Hey guys, i have a problem. Since a few days ago, my browser is cluttered with ads, with the writing "Ads by BlockAndSurf" under them. I read that it may be caused by a program so i went to the controlpanel and uninstalled every suspicious software. But the adware is still there. I already tried a lot of antivirus softwares, and i also did scans in safe mode. My pc has Win7 Professional 64-bit. I'd appreciate it if someone helped me out!
OTL logfile created on: 10.12.2014 00:06:21 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\LoniVanBuni\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,92 Gb Total Physical Memory | 4,27 Gb Available Physical Memory | 53,91% Memory free
15,84 Gb Paging File | 11,57 Gb Available in Paging File | 73,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 595,21 Gb Free Space | 63,90% Space Free | Partition Type: NTFS
Computer Name: LONIVANBUNIS-PC | User Name: LoniVanBuni | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.12.10 00:05:07 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\LoniVanBuni\Downloads\OTL.exe
PRC - [2014.12.09 19:05:43 | 000,076,152 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2014.12.09 00:20:58 | 005,226,600 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastUI.exe
PRC - [2014.12.09 00:20:47 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe
PRC - [2014.12.03 19:08:25 | 003,618,648 | ---- | M] (Electronic Arts) -- C:\Program Files (x86)\Origin\Origin.exe
PRC - [2014.12.01 15:51:42 | 003,835,728 | ---- | M] (LogMeIn Inc.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2014.11.25 10:57:09 | 000,535,160 | ---- | M] () -- C:\Program Files (x86)\Opera\26.0.1656.32\opera_crashreporter.exe
PRC - [2014.11.25 10:57:07 | 050,335,864 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\26.0.1656.32\opera.exe
PRC - [2014.11.24 10:23:31 | 000,431,920 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2014.11.24 10:23:22 | 000,431,920 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2014.11.24 10:23:21 | 000,702,768 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2014.11.21 06:12:56 | 000,969,016 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014.11.21 06:12:54 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014.11.21 06:12:46 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014.11.18 21:23:36 | 001,519,808 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
PRC - [2014.11.18 21:23:34 | 001,940,160 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe
PRC - [2014.11.18 21:23:34 | 000,833,728 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2014.10.22 15:16:42 | 000,124,208 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
PRC - [2014.10.22 15:16:38 | 000,164,656 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
PRC - [2014.06.21 11:52:02 | 002,011,904 | ---- | M] (CurioLab S.M.B.A.) -- C:\Program Files (x86)\Exterminate It!\ExterminateIt.exe
PRC - [2013.11.01 11:34:48 | 000,389,120 | ---- | M] (AMD) -- C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
PRC - [2013.08.08 14:30:28 | 000,283,648 | ---- | M] () -- C:\Programme\Qualcomm Atheros\Network Manager\NetworkManager.exe
PRC - [2012.04.11 10:41:04 | 000,097,280 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
========== Modules (No Company Name) ==========
MOD - [2014.12.09 00:20:51 | 038,562,088 | ---- | M] () -- C:\Programme\AVAST Software\Avast\libcef.dll
MOD - [2014.12.03 19:08:24 | 001,007,104 | ---- | M] () -- C:\Program Files (x86)\Origin\platforms\qwindows.dll
MOD - [2014.12.03 19:08:24 | 000,337,408 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qtiff.dll
MOD - [2014.12.03 19:08:24 | 000,261,120 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qmng.dll
MOD - [2014.12.03 19:08:24 | 000,216,576 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qjpeg.dll
MOD - [2014.12.03 19:08:24 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qico.dll
MOD - [2014.12.03 19:08:24 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qgif.dll
MOD - [2014.12.03 19:08:24 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qtga.dll
MOD - [2014.12.03 19:08:24 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Origin\imageformats\qwbmp.dll
MOD - [2014.11.25 10:57:19 | 009,312,888 | ---- | M] () -- C:\Program Files (x86)\Opera\26.0.1656.32\pdf.dll
MOD - [2014.11.25 10:57:14 | 001,358,456 | ---- | M] () -- C:\Program Files (x86)\Opera\26.0.1656.32\libglesv2.dll
MOD - [2014.11.25 10:57:13 | 000,219,256 | ---- | M] () -- C:\Program Files (x86)\Opera\26.0.1656.32\libegl.dll
MOD - [2014.11.25 10:57:12 | 000,991,352 | ---- | M] () -- C:\Program Files (x86)\Opera\26.0.1656.32\ffmpegsumo.dll
MOD - [2014.11.25 10:57:09 | 000,535,160 | ---- | M] () -- C:\Program Files (x86)\Opera\26.0.1656.32\opera_crashreporter.exe
MOD - [2014.11.18 21:23:50 | 002,227,904 | ---- | M] () -- C:\Program Files (x86)\Steam\video.dll
MOD - [2014.11.18 21:23:34 | 000,690,880 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.DLL
MOD - [2014.11.11 19:48:12 | 001,171,456 | ---- | M] () -- C:\Program Files (x86)\Steam\libavcodec-56.dll
MOD - [2014.11.11 19:48:12 | 000,485,888 | ---- | M] () -- C:\Program Files (x86)\Steam\libswscale-3.dll
MOD - [2014.11.11 19:48:12 | 000,442,368 | ---- | M] () -- C:\Program Files (x86)\Steam\libavutil-54.dll
MOD - [2014.11.11 19:48:12 | 000,403,968 | ---- | M] () -- C:\Program Files (x86)\Steam\libavformat-56.dll
MOD - [2014.11.11 19:48:12 | 000,332,800 | ---- | M] () -- C:\Program Files (x86)\Steam\libavresample-2.dll
MOD - [2014.11.11 19:48:04 | 034,589,888 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2014.11.11 19:47:56 | 000,774,656 | ---- | M] () -- C:\Program Files (x86)\Steam\SDL2.dll
MOD - [2014.10.11 13:06:16 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014.10.11 13:05:58 | 001,044,776 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013.12.03 18:40:01 | 000,256,512 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\8ea4f2a14f034a52843ddf37991c9f6d\WindowsFormsIntegration.ni.dll
MOD - [2013.12.03 18:39:34 | 002,956,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\c37bcdac22f4bcd9531dfcc4b9ebda56\System.IdentityModel.ni.dll
MOD - [2013.12.03 18:39:32 | 019,522,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\ec19fdffa5eaea430a77160272ed897e\System.ServiceModel.ni.dll
MOD - [2013.12.03 18:39:01 | 000,018,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\dcf2b1a7011858156e5b759de2e5e598\PresentationFramework-SystemXml.ni.dll
MOD - [2013.12.03 18:39:01 | 000,016,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a7b877#\0dbb2348461d98c3319e8a3fa729eb68\PresentationFramework-SystemData.ni.dll
MOD - [2013.12.03 18:08:38 | 018,524,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\97e6b67983d07a066b68b3ae8be2f53d\PresentationFramework.ni.dll
MOD - [2013.12.03 18:08:33 | 002,505,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.Linq\fb1e17d7933d852614890b82126e6ab8\System.Data.Linq.ni.dll
MOD - [2013.12.03 18:08:32 | 000,462,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\e7d92730b571b31e62c2cf257f04a974\PresentationFramework.Aero.ni.dll
MOD - [2013.12.03 18:08:30 | 000,220,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\ad2f6440da38a0dbae2df194782b35d1\System.ServiceProcess.ni.dll
MOD - [2013.12.03 18:08:29 | 010,914,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b52bc540630c3aa5de542c382af35c20\PresentationCore.ni.dll
MOD - [2013.12.03 18:08:26 | 007,248,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\9a6093eb864d6729de75ec4b955dddb1\System.Data.ni.dll
MOD - [2013.12.03 18:08:24 | 012,692,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\22ae167d586450ad3a9b9a9ee43ebc86\System.Windows.Forms.ni.dll
MOD - [2013.12.03 18:08:22 | 006,995,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\b9f7adbc90a2bcbe8eb9e6e8d2bb975b\System.Core.ni.dll
MOD - [2013.12.03 18:08:22 | 003,905,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\cd235caf797fb017f140016be88f33b7\WindowsBase.ni.dll
MOD - [2013.12.03 18:08:21 | 007,559,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9ba07396ae369d010c5c3927a82ef426\System.Xml.ni.dll
MOD - [2013.12.03 18:08:20 | 001,870,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\cc4d9093563dadee370788bbc3ecf4fb\System.Xaml.ni.dll
MOD - [2013.12.03 18:08:18 | 002,785,280 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\293cfe2c05a8ee921726927fd00ea81c\System.Runtime.Serialization.ni.dll
MOD - [2013.12.03 18:08:18 | 001,630,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\72269ea7cc6281139e4d155e7c57dc67\System.Drawing.ni.dll
MOD - [2013.12.03 18:08:18 | 000,802,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\df55f04bc0ebe6c1abde4bc467bf4d03\System.ServiceModel.Internals.ni.dll
MOD - [2013.12.03 18:08:17 | 009,925,120 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\e40da7a49f8c3f0108e7c835b342f382\System.ni.dll
MOD - [2013.12.03 18:08:17 | 000,958,464 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\28586400bcaf94c13a9fd0dff4a1e090\System.Configuration.ni.dll
MOD - [2013.12.03 18:08:17 | 000,121,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\98e3281d79512c9a2a0a89e3bc2e554f\SMDiagnostics.ni.dll
MOD - [2013.12.03 18:08:13 | 000,145,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\1346fe7d35b70702029e422970db1201\System.Numerics.ni.dll
MOD - [2013.12.03 18:08:12 | 016,501,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\51e2934144ba15628ba5a31be2dae7dc\mscorlib.ni.dll
MOD - [2013.08.08 14:30:28 | 000,283,648 | ---- | M] () -- C:\Programme\Qualcomm Atheros\Network Manager\NetworkManager.exe
MOD - [2011.11.02 09:02:56 | 000,318,531 | ---- | M] () -- C:\Program Files (x86)\Exterminate It!\sqlite3.dll
========== Services (SafeList) ==========
SRV:64bit: - [2013.11.01 11:46:24 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2013.10.08 03:00:50 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009.07.14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014.12.09 19:05:43 | 000,076,152 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014.12.09 00:20:47 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Programme\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2014.12.09 00:20:37 | 004,012,248 | ---- | M] (Avast Software) [On_Demand | Running] -- C:\Programme\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe -- (AvastVBoxSvc)
SRV - [2014.12.03 19:08:25 | 001,900,400 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- C:\Program Files (x86)\Origin\OriginClientService.exe -- (Origin Client Service)
SRV - [2014.12.01 15:51:22 | 002,530,128 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2014.11.24 10:23:31 | 000,431,920 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2014.11.24 10:23:22 | 000,431,920 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2014.11.21 06:12:56 | 000,969,016 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014.11.21 06:12:54 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014.11.18 21:23:34 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014.11.14 18:28:26 | 000,417,552 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2014.10.22 15:16:38 | 000,164,656 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe -- (Avira.OE.ServiceHost)
SRV - [2014.07.23 00:31:23 | 000,172,344 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Programme\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV - [2013.08.08 14:30:40 | 000,343,040 | ---- | M] (Qualcomm Atheros) [Auto | Running] -- C:\Programme\Qualcomm Atheros\Network Manager\KillerService.exe -- (Qualcomm Atheros Killer Service V2)
SRV - [2012.07.09 00:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014.12.09 23:40:58 | 000,129,752 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2014.12.09 00:20:59 | 001,050,432 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:64bit: - [2014.12.09 00:20:52 | 000,436,624 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2014.12.09 00:20:52 | 000,267,632 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014.12.09 00:20:52 | 000,116,728 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2014.12.09 00:20:52 | 000,083,280 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswmonflt.sys -- (aswMonFlt)
DRV:64bit: - [2014.12.09 00:20:52 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2014.12.09 00:20:52 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014.12.09 00:20:51 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014.12.07 02:16:53 | 000,022,704 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\EsgScanner.sys -- (EsgScanner)
DRV:64bit: - [2014.12.06 18:47:14 | 000,106,456 | ---- | M] (Corsica) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\webinstrNewH.sys -- (webinstrNewH)
DRV:64bit: - [2014.11.24 10:23:23 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2014.11.24 10:23:22 | 000,131,608 | ---- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2014.11.24 10:23:21 | 000,119,272 | ---- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2014.11.21 06:14:22 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014.11.21 06:14:08 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2013.10.08 05:30:14 | 013,199,360 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013.10.08 02:30:10 | 000,624,128 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013.09.24 15:53:50 | 000,094,208 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2013.08.16 15:37:12 | 000,424,192 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2013.08.16 15:37:12 | 000,140,032 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2013.06.27 16:50:46 | 000,042,304 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2013.06.27 16:50:44 | 000,082,240 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2013.05.27 20:09:38 | 000,227,648 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdxhc.sys -- (amdxhc)
DRV:64bit: - [2013.05.27 20:09:38 | 000,106,816 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdhub30.sys -- (amdhub30)
DRV:64bit: - [2013.03.20 16:46:40 | 000,154,320 | ---- | M] (Qualcomm Atheros, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e22W7x64.sys -- (Ke2200)
DRV:64bit: - [2013.02.13 15:07:46 | 000,067,888 | ---- | M] (Qualcomm Atheros, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\bflwfx64.sys -- (BfLwf)
DRV:64bit: - [2012.10.03 16:14:56 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2010.11.21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010.11.21 04:24:15 | 000,146,432 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rmcast.sys -- (RMCAST)
DRV:64bit: - [2010.11.21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 04:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010.11.21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010.11.21 04:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2014.12.09 00:20:37 | 000,271,752 | ---- | M] (Avast Software) [Kernel | Auto | Running] -- C:\Programme\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys -- (VBoxAswDrv)
DRV - [2014.12.09 00:17:40 | 000,057,024 | ---- | M] (Emsisoft GmbH) [File_System | On_Demand | Running] -- C:\EEK\bin\cleanhlp64.sys -- (cleanhlp)
DRV - [2014.12.09 00:17:40 | 000,026,176 | ---- | M] (Emsisoft GmbH) [File_System | System | Running] -- C:\EEK\bin\a2ddax64.sys -- (A2DDA)
DRV - [2013.09.19 23:05:02 | 000,059,648 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2.0)
DRV - [2011.07.22 17:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV - [2011.07.12 22:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Programme\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2009.07.14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,NewTabPageShow = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,NewTabPageShow = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *origin.com;*ea.com;*akamaihd.net;<local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:31626
========== FireFox ==========
FF - prefs.js..browser.search.isUS: false
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.5.1: C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.25.2: C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2: C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@omaha.maxiget.com/Maxiget Updater;version=3: C:\Program Files (x86)\Maxiget\Updater\70.3.29.7018\npMaxigetUpdater3.dll File not found
FF - HKLM\Software\MozillaPlugins\@omaha.maxiget.com/Maxiget Updater;version=9: C:\Program Files (x86)\Maxiget\Updater\70.3.29.7018\npMaxigetUpdater3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014.12.09 00:20:53 | 000,000,000 | ---D | M]
[2014.12.07 00:53:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LoniVanBuni\AppData\Roaming\mozilla\Extensions
[2014.12.07 04:20:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LoniVanBuni\AppData\Roaming\mozilla\Firefox\Profiles\er6wx06q.default-1417913129901\extensions
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe (Advanced Micro Devices, Inc.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B79EE812-3E2F-4143-ABFE-095511092D6D}: DhcpNameServer = 192.168.178.1
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Programme\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Programme\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\Userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014.12.07 02:19:19 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.12.10 00:05:29 | 000,000,000 | ---D | C] -- C:\EEK
[2014.12.09 23:58:59 | 002,480,312 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\LoniVanBuni\Desktop\procexp.exe
[2014.12.09 23:51:12 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Curiolab
[2014.12.09 23:50:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exterminate It!
[2014.12.09 23:50:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Exterminate It!
[2014.12.09 23:41:02 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\VirtualStore
[2014.12.09 18:38:24 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Ubisoft
[2014.12.09 16:37:16 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014.12.09 10:31:36 | 000,043,064 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2014.12.09 02:59:43 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Documents\WB Games
[2014.12.09 01:06:40 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Opera Software
[2014.12.09 01:06:40 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Opera Software
[2014.12.09 01:06:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2014.12.09 00:20:53 | 000,364,512 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014.12.09 00:20:51 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.12.09 00:16:02 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vbox
[2014.12.09 00:16:02 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vbox
[2014.12.09 00:15:29 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\AVAST Software
[2014.12.09 00:15:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014.12.09 00:14:30 | 000,116,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014.12.09 00:14:29 | 000,436,624 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014.12.09 00:14:29 | 000,093,568 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014.12.09 00:14:29 | 000,083,280 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswmonflt.sys
[2014.12.09 00:14:28 | 001,050,432 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2014.12.09 00:13:47 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014.12.09 00:13:06 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014.12.08 22:10:23 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.12.08 22:10:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014.12.08 22:10:09 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014.12.08 22:10:09 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014.12.08 22:10:09 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014.12.08 22:10:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014.12.08 22:04:28 | 000,000,000 | ---D | C] -- C:\FRST
[2014.12.08 22:04:05 | 002,119,680 | ---- | C] (Farbar) -- C:\Users\LoniVanBuni\Desktop\FRST64.exe
[2014.12.08 21:49:02 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Chromium
[2014.12.08 20:58:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2014.12.08 20:13:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2014.12.07 22:59:18 | 000,000,000 | ---D | C] -- C:\SUPERDelete
[2014.12.07 21:31:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2014.12.07 21:28:30 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\LogMeIn Hamachi
[2014.12.07 21:28:30 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\LogMeIn
[2014.12.07 21:28:30 | 000,000,000 | ---D | C] -- C:\ProgramData\LogMeIn
[2014.12.07 21:28:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2014.12.07 21:28:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2014.12.07 20:59:19 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\SUPERAntiSpyware.com
[2014.12.07 20:59:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2014.12.07 20:59:03 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2014.12.07 20:59:03 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2014.12.07 19:56:30 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\ESN
[2014.12.07 19:12:34 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\QuickScan
[2014.12.07 18:45:56 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\SCE
[2014.12.07 17:46:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
[2014.12.07 17:46:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Anvisoft
[2014.12.07 16:21:39 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2014.12.07 12:05:55 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\PunkBuster
[2014.12.07 12:05:53 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Documents\Battlefield 3
[2014.12.07 12:05:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Battlelog Web Plugins
[2014.12.07 12:04:34 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Logs
[2014.12.07 12:04:34 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Core
[2014.12.07 08:39:45 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller
[2014.12.07 04:02:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft
[2014.12.07 04:02:24 | 000,000,000 | ---D | C] -- C:\Program Files\Adware-Removal-Tool
[2014.12.07 03:00:56 | 000,013,824 | ---- | C] (Kephyr) -- C:\Windows\SysNative\ffnd.exe
[2014.12.07 02:35:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2014.12.07 02:34:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2014.12.07 02:32:14 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\MFAData
[2014.12.07 02:19:05 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Enigma Software Group
[2014.12.07 02:19:03 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Start Menu
[2014.12.07 02:03:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2014.12.07 02:03:07 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014.12.07 00:59:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014.12.07 00:54:22 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Macromedia
[2014.12.07 00:53:13 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Mozilla
[2014.12.07 00:53:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2014.12.07 00:49:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2014.12.07 00:35:34 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\PAYDAY 2
[2014.12.06 21:33:39 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Apps
[2014.12.06 20:40:30 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\java
[2014.12.06 20:40:16 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\.minecraft
[2014.12.06 20:39:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014.12.06 20:39:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014.12.06 20:39:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2014.12.06 20:39:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2014.12.06 20:10:56 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Mozilla
[2014.12.06 20:10:18 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Avira
[2014.12.06 20:08:43 | 000,131,608 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2014.12.06 20:08:43 | 000,119,272 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2014.12.06 20:08:43 | 000,028,600 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2014.12.06 20:08:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2014.12.06 20:08:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2014.12.06 18:49:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.12.06 18:47:31 | 000,106,456 | ---- | C] (Corsica) -- C:\Windows\SysNative\drivers\webinstrNewH.sys
[2014.12.06 18:42:23 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\docksbdrop32
[2014.12.06 18:42:10 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Programs
[2014.12.06 18:16:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\4chan Image Downloader
[2014.12.06 17:20:50 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\SniperV2
[2014.12.06 15:45:08 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\WinRAR
[2014.12.06 15:42:06 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014.12.06 15:42:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2014.12.06 15:42:01 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2014.12.06 15:24:40 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Skyrim
[2014.12.06 15:06:39 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Apple Computer
[2014.12.06 15:06:39 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Apple Computer
[2014.12.06 15:06:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014.12.06 15:06:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2014.12.06 15:06:26 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014.12.06 15:06:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014.12.06 15:06:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2014.12.06 15:06:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2014.12.06 15:06:02 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Apple
[2014.12.06 15:06:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2014.12.06 15:05:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2014.12.06 15:05:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2014.12.06 15:05:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2014.12.06 00:12:47 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2014.12.05 23:56:39 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Desktop\Enterbrain
[2014.12.05 23:50:06 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Desktop\RPGVXAce
[2014.12.05 23:47:00 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Desktop\Content
[2014.12.05 23:37:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks
[2014.12.05 23:37:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bethesda Softworks
[2014.12.05 23:36:50 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Oblivion
[2014.12.05 23:22:51 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Documents\My Games
[2014.12.05 23:22:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft XNA
[2014.12.04 22:58:23 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2014.12.04 18:46:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2014.12.04 18:46:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2014.12.04 18:37:53 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Google
[2014.12.04 01:00:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pong Screensaver
[2014.12.04 00:58:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pong Clock
[2014.12.04 00:07:04 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\Documents\theHunter
[2014.12.04 00:06:57 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\theHunter
[2014.12.04 00:06:56 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\theHunter
[2014.12.04 00:05:11 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\theHunterSteam
[2014.12.03 21:43:26 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Unity
[2014.12.03 21:38:22 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Unity
[2014.12.03 20:50:16 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Macromedia
[2014.12.03 20:50:16 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Adobe
[2014.12.03 20:47:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2014.12.03 20:46:57 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2014.12.03 20:46:27 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Adobe
[2014.12.03 20:40:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2014.12.03 20:30:38 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
[2014.12.03 19:10:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin Games
[2014.12.03 19:08:35 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Roaming\Origin
[2014.12.03 19:08:33 | 000,000,000 | ---D | C] -- C:\Users\LoniVanBuni\AppData\Local\Origin
[2014.12.03 19:06:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2014.12.03 19:05:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2014.12.03 19:05:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin
[2014.12.03 19:05:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts
[2014.12.03 19:02:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2014.12.03 19:02:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2014.12.03 19:02:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.12.10 00:05:49 | 000,000,743 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\Start Emsisoft Emergency Kit.lnk
[2014.12.09 23:50:28 | 000,001,085 | ---- | M] () -- C:\Users\Public\Desktop\Exterminate It!.lnk
[2014.12.09 23:41:03 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.12.09 23:40:58 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.12.09 23:38:00 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.12.09 23:12:37 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.12.09 23:12:37 | 000,021,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.12.09 23:10:57 | 001,614,718 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.12.09 23:10:57 | 000,697,468 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2014.12.09 23:10:57 | 000,652,546 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.12.09 23:10:57 | 000,148,164 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2014.12.09 23:10:57 | 000,120,948 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.12.09 23:03:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.12.09 23:03:27 | 2085,568,511 | -HS- | M] () -- C:\hiberfil.sys
[2014.12.09 21:51:28 | 000,348,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2014.12.09 21:51:28 | 000,348,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014.12.09 21:50:20 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2014.12.09 20:59:01 | 000,000,522 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task d5001a5f-a972-4973-8a0d-87dd2a321522.job
[2014.12.09 19:05:43 | 000,076,152 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014.12.09 10:31:08 | 000,043,064 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2014.12.09 02:00:01 | 000,000,522 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1c850ab7-3c79-44c0-ad21-18ab2de2575a.job
[2014.12.09 01:06:32 | 000,001,139 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2014.12.09 00:21:08 | 000,001,964 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.12.09 00:20:59 | 001,050,432 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2014.12.09 00:20:52 | 000,436,624 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014.12.09 00:20:52 | 000,364,512 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014.12.09 00:20:52 | 000,267,632 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014.12.09 00:20:52 | 000,116,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014.12.09 00:20:52 | 000,083,280 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswmonflt.sys
[2014.12.09 00:20:52 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014.12.09 00:20:52 | 000,029,208 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014.12.09 00:20:51 | 000,093,568 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014.12.09 00:20:51 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014.12.08 22:10:11 | 000,001,106 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.12.08 22:04:11 | 002,119,680 | ---- | M] (Farbar) -- C:\Users\LoniVanBuni\Desktop\FRST64.exe
[2014.12.08 20:33:29 | 003,130,440 | ---- | M] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2014.12.08 11:37:21 | 000,000,220 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\Garry's Mod.url
[2014.12.08 11:33:41 | 000,000,221 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\The Elder Scrolls V Skyrim.url
[2014.12.08 11:33:33 | 000,000,222 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\Unturned.url
[2014.12.08 11:33:29 | 000,000,221 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\Sniper Elite V2.url
[2014.12.08 11:33:22 | 000,000,222 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\Saints Row IV.url
[2014.12.08 11:33:16 | 000,000,222 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\PlanetSide 2.url
[2014.12.08 11:33:11 | 000,000,222 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\Alien Isolation.url
[2014.12.08 11:33:06 | 000,000,222 | ---- | M] () -- C:\Users\LoniVanBuni\Desktop\PAYDAY 2.url
[2014.12.07 15:58:58 | 000,007,605 | ---- | M] () -- C:\Users\LoniVanBuni\AppData\Local\Resmon.ResmonCfg
[2014.12.07 08:39:46 | 000,001,174 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2014.12.07 02:19:19 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2014.12.07 02:16:53 | 000,022,704 | ---- | M] () -- C:\Windows\SysNative\drivers\EsgScanner.sys
[2014.12.07 01:04:20 | 000,001,122 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2014.12.06 18:47:31 | 000,001,971 | ---- | M] () -- C:\Windows\patsearch.bin
[2014.12.06 18:47:31 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstrNewH_01009.Wdf
[2014.12.06 18:47:14 | 000,106,456 | ---- | M] (Corsica) -- C:\Windows\SysNative\drivers\webinstrNewH.sys
[2014.12.06 15:06:38 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014.12.06 00:07:27 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014.12.05 23:56:47 | 000,002,168 | ---- | M] () -- C:\Users\Public\Desktop\Oblivion.lnk
[2014.12.05 22:55:17 | 000,031,913 | ---- | M] () -- C:\Users\LoniVanBuni\Documents\23.wma
[2014.12.05 22:54:59 | 000,031,913 | ---- | M] () -- C:\Users\LoniVanBuni\Documents\Unbenannt.wma
[2014.12.04 23:24:21 | 000,000,099 | ---- | M] () -- C:\Users\LoniVanBuni\AppData\Roaming\LauncherSettings_live.cfg
[2014.12.04 22:37:29 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2014.12.04 19:01:39 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\spu_storage.bin
[2014.12.04 18:45:04 | 001,588,294 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014.12.04 00:06:56 | 000,000,040 | ---- | M] () -- C:\Users\LoniVanBuni\AppData\Roaming\TheHunterSettings_steam_live.cfg
[2014.12.03 19:05:59 | 000,000,983 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2014.12.03 19:02:01 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2014.11.24 10:23:23 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2014.11.24 10:23:22 | 000,131,608 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2014.11.24 10:23:21 | 000,119,272 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2014.11.21 06:14:22 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014.11.21 06:14:12 | 000,093,400 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014.11.21 06:14:08 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.12.10 00:05:49 | 000,000,743 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\Start Emsisoft Emergency Kit.lnk
[2014.12.09 23:58:59 | 000,072,154 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\procexp.chm
[2014.12.09 23:50:28 | 000,001,085 | ---- | C] () -- C:\Users\Public\Desktop\Exterminate It!.lnk
[2014.12.09 01:06:32 | 000,001,139 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2014.12.09 01:06:32 | 000,001,139 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2014.12.09 00:15:24 | 000,001,964 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2014.12.09 00:14:30 | 000,267,632 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014.12.09 00:14:29 | 000,065,776 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014.12.09 00:14:29 | 000,029,208 | ---- | C] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014.12.08 22:10:11 | 000,001,106 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.12.08 20:58:32 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2014.12.08 11:37:21 | 000,000,220 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\Garry's Mod.url
[2014.12.08 11:33:41 | 000,000,221 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\The Elder Scrolls V Skyrim.url
[2014.12.08 11:33:33 | 000,000,222 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\Unturned.url
[2014.12.08 11:33:29 | 000,000,221 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\Sniper Elite V2.url
[2014.12.08 11:33:22 | 000,000,222 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\Saints Row IV.url
[2014.12.08 11:33:16 | 000,000,222 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\PlanetSide 2.url
[2014.12.08 11:33:11 | 000,000,222 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\Alien Isolation.url
[2014.12.08 11:33:06 | 000,000,222 | ---- | C] () -- C:\Users\LoniVanBuni\Desktop\PAYDAY 2.url
[2014.12.07 20:59:22 | 000,000,522 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task d5001a5f-a972-4973-8a0d-87dd2a321522.job
[2014.12.07 20:59:22 | 000,000,522 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 1c850ab7-3c79-44c0-ad21-18ab2de2575a.job
[2014.12.07 15:58:58 | 000,007,605 | ---- | C] () -- C:\Users\LoniVanBuni\AppData\Local\Resmon.ResmonCfg
[2014.12.07 12:05:59 | 000,348,928 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2014.12.07 08:39:46 | 000,001,174 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2014.12.07 08:39:20 | 000,348,928 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014.12.07 08:39:20 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2014.12.07 08:39:19 | 000,076,152 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014.12.07 02:19:19 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2014.12.07 02:16:53 | 000,022,704 | ---- | C] () -- C:\Windows\SysNative\drivers\EsgScanner.sys
[2014.12.07 01:04:20 | 000,001,122 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2014.12.06 18:47:31 | 000,001,971 | ---- | C] () -- C:\Windows\patsearch.bin
[2014.12.06 18:47:31 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstrNewH_01009.Wdf
[2014.12.06 15:06:38 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014.12.06 15:06:01 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2014.12.06 00:07:27 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2014.12.05 23:37:32 | 000,002,168 | ---- | C] () -- C:\Users\Public\Desktop\Oblivion.lnk
[2014.12.05 22:55:17 | 000,031,913 | ---- | C] () -- C:\Users\LoniVanBuni\Documents\23.wma
[2014.12.05 22:54:59 | 000,031,913 | ---- | C] () -- C:\Users\LoniVanBuni\Documents\Unbenannt.wma
[2014.12.04 22:37:29 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2014.12.04 19:01:39 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\spu_storage.bin
[2014.12.04 00:11:47 | 000,000,099 | ---- | C] () -- C:\Users\LoniVanBuni\AppData\Roaming\LauncherSettings_live.cfg
[2014.12.04 00:06:56 | 000,000,040 | ---- | C] () -- C:\Users\LoniVanBuni\AppData\Roaming\TheHunterSettings_steam_live.cfg
[2014.12.03 19:05:59 | 000,000,983 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2014.12.03 19:02:01 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2013.12.03 18:21:43 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.12.03 17:52:27 | 001,588,294 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.12.03 17:49:25 | 000,000,000 | ---- | C] () -- C:\Users\LoniVanBuni\AppData\Local\Driver_LOM_8161Present.flag
[2013.10.08 03:45:08 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.10.08 03:45:08 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.10.08 02:42:12 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.10.08 02:42:12 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.10.07 22:50:56 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010.11.21 04:23:55 | 014,174,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010.11.21 04:24:02 | 012,872,192 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014.12.06 20:45:15 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\.minecraft
[2014.12.09 00:15:29 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\AVAST Software
[2014.12.09 23:51:12 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\Curiolab
[2014.12.07 02:19:05 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\Enigma Software Group
[2014.12.06 20:40:30 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\java
[2014.12.09 01:06:40 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\Opera Software
[2014.12.03 20:43:01 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\Origin
[2014.12.07 19:15:22 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\QuickScan
[2014.12.04 00:06:57 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\theHunter
[2014.12.04 00:05:11 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\theHunterSteam
[2014.12.03 21:43:26 | 000,000,000 | ---D | M] -- C:\Users\LoniVanBuni\AppData\Roaming\Unity
========== Purity Check ==========
< End of report >