![]() |
|
Log-Analyse und Auswertung: Logfile mit FRST64Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Logfile mit FRST64 Hi ![]() Also... ich hab den Rechner meiner Freundin hier und sie hat nen BKA-Trojaner drauf. Ich hab mit FRST64 nen Logfile erstellt und hoffe nun weitere Hilfe hier zu erhaltem, nachdem ich die ganze Nacht schon mit KasperskyUnlocker und oltpenet.exe echt am verzweifeln war... ![]() Ich bin schon wirklich dankbar dafür das ich jetz nen Logfile erstellen konnte und nach all den Versuchen mit anderen Programmen etwas anderes als weiß sehe ![]() Hier der Logfile : FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2013 01 Ran by SYSTEM on 25-08-2013 07:27:58 Running from H:\ Windows 7 Home Premium (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet002 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2095400 2010-04-15] (Synaptics Incorporated) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6234144 2010-03-13] (Realtek Semiconductor) HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company) HKLM\...\Winlogon: [Userinit] C:\Program Files (x86)\Common Files\TrustPort\bin\wsctool.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-12] (Intel Corporation) HKLM-x32\...\Run: [Microsoft Default Manager] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288088 2009-11-11] (Microsoft Corporation) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602680 2010-07-02] (Hewlett-Packard Company) HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-02] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41208 2012-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [x] HKLM-x32\...\Run: [AntivirusCommunicatorAgent] - C:\Program Files (x86)\TrustPort\Antivirus\bin\avcom.exe [880912 2011-08-16] (TrustPort, a.s.) HKLM-x32\...\Run: [TrustPortTray] - C:\Program Files (x86)\Common Files\TrustPort\Bin\tptray.exe [872720 2011-08-16] () HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SearchSettings] - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe [1303360 2013-08-08] (Spigot, Inc.) HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] () HKU\Default User\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] () HKU\Gast\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] () HKU\Gast\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-05-19] (Hewlett-Packard Company) HKU\Gast\...\Run: [Facebook Update] - C:\Users\Gast\AppData\Local\Facebook\Update\FacebookUpdate.exe [137536 2011-09-03] (Facebook Inc.) HKU\Gast\...\Policies\system: [DisableLockWorkstation] 0 HKU\Gast\...\Policies\system: [DisableChangePassword] 0 HKU\Jessica\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] () HKU\Jessica\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-05-19] (Hewlett-Packard Company) HKU\Jessica\...\Run: [EA Core] - C:\Program Files (x86)\Electronic Arts\EADM\Core.exe [3325952 2009-03-28] (Electronic Arts) HKU\Jessica\...\Run: [PCSpeedUp] - C:\Program Files (x86)\PC Beschleunigen\PCSpeedUp.lnk [2194 2011-12-16] () HKU\Jessica\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.) HKU\Jessica\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [79664 2012-06-10] (PC Utilities Pro) HKU\Jessica\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation) HKU\Jessica\...\Policies\system: [DisableLockWorkstation] 0 HKU\Jessica\...\Policies\system: [DisableChangePassword] 0 Startup: C:\Users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * tpnative ==================== Services (Whitelisted) ================= S3 avas_service; C:\Program Files (x86)\TrustPort\Antivirus\bin\avas.exe [504080 2011-08-16] (TrustPort, a.s.) S3 avss_service; C:\Program Files (x86)\TrustPort\Antivirus\bin\avss.exe [303376 2011-08-16] (TrustPort, a.s.) S3 gozer; C:\Program Files (x86)\TrustPort\Antivirus\bin\gozer.exe [491792 2011-08-16] (TrustPort, a.s.) S2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-07-02] () S2 IB Updater; C:\Program Files\IB Updater\ExtensionUpdaterService.exe [188760 2013-01-29] () S2 IBUpdaterService; C:\Windows\system32\dmwu.exe [1455408 2013-04-07] () S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe [227232 2010-09-02] (McAfee, Inc.) S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation) S2 PCSUService; C:\Program Files (x86)\PC Beschleunigen\PCSUService.exe [235232 2011-11-07] () S2 tpmgma_service; C:\Program Files (x86)\Common Files\TrustPort\bin\tpmgma.exe [437000 2011-08-16] (TrustPort, a.s.) ==================== Drivers (Whitelisted) ==================== S3 avasdmft; C:\Windows\System32\DRIVERS\avasdmft.sys [49936 2011-08-16] (TrustPort, a.s.) S3 dsio; C:\Program Files (x86)\Common Files\TrustPort\bin\dsio.sys [20240 2011-08-16] () S3 dsio; C:\Program Files (x86)\Common Files\TrustPort\bin\dsio.sys [20240 2011-08-16] () S2 tdifw; C:\Windows\System32\drivers\tdifw.sys [51472 2011-08-16] () S1 tdimapper; C:\Program Files (x86)\TrustPort\PersonalFirewall\bin\tdimapper.sys [20752 2011-08-16] () S1 tdimapper; C:\Program Files (x86)\TrustPort\PersonalFirewall\bin\tdimapper.sys [20752 2011-08-16] () S3 TPPFHOOK; C:\Program Files (x86)\TrustPort\PersonalFirewall\bin\TPPFHOOK.sys [33552 2011-08-16] () S3 TPPFHOOK; C:\Program Files (x86)\TrustPort\PersonalFirewall\bin\TPPFHOOK.sys [33552 2011-08-16] () S2 tpsec; C:\Windows\System32\drivers\tpsec.sys [51376 2011-08-16] (TrustPort, a.s.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-19 08:37 - 2013-08-19 08:37 - 00126976 ____R C:\Users\Jessica\AppData\Roaming\cache.dat 2013-08-18 05:21 - 2013-07-25 21:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-08-18 05:21 - 2013-07-25 21:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-08-18 05:21 - 2013-07-25 21:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-08-18 05:21 - 2013-07-25 21:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-08-18 05:21 - 2013-07-25 21:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-08-18 05:21 - 2013-07-25 19:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-08-18 05:21 - 2013-07-25 19:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-18 05:21 - 2013-07-25 19:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-18 05:21 - 2013-07-25 19:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-18 05:21 - 2013-07-25 19:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-18 05:21 - 2013-07-25 18:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-18 05:21 - 2013-07-25 18:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-08-18 05:21 - 2013-07-25 17:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-18 05:20 - 2013-07-25 21:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-08-18 05:20 - 2013-07-25 21:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-08-18 05:20 - 2013-07-25 19:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-18 05:20 - 2013-07-25 19:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-18 05:13 - 2013-08-18 05:13 - 00000000 ____D C:\Windows\System32\MRT 2013-08-17 15:46 - 2013-08-17 15:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-17 15:04 - 2013-07-08 21:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2013-08-17 15:04 - 2013-07-08 21:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-08-17 15:04 - 2013-07-08 21:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-08-17 15:04 - 2013-07-08 21:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-08-17 15:04 - 2013-07-08 20:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-17 15:04 - 2013-07-08 20:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-17 15:04 - 2013-07-08 20:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-17 15:04 - 2013-07-08 20:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-17 15:03 - 2013-07-25 01:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL 2013-08-17 15:03 - 2013-07-25 00:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-17 15:03 - 2013-07-18 17:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll 2013-08-17 15:03 - 2013-07-18 17:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-17 15:03 - 2013-07-08 21:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll 2013-08-17 15:03 - 2013-07-08 20:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-17 15:03 - 2013-07-05 22:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-08-17 15:03 - 2013-06-14 20:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\tssecsrv.sys 2013-08-09 13:32 - 2013-08-09 13:32 - 00000000 ____D C:\Program Files (x86)\YTD Toolbar 2013-08-09 13:32 - 2013-08-09 13:32 - 00000000 ____D C:\Program Files (x86)\Application Updater 2013-08-08 14:28 - 2013-08-08 14:28 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-07-31 04:45 - 2013-07-31 04:48 - 00000000 ____D C:\Users\Jessica\Desktop\maxi 2013-07-26 12:26 - 2013-07-26 12:26 - 00000000 ____D C:\Users\Jessica\Documents\Electronic Arts 2013-07-26 12:20 - 2013-07-26 12:20 - 00002090 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-07-26 11:33 - 2013-07-26 11:33 - 00001302 _____ C:\Users\Public\Desktop\Barbie® als Dornröschen.lnk 2013-07-26 11:33 - 2013-07-26 11:33 - 00000000 ____D C:\Program Files (x86)\Mattel Media 2013-07-26 11:32 - 1998-01-23 02:20 - 00305664 _____ (InstallShield Software Corporation ) C:\Windows\IsUn0407.exe ==================== One Month Modified Files and Folders ======= 2013-08-25 07:27 - 2013-08-25 07:27 - 00000000 ____D C:\FRST 2013-08-25 07:23 - 2011-07-13 11:29 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-08-25 07:23 - 2011-01-23 07:21 - 00000000 ____D C:\users\Gast 2013-08-25 07:23 - 2010-12-18 08:11 - 00000000 ____D C:\users\**** 2013-08-25 07:23 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration 2013-08-19 08:37 - 2013-08-19 08:37 - 00126976 ____R C:\Users\****\AppData\Roaming\cache.dat 2013-08-19 07:37 - 2010-09-27 18:43 - 01772050 _____ C:\Windows\WindowsUpdate.log 2013-08-19 07:37 - 2009-07-13 20:45 - 00023024 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-19 07:37 - 2009-07-13 20:45 - 00023024 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-19 07:36 - 2011-11-11 14:31 - 00000000 ____D C:\Users\****\AppData\Local\CrashDumps 2013-08-19 07:32 - 2010-12-18 08:43 - 00003946 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{35225405-9993-4E6A-8DB0-D33F81308529} 2013-08-19 07:27 - 2010-12-29 07:46 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-19 07:27 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-19 07:27 - 2009-07-13 20:51 - 00096939 _____ C:\Windows\setupact.log 2013-08-18 05:55 - 2013-04-22 09:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-18 05:38 - 2012-08-09 09:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-18 05:25 - 2010-12-29 07:46 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-18 05:18 - 2010-07-17 10:47 - 00669456 _____ C:\Windows\System32\perfh007.dat 2013-08-18 05:18 - 2010-07-17 10:47 - 00134982 _____ C:\Windows\System32\perfc007.dat 2013-08-18 05:18 - 2009-07-13 21:13 - 01550506 _____ C:\Windows\System32\PerfStringBackup.INI 2013-08-18 05:16 - 2013-08-18 05:13 - 00000000 ____D C:\Windows\System32\MRT 2013-08-18 05:13 - 2011-04-08 09:53 - 78161360 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-08-17 15:46 - 2013-08-17 15:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-09 14:32 - 2010-12-21 06:28 - 00000000 ____D C:\Users\****\AppData\Roaming\Skype 2013-08-09 13:56 - 2011-09-03 13:56 - 00003850 _____ C:\Windows\System32\Tasks\TrustPort Updater 2013-08-09 13:32 - 2013-08-09 13:32 - 00000000 ____D C:\Program Files (x86)\YTD Toolbar 2013-08-09 13:32 - 2013-08-09 13:32 - 00000000 ____D C:\Program Files (x86)\Application Updater 2013-08-08 14:28 - 2013-08-08 14:28 - 00002212 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-08-08 14:28 - 2010-12-26 10:02 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-31 04:48 - 2013-07-31 04:45 - 00000000 ____D C:\Users\****\Desktop\maxi 2013-07-31 04:44 - 2013-06-09 12:43 - 00000000 ____D C:\Users\****\Desktop\gig 2013-07-26 12:26 - 2013-07-26 12:26 - 00000000 ____D C:\Users\****\Documents\Electronic Arts 2013-07-26 12:20 - 2013-07-26 12:20 - 00002090 _____ C:\Users\Public\Desktop\Die*Sims™*3.lnk 2013-07-26 12:02 - 2011-01-03 12:53 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-07-26 12:01 - 2010-07-17 01:21 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-26 11:33 - 2013-07-26 11:33 - 00001302 _____ C:\Users\Public\Desktop\Barbie® als Dornröschen.lnk 2013-07-26 11:33 - 2013-07-26 11:33 - 00000000 ____D C:\Program Files (x86)\Mattel Media Files to move or delete: ==================== C:\Users\****\AppData\Roaming\cache.dat C:\Users\****\AppData\Local\Temp\0a50e25a83046228c11dcaa7eeed09bb.exe C:\Users\****\AppData\Local\Temp\avguidx.dll C:\Users\****\AppData\Local\Temp\contentDATs.exe C:\Users\****\AppData\Local\Temp\EAD11FA.exe C:\Users\****\AppData\Local\Temp\EAD11FB.exe C:\Users\****\AppData\Local\Temp\EAD12B5.exe C:\Users\****\AppData\Local\Temp\EAD18DC.exe C:\Users\****\AppData\Local\Temp\EAD1B1E.exe C:\Users\****\AppData\Local\Temp\EAD1D40.exe C:\Users\****\AppData\Local\Temp\EAD208A.exe C:\Users\J****\AppData\Local\Temp\EAD2922.exe C:\Users\****\AppData\Local\Temp\EAD2AB7.exe C:\Users\****\AppData\Local\Temp\EAD2F49.exe C:\Users\****\AppData\Local\Temp\EAD361D.exe C:\Users\****\AppData\Local\Temp\EAD3A22.exe C:\Users\****\AppData\Local\Temp\EAD3ABE.exe C:\Users\****\AppData\Local\Temp\EAD3B98.exe C:\Users\****\AppData\Local\Temp\EAD4336.exe C:\Users\****\AppData\Local\Temp\EAD43E2.exe C:\Users\****\AppData\Local\Temp\EAD4558.exe C:\Users\****\AppData\Local\Temp\EAD4D25.exe C:\Users\****\AppData\Local\Temp\EAD4E0F.exe C:\Users\****\AppData\Local\Temp\EAD5427.exe C:\Users\****\AppData\Local\Temp\EAD5669.exe C:\Users\****\AppData\Local\Temp\EAD5A7E.exe C:\Users\****\AppData\Local\Temp\EAD5B96.exe C:\Users\****\AppData\Local\Temp\EAD5D.exe C:\Users\****\AppData\Local\Temp\EAD5DB8.exe C:\Users\****\AppData\Local\Temp\EAD5F8.exe C:\Users\****\AppData\Local\Temp\EAD61AE.exe C:\Users\****\AppData\Local\Temp\EAD6D.exe C:\Users\****\AppData\Local\Temp\EAD7213.exe C:\Users\****\AppData\Local\Temp\EAD735B.exe C:\Users\****\AppData\Local\Temp\EAD89C7.exe C:\Users\****\AppData\Local\Temp\EAD8FB1.exe C:\Users\****\AppData\Local\Temp\EAD908F.exe C:\Users\****\AppData\Local\Temp\EAD9617.exe C:\Users\****\AppData\Local\Temp\EAD9C5D.exe C:\Users\****\AppData\Local\Temp\EAD9E9F.exe C:\Users\****\AppData\Local\Temp\EAD9F69.exe C:\Users\****\AppData\Local\Temp\EADA0E0.exe C:\Users\****\AppData\Local\Temp\EADA15D.exe C:\Users\****\AppData\Local\Temp\EADA4D6.exe C:\Users\****\AppData\Local\Temp\EADA67B.exe C:\Users\****\AppData\Local\Temp\EADA6F8.exe C:\Users\****\AppData\Local\Temp\EADA727.exe C:\Users\****\AppData\Local\Temp\EADAA33.exe C:\Users\****\AppData\Local\Temp\EADAB6B.exe C:\Users\Jessica\AppData\Local\Temp\EADAD8.exe C:\Users\Jessica\AppData\Local\Temp\EADAFBE.exe C:\Users\Jessica\AppData\Local\Temp\EADB337.exe C:\Users\Jessica\AppData\Local\Temp\EADB46.exe C:\Users\Jessica\AppData\Local\Temp\EADB5A7.exe C:\Users\Jessica\AppData\Local\Temp\EADB6EF.exe C:\Users\Jessica\AppData\Local\Temp\EADB7BA.exe C:\Users\Jessica\AppData\Local\Temp\EADBC6B.exe C:\Users\Jessica\AppData\Local\Temp\EADBE01.exe C:\Users\Jessica\AppData\Local\Temp\EADC032.exe C:\Users\Jessica\AppData\Local\Temp\EADC32F.exe C:\Users\Jessica\AppData\Local\Temp\EADC64A.exe C:\Users\Jessica\AppData\Local\Temp\EADC744.exe C:\Users\Jessica\AppData\Local\Temp\EADCC62.exe C:\Users\Jessica\AppData\Local\Temp\EADCCEF.exe C:\Users\Jessica\AppData\Local\Temp\EADCD7B.exe C:\Users\Jessica\AppData\Local\Temp\EADCF3F.exe C:\Users\Jessica\AppData\Local\Temp\EADD46D.exe C:\Users\Jessica\AppData\Local\Temp\EADDAD3.exe C:\Users\Jessica\AppData\Local\Temp\EADDB60.exe C:\Users\Jessica\AppData\Local\Temp\EADDDB1.exe C:\Users\Jessica\AppData\Local\Temp\EADDED9.exe C:\Users\Jessica\AppData\Local\Temp\EADE3D9.exe C:\Users\Jessica\AppData\Local\Temp\EADE5AC.exe C:\Users\Jessica\AppData\Local\Temp\EADE658.exe C:\Users\Jessica\AppData\Local\Temp\EADE6B5.exe C:\Users\Jessica\AppData\Local\Temp\EADE84B.exe C:\Users\Jessica\AppData\Local\Temp\EADEDE6.exe C:\Users\Jessica\AppData\Local\Temp\EADEE34.exe C:\Users\Jessica\AppData\Local\Temp\EADF20B.exe C:\Users\Jessica\AppData\Local\Temp\EADFC38.exe C:\Users\Jessica\AppData\Local\Temp\EADFEE7.exe C:\Users\Jessica\AppData\Local\Temp\EADFF25.exe C:\Users\Jessica\AppData\Local\Temp\GLF2459.tmp.tbDVDV.dll C:\Users\Jessica\AppData\Local\Temp\GLFB966.tmp.ConduitEngineSetup.exe C:\Users\Jessica\AppData\Local\Temp\GLFE334.tmp.tbSear.dll C:\Users\Jessica\AppData\Local\Temp\HPAsset.exe.manifest C:\Users\Jessica\AppData\Local\Temp\hpdobject.exe.manifest C:\Users\Jessica\AppData\Local\Temp\HPDownload.exe.manifest C:\Users\Jessica\AppData\Local\Temp\HPQSi.exe C:\Users\Jessica\AppData\Local\Temp\installerdll102617.dll C:\Users\Jessica\AppData\Local\Temp\installerdll103740.dll C:\Users\Jessica\AppData\Local\Temp\installerdll107968.dll C:\Users\Jessica\AppData\Local\Temp\installerdll110947.dll C:\Users\Jessica\AppData\Local\Temp\installerdll121368.dll C:\Users\Jessica\AppData\Local\Temp\installerdll121555.dll C:\Users\Jessica\AppData\Local\Temp\installerdll127530.dll C:\Users\Jessica\AppData\Local\Temp\installerdll129059.dll C:\Users\Jessica\AppData\Local\Temp\installerdll130604.dll C:\Users\Jessica\AppData\Local\Temp\installerdll130635.dll C:\Users\Jessica\AppData\Local\Temp\installerdll134363.dll C:\Users\Jessica\AppData\Local\Temp\installerdll137483.dll C:\Users\Jessica\AppData\Local\Temp\installerdll144488.dll C:\Users\Jessica\AppData\Local\Temp\installerdll149745.dll C:\Users\Jessica\AppData\Local\Temp\installerdll155517.dll C:\Users\Jessica\AppData\Local\Temp\installerdll156890.dll C:\Users\Jessica\AppData\Local\Temp\installerdll163379.dll C:\Users\Jessica\AppData\Local\Temp\installerdll1678664.dll C:\Users\Jessica\AppData\Local\Temp\installerdll169963.dll C:\Users\Jessica\AppData\Local\Temp\installerdll172864.dll C:\Users\Jessica\AppData\Local\Temp\installerdll182661.dll C:\Users\Jessica\AppData\Local\Temp\installerdll202551.dll C:\Users\Jessica\AppData\Local\Temp\installerdll212738.dll C:\Users\Jessica\AppData\Local\Temp\installerdll244500.dll C:\Users\Jessica\AppData\Local\Temp\installerdll302095.dll C:\Users\Jessica\AppData\Local\Temp\installerdll319302.dll C:\Users\Jessica\AppData\Local\Temp\installerdll445226.dll C:\Users\Jessica\AppData\Local\Temp\installerdll72462.dll C:\Users\Jessica\AppData\Local\Temp\installerdll73055.dll C:\Users\Jessica\AppData\Local\Temp\installerdll76019.dll C:\Users\Jessica\AppData\Local\Temp\installerdll77282.dll C:\Users\Jessica\AppData\Local\Temp\installerdll79591.dll C:\Users\Jessica\AppData\Local\Temp\installerdll79997.dll C:\Users\Jessica\AppData\Local\Temp\installerdll83273.dll C:\Users\Jessica\AppData\Local\Temp\installerdll86143.dll C:\Users\Jessica\AppData\Local\Temp\installerdll86845.dll C:\Users\Jessica\AppData\Local\Temp\installerdll92024.dll C:\Users\Jessica\AppData\Local\Temp\installerdll96533.dll C:\Users\Jessica\AppData\Local\Temp\MachineIdCreator.exe C:\Users\Jessica\AppData\Local\Temp\oi_{BF9A1093-DD17-4CE8-AFBB-51E88B64C2ED}.exe C:\Users\Jessica\AppData\Local\Temp\PicasaUpdater_1e87.exe C:\Users\Jessica\AppData\Local\Temp\PicasaUpdater_4c26.exe C:\Users\Jessica\AppData\Local\Temp\PicasaUpdater_c40.exe C:\Users\Jessica\AppData\Local\Temp\ResetFileTime.exe.manifest C:\Users\Jessica\AppData\Local\Temp\SecurityScan_Release.exe C:\Users\Jessica\AppData\Local\Temp\Setup.exe C:\Users\Jessica\AppData\Local\Temp\setupa2.exe C:\Users\Jessica\AppData\Local\Temp\SetupAC.exe C:\Users\Jessica\AppData\Local\Temp\si_sparpilot.exe C:\Users\Jessica\AppData\Local\Temp\SkypeSetup.exe C:\Users\Jessica\AppData\Local\Temp\softonic-de3.exe C:\Users\Jessica\AppData\Local\Temp\softonic_s_de3.exe C:\Users\Jessica\AppData\Local\Temp\sp50843.exe.exe C:\Users\Jessica\AppData\Local\Temp\ToolbarInstaller.exe C:\Users\Jessica\AppData\Local\Temp\UninstallHPTCA.exe C:\Users\Jessica\AppData\Local\Temp\unwise.exe C:\Users\Jessica\AppData\Local\Temp\{}\toolbar\components\RadioWMPCore.dll C:\Users\Jessica\AppData\Local\Temp\{}\toolbar\components\RadioWMPCoreGecko19.dll C:\Users\Jessica\AppData\Local\Temp\{}\conduitengine\components\RadioWMPCore.dll C:\Users\Jessica\AppData\Local\Temp\{}\conduitengine\components\RadioWMPCoreGecko19.dll C:\Users\Jessica\AppData\Local\Temp\{E96CF988-0594-4B0C-BE12-2BBB319552B7}\ISBEW64.exe C:\Users\Jessica\AppData\Local\Temp\{DD948866-7DD6-4A1C-98DF-7FCED786575A}\frwl_svc.exe C:\Users\Jessica\AppData\Local\Temp\{DD948866-7DD6-4A1C-98DF-7FCED786575A}\spideragent_set.exe C:\Users\Jessica\AppData\Local\Temp\{C7DBD042-B0AD-4D4E-95F3-9FFE51BCD4D6}\ICQ7.exe C:\Users\Jessica\AppData\Local\Temp\{C712D132-68DF-4159-AFAD-4E524560C080}\CleanerUI\cleanapi.dll C:\Users\Jessica\AppData\Local\Temp\{C712D132-68DF-4159-AFAD-4E524560C080}\CleanerUI\cleanapi.exe C:\Users\Jessica\AppData\Local\Temp\{C712D132-68DF-4159-AFAD-4E524560C080}\CleanerUI\klssrmv.dll C:\Users\Jessica\AppData\Local\Temp\{C712D132-68DF-4159-AFAD-4E524560C080}\CleanerStorage\cleanapi.dll C:\Users\Jessica\AppData\Local\Temp\{C712D132-68DF-4159-AFAD-4E524560C080}\CleanerStorage\cleanapi.exe C:\Users\Jessica\AppData\Local\Temp\{C712D132-68DF-4159-AFAD-4E524560C080}\CleanerStorage\klssrmv.dll C:\Users\Jessica\AppData\Local\Temp\{8CB9282C-6890-4922-826E-CBA6CDBBF276}\CleanerUI\cleanapi.dll C:\Users\Jessica\AppData\Local\Temp\{8CB9282C-6890-4922-826E-CBA6CDBBF276}\CleanerUI\cleanapi.exe C:\Users\Jessica\AppData\Local\Temp\{8CB9282C-6890-4922-826E-CBA6CDBBF276}\CleanerUI\klssrmv.dll C:\Users\Jessica\AppData\Local\Temp\{8CB9282C-6890-4922-826E-CBA6CDBBF276}\CleanerStorage\cleanapi.dll C:\Users\Jessica\AppData\Local\Temp\{8CB9282C-6890-4922-826E-CBA6CDBBF276}\CleanerStorage\cleanapi.exe C:\Users\Jessica\AppData\Local\Temp\{8CB9282C-6890-4922-826E-CBA6CDBBF276}\CleanerStorage\klssrmv.dll C:\Users\Jessica\AppData\Local\Temp\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\install_dll\MoveIt.dll C:\Users\Jessica\AppData\Local\Temp\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\install_dll\MReport.dll C:\Users\Jessica\AppData\Local\Temp\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\install_dll\_CustomDialog.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\GoogleCrashHandler.exe C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\GoogleUpdate.exe C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdate.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\GoopdateBho.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ar.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_bg.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_bn.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ca.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_cs.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_da.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_de.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_el.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_en-GB.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_en.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_es-419.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_es.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_et.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_fa.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_fi.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_fil.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_fr.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_gu.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_hi.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_hr.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_hu.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_id.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_is.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_it.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_iw.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ja.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_kn.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ko.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_lt.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_lv.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ml.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_mr.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ms.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_nl.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_no.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_or.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_pl.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_pt-BR.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_pt-PT.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ro.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ru.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_sk.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_sl.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_sr.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_sv.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ta.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_te.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_th.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_tr.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_uk.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_ur.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_vi.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_zh-CN.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\goopdateres_zh-TW.dll C:\Users\Jessica\AppData\Local\Temp\{61DFBD7C-F2EA-4FB4-AF38-0AE41A7B2367}\npGoogleOneClick8.dll C:\Users\Jessica\AppData\Local\Temp\_ISTMP1.DIR\ZDataI51.dll C:\Users\Jessica\AppData\Local\Temp\_ISTMP1.DIR\_WUTL951.DLL C:\Users\Jessica\AppData\Local\Temp\x86\HPWarrantyIDDll.dll C:\Users\Jessica\AppData\Local\Temp\x64\HPWarrantyIDDll.dll C:\Users\Jessica\AppData\Local\Temp\nsy17D6.tmp\NSIS_Picasa_Unicode.dll C:\Users\Jessica\AppData\Local\Temp\nswADA4.tmp\NSIS_Picasa.dll C:\Users\Jessica\AppData\Local\Temp\nsv2D38.tmp\System.dll C:\Users\Jessica\AppData\Local\Temp\nsq3237.tmp\System.dll C:\Users\Jessica\AppData\Local\Temp\is-B3832.tmp\IssProc.dll C:\Users\Jessica\AppData\Local\Temp\ICReinstall\FLVPlayerSetup.exe C:\Users\Jessica\AppData\Local\Temp\E5EC.dir\InstallFlashPlayer.exe C:\Users\Jessica\AppData\Local\Temp\Ceement\src\setup.exe C:\Users\Jessica\AppData\Local\Temp\c851fbbb67f46411269eb41eba4cde4e\si_sparpilot.exe C:\Users\Jessica\AppData\Local\Temp\C561.dir\InstallFlashPlayer.exe C:\Users\Jessica\AppData\Local\Temp\9a1041ffd275653647d1ec85942cdc94\incredibar_install.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\HPZids01.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\HPZids40.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\hpzsetup.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\HPZstub.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\Setup.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\CCC_Uninstaller.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\FixErr1714.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\hpqrrx08.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\trk\WindowsXP-KB822603-x86-TRK.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\sve\WindowsXP-KB822603-x86-SVE.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\rus\WindowsXP-KB822603-x86-RUS.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\ptb\WindowsXP-KB822603-x86-ptb.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\plk\WindowsXP-KB822603-x86-PLK.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\nob\WindowsXP-KB822603-x86-NOR.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\nld\WindowsXP-KB822603-x86-NLD.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\kor\WindowsXP-KB822603-x86-KOR.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\jpn\WindowsXP-KB822603-x86-jpn.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\ita\WindowsXP-KB822603-x86-ITA.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\hun\WindowsXP-KB822603-x86-HUN.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\fra\WindowsXP-KB822603-x86-fra.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\fin\WindowsXP-KB822603-x86-FIN.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\esn\WindowsXP-KB822603-x86-esn.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\enu\WindowsXP-KB822603-x86-enu.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\ell\WindowsXP-KB822603-x86-ELL.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\deu\WindowsXP-KB822603-x86-DEU.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\dan\WindowsXP-KB822603-x86-DAN.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\csy\WindowsXP-KB822603-x86-CSY.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\cht\WindowsXP-KB822603-x86-CHT.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\util\ccc\chs\WindowsXP-KB822603-x86-CHS.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\BlockSysUserInstall.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\difxapi.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPCommunication.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPeDiag.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPeSupport.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\hpqbhp01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPScripting.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZarp01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZcdl01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZchk01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZdui01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZdui40.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\hpzfwx01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZgat01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZmsi01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZnop01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\hpznui01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZnui40.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\hpznuiprn01.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\hpznuiprn40.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZpnp01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZpnp40.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZprl01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZprl40.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZpsc01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZpsl01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZrcn01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZrcv01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZrein01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZscr01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZscr40.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZshl01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZshl40.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZSWP01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZtim01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZwis01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZwrp01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\HPZwup01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\InstallMetrics.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\InternetUtil.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\msxml3.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\msxml3a.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\msxml3r.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\RDVCoinstFix.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\RenameAutorun.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\RulesEngine.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\TwainFix.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\usbready.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\yahoo\ytb_7.2.2.0_1.5.4_mail_bts_pub_uber_rev_setup_2008.11.25.01.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\yahoo\y_hp_intl_detect.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\x64\difxapi.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\wis\Win2K_XP\instmsi.exe C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\atl90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\hpqNwDr01.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\hpzscb01.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\hpzscbi0SmrtK.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\hpzscbi1BPDUSB.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\hpzscbi257usw.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\hpzscbi259Nop.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\hpzscbi2Snmp.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\mfc90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\mfc90u.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\mfcm90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\mfcm90u.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\msvcm90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\msvcp90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx86\msvcr90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\atl90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\hpqNwDr40.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\hpzscb01.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\hpzscbi0SmrtK.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\hpzscbi1BPDUSB.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\hpzscbi257usw.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\hpzscbi259Nop.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\hpzscbi2Snmp.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\mfc90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\mfc90u.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\mfcm90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\mfcm90u.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\msvcm90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\msvcp90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\setup\networkx64\msvcr90.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x64\hpotiop1.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x64\hpotscl1.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x64\hpovst01.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x64\hpowiav1.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x64\hpowiax1.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x32\hpotiop1.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x32\hpotpusd.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x32\hpotscl1.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x32\hpovst01.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x32\hpowiav1.dll C:\Users\Jessica\AppData\Local\Temp\7zS11FD\drivers\scanner\x32\hpowiax1.dll C:\Users\Jessica\AppData\Local\Temp\2bc7f693c2d13e046771d4aac84aa3fd\OptimizerPro.exe C:\Users\Jessica\AppData\Local\Temp\._msige60\GoogleEarth.exe C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\earthps.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\geplugin.exe C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\ge_expat.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\googleearth.exe.local C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\googleearth_free.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\msvcp80.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\msvcr80.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\npgeplugin.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\plugin\plugin_ax.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\earthflashsol.exe C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\earthps.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\ge_expat.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\googleearth.exe C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\googleearth.exe.local C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\googleearth_free.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\gpsbabel.exe C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\msvcp80.dll C:\Users\Jessica\AppData\Local\Temp\._msige60\program files\Google\Google Earth\client\msvcr80.dll ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-07-13 09:47:20 Restore point made on: 2013-07-14 07:24:32 Restore point made on: 2013-07-18 11:56:07 Restore point made on: 2013-07-18 11:59:13 Restore point made on: 2013-07-22 10:27:33 Restore point made on: 2013-07-23 11:29:07 Restore point made on: 2013-07-26 12:01:52 Restore point made on: 2013-07-28 09:00:20 Restore point made on: 2013-07-31 04:02:29 Restore point made on: 2013-08-06 11:31:52 Restore point made on: 2013-08-06 11:34:28 Restore point made on: 2013-08-09 13:35:00 Restore point made on: 2013-08-12 13:15:01 Restore point made on: 2013-08-17 15:02:56 Restore point made on: 2013-08-18 05:13:14 Restore point made on: 2013-08-19 07:38:03 ==================== Memory info =========================== Percentage of memory in use: 18% Total physical RAM: 3893.86 MB Available physical RAM: 3161.84 MB Total Pagefile: 3892.01 MB Available Pagefile: 3160.97 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:282.08 GB) (Free:176.67 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (RECOVERY) (Fixed) (Total:15.72 GB) (Free:2.25 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 Drive h: () (Removable) (Total:3.78 GB) (Free:3.78 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.15 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: 91CA769B) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=282 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=16 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ======================================================== Disk: 1 (Size: 4 GB) (Disk ID: 903EA767) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) LastRegBack: 2013-05-26 07:54 ==================== End Of Log ============================ ![]() Geändert von foerb (25.08.2013 um 02:17 Uhr) |