|
Plagegeister aller Art und deren Bekämpfung: Anchor.hss Was ist das?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.06.2013, 17:45 | #1 |
| Anchor.hss Was ist das? Hi, ich habe grade Spybot laufen gelassen und habe einen Eintrag gefunden : Anchor.hss war unter der Kategorie Pupsc. Da ich weder im Internet noch hier im Forum was gefunden habe: Was ist das? Hatte nur ein Verzeichnis Ordner "open candy" ,den Spybot auch gelöscht hat. Könnte es damit zusammen hängen, dass ich vor einigen Monaten Win32.Downloader.gen hatte? MfG |
20.06.2013, 17:46 | #2 |
/// the machine /// TB-Ausbilder | Anchor.hss Was ist das? Hi,
__________________Logfile von Spybot? Oder soll ich die Glaskugel auspacken und raten?
__________________ |
20.06.2013, 17:59 | #3 |
| Anchor.hss Was ist das? Bin wohl grade auf reset Lists gekommen...
__________________Kann ich die sonst noch irgendwo einsehen? Ich mache grade nochmal ein Durchlauf, vlt findet er ja wieder was.. Nein anscheinend ist es nun weg..Gab kein Ergebnis beim erneuten Durchlauf.. Kann man das in irgendeine Kategorie fassen? Falls was ernstes ist, würde ich Win neu aufsetzten... |
20.06.2013, 18:22 | #4 |
/// the machine /// TB-Ausbilder | Anchor.hss Was ist das? Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.06.2013, 18:27 | #5 |
| Anchor.hss Was ist das?FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-06-2013 01 Ran by Tobias (administrator) on 20-06-2013 19:25:02 Running from C:\Users\Tobias\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Program Files (x86)\CPUCooL\CooLSrv.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Windows\system32\inetsrv\inetinfo.exe (Microsoft Corporation) C:\Windows\system32\mqsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Microsoft Corporation) C:\Windows\system32\mqtgsvc.exe (Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (PANTERASoft) C:\Program Files (x86)\HDD Health\hddhealth.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Dropbox, Inc.) C:\Users\Tobias\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Program Files\Rainmeter\Rainmeter.exe (Game Inc.) C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11776104 2011-02-11] (Realtek Semiconductor) HKLM\...\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [7406392 2012-11-29] (Logitech Inc.) HKLM\...\Run: [MsmqIntCert] regsvr32 /s mqrt.dll [x] HKLM\...\RunOnce: [RPMKickstart] C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.) HKCU\...\Run: [HDDHealth] C:\Program Files (x86)\HDD Health\hddhealth.exe -wl [1687552 2008-04-12] (PANTERASoft) HKCU\...\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GamingKeyboard] "C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe" [1803264 2012-06-07] (Game Inc.) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [250504 2013-02-10] (NVIDIA Corporation) Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tobias\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - {D985E0F7-5C0C-4dc8-A1E9-164E32C8BF71} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV BHO: GBHO.BHO - {45d30484-7ded-43d9-957a-d2fd1f046511} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default FF SelectedSearchEngine: Google FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.118.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.140.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: WOT - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: jid1-qQSMEVsYTOjgYA - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\jid1-qQSMEVsYTOjgYA@jetpack.xpi FF Extension: personas - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\personas@christopher.beard.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 CPUCooLServer; C:\Program Files (x86)\CPUCooL\CooLSrv.exe [743936 2011-12-01] () R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [678416 2012-11-14] () R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-20] (Microsoft Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-10-16] () R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S3 AQFileRestore; C:\Windows\System32\DRIVERS\AQFileRestore.sys [21040 2012-01-13] () S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-26] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-26] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-16] (Symantec Corporation) R2 ESLWireAC; C:\Windows\system32\drivers\ESLWireACD.sys [160784 2012-11-14] (<Turtle Entertainment>) S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-07] (Windows (R) Server 2003 DDK provider) S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-07] (Windows (R) Server 2003 DDK provider) S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH) S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-25] (AVM GmbH) R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () R3 gdrv; C:\Windows\gdrv.sys [25640 2013-06-20] (Windows (R) Server 2003 DDK provider) R3 gdrv; C:\Windows\gdrv.sys [25640 2013-06-20] (Windows (R) Server 2003 DDK provider) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-06-07] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-06-07] () R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys [513184 2013-01-04] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys [513184 2013-01-04] (Symantec Corporation) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66360 2012-10-03] (Logitech Inc.) S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [43832 2012-10-03] (Logitech Inc.) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\ENG64.SYS [126040 2013-05-22] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\ENG64.SYS [126040 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\EX64.SYS [2098776 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\EX64.SYS [2098776 2013-05-22] (Symantec Corporation) R1 ntiopnp; C:\Windows\System32\Drivers\ntiopnp.sys [19544 2010-11-11] () R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) S3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 MSICDSetup; \??\D:\CDriver64.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-20 19:24 - 2013-06-20 19:24 - 01929538 ____A (Farbar) C:\Users\Tobias\Desktop\FRST64.exe 2013-06-20 19:24 - 2013-06-20 19:24 - 00000000 ____D C:\FRST 2013-06-20 18:23 - 2013-04-04 18:10 - 00445511 ____A C:\Windows\System32\Drivers\etc\hosts.20130620-182311.backup 2013-06-20 17:59 - 2013-06-20 18:00 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-06-17 19:21 - 2013-06-17 19:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-06-17 19:20 - 2013-06-17 19:20 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 15:45 - 2013-06-17 15:45 - 03839648 ____A (Piriform Ltd) C:\Users\Tobias\Desktop\dfsetup214.exe 2013-06-12 09:49 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 09:49 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 09:49 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 09:49 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 09:49 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 09:49 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 09:49 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 09:49 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 09:49 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 09:49 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-09 22:22 - 2013-06-09 22:22 - 00000000 ____D C:\ProgramData\Codemasters 2013-06-07 15:10 - 2013-06-12 11:37 - 00000000 ____D C:\Users\Tobias\Documents\Password Depot 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\AceBIT 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Program Files (x86)\AceBIT 2013-06-07 15:10 - 2009-08-13 17:07 - 00729424 ____A (WeOnlyDo Software) C:\Windows\SysWOW64\wodSFTP.dll 2013-06-07 15:10 - 2009-08-13 17:07 - 00672024 ____A (WeOnlyDo! COM) C:\Windows\SysWOW64\wodKeys.dll 2013-06-07 13:52 - 2013-06-07 16:16 - 00000000 ____D C:\ProgramData\Avanquest 2013-06-07 13:52 - 2013-06-07 13:52 - 00000000 ____D C:\Program Files (x86)\Avanquest 2013-06-07 13:52 - 2012-01-13 13:48 - 00021040 ____N C:\Windows\System32\Drivers\AQFileRestore.sys 2013-06-07 13:22 - 2013-06-07 13:22 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\etdrv.sys 2013-06-02 20:21 - 2013-06-02 20:21 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-05-27 09:51 - 2013-05-27 09:51 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-05-26 21:42 - 2013-06-09 22:22 - 00000000 ____D C:\Users\Tobias\Documents\My Games 2013-05-24 11:22 - 2013-05-24 11:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-06-20 19:24 - 2013-06-20 19:24 - 01929538 ____A (Farbar) C:\Users\Tobias\Desktop\FRST64.exe 2013-06-20 19:24 - 2013-06-20 19:24 - 00000000 ____D C:\FRST 2013-06-20 19:11 - 2012-09-02 17:54 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-20 18:21 - 2012-01-20 22:27 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-06-20 18:18 - 2012-11-19 16:29 - 00000000 ____D C:\Program Files (x86)\Steam 2013-06-20 18:06 - 2013-02-18 11:01 - 02023619 ____A C:\Windows\WindowsUpdate.log 2013-06-20 18:06 - 2012-07-10 21:58 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\TS3Client 2013-06-20 18:06 - 2012-04-16 21:18 - 00000000 ____D C:\Users\Tobias\AppData\Local\LogMeIn Hamachi 2013-06-20 18:06 - 2012-01-20 07:20 - 00000000 ____D C:\Windows\Panther 2013-06-20 18:00 - 2013-06-20 17:59 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-06-20 17:56 - 2012-01-25 20:26 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\DVDVideoSoft 2013-06-20 17:40 - 2012-01-22 18:41 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Skype 2013-06-20 17:05 - 2012-01-20 00:49 - 00000000 ___RD C:\Users\Tobias\Desktop\Anderes 2013-06-20 16:52 - 2009-07-14 06:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-20 16:52 - 2009-07-14 06:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-20 16:47 - 2012-01-23 20:29 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Dropbox 2013-06-20 16:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\inetsrv 2013-06-20 16:46 - 2012-01-23 20:31 - 00000000 ___RD C:\Users\Tobias\Desktop\Dropbox 2013-06-20 16:45 - 2012-01-20 19:21 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-06-20 16:45 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-20 16:44 - 2012-10-17 00:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-06-19 13:25 - 2012-03-22 13:32 - 00000000 ____D C:\Windows\System32\Drivers\N360x64 2013-06-19 10:44 - 2012-03-22 13:33 - 00177312 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS 2013-06-19 10:44 - 2012-03-22 13:33 - 00007631 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT 2013-06-18 11:50 - 2012-01-20 22:48 - 00000000 ____D C:\Program Files (x86)\Origin 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\zh-HK 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\tr-TR 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-06-17 19:38 - 2012-01-21 00:08 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-06-17 19:21 - 2013-06-17 19:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-06-17 19:20 - 2013-06-17 19:20 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 18:49 - 2012-03-21 11:04 - 00000000 ____D C:\Users\Tobias\Desktop\Uni 2013-06-17 15:45 - 2013-06-17 15:45 - 03839648 ____A (Piriform Ltd) C:\Users\Tobias\Desktop\dfsetup214.exe 2013-06-17 15:40 - 2012-01-20 22:33 - 00000000 ____D C:\Users\Tobias\Desktop\Spiele 2013-06-14 22:23 - 2012-01-20 00:45 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-06-14 21:58 - 2012-01-21 00:30 - 00291088 ____A C:\Windows\SysWOW64\PnkBstrB.xtr 2013-06-14 21:58 - 2012-01-20 23:34 - 00291088 ____A C:\Windows\SysWOW64\PnkBstrB.exe 2013-06-14 21:58 - 2012-01-20 23:34 - 00280904 ____A C:\Windows\SysWOW64\PnkBstrB.ex0 2013-06-12 11:37 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\Documents\Password Depot 2013-06-12 11:21 - 2012-01-30 18:12 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 23:11 - 2012-09-02 17:54 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-11 23:11 - 2012-09-02 17:54 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-09 22:22 - 2013-06-09 22:22 - 00000000 ____D C:\ProgramData\Codemasters 2013-06-09 22:22 - 2013-05-26 21:42 - 00000000 ____D C:\Users\Tobias\Documents\My Games 2013-06-07 16:17 - 2012-01-29 23:04 - 00000000 ____D C:\Users\Tobias\AppData\Local\CrashDumps 2013-06-07 16:16 - 2013-06-07 13:52 - 00000000 ____D C:\ProgramData\Avanquest 2013-06-07 16:15 - 2012-01-20 00:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-07 15:43 - 2012-01-20 19:21 - 00030528 ____A C:\Windows\GVTDrv64.sys 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\AceBIT 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Program Files (x86)\AceBIT 2013-06-07 13:52 - 2013-06-07 13:52 - 00000000 ____D C:\Program Files (x86)\Avanquest 2013-06-07 13:29 - 2012-12-18 14:55 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys 2013-06-07 13:22 - 2013-06-07 13:22 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\etdrv.sys 2013-06-06 18:56 - 2012-01-20 22:25 - 00000000 ____D C:\Program Files\CCleaner 2013-06-02 20:21 - 2013-06-02 20:21 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-02 20:21 - 2012-01-22 18:41 - 00000000 ____D C:\ProgramData\Skype 2013-05-28 17:40 - 2012-01-20 22:33 - 00000000 ____D C:\Users\Tobias\Desktop\Tobias 2013-05-28 14:45 - 2009-07-14 19:58 - 00790852 ____A C:\Windows\System32\perfh007.dat 2013-05-28 14:45 - 2009-07-14 19:58 - 00182760 ____A C:\Windows\System32\perfc007.dat 2013-05-28 14:45 - 2009-07-14 07:13 - 01852714 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-27 09:51 - 2013-05-27 09:51 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-05-27 09:51 - 2012-04-24 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-05-24 11:22 - 2013-05-24 11:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-22 18:54 - 2012-01-20 23:05 - 00000000 ____D C:\Program Files (x86)\Games 2013-05-22 18:50 - 2012-05-07 16:46 - 00000000 ____D C:\Users\Tobias\Documents\KONAMI 2013-05-22 18:50 - 2012-05-06 23:34 - 00000000 ____D C:\ProgramData\KONAMI 2013-05-21 17:25 - 2012-04-17 11:31 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\.minecraft ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-04-16 00:52 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-06-2013 01 Ran by Tobias at 2013-06-20 19:25:23 Run: Running from C:\Users\Tobias\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= @BIOS (Version: 2.12) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader XI (11.0.03) - Deutsch (Version: 11.0.03) Advanced Tactical Center™ 1.12 (Version: 1.1.2.0) AirPlus G (Version: 1.0.22) AutoGreen B10.1021.1 (Version: 1.00.0000) Bandicam (Version: 1.8.6.321) Bandisoft MPEG-1 Decoder Battlefield 3™ (Version: 1.4.0.0) Battlelog Web Plugins (Version: 2.1.7) BF3 Settings Editor (Version: 2.3) CCleaner (Version: 4.02) CDBurnerXP (Version: 4.4.0.2905) Chivalry: Medieval Warfare Cisco AnyConnect Secure Mobility Client (Version: 3.1.02026) Cisco AnyConnect Secure Mobility Client (Version: 3.1.02026) CPUCooL (remove only) Creative Systeminformationen (Version: 1.10) Dropbox (Version: 2.0.22) Easy Tune 6 B11.0512.1 (Version: 1.00.0000) ESET Online Scanner v3 ESL Wire 1.15 ESN Sonar (Version: 0.70.4) GRID 2 HD Tune 2.55 HDD Health v3.3 Beta ICQ7.7 (Version: 7.7) Intel(R) Control Center (Version: 1.2.1.1007) Intel(R) Management Engine Components (Version: 7.0.0.1118) Intel(R) Processor Graphics (Version: 8.15.10.2361) Java 7 Update 21 (64-bit) (Version: 7.0.210) Logitech Gaming Software (Version: 8.40.83) Logitech Gaming Software 5.10 (Version: 5.10.127) Logitech Gaming Software 8.40 (Version: 8.40.83) LogMeIn Hamachi (Version: 2.1.0.362) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Office Word Viewer 2003 (Version: 11.0.8173.0) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319) Mozilla Firefox 21.0 (x86 en-US) (Version: 21.0) Mozilla Maintenance Service (Version: 21.0) MSI Afterburner 2.1.0 (Version: 2.1.0) NBA 2K13 Norton 360 (Version: 20.4.0.40) Notepad++ (Version: 6.1) NVIDIA 3D Vision Controller-Treiber 314.07 (Version: 314.07) NVIDIA 3D Vision Treiber 314.07 (Version: 314.07) NVIDIA Grafiktreiber 314.07 (Version: 314.07) NVIDIA HD-Audiotreiber 1.3.23.1 (Version: 1.3.23.1) NVIDIA PhysX (Version: 9.12.1031) NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031) NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1407) NVIDIA Update 1.12.12 (Version: 1.12.12) ON_OFF Charge B11.0110.1 (Version: 1.00.0001) Origin (Version: 8.5.0.4550) Password Depot 6 (Version: 6.2.4) PDF-Viewer (Version: 2.5.210.0) Pro Evolution Soccer 2013 (Version: 1.00.0000) PunkBuster Services (Version: 0.991) Rainmeter (Version: 2.4 beta r1623) Realtek Ethernet Controller Driver (Version: 7.38.113.2011) Realtek High Definition Audio Driver (Version: 6.0.1.6307) Security Task Manager 1.8d (Version: 1.8d) SHARKOON Skiller (Version: 1.00.0000) Skype™ 6.3 (Version: 6.3.107) Smart 6 B11.0512.1 (Version: 1.00.0000) SopCast 3.5.0 (Version: 3.5.0) Sound Blaster Tactic(3D) Sigma (Version: 1.0) Spybot - Search & Destroy (Version: 1.6.2) Steam (Version: 1.0.0.0) swMSM (Version: 12.0.0.1) TeamSpeak 3 Client (Version: 3.0.10.1) TeamViewer 7 (Version: 7.0.14563) Trials Evolution Gold Edition (Version: 1.0.0.2) Uplay (Version: 2.0) VLC media player 1.1.11 (Version: 1.1.11) WinRAR 4.10 (64-Bit) (Version: 4.10.0) ==================== Restore Points ========================= 07-06-2013 12:56:28 Removed Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 07-06-2013 12:56:55 Removed Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 07-06-2013 13:50:37 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 07-06-2013 13:51:15 Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 07-06-2013 13:51:34 Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 07-06-2013 13:52:03 Microsoft Visual C++ 2005 Redistributable (x64) wird entfernt 07-06-2013 13:56:34 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 07-06-2013 13:57:35 Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 07-06-2013 13:58:03 Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 07-06-2013 13:59:21 Microsoft Visual C++ 2005 Redistributable wird entfernt 07-06-2013 14:01:18 Microsoft Visual C++ 2005 Redistributable (x64) wird entfernt 07-06-2013 14:02:21 Microsoft Visual C++ 2005 Redistributable wird entfernt 07-06-2013 15:04:42 Windows Update 07-06-2013 18:16:43 Windows Update 12-06-2013 09:20:52 Windows Update 17-06-2013 17:18:01 Windows Update ==================== Hosts content: ========================== # Start of entries inserted by Spybot - Search & Destroy # This list is Copyright 2000-2008 Safer Networking Limited # End of entries inserted by Spybot - Search & Destroy 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com There are more than 1000 lines starting with "127.0.0.1" ==================== Scheduled Tasks (whitelisted) ============= Task: {4A5ED360-FE4B-4CF1-BB25-33B9E7809045} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {630EDF6F-85EC-485A-928D-7E604F9AC585} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation) Task: {66146BE9-EED1-44ED-97E2-EC8017BEA196} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11] (Adobe Systems Incorporated) Task: {6C7A67C5-6AEE-41AD-BC4C-EE054BF242DF} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation) Task: {6D3A0321-4CE6-424E-82CF-6E516AF0BA50} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd) Task: {C1094D45-BA8F-4687-90C1-74244DFD2588} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {DD500CC4-9BCE-4492-BC46-5B132C5564CC} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Realtek PCIe GBE Family Controller Description: Realtek PCIe GBE Family Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Service: RTL8167 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (06/20/2013 04:45:55 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/20/2013 11:51:28 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/19/2013 01:25:23 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/19/2013 10:24:13 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/18/2013 11:38:44 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/18/2013 09:08:57 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/17/2013 06:48:54 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/17/2013 03:15:05 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/15/2013 09:08:17 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (06/14/2013 09:10:44 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (06/20/2013 06:05:35 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (06/20/2013 06:05:34 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (06/20/2013 04:47:26 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (06/20/2013 04:47:22 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (06/20/2013 04:47:22 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/20/2013 04:46:23 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (06/20/2013 04:43:38 PM) (Source: DCOM) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (06/20/2013 04:22:16 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (06/20/2013 04:22:14 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Error: (06/20/2013 02:59:33 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80070422 Microsoft Office Sessions: ========================= Error: (06/20/2013 04:45:55 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/20/2013 11:51:28 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/19/2013 01:25:23 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/19/2013 10:24:13 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/18/2013 11:38:44 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/18/2013 09:08:57 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/17/2013 06:48:54 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/17/2013 03:15:05 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/15/2013 09:08:17 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe Error: (06/14/2013 09:10:44 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"C:\Program Files\Logitech\Gaming Software\LWEMon.exe CodeIntegrity Errors: =================================== Date: 2013-04-03 14:39:08.968 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-04-03 14:39:08.922 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 35% Total physical RAM: 8109.18 MB Available physical RAM: 5264.05 MB Total Pagefile: 16216.54 MB Available Pagefile: 13251.3 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:698.54 GB) (Free:193.26 GB) NTFS (Disk=0 Partition=2) Drive d: (PES2013_R2) (CDROM) (Total:6.07 GB) (Free:0 GB) UDF Drive e: (Externe Festplatte) (Fixed) (Total:1863.02 GB) (Free:1230.1 GB) NTFS (Disk=1 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: FAE02DB5) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=699 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 1863 GB) (Disk ID: 3355908D) Partition 1: (Not Active) - (Size=-198625372160) - (Type=07 NTFS) ==================== End Of Log ============================ |
20.06.2013, 18:28 | #6 | |
/// the machine /// TB-Ausbilder | Anchor.hss Was ist das?Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ --> Anchor.hss Was ist das? |
20.06.2013, 18:53 | #7 |
| Anchor.hss Was ist das? Also hatte leichte probleme Norton 360 zu deaktivieren..Habe eig alles deaktiviert gehabt, aber Combofix meinte es würde immer noch laufen.. Und Neustarten musste ich auch nicht, ist das normal? Code:
ATTFilter ComboFix 13-06-20.01 - Tobias 20.06.2013 19:45:09.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.8109.5643 [GMT 2:00] ausgeführt von:: c:\users\Tobias\Desktop\ComboFix.exe AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Tobias\AppData\Roaming\Microsoft\Windows\Recent\AQT{9F651477-CDE8-438E-BF62-7492238F7C27} c:\users\Tobias\AppData\Roaming\Microsoft\Windows\Recent\AQT{DEB5A8A2-9F67-4057-B711-7377C44DA1CC} . . ((((((((((((((((((((((( Dateien erstellt von 2013-05-20 bis 2013-06-20 )))))))))))))))))))))))))))))) . . 2013-06-20 17:24 . 2013-06-20 17:24 -------- d-----w- C:\FRST 2013-06-20 15:59 . 2013-06-20 16:00 -------- d-----w- c:\windows\SysWow64\Adobe 2013-06-17 23:01 . 2013-06-17 23:01 -------- d-----w- c:\windows\SysWow64\wbem\en-US 2013-06-17 23:01 . 2013-06-17 23:01 -------- d-----w- c:\windows\system32\wbem\en-US 2013-06-17 17:20 . 2013-06-17 17:20 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-13 15:06 . 2013-06-19 11:23 -------- d-----w- c:\windows\system32\drivers\N360x64\1404000.028 2013-06-09 20:22 . 2013-06-09 20:22 -------- d-----w- c:\programdata\Codemasters 2013-06-07 13:10 . 2013-06-07 13:10 -------- d-----w- c:\users\Tobias\AppData\Roaming\AceBIT 2013-06-07 13:10 . 2009-08-13 15:07 672024 ----a-w- c:\windows\SysWow64\wodKeys.dll 2013-06-07 13:10 . 2009-08-13 15:07 729424 ----a-w- c:\windows\SysWow64\wodSFTP.dll 2013-06-07 13:10 . 2013-06-07 13:10 -------- d-----w- c:\program files (x86)\AceBIT 2013-06-07 11:52 . 2012-01-13 11:48 21040 ------w- c:\windows\system32\drivers\AQFileRestore.sys 2013-06-07 11:52 . 2013-06-07 14:16 -------- d-----w- c:\programdata\Avanquest 2013-06-07 11:52 . 2013-06-07 11:52 -------- d-----w- c:\program files (x86)\Avanquest 2013-06-07 11:22 . 2013-06-07 11:22 25640 ----a-w- c:\windows\etdrv.sys 2013-06-02 18:21 . 2013-06-02 18:21 -------- d-----w- c:\program files (x86)\Common Files\Skype 2013-06-02 18:21 . 2013-06-02 18:21 -------- d-----r- c:\program files (x86)\Skype 2013-05-27 07:51 . 2013-05-27 07:51 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-20 14:45 . 2012-01-20 17:21 25640 ----a-w- c:\windows\gdrv.sys 2013-06-20 14:45 . 2013-04-05 22:04 4194304 ----a-w- c:\windows\ServiceProfiles\NetworkService\msmqlog.bin 2013-06-19 08:44 . 2012-03-22 11:33 177312 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2013-06-14 19:58 . 2012-01-20 22:30 291088 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-06-14 19:58 . 2012-01-20 21:34 291088 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-06-14 19:58 . 2012-01-20 21:34 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-06-12 09:21 . 2012-01-30 16:12 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-06-11 21:11 . 2012-09-02 15:54 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-11 21:11 . 2012-09-02 15:54 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-07 13:43 . 2012-01-20 17:21 30528 ----a-w- c:\windows\GVTDrv64.sys 2013-06-07 11:29 . 2012-12-18 12:55 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2013-05-19 23:40 . 2013-05-19 23:40 311200 ----a-w- c:\windows\system32\javaws.exe 2013-05-19 23:40 . 2013-05-19 23:40 1092512 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-05-19 23:40 . 2013-05-19 23:40 188832 ----a-w- c:\windows\system32\javaw.exe 2013-05-19 23:40 . 2013-05-19 23:40 188320 ----a-w- c:\windows\system32\java.exe 2013-05-19 23:40 . 2013-05-19 23:40 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-05-19 23:40 . 2012-04-17 09:47 971680 ----a-w- c:\windows\system32\deployJava1.dll 2013-05-07 19:01 . 2012-09-02 15:41 866720 ----a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-05-07 19:01 . 2012-02-05 13:21 788896 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-04-12 14:45 . 2013-04-24 11:58 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 06:01 . 2013-05-15 18:59 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-04-10 06:01 . 2013-05-15 18:59 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-04-10 03:30 . 2013-05-15 18:59 3153920 ----a-w- c:\windows\system32\win32k.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-17 14:45 130736 ----a-w- c:\users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-17 14:45 130736 ----a-w- c:\users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-17 14:45 130736 ----a-w- c:\users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HDDHealth"="c:\program files (x86)\HDD Health\hddhealth.exe" [2008-04-12 1687552] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "GamingKeyboard"="c:\program files (x86)\SHARKOON Skiller\GameMon.exe" [2012-06-07 1803264] . c:\users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Tobias\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968] Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2012-9-9 41160] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer7"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 acsock;acsock;c:\windows\system32\DRIVERS\acsock64.sys;c:\windows\SYSNATIVE\DRIVERS\acsock64.sys [x] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x] R3 AQFileRestore;AQFileRestore;c:\windows\system32\DRIVERS\AQFileRestore.sys;c:\windows\SYSNATIVE\DRIVERS\AQFileRestore.sys [x] R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys;c:\windows\SYSNATIVE\drivers\avmeject.sys [x] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x] R3 etdrv;etdrv;c:\windows\etdrv.sys;c:\windows\etdrv.sys [x] R3 fwlanusb4;FRITZ!WLAN N/G;c:\windows\system32\DRIVERS\fwlanusb4.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusb4.sys [x] R3 fwlanusbn;FRITZ!WLAN N;c:\windows\system32\DRIVERS\fwlanusbn.sys;c:\windows\SYSNATIVE\DRIVERS\fwlanusbn.sys [x] R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x] R3 LGSUsbFilt;Logitech Gaming KMDF USB Filter Driver;c:\windows\system32\DRIVERS\LGSUsbFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSUsbFilt.Sys [x] R3 MSICDSetup;MSICDSetup;d:\cdriver64.sys;d:\CDriver64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x] R3 XENfiltv;XENfiltv;c:\windows\system32\drivers\XENfiltv.sys;c:\windows\SYSNATIVE\drivers\XENfiltv.sys [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\1404000.028\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\1404000.028\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\SYMEFA64.SYS [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [x] S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\ccSetx64.sys [x] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1404000.028\Ironx64.SYS [x] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\N360x64\1404000.028\SYMNETS.SYS [x] S2 ESLWireAC;ESLWireAC;c:\windows\system32\drivers\ESLWireACD.sys;c:\windows\SYSNATIVE\drivers\ESLWireACD.sys [x] S2 EslWireHelper;ESL Wire Helper Service;c:\program files\EslWire\service\WireHelperSvc.exe;c:\program files\EslWire\service\WireHelperSvc.exe [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe;c:\program files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [x] S2 Smart TimeLock;Smart TimeLock Service;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe;c:\program files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x] S2 vpnagent;Cisco AnyConnect Secure Mobility Agent;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe;c:\program files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 GameKB;SHARKOON Skiller;c:\windows\system32\drivers\GameKB.sys;c:\windows\SYSNATIVE\drivers\GameKB.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] S3 netr7364;RT73 USB-Drahtlos-LAN-Kartentreiber für Vista;c:\windows\system32\DRIVERS\netr7364.sys;c:\windows\SYSNATIVE\DRIVERS\netr7364.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] iissvcs REG_MULTI_SZ w3svc was apphost REG_MULTI_SZ apphostsvc . Inhalt des "geplante Tasks" Ordners . 2013-06-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-02 21:11] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}] 2010-11-05 01:57 444752 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{1d09c093-f71e-43c3-b948-19316cbd695e}"= "mscoree.dll" [2010-11-05 444752] . [HKEY_CLASSES_ROOT\CLSID\{1d09c093-f71e-43c3-b948-19316cbd695e}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-17 14:45 164016 ----a-w- c:\users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-17 14:45 164016 ----a-w- c:\users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-17 14:45 164016 ----a-w- c:\users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-17 14:45 164016 ----a-w- c:\users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-11 11776104] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472] "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536] "Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2012-11-29 7406392] "MsmqIntCert"="mqrt.dll" [2010-11-20 247808] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "RPMKickstart"="c:\program files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe" [2011-03-30 2552320] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: Free YouTube Download - c:\users\Tobias\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files (x86)\ICQ7.7\ICQ.exe TCP: DhcpNameServer = 192.168.0.1 FF - ProfilePath - c:\users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ FF - ExtSQL: 2013-06-07 15:10; passworddepot@acebit.com; c:\program files (x86)\AceBIT\Password Depot 6\Firefox . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\20.4.0.40\diMaster.dll\" /prefetch:1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011] "ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-06-20 19:51:12 ComboFix-quarantined-files.txt 2013-06-20 17:51 . Vor Suchlauf: 12 Verzeichnis(se), 207.416.426.496 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 206.935.937.024 Bytes frei . - - End Of File - - C6C997B92E87CA532CF4F1D2BE514AC9 A36C5E4F47E84449FF07ED3517B43A31 Normal? Hatte nur "erlauben" zur Auswahl... |
21.06.2013, 07:30 | #8 |
/// the machine /// TB-Ausbilder | Anchor.hss Was ist das? Spybot bitte während unserer Scans deaktivieren, oder am besten deinstallieren. Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST Log.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.06.2013, 09:08 | #9 |
| Anchor.hss Was ist das?Code:
ATTFilter # AdwCleaner v2.303 - Datei am 21/06/2013 um 09:58:01 erstellt # Aktualisiert am 08/06/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzer : Tobias - RETROGOTT # Bootmodus : Normal # Ausgeführt unter : C:\Users\Tobias\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin-10.xml Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin-4.xml Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin-5.xml Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin-6.xml Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin-7.xml Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin-8.xml Datei Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\searchplugins\icqplugin-9.xml Ordner Gelöscht : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\jetpack ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16618 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v21.0 (en-US) Datei : C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [2056 octets] - [21/06/2013 09:58:01] ########## EOF - C:\AdwCleaner[S1].txt - [2116 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Ultimate x64 Ran by Tobias on 21.06.2013 at 10:02:19,72 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Tobias\AppData\Roaming\splashtop" ~~~ FireFox Successfully deleted: [File] "C:\Users\Tobias\AppData\Roaming\mozilla\firefox\profiles\xy7b10iz.default\extensions\jid1-qQSMEVsYTOjgYA@jetpack.xpi" Successfully deleted the following from C:\Users\Tobias\AppData\Roaming\mozilla\firefox\profiles\xy7b10iz.default\prefs.js user_pref("extensions.personas.current", "{\"id\":\"164049\",\"name\":\"My Vinyl\",\"category\":null,\"description\":\"\",\"author\":\"baliclem\",\"username\":\"baliclem\",\"h user_pref("extensions.personas.lastselected0", "{\"id\":\"164049\",\"name\":\"My Vinyl\",\"category\":null,\"description\":\"\",\"author\":\"baliclem\",\"username\":\"baliclem Emptied folder: C:\Users\Tobias\AppData\Roaming\mozilla\firefox\profiles\xy7b10iz.default\minidumps [104 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.06.2013 at 10:05:41,84 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-06-2013 01 Ran by Tobias (administrator) on 21-06-2013 10:07:08 Running from C:\Users\Tobias\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Program Files (x86)\CPUCooL\CooLSrv.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Windows\system32\inetsrv\inetinfo.exe (Microsoft Corporation) C:\Windows\system32\mqsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\system32\mqtgsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (PANTERASoft) C:\Program Files (x86)\HDD Health\hddhealth.exe (Dropbox, Inc.) C:\Users\Tobias\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Program Files\Rainmeter\Rainmeter.exe (Game Inc.) C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11776104 2011-02-11] (Realtek Semiconductor) HKLM\...\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [7406392 2012-11-29] (Logitech Inc.) HKLM\...\Run: [MsmqIntCert] regsvr32 /s mqrt.dll [x] HKLM\...\RunOnce: [RPMKickstart] C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.) HKCU\...\Run: [HDDHealth] C:\Program Files (x86)\HDD Health\hddhealth.exe -wl [1687552 2008-04-12] (PANTERASoft) HKCU\...\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GamingKeyboard] "C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe" [1803264 2012-06-07] (Game Inc.) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [250504 2013-02-10] (NVIDIA Corporation) Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tobias\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - {D985E0F7-5C0C-4dc8-A1E9-164E32C8BF71} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV BHO: GBHO.BHO - {45d30484-7ded-43d9-957a-d2fd1f046511} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default FF SelectedSearchEngine: Google FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.118.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.140.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: WOT - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: personas - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\personas@christopher.beard.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 CPUCooLServer; C:\Program Files (x86)\CPUCooL\CooLSrv.exe [743936 2011-12-01] () R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [678416 2012-11-14] () R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-20] (Microsoft Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-10-16] () R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S3 AQFileRestore; C:\Windows\System32\DRIVERS\AQFileRestore.sys [21040 2012-01-13] () S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-26] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-26] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-16] (Symantec Corporation) R2 ESLWireAC; C:\Windows\system32\drivers\ESLWireACD.sys [160784 2012-11-14] (<Turtle Entertainment>) S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-07] (Windows (R) Server 2003 DDK provider) S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-07] (Windows (R) Server 2003 DDK provider) S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH) S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-25] (AVM GmbH) R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () R3 gdrv; C:\Windows\gdrv.sys [25640 2013-06-21] (Windows (R) Server 2003 DDK provider) R3 gdrv; C:\Windows\gdrv.sys [25640 2013-06-21] (Windows (R) Server 2003 DDK provider) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-06-07] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-06-07] () R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys [513184 2013-01-04] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys [513184 2013-01-04] (Symantec Corporation) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66360 2012-10-03] (Logitech Inc.) S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [43832 2012-10-03] (Logitech Inc.) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\ENG64.SYS [126040 2013-05-22] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\ENG64.SYS [126040 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\EX64.SYS [2098776 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\EX64.SYS [2098776 2013-05-22] (Symantec Corporation) R1 ntiopnp; C:\Windows\System32\Drivers\ntiopnp.sys [19544 2010-11-11] () R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) S3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 MSICDSetup; \??\D:\CDriver64.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-21 10:05 - 2013-06-21 10:05 - 00001464 ____A C:\Users\Tobias\Desktop\JRT.txt 2013-06-21 10:02 - 2013-06-21 10:02 - 00000000 ____D C:\JRT 2013-06-21 09:58 - 2013-06-21 09:58 - 00002185 ____A C:\AdwCleaner[S1].txt 2013-06-21 09:54 - 2013-06-21 09:54 - 00648201 ____A C:\Users\Tobias\Desktop\adwcleaner.exe 2013-06-21 09:54 - 2013-06-21 09:54 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Tobias\Desktop\JRT.exe 2013-06-20 20:42 - 2013-06-21 09:59 - 00000224 ____A C:\Windows\setupact.log 2013-06-20 20:42 - 2013-06-20 20:42 - 00000000 ____A C:\Windows\setuperr.log 2013-06-20 20:41 - 2013-06-20 20:41 - 00001496 ____A C:\Windows\PFRO.log 2013-06-20 19:51 - 2013-06-20 19:51 - 00023302 ____A C:\ComboFix.txt 2013-06-20 19:43 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-06-20 19:43 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-06-20 19:43 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-06-20 19:33 - 2013-06-20 19:51 - 00000000 ____D C:\Qoobox 2013-06-20 19:31 - 2013-06-20 19:31 - 05081444 ____R (Swearware) C:\Users\Tobias\Desktop\ComboFix.exe 2013-06-20 19:25 - 2013-06-20 19:25 - 00020024 ____A C:\Users\Tobias\Desktop\Addition.txt 2013-06-20 19:24 - 2013-06-20 19:24 - 01929538 ____A (Farbar) C:\Users\Tobias\Desktop\FRST64.exe 2013-06-20 19:24 - 2013-06-20 19:24 - 00000000 ____D C:\FRST 2013-06-20 18:23 - 2013-04-04 18:10 - 00445511 ____A C:\Windows\System32\Drivers\etc\hosts.20130620-182311.backup 2013-06-20 17:59 - 2013-06-20 18:00 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-06-17 19:21 - 2013-06-17 19:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-06-17 19:20 - 2013-06-17 19:20 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 15:45 - 2013-06-17 15:45 - 03839648 ____A (Piriform Ltd) C:\Users\Tobias\Desktop\dfsetup214.exe 2013-06-12 09:49 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 09:49 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 09:49 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 09:49 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 09:49 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 09:49 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 09:49 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 09:49 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 09:49 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 09:49 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-09 22:22 - 2013-06-09 22:22 - 00000000 ____D C:\ProgramData\Codemasters 2013-06-07 15:10 - 2013-06-12 11:37 - 00000000 ____D C:\Users\Tobias\Documents\Password Depot 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\AceBIT 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Program Files (x86)\AceBIT 2013-06-07 15:10 - 2009-08-13 17:07 - 00729424 ____A (WeOnlyDo Software) C:\Windows\SysWOW64\wodSFTP.dll 2013-06-07 15:10 - 2009-08-13 17:07 - 00672024 ____A (WeOnlyDo! COM) C:\Windows\SysWOW64\wodKeys.dll 2013-06-07 13:52 - 2013-06-07 16:16 - 00000000 ____D C:\ProgramData\Avanquest 2013-06-07 13:52 - 2013-06-07 13:52 - 00000000 ____D C:\Program Files (x86)\Avanquest 2013-06-07 13:52 - 2012-01-13 13:48 - 00021040 ____N C:\Windows\System32\Drivers\AQFileRestore.sys 2013-06-07 13:22 - 2013-06-07 13:22 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\etdrv.sys 2013-06-02 20:21 - 2013-06-02 20:21 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-05-27 09:51 - 2013-05-27 09:51 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-05-26 21:42 - 2013-06-09 22:22 - 00000000 ____D C:\Users\Tobias\Documents\My Games 2013-05-24 11:22 - 2013-05-24 11:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-06-21 10:07 - 2009-07-14 06:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-21 10:07 - 2009-07-14 06:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-21 10:05 - 2013-06-21 10:05 - 00001464 ____A C:\Users\Tobias\Desktop\JRT.txt 2013-06-21 10:02 - 2013-06-21 10:02 - 00000000 ____D C:\JRT 2013-06-21 10:02 - 2013-04-03 18:44 - 00000000 ____D C:\Windows\ERUNT 2013-06-21 10:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\inetsrv 2013-06-21 10:00 - 2012-04-16 21:18 - 00000000 ____D C:\Users\Tobias\AppData\Local\LogMeIn Hamachi 2013-06-21 10:00 - 2012-01-23 20:31 - 00000000 ___RD C:\Users\Tobias\Desktop\Dropbox 2013-06-21 10:00 - 2012-01-23 20:29 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Dropbox 2013-06-21 09:59 - 2013-06-20 20:42 - 00000224 ____A C:\Windows\setupact.log 2013-06-21 09:59 - 2012-10-17 00:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-06-21 09:59 - 2012-01-20 19:21 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-06-21 09:59 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-21 09:58 - 2013-06-21 09:58 - 00002185 ____A C:\AdwCleaner[S1].txt 2013-06-21 09:58 - 2013-02-18 11:01 - 02092696 ____A C:\Windows\WindowsUpdate.log 2013-06-21 09:54 - 2013-06-21 09:54 - 00648201 ____A C:\Users\Tobias\Desktop\adwcleaner.exe 2013-06-21 09:54 - 2013-06-21 09:54 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Tobias\Desktop\JRT.exe 2013-06-21 00:30 - 2012-11-19 16:29 - 00000000 ____D C:\Program Files (x86)\Steam 2013-06-21 00:11 - 2012-09-02 17:54 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-20 20:42 - 2013-06-20 20:42 - 00000000 ____A C:\Windows\setuperr.log 2013-06-20 20:41 - 2013-06-20 20:41 - 00001496 ____A C:\Windows\PFRO.log 2013-06-20 19:51 - 2013-06-20 19:51 - 00023302 ____A C:\ComboFix.txt 2013-06-20 19:51 - 2013-06-20 19:33 - 00000000 ____D C:\Qoobox 2013-06-20 19:49 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-06-20 19:31 - 2013-06-20 19:31 - 05081444 ____R (Swearware) C:\Users\Tobias\Desktop\ComboFix.exe 2013-06-20 19:25 - 2013-06-20 19:25 - 00020024 ____A C:\Users\Tobias\Desktop\Addition.txt 2013-06-20 19:24 - 2013-06-20 19:24 - 01929538 ____A (Farbar) C:\Users\Tobias\Desktop\FRST64.exe 2013-06-20 19:24 - 2013-06-20 19:24 - 00000000 ____D C:\FRST 2013-06-20 18:21 - 2012-01-20 22:27 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-06-20 18:06 - 2012-07-10 21:58 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\TS3Client 2013-06-20 18:06 - 2012-01-20 07:20 - 00000000 ____D C:\Windows\Panther 2013-06-20 18:00 - 2013-06-20 17:59 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-06-20 17:56 - 2012-01-25 20:26 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\DVDVideoSoft 2013-06-20 17:40 - 2012-01-22 18:41 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Skype 2013-06-20 17:05 - 2012-01-20 00:49 - 00000000 ___RD C:\Users\Tobias\Desktop\Anderes 2013-06-19 13:25 - 2012-03-22 13:32 - 00000000 ____D C:\Windows\System32\Drivers\N360x64 2013-06-19 10:44 - 2012-03-22 13:33 - 00177312 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS 2013-06-19 10:44 - 2012-03-22 13:33 - 00007631 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT 2013-06-18 11:50 - 2012-01-20 22:48 - 00000000 ____D C:\Program Files (x86)\Origin 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\zh-HK 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\tr-TR 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-06-17 19:38 - 2012-01-21 00:08 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-06-17 19:21 - 2013-06-17 19:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-06-17 19:20 - 2013-06-17 19:20 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 18:49 - 2012-03-21 11:04 - 00000000 ____D C:\Users\Tobias\Desktop\Uni 2013-06-17 15:45 - 2013-06-17 15:45 - 03839648 ____A (Piriform Ltd) C:\Users\Tobias\Desktop\dfsetup214.exe 2013-06-17 15:40 - 2012-01-20 22:33 - 00000000 ____D C:\Users\Tobias\Desktop\Spiele 2013-06-14 22:23 - 2012-01-20 00:45 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-06-14 21:58 - 2012-01-21 00:30 - 00291088 ____A C:\Windows\SysWOW64\PnkBstrB.xtr 2013-06-14 21:58 - 2012-01-20 23:34 - 00291088 ____A C:\Windows\SysWOW64\PnkBstrB.exe 2013-06-14 21:58 - 2012-01-20 23:34 - 00280904 ____A C:\Windows\SysWOW64\PnkBstrB.ex0 2013-06-12 11:37 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\Documents\Password Depot 2013-06-12 11:21 - 2012-01-30 18:12 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 23:11 - 2012-09-02 17:54 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-11 23:11 - 2012-09-02 17:54 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-09 22:22 - 2013-06-09 22:22 - 00000000 ____D C:\ProgramData\Codemasters 2013-06-09 22:22 - 2013-05-26 21:42 - 00000000 ____D C:\Users\Tobias\Documents\My Games 2013-06-07 16:17 - 2012-01-29 23:04 - 00000000 ____D C:\Users\Tobias\AppData\Local\CrashDumps 2013-06-07 16:16 - 2013-06-07 13:52 - 00000000 ____D C:\ProgramData\Avanquest 2013-06-07 16:15 - 2012-01-20 00:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-07 15:43 - 2012-01-20 19:21 - 00030528 ____A C:\Windows\GVTDrv64.sys 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\AceBIT 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Program Files (x86)\AceBIT 2013-06-07 13:52 - 2013-06-07 13:52 - 00000000 ____D C:\Program Files (x86)\Avanquest 2013-06-07 13:29 - 2012-12-18 14:55 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys 2013-06-07 13:22 - 2013-06-07 13:22 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\etdrv.sys 2013-06-06 18:56 - 2012-01-20 22:25 - 00000000 ____D C:\Program Files\CCleaner 2013-06-02 20:21 - 2013-06-02 20:21 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-02 20:21 - 2012-01-22 18:41 - 00000000 ____D C:\ProgramData\Skype 2013-05-28 17:40 - 2012-01-20 22:33 - 00000000 ____D C:\Users\Tobias\Desktop\Tobias 2013-05-28 14:45 - 2009-07-14 19:58 - 00790852 ____A C:\Windows\System32\perfh007.dat 2013-05-28 14:45 - 2009-07-14 19:58 - 00182760 ____A C:\Windows\System32\perfc007.dat 2013-05-28 14:45 - 2009-07-14 07:13 - 01852714 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-27 09:51 - 2013-05-27 09:51 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-05-27 09:51 - 2012-04-24 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-05-24 11:22 - 2013-05-24 11:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-22 18:54 - 2012-01-20 23:05 - 00000000 ____D C:\Program Files (x86)\Games 2013-05-22 18:50 - 2012-05-07 16:46 - 00000000 ____D C:\Users\Tobias\Documents\KONAMI 2013-05-22 18:50 - 2012-05-06 23:34 - 00000000 ____D C:\ProgramData\KONAMI ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-04-16 00:52 ==================== End Of Log ============================ |
21.06.2013, 09:26 | #10 |
/// the machine /// TB-Ausbilder | Anchor.hss Was ist das? Supi, ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST Log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.06.2013, 10:51 | #11 |
| Anchor.hss Was ist das?Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=071a31b075cbff418c180ca5c8a90cbf # engine=13539 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-03 02:38:42 # local_time=2013-04-03 04:38:42 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=3592 16777213 100 91 112751 115662418 0 0 # compatibility_mode=5893 16776574 66 85 37063087 116629772 0 0 # scanned=165032 # found=1 # cleaned=0 # scan_time=3200 sh=74E07DE7B3AEE058952F4CDD5E99EAC2008932C8 ft=1 fh=f4cb98639c10ef0c vn="a variant of Win32/Packed.VMProtect.AAH trojan" ac=I fn="C:\Program Files (x86)\Games\Pro Evo 2012\rld.dll" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=071a31b075cbff418c180ca5c8a90cbf # engine=14123 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-06-21 09:50:39 # local_time=2013-06-21 11:50:39 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=3592 16777213 100 91 86413 122470735 0 0 # compatibility_mode=5893 16776574 66 85 43871404 123438089 0 0 # scanned=176962 # found=0 # cleaned=0 # scan_time=4625 Bei Sec Check sagt er mir : Unsupported operating system! |
21.06.2013, 12:49 | #12 |
/// the machine /// TB-Ausbilder | Anchor.hss Was ist das? Ok dann bitte das frische FRST log und meine Frage noch beantworten
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.06.2013, 13:13 | #13 |
| Anchor.hss Was ist das?FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-06-2013 01 Ran by Tobias (administrator) on 21-06-2013 14:10:53 Running from C:\Users\Tobias\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe () C:\Program Files (x86)\CPUCooL\CooLSrv.exe () C:\Program Files\EslWire\service\WireHelperSvc.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Windows\system32\inetsrv\inetinfo.exe (Microsoft Corporation) C:\Windows\system32\mqsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\system32\mqtgsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe (Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (PANTERASoft) C:\Program Files (x86)\HDD Health\hddhealth.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Dropbox, Inc.) C:\Users\Tobias\AppData\Roaming\Dropbox\bin\Dropbox.exe () C:\Program Files\Rainmeter\Rainmeter.exe (Game Inc.) C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11776104 2011-02-11] (Realtek Semiconductor) HKLM\...\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized [7406392 2012-11-29] (Logitech Inc.) HKLM\...\Run: [MsmqIntCert] regsvr32 /s mqrt.dll [x] HKLM\...\RunOnce: [RPMKickstart] C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.) HKCU\...\Run: [HDDHealth] C:\Program Files (x86)\HDD Health\hddhealth.exe -wl [1687552 2008-04-12] (PANTERASoft) HKCU\...\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GamingKeyboard] "C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe" [1803264 2012-06-07] (Game Inc.) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [250504 2013-02-10] (NVIDIA Corporation) Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tobias\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - {D985E0F7-5C0C-4dc8-A1E9-164E32C8BF71} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV BHO: GBHO.BHO - {45d30484-7ded-43d9-957a-d2fd1f046511} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\System32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default FF SelectedSearchEngine: Google FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.118.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.132.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=1.140.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: WOT - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: personas - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\personas@christopher.beard.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\xy7b10iz.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 CPUCooLServer; C:\Program Files (x86)\CPUCooL\CooLSrv.exe [743936 2011-12-01] () R2 EslWireHelper; C:\Program Files\EslWire\service\WireHelperSvc.exe [678416 2012-11-14] () R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-20] (Microsoft Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [189440 2010-11-20] (Microsoft Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-10-16] () R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S3 AQFileRestore; C:\Windows\System32\DRIVERS\AQFileRestore.sys [21040 2012-01-13] () S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-04] (AVM Berlin) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130531.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-26] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-26] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2012-08-16] (Symantec Corporation) R2 ESLWireAC; C:\Windows\system32\drivers\ESLWireACD.sys [160784 2012-11-14] (<Turtle Entertainment>) S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-07] (Windows (R) Server 2003 DDK provider) S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-07] (Windows (R) Server 2003 DDK provider) S3 fwlanusb4; C:\Windows\System32\DRIVERS\fwlanusb4.sys [1293824 2010-10-04] (AVM GmbH) S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-25] (AVM GmbH) R3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () R3 gdrv; C:\Windows\gdrv.sys [25640 2013-06-21] (Windows (R) Server 2003 DDK provider) R3 gdrv; C:\Windows\gdrv.sys [25640 2013-06-21] (Windows (R) Server 2003 DDK provider) S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-06-07] () S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-06-07] () R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys [513184 2013-01-04] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130619.001\IDSvia64.sys [513184 2013-01-04] (Symantec Corporation) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66360 2012-10-03] (Logitech Inc.) S3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [43832 2012-10-03] (Logitech Inc.) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\ENG64.SYS [126040 2013-05-22] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\ENG64.SYS [126040 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\EX64.SYS [2098776 2013-05-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20130619.021\EX64.SYS [2098776 2013-05-22] (Symantec Corporation) R1 ntiopnp; C:\Windows\System32\Drivers\ntiopnp.sys [19544 2010-11-11] () R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) S3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 MSICDSetup; \??\D:\CDriver64.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-21 10:30 - 2013-06-21 10:30 - 00890839 ____A C:\Users\Tobias\Desktop\SecurityCheck.exe 2013-06-21 10:29 - 2013-06-21 10:29 - 02347384 ____A (ESET) C:\Users\Tobias\Desktop\esetsmartinstaller_enu.exe 2013-06-21 10:05 - 2013-06-21 10:05 - 00001464 ____A C:\Users\Tobias\Desktop\JRT.txt 2013-06-21 10:02 - 2013-06-21 10:02 - 00000000 ____D C:\JRT 2013-06-21 09:58 - 2013-06-21 09:58 - 00002185 ____A C:\AdwCleaner[S1].txt 2013-06-21 09:54 - 2013-06-21 09:54 - 00648201 ____A C:\Users\Tobias\Desktop\adwcleaner.exe 2013-06-21 09:54 - 2013-06-21 09:54 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Tobias\Desktop\JRT.exe 2013-06-20 20:42 - 2013-06-21 12:55 - 00000280 ____A C:\Windows\setupact.log 2013-06-20 20:42 - 2013-06-20 20:42 - 00000000 ____A C:\Windows\setuperr.log 2013-06-20 20:41 - 2013-06-20 20:41 - 00001496 ____A C:\Windows\PFRO.log 2013-06-20 19:51 - 2013-06-20 19:51 - 00023302 ____A C:\ComboFix.txt 2013-06-20 19:43 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-06-20 19:43 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-06-20 19:43 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-06-20 19:43 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-06-20 19:33 - 2013-06-20 19:51 - 00000000 ____D C:\Qoobox 2013-06-20 19:31 - 2013-06-20 19:31 - 05081444 ____R (Swearware) C:\Users\Tobias\Desktop\ComboFix.exe 2013-06-20 19:25 - 2013-06-20 19:25 - 00020024 ____A C:\Users\Tobias\Desktop\Addition.txt 2013-06-20 19:24 - 2013-06-20 19:24 - 01929538 ____A (Farbar) C:\Users\Tobias\Desktop\FRST64.exe 2013-06-20 19:24 - 2013-06-20 19:24 - 00000000 ____D C:\FRST 2013-06-20 18:23 - 2013-04-04 18:10 - 00445511 ____A C:\Windows\System32\Drivers\etc\hosts.20130620-182311.backup 2013-06-20 17:59 - 2013-06-20 18:00 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-06-17 19:21 - 2013-06-17 19:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-06-17 19:20 - 2013-06-17 19:20 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 15:45 - 2013-06-17 15:45 - 03839648 ____A (Piriform Ltd) C:\Users\Tobias\Desktop\dfsetup214.exe 2013-06-12 09:49 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 09:49 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 09:49 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 09:49 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 09:49 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 09:49 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 09:49 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 09:49 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 09:49 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 09:49 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 09:49 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-09 22:22 - 2013-06-09 22:22 - 00000000 ____D C:\ProgramData\Codemasters 2013-06-07 15:10 - 2013-06-12 11:37 - 00000000 ____D C:\Users\Tobias\Documents\Password Depot 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\AceBIT 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Program Files (x86)\AceBIT 2013-06-07 15:10 - 2009-08-13 17:07 - 00729424 ____A (WeOnlyDo Software) C:\Windows\SysWOW64\wodSFTP.dll 2013-06-07 15:10 - 2009-08-13 17:07 - 00672024 ____A (WeOnlyDo! COM) C:\Windows\SysWOW64\wodKeys.dll 2013-06-07 13:52 - 2013-06-07 16:16 - 00000000 ____D C:\ProgramData\Avanquest 2013-06-07 13:52 - 2013-06-07 13:52 - 00000000 ____D C:\Program Files (x86)\Avanquest 2013-06-07 13:52 - 2012-01-13 13:48 - 00021040 ____N C:\Windows\System32\Drivers\AQFileRestore.sys 2013-06-07 13:22 - 2013-06-07 13:22 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\etdrv.sys 2013-06-02 20:21 - 2013-06-02 20:21 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-05-27 09:51 - 2013-05-27 09:51 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-05-26 21:42 - 2013-06-09 22:22 - 00000000 ____D C:\Users\Tobias\Documents\My Games 2013-05-24 11:22 - 2013-05-24 11:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-06-21 14:11 - 2012-09-02 17:54 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-21 13:02 - 2009-07-14 06:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-21 13:02 - 2009-07-14 06:45 - 00017136 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-21 12:59 - 2012-11-19 16:29 - 00000000 ____D C:\Program Files (x86)\Steam 2013-06-21 12:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\inetsrv 2013-06-21 12:56 - 2012-01-23 20:31 - 00000000 ___RD C:\Users\Tobias\Desktop\Dropbox 2013-06-21 12:56 - 2012-01-23 20:29 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Dropbox 2013-06-21 12:56 - 2012-01-20 19:21 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-06-21 12:55 - 2013-06-20 20:42 - 00000280 ____A C:\Windows\setupact.log 2013-06-21 12:55 - 2012-10-17 00:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-06-21 12:55 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-21 12:54 - 2013-02-18 11:01 - 02096481 ____A C:\Windows\WindowsUpdate.log 2013-06-21 10:30 - 2013-06-21 10:30 - 00890839 ____A C:\Users\Tobias\Desktop\SecurityCheck.exe 2013-06-21 10:29 - 2013-06-21 10:29 - 02347384 ____A (ESET) C:\Users\Tobias\Desktop\esetsmartinstaller_enu.exe 2013-06-21 10:05 - 2013-06-21 10:05 - 00001464 ____A C:\Users\Tobias\Desktop\JRT.txt 2013-06-21 10:02 - 2013-06-21 10:02 - 00000000 ____D C:\JRT 2013-06-21 10:02 - 2013-04-03 18:44 - 00000000 ____D C:\Windows\ERUNT 2013-06-21 10:00 - 2012-04-16 21:18 - 00000000 ____D C:\Users\Tobias\AppData\Local\LogMeIn Hamachi 2013-06-21 09:58 - 2013-06-21 09:58 - 00002185 ____A C:\AdwCleaner[S1].txt 2013-06-21 09:54 - 2013-06-21 09:54 - 00648201 ____A C:\Users\Tobias\Desktop\adwcleaner.exe 2013-06-21 09:54 - 2013-06-21 09:54 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Tobias\Desktop\JRT.exe 2013-06-20 20:42 - 2013-06-20 20:42 - 00000000 ____A C:\Windows\setuperr.log 2013-06-20 20:41 - 2013-06-20 20:41 - 00001496 ____A C:\Windows\PFRO.log 2013-06-20 19:51 - 2013-06-20 19:51 - 00023302 ____A C:\ComboFix.txt 2013-06-20 19:51 - 2013-06-20 19:33 - 00000000 ____D C:\Qoobox 2013-06-20 19:49 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-06-20 19:31 - 2013-06-20 19:31 - 05081444 ____R (Swearware) C:\Users\Tobias\Desktop\ComboFix.exe 2013-06-20 19:25 - 2013-06-20 19:25 - 00020024 ____A C:\Users\Tobias\Desktop\Addition.txt 2013-06-20 19:24 - 2013-06-20 19:24 - 01929538 ____A (Farbar) C:\Users\Tobias\Desktop\FRST64.exe 2013-06-20 19:24 - 2013-06-20 19:24 - 00000000 ____D C:\FRST 2013-06-20 18:21 - 2012-01-20 22:27 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-06-20 18:06 - 2012-07-10 21:58 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\TS3Client 2013-06-20 18:06 - 2012-01-20 07:20 - 00000000 ____D C:\Windows\Panther 2013-06-20 18:00 - 2013-06-20 17:59 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-06-20 17:56 - 2012-01-25 20:26 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\DVDVideoSoft 2013-06-20 17:40 - 2012-01-22 18:41 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\Skype 2013-06-20 17:05 - 2012-01-20 00:49 - 00000000 ___RD C:\Users\Tobias\Desktop\Anderes 2013-06-19 13:25 - 2012-03-22 13:32 - 00000000 ____D C:\Windows\System32\Drivers\N360x64 2013-06-19 10:44 - 2012-03-22 13:33 - 00177312 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT64x86.SYS 2013-06-19 10:44 - 2012-03-22 13:33 - 00007631 ____A C:\Windows\System32\Drivers\SYMEVENT64x86.CAT 2013-06-18 11:50 - 2012-01-20 22:48 - 00000000 ____D C:\Program Files (x86)\Origin 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\zh-HK 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\tr-TR 2013-06-18 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-06-17 19:38 - 2012-01-21 00:08 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-06-17 19:21 - 2013-06-17 19:21 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-17 19:21 - 2013-06-17 19:21 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-06-17 19:21 - 2013-06-17 19:21 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-06-17 19:21 - 2013-06-17 19:21 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-06-17 19:21 - 2013-06-17 19:21 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-06-17 19:21 - 2013-06-17 19:21 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-06-17 19:21 - 2013-06-17 19:21 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-06-17 19:20 - 2013-06-17 19:20 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 19:20 - 2013-06-17 19:20 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-06-17 18:49 - 2012-03-21 11:04 - 00000000 ____D C:\Users\Tobias\Desktop\Uni 2013-06-17 15:45 - 2013-06-17 15:45 - 03839648 ____A (Piriform Ltd) C:\Users\Tobias\Desktop\dfsetup214.exe 2013-06-17 15:40 - 2012-01-20 22:33 - 00000000 ____D C:\Users\Tobias\Desktop\Spiele 2013-06-14 22:23 - 2012-01-20 00:45 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-06-14 21:58 - 2012-01-21 00:30 - 00291088 ____A C:\Windows\SysWOW64\PnkBstrB.xtr 2013-06-14 21:58 - 2012-01-20 23:34 - 00291088 ____A C:\Windows\SysWOW64\PnkBstrB.exe 2013-06-14 21:58 - 2012-01-20 23:34 - 00280904 ____A C:\Windows\SysWOW64\PnkBstrB.ex0 2013-06-12 11:37 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\Documents\Password Depot 2013-06-12 11:21 - 2012-01-30 18:12 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 23:11 - 2012-09-02 17:54 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-11 23:11 - 2012-09-02 17:54 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-09 22:22 - 2013-06-09 22:22 - 00000000 ____D C:\ProgramData\Codemasters 2013-06-09 22:22 - 2013-05-26 21:42 - 00000000 ____D C:\Users\Tobias\Documents\My Games 2013-06-07 16:17 - 2012-01-29 23:04 - 00000000 ____D C:\Users\Tobias\AppData\Local\CrashDumps 2013-06-07 16:16 - 2013-06-07 13:52 - 00000000 ____D C:\ProgramData\Avanquest 2013-06-07 16:15 - 2012-01-20 00:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-07 15:43 - 2012-01-20 19:21 - 00030528 ____A C:\Windows\GVTDrv64.sys 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Users\Tobias\AppData\Roaming\AceBIT 2013-06-07 15:10 - 2013-06-07 15:10 - 00000000 ____D C:\Program Files (x86)\AceBIT 2013-06-07 13:52 - 2013-06-07 13:52 - 00000000 ____D C:\Program Files (x86)\Avanquest 2013-06-07 13:29 - 2012-12-18 14:55 - 00018960 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LNonPnP.sys 2013-06-07 13:22 - 2013-06-07 13:22 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\etdrv.sys 2013-06-06 18:56 - 2012-01-20 22:25 - 00000000 ____D C:\Program Files\CCleaner 2013-06-02 20:21 - 2013-06-02 20:21 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-02 20:21 - 2012-01-22 18:41 - 00000000 ____D C:\ProgramData\Skype 2013-05-28 17:40 - 2012-01-20 22:33 - 00000000 ____D C:\Users\Tobias\Desktop\Tobias 2013-05-28 14:45 - 2009-07-14 19:58 - 00790852 ____A C:\Windows\System32\perfh007.dat 2013-05-28 14:45 - 2009-07-14 19:58 - 00182760 ____A C:\Windows\System32\perfc007.dat 2013-05-28 14:45 - 2009-07-14 07:13 - 01852714 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-27 09:51 - 2013-05-27 09:51 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-05-27 09:51 - 2012-04-24 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-05-24 11:22 - 2013-05-24 11:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-05-22 18:54 - 2012-01-20 23:05 - 00000000 ____D C:\Program Files (x86)\Games 2013-05-22 18:50 - 2012-05-07 16:46 - 00000000 ____D C:\Users\Tobias\Documents\KONAMI 2013-05-22 18:50 - 2012-05-06 23:34 - 00000000 ____D C:\ProgramData\KONAMI ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-04-16 00:52 ==================== End Of Log ============================ Nope Probleme habe ich eigentlich keine. Windows hängt bzw lädt zwar nachdem ich mein Passwort eingegeben habe, so ca 20 Sec bei "Willkommen" aber das ist glaube ich normal?! |
21.06.2013, 13:33 | #14 |
/// the machine /// TB-Ausbilder | Anchor.hss Was ist das? Öffne mal den Taskmanager > Reiter Autostart und deaktiviere was DU nicht brauchst. TEste dann nochmal
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.06.2013, 13:45 | #15 |
| Anchor.hss Was ist das? Ja habe ich schon, brauche aber recht viele Programme..Vlt fällts mir auche rst auf , als ich ein Virus drauf hatte..Ist halt so schlimm. ABer sonst ist nichts drauf? Also alles in Ordnung? |
Themen zu Anchor.hss Was ist das? |
anchor.hss, candy, eintrag, forum, gefunde, gelöscht, gen, hänge, hängen, inter, interne, internet, laufe, laufen, monate, open candy, ordner, spybot, verzeichnis, win, win32.downloader.gen, zusammen |