![]() |
|
Plagegeister aller Art und deren Bekämpfung: Spiele laufen plötzlich extrem langsamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #3 |
![]() ![]() ![]() | ![]() Spiele laufen plötzlich extrem langsam ui, danke für die schnelle antwort!!
__________________![]() FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013 Ran by Psychochick (administrator) on 15-06-2013 11:50:33 Running from C:\Users\Psychochick\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Telefónica) C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Windows\PLFSetI.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-23] (Alcor Micro Corp.) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9643552 2009-12-11] (Realtek Semiconductor) HKLM\...\Run: [PLFSetI] C:\Windows\PLFSetI.exe [206208 2011-01-20] () HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [325120 2009-10-22] (Alps Electric Co., Ltd.) HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860192 2010-02-05] (Acer Incorporated) HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18678376 2013-04-19] (Skype Technologies S.A.) HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-24] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-01-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [1288784 2010-02-24] (Dritek System Inc.) HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-05-02] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] () HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] () Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: No Name - {326E768D-4182-46FD-9C16-1449A49795F4} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{8CB4D6D6-951B-4BAD-A8B0-444F3751BDC5}: [NameServer]193.189.244.225 193.189.244.206 Tcpip\..\Interfaces\{F4F1CC72-052F-4250-ABA5-EA316A939453}: [NameServer]193.189.244.225 193.189.244.206 FireFox: ======== FF ProfilePath: C:\Users\Psychochick\AppData\Roaming\Mozilla\Firefox\Profiles\qbt8oke0.default FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll No File FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @gametap.com/npdd,version=1.0 - C:\Program Files (x86)\Downloader\npdd.dll (Metaboli) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: No Name - C:\Users\Psychochick\AppData\Roaming\Mozilla\Firefox\Profiles\qbt8oke0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll No File CHR Plugin: ( "name": "",) - C:\Users\Psychochick\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\chromeNPAPI.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Psychochick\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll No File CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (Downloader Detector) - C:\Program Files (x86)\Downloader\npdd.dll (Metaboli) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (AdBlock) - C:\Users\Psychochick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.64_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-03-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-03-27] (Avira Operations GmbH & Co. KG) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.) R2 TGCM_ImportWiFiSvc; C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe [201080 2011-06-14] (Telefónica) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-27] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-27] (Avira Operations GmbH & Co. KG) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.) R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; c:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2010-01-22] (CyberLink Corp.) R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; c:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2010-01-22] (CyberLink Corp.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-15 11:50 - 2013-06-15 11:50 - 00000000 ____D C:\FRST 2013-06-15 11:49 - 2013-06-15 11:49 - 01920398 ____A (Farbar) C:\Users\Psychochick\Downloads\FRST64.exe 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setuperr.log 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setupact.log 2013-06-13 15:50 - 2013-06-13 15:50 - 00002166 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-06-13 15:00 - 2013-06-15 08:34 - 00168346 ____A C:\Windows\WindowsUpdate.log 2013-06-12 16:17 - 2013-05-17 03:25 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-12 16:17 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-12 16:17 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-12 16:17 - 2013-05-17 02:58 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-12 16:17 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-12 16:17 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-12 16:17 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-12 16:17 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 13:15 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 13:14 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 13:14 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 13:14 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 13:14 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 13:14 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 13:14 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 13:14 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 13:14 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 13:14 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 13:14 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 13:14 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 13:14 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 13:14 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 13:14 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-12 13:14 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 13:14 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-12 13:14 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-12 13:14 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-11 19:30 - 2013-06-11 19:31 - 30091776 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-06-11 19:17 - 2013-06-11 19:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-11 19:11 - 2013-06-11 19:37 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Opera 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Local\Opera 2013-06-11 19:09 - 2013-06-11 19:10 - 13168216 ____A (Opera Software ASA) C:\Users\Psychochick\Downloads\Opera_1215_int_Setup.exe 2013-06-11 14:21 - 2013-06-11 14:21 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2013-06-11 14:20 - 2013-06-11 14:20 - 28181408 ____A (TuneUp Software) C:\Users\Psychochick\Downloads\TuneUpUtilities2013_de-DE.exe 2013-06-11 14:11 - 2013-06-11 14:11 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Psychochick\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-06-11 10:35 - 2013-06-11 10:35 - 10255080 ____A (Lavalys, Inc. ) C:\Users\Psychochick\Downloads\everestultimate550.exe 2013-06-11 10:28 - 2013-06-11 10:39 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Systweak 2013-06-11 10:28 - 2013-02-28 16:27 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-06-11 10:27 - 2013-06-11 10:27 - 04326992 ____A (Systweak Inc ) C:\Users\Psychochick\Downloads\rcpsetup_2005.exe 2013-06-10 20:07 - 2013-06-10 20:08 - 51415040 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-06-08 09:16 - 2013-06-08 09:15 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-08 09:15 - 2013-06-08 09:15 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-08 09:13 - 2013-06-08 09:14 - 31666592 ____A (Oracle Corporation) C:\Users\Psychochick\Downloads\jre-7u21-windows-i586.exe 2013-06-03 18:20 - 2013-06-03 18:20 - 00000000 ____D C:\Users\Psychochick\Documents\Podcast Studio 2013-06-03 18:19 - 2013-06-06 12:27 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\concept design 2013-06-03 18:19 - 2013-06-06 12:27 - 00000000 ____D C:\Program Files (x86)\concept design 2013-06-03 18:19 - 2012-03-01 11:08 - 00966144 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioInformation2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00877568 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\NCTAudioFile2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00634880 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioEditor2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00522752 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioTransform2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00467968 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioRecord2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00467456 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioPlayer2.dll 2013-06-03 18:19 - 2012-02-11 21:07 - 00413696 ____A (Gabest) C:\Windows\SysWOW64\flvsplitter.ax 2013-06-03 18:19 - 2011-03-29 12:52 - 00962560 ____A (East Wind Software) C:\Windows\SysWOW64\advdaudio.ocx 2013-06-03 18:19 - 2011-03-29 12:52 - 00110080 ____A C:\Windows\SysWOW64\advd.dll 2013-06-03 18:19 - 2011-03-29 12:52 - 00023040 ____A C:\Windows\SysWOW64\auth.dll 2013-06-03 18:19 - 2003-08-07 14:01 - 00237568 ____A C:\Windows\SysWOW64\lame_enc.dll 2013-06-03 18:16 - 2013-06-03 18:16 - 14157600 ____A (concept/design GmbH ) C:\Users\Psychochick\Downloads\otv8setup84.exe ==================== One Month Modified Files and Folders ======= 2013-06-15 11:50 - 2013-06-15 11:50 - 00000000 ____D C:\FRST 2013-06-15 11:49 - 2013-06-15 11:49 - 01920398 ____A (Farbar) C:\Users\Psychochick\Downloads\FRST64.exe 2013-06-15 11:45 - 2011-01-20 03:19 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Skype 2013-06-15 11:33 - 2013-03-19 11:22 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-15 11:29 - 2011-01-20 03:26 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-15 11:29 - 2011-01-20 03:26 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-15 11:17 - 2013-06-13 15:00 - 00168346 ____A C:\Windows\WindowsUpdate.log 2013-06-15 09:33 - 2009-07-14 06:45 - 00017376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-15 09:33 - 2009-07-14 06:45 - 00017376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setuperr.log 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setupact.log 2013-06-13 15:50 - 2013-06-13 15:50 - 00002166 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-06-13 15:50 - 2013-03-19 11:22 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-13 15:50 - 2013-03-10 11:27 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-13 15:50 - 2011-01-22 13:59 - 00000000 ____D C:\Users\Psychochick\AppData\Local\Adobe 2013-06-13 15:00 - 2011-01-20 14:22 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Winamp 2013-06-13 14:58 - 2011-02-01 16:35 - 00004362 ____A C:\Windows\cdplayer.ini 2013-06-13 14:56 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-12 16:25 - 2009-07-27 22:41 - 00000000 ____D C:\Windows\Panther 2013-06-12 16:20 - 2010-02-11 04:19 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-06-12 16:17 - 2011-01-21 13:47 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 19:37 - 2013-06-11 19:11 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-11 19:31 - 2013-06-11 19:30 - 30091776 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-06-11 19:17 - 2013-06-11 19:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-11 19:17 - 2011-01-20 13:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Opera 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Local\Opera 2013-06-11 19:10 - 2013-06-11 19:09 - 13168216 ____A (Opera Software ASA) C:\Users\Psychochick\Downloads\Opera_1215_int_Setup.exe 2013-06-11 14:21 - 2013-06-11 14:21 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2013-06-11 14:20 - 2013-06-11 14:20 - 28181408 ____A (TuneUp Software) C:\Users\Psychochick\Downloads\TuneUpUtilities2013_de-DE.exe 2013-06-11 14:11 - 2013-06-11 14:11 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Psychochick\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-06-11 10:39 - 2013-06-11 10:28 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Systweak 2013-06-11 10:37 - 2012-11-12 21:38 - 00000000 ____D C:\Program Files (x86)\Lavalys 2013-06-11 10:35 - 2013-06-11 10:35 - 10255080 ____A (Lavalys, Inc. ) C:\Users\Psychochick\Downloads\everestultimate550.exe 2013-06-11 10:27 - 2013-06-11 10:27 - 04326992 ____A (Systweak Inc ) C:\Users\Psychochick\Downloads\rcpsetup_2005.exe 2013-06-10 20:08 - 2013-06-10 20:07 - 51415040 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-06-08 09:15 - 2013-06-08 09:16 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-08 09:15 - 2013-06-08 09:15 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-08 09:15 - 2012-05-28 16:37 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-06-08 09:15 - 2011-11-06 14:09 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-06-08 09:14 - 2013-06-08 09:13 - 31666592 ____A (Oracle Corporation) C:\Users\Psychochick\Downloads\jre-7u21-windows-i586.exe 2013-06-06 12:27 - 2013-06-03 18:19 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\concept design 2013-06-06 12:27 - 2013-06-03 18:19 - 00000000 ____D C:\Program Files (x86)\concept design 2013-06-03 18:20 - 2013-06-03 18:20 - 00000000 ____D C:\Users\Psychochick\Documents\Podcast Studio 2013-06-03 18:16 - 2013-06-03 18:16 - 14157600 ____A (concept/design GmbH ) C:\Users\Psychochick\Downloads\otv8setup84.exe 2013-05-20 07:56 - 2011-01-20 03:19 - 00000000 ____D C:\ProgramData\Skype 2013-05-19 15:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-05-17 03:25 - 2013-06-12 16:17 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-05-17 02:59 - 2013-06-12 16:17 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-17 02:59 - 2013-06-12 16:17 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-17 02:58 - 2013-06-12 16:17 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-05-16 10:58 - 2009-07-14 06:45 - 00427872 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-16 10:31 - 2011-01-20 11:20 - 00654400 ____A C:\Windows\System32\perfh007.dat 2013-05-16 10:31 - 2011-01-20 11:20 - 00130240 ____A C:\Windows\System32\perfc007.dat 2013-05-16 10:31 - 2009-07-14 07:13 - 01520734 ____A C:\Windows\System32\PerfStringBackup.INI ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-08 19:34 ==================== End Of Log ============================ --- --- --- --- --- --- FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-06-2013 Ran by Psychochick (administrator) on 15-06-2013 11:50:33 Running from C:\Users\Psychochick\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Telefónica) C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe (Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Windows\PLFSetI.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-23] (Alcor Micro Corp.) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [9643552 2009-12-11] (Realtek Semiconductor) HKLM\...\Run: [PLFSetI] C:\Windows\PLFSetI.exe [206208 2011-01-20] () HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [325120 2009-10-22] (Alps Electric Co., Ltd.) HKLM\...\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860192 2010-02-05] (Acer Incorporated) HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18678376 2013-04-19] (Skype Technologies S.A.) HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-24] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-01-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe [1288784 2010-02-24] (Dritek System Inc.) HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-05-02] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] () HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [154144 2010-01-15] () Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: No Name - {326E768D-4182-46FD-9C16-1449A49795F4} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{8CB4D6D6-951B-4BAD-A8B0-444F3751BDC5}: [NameServer]193.189.244.225 193.189.244.206 Tcpip\..\Interfaces\{F4F1CC72-052F-4250-ABA5-EA316A939453}: [NameServer]193.189.244.225 193.189.244.206 FireFox: ======== FF ProfilePath: C:\Users\Psychochick\AppData\Roaming\Mozilla\Firefox\Profiles\qbt8oke0.default FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll No File FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @gametap.com/npdd,version=1.0 - C:\Program Files (x86)\Downloader\npdd.dll (Metaboli) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: No Name - C:\Users\Psychochick\AppData\Roaming\Mozilla\Firefox\Profiles\qbt8oke0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_257.dll No File CHR Plugin: ( "name": "",) - C:\Users\Psychochick\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\chromeNPAPI.dll No File CHR Plugin: (Skype Toolbars) - C:\Users\Psychochick\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll No File CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (Downloader Detector) - C:\Program Files (x86)\Downloader\npdd.dll (Metaboli) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (AdBlock) - C:\Users\Psychochick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.64_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-03-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-03-27] (Avira Operations GmbH & Co. KG) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.) R2 TGCM_ImportWiFiSvc; C:\Program Files (x86)\o2\Mobile Connection Manager\ImpWiFiSvc.exe [201080 2011-06-14] (Telefónica) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-27] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-03-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-03-27] (Avira Operations GmbH & Co. KG) S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.) R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; c:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2010-01-22] (CyberLink Corp.) R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; c:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2010-01-22] (CyberLink Corp.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-15 11:50 - 2013-06-15 11:50 - 00000000 ____D C:\FRST 2013-06-15 11:49 - 2013-06-15 11:49 - 01920398 ____A (Farbar) C:\Users\Psychochick\Downloads\FRST64.exe 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setuperr.log 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setupact.log 2013-06-13 15:50 - 2013-06-13 15:50 - 00002166 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-06-13 15:00 - 2013-06-15 08:34 - 00168346 ____A C:\Windows\WindowsUpdate.log 2013-06-12 16:17 - 2013-05-17 03:25 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-12 16:17 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-12 16:17 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-12 16:17 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-12 16:17 - 2013-05-17 02:58 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-12 16:17 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-12 16:17 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-12 16:17 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-12 16:17 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-12 16:17 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 13:15 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 13:14 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 13:14 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 13:14 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 13:14 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 13:14 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 13:14 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 13:14 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 13:14 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 13:14 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 13:14 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 13:14 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 13:14 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 13:14 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 13:14 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-12 13:14 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 13:14 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-12 13:14 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-12 13:14 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-11 19:30 - 2013-06-11 19:31 - 30091776 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-06-11 19:17 - 2013-06-11 19:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-11 19:11 - 2013-06-11 19:37 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Opera 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Local\Opera 2013-06-11 19:09 - 2013-06-11 19:10 - 13168216 ____A (Opera Software ASA) C:\Users\Psychochick\Downloads\Opera_1215_int_Setup.exe 2013-06-11 14:21 - 2013-06-11 14:21 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2013-06-11 14:20 - 2013-06-11 14:20 - 28181408 ____A (TuneUp Software) C:\Users\Psychochick\Downloads\TuneUpUtilities2013_de-DE.exe 2013-06-11 14:11 - 2013-06-11 14:11 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Psychochick\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-06-11 10:35 - 2013-06-11 10:35 - 10255080 ____A (Lavalys, Inc. ) C:\Users\Psychochick\Downloads\everestultimate550.exe 2013-06-11 10:28 - 2013-06-11 10:39 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Systweak 2013-06-11 10:28 - 2013-02-28 16:27 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-06-11 10:27 - 2013-06-11 10:27 - 04326992 ____A (Systweak Inc ) C:\Users\Psychochick\Downloads\rcpsetup_2005.exe 2013-06-10 20:07 - 2013-06-10 20:08 - 51415040 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-06-08 09:16 - 2013-06-08 09:15 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-08 09:15 - 2013-06-08 09:15 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-08 09:13 - 2013-06-08 09:14 - 31666592 ____A (Oracle Corporation) C:\Users\Psychochick\Downloads\jre-7u21-windows-i586.exe 2013-06-03 18:20 - 2013-06-03 18:20 - 00000000 ____D C:\Users\Psychochick\Documents\Podcast Studio 2013-06-03 18:19 - 2013-06-06 12:27 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\concept design 2013-06-03 18:19 - 2013-06-06 12:27 - 00000000 ____D C:\Program Files (x86)\concept design 2013-06-03 18:19 - 2012-03-01 11:08 - 00966144 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioInformation2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00877568 ____A (NCT Company Ltd.) C:\Windows\SysWOW64\NCTAudioFile2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00634880 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioEditor2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00522752 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioTransform2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00467968 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioRecord2.dll 2013-06-03 18:19 - 2012-03-01 11:08 - 00467456 ____A (Online Media Technologies Ltd.) C:\Windows\SysWOW64\NCTAudioPlayer2.dll 2013-06-03 18:19 - 2012-02-11 21:07 - 00413696 ____A (Gabest) C:\Windows\SysWOW64\flvsplitter.ax 2013-06-03 18:19 - 2011-03-29 12:52 - 00962560 ____A (East Wind Software) C:\Windows\SysWOW64\advdaudio.ocx 2013-06-03 18:19 - 2011-03-29 12:52 - 00110080 ____A C:\Windows\SysWOW64\advd.dll 2013-06-03 18:19 - 2011-03-29 12:52 - 00023040 ____A C:\Windows\SysWOW64\auth.dll 2013-06-03 18:19 - 2003-08-07 14:01 - 00237568 ____A C:\Windows\SysWOW64\lame_enc.dll 2013-06-03 18:16 - 2013-06-03 18:16 - 14157600 ____A (concept/design GmbH ) C:\Users\Psychochick\Downloads\otv8setup84.exe ==================== One Month Modified Files and Folders ======= 2013-06-15 11:50 - 2013-06-15 11:50 - 00000000 ____D C:\FRST 2013-06-15 11:49 - 2013-06-15 11:49 - 01920398 ____A (Farbar) C:\Users\Psychochick\Downloads\FRST64.exe 2013-06-15 11:45 - 2011-01-20 03:19 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Skype 2013-06-15 11:33 - 2013-03-19 11:22 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-15 11:29 - 2011-01-20 03:26 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-15 11:29 - 2011-01-20 03:26 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-15 11:17 - 2013-06-13 15:00 - 00168346 ____A C:\Windows\WindowsUpdate.log 2013-06-15 09:33 - 2009-07-14 06:45 - 00017376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-15 09:33 - 2009-07-14 06:45 - 00017376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setuperr.log 2013-06-15 09:13 - 2013-06-15 09:13 - 00000000 ____A C:\Windows\setupact.log 2013-06-13 15:50 - 2013-06-13 15:50 - 00002166 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-06-13 15:50 - 2013-06-13 15:50 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-06-13 15:50 - 2013-03-19 11:22 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-13 15:50 - 2013-03-10 11:27 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-13 15:50 - 2011-01-22 13:59 - 00000000 ____D C:\Users\Psychochick\AppData\Local\Adobe 2013-06-13 15:00 - 2011-01-20 14:22 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Winamp 2013-06-13 14:58 - 2011-02-01 16:35 - 00004362 ____A C:\Windows\cdplayer.ini 2013-06-13 14:56 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-12 16:25 - 2009-07-27 22:41 - 00000000 ____D C:\Windows\Panther 2013-06-12 16:20 - 2010-02-11 04:19 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-06-12 16:17 - 2011-01-21 13:47 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 19:37 - 2013-06-11 19:11 - 00000000 ____D C:\Program Files (x86)\Opera 2013-06-11 19:31 - 2013-06-11 19:30 - 30091776 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-06-11 19:17 - 2013-06-11 19:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-11 19:17 - 2011-01-20 13:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Opera 2013-06-11 19:11 - 2013-06-11 19:11 - 00000000 ____D C:\Users\Psychochick\AppData\Local\Opera 2013-06-11 19:10 - 2013-06-11 19:09 - 13168216 ____A (Opera Software ASA) C:\Users\Psychochick\Downloads\Opera_1215_int_Setup.exe 2013-06-11 14:21 - 2013-06-11 14:21 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2013-06-11 14:20 - 2013-06-11 14:20 - 28181408 ____A (TuneUp Software) C:\Users\Psychochick\Downloads\TuneUpUtilities2013_de-DE.exe 2013-06-11 14:11 - 2013-06-11 14:11 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Psychochick\Downloads\mbam-setup-1.75.0.1300 (1).exe 2013-06-11 10:39 - 2013-06-11 10:28 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\Systweak 2013-06-11 10:37 - 2012-11-12 21:38 - 00000000 ____D C:\Program Files (x86)\Lavalys 2013-06-11 10:35 - 2013-06-11 10:35 - 10255080 ____A (Lavalys, Inc. ) C:\Users\Psychochick\Downloads\everestultimate550.exe 2013-06-11 10:27 - 2013-06-11 10:27 - 04326992 ____A (Systweak Inc ) C:\Users\Psychochick\Downloads\rcpsetup_2005.exe 2013-06-10 20:08 - 2013-06-10 20:07 - 51415040 ____A (Microsoft Corporation) C:\Users\Psychochick\Downloads\IE10-Windows6.1-x64-de-de_b16521.exe 2013-06-08 09:15 - 2013-06-08 09:16 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-08 09:15 - 2013-06-08 09:15 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-08 09:15 - 2013-06-08 09:15 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-08 09:15 - 2012-05-28 16:37 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-06-08 09:15 - 2011-11-06 14:09 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-06-08 09:14 - 2013-06-08 09:13 - 31666592 ____A (Oracle Corporation) C:\Users\Psychochick\Downloads\jre-7u21-windows-i586.exe 2013-06-06 12:27 - 2013-06-03 18:19 - 00000000 ____D C:\Users\Psychochick\AppData\Roaming\concept design 2013-06-06 12:27 - 2013-06-03 18:19 - 00000000 ____D C:\Program Files (x86)\concept design 2013-06-03 18:20 - 2013-06-03 18:20 - 00000000 ____D C:\Users\Psychochick\Documents\Podcast Studio 2013-06-03 18:16 - 2013-06-03 18:16 - 14157600 ____A (concept/design GmbH ) C:\Users\Psychochick\Downloads\otv8setup84.exe 2013-05-20 07:56 - 2011-01-20 03:19 - 00000000 ____D C:\ProgramData\Skype 2013-05-19 15:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-05-17 03:25 - 2013-06-12 16:17 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-17 03:25 - 2013-06-12 16:17 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-05-17 02:59 - 2013-06-12 16:17 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-17 02:59 - 2013-06-12 16:17 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-17 02:58 - 2013-06-12 16:17 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-17 02:58 - 2013-06-12 16:17 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-05-16 10:58 - 2009-07-14 06:45 - 00427872 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-16 10:31 - 2011-01-20 11:20 - 00654400 ____A C:\Windows\System32\perfh007.dat 2013-05-16 10:31 - 2011-01-20 11:20 - 00130240 ____A C:\Windows\System32\perfc007.dat 2013-05-16 10:31 - 2009-07-14 07:13 - 01520734 ____A C:\Windows\System32\PerfStringBackup.INI ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-08 19:34 ==================== End Of Log ============================ --- --- --- |
Themen zu Spiele laufen plötzlich extrem langsam |
acer, acer aspire, adobe, adobe flash player, arbeitsspeicher, ccleaner, explorer, firefox, flash player, google, grafikkarte, internet explorer, java, langsam, malware, mozilla, neues, player, plötzlich, programm, seite, spiele, spielen, treiber, virus, windows, windows 7 |