---D | C] -- C:\Users\<myname>\Documents\Larian Studios
[2014.06.28 12:01:25 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Roaming\NVIDIA
[2014.06.28 11:23:17 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\NVIDIA Corporation
[2014.06.28 11:22:50 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2014.06.28 11:21:57 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2014.06.28 11:20:23 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2014.06.28 11:20:07 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2014.06.27 22:59:17 | 000,000,000 | ---D | C] -- C:\Users\<myname>\AppData\Local\Sniper3
[2014.06.15 21:05:36 | 002,869,264 | ---- | C] (Microsoft Corporation) -- C:\Users\<myname>\AppData\Roaming\dotNetFx35setup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.07.27 18:34:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.07.27 18:14:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.07.27 10:40:43 | 000,020,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.07.27 10:40:43 | 000,020,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.07.27 10:31:27 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.07.27 10:30:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.07.27 10:30:33 | 2099,032,063 | -HS- | M] () -- C:\hiberfil.sys
[2014.07.27 01:09:53 | 001,593,558 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014.07.27 01:09:53 | 000,697,970 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2014.07.27 01:09:53 | 000,654,968 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.07.27 01:09:53 | 000,149,436 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2014.07.27 01:09:53 | 000,122,338 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.07.27 01:09:47 | 001,593,558 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.07.26 17:08:02 | 000,000,919 | ---- | M] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2014.07.26 17:07:56 | 003,410,768 | ---- | M] () -- C:\Users\<myname>\Desktop\GameClient 2014-07-26 17-07-55-25.png
[2014.07.26 17:07:38 | 003,387,948 | ---- | M] () -- C:\Users\<myname>\Desktop\GameClient 2014-07-26 17-07-37-48.png
[2014.07.26 10:02:33 | 005,035,776 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014.07.26 01:45:22 | 000,001,044 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HDDHealth.lnk
[2014.07.25 22:43:13 | 000,042,040 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2014.07.25 22:42:44 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2014.07.25 22:19:02 | 000,002,165 | ---- | M] () -- C:\Users\<myname>\AppData\Roaming\EasyToolz.ini
[2014.07.25 21:59:31 | 000,001,870 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Firewall.lnk
[2014.07.25 21:56:42 | 000,002,013 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2014.07.25 21:56:42 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2014.07.25 21:56:30 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Comodo Dragon.lnk
[2014.07.25 21:56:28 | 000,057,096 | ---- | M] (COMODO CA Limited) -- C:\Windows\SysNative\certsentry.dll
[2014.07.25 21:56:28 | 000,048,392 | ---- | M] (COMODO CA Limited) -- C:\Windows\SysWow64\certsentry.dll
[2014.07.20 14:23:30 | 000,231,376 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\SysNative\drivers\truecrypt.sys
[2014.07.20 12:15:48 | 000,001,100 | ---- | M] () -- C:\Users\<myname>\Application Data\Microsoft\Internet Explorer\Quick Launch\Oracle VM VirtualBox.lnk
[2014.07.20 12:15:48 | 000,001,076 | ---- | M] () -- C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
[2014.07.20 12:10:19 | 000,001,024 | ---- | M] () -- C:\Windows\SysWow64\%TMP%
[2014.07.19 23:30:43 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2014.07.19 23:30:43 | 000,000,934 | ---- | M] () -- C:\Users\Public\Desktop\Nexus Mod Manager.lnk
[2014.07.19 22:31:04 | 000,001,347 | ---- | M] () -- C:\Users\Public\Desktop\GeForce Experience.lnk
[2014.07.18 08:54:02 | 035,524,570 | ---- | M] () -- C:\Users\<myname>\Desktop\Desktop.zip
[2014.07.15 16:31:14 | 000,000,024 | ---- | M] () -- C:\Users\<myname>\random.dat
[2014.07.15 16:30:25 | 000,000,043 | ---- | M] () -- C:\Users\<myname>\jagex_cl_oldschool_LIVE.dat
[2014.07.15 16:19:12 | 000,002,271 | ---- | M] () -- C:\Users\<myname>\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014.07.15 16:14:20 | 000,000,043 | ---- | M] () -- C:\Users\<myname>\jagex_cl_runescape_LIVE.dat
[2014.07.15 15:58:15 | 000,000,044 | ---- | M] () -- C:\Users\<myname>\jagex_cl_runescape_LIVE1.dat
[2014.07.15 15:54:18 | 000,000,023 | ---- | M] () -- C:\Users\<myname>\jagexappletviewer.preferences
[2014.07.13 15:24:27 | 000,001,156 | ---- | M] () -- C:\Users\Public\Desktop\Diablo III.lnk
[2014.07.13 02:43:30 | 000,001,044 | ---- | M] () -- C:\Users\<myname>\Desktop\TERA.lnk
[2014.07.12 18:02:40 | 000,000,331 | ---- | M] () -- C:\Users\<myname>\Documents\Preset 1.mbcfg
[2014.07.12 18:02:40 | 000,000,331 | ---- | M] () -- C:\Users\<myname>\Documents\Preset 0.mbcfg
[2014.07.12 14:59:32 | 000,000,183 | ---- | M] () -- C:\Users\Public\Desktop\Vindictus EU.url
[2014.07.04 21:41:58 | 000,001,101 | ---- | M] () -- C:\Users\<myname>\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2014.07.04 21:06:19 | 477,616,821 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014.07.03 19:18:54 | 000,000,932 | ---- | M] () -- C:\Users\Public\Desktop\Guild Wars 2.lnk
[2014.07.02 22:05:25 | 000,214,392 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014.07.02 22:00:56 | 000,000,653 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
[2014.07.02 13:06:42 | 000,130,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2014.07.02 13:06:42 | 000,117,712 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2014.07.02 13:06:42 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2014.06.28 14:07:47 | 000,000,231 | ---- | M] () -- C:\Users\<myname>\Desktop\Watch_Dogs.url
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.07.26 17:07:55 | 003,410,768 | ---- | C] () -- C:\Users\<myname>\Desktop\GameClient 2014-07-26 17-07-55-25.png
[2014.07.26 17:07:37 | 003,387,948 | ---- | C] () -- C:\Users\<myname>\Desktop\GameClient 2014-07-26 17-07-37-48.png
[2014.07.26 02:14:18 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2014.07.26 01:45:22 | 000,001,044 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HDDHealth.lnk
[2014.07.25 22:42:44 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2014.07.25 21:59:31 | 000,001,870 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Firewall.lnk
[2014.07.25 21:56:42 | 000,002,013 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[2014.07.25 21:56:42 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2014.07.25 21:56:30 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Comodo Dragon.lnk
[2014.07.24 23:23:14 | 000,002,059 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
[2014.07.20 14:23:34 | 000,000,919 | ---- | C] () -- C:\Users\Public\Desktop\TrueCrypt.lnk
[2014.07.20 12:15:48 | 000,001,100 | ---- | C] () -- C:\Users\<myname>\Application Data\Microsoft\Internet Explorer\Quick Launch\Oracle VM VirtualBox.lnk
[2014.07.20 12:15:48 | 000,001,076 | ---- | C] () -- C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
[2014.07.20 12:10:19 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\%TMP%
[2014.07.19 22:31:04 | 000,001,347 | ---- | C] () -- C:\Users\Public\Desktop\GeForce Experience.lnk
[2014.07.18 08:53:57 | 035,524,570 | ---- | C] () -- C:\Users\<myname>\Desktop\Desktop.zip
[2014.07.15 16:30:25 | 000,000,043 | ---- | C] () -- C:\Users\<myname>\jagex_cl_oldschool_LIVE.dat
[2014.07.15 15:58:15 | 000,000,044 | ---- | C] () -- C:\Users\<myname>\jagex_cl_runescape_LIVE1.dat
[2014.07.15 15:53:23 | 000,000,043 | ---- | C] () -- C:\Users\<myname>\jagex_cl_runescape_LIVE.dat
[2014.07.15 15:53:23 | 000,000,024 | ---- | C] () -- C:\Users\<myname>\random.dat
[2014.07.15 15:53:14 | 000,000,023 | ---- | C] () -- C:\Users\<myname>\jagexappletviewer.preferences
[2014.07.15 15:52:58 | 000,002,076 | ---- | C] () -- C:\Users\<myname>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RuneScape.lnk
[2014.07.13 15:24:26 | 000,001,156 | ---- | C] () -- C:\Users\Public\Desktop\Diablo III.lnk
[2014.07.13 02:43:31 | 000,001,044 | ---- | C] () -- C:\Users\<myname>\Desktop\TERA.lnk
[2014.07.12 14:59:32 | 000,000,183 | ---- | C] () -- C:\Users\Public\Desktop\Vindictus EU.url
[2014.07.04 21:41:58 | 000,001,121 | ---- | C] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2014.07.04 21:41:58 | 000,001,101 | ---- | C] () -- C:\Users\<myname>\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2014.07.03 19:18:54 | 000,000,932 | ---- | C] () -- C:\Users\Public\Desktop\Guild Wars 2.lnk
[2014.07.02 22:00:56 | 000,000,653 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
[2014.07.02 21:13:21 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2014.06.28 14:07:47 | 000,000,231 | ---- | C] () -- C:\Users\<myname>\Desktop\Watch_Dogs.url
[2014.06.28 11:22:13 | 003,774,821 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2014.06.28 11:21:17 | 000,026,069 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2014.05.25 13:07:14 | 000,354,304 | ---- | C] () -- C:\Windows\SysWow64\pythoncom27.dll
[2014.05.25 13:07:14 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\pywintypes27.dll
[2014.05.25 13:07:14 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\pythoncomloader27.dll
[2014.05.12 21:11:32 | 000,214,392 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014.05.12 21:11:31 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014.05.10 20:54:24 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2014.05.06 09:49:18 | 005,117,607 | ---- | C] () -- C:\Users\<myname>\1.7.2-Forge10.12.1.1065.jar
[2014.05.01 01:57:36 | 001,593,558 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014.05.01 01:52:48 | 006,664,704 | ---- | C] () -- C:\Windows\REMOVEWAT.EXE
[2014.04.30 22:38:32 | 000,002,165 | ---- | C] () -- C:\Users\<myname>\AppData\Roaming\EasyToolz.ini
[2014.04.30 21:36:56 | 000,007,605 | ---- | C] () -- C:\Users\<myname>\AppData\Local\Resmon.ResmonCfg
[2013.07.18 14:32:38 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2013.07.18 14:32:34 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2013.07.18 14:32:34 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013.07.18 14:32:34 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013.07.18 14:32:34 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013.03.01 03:47:36 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2013.02.13 12:27:54 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2012.09.28 21:45:06 | 000,247,296 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014.03.25 04:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.03.25 04:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014.07.25 15:26:21 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\.minecraft
[2014.05.04 13:41:59 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\.technic
[2014.06.25 17:35:28 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Aeria Games & Entertainment
[2014.05.06 01:00:34 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Autodesk
[2014.06.07 12:42:51 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Battle.net
[2014.06.25 12:21:22 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Bullet Candy
[2014.04.30 23:43:37 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\CPUControl
[2014.04.30 21:14:50 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Craften Terminal
[2014.05.31 21:10:16 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Crytek
[2014.05.02 17:47:39 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\DAEMON Tools Lite
[2014.05.25 10:42:06 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\DarkSoulsII
[2014.04.30 21:40:59 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Easeware
[2014.05.01 14:52:08 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\ftblauncher
[2014.07.03 23:09:23 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Guild Wars 2
[2014.07.26 01:45:29 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\HDDHealth
[2014.07.02 21:16:18 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\iMobie
[2014.05.01 01:53:47 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\java
[2014.05.01 02:14:46 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\library_dir
[2014.04.30 22:47:12 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\MotioninJoy
[2014.07.09 14:06:19 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Mount&Blade Warband
[2014.06.19 23:10:49 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\MultiBit
[2014.05.01 13:38:18 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Notepad++
[2014.05.12 21:05:27 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Origin
[2014.05.07 20:21:29 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\RadeonPro
[2014.05.02 21:51:58 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\RIFT
[2014.07.16 00:58:54 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\RotMG.Production
[2014.06.14 14:13:37 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Samsung
[2014.05.01 00:08:59 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\sweet-page
[2014.07.15 12:19:24 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Synthesia
[2014.05.10 12:53:27 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\TeamViewer
[2014.05.11 15:26:19 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\TERA
[2014.06.25 19:36:58 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\The Creative Assembly
[2014.05.28 12:31:43 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\To the Moon - Freebird Games
[2014.07.20 15:52:23 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\TrueCrypt
[2014.07.22 23:22:43 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\TS3Client
[2014.07.20 21:54:10 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\uTorrent
[2014.05.29 13:23:50 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\XRay Engine
[2014.05.17 13:10:04 | 000,000,000 | ---D | M] -- C:\Users\<myname>\AppData\Roaming\Zeal Game Studio
========== Purity Check ==========
< End of report >