|
Plagegeister aller Art und deren Bekämpfung: Google chrom offnet sich unkontrolliertWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.07.2013, 10:24 | #1 |
| Google chrom offnet sich unkontrolliert ich habe mich bis jetzt an http://www.trojaner-board.de/135866-...-loeschen.html gehalten es hat sich aber nichts verändert. chrom öffnet sich dauernd und es sind vermutlich diverse .exe offen beide programme haben gemeldet webcake deletet doch leider hat sich nix verändert. bitte um eure hilfe |
07.07.2013, 10:57 | #2 |
/// the machine /// TB-Ausbilder | Google chrom offnet sich unkontrolliert hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
07.07.2013, 12:05 | #3 |
| Google chrom offnet sich unkontrolliert Durchgeführt ergebnisse im anhang
__________________ |
07.07.2013, 12:48 | #4 | |
/// the machine /// TB-Ausbilder | Google chrom offnet sich unkontrolliert Hi, Logs bitte immer in den Thread posten Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.07.2013, 13:19 | #5 |
| Google chrom offnet sich unkontrolliert ! ich habe antivir echtzeitscan deaktiviert trozdem hat es mir eine nachricht ausgeben "registry verhindert" ich hoffe das ist nicht weiter schlimm [CODE] Combofix Logfile: Code:
ATTFilter ComboFix 13-07-07.01 - Joke 07.07.2013 14:10:54.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.43.1031.18.8140.5463 [GMT 2:00] ausgeführt von:: c:\users\Joke\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2013-06-07 bis 2013-07-07 )))))))))))))))))))))))))))))) . . 2013-07-07 12:15 . 2013-07-07 12:15 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-07 12:10 . 2013-07-07 12:10 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CAA87606-7EB9-47C4-A19B-0E6375DEEF7C}\offreg.dll 2013-07-07 11:00 . 2013-07-07 11:00 -------- d-----w- C:\FRST 2013-07-07 10:38 . 2013-07-07 10:54 -------- d-----w- c:\programdata\SecTaskMan 2013-07-07 10:37 . 2013-07-07 10:37 -------- d-----w- c:\program files (x86)\Security Task Manager 2013-07-07 10:28 . 2013-07-07 10:28 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-07-07 10:28 . 2013-07-07 10:28 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-07-07 10:28 . 2013-07-07 10:28 -------- d-----w- c:\windows\system32\Macromed 2013-07-05 13:38 . 2013-06-17 00:10 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CAA87606-7EB9-47C4-A19B-0E6375DEEF7C}\mpengine.dll 2013-06-30 17:53 . 2013-06-30 17:53 -------- d-----w- c:\program files (x86)\Common Files\LogiShrd 2013-06-30 17:53 . 2013-06-30 17:53 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys 2013-06-30 17:52 . 2013-06-30 17:53 -------- d-----w- c:\programdata\Logitech 2013-06-30 17:52 . 2013-06-30 17:53 -------- d-----w- c:\programdata\Logishrd 2013-06-30 17:52 . 2013-06-30 17:52 -------- d-----w- c:\program files\Logitech 2013-06-30 17:52 . 2013-06-30 17:53 -------- d-----w- c:\program files\Common Files\Logishrd 2013-06-29 18:50 . 2013-06-29 18:50 -------- d-----w- c:\program files\CCleaner 2013-06-29 17:52 . 2013-06-29 17:52 -------- d-----w- c:\programdata\ATI 2013-06-29 17:35 . 2013-06-29 17:35 0 ----a-w- c:\windows\ativpsrm.bin 2013-06-29 17:17 . 2013-06-29 17:17 -------- d-----w- c:\programdata\AMD 2013-06-29 17:17 . 2013-06-29 17:17 -------- d-----w- c:\program files (x86)\AMD AVT 2013-06-29 17:17 . 2013-06-29 17:17 -------- d-----w- c:\program files\Common Files\ATI Technologies 2013-06-29 17:17 . 2013-06-29 17:17 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies 2013-06-29 17:08 . 2013-06-29 17:17 -------- d-----w- c:\program files (x86)\ATI Technologies 2013-06-29 17:07 . 2013-06-29 17:08 -------- d-----w- c:\programdata\Package Cache 2013-06-29 17:06 . 2013-06-29 17:06 -------- d-----w- c:\program files\ATI 2013-06-29 17:06 . 2013-06-29 17:16 -------- d-----w- c:\program files\ATI Technologies 2013-06-29 16:11 . 2012-12-19 01:09 277640 ----a-w- c:\windows\SysWow64\IntelCpHeciSvc.exe 2013-06-29 15:56 . 2013-06-29 17:03 -------- d-----w- c:\program files (x86)\Driver Fusion 2013-06-28 09:59 . 2013-06-28 10:00 -------- d-----w- c:\program files\OpenVPN 2013-06-28 09:59 . 2013-06-28 10:00 -------- d-----w- c:\program files\TAP-Windows 2013-06-28 09:56 . 2013-06-28 10:00 -------- d-----w- c:\program files (x86)\Mount&Blade Warband 2013-06-27 19:12 . 2013-06-27 19:12 -------- d-----w- c:\program files (x86)\Microsoft XNA 2013-06-27 17:48 . 2013-06-27 17:48 -------- d-----w- c:\program files (x86)\Audacity 2013-06-27 17:46 . 2013-06-27 17:46 715038 ----a-w- c:\windows\unins000.exe 2013-06-27 17:46 . 2011-12-07 17:37 148992 ----a-w- c:\windows\system32\lagarith.dll 2013-06-27 17:46 . 2011-12-07 17:32 216064 ----a-w- c:\windows\SysWow64\lagarith.dll 2013-06-27 17:46 . 2013-06-28 09:56 -------- d-----w- C:\Let's Play backup 2013-06-27 14:26 . 2013-06-27 14:26 -------- d-----w- c:\program files (x86)\Dotjosh Studios 2013-06-27 11:31 . 2011-02-16 16:11 74272 ----a-w- c:\windows\system32\RtNicProp64.dll 2013-06-27 11:31 . 2011-02-16 16:11 107552 ----a-w- c:\windows\system32\RTNUninst64.dll 2013-06-27 10:03 . 2013-06-27 10:03 -------- d-----w- c:\program files\IDT 2013-06-27 09:01 . 2013-06-27 09:01 -------- d--h--w- c:\windows\msdownld.tmp 2013-06-27 09:01 . 2013-06-27 09:02 -------- d-----w- c:\program files (x86)\MSI Afterburner 2013-06-26 22:59 . 2008-07-12 06:18 467984 ----a-w- c:\windows\SysWow64\d3dx10_39.dll 2013-06-26 22:59 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\SysWow64\D3DCompiler_39.dll 2013-06-26 22:59 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\SysWow64\D3DX9_39.dll 2013-06-26 22:58 . 2013-06-26 22:58 -------- d-sh--w- c:\windows\SysWow64\AI_RecycleBin 2013-06-26 22:58 . 2013-06-26 22:58 -------- d-----w- C:\Riot Games 2013-06-26 22:46 . 2013-06-26 22:46 -------- d-----w- c:\program files (x86)\Pando Networks 2013-06-26 21:37 . 2013-06-26 21:37 -------- d-----w- c:\program files (x86)\7-Zip 2013-06-26 20:27 . 2013-06-26 20:27 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-06-26 20:27 . 2013-06-26 20:27 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-06-23 10:36 . 2013-06-23 10:36 -------- d-----w- c:\programdata\Synaptics 2013-06-23 01:45 . 2013-06-23 01:45 -------- d-----w- c:\windows\SysWow64\Wat 2013-06-23 01:45 . 2013-06-23 01:45 -------- d-----w- c:\windows\system32\Wat 2013-06-22 18:22 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui 2013-06-22 18:22 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys 2013-06-22 18:22 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2013-06-22 18:22 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll 2013-06-22 18:11 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe 2013-06-22 17:51 . 2013-06-02 15:11 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-06-22 17:50 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll 2013-06-22 17:50 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll 2013-06-22 17:50 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll 2013-06-22 17:50 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2013-06-22 17:48 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2013-06-22 17:48 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2013-06-22 17:48 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2013-06-22 17:48 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2013-06-22 17:48 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2013-06-22 17:48 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2013-06-22 17:48 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2013-06-22 17:37 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2013-06-22 17:37 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll 2013-06-22 17:37 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll 2013-06-22 17:37 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll 2013-06-22 17:37 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll 2013-06-22 17:17 . 2011-05-20 07:53 557848 ----a-w- c:\windows\system32\drivers\iaStor.sys 2013-06-22 17:14 . 2013-06-22 17:14 9888360 ----a-w- c:\windows\SysWow64\RtsPStorIcon.dll 2013-06-22 17:12 . 2013-06-23 10:36 -------- d-----w- c:\programdata\Intel 2013-06-22 17:11 . 2013-06-22 17:11 -------- d-----w- c:\program files (x86)\Cisco 2013-06-22 16:59 . 2013-06-22 16:59 8604672 ----a-w- c:\windows\system32\drivers\NETwNs64.sys 2013-06-22 16:56 . 2013-06-22 16:56 91648 ----a-w- c:\windows\system32\drivers\nusb3hub.sys 2013-06-22 16:56 . 2013-06-22 16:56 81920 ----a-w- c:\windows\system32\nusb3co2.dll 2013-06-22 16:56 . 2013-06-22 16:56 208896 ----a-w- c:\windows\system32\drivers\nusb3xhc.sys 2013-06-22 16:55 . 2013-06-22 16:55 66856 ----a-w- c:\windows\SysWow64\SynTPEnhPS.dll 2013-06-22 16:55 . 2013-06-22 16:55 226600 ----a-w- c:\windows\system32\SynTPAPI.dll 2013-06-22 16:55 . 2013-06-22 16:55 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll 2013-06-22 16:55 . 2013-06-22 16:55 148264 ----a-w- c:\windows\system32\SynTPCo9.dll 2013-06-22 16:55 . 2013-06-22 16:55 1451056 ----a-w- c:\windows\system32\drivers\SynTP.sys 2013-06-22 16:55 . 2013-06-22 16:55 107816 ----a-w- c:\windows\SysWow64\SynTPCOM.dll 2013-06-22 16:55 . 2013-06-22 16:55 276264 ----a-w- c:\windows\system32\SynCtrl.dll 2013-06-22 16:55 . 2013-06-22 16:55 222504 ----a-w- c:\windows\SysWow64\SynCtrl.dll 2013-06-22 16:55 . 2013-06-22 16:55 177448 ----a-w- c:\windows\SysWow64\SynCOM.dll 2013-06-22 16:04 . 2013-02-15 20:44 8300544 ----a-w- c:\windows\SysWow64\DxtoryCodec.dll 2013-06-22 16:04 . 2013-02-15 20:44 8043008 ----a-w- c:\windows\system32\DxtoryCodec.dll 2013-06-22 16:04 . 2013-06-22 16:04 -------- d-----w- c:\program files (x86)\Dxtory Software 2013-06-22 13:07 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll 2013-06-22 12:02 . 2013-06-22 12:02 -------- d-----w- c:\program files (x86)\Microsoft.NET 2013-06-22 11:47 . 2013-06-22 11:49 -------- d-----w- c:\program files\NetBeans 7.3.1 2013-06-22 11:47 . 2013-06-22 11:47 972712 ----a-w- c:\windows\system32\deployJava1.dll 2013-06-22 11:47 . 2013-06-22 11:47 312232 ----a-w- c:\windows\system32\javaws.exe 2013-06-22 11:47 . 2013-06-22 11:47 1093032 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-06-22 11:47 . 2013-06-22 11:47 189352 ----a-w- c:\windows\system32\javaw.exe 2013-06-22 11:47 . 2013-06-22 11:47 188840 ----a-w- c:\windows\system32\java.exe 2013-06-22 11:47 . 2013-06-22 11:47 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-06-22 11:46 . 2013-06-22 11:47 -------- d-----w- c:\program files\Java 2013-06-22 11:27 . 2011-06-16 05:49 199680 ----a-w- c:\windows\system32\xmllite.dll 2013-06-22 11:25 . 2013-02-27 05:52 14172672 ----a-w- c:\windows\system32\shell32.dll 2013-06-22 11:24 . 2012-11-01 05:43 2002432 ----a-w- c:\windows\system32\msxml6.dll 2013-06-22 11:23 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys 2013-06-22 11:22 . 2012-11-30 05:45 362496 ----a-w- c:\windows\system32\wow64win.dll 2013-06-22 11:21 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe 2013-06-22 11:21 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll 2013-06-22 11:21 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll 2013-06-22 11:21 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll 2013-06-22 11:21 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll 2013-06-22 11:19 . 2013-05-13 05:51 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2013-06-22 11:19 . 2013-05-13 05:51 1464320 ----a-w- c:\windows\system32\crypt32.dll 2013-06-22 11:19 . 2013-05-13 05:51 139776 ----a-w- c:\windows\system32\cryptnet.dll 2013-06-22 11:19 . 2013-05-13 04:45 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-06-22 11:19 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-06-22 11:19 . 2013-05-13 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-06-22 11:19 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe 2013-06-22 11:19 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-22 16:55 . 2010-12-17 02:26 411944 ----a-w- c:\windows\system32\SynCOM.dll 2013-06-22 13:54 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll 2013-06-22 13:54 . 2009-08-18 09:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-06-04 07:15 . 2013-06-04 07:15 103448 ----a-w- c:\windows\system32\drivers\ssudbus.sys 2013-06-04 07:15 . 2013-06-04 07:15 203672 ----a-w- c:\windows\system32\drivers\ssudmdm.sys 2013-05-02 00:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-04-13 05:49 . 2013-06-22 11:26 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-06-22 11:26 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-06-22 11:26 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-06-22 11:26 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-06-22 11:26 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-06-22 11:26 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dxtory Update Checker 2.0"="c:\program files (x86)\Dxtory Software\Dxtory2.0\UpdateChecker.exe" [2010-10-17 93696] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2013-06-22 113288] "HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-02-15 94264] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-06-27 345144] "HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2011-07-11 574008] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-05-23 676608] . c:\users\Joke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech . Produktregistrierung.lnk - c:\program files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe /remind /language=DEA /_WFM="." [2009-11-16 517384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x] R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 hpCMSrv;HP Connection Manager 4.0 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x] R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys;c:\program files (x86)\MSI Afterburner\RTCore64.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] R4 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x] R4 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x] R4 CLKMSVC10_38F51D56;CyberLink Product - 2013/06/21 08:19;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [x] R4 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x] S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x] S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-07-07 10:55 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-07-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-07 10:28] . 2013-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-07 10:55] . 2013-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-07 10:55] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-01-24 10355200] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-07-27 1935120] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-03-11 1128448] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-19 172168] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-19 400008] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-19 441992] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2013-02-21 2991856] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.at/ mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 10.0.0.138 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-BattlEye for A2 - c:\program files (x86)\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-07-07 14:16:28 ComboFix-quarantined-files.txt 2013-07-07 12:16 ComboFix2.txt 2013-07-07 08:01 . Vor Suchlauf: 18 Verzeichnis(se), 658.800.844.800 Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 658.761.068.544 Bytes frei . - - End Of File - - 7C0624FDF0F9BCFAB348A3502C5EDB59 --- --- --- D41D8CD98F00B204E9800998ECF8427E |
07.07.2013, 14:10 | #6 |
/// the machine /// TB-Ausbilder | Google chrom offnet sich unkontrolliert Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST Log bitte.
__________________ --> Google chrom offnet sich unkontrolliert |
07.07.2013, 19:35 | #7 |
| Google chrom offnet sich unkontrolliert Ich muss mich leider korrigiern. Es werden so viele neue browser angelegt bzw alte gerefresht, sodas der pc nichtmehr damit klarkommt. Der Virus hat komischer weise an agresivität zugelegt. Er benützt auch immer den browser den ich gerade benütze bzw der als letztes benützt wurde. Ich habe mir bei HP eine neue backup cd bestellt doch ich habe angst das der virus bleibt oder direkt im bios sitzt. Haben sie irgendeine idee welche schritte als nächstes unternommen werden müssen? danke für ihre hilfe bisher. Soll ich versuchen alle tests neu durchzuführen, da ich den pc wiederherstellen musste weil er sich nichtmehr starten ließ. Geändert von whiskeyboy9 (07.07.2013 um 19:57 Uhr) |
07.07.2013, 20:47 | #8 |
/// the machine /// TB-Ausbilder | Google chrom offnet sich unkontrolliert Auf jeden Fall die beiden Tools oben laufen lassen und ein frisches FRST log.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.07.2013, 17:34 | #9 |
| Google chrom offnet sich unkontrolliert FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013 Ran by BoB (administrator) on 07-07-2013 21:12:06 Running from C:\Users\BoB\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10n_ActiveX.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [10355200 2011-01-24] (Intel Corporation) HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1832760 2012-09-20] (Logitech, Inc.) HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-11] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated) HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1933584 2011-02-04] (Intel(R) Corporation) HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-13] (Intel Corporation) HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-15] (Hewlett-Packard Development Company L.P.) HKLM-x32\...\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-01-25] (cyberlink) HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [87336 2010-02-03] (CyberLink Corp.) HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-03-15] (Advanced Micro Devices, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) BHO-x32: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 ==================== Services (Whitelisted) ================= S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-01-25] (CyberLink) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-02-04] () ==================== Drivers (Whitelisted) ==================== ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-08 03:31 - 2013-07-08 03:31 - 01924480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-07-08 03:31 - 2013-07-08 03:31 - 00951680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys 2013-07-08 03:30 - 2009-06-10 22:30 - 00048265 ____A C:\Windows\HomePremium.xml 2013-07-08 03:29 - 2013-07-08 03:29 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-07-07 21:12 - 2013-07-07 21:12 - 00000000 ____D C:\FRST 2013-07-07 21:08 - 2013-07-07 21:08 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\BoB\Desktop\JRT.exe 2013-07-07 21:07 - 2013-07-07 21:07 - 00650027 ____A C:\Users\BoB\Desktop\adwcleaner.exe 2013-07-07 20:33 - 2013-07-07 20:33 - 05087001 ____A (Swearware) C:\Users\BoB\Desktop\ComboFix.exe 2013-07-07 20:32 - 2013-07-07 20:33 - 01934636 ____A (Farbar) C:\Users\BoB\Desktop\FRST64.exe 2013-07-07 18:41 - 2012-02-17 08:38 - 01031680 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll 2013-07-07 18:41 - 2012-02-17 07:34 - 00826880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-07-07 18:41 - 2012-02-17 06:58 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2013-07-07 18:41 - 2012-02-17 06:57 - 00023552 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys 2013-07-07 18:40 - 2013-07-07 18:40 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Macromedia 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\Users\BoB\AppData\Roaming\ATI 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Adobe 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\Users\BoB\AppData\Local\ATI 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\ProgramData\ATI 2013-07-07 18:38 - 2013-07-07 18:38 - 00057560 ____A C:\Users\BoB\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 18:38 - 2013-07-07 18:38 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Synaptics 2013-07-07 18:38 - 2013-07-07 18:38 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel Corporation 2013-07-07 18:38 - 2013-07-07 18:38 - 00000000 ____D C:\Users\BoB\AppData\Roaming\hpqLog 2013-07-07 18:37 - 2013-07-07 18:37 - 00000000 ____D C:\Users\BoB\AppData\Local\VirtualStore 2013-07-07 18:37 - 2012-06-03 00:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2013-07-07 18:37 - 2012-06-03 00:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2013-07-07 18:37 - 2012-06-03 00:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2013-07-07 18:37 - 2012-06-03 00:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2013-07-07 18:36 - 2013-07-07 18:38 - 00000000 ____D C:\users\BoB 2013-07-07 18:36 - 2013-07-07 18:36 - 00000020 ___SH C:\Users\BoB\ntuser.ini 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Public\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Public\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Vorlagen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Startmenü 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Netzwerkumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Lokale Einstellungen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Eigene Dateien 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Druckumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\AppData\Local\Verlauf 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\AppData\Local\Verlauf 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Vorlagen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Startmenü 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Netzwerkumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Lokale Einstellungen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Eigene Dateien 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Druckumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\AppData\Local\Verlauf 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\AppData\Local\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Programme 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Vorlagen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Startmenü 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Favoriten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Dokumente 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Program Files\Gemeinsame Dateien 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Dokumente und Einstellungen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel 2013-07-07 18:36 - 2012-06-03 00:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2013-07-07 18:36 - 2012-06-03 00:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2013-07-07 18:36 - 2012-06-03 00:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2013-07-07 18:36 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2013-07-07 18:36 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2013-07-07 17:57 - 2013-07-07 17:57 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-07-07 17:57 - 2013-07-07 17:57 - 00000000 ____D C:\ProgramData\Norton 2013-07-07 17:57 - 2013-07-07 17:57 - 00000000 ____D C:\ProgramData\CyberLink 2013-07-07 17:56 - 2013-07-07 17:56 - 00505128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2013-07-07 17:56 - 2013-07-07 17:56 - 00353576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2013-07-07 17:56 - 2013-07-07 17:56 - 00029480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WDKMD_01009.Wdf 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\Program Files\Common Files\AuthenTec 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\Program Files (x86)\Intel Corporation 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\Program Files (x86)\HP SimplePass 2011 2013-07-07 17:54 - 2013-07-07 17:54 - 00000000 ____D C:\Users\Public\Documents\YouCam 2013-07-07 17:53 - 2013-07-07 17:57 - 00000000 ____D C:\Program Files (x86)\CyberLink 2013-07-07 17:51 - 2013-07-07 17:51 - 00002179 ____A C:\Users\Public\Desktop\HP Support Assistant.lnk 2013-07-07 17:51 - 2013-07-07 17:51 - 00000000 ____D C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60} 2013-07-07 17:50 - 2013-07-07 17:50 - 00000593 ____A C:\Windows\System32\ndCPrepLog 2013-07-07 17:49 - 2013-07-07 17:49 - 00000000 ____A C:\Windows\ativpsrm.bin 2013-07-07 17:48 - 2013-07-07 17:52 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-07-07 17:48 - 2013-07-07 17:48 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_iBtFltCoex_01009.Wdf 2013-07-07 17:48 - 2013-07-07 17:48 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_btmaux_01009.Wdf 2013-07-07 17:46 - 2013-07-07 18:03 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-07-07 17:46 - 2013-07-07 17:55 - 00000000 ____D C:\ProgramData\Intel 2013-07-07 17:46 - 2013-07-07 17:55 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2013-07-07 17:46 - 2013-07-07 17:47 - 00000000 ____D C:\Windows\HPQ 2013-07-07 17:46 - 2013-07-07 17:46 - 00000000 ____D C:\Program Files\Intel 2013-07-07 17:46 - 2013-07-07 17:46 - 00000000 ____D C:\Program Files (x86)\Cisco 2013-07-07 17:45 - 2013-07-07 17:45 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_wbf_vfs_0018_01_09_00.Wdf 2013-07-07 17:45 - 2013-07-07 17:45 - 00000000 ____D C:\Program Files\Validity Sensors 2013-07-07 17:45 - 2013-07-07 17:45 - 00000000 ____D C:\Program Files (x86)\Renesas Electronics 2013-07-07 17:44 - 2013-07-07 17:48 - 00015622 ____A C:\Windows\DPINST.LOG 2013-07-07 17:44 - 2013-07-07 17:44 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-07-07 17:44 - 2013-07-07 17:44 - 00000000 ____D C:\Program Files\Synaptics 2013-07-07 17:43 - 2013-07-07 17:57 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-07 17:43 - 2013-07-07 17:46 - 00000000 ____D C:\Program Files\Common Files\Intel 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Windows\SysWOW64\sda 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Windows\System32\SRSLabs 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Program Files\IDT 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-07-07 17:43 - 2011-03-11 12:23 - 06351872 ____A (IDT, Inc.) C:\Windows\System32\IDTNGUI.exe 2013-07-07 17:43 - 2011-03-11 12:23 - 04642816 ____A (IDT, Inc.) C:\Windows\System32\stlang64.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 03293184 ____A (IDT, Inc.) C:\Windows\System32\IDTNHP.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 01523712 ____A (IDT, Inc.) C:\Windows\System32\IDTNC64.cpl 2013-07-07 17:43 - 2011-03-11 12:23 - 01500672 ____A (IDT, Inc.) C:\Windows\System32\stapo64.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 01128448 ____A (IDT, Inc.) C:\Windows\sttray64.exe 2013-07-07 17:43 - 2011-03-11 12:23 - 01020416 ____A (IDT, Inc.) C:\Windows\System32\IDTNX.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 00652288 ____N (IDT, Inc.) C:\Windows\System32\stapi64.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 00521728 ____A (IDT, Inc.) C:\Windows\System32\Drivers\stwrt64.sys 2013-07-07 17:43 - 2011-03-11 12:23 - 00431616 ____A (IDT, Inc.) C:\Windows\System32\stcplx64.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 00221184 ____A (IDT, Inc.) C:\Windows\System32\HPToneCtrls64.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 00220160 ____A (IDT, Inc.) C:\Windows\System32\staco64.dll 2013-07-07 17:43 - 2011-03-11 12:23 - 00212480 ____A (IDT, Inc.) C:\Windows\System32\IDTNJ.exe 2013-07-07 17:43 - 2011-02-17 03:11 - 00428136 ____A (Realtek ) C:\Windows\System32\Drivers\Rt64win7.sys 2013-07-07 17:43 - 2011-02-17 03:11 - 00107552 ____A (Realtek Semiconductor Corporation) C:\Windows\System32\RTNUninst64.dll 2013-07-07 17:43 - 2011-02-17 03:11 - 00074272 ____A C:\Windows\System32\RtNicProp64.dll 2013-07-07 17:43 - 2011-01-13 02:10 - 09888360 ____A (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll 2013-07-07 17:43 - 2011-01-13 02:10 - 00333928 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\RtsPStor.sys 2013-07-07 17:43 - 2010-04-02 00:11 - 00162304 ____A (Andrea Electronics Corporation) C:\Windows\System32\AESTAC64.dll 2013-07-07 17:43 - 2009-10-10 10:45 - 00442368 ____A (Andrea Electronics Corporation) C:\Windows\System32\AESTEC64.dll 2013-07-07 17:43 - 2009-03-03 11:58 - 00068608 ____A (Andrea Electronics Corporation) C:\Windows\System32\AESTAR64.dll 2013-07-07 17:43 - 2009-03-03 11:47 - 00090624 ____A (Andrea Electronics Corporation) C:\Windows\System32\AESTCo64.dll 2013-07-07 17:42 - 2011-01-12 22:03 - 00003155 ____A C:\Windows\SysWOW64\atipblup.dat 2013-07-07 17:42 - 2011-01-12 22:03 - 00003155 ____A C:\Windows\System32\atipblup.dat 2013-07-07 17:41 - 2013-07-07 17:42 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-07-07 17:41 - 2013-07-07 17:41 - 00000000 ____D C:\Program Files\ATI 2013-07-07 17:40 - 2011-03-15 20:28 - 09259520 ____A (ATI Technologies Inc.) C:\Windows\System32\Drivers\atikmdag.sys 2013-07-07 17:40 - 2011-03-15 20:26 - 22518272 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll 2013-07-07 17:40 - 2011-03-15 20:06 - 17397248 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-07-07 17:40 - 2011-03-15 20:02 - 00680960 ____A (ATI Technologies Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-07-07 17:40 - 2011-03-15 20:02 - 00152384 ____A C:\Windows\System32\atiapfxx.blb 2013-07-07 17:40 - 2011-03-15 20:02 - 00143360 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe 2013-07-07 17:40 - 2011-03-15 20:01 - 00796160 ____A (ATI Technologies Inc. ) C:\Windows\System32\aticfx64.dll 2013-07-07 17:40 - 2011-03-15 19:59 - 00480256 ____A (AMD) C:\Windows\System32\atieclxx.exe 2013-07-07 17:40 - 2011-03-15 19:59 - 00462848 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll 2013-07-07 17:40 - 2011-03-15 19:58 - 00203776 ____A (AMD) C:\Windows\System32\atiesrxx.exe 2013-07-07 17:40 - 2011-03-15 19:57 - 00423424 ____A (ATI Technologies, Inc.) C:\Windows\System32\atipdl64.dll 2013-07-07 17:40 - 2011-03-15 19:57 - 00356352 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\atipdlxx.dll 2013-07-07 17:40 - 2011-03-15 19:57 - 00278528 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\Oemdspif.dll 2013-07-07 17:40 - 2011-03-15 19:57 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll 2013-07-07 17:40 - 2011-03-15 19:56 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll 2013-07-07 17:40 - 2011-03-15 19:56 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2013-07-07 17:40 - 2011-03-15 19:56 - 00016384 ____A (AMD) C:\Windows\System32\atimuixx.dll 2013-07-07 17:40 - 2011-03-15 19:54 - 04277760 ____A (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-07-07 17:40 - 2011-03-15 19:46 - 05044224 ____A (ATI Technologies Inc. ) C:\Windows\System32\atidxx64.dll 2013-07-07 17:40 - 2011-03-15 19:39 - 07025152 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll 2013-07-07 17:40 - 2011-03-15 19:39 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll 2013-07-07 17:40 - 2011-03-15 19:39 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-07-07 17:40 - 2011-03-15 19:39 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll 2013-07-07 17:40 - 2011-03-15 19:39 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-07-07 17:40 - 2011-03-15 19:38 - 05619200 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-07-07 17:40 - 2011-03-15 19:37 - 04294656 ____A (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-07-07 17:40 - 2011-03-15 19:35 - 03239936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll 2013-07-07 17:40 - 2011-03-15 19:35 - 01912832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll 2013-07-07 17:40 - 2011-03-15 19:35 - 01208320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6v.dll 2013-07-07 17:40 - 2011-03-15 19:32 - 00788800 ____A C:\Windows\System32\atiumd6a.cap 2013-07-07 17:40 - 2011-03-15 19:31 - 05438976 ____A (ATI Technologies Inc. ) C:\Windows\System32\atiumd64.dll 2013-07-07 17:40 - 2011-03-15 19:31 - 00058880 ____A (AMD) C:\Windows\System32\coinst.dll 2013-07-07 17:40 - 2011-03-15 19:28 - 03471872 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-07-07 17:40 - 2011-03-15 19:27 - 00788800 ____A C:\Windows\SysWOW64\atiumdva.cap 2013-07-07 17:40 - 2011-03-15 19:25 - 00360448 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll 2013-07-07 17:40 - 2011-03-15 19:25 - 00258048 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-07-07 17:40 - 2011-03-15 19:25 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll 2013-07-07 17:40 - 2011-03-15 19:24 - 00301056 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys 2013-07-07 17:40 - 2011-03-15 19:24 - 00039936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll 2013-07-07 17:40 - 2011-03-15 19:24 - 00039936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll 2013-07-07 17:40 - 2011-03-15 19:24 - 00032768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-07-07 17:40 - 2011-03-15 19:24 - 00012800 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-07-07 17:40 - 2011-03-15 19:23 - 00053248 ____A (ATI Technologies Inc.) C:\Windows\System32\Drivers\ati2erec.dll 2013-07-07 17:40 - 2011-03-15 19:23 - 00038400 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll 2013-07-07 17:40 - 2011-03-15 19:23 - 00031232 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-07-07 17:40 - 2011-03-15 19:23 - 00028672 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-07-07 17:40 - 2011-03-15 19:16 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll 2013-07-07 17:40 - 2011-03-15 19:16 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll 2013-07-07 17:40 - 2011-03-15 19:16 - 00052736 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-07-07 17:40 - 2011-03-15 19:16 - 00052736 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-07-07 17:40 - 2011-02-02 03:01 - 00227586 ____A C:\Windows\System32\atiicdxx.dat 2013-07-07 17:40 - 2011-01-27 19:29 - 00013476 ____A C:\Windows\System32\iglhxs64.vp 2013-07-07 17:40 - 2011-01-27 19:15 - 04368920 ____A (Intel Corporation) C:\Windows\System32\GfxUI.exe 2013-07-07 17:40 - 2011-01-27 19:15 - 00509976 ____A (Intel Corporation) C:\Windows\System32\igfxsrvc.exe 2013-07-07 17:40 - 2011-01-27 19:15 - 00418328 ____A (Intel Corporation) C:\Windows\System32\igfxpers.exe 2013-07-07 17:40 - 2011-01-27 19:15 - 00391704 ____A (Intel Corporation) C:\Windows\System32\hkcmd.exe 2013-07-07 17:40 - 2011-01-27 19:15 - 00239128 ____A (Intel Corporation) C:\Windows\System32\igfxext.exe 2013-07-07 17:40 - 2011-01-27 19:15 - 00179736 ____A C:\Windows\System32\difx64.exe 2013-07-07 17:40 - 2011-01-27 19:15 - 00167960 ____A (Intel Corporation) C:\Windows\System32\igfxtray.exe 2013-07-07 17:40 - 2011-01-27 18:57 - 12273408 ____A (Intel Corporation) C:\Windows\System32\Drivers\igdpmd64.sys 2013-07-07 17:40 - 2011-01-27 18:57 - 12273408 ____A (Intel Corporation) C:\Windows\System32\Drivers\igdkmd64.sys 2013-07-07 17:40 - 2011-01-27 18:57 - 07470080 ____A (Intel Corporation) C:\Windows\System32\igdumd64.dll 2013-07-07 17:40 - 2011-01-27 18:55 - 00960940 ____A C:\Windows\SysWOW64\igkrng600.bin 2013-07-07 17:40 - 2011-01-27 18:55 - 00960940 ____A C:\Windows\System32\igkrng600.bin 2013-07-07 17:40 - 2011-01-27 18:55 - 00213332 ____A C:\Windows\SysWOW64\igfcg600m.bin 2013-07-07 17:40 - 2011-01-27 18:55 - 00213332 ____A C:\Windows\System32\igfcg600m.bin 2013-07-07 17:40 - 2011-01-27 18:55 - 00145804 ____A C:\Windows\SysWOW64\igcompkrng600.bin 2013-07-07 17:40 - 2011-01-27 18:55 - 00145804 ____A C:\Windows\System32\igcompkrng600.bin 2013-07-07 17:40 - 2011-01-27 18:51 - 05689344 ____A (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll 2013-07-07 17:40 - 2011-01-27 18:48 - 00575488 ____A (Intel Corporation) C:\Windows\SysWOW64\igdumdx32.dll 2013-07-07 17:40 - 2011-01-27 18:47 - 07386112 ____A (Intel Corporation) C:\Windows\System32\igd10umd64.dll 2013-07-07 17:40 - 2011-01-27 18:44 - 06068224 ____A (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2013-07-07 17:40 - 2011-01-27 18:38 - 19591680 ____A (Intel Corporation) C:\Windows\System32\ig4icd64.dll 2013-07-07 17:40 - 2011-01-27 18:30 - 14292992 ____A (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll 2013-07-07 17:40 - 2011-01-27 18:26 - 00208335 ____A C:\Windows\System32\Gfxres.th-TH.resources 2013-07-07 17:40 - 2011-01-27 18:26 - 00135119 ____A C:\Windows\System32\Gfxres.ro-RO.resources 2013-07-07 17:40 - 2011-01-27 18:26 - 00133868 ____A C:\Windows\System32\Gfxres.tr-TR.resources 2013-07-07 17:40 - 2011-01-27 18:26 - 00132422 ____A C:\Windows\System32\Gfxres.sv-SE.resources 2013-07-07 17:40 - 2011-01-27 18:26 - 00130414 ____A C:\Windows\System32\Gfxres.hr-HR.resources 2013-07-07 17:40 - 2011-01-27 18:26 - 00127599 ____A C:\Windows\System32\Gfxres.sl-SI.resources 2013-07-07 17:40 - 2011-01-27 18:26 - 00116413 ____A C:\Windows\System32\Gfxres.zh-TW.resources 2013-07-07 17:40 - 2011-01-27 18:26 - 00115195 ____A C:\Windows\System32\Gfxres.zh-CN.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00287232 ____A (Intel Corporation) C:\Windows\System32\igfxrfra.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00287232 ____A (Intel Corporation) C:\Windows\System32\igfxresn.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00287232 ____A (Intel Corporation) C:\Windows\System32\igfxrell.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrsky.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrrus.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrrom.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrptg.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrplk.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrnld.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrita.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrhrv.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrdeu.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\System32\igfxrcsy.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\System32\igfxrtrk.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\System32\igfxrsve.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\System32\igfxrslv.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\System32\igfxrptb.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\System32\igfxrnor.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\System32\igfxrhun.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\System32\igfxrfin.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00285696 ____A (Intel Corporation) C:\Windows\System32\igfxrtha.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00285696 ____A (Intel Corporation) C:\Windows\System32\igfxrdan.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00285184 ____A (Intel Corporation) C:\Windows\System32\igfxrheb.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00285184 ____A (Intel Corporation) C:\Windows\System32\igfxrara.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00283648 ____A (Intel Corporation) C:\Windows\System32\igfxrjpn.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00283136 ____A (Intel Corporation) C:\Windows\System32\igfxrkor.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00282624 ____A (Intel Corporation) C:\Windows\System32\igfxrcht.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00282624 ____A (Intel Corporation) C:\Windows\System32\igfxrchs.lrc 2013-07-07 17:40 - 2011-01-27 18:25 - 00195681 ____A C:\Windows\System32\Gfxres.el-GR.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00180246 ____A C:\Windows\System32\Gfxres.ru-RU.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00154366 ____A C:\Windows\System32\Gfxres.ar-SA.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00151350 ____A C:\Windows\System32\Gfxres.ja-JP.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00147392 ____A C:\Windows\System32\Gfxres.he-IL.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00138635 ____A C:\Windows\System32\Gfxres.it-IT.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00137000 ____A C:\Windows\System32\Gfxres.ko-KR.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00136226 ____A C:\Windows\System32\Gfxres.de-DE.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00136172 ____A C:\Windows\System32\Gfxres.es-ES.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00134081 ____A C:\Windows\System32\Gfxres.fr-FR.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00133321 ____A C:\Windows\System32\Gfxres.pt-BR.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00132876 ____A C:\Windows\System32\Gfxres.nl-NL.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00132861 ____A C:\Windows\System32\Gfxres.hu-HU.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00132299 ____A C:\Windows\System32\Gfxres.pt-PT.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00131897 ____A C:\Windows\System32\Gfxres.cs-CZ.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00131711 ____A C:\Windows\System32\Gfxres.pl-PL.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00131456 ____A C:\Windows\System32\Gfxres.fi-FI.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00131290 ____A C:\Windows\System32\Gfxres.sk-SK.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00127367 ____A C:\Windows\System32\Gfxres.nb-NO.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00127109 ____A C:\Windows\System32\Gfxres.da-DK.resources 2013-07-07 17:40 - 2011-01-27 18:25 - 00126976 ____A (Intel Corporation) C:\Windows\System32\igfxcpl.cpl 2013-07-07 17:40 - 2011-01-27 18:25 - 00122646 ____A C:\Windows\System32\Gfxres.en-US.resources 2013-07-07 17:40 - 2011-01-27 18:24 - 00380928 ____A (Intel Corporation) C:\Windows\System32\igfxTMM.dll 2013-07-07 17:40 - 2011-01-27 18:24 - 00335872 ____A (Intel Corporation) C:\Windows\System32\igfxpph.dll 2013-07-07 17:40 - 2011-01-27 18:24 - 00062464 ____A (Intel Corporation) C:\Windows\System32\igfxsrvc.dll 2013-07-07 17:40 - 2011-01-27 18:24 - 00028672 ____A (Intel Corporation) C:\Windows\System32\igfxexps.dll 2013-07-07 17:40 - 2011-01-27 18:23 - 00385024 ____A (Intel Corporation) C:\Windows\System32\igfxdev.dll 2013-07-07 17:40 - 2011-01-27 18:23 - 00144896 ____A (Intel Corporation) C:\Windows\System32\gfxSrvc.dll 2013-07-07 17:40 - 2011-01-27 18:23 - 00109056 ____A (Intel Corporation) C:\Windows\System32\hccutils.dll 2013-07-07 17:40 - 2011-01-27 18:23 - 00004096 ____A ( ) C:\Windows\System32\IGFXDEVLib.dll 2013-07-07 17:40 - 2011-01-27 18:22 - 09014784 ____A (Intel Corporation) C:\Windows\System32\igfxress.dll 2013-07-07 17:40 - 2011-01-27 18:22 - 00285696 ____A (Intel Corporation) C:\Windows\System32\igfxrenu.lrc 2013-07-07 17:40 - 2011-01-27 18:22 - 00142336 ____A (Intel Corporation) C:\Windows\System32\igfxdo.dll 2013-07-07 17:40 - 2011-01-27 18:18 - 00024576 ____A (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2013-07-07 17:40 - 2011-01-27 18:17 - 00288768 ____A (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 01991936 ____A C:\Windows\System32\iglhxa64.cpa 2013-07-07 17:40 - 2011-01-27 18:11 - 00368640 ____A (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 00364032 ____A (Intel Corporation) C:\Windows\System32\iglhsip64.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 00142848 ____A (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 00122368 ____A (Intel Corporation) C:\Windows\System32\igfxcmrt64.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 00095744 ____A (Intel Corporation) C:\Windows\System32\iglhcp64.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 00094208 ____A C:\Windows\System32\IccLibDll_x64.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 00086528 ____A (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll 2013-07-07 17:40 - 2011-01-27 18:11 - 00060254 ____A C:\Windows\System32\iglhxg64.vp 2013-07-07 17:40 - 2011-01-27 18:11 - 00060226 ____A C:\Windows\System32\iglhxc64.vp 2013-07-07 17:40 - 2011-01-27 18:11 - 00060015 ____A C:\Windows\System32\iglhxo64.vp 2013-07-07 17:40 - 2011-01-27 18:11 - 00001090 ____A C:\Windows\System32\iglhxa64.vp 2013-07-07 17:40 - 2011-01-14 22:00 - 00030831 ____A C:\Windows\atiogl.xml 2013-07-07 17:40 - 2011-01-13 08:03 - 00003155 ____A C:\Windows\SysWOW64\atipblag.dat 2013-07-07 17:40 - 2011-01-13 08:03 - 00003155 ____A C:\Windows\System32\atipblag.dat 2013-07-07 17:40 - 2010-12-22 22:06 - 00008192 ____A C:\Windows\System32\Drivers\IntelMEFWVer.dll 2013-07-07 17:40 - 2010-10-15 11:28 - 00317440 ____A (Intel(R) Corporation) C:\Windows\System32\Drivers\IntcDAud.sys 2013-07-07 17:40 - 2010-10-15 11:27 - 00014848 ____A (Intel(R) Corporation) C:\Windows\System32\IntcDAuC.dll 2013-07-07 17:40 - 2009-05-12 03:35 - 00118784 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atibtmon.exe 2013-07-07 17:39 - 2013-07-07 17:47 - 00000000 ____D C:\Program Files (x86)\Intel 2013-07-07 17:39 - 2013-07-07 17:39 - 00000000 _RASH C:\Windows\SysWOW64\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-042_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130707_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-07 17:39 - 2013-07-07 17:39 - 00000000 _RASH C:\Windows\System32\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-042_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130707_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-07 17:39 - 2013-07-07 17:39 - 00000000 ____D C:\Intel 2013-07-07 17:39 - 2010-12-23 21:09 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2013-07-07 17:35 - 2013-07-07 20:42 - 00292298 ____A C:\Windows\WindowsUpdate.log ==================== One Month Modified Files and Folders ======= 2013-07-08 03:31 - 2013-07-08 03:31 - 01924480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-07-08 03:31 - 2013-07-08 03:31 - 00951680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys 2013-07-08 03:31 - 2011-06-21 21:35 - 00000012 ____A C:\Windows\CSUP.txt 2013-07-08 03:29 - 2013-07-08 03:29 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-07-08 03:29 - 2009-07-14 07:38 - 00025600 __ASH C:\Windows\System32\config\BCD-Template.LOG 2013-07-08 03:29 - 2009-07-14 07:32 - 00028672 ____A C:\Windows\System32\config\BCD-Template 2013-07-08 03:29 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games 2013-07-08 03:29 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker 2013-07-08 03:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-07-07 21:12 - 2013-07-07 21:12 - 00000000 ____D C:\FRST 2013-07-07 21:08 - 2013-07-07 21:08 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\BoB\Desktop\JRT.exe 2013-07-07 21:07 - 2013-07-07 21:07 - 00650027 ____A C:\Users\BoB\Desktop\adwcleaner.exe 2013-07-07 21:06 - 2009-07-14 06:45 - 00031856 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-07 21:06 - 2009-07-14 06:45 - 00031856 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-07 21:03 - 2011-06-21 21:41 - 00643866 ____A C:\Windows\System32\perfh007.dat 2013-07-07 21:03 - 2011-06-21 21:41 - 00126394 ____A C:\Windows\System32\perfc007.dat 2013-07-07 21:03 - 2009-07-14 07:13 - 01472002 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-07 21:02 - 2013-07-07 17:35 - 00292298 ____A C:\Windows\WindowsUpdate.log 2013-07-07 20:59 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-07 20:59 - 2009-07-14 06:51 - 00038236 ____A C:\Windows\setupact.log 2013-07-07 20:33 - 2013-07-07 20:33 - 05087001 ____A (Swearware) C:\Users\BoB\Desktop\ComboFix.exe 2013-07-07 20:33 - 2013-07-07 20:32 - 01934636 ____A (Farbar) C:\Users\BoB\Desktop\FRST64.exe 2013-07-07 18:40 - 2013-07-07 18:40 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Macromedia 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\Users\BoB\AppData\Roaming\ATI 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Adobe 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\Users\BoB\AppData\Local\ATI 2013-07-07 18:39 - 2013-07-07 18:39 - 00000000 ____D C:\ProgramData\ATI 2013-07-07 18:38 - 2013-07-07 18:38 - 00057560 ____A C:\Users\BoB\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 18:38 - 2013-07-07 18:38 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Synaptics 2013-07-07 18:38 - 2013-07-07 18:38 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel Corporation 2013-07-07 18:38 - 2013-07-07 18:38 - 00000000 ____D C:\Users\BoB\AppData\Roaming\hpqLog 2013-07-07 18:38 - 2013-07-07 18:36 - 00000000 ____D C:\users\BoB 2013-07-07 18:37 - 2013-07-07 18:37 - 00000000 ____D C:\Users\BoB\AppData\Local\VirtualStore 2013-07-07 18:37 - 2011-02-10 21:23 - 00000000 ___HD C:\SYSTEM.SAV 2013-07-07 18:37 - 2011-02-10 21:23 - 00000000 ____D C:\SWSetup 2013-07-07 18:37 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\System32\restore 2013-07-07 18:37 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\Recovery 2013-07-07 18:37 - 2007-01-02 03:32 - 00000000 __SHD C:\Recovery 2013-07-07 18:36 - 2013-07-07 18:36 - 00000020 ___SH C:\Users\BoB\ntuser.ini 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Public\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Public\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Vorlagen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Startmenü 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Netzwerkumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Lokale Einstellungen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Eigene Dateien 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Druckumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\AppData\Local\Verlauf 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\AppData\Local\Verlauf 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Vorlagen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Startmenü 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Netzwerkumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Lokale Einstellungen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Eigene Dateien 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Druckumgebung 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Musik 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Bilder 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\AppData\Local\Verlauf 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\AppData\Local\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Users\BoB\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Programme 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Vorlagen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Startmenü 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Favoriten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Dokumente 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\ProgramData\Anwendungsdaten 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Program Files\Gemeinsame Dateien 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 __SHD C:\Dokumente und Einstellungen 2013-07-07 18:36 - 2013-07-07 18:36 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel 2013-07-07 18:36 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default 2013-07-07 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2013-07-07 18:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-07-07 18:07 - 2007-01-02 03:25 - 00000000 ____D C:\Windows\Panther 2013-07-07 18:04 - 2009-07-14 06:46 - 00004059 ____A C:\Windows\DtcInstall.log 2013-07-07 18:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\sysprep 2013-07-07 18:03 - 2013-07-07 17:46 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-07-07 17:57 - 2013-07-07 17:57 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2013-07-07 17:57 - 2013-07-07 17:57 - 00000000 ____D C:\ProgramData\Norton 2013-07-07 17:57 - 2013-07-07 17:57 - 00000000 ____D C:\ProgramData\CyberLink 2013-07-07 17:57 - 2013-07-07 17:53 - 00000000 ____D C:\Program Files (x86)\CyberLink 2013-07-07 17:57 - 2013-07-07 17:43 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-07 17:56 - 2013-07-07 17:56 - 00505128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2013-07-07 17:56 - 2013-07-07 17:56 - 00353576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2013-07-07 17:56 - 2013-07-07 17:56 - 00029480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WDKMD_01009.Wdf 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\Program Files\Common Files\AuthenTec 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\Program Files (x86)\Intel Corporation 2013-07-07 17:55 - 2013-07-07 17:55 - 00000000 ____D C:\Program Files (x86)\HP SimplePass 2011 2013-07-07 17:55 - 2013-07-07 17:46 - 00000000 ____D C:\ProgramData\Intel 2013-07-07 17:55 - 2013-07-07 17:46 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2013-07-07 17:55 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\System32\WinBioDatabase 2013-07-07 17:54 - 2013-07-07 17:54 - 00000000 ____D C:\Users\Public\Documents\YouCam 2013-07-07 17:52 - 2013-07-07 17:48 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-07-07 17:51 - 2013-07-07 17:51 - 00002179 ____A C:\Users\Public\Desktop\HP Support Assistant.lnk 2013-07-07 17:51 - 2013-07-07 17:51 - 00000000 ____D C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60} 2013-07-07 17:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help 2013-07-07 17:50 - 2013-07-07 17:50 - 00000593 ____A C:\Windows\System32\ndCPrepLog 2013-07-07 17:49 - 2013-07-07 17:49 - 00000000 ____A C:\Windows\ativpsrm.bin 2013-07-07 17:49 - 2010-11-21 05:47 - 00004986 ____A C:\Windows\PFRO.log 2013-07-07 17:48 - 2013-07-07 17:48 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_iBtFltCoex_01009.Wdf 2013-07-07 17:48 - 2013-07-07 17:48 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_btmaux_01009.Wdf 2013-07-07 17:48 - 2013-07-07 17:44 - 00015622 ____A C:\Windows\DPINST.LOG 2013-07-07 17:48 - 2011-03-16 21:10 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-07-07 17:47 - 2013-07-07 17:46 - 00000000 ____D C:\Windows\HPQ 2013-07-07 17:47 - 2013-07-07 17:39 - 00000000 ____D C:\Program Files (x86)\Intel 2013-07-07 17:46 - 2013-07-07 17:46 - 00000000 ____D C:\Program Files\Intel 2013-07-07 17:46 - 2013-07-07 17:46 - 00000000 ____D C:\Program Files (x86)\Cisco 2013-07-07 17:46 - 2013-07-07 17:43 - 00000000 ____D C:\Program Files\Common Files\Intel 2013-07-07 17:45 - 2013-07-07 17:45 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_wbf_vfs_0018_01_09_00.Wdf 2013-07-07 17:45 - 2013-07-07 17:45 - 00000000 ____D C:\Program Files\Validity Sensors 2013-07-07 17:45 - 2013-07-07 17:45 - 00000000 ____D C:\Program Files (x86)\Renesas Electronics 2013-07-07 17:45 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\System32\WinBioPlugIns 2013-07-07 17:44 - 2013-07-07 17:44 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-07-07 17:44 - 2013-07-07 17:44 - 00000000 ____D C:\Program Files\Synaptics 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Windows\SysWOW64\sda 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Windows\System32\SRSLabs 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Program Files\IDT 2013-07-07 17:43 - 2013-07-07 17:43 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-07-07 17:42 - 2013-07-07 17:41 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-07-07 17:41 - 2013-07-07 17:41 - 00000000 ____D C:\Program Files\ATI 2013-07-07 17:41 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-07-07 17:39 - 2013-07-07 17:39 - 00000000 _RASH C:\Windows\SysWOW64\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-042_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130707_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-07 17:39 - 2013-07-07 17:39 - 00000000 _RASH C:\Windows\System32\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-042_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130707_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-07 17:39 - 2013-07-07 17:39 - 00000000 ____D C:\Intel 2013-07-07 17:35 - 2007-01-02 03:29 - 00003652 ____A C:\Windows\TSSysprep.log 2013-07-07 17:32 - 2009-07-14 06:45 - 00274464 ____A C:\Windows\System32\FNTCACHE.DAT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2007-01-02 03:26 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2013 Ran by BoB at 2013-07-07 21:12:31 Running from C:\Users\BoB\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3) Adobe Flash Player 10 ActiveX (x32 Version: 10.2.152.32) ATI Catalyst Install Manager (Version: 3.0.816.0) AuthenTec TrueAPI (Version: 1.2.1.33) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2011.0315.958.16016) Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0315.958.16016) Catalyst Control Center InstallProxy (x32 Version: 2011.0315.958.16016) Catalyst Control Center Localization All (x32 Version: 2011.0315.958.16016) Catalyst Control Center Profiles Mobile (x32 Version: 2011.0315.958.16016) CCC Help Chinese Standard (x32 Version: 2011.0315.0957.16016) CCC Help Chinese Traditional (x32 Version: 2011.0315.0957.16016) CCC Help Czech (x32 Version: 2011.0315.0957.16016) CCC Help Danish (x32 Version: 2011.0315.0957.16016) CCC Help Dutch (x32 Version: 2011.0315.0957.16016) CCC Help English (x32 Version: 2011.0315.0957.16016) CCC Help Finnish (x32 Version: 2011.0315.0957.16016) CCC Help French (x32 Version: 2011.0315.0957.16016) CCC Help German (x32 Version: 2011.0315.0957.16016) CCC Help Greek (x32 Version: 2011.0315.0957.16016) CCC Help Hungarian (x32 Version: 2011.0315.0957.16016) CCC Help Italian (x32 Version: 2011.0315.0957.16016) CCC Help Japanese (x32 Version: 2011.0315.0957.16016) CCC Help Korean (x32 Version: 2011.0315.0957.16016) CCC Help Norwegian (x32 Version: 2011.0315.0957.16016) CCC Help Polish (x32 Version: 2011.0315.0957.16016) CCC Help Portuguese (x32 Version: 2011.0315.0957.16016) CCC Help Russian (x32 Version: 2011.0315.0957.16016) CCC Help Spanish (x32 Version: 2011.0315.0957.16016) CCC Help Swedish (x32 Version: 2011.0315.0957.16016) CCC Help Thai (x32 Version: 2011.0315.0957.16016) CCC Help Turkish (x32 Version: 2011.0315.0957.16016) ccc-utility64 (Version: 2011.0315.958.16016) CyberLink PowerDVD 10 (x32 Version: 10.0.3.2714) CyberLink YouCam (x32 Version: 3.5.1.3908) ESU for Microsoft Windows 7 (x32 Version: 1.0.0) HP 3D DriveGuard (Version: 4.1.5.1) HP Connection Manager (x32 Version: 4.0.45.1) HP On Screen Display (x32 Version: 1.1.2) HP Quick Launch (x32 Version: 2.3.6) HP SimplePass 2011 (x32 Version: 5.1.0.495) HP Software Framework (x32 Version: 4.0.110.1) HP Support Assistant (x32 Version: 5.2.9.2) HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3) IDT Audio (x32 Version: 1.0.6329.0) Intel PROSet Wireless Intel(R) Display Audio Driver (x32 Version: 6.14.00.3074) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.2.0511) Intel(R) PROSet/Wireless WiFi-Software (Version: 14.0.3000) Intel(R) Rapid Storage Technology (x32 Version: 10.1.2.1004) Intel(R) Wireless Display Intel(R) Wireless Display (x32 Version: 2.0.30.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) PX Profile Update (x32 Version: 1.00.1.) Realtek Ethernet Controller Driver (x32 Version: 7.41.216.2011) Realtek PCIE Card Reader (x32 Version: 6.1.7600.74) Recovery Manager (x32 Version: 2.0.0) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0) Synaptics Pointing Device Driver (Version: 15.2.4.4) Validity WBF DDK (Version: 4.3.118.0) ==================== Restore Points ========================= 07-07-2013 16:37:29 First_User_Boot 07-07-2013 16:41:58 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {19E12310-C7A2-4136-86D8-CBF43B49522B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-08] (CyberLink) Task: {774368E7-E5E2-42B6-8654-92781BBE2F35} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {AE13D338-A1F9-419D-952E-E87C51A86C9C} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {B6105A45-29BB-4980-A4D6-D4431FC437AC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\First Boot => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2011-02-23] (Hewlett-Packard Company) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/07/2013 09:01:34 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (07/07/2013 08:59:53 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2013 08:31:53 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (07/07/2013 08:29:53 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2013 06:42:08 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . System errors: ============= Microsoft Office Sessions: ========================= Error: (07/07/2013 09:01:34 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. Error: (07/07/2013 08:59:53 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2013 08:31:53 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. Error: (07/07/2013 08:29:53 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/07/2013 06:42:08 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. ==================== Memory info =========================== Percentage of memory in use: 21% Total physical RAM: 8139.86 MB Available physical RAM: 6350.27 MB Total Pagefile: 16277.92 MB Available Pagefile: 14024.68 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:682.97 GB) (Free:655.16 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:15.37 GB) (Free:1.66 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 21053EDB) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=683 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================ |
08.07.2013, 18:25 | #10 |
/// the machine /// TB-Ausbilder | Google chrom offnet sich unkontrolliert Hast Du aktuell noch Probleme? sieht gut aus soweit.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.07.2013, 19:11 | #11 |
| Google chrom offnet sich unkontrolliert gnau das selbe wie forher. nur schlimmer Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by BoB on 08.07.2013 at 18:17:19,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.07.2013 at 18:20:02,75 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und es fängt wieder an FU. Ich hoffe du kannst mir helfen es wird wieder schilmmer und es scheint irgendwie auf zeit zu laufen es ist genau das gleiche spiel wie forher hir mal ein browser da mal ne aktualisierung aber das war das 1. mal auch schon so Geändert von whiskeyboy9 (08.07.2013 um 19:58 Uhr) |
08.07.2013, 21:14 | #12 |
/// the machine /// TB-Ausbilder | Google chrom offnet sich unkontrolliert Lösche bitte COmbofix und lade es neu, lass es nochmal laufen und poste das Logfile.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 19:04 | #13 |
| Google chrom offnet sich unkontrolliert Der Pc war leider WIEDER in einem so schlimmen zustand das ich ihn neu aufgesetzt habe, da er sich nichtmehr starten ließ. Diesmal mit frisch zugeschickter hp recovery CD. Das spiel geht von forne loos ich werde nochmal alle schritte befolgen. (das erneute Combofix durchführen brachte nix) trozdem danke für ihre geduld und hilfe |
09.07.2013, 19:49 | #14 |
/// the machine /// TB-Ausbilder | Google chrom offnet sich unkontrolliert Lass nur mal FRST Laufen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.07.2013, 17:34 | #15 |
| Google chrom offnet sich unkontrolliert FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-07-2013 01 Ran by BoB (administrator) on 10-07-2013 18:33:38 Running from C:\Users\BoB\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard Company) C:\Windows\system32\Hpservice.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\BingBar.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\BingApp.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10n_ActiveX.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (Microsoft Corporation) C:\Windows\system32\makecab.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IgfxTray] - C:\Windows\system32\igfxtray.exe [167960 2011-01-27] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [391704 2011-01-27] (Intel Corporation) HKLM\...\Run: [Persistence] - C:\Windows\system32\igfxpers.exe [418328 2011-01-27] (Intel Corporation) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-11] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated) HKLM\...\Run: [IntelWireless] - "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1933584 2011-02-04] (Intel(R) Corporation) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [10355200 2011-01-24] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-13] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2011-03-15] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [NUSB3MON] - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-15] (Hewlett-Packard Development Company L.P.) HKLM-x32\...\Run: [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [87336 2010-02-03] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-01-25] (cyberlink) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [35736 2010-11-15] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [932288 2010-11-15] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-03-16] (EasyBits Software AS) HKLM-x32\...\Run: [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-27] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-29] (Sun Microsystems, Inc.) HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT/4 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 SearchScopes: HKLM - {20F6E0BA-D9AE-43EA-A258-276EF4814812} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKLM-x32 - {20F6E0BA-D9AE-43EA-A258-276EF4814812} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} SearchScopes: HKCU - {20F6E0BA-D9AE-43EA-A258-276EF4814812} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms} BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll (Symantec Corporation) BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL [52920 2011-03-31] (EasyBits Software Corp.) Tcpip\Parameters: [DhcpNameServer] 10.0.0.138 ==================== Services (Whitelisted) ================= S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-01-25] (CyberLink) R2 HPAuto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [682040 2011-02-16] (Hewlett-Packard) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-02-04] () R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe [130000 2010-11-24] (Symantec Corporation) ==================== Drivers (Whitelisted) ==================== R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20101123.003\BHDrvx64.sys [953904 2010-11-23] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20101123.003\BHDrvx64.sys [953904 2010-11-23] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20101201.001\IDSVia64.sys [476792 2010-11-11] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20101201.001\IDSVia64.sys [476792 2010-11-11] (Symantec Corporation) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110106.003\ENG64.SYS [117880 2011-01-06] (Symantec Corporation) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110106.003\ENG64.SYS [117880 2011-01-06] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110106.003\EX64.SYS [1791096 2011-01-06] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\VirusDefs\20110106.003\EX64.SYS [1791096 2011-01-06] (Symantec Corporation) S3 SRTSP; C:\Windows\system32\drivers\NISx64\1205000.07D\SRTSP64.SYS [735864 2010-11-23] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1205000.07D\SRTSPX64.SYS [40568 2010-11-23] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1205000.07D\SYMDS64.SYS [450608 2010-10-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1205000.07D\SYMEFA64.SYS [802864 2010-11-18] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174640 2013-07-09] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1205000.07D\Ironx64.SYS [171128 2010-11-16] (Symantec Corporation) R1 SymNetS; C:\Windows\system32\drivers\NISx64\1205000.07D\SYMNETS.SYS [382072 2010-12-01] (Symantec Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-10 18:33 - 2013-07-10 18:33 - 01776889 ____A (Farbar) C:\Users\BoB\Desktop\FRST64.exe 2013-07-10 18:33 - 2013-07-10 18:33 - 00000000 ____D C:\FRST 2013-07-10 18:25 - 2013-07-10 18:25 - 00000000 ____D C:\Users\BoB\AppData\Local\CrashDumps 2013-07-10 04:28 - 2013-07-10 04:28 - 01924480 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00287744 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00158208 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00128000 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00090624 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00476160 ____A (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00467456 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00411648 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00357888 ____A (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00294912 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00288256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00270336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00183296 ____A (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00167936 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00046080 ____A (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00030208 ____A (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2013-07-10 04:27 - 2013-07-10 04:27 - 00028672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2013-07-10 04:26 - 2013-07-10 04:26 - 03135488 ____A (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 04:26 - 2013-07-10 04:26 - 01395712 ____A (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 01359872 ____A (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 01164288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 01137664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00976896 ____A (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00741376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00642944 ____A (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-10 04:26 - 2013-07-10 04:26 - 00605552 ____A (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-10 04:26 - 2013-07-10 04:26 - 00566208 ____A (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-10 04:26 - 2013-07-10 04:26 - 00518672 ____A (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-10 04:26 - 2013-07-10 04:26 - 00020352 ____A (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00019328 ____A (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00017792 ____A (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 01118720 ____A (Microsoft Corporation) C:\Windows\system32\sbe.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00961024 ____A (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00951680 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-10 04:25 - 2013-07-10 04:25 - 00850944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00723968 ____A (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00642048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00534528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00267776 ____A (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2013-07-10 04:25 - 2013-07-10 04:25 - 00259072 ____A (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2013-07-10 04:25 - 2013-07-10 04:25 - 00199680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax 2013-07-10 04:23 - 2013-07-10 04:23 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-07-10 04:23 - 2009-06-10 22:30 - 00048265 ____A C:\Windows\HomePremium.xml 2013-07-09 20:09 - 2013-07-09 20:09 - 00000000 ____D C:\HP_TOOLS_mountHPSF 2013-07-09 19:55 - 2013-07-09 19:55 - 00000000 ____D C:\Users\BoB\AppData\Roaming\ATI 2013-07-09 19:55 - 2013-07-09 19:55 - 00000000 ____D C:\Users\BoB\AppData\Local\ATI 2013-07-09 19:54 - 2013-07-09 19:54 - 00003914 ____A C:\Windows\System32\Tasks\User_Feed_Synchronization-{5BEAABCA-6AA0-4D99-9BD3-176B972AEB76} 2013-07-09 19:54 - 2013-07-09 19:54 - 00003868 ____A C:\Windows\System32\Tasks\SetupManager 2013-07-09 19:54 - 2013-07-09 19:54 - 00001443 ____A C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-09 19:54 - 2013-07-09 19:54 - 00001409 ____A C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-07-09 19:54 - 2013-07-09 19:54 - 00000476 ___SH C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini 2013-07-09 19:54 - 2013-07-09 19:54 - 00000174 ___SH C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ___RD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ___RD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Synaptics 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Macromedia 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel Corporation 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\hpqLog 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Adobe 2013-07-09 19:53 - 2013-07-09 19:53 - 00003400 ____A C:\Windows\System32\Tasks\ServicePlan 2013-07-09 19:53 - 2013-07-09 19:53 - 00000000 ____D C:\Users\BoB\AppData\Local\RemEngine 2013-07-09 19:52 - 2013-07-09 19:52 - 00057560 ____A C:\Users\BoB\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-09 19:51 - 2012-02-17 08:38 - 01031680 ____A (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2013-07-09 19:51 - 2012-02-17 07:34 - 00826880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2013-07-09 19:51 - 2012-02-17 06:58 - 00210944 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-07-09 19:51 - 2012-02-17 06:57 - 00023552 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys 2013-07-09 19:48 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Hewlett-Packard 2013-07-09 19:47 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Local\Hewlett-Packard_Company 2013-07-09 19:47 - 2013-07-09 19:53 - 00000000 ____D C:\Users\BoB\AppData\Local\Hewlett-Packard 2013-07-09 19:47 - 2013-07-09 18:50 - 00002128 ____A C:\Users\Public\Desktop\Snapfish.lnk 2013-07-09 19:47 - 2011-03-31 15:59 - 00002186 ____A C:\Users\Public\Desktop\eBay.lnk 2013-07-09 19:45 - 2013-07-09 19:45 - 00000020 ___SH C:\Users\BoB\ntuser.ini 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Vorlagen 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Startmenü 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Netzwerkumgebung 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Lokale Einstellungen 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Eigene Dateien 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Druckumgebung 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Musik 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Bilder 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\AppData\Local\Verlauf 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\AppData\Local\Anwendungsdaten 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Anwendungsdaten 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 ____D C:\Windows\System32\Tasks\Symantec 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 ____D C:\Users\BoB\AppData\Local\VirtualStore 2013-07-09 19:45 - 2012-06-03 00:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-07-09 19:45 - 2012-06-03 00:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-07-09 19:45 - 2012-06-03 00:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-07-09 19:45 - 2012-06-03 00:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-07-09 19:45 - 2012-06-03 00:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-07-09 19:45 - 2012-06-03 00:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-07-09 19:45 - 2012-06-03 00:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-07-09 19:45 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-07-09 19:45 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-07-09 19:44 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Public\Documents\Eigene Musik 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Public\Documents\Eigene Bilder 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Vorlagen 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Startmenü 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Netzwerkumgebung 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Lokale Einstellungen 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Eigene Dateien 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Druckumgebung 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Documents\Eigene Musik 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Documents\Eigene Bilder 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\AppData\Local\Verlauf 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Musik 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Bilder 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\AppData\Local\Verlauf 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Programme 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Vorlagen 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Startmenü 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Favoriten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Dokumente 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Program Files\Gemeinsame Dateien 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Dokumente und Einstellungen 2013-07-09 19:44 - 2009-07-14 06:54 - 00000000 ___RD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-07-09 19:44 - 2009-07-14 06:49 - 00000000 ___RD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-07-09 19:01 - 2013-07-09 19:01 - 00000000 ____D C:\ProgramData\ATI 2013-07-09 18:54 - 2013-07-09 18:54 - 00000000 ____D C:\ProgramData\CyberLink 2013-07-09 18:52 - 2013-07-09 18:52 - 00029480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2013-07-09 18:51 - 2013-07-09 18:51 - 00174640 ____A (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-07-09 18:51 - 2013-07-09 18:51 - 00007440 ____A C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_WDKMD_01009.Wdf 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\Program Files\Symantec 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\Program Files\Common Files\AuthenTec 2013-07-09 18:50 - 2013-07-09 19:45 - 00000000 ____D C:\ProgramData\Norton 2013-07-09 18:50 - 2013-07-09 18:50 - 00003148 ____A C:\Windows\System32\Tasks\MirageAgent 2013-07-09 18:50 - 2013-07-09 18:50 - 00000000 ____D C:\Windows\system32\Drivers\NISx64 2013-07-09 18:50 - 2013-07-09 18:50 - 00000000 ____D C:\Users\Public\Documents\YouCam 2013-07-09 18:47 - 2013-07-09 18:47 - 00000593 ____A C:\Windows\system32\ndCPrepLog 2013-07-09 18:46 - 2013-07-09 18:46 - 00000000 ____A C:\Windows\ativpsrm.bin 2013-07-09 18:44 - 2013-07-09 18:44 - 17773056 ____A (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 12268544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 10884096 ____A (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 09702400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-07-09 18:44 - 2013-07-09 18:44 - 03695416 ____A (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-07-09 18:44 - 2013-07-09 18:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-09 18:44 - 2013-07-09 18:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-09 18:44 - 2013-07-09 18:44 - 02303488 ____A (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 02136064 ____A (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01797632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01785344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01492992 ____A (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-09 18:44 - 2013-07-09 18:44 - 01427456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-07-09 18:44 - 2013-07-09 18:44 - 01389056 ____A (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01344000 ____A (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01126912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01102336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00818176 ____A (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00697344 ____A (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00603648 ____A (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00534528 ____A (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00452608 ____A (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00448512 ____A (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-09 18:44 - 2013-07-09 18:44 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00403248 ____A (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-07-09 18:44 - 2013-07-09 18:44 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00282112 ____A (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00267776 ____A (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00249344 ____A (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00248320 ____A (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00236544 ____A (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00222208 ____A (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00197120 ____A (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00173056 ____A (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00165888 ____A (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00163840 ____A (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00160256 ____A (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00160256 ____A (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00149504 ____A (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00145920 ____A (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00135168 ____A (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00114176 ____A (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00111616 ____A (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00103936 ____A (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00096256 ____A (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00091648 ____A (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00089088 ____A (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00089088 ____A (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00085504 ____A (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00085504 ____A (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00082432 ____A (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00076800 ____A (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-07-09 18:44 - 2013-07-09 18:44 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00065024 ____A (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-07-09 18:44 - 2013-07-09 18:44 - 00055296 ____A (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00049664 ____A (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00048640 ____A (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00039936 ____A (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00030720 ____A (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00012288 ____A (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00010752 ____A (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-09 18:43 - 2013-07-09 18:48 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-07-09 18:43 - 2013-07-09 18:43 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_btmaux_01009.Wdf 2013-07-09 18:42 - 2013-07-09 18:42 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_iBtFltCoex_01009.Wdf 2013-07-09 18:41 - 2013-07-09 18:51 - 00000000 ____D C:\ProgramData\Intel 2013-07-09 18:41 - 2013-07-09 18:42 - 00000000 ____D C:\Windows\HPQ 2013-07-09 18:41 - 2013-07-09 18:41 - 00000000 ____D C:\Program Files\Intel 2013-07-09 18:40 - 2013-07-09 18:40 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_User_wbf_vfs_0018_01_09_00.Wdf 2013-07-09 18:39 - 2013-07-09 18:42 - 00015622 ____A C:\Windows\DPINST.LOG 2013-07-09 18:39 - 2013-07-09 18:39 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-07-09 18:39 - 2013-07-09 18:39 - 00000000 ____D C:\Program Files\Validity Sensors 2013-07-09 18:39 - 2013-07-09 18:39 - 00000000 ____D C:\Program Files\Synaptics 2013-07-09 18:38 - 2013-07-09 18:38 - 00000000 ____D C:\Windows\SysWOW64\sda 2013-07-09 18:38 - 2013-07-09 18:38 - 00000000 ____D C:\Windows\system32\SRSLabs 2013-07-09 18:38 - 2013-07-09 18:38 - 00000000 ____D C:\Program Files\IDT 2013-07-09 18:38 - 2011-03-11 12:23 - 06351872 ____A (IDT, Inc.) C:\Windows\system32\IDTNGUI.exe 2013-07-09 18:38 - 2011-03-11 12:23 - 04642816 ____A (IDT, Inc.) C:\Windows\system32\stlang64.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 03293184 ____A (IDT, Inc.) C:\Windows\system32\IDTNHP.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 01523712 ____A (IDT, Inc.) C:\Windows\system32\IDTNC64.cpl 2013-07-09 18:38 - 2011-03-11 12:23 - 01500672 ____A (IDT, Inc.) C:\Windows\system32\stapo64.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 01128448 ____A (IDT, Inc.) C:\Windows\sttray64.exe 2013-07-09 18:38 - 2011-03-11 12:23 - 01020416 ____A (IDT, Inc.) C:\Windows\system32\IDTNX.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 00652288 ____N (IDT, Inc.) C:\Windows\system32\stapi64.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 00521728 ____A (IDT, Inc.) C:\Windows\system32\Drivers\stwrt64.sys 2013-07-09 18:38 - 2011-03-11 12:23 - 00431616 ____A (IDT, Inc.) C:\Windows\system32\stcplx64.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 00221184 ____A (IDT, Inc.) C:\Windows\system32\HPToneCtrls64.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 00220160 ____A (IDT, Inc.) C:\Windows\system32\staco64.dll 2013-07-09 18:38 - 2011-03-11 12:23 - 00212480 ____A (IDT, Inc.) C:\Windows\system32\IDTNJ.exe 2013-07-09 18:38 - 2011-02-17 03:11 - 00428136 ____A (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-07-09 18:38 - 2011-02-17 03:11 - 00107552 ____A (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2013-07-09 18:38 - 2011-02-17 03:11 - 00074272 ____A C:\Windows\system32\RtNicProp64.dll 2013-07-09 18:38 - 2011-01-13 02:10 - 09888360 ____A (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll 2013-07-09 18:38 - 2011-01-13 02:10 - 00333928 ____A (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsPStor.sys 2013-07-09 18:38 - 2010-04-02 00:11 - 00162304 ____A (Andrea Electronics Corporation) C:\Windows\system32\AESTAC64.dll 2013-07-09 18:38 - 2009-10-10 10:45 - 00442368 ____A (Andrea Electronics Corporation) C:\Windows\system32\AESTEC64.dll 2013-07-09 18:38 - 2009-03-03 11:58 - 00068608 ____A (Andrea Electronics Corporation) C:\Windows\system32\AESTAR64.dll 2013-07-09 18:38 - 2009-03-03 11:47 - 00090624 ____A (Andrea Electronics Corporation) C:\Windows\system32\AESTCo64.dll 2013-07-09 18:37 - 2013-07-09 18:41 - 00000000 ____D C:\Program Files\Common Files\Intel 2013-07-09 18:37 - 2011-01-12 22:03 - 00003155 ____A C:\Windows\SysWOW64\atipblup.dat 2013-07-09 18:37 - 2011-01-12 22:03 - 00003155 ____A C:\Windows\system32\atipblup.dat 2013-07-09 18:36 - 2013-07-09 18:36 - 00000000 ____D C:\Program Files\ATI 2013-07-09 18:35 - 2011-03-15 20:28 - 09259520 ____A (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys 2013-07-09 18:35 - 2011-03-15 20:26 - 22518272 ____A (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll 2013-07-09 18:35 - 2011-03-15 20:06 - 17397248 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll 2013-07-09 18:35 - 2011-03-15 20:02 - 00680960 ____A (ATI Technologies Inc. ) C:\Windows\SysWOW64\aticfx32.dll 2013-07-09 18:35 - 2011-03-15 20:02 - 00152384 ____A C:\Windows\system32\atiapfxx.blb 2013-07-09 18:35 - 2011-03-15 20:02 - 00143360 ____A (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe 2013-07-09 18:35 - 2011-03-15 20:01 - 00796160 ____A (ATI Technologies Inc. ) C:\Windows\system32\aticfx64.dll 2013-07-09 18:35 - 2011-03-15 19:59 - 00480256 ____A (AMD) C:\Windows\system32\atieclxx.exe 2013-07-09 18:35 - 2011-03-15 19:59 - 00462848 ____A (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll 2013-07-09 18:35 - 2011-03-15 19:58 - 00203776 ____A (AMD) C:\Windows\system32\atiesrxx.exe 2013-07-09 18:35 - 2011-03-15 19:57 - 00423424 ____A (ATI Technologies, Inc.) C:\Windows\system32\atipdl64.dll 2013-07-09 18:35 - 2011-03-15 19:57 - 00356352 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\atipdlxx.dll 2013-07-09 18:35 - 2011-03-15 19:57 - 00278528 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\Oemdspif.dll 2013-07-09 18:35 - 2011-03-15 19:57 - 00120320 ____A (AMD) C:\Windows\system32\atitmm64.dll 2013-07-09 18:35 - 2011-03-15 19:56 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll 2013-07-09 18:35 - 2011-03-15 19:56 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll 2013-07-09 18:35 - 2011-03-15 19:56 - 00016384 ____A (AMD) C:\Windows\system32\atimuixx.dll 2013-07-09 18:35 - 2011-03-15 19:54 - 04277760 ____A (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll 2013-07-09 18:35 - 2011-03-15 19:46 - 05044224 ____A (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll 2013-07-09 18:35 - 2011-03-15 19:39 - 07025152 ____A (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll 2013-07-09 18:35 - 2011-03-15 19:39 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll 2013-07-09 18:35 - 2011-03-15 19:39 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll 2013-07-09 18:35 - 2011-03-15 19:39 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll 2013-07-09 18:35 - 2011-03-15 19:39 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll 2013-07-09 18:35 - 2011-03-15 19:38 - 05619200 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll 2013-07-09 18:35 - 2011-03-15 19:37 - 04294656 ____A (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll 2013-07-09 18:35 - 2011-03-15 19:35 - 03239936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll 2013-07-09 18:35 - 2011-03-15 19:35 - 01912832 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll 2013-07-09 18:35 - 2011-03-15 19:35 - 01208320 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6v.dll 2013-07-09 18:35 - 2011-03-15 19:32 - 00788800 ____A C:\Windows\system32\atiumd6a.cap 2013-07-09 18:35 - 2011-03-15 19:31 - 05438976 ____A (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll 2013-07-09 18:35 - 2011-03-15 19:31 - 00058880 ____A (AMD) C:\Windows\system32\coinst.dll 2013-07-09 18:35 - 2011-03-15 19:28 - 03471872 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll 2013-07-09 18:35 - 2011-03-15 19:27 - 00788800 ____A C:\Windows\SysWOW64\atiumdva.cap 2013-07-09 18:35 - 2011-03-15 19:25 - 00360448 ____A (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll 2013-07-09 18:35 - 2011-03-15 19:25 - 00258048 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll 2013-07-09 18:35 - 2011-03-15 19:25 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll 2013-07-09 18:35 - 2011-03-15 19:24 - 00301056 ____A (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys 2013-07-09 18:35 - 2011-03-15 19:24 - 00039936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll 2013-07-09 18:35 - 2011-03-15 19:24 - 00039936 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll 2013-07-09 18:35 - 2011-03-15 19:24 - 00032768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll 2013-07-09 18:35 - 2011-03-15 19:24 - 00012800 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll 2013-07-09 18:35 - 2011-03-15 19:23 - 00053248 ____A (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll 2013-07-09 18:35 - 2011-03-15 19:23 - 00038400 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll 2013-07-09 18:35 - 2011-03-15 19:23 - 00031232 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll 2013-07-09 18:35 - 2011-03-15 19:23 - 00028672 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll 2013-07-09 18:35 - 2011-03-15 19:16 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll 2013-07-09 18:35 - 2011-03-15 19:16 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll 2013-07-09 18:35 - 2011-03-15 19:16 - 00052736 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll 2013-07-09 18:35 - 2011-03-15 19:16 - 00052736 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll 2013-07-09 18:35 - 2011-02-02 03:01 - 00227586 ____A C:\Windows\system32\atiicdxx.dat 2013-07-09 18:35 - 2011-01-27 19:29 - 00013476 ____A C:\Windows\system32\iglhxs64.vp 2013-07-09 18:35 - 2011-01-27 19:15 - 04368920 ____A (Intel Corporation) C:\Windows\system32\GfxUI.exe 2013-07-09 18:35 - 2011-01-27 19:15 - 00509976 ____A (Intel Corporation) C:\Windows\system32\igfxsrvc.exe 2013-07-09 18:35 - 2011-01-27 19:15 - 00418328 ____A (Intel Corporation) C:\Windows\system32\igfxpers.exe 2013-07-09 18:35 - 2011-01-27 19:15 - 00391704 ____A (Intel Corporation) C:\Windows\system32\hkcmd.exe 2013-07-09 18:35 - 2011-01-27 19:15 - 00239128 ____A (Intel Corporation) C:\Windows\system32\igfxext.exe 2013-07-09 18:35 - 2011-01-27 19:15 - 00179736 ____A C:\Windows\system32\difx64.exe 2013-07-09 18:35 - 2011-01-27 19:15 - 00167960 ____A (Intel Corporation) C:\Windows\system32\igfxtray.exe 2013-07-09 18:35 - 2011-01-27 18:57 - 12273408 ____A (Intel Corporation) C:\Windows\system32\Drivers\igdpmd64.sys 2013-07-09 18:35 - 2011-01-27 18:57 - 12273408 ____A (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys 2013-07-09 18:35 - 2011-01-27 18:57 - 07470080 ____A (Intel Corporation) C:\Windows\system32\igdumd64.dll 2013-07-09 18:35 - 2011-01-27 18:55 - 00960940 ____A C:\Windows\SysWOW64\igkrng600.bin 2013-07-09 18:35 - 2011-01-27 18:55 - 00960940 ____A C:\Windows\system32\igkrng600.bin 2013-07-09 18:35 - 2011-01-27 18:55 - 00213332 ____A C:\Windows\SysWOW64\igfcg600m.bin 2013-07-09 18:35 - 2011-01-27 18:55 - 00213332 ____A C:\Windows\system32\igfcg600m.bin 2013-07-09 18:35 - 2011-01-27 18:55 - 00145804 ____A C:\Windows\SysWOW64\igcompkrng600.bin 2013-07-09 18:35 - 2011-01-27 18:55 - 00145804 ____A C:\Windows\system32\igcompkrng600.bin 2013-07-09 18:35 - 2011-01-27 18:51 - 05689344 ____A (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll 2013-07-09 18:35 - 2011-01-27 18:48 - 00575488 ____A (Intel Corporation) C:\Windows\SysWOW64\igdumdx32.dll 2013-07-09 18:35 - 2011-01-27 18:47 - 07386112 ____A (Intel Corporation) C:\Windows\system32\igd10umd64.dll 2013-07-09 18:35 - 2011-01-27 18:44 - 06068224 ____A (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2013-07-09 18:35 - 2011-01-27 18:38 - 19591680 ____A (Intel Corporation) C:\Windows\system32\ig4icd64.dll 2013-07-09 18:35 - 2011-01-27 18:30 - 14292992 ____A (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll 2013-07-09 18:35 - 2011-01-27 18:26 - 00208335 ____A C:\Windows\system32\Gfxres.th-TH.resources 2013-07-09 18:35 - 2011-01-27 18:26 - 00135119 ____A C:\Windows\system32\Gfxres.ro-RO.resources 2013-07-09 18:35 - 2011-01-27 18:26 - 00133868 ____A C:\Windows\system32\Gfxres.tr-TR.resources 2013-07-09 18:35 - 2011-01-27 18:26 - 00132422 ____A C:\Windows\system32\Gfxres.sv-SE.resources 2013-07-09 18:35 - 2011-01-27 18:26 - 00130414 ____A C:\Windows\system32\Gfxres.hr-HR.resources 2013-07-09 18:35 - 2011-01-27 18:26 - 00127599 ____A C:\Windows\system32\Gfxres.sl-SI.resources 2013-07-09 18:35 - 2011-01-27 18:26 - 00116413 ____A C:\Windows\system32\Gfxres.zh-TW.resources 2013-07-09 18:35 - 2011-01-27 18:26 - 00115195 ____A C:\Windows\system32\Gfxres.zh-CN.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00287232 ____A (Intel Corporation) C:\Windows\system32\igfxrfra.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00287232 ____A (Intel Corporation) C:\Windows\system32\igfxresn.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00287232 ____A (Intel Corporation) C:\Windows\system32\igfxrell.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrsky.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrrus.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrrom.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrptg.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrplk.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrnld.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrita.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286720 ____A (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\system32\igfxrsve.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\system32\igfxrslv.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\system32\igfxrptb.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\system32\igfxrnor.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\system32\igfxrhun.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00286208 ____A (Intel Corporation) C:\Windows\system32\igfxrfin.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00285696 ____A (Intel Corporation) C:\Windows\system32\igfxrtha.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00285696 ____A (Intel Corporation) C:\Windows\system32\igfxrdan.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00285184 ____A (Intel Corporation) C:\Windows\system32\igfxrheb.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00285184 ____A (Intel Corporation) C:\Windows\system32\igfxrara.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00283648 ____A (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00283136 ____A (Intel Corporation) C:\Windows\system32\igfxrkor.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00282624 ____A (Intel Corporation) C:\Windows\system32\igfxrcht.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00282624 ____A (Intel Corporation) C:\Windows\system32\igfxrchs.lrc 2013-07-09 18:35 - 2011-01-27 18:25 - 00195681 ____A C:\Windows\system32\Gfxres.el-GR.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00180246 ____A C:\Windows\system32\Gfxres.ru-RU.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00154366 ____A C:\Windows\system32\Gfxres.ar-SA.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00151350 ____A C:\Windows\system32\Gfxres.ja-JP.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00147392 ____A C:\Windows\system32\Gfxres.he-IL.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00138635 ____A C:\Windows\system32\Gfxres.it-IT.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00137000 ____A C:\Windows\system32\Gfxres.ko-KR.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00136226 ____A C:\Windows\system32\Gfxres.de-DE.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00136172 ____A C:\Windows\system32\Gfxres.es-ES.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00134081 ____A C:\Windows\system32\Gfxres.fr-FR.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00133321 ____A C:\Windows\system32\Gfxres.pt-BR.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00132876 ____A C:\Windows\system32\Gfxres.nl-NL.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00132861 ____A C:\Windows\system32\Gfxres.hu-HU.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00132299 ____A C:\Windows\system32\Gfxres.pt-PT.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00131897 ____A C:\Windows\system32\Gfxres.cs-CZ.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00131711 ____A C:\Windows\system32\Gfxres.pl-PL.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00131456 ____A C:\Windows\system32\Gfxres.fi-FI.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00131290 ____A C:\Windows\system32\Gfxres.sk-SK.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00127367 ____A C:\Windows\system32\Gfxres.nb-NO.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00127109 ____A C:\Windows\system32\Gfxres.da-DK.resources 2013-07-09 18:35 - 2011-01-27 18:25 - 00126976 ____A (Intel Corporation) C:\Windows\system32\igfxcpl.cpl 2013-07-09 18:35 - 2011-01-27 18:25 - 00122646 ____A C:\Windows\system32\Gfxres.en-US.resources 2013-07-09 18:35 - 2011-01-27 18:24 - 00380928 ____A (Intel Corporation) C:\Windows\system32\igfxTMM.dll 2013-07-09 18:35 - 2011-01-27 18:24 - 00335872 ____A (Intel Corporation) C:\Windows\system32\igfxpph.dll 2013-07-09 18:35 - 2011-01-27 18:24 - 00062464 ____A (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2013-07-09 18:35 - 2011-01-27 18:24 - 00028672 ____A (Intel Corporation) C:\Windows\system32\igfxexps.dll 2013-07-09 18:35 - 2011-01-27 18:23 - 00385024 ____A (Intel Corporation) C:\Windows\system32\igfxdev.dll 2013-07-09 18:35 - 2011-01-27 18:23 - 00144896 ____A (Intel Corporation) C:\Windows\system32\gfxSrvc.dll 2013-07-09 18:35 - 2011-01-27 18:23 - 00109056 ____A (Intel Corporation) C:\Windows\system32\hccutils.dll 2013-07-09 18:35 - 2011-01-27 18:23 - 00004096 ____A ( ) C:\Windows\system32\IGFXDEVLib.dll 2013-07-09 18:35 - 2011-01-27 18:22 - 09014784 ____A (Intel Corporation) C:\Windows\system32\igfxress.dll 2013-07-09 18:35 - 2011-01-27 18:22 - 00285696 ____A (Intel Corporation) C:\Windows\system32\igfxrenu.lrc 2013-07-09 18:35 - 2011-01-27 18:22 - 00142336 ____A (Intel Corporation) C:\Windows\system32\igfxdo.dll 2013-07-09 18:35 - 2011-01-27 18:18 - 00024576 ____A (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2013-07-09 18:35 - 2011-01-27 18:17 - 00288768 ____A (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 01991936 ____A C:\Windows\system32\iglhxa64.cpa 2013-07-09 18:35 - 2011-01-27 18:11 - 00368640 ____A (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 00364032 ____A (Intel Corporation) C:\Windows\system32\iglhsip64.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 00142848 ____A (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 00122368 ____A (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 00095744 ____A (Intel Corporation) C:\Windows\system32\iglhcp64.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 00094208 ____A C:\Windows\system32\IccLibDll_x64.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 00086528 ____A (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll 2013-07-09 18:35 - 2011-01-27 18:11 - 00060254 ____A C:\Windows\system32\iglhxg64.vp 2013-07-09 18:35 - 2011-01-27 18:11 - 00060226 ____A C:\Windows\system32\iglhxc64.vp 2013-07-09 18:35 - 2011-01-27 18:11 - 00060015 ____A C:\Windows\system32\iglhxo64.vp 2013-07-09 18:35 - 2011-01-27 18:11 - 00001090 ____A C:\Windows\system32\iglhxa64.vp 2013-07-09 18:35 - 2011-01-14 22:00 - 00030831 ____A C:\Windows\atiogl.xml 2013-07-09 18:35 - 2011-01-13 08:03 - 00003155 ____A C:\Windows\SysWOW64\atipblag.dat 2013-07-09 18:35 - 2011-01-13 08:03 - 00003155 ____A C:\Windows\system32\atipblag.dat 2013-07-09 18:35 - 2010-12-22 22:06 - 00008192 ____A C:\Windows\system32\Drivers\IntelMEFWVer.dll 2013-07-09 18:35 - 2010-10-15 11:28 - 00317440 ____A (Intel(R) Corporation) C:\Windows\system32\Drivers\IntcDAud.sys 2013-07-09 18:35 - 2010-10-15 11:27 - 00014848 ____A (Intel(R) Corporation) C:\Windows\system32\IntcDAuC.dll 2013-07-09 18:35 - 2009-05-12 03:35 - 00118784 ____A (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe 2013-07-09 18:34 - 2013-07-09 18:34 - 00000000 _RASH C:\Windows\SysWOW64\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-041_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130709_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-09 18:34 - 2013-07-09 18:34 - 00000000 _RASH C:\Windows\system32\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-041_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130709_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-09 18:34 - 2013-07-09 18:34 - 00000000 ____D C:\Intel 2013-07-09 18:34 - 2010-12-23 21:09 - 00053248 ____A (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll 2013-07-09 18:32 - 2013-07-10 18:23 - 00280338 ____A C:\Windows\WindowsUpdate.log 2013-07-09 18:30 - 2013-07-09 18:30 - 00000056 ___AH C:\Windows\SysWOW64\ezsidmv.dat ==================== One Month Modified Files and Folders ======= 2013-07-10 18:33 - 2013-07-10 18:33 - 01776889 ____A (Farbar) C:\Users\BoB\Desktop\FRST64.exe 2013-07-10 18:33 - 2013-07-10 18:33 - 00000000 ____D C:\FRST 2013-07-10 18:33 - 2013-07-09 18:32 - 00280338 ____A C:\Windows\WindowsUpdate.log 2013-07-10 18:30 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-10 18:30 - 2009-07-14 06:51 - 00046834 ____A C:\Windows\setupact.log 2013-07-10 18:25 - 2013-07-10 18:25 - 00000000 ____D C:\Users\BoB\AppData\Local\CrashDumps 2013-07-10 18:23 - 2009-07-14 06:45 - 00031856 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-10 18:23 - 2009-07-14 06:45 - 00031856 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-10 18:18 - 2010-11-21 05:47 - 00006478 ____A C:\Windows\PFRO.log 2013-07-10 05:30 - 2011-03-31 15:45 - 00000000 ____D C:\ProgramData\WildTangent 2013-07-10 04:28 - 2013-07-10 04:28 - 01924480 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00287744 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00158208 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00128000 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2013-07-10 04:28 - 2013-07-10 04:28 - 00090624 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00476160 ____A (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00467456 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00411648 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00357888 ____A (Microsoft Corporation) C:\Windows\system32\dnsapi.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00294912 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00288256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00270336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00183296 ____A (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00167936 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2013-07-10 04:27 - 2013-07-10 04:27 - 00046080 ____A (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-07-10 04:27 - 2013-07-10 04:27 - 00030208 ____A (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe 2013-07-10 04:27 - 2013-07-10 04:27 - 00028672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe 2013-07-10 04:26 - 2013-07-10 04:26 - 03135488 ____A (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 04:26 - 2013-07-10 04:26 - 01395712 ____A (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 01359872 ____A (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 01164288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 01137664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00976896 ____A (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00741376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00642944 ____A (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-10 04:26 - 2013-07-10 04:26 - 00605552 ____A (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-10 04:26 - 2013-07-10 04:26 - 00566208 ____A (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-10 04:26 - 2013-07-10 04:26 - 00518672 ____A (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-10 04:26 - 2013-07-10 04:26 - 00020352 ____A (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00019328 ____A (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2013-07-10 04:26 - 2013-07-10 04:26 - 00017792 ____A (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 01118720 ____A (Microsoft Corporation) C:\Windows\system32\sbe.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00961024 ____A (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00951680 ____A (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-10 04:25 - 2013-07-10 04:25 - 00850944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00723968 ____A (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00642048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00534528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2013-07-10 04:25 - 2013-07-10 04:25 - 00267776 ____A (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe 2013-07-10 04:25 - 2013-07-10 04:25 - 00259072 ____A (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax 2013-07-10 04:25 - 2013-07-10 04:25 - 00199680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax 2013-07-10 04:25 - 2011-04-01 01:19 - 00000012 ____A C:\Windows\CSUP.txt 2013-07-10 04:23 - 2013-07-10 04:23 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-07-10 04:23 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games 2013-07-10 04:23 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker 2013-07-10 04:22 - 2009-07-14 07:38 - 00025600 __ASH C:\Windows\system32\config\BCD-Template.LOG 2013-07-10 04:22 - 2009-07-14 07:32 - 00028672 ____A C:\Windows\system32\config\BCD-Template 2013-07-09 20:09 - 2013-07-09 20:09 - 00000000 ____D C:\HP_TOOLS_mountHPSF 2013-07-09 19:55 - 2013-07-09 19:55 - 00000000 ____D C:\Users\BoB\AppData\Roaming\ATI 2013-07-09 19:55 - 2013-07-09 19:55 - 00000000 ____D C:\Users\BoB\AppData\Local\ATI 2013-07-09 19:54 - 2013-07-09 19:54 - 00003914 ____A C:\Windows\System32\Tasks\User_Feed_Synchronization-{5BEAABCA-6AA0-4D99-9BD3-176B972AEB76} 2013-07-09 19:54 - 2013-07-09 19:54 - 00003868 ____A C:\Windows\System32\Tasks\SetupManager 2013-07-09 19:54 - 2013-07-09 19:54 - 00001443 ____A C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-09 19:54 - 2013-07-09 19:54 - 00001409 ____A C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2013-07-09 19:54 - 2013-07-09 19:54 - 00000476 ___SH C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini 2013-07-09 19:54 - 2013-07-09 19:54 - 00000174 ___SH C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ___RD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ___RD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Synaptics 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Macromedia 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel Corporation 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\hpqLog 2013-07-09 19:54 - 2013-07-09 19:54 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Adobe 2013-07-09 19:54 - 2013-07-09 19:48 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Hewlett-Packard 2013-07-09 19:54 - 2013-07-09 19:47 - 00000000 ____D C:\Users\BoB\AppData\Local\Hewlett-Packard_Company 2013-07-09 19:54 - 2013-07-09 19:44 - 00000000 ____D C:\Users\BoB 2013-07-09 19:53 - 2013-07-09 19:53 - 00003400 ____A C:\Windows\System32\Tasks\ServicePlan 2013-07-09 19:53 - 2013-07-09 19:53 - 00000000 ____D C:\Users\BoB\AppData\Local\RemEngine 2013-07-09 19:53 - 2013-07-09 19:47 - 00000000 ____D C:\Users\BoB\AppData\Local\Hewlett-Packard 2013-07-09 19:52 - 2013-07-09 19:52 - 00057560 ____A C:\Users\BoB\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-09 19:47 - 2011-03-31 15:59 - 00000000 ___RD C:\Program Files\Online Services 2013-07-09 19:47 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-07-09 19:46 - 2011-02-10 21:23 - 00000000 ___HD C:\SYSTEM.SAV 2013-07-09 19:46 - 2011-02-10 21:23 - 00000000 ____D C:\SWSetup 2013-07-09 19:46 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\restore 2013-07-09 19:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Recovery 2013-07-09 19:46 - 2007-01-02 03:32 - 00000000 __SHD C:\Recovery 2013-07-09 19:45 - 2013-07-09 19:45 - 00000020 ___SH C:\Users\BoB\ntuser.ini 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Vorlagen 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Startmenü 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Netzwerkumgebung 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Lokale Einstellungen 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Eigene Dateien 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Druckumgebung 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Musik 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Documents\Eigene Bilder 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\AppData\Local\Verlauf 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\AppData\Local\Anwendungsdaten 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 __SHD C:\Users\BoB\Anwendungsdaten 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 ____D C:\Windows\System32\Tasks\Symantec 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 ____D C:\Users\BoB\AppData\Roaming\Intel 2013-07-09 19:45 - 2013-07-09 19:45 - 00000000 ____D C:\Users\BoB\AppData\Local\VirtualStore 2013-07-09 19:45 - 2013-07-09 18:50 - 00000000 ____D C:\ProgramData\Norton 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Public\Documents\Eigene Musik 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Public\Documents\Eigene Bilder 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Vorlagen 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Startmenü 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Netzwerkumgebung 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Lokale Einstellungen 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Eigene Dateien 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Druckumgebung 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Documents\Eigene Musik 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Documents\Eigene Bilder 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\AppData\Local\Verlauf 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\AppData\Local\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Musik 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\Documents\Eigene Bilder 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\AppData\Local\Verlauf 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Users\Default User\AppData\Local\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Programme 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Vorlagen 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Startmenü 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Favoriten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Dokumente 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\ProgramData\Anwendungsdaten 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Program Files\Gemeinsame Dateien 2013-07-09 19:44 - 2013-07-09 19:44 - 00000000 __SHD C:\Dokumente und Einstellungen 2013-07-09 19:44 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-07-09 19:44 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2013-07-09 19:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-07-09 19:42 - 2011-04-01 01:25 - 00643866 ____A C:\Windows\system32\perfh007.dat 2013-07-09 19:42 - 2011-04-01 01:25 - 00126394 ____A C:\Windows\system32\perfc007.dat 2013-07-09 19:42 - 2009-07-14 07:13 - 01472002 ____A C:\Windows\system32\PerfStringBackup.INI 2013-07-09 19:38 - 2007-01-02 03:25 - 00000000 ____D C:\Windows\Panther 2013-07-09 19:01 - 2013-07-09 19:01 - 00000000 ____D C:\ProgramData\ATI 2013-07-09 19:01 - 2011-03-31 15:53 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2013-07-09 19:01 - 2009-07-14 06:46 - 00005075 ____A C:\Windows\DtcInstall.log 2013-07-09 19:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep 2013-07-09 18:54 - 2013-07-09 18:54 - 00000000 ____D C:\ProgramData\CyberLink 2013-07-09 18:54 - 2011-02-16 20:51 - 00000000 ___HD C:\HP 2013-07-09 18:52 - 2013-07-09 18:52 - 00029480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2013-07-09 18:52 - 2011-02-02 15:31 - 00505128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2013-07-09 18:52 - 2011-02-02 15:31 - 00353576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2013-07-09 18:51 - 2013-07-09 18:51 - 00174640 ____A (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-07-09 18:51 - 2013-07-09 18:51 - 00007440 ____A C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_WDKMD_01009.Wdf 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\ProgramData\Downloaded Installations 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\Program Files\Symantec 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared 2013-07-09 18:51 - 2013-07-09 18:51 - 00000000 ____D C:\Program Files\Common Files\AuthenTec 2013-07-09 18:51 - 2013-07-09 18:41 - 00000000 ____D C:\ProgramData\Intel 2013-07-09 18:51 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioDatabase 2013-07-09 18:50 - 2013-07-09 19:47 - 00002128 ____A C:\Users\Public\Desktop\Snapfish.lnk 2013-07-09 18:50 - 2013-07-09 18:50 - 00003148 ____A C:\Windows\System32\Tasks\MirageAgent 2013-07-09 18:50 - 2013-07-09 18:50 - 00000000 ____D C:\Windows\system32\Drivers\NISx64 2013-07-09 18:50 - 2013-07-09 18:50 - 00000000 ____D C:\Users\Public\Documents\YouCam 2013-07-09 18:48 - 2013-07-09 18:43 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-07-09 18:47 - 2013-07-09 18:47 - 00000593 ____A C:\Windows\system32\ndCPrepLog 2013-07-09 18:46 - 2013-07-09 18:46 - 00000000 ____A C:\Windows\ativpsrm.bin 2013-07-09 18:45 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-07-09 18:44 - 2013-07-09 18:44 - 17773056 ____A (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 12268544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 10884096 ____A (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 09702400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-07-09 18:44 - 2013-07-09 18:44 - 03695416 ____A (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-07-09 18:44 - 2013-07-09 18:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-09 18:44 - 2013-07-09 18:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-09 18:44 - 2013-07-09 18:44 - 02303488 ____A (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 02136064 ____A (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01797632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01785344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01492992 ____A (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-09 18:44 - 2013-07-09 18:44 - 01427456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-07-09 18:44 - 2013-07-09 18:44 - 01389056 ____A (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01344000 ____A (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01126912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 01102336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00818176 ____A (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00697344 ____A (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00603648 ____A (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00534528 ____A (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00452608 ____A (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00448512 ____A (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-09 18:44 - 2013-07-09 18:44 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00403248 ____A (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-07-09 18:44 - 2013-07-09 18:44 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00282112 ____A (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00267776 ____A (Microsoft Corporation) C:\Windows\system32\ieaksie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00249344 ____A (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00248320 ____A (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00236544 ____A (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00222208 ____A (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00197120 ____A (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00173056 ____A (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00165888 ____A (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00163840 ____A (Microsoft Corporation) C:\Windows\system32\ieakui.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00160256 ____A (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00160256 ____A (Microsoft Corporation) C:\Windows\system32\ieakeng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00149504 ____A (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00145920 ____A (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00135168 ____A (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00114176 ____A (Microsoft Corporation) C:\Windows\system32\admparse.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00111616 ____A (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00103936 ____A (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00096256 ____A (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00091648 ____A (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00089088 ____A (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00089088 ____A (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00085504 ____A (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00085504 ____A (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00082432 ____A (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00076800 ____A (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-07-09 18:44 - 2013-07-09 18:44 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00072704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00065024 ____A (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-07-09 18:44 - 2013-07-09 18:44 - 00055296 ____A (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00049664 ____A (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00048640 ____A (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00039936 ____A (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00030720 ____A (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-07-09 18:44 - 2013-07-09 18:44 - 00012288 ____A (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-07-09 18:44 - 2013-07-09 18:44 - 00010752 ____A (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-09 18:43 - 2013-07-09 18:43 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_btmaux_01009.Wdf 2013-07-09 18:43 - 2011-03-16 21:10 - 00000000 ____D C:\Program Files\Hewlett-Packard 2013-07-09 18:42 - 2013-07-09 18:42 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_iBtFltCoex_01009.Wdf 2013-07-09 18:42 - 2013-07-09 18:41 - 00000000 ____D C:\Windows\HPQ 2013-07-09 18:42 - 2013-07-09 18:39 - 00015622 ____A C:\Windows\DPINST.LOG 2013-07-09 18:41 - 2013-07-09 18:41 - 00000000 ____D C:\Program Files\Intel 2013-07-09 18:41 - 2013-07-09 18:37 - 00000000 ____D C:\Program Files\Common Files\Intel 2013-07-09 18:40 - 2013-07-09 18:40 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_User_wbf_vfs_0018_01_09_00.Wdf 2013-07-09 18:39 - 2013-07-09 18:39 - 00000000 ___AH C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-07-09 18:39 - 2013-07-09 18:39 - 00000000 ____D C:\Program Files\Validity Sensors 2013-07-09 18:39 - 2013-07-09 18:39 - 00000000 ____D C:\Program Files\Synaptics 2013-07-09 18:39 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2013-07-09 18:38 - 2013-07-09 18:38 - 00000000 ____D C:\Windows\SysWOW64\sda 2013-07-09 18:38 - 2013-07-09 18:38 - 00000000 ____D C:\Windows\system32\SRSLabs 2013-07-09 18:38 - 2013-07-09 18:38 - 00000000 ____D C:\Program Files\IDT 2013-07-09 18:36 - 2013-07-09 18:36 - 00000000 ____D C:\Program Files\ATI 2013-07-09 18:34 - 2013-07-09 18:34 - 00000000 _RASH C:\Windows\SysWOW64\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-041_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130709_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-09 18:34 - 2013-07-09 18:34 - 00000000 _RASH C:\Windows\system32\Drivers\103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_Q5CH1342P4H_E648941-041_4A_I3389_SHP_V10.31_BF.1B_T111005_W73-1_L407_M8140_J750_7Intel_86A7_92.00_#130709_N_(LS082EA#ABD)_XMOBILE_CN10_Z_2058D110000244620001620100.MRK 2013-07-09 18:34 - 2013-07-09 18:34 - 00000000 ____D C:\Intel 2013-07-09 18:31 - 2007-01-02 03:29 - 00005949 ____A C:\Windows\TSSysprep.log 2013-07-09 18:30 - 2013-07-09 18:30 - 00000056 ___AH C:\Windows\SysWOW64\ezsidmv.dat 2013-07-09 18:29 - 2009-07-14 06:45 - 00276216 ____A C:\Windows\system32\FNTCACHE.DAT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2007-01-02 03:26 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-07-2013 01 Ran by BoB at 2013-07-10 18:34:11 Running from C:\Users\BoB\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3) Adobe Flash Player 10 ActiveX (x32 Version: 10.2.152.32) Adobe Reader X MUI (x32 Version: 10.0.0) Adobe Shockwave Player 11.5 (x32 Version: 11.5.9.620) Agatha Christie - Peril at End House (x32 Version: 2.2.0.95) ATI Catalyst Install Manager (Version: 3.0.816.0) AuthenTec TrueAPI (Version: 1.2.1.33) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95) Big Rig Europe (x32 Version: 2.2.0.95) Bing Bar (x32 Version: 7.0.610.0) Blasterball 3 (x32 Version: 2.2.0.95) Bounce Symphony (x32 Version: 2.2.0.95) Cake Mania (x32 Version: 2.2.0.95) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2011.0315.958.16016) Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0315.958.16016) Catalyst Control Center InstallProxy (x32 Version: 2011.0315.958.16016) Catalyst Control Center Localization All (x32 Version: 2011.0315.958.16016) Catalyst Control Center Profiles Mobile (x32 Version: 2011.0315.958.16016) CCC Help Chinese Standard (x32 Version: 2011.0315.0957.16016) CCC Help Chinese Traditional (x32 Version: 2011.0315.0957.16016) CCC Help Czech (x32 Version: 2011.0315.0957.16016) CCC Help Danish (x32 Version: 2011.0315.0957.16016) CCC Help Dutch (x32 Version: 2011.0315.0957.16016) CCC Help English (x32 Version: 2011.0315.0957.16016) CCC Help Finnish (x32 Version: 2011.0315.0957.16016) CCC Help French (x32 Version: 2011.0315.0957.16016) CCC Help German (x32 Version: 2011.0315.0957.16016) CCC Help Greek (x32 Version: 2011.0315.0957.16016) CCC Help Hungarian (x32 Version: 2011.0315.0957.16016) CCC Help Italian (x32 Version: 2011.0315.0957.16016) CCC Help Japanese (x32 Version: 2011.0315.0957.16016) CCC Help Korean (x32 Version: 2011.0315.0957.16016) CCC Help Norwegian (x32 Version: 2011.0315.0957.16016) CCC Help Polish (x32 Version: 2011.0315.0957.16016) CCC Help Portuguese (x32 Version: 2011.0315.0957.16016) CCC Help Russian (x32 Version: 2011.0315.0957.16016) CCC Help Spanish (x32 Version: 2011.0315.0957.16016) CCC Help Swedish (x32 Version: 2011.0315.0957.16016) CCC Help Thai (x32 Version: 2011.0315.0957.16016) CCC Help Turkish (x32 Version: 2011.0315.0957.16016) ccc-utility64 (Version: 2011.0315.958.16016) Chuzzle Deluxe (x32 Version: 2.2.0.95) Crazy Chicken Kart 2 (x32 Version: 2.2.0.95) CyberLink PowerDVD 10 (x32 Version: 10.0.3.2714) CyberLink YouCam (x32 Version: 3.5.1.3908) D3DX10 (x32 Version: 15.4.2368.0902) Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95) el PROSet Wireless Energy Star Digital Logo (x32 Version: 1.0.1) ESU for Microsoft Windows 7 (x32 Version: 1.0.0) Evernote v. 4.2.2 (x32 Version: 4.2.2.3979) Farm Frenzy (x32 Version: 2.2.0.95) FATE (x32 Version: 2.2.0.95) Fishdom (x32 Version: 2.2.0.95) HP 3D DriveGuard (Version: 4.1.5.1) HP Auto (Version: 1.0.12935.3667) HP Client Services (Version: 1.1.12938.3539) HP Connection Manager (x32 Version: 4.0.45.1) HP Customer Experience Enhancements (x32 Version: 6.0.1.7) HP Documentation (x32 Version: 1.1.0.0) HP Games (x32 Version: 1.0.2.4) HP On Screen Display (x32 Version: 1.1.2) HP Power Manager (x32 Version: 1.2.3) HP Quick Launch (x32 Version: 2.3.6) HP Setup (x32 Version: 8.6.4530.3651) HP Setup Manager (x32 Version: 1.1.13231.3673) HP SimplePass 2011 (x32 Version: 5.1.0.495) HP Software Framework (x32 Version: 4.0.110.1) HP Support Assistant (x32 Version: 5.2.9.2) HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3) IDT Audio (x32 Version: 1.0.6329.0) Intel(R) Display Audio Driver (x32 Version: 6.14.00.3074) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.2.0511) Intel(R) PROSet/Wireless WiFi-Software (Version: 14.0.3000) Intel(R) Rapid Storage Technology (x32 Version: 10.1.2.1004) Intel(R) Wireless Display Intel(R) Wireless Display (x32 Version: 2.0.30.0) Java Auto Updater (x32 Version: 2.0.3.1) Java(TM) 6 Update 24 (64-bit) (Version: 6.0.240) Java(TM) 6 Update 24 (x32 Version: 6.0.240) Jewel Quest Solitaire (x32 Version: 2.2.0.95) Junk Mail filter update (x32 Version: 15.4.3502.0922) Magic Desktop (x32 Version: 3.0) Mah Jong Medley (x32 Version: 2.2.0.95) Mesh Runtime (x32 Version: 15.4.5722.2) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.0.50401.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) Mystery P.I. - The London Caper (x32 Version: 2.2.0.95) Namco All-Stars PAC-MAN (x32 Version: 2.2.0.95) Norton Internet Security (x32 Version: 18.5.0.125) Penguins! (x32 Version: 2.2.0.95) Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95) Polar Bowler (x32 Version: 2.2.0.95) PX Profile Update (x32 Version: 1.00.1.) Realtek Ethernet Controller Driver (x32 Version: 7.41.216.2011) Realtek PCIE Card Reader (x32 Version: 6.1.7600.74) Recovery Manager (x32 Version: 2.0.0) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0) Slingo Deluxe (x32 Version: 2.2.0.95) Synaptics Pointing Device Driver (Version: 15.2.4.4) Update Installer for WildTangent Games App (x32) Validity WBF DDK (Version: 4.3.118.0) Virtual Villagers - The Secret City (x32 Version: 2.2.0.95) Wedding Dash (x32 Version: 2.2.0.95) WildTangent Games App (HP Games) (x32 Version: 4.0.5.2) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3508.1109) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3508.1109) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Zuma Deluxe (x32 Version: 2.2.0.95) ==================== Restore Points ========================= 09-07-2013 17:46:37 First_User_Boot 09-07-2013 17:54:21 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {03DBD050-E2B9-4C74-8468-AC29DA476C14} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-08] (CyberLink) Task: {10D9D374-46A1-4713-B9D6-ED064C0676A5} - System32\Tasks\User_Feed_Synchronization-{5BEAABCA-6AA0-4D99-9BD3-176B972AEB76} => C:\Windows\system32\msfeedssync.exe [2013-07-09] (Microsoft Corporation) Task: {231D5E55-D004-492E-A8B1-89A15FFB0CD3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {25D4D95B-92D7-4B00-8EB5-68C7D56B6C34} - System32\Tasks\Symantec\Norton Error Processor 18.5.0.125 => C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\SymErr.exe [2010-12-04] (Symantec Corporation) Task: {46B24604-CE4B-44CF-A0C6-BBFE3F445D4A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\First Boot => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF_Utils.exe [2011-02-23] (Hewlett-Packard Company) Task: {6831AFF1-24B9-4FA0-8E7E-00E721BEFE4E} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {EA4365B5-657B-4B9C-B9D5-040ACE793BAE} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {F07FDEF2-1C1F-4571-9413-FD0F1163B5B3} - System32\Tasks\SetupManager => C:\Program Files (x86)\Hewlett-Packard\Setup Manager\toaster.exe [2011-02-22] (Microsoft) Task: {FD43C76C-D8AC-4491-9623-FEB2E94ED219} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-31] () Task: {FEA1D6FD-EE88-40E1-BC60-AC03BC359AAD} - System32\Tasks\Symantec\Norton Error Analyzer 18.5.0.125 => C:\Program Files (x86)\Norton Internet Security\Engine\18.5.0.125\SymErr.exe [2010-12-04] (Symantec Corporation) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/10/2013 06:30:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/10/2013 06:25:39 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 9.0.8112.16421, Zeitstempel: 0x4d76255d Name des fehlerhaften Moduls: SeaNote.dll, Version: 3.1.158.0, Zeitstempel: 0x4d55f072 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00020fd0 ID des fehlerhaften Prozesses: 0xdf8 Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0 Pfad der fehlerhaften Anwendung: iexplore.exe1 Pfad des fehlerhaften Moduls: iexplore.exe2 Berichtskennung: iexplore.exe3 Error: (07/10/2013 06:24:42 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/10/2013 06:19:44 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (07/09/2013 08:10:16 PM) (Source: DCOM) (User: ) Description: {A483C63A-CDBC-426E-BF93-872502E8144E} Microsoft Office Sessions: ========================= Error: (07/10/2013 06:30:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/10/2013 06:25:39 PM) (Source: Application Error)(User: ) Description: iexplore.exe9.0.8112.164214d76255dSeaNote.dll3.1.158.04d55f072c000000500020fd0df801ce7d8a1358b1d7C:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Microsoft\BingBar\SeaNote.dll5b104e7b-e97d-11e2-a142-ac7289793ea1 Error: (07/10/2013 06:24:42 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/10/2013 06:19:44 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 8139.86 MB Available physical RAM: 5803.82 MB Total Pagefile: 16277.92 MB Available Pagefile: 13554.27 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:683.02 GB) (Free:647.43 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:15.32 GB) (Free:1.67 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: C36D2685) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=683 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================ |
Themen zu Google chrom offnet sich unkontrolliert |
.exe, .html, dauernd, delete, diverse, gemeldet, google, google chrome webcake, hilfe, kontrolliert, nichts, programme, unkontrolliert, vermutlich, öffnet |