|
Log-Analyse und Auswertung: Problem: Internet Explorer Meldung getwindowinfoWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
13.09.2013, 08:59 | #1 |
| Problem: Internet Explorer Meldung getwindowinfo Hallo an alle, ich verwende für das Internet Firefox. Umso mehr wundert es mich, dass ich ein Problem mit dem Internet Explorer habe. Seit gestern öffnet sich dieser mit der Meldung "Webseite kann nicht geöffnet werden". In der Anzeige steht "hxxp://www_getwindowinfo/". Immer wenn ich den IE schließen möchte, öffnet sich dieser einfach wieder mit der oben erwähnten Meldung. Ich habe schon den Avira und den Malwarebytes drüberlaufen lassen. Leider hat nichts etwas gebracht. Handelt es sich hierbei überhaupt um einen Virus? Hat jemand einen Vorschlag, wie ich weiter vorgehen soll. FRST Log Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 Ran by Gaga (administrator) on DAVID on 13-09-2013 09:38:23 Running from C:\Users\Gaga\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\libusbd-nt.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\system32\PnkBstrA.exe () C:\Windows\system32\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Syntek America Inc.) C:\Windows\System32\StkCSrv.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe () C:\Program Files\phonostar-Player\phonostarTimer.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Spotify Ltd) C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (combib) C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (Windows Net) C:\Users\Gaga\AppData\Roaming\Windows Net Data\net.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Simplygen) C:\Program Files\HomeTab\ProtectedSearch.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-10-26] (Synaptics, Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-07-22] (Intel Corporation) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-08-04] () HKLM\...\Run: [QuickTime Task] - C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe [417792 2009-09-05] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [141600 2009-10-28] (Apple Inc.) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CloneCDTray] - C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-08-31] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [522232 2012-09-26] (Cisco Systems, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [phonostarTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [phonostar-PlayerTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-07] (Spotify Ltd) HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Herrnhuter Losungen.LNK ShortcutTarget: Herrnhuter Losungen.LNK -> C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (combib) Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Gaga\AppData\Roaming\Windows Net Data\net.exe (Windows Net) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: No Name - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: softonic-de3 Toolbar - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU -softonic-de3 Toolbar - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG2012\avgpp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default FF NewTab: about:home FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=6.0.11.2321 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1483 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @phonostar.de/phonostar - C:\Program Files\phonostar-Player\npphonostarDetectNP.dll ( ) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Gaga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-lut.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-ng.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\imdb.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\wolframalpha.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\qvo6.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: pricealarm - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: Microsoft .NET Framework Assistant - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: HomeTab - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} FF Extension: ST-de3 Community Toolbar - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} FF Extension: FoxyDeal - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} FF Extension: OberonGameHost - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\OberonGameHost@OberonGames.com.xpi FF Extension: toolbar - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\toolbar@web.de.xpi FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\15.5.0.2 FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\15.5.0.2 FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808LXD518XD518&ts=1379006862 ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672 2009-08-28] (Apple Inc.) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 libusbd; C:\Windows\System32\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2009-09-11] () R2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [107832 2009-09-11] () R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [31248 2008-01-16] (Syntek America Inc.) R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [479224 2012-09-26] (Cisco Systems, Inc.) S4 vToolbarUpdater15.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-18] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== R2 ACEDRV05; C:\Windows\system32\drivers\ACEDRV05.sys [97792 2008-12-25] (Protect Software GmbH) S3 acsint; C:\Windows\System32\DRIVERS\acsint.sys [38440 2012-09-26] (Cisco Systems, Inc.) S3 acsmux; C:\Windows\System32\DRIVERS\acsmux.sys [57256 2012-09-26] (Cisco Systems, Inc.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) S4 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-18] (AVG Technologies) R0 CLFS; C:\Windows\System32\CLFS.sys [247352 2008-01-21] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2010-01-01] (Elaborate Bytes AG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2008-06-25] (SAMSUNG ELECTRONICS CO., LTD.) R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [33792 2005-03-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-09-13] (Malwarebytes Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2008-11-05] () R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-29] (Samsung Electronics) R3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1363088 2008-03-28] (Syntek) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [123392 2008-12-05] (Texas Instruments) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [10144 2005-04-12] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [22240 2005-04-12] (Logitech Inc.) S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [17632 2005-04-12] (Logitech Inc.) S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [5600 2005-04-12] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [45504 2005-04-12] (Logitech Inc.) S3 ADDMEM; \??\C:\Users\Gaga\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS [x] U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Gaga\AppData\Local\Temp\catchme.sys [x] S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-13 09:37 - 2013-09-13 09:37 - 00000000 ____D C:\FRST 2013-09-13 09:36 - 2013-09-13 09:36 - 01082459 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-13 09:02 - 2013-09-13 09:02 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:29 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-12 23:41 - 2013-09-12 23:53 - 00000000 ____D C:\ComboFix 2013-09-12 21:45 - 2013-09-12 22:01 - 00000000 ____D C:\Windows\erdnt 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:27 - 2013-09-12 21:29 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:26 - 2013-09-12 21:27 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:26 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Local\Max Secure Software 2013-09-12 21:25 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-13 00:01 - 00001267 _____ C:\DelFix.txt 2013-09-12 20:57 - 2013-09-12 21:13 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 20:33 - 2013-09-12 20:34 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 ____N C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 19:45 - 2013-09-12 19:57 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Windows Net Data 2013-09-12 19:44 - 2013-09-13 08:55 - 00000000 ____D C:\Program Files\HomeTab 2013-09-12 19:44 - 2013-09-12 21:02 - 00000000 ____D C:\SoloApp 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\HomeTab 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Program Files\FoxyDeal 2013-09-12 19:44 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:47 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:39 - 2013-09-12 18:51 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:28 - 2013-09-12 18:29 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:23 - 2013-09-12 18:25 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-12 23:11 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-12 21:54 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-01 01:09 - 2013-09-12 19:44 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-30 15:42 - 2013-08-30 17:20 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:42 - 2013-08-30 15:49 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:52 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:39 - 2013-08-30 15:40 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-09-12 19:44 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-30 10:59 - 2013-08-30 11:00 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 18:20 - 2013-08-30 11:07 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-13 09:37 - 2013-09-13 09:37 - 00000000 ____D C:\FRST 2013-09-13 09:36 - 2013-09-13 09:36 - 01082459 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-13 09:35 - 2008-10-24 00:26 - 00000416 ____H C:\Windows\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD}.job 2013-09-13 09:35 - 2008-10-06 04:42 - 01399103 _____ C:\Windows\WindowsUpdate.log 2013-09-13 09:34 - 2008-12-01 18:45 - 00000416 ____H C:\Windows\Tasks\SupBackGroundTask.job 2013-09-13 09:17 - 2012-10-08 11:33 - 00000430 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-09-13 09:17 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.001 2013-09-13 09:17 - 2010-01-02 20:29 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-13 09:17 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-13 09:17 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-13 09:16 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-13 09:15 - 2008-06-25 23:08 - 00000836 _____ C:\Windows\bthservsdp.dat 2013-09-13 09:15 - 2006-11-02 15:01 - 00032514 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-13 09:08 - 2012-09-26 00:02 - 00000858 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-09-13 09:08 - 2011-11-03 23:14 - 00000000 ____D C:\ProgramData\MFAData 2013-09-13 09:02 - 2013-09-13 09:02 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-09-13 08:57 - 2008-01-21 04:47 - 00107054 _____ C:\Windows\PFRO.log 2013-09-13 08:55 - 2013-09-12 19:44 - 00000000 ____D C:\Program Files\HomeTab 2013-09-13 07:57 - 2010-01-02 20:29 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:01 - 2013-09-12 21:13 - 00001267 _____ C:\DelFix.txt 2013-09-12 23:53 - 2013-09-12 23:41 - 00000000 ____D C:\ComboFix 2013-09-12 23:51 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-09-12 23:34 - 2006-11-02 14:47 - 00392384 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 23:19 - 2006-11-02 12:33 - 01613470 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-12 23:13 - 2008-10-24 00:05 - 00105992 _____ C:\Users\Gaga\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-12 23:11 - 2013-09-04 18:41 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-09-12 22:01 - 2013-09-12 21:45 - 00000000 ____D C:\Windows\erdnt 2013-09-12 22:00 - 2008-10-24 00:03 - 00000000 ____D C:\Users\Gaga 2013-09-12 21:54 - 2013-09-04 18:14 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:29 - 2013-09-12 21:27 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:27 - 2013-09-12 21:26 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:26 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Local\Max Secure Software 2013-09-12 21:26 - 2013-09-12 21:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:23 - 2009-01-05 08:00 - 00000000 ____D C:\Program Files\7-Zip 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-12 20:57 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 21:02 - 2013-09-12 19:44 - 00000000 ____D C:\SoloApp 2013-09-12 20:34 - 2013-09-12 20:33 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:26 - 2008-10-24 00:05 - 00000905 _____ C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 ____N C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 20:06 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.dat 2013-09-12 19:57 - 2013-09-12 19:45 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Windows Net Data 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\HomeTab 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Program Files\FoxyDeal 2013-09-12 19:44 - 2013-09-01 01:09 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-12 19:44 - 2013-08-30 11:07 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-12 19:44 - 2008-12-18 19:44 - 00001724 _____ C:\Users\Gaga\Desktop\Mozilla Firefox.lnk 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:31 - 2008-06-25 07:38 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:51 - 2013-09-12 18:39 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:48 - 2013-09-12 18:47 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:29 - 2013-09-12 18:28 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:25 - 2013-09-12 18:23 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:24 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Spotify 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-11 23:45 - 2013-08-05 00:11 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:41 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-11 17:56 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Local\Spotify 2013-09-11 14:38 - 2012-04-09 14:53 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Skype 2013-09-11 12:01 - 2008-12-29 15:05 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\ICQ 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-09 19:33 - 2012-12-22 13:10 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\vlc 2013-09-09 11:06 - 2010-06-05 13:32 - 00000000 ___RD C:\Users\Gaga\Documents\My Dropbox 2013-09-09 11:06 - 2010-06-05 13:31 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Dropbox 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-03 07:06 - 2012-05-08 10:02 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-01 13:01 - 2008-12-22 18:19 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2013-09-01 01:09 - 2008-12-22 18:20 - 00000000 ____D C:\Users\Gaga\AppData\Local\Google 2013-09-01 01:09 - 2008-12-22 18:19 - 00000000 ____D C:\Program Files\Google 2013-08-30 17:20 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:52 - 2013-08-30 15:41 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:49 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:40 - 2013-08-30 15:39 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-08-18 18:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-30 11:00 - 2013-08-30 10:59 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 14:47 - 2013-06-27 08:40 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-18 14:47 - 2012-09-26 00:02 - 00000000 ____D C:\Program Files\AVG Secure Search 2013-08-18 14:46 - 2012-09-26 00:02 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-13 09:23 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-09-2013 Ran by Gaga at 2013-09-13 09:40:44 Running from C:\Users\Gaga\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) 2007 Microsoft Office system (Version: 12.0.6612.1000) 7-Zip 4.64 7-Zip 9.21 (Version: 9.21.00.0) AAC Decoder (Version: 7.1.0) Activation Assistant for the 2007 Microsoft Office suites Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0) Activision(R) (Version: 1.00.0000) Adobe AIR (Version: 2.7.1.19610) Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Reader 8.3.1 - Deutsch (Version: 8.3.1) Adobe Shockwave Player 12.0 (Version: 12.0.2.122) AGEIA PhysX v7.09.13 (Version: 7.09.13) Agere Systems HDA Modem AHR Sudoku 4.1 (Version: 4.1.4.321) Amazon MP3-Downloader 1.0.9 Any Video Converter 3.0.3 AP Tuner 3.08 Apple Application Support (Version: 1.0.1) Apple Mobile Device Support (Version: 2.6.0.32) Apple Software Update (Version: 2.1.1.116) Assassin's Creed (Version: 1.00) Atheros WLAN Client (Version: 1.00.000) Audacity 1.2.6 AutoUpdate (Version: 1.1) AVG 2013 (Version: 13.0.3222) AVG 2013 (Version: 13.0.3408) AVG 2013 (Version: 2013.0.3408) AVG Security Toolbar (Version: 15.5.0.2) Blobby Volley 2 Version 1.0RC1 Blur(TM) (Version: 1.00.0000) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1) CABAReT Stage 4.1 (Version: 4.1) calibre (Version: 1.1.0) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (Version: 1.6) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (Version: 1.7) CANON iMAGE GATEWAY Task for ZoomBrowser EX (Version: 1.5.0.3) Canon Internet Library for ZoomBrowser EX (Version: 1.6.1.6) Canon RAW Image Task for ZoomBrowser EX (Version: 3.3.0.5) Canon Utilities CameraWindow (Version: 7.1.0.2) Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (Version: 6.4.2.16) Canon Utilities Digital Photo Professional 3.4 (Version: 3.4.0.0) Canon Utilities EOS Utility (Version: 2.4.0.1) Canon Utilities MyCamera (Version: 6.4.0.5) Canon Utilities PhotoStitch (Version: 3.1.21.45) Canon Utilities Picture Style Editor (Version: 1.3.0.0) Canon Utilities RemoteCapture Task for ZoomBrowser EX (Version: 1.7.1.9) Canon Utilities ZoomBrowser EX (Version: 6.1.1.21) Canon ZoomBrowser EX Memory Card Utility (Version: 1.1.0.8) Carom3D Cisco AnyConnect Secure Mobility Client (Version: 3.0.10057) Cisco AnyConnect Secure Mobility Client (Version: 3.0.10057) CloneCD CloneDVD2 (Version: 2.9.2.8) Data Lifeguard Diagnostic for Windows (Version: 1.13) Deluxe Ski Jump 4 Beta-2 (Version: 0.9.1) DivX Codec (Version: 6.8.5) DivX Converter (Version: 7.1.0) DivX Player (Version: 7.2.0) DivX Plus DirectShow Filters DivX Version Checker (Version: 7.1.0.2) DivX Web Player (Version: 1.5.0) Dropbox (HKCU Version: 2.0.22) EA Download Manager (Version: 4.0.0.462) Easy Battery Manager (Version: 3.2.1.7) Easy Display Manager (Version: 2.0.0.0) Easy Network Manager 3.0 (Version: 3.0.0.0) Easy SpeedUp Manager (Version: 2.0.1.0) EOS USB WIA Driver (Version: 6.0.1.5) EZDownloader (Version: 1.0) Fallout 3 (Version: 1.00.0000) Far Cry 2 (Version: 1.00.00) FLOCK! Demo (Version: 1.00.0000) FluidSIM 4.2l Pneumatik MecLab GIMP 2.6.11 (Version: 2.6.11) Google Chrome (Version: 29.0.1547.66) Google Earth (Version: 7.1.1.1888) Google Update Helper (Version: 1.3.21.153) Google Updater (Version: 2.4.2432.1652) Grand Theft Auto IV (Version: 1.00.0000) H.264 Decoder (Version: 1.1.0) Herrnhuter Losungen (Version: 3.2.0) HomeTab 4.4 (Version: 4.4) HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (Version: 22.0.334.0) HP Deskjet 1000 J110 series Hilfe (Version: 140.0.65.65) ICQ7.5 (Version: 7.5) Image Editor Packages imagine digital freedom - Samsung (Version: 1.0.2.0) INCEPTION SCREENSAVER Intel PROSet Wireless Intel(R) PROSet/Wireless WiFi-Software (Version: 12.04.4000) Intel® Matrix Storage Manager Internet Explorer (Version: 9) iTunes (Version: 9.0.2.25) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Java(TM) 6 Update 37 (Version: 6.0.370) K-Lite Mega Codec Pack 1.57 (Version: 1.57) Kransimulator 2009 Demo (Version: 0.5.0) LibUSB-Win32-0.1.10.1 (Version: 0.1.10.1) Logitech Gaming Software (Version: 4.60) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Maple 9.5 (Version: 1.0.0.0) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Games for Windows - LIVE Redistributable (Version: 3.5.88.0) Microsoft Games for Windows Marketplace (Version: 3.5.50.0) Microsoft Office 2003 Web Components (Version: 11.0.8003.0) Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft PowerPoint Viewer (Version: 14.0.7015.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SOAP Toolkit 2.0 SP2 (Version: 623.1) Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) MiKTeX 2.9 (Version: 2.9) MKV Splitter (Version: 1.0.1) Mobile Partner (Version: 16.002.03.02.511) Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1) Mozilla Maintenance Service (Version: 23.0.1) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Need For Speed Underground Demo Need For Speed™ World (Version: 1.0.0.68) neroxml (Version: 1.0.0) NVIDIA Drivers (Version: 1.3) NVIDIA GAME System Software 2.8.1 (Version: 2.8.1) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0) NVIDIA Install Application (Version: 2.1002.109.718) oneworld Flugplan und Reiseplaner OpenLP 2.0 OpenOffice.org 3.0 (Version: 3.0.9358) PDF Editor 2 PDFCreator (Version: 1.5.1) phonostar-Player Version 3.02.8 Picasa 3 (Version: 3.8) Play AVStation (Version: 4.1.20.50) Play Camera (Version: 2.0.0.13) PunkBuster Services (Version: 0.986) QuickTime (Version: 7.64.17.73) Realtek High Definition Audio Driver (Version: 6.0.1.5605) Richard Burns Rally (Version: 1.00.000) Rockstar Games Social Club (Version: 1.00.0000) Samsung Magic Doctor (Version: 5.00) Samsung Recovery Solution III (Version: 3.0.0.5) Samsung Update Plus (Version: 2.0) simfy (Version: 1.5.0) Simple Sudoku 4.2 Skat 8.4 (Version: 8.4.1.40) Skype™ 6.6 (Version: 6.6.106) SopCast 3.2.9 (Version: 3.2.9) Spotify (HKCU Version: 0.9.1.57.ge7405149) SumatraPDF (Version: 2.1.1) Super Mario Flash v1.0 swMSM (Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 10.1.2.0) System Requirements Lab TeXnicCenter Version 1.0 Stable RC1 (Version: Version 1.0 Stable RC1) TI-Nspire™ CAS Computer Software (Version: 1.7.2741) TI-Nspire™ Computer Link Software (Version: 1.3.11897) Tomb Raider: Underworld 1.0 Ubuntu (Version: 8.10.515) Unity Web Player (HKCU Version: ) Unreal Tournament 3 (LG) (HKCU Version: 1.00.0000) Unreal Tournament 3 (LG) (Version: 1.00.0000) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825641) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) USB2.0 UVC WebCam (Version: 6.11.706.012) User Guide (Version: 1.0) VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0) Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0) VLC media player 2.0.6 (Version: 2.0.6) Wartung Samsung ML-1660 Series WIDCOMM Bluetooth Software 6.0.1.6300 (Version: 6.0.1.6300) Winamp (Version: 5.541 ) Windows 7 Upgrade Advisor (Version: 2.0.3001.0) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) Windows Media Player Firefox Plugin (Version: 1.0.0.8) Windows Utils WinRAR WinSudoku (Version: 1.0.0) Wolfenstein (Version: 1.1) Worms World Party ==================== Restore Points ========================= 12-09-2013 22:01:15 Ende der Bereinigung ==================== Hosts content: ========================== 2006-11-02 12:23 - 2013-09-12 23:51 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0AA60ADE-1999-4F56-A1B9-EF09CA2714C6} - System32\Tasks\SamsungMagicDoctor => C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [2007-07-05] (Samsung Electronics Co., Ltd.) Task: {0D2DBBD5-A610-4557-86E3-FC35AA70FBE6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-02] (Google Inc.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3C685C04-F44B-433E-9BB3-E4B6796B5CC9} - System32\Tasks\Browser Updater\Browser Updater => C:\Program Files\HomeTab\TBUpdater.dll [2013-07-08] (Simply Tech Ltd.) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {49F3B6FC-9BEE-4734-82C4-FAA606100F0A} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2008-05-22] (SAMSUNG Electronics) Task: {53403752-F29A-45E1-97AD-465D3F834308} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [2008-04-17] (SAMSUNG Electronics co., LTD.) Task: {810EDE5B-A771-41AB-AAFC-E4881CC286F7} - \DealPly No Task File Task: {862247A7-5B9B-49A5-B9DA-0C78927F04EA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-02] (Google Inc.) Task: {941FD8D6-59AD-4980-AC39-88DA8A84FC45} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2008-04-25] (Samsung Electronics Co., Ltd.) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-21] (Microsoft Corporation) Task: {AEDB9B78-923B-406D-997D-7B468BCD8A11} - System32\Tasks\SupBackGroundTask => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [2010-04-20] () Task: {BA873B36-FCCA-49F6-979A-F86AEC274C60} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-09-28] (Google) Task: {C8F931E0-ED56-46A0-915D-E64BBED594A0} - System32\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD} => C:\Windows\system32\msfeedssync.exe [2011-05-28] (Microsoft Corporation) Task: {D7EC6DD3-C63E-4D8A-9B63-91F1040857DA} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Gaga => C:\Program Files\Windows Calendar\WinCal.exe [2008-01-21] (Microsoft Corporation) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EBD845BB-D919-4912-B516-ADC0A99D5B49} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30] (Apple Inc.) Task: {F4C1ED60-9B39-49C5-8CC9-48E3DC0251B3} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files\HomeTab\ProtectedSearch.exe [2013-08-13] (Simplygen) Task: {F99D7667-0349-4A84-B7BD-0ADF7C5E9D73} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-21] (Microsoft Corp.) Task: {FDCE8A69-BAB4-4D61-A394-6E84F9E20D62} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation) Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SupBackGroundTask.job => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============= 2009-02-25 06:49 - 2009-02-25 06:49 - 05976064 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2008-02-12 06:19 - 2008-02-12 06:19 - 00208896 _____ (Broadcom Corporation.) C:\Windows\system32\btmmhook.dll 2013-05-25 02:36 - 2013-05-25 02:36 - 00130736 _____ (Dropbox, Inc.) C:\Users\Gaga\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll 2008-02-12 05:36 - 2008-02-12 05:36 - 00184320 _____ (Broadcom Corporation.) C:\Windows\system32\btncopy.dll 2009-12-06 00:24 - 2009-08-16 18:06 - 00141312 _____ () C:\Program Files\WinRAR\rarext.dll 2006-11-02 14:35 - 2006-11-02 14:35 - 00116736 _____ (Microsoft Corporation) C:\Windows\eHome\ehProxy.dll 2008-02-12 05:31 - 2008-02-12 05:31 - 00602112 _____ (Broadcom Corporation.) C:\Windows\system32\btwapi.dll 2008-02-12 05:46 - 2008-02-12 05:46 - 00233472 _____ (Broadcom Corporation.) C:\Windows\system32\btosif.dll 2008-02-12 05:58 - 2008-02-12 05:58 - 00393216 _____ (Broadcom Corporation.) C:\Windows\system32\btwhidcs.DLL 2008-02-12 05:26 - 2008-02-12 05:26 - 05271552 _____ (Broadcom Corporation.) C:\Windows\system32\btrez.dll 2008-06-25 07:30 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Samsung Magic Doctor\HookDllPS2.dll 2007-12-12 06:41 - 2007-12-12 06:41 - 01750960 _____ (Codejock Software) C:\Windows\system32\Codejock.CommandBars.v11.2.2.ocx 2007-12-12 06:41 - 2007-12-12 06:41 - 00518064 _____ (Codejock Software) C:\Windows\system32\Codejock.SkinFramework.v11.2.2.ocx 2005-11-08 10:37 - 2005-11-08 10:37 - 00049152 _____ (BasicPro) C:\Windows\system32\ComBibSub32.ocx 2009-02-25 06:49 - 2009-02-25 06:49 - 00520192 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2008-06-25 07:30 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2008-06-25 07:30 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\SAMSUNG\EasySpeedUpManager\HookDllPS2.dll 2013-09-12 19:44 - 2013-08-13 08:38 - 00100352 _____ () C:\Program Files\HomeTab\InstallHelper.dll 2013-09-12 19:44 - 2013-08-13 08:38 - 00152136 _____ (Simply Tech Ltd.) C:\Program Files\HomeTab\cinshlpr.dll 2013-08-18 18:21 - 2013-08-14 19:55 - 03551640 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-07-28 19:01 - 2013-07-28 19:01 - 16166280 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\Users\Gaga\Desktop\ein Tag im Leben.mpg:TOC.WMV ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/13/2013 09:18:22 AM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. Error: (09/13/2013 09:17:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 08:59:07 AM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. Error: (09/13/2013 08:58:53 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\5> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\5> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\4> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\4> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\3> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\3> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Error: (09/13/2013 09:19:32 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (09/13/2013 09:17:49 AM) (Source: ipnathlp) (User: ) Description: Die DHCP-Zuweisung wurde für IP-Adresse 192.168.1.2 deaktiviert, da die IP-Adresse außerhalb des Bereichs 192.168.0.0/255.255.255.0 liegt, von der die Adressen DHCP-Clients zu gewiesen werden. Ändern Sie den Bereich, sodass die IP-Adresse mit einbezogen wird, oder ändern Sie die IP-Adresse, sodass sie innerhalb dieses Bereichs liegt, um die DHCP-Zuweisung zu aktivieren. Error: (09/13/2013 09:17:49 AM) (Source: ipnathlp) (User: ) Description: ICS_IPV6 konnte den IPv6-Stapel nicht konfigurieren. Error: (09/13/2013 09:17:41 AM) (Source: Service Control Manager) (User: ) Description: 30000vpnagent Error: (09/13/2013 09:17:41 AM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%2 Error: (09/13/2013 09:17:41 AM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (09/13/2013 09:16:52 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: C:\Windows\System32\IWMSSvc.dll126 Error: (09/13/2013 09:16:51 AM) (Source: HTTP) (User: ) Description: \Device\Http\ReqQueueKerberos Error: (09/13/2013 09:15:25 AM) (Source: Service Control Manager) (User: ) Description: ScRegSetValueExWFailureActions%%5 Error: (09/13/2013 09:00:09 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-09-13 09:39:15.836 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.601 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.436 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.252 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.005 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:14.751 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:14.598 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:14.444 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:38:52.414 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:38:52.219 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 65% Total physical RAM: 3065.88 MB Available physical RAM: 1060.72 MB Total Pagefile: 6334.91 MB Available Pagefile: 4571.86 MB Total Virtual: 2047.88 MB Available Virtual: 1900.46 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:144.09 GB) (Free:25.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:144 GB) (Free:15.59 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 3A21C8C8) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=144 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=144 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
13.09.2013, 09:03 | #2 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo hi,
__________________Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Gaga\AppData\Roaming\Windows Net Data\net.exe (Windows Net) C:\Users\Gaga\AppData\Roaming\Windows Net Data Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
13.09.2013, 10:09 | #3 |
| Problem: Internet Explorer Meldung getwindowinfo Fixlog
__________________Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-09-2013 Ran by Gaga at 2013-09-13 10:10:11 Run:1 Running from C:\Users\Gaga\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Gaga\AppData\Roaming\Windows Net Data\net.exe (Windows Net) C:\Users\Gaga\AppData\Roaming\Windows Net Data ***************** C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk => Moved successfully. C:\Users\Gaga\AppData\Roaming\Windows Net Data\net.exe => Moved successfully. "C:\Users\Gaga\AppData\Roaming\Windows Net Data" directory move: C:\Users\Gaga\AppData\Roaming\Windows Net Data\id.dat => Moved successfully. C:\Users\Gaga\AppData\Roaming\Windows Net Data\uninstaller.exe => Moved successfully. Could not move "C:\Users\Gaga\AppData\Roaming\Windows Net Data" directory. => Scheduled to move on reboot. =========== Result of Scheduled Files to move =========== C:\Users\Gaga\AppData\Roaming\Windows Net Data => Moved successfully. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.12.10 Windows Vista Service Pack 1 x86 NTFS Internet Explorer 8.0.6001.19088 Gaga :: DAVID [Administrator] Schutz: Aktiviert 13.09.2013 00:30:51 mbam-log-2013-09-13 (00-30-51).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 561728 Laufzeit: 2 Stunde(n), 14 Minute(n), 54 Sekunde(n) Infizierte Speicherprozesse: 1 C:\Program Files\HomeTab\ProtectedSearch.exe (PUP.Optional.HomeTab.A) -> 4584 -> Keine Aktion durchgeführt. Infizierte Speichermodule: 2 C:\Program Files\HomeTab\cinshlpr.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\InstallHelper.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. Infizierte Registrierungsschlüssel: 6 HKCR\Typelib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} (PUP.Optional.BabylonToolBar.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} (PUP.Optional.BabylonToolBar.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{11707A71-0512-FCBA-C8CE-96B390E4B184} (PUP.Optional.Tarma.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{327b0f8c-49d9-466c-a8ab-0c30310a3ad0}_is1 (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo (PUP.Optional.Elex.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1 (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 9 C:\Program Files\HomeTab (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\chrome (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\chrome (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\components (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\plugins (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Windows\System32\config\systemprofile\AppData\Roaming\DealPly (PUP.Optional.DealPly.A) -> Keine Aktion durchgeführt. C:\Windows\System32\config\systemprofile\AppData\Roaming\DealPly\UpdateProc (PUP.Optional.DealPly.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 47 C:\Program Files\ICQ7.5\upgrade\2dcd1d63cb45e6613582211c3d5f4b23 (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt. C:\ProgramData\InstallMate\{1129172D-7473-4CB8-AE53-3C51CACA35DB}\Setup.exe (PUP.Optional.Tarma.A) -> Keine Aktion durchgeführt. C:\ProgramData\InstallMate\{1129172D-7473-4CB8-AE53-3C51CACA35DB}\TsuDll.dll (PUP.Optional.Tarma.A) -> Keine Aktion durchgeführt. C:\Users\Gaga\Downloads\PDFCreatorSetup.exe (PUP.Adware.InstallCore) -> Keine Aktion durchgeführt. C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt. C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt. C:\Users\Gaga\Downloads\ImageEditorSetup.exe (PUP.Optional.Installcore) -> Keine Aktion durchgeführt. C:\Users\Gaga\Downloads\Setup.exe (PUP.Optional.iBryte) -> Keine Aktion durchgeführt. C:\Users\Public\Desktop\EZDownloader.lnk (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\Microsoft.Win32.TaskScheduler.xml (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\cinshlpr.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\hometab_icon.ico (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\InstallHelper.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\Interop.IWshRuntimeLibrary.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\Microsoft.Win32.TaskScheduler.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\ProtectedSearch.exe (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\ProtectedSearch.ico (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\STInst32.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\STInst32.exe (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\System.Data.SQLite.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\TaskSchedulerCreator.exe (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\TBUpdater.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\ToolbarUninstall.exe (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\unins000.dat (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\unins000.exe (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\chrome\HomeTab.crx (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\chrome.manifest (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\install.js (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\install.rdf (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\pop.htm (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\chrome\HomeTab_6787.jar (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\components\wtb_complete.js (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\support@HomeTab.com\plugins\npwiddit.dll (PUP.Optional.HomeTab.A) -> Keine Aktion durchgeführt. C:\Windows\System32\config\systemprofile\AppData\Roaming\DealPly\UpdateProc\config.dat (PUP.Optional.DealPly.A) -> Keine Aktion durchgeführt. C:\Windows\System32\config\systemprofile\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe (PUP.Optional.DealPly.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\EZDownloader.Core.dll (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\EZDownloader.exe (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\EZDownloader.exe.config (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\EZDownloader.Extension.dll (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\EZDownloader.Spider.dll (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\ICSharpCode.SharpZipLib.dll (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\Interop.SHDocVw.dll (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\TabStrip.dll (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\unins000.dat (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\EZDownloader\unins000.exe (PUP.Optional.EZDownloader.A) -> Keine Aktion durchgeführt. C:\Program Files\HomeTab\STInst32.exe (Trojan.MSIL) -> Erfolgreich gelöscht und in Quarantäne gestellt. D:\Call of Duty 4\rzr-cod4.exe (Trojan.Agent.CK) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Muss ich jetzt sonst noch was machen? adwcleaner Log Code:
ATTFilter # AdwCleaner v3.003 - Bericht erstellt am 13/09/2013 um 10:49:04 # Updated 07/09/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 1 (32 bits) # Benutzername : Gaga - DAVID # Gestartet von : C:\Users\Gaga\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\HomeTab Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Conduit Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\ConduitEngine Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\CT2431245 Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\Conduit Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\ConduitCommon Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\ConduitEngine Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\CT2431245 Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\Extensions\engine@conduit.com Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} Ordner Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} Ordner Gelöscht : C:\Users\Gaga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiennapmieppnpfhhogglccgepbdajan Ordner Gelöscht : C:\Users\Gaga\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Datei Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\foxydeal.sqlite Datei Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\foxydeal.sqlite Datei Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\11-suche.xml Datei Gelöscht : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\searchplugins\11-suche.xml Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\qvo6.xml Datei Gelöscht : C:\Windows\System32\Tasks\Browser Updater ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dealply [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{810EDE5B-A771-41AB-AAFC-E4881CC286F7} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{810EDE5B-A771-41AB-AAFC-E4881CC286F7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FEE19A62-9BD5-4E02-AAAA-2944FE453431} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FEE19A62-9BD5-4E02-AAAA-2944FE453431} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046} [#] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A25E7121-3DD8-41B3-855B-756C5BC45449} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FEE19A62-9BD5-4E02-AAAA-2944FE453431} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FEE19A62-9BD5-4E02-AAAA-2944FE453431} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}] Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\FoxyDeal Schlüssel Gelöscht : HKCU\Software\AppDataLow\FoxyDeal Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\softonic-de3 Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\Software\softonic-de3 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\FoxyDeal Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\softonic-de3 Toolbar Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WSysControl ***** [ Browser ] ***** -\\ Internet Explorer v8.0.6001.19088 -\\ Mozilla Firefox v23.0.1 (de) [ Datei : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\prefs.js ] [ Datei : C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_480562\prefs.js ] Zeile gelöscht : user_pref("browser.search.defaultenginename", "qvo6"); Zeile gelöscht : user_pref("browser.search.order.1", "qvo6"); Zeile gelöscht : user_pref("browser.search.selectedEngine", "qvo6"); ************************* AdwCleaner[R0].txt - [11506 octets] - [13/09/2013 10:46:12] AdwCleaner[R1].txt - [10735 octets] - [13/09/2013 10:48:25] AdwCleaner[S0].txt - [1162 octets] - [13/09/2013 10:46:56] AdwCleaner[S1].txt - [8973 octets] - [13/09/2013 10:49:04] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [9033 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.0 (09.12.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by Gaga on 13.09.2013 at 10:58:28,26 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Gaga\AppData\Roaming\mozilla\firefox\profiles\6yfegq12.default\minidumps [7 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.09.2013 at 11:05:11,98 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 Ran by Gaga (administrator) on DAVID on 13-09-2013 11:07:17 Running from C:\Users\Gaga\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\libusbd-nt.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\system32\PnkBstrA.exe () C:\Windows\system32\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Syntek America Inc.) C:\Windows\System32\StkCSrv.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe () C:\Program Files\phonostar-Player\phonostarTimer.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Spotify Ltd) C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (combib) C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe () C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-10-26] (Synaptics, Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-07-22] (Intel Corporation) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-08-04] () HKLM\...\Run: [QuickTime Task] - C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe [417792 2009-09-05] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [141600 2009-10-28] (Apple Inc.) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CloneCDTray] - C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-08-31] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [522232 2012-09-26] (Cisco Systems, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [phonostarTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [phonostar-PlayerTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-07] (Spotify Ltd) HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Herrnhuter Losungen.LNK ShortcutTarget: Herrnhuter Losungen.LNK -> C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (combib) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG2012\avgpp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default FF NewTab: about:home FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=6.0.11.2321 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1483 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @phonostar.de/phonostar - C:\Program Files\phonostar-Player\npphonostarDetectNP.dll ( ) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Gaga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-lut.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-ng.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\imdb.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\wolframalpha.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: pricealarm - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: Microsoft .NET Framework Assistant - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: HomeTab - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} FF Extension: FoxyDeal - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} FF Extension: OberonGameHost - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\OberonGameHost@OberonGames.com.xpi FF Extension: toolbar - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\toolbar@web.de.xpi FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672 2009-08-28] (Apple Inc.) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 libusbd; C:\Windows\System32\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2009-09-11] () R2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [107832 2009-09-11] () R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [31248 2008-01-16] (Syntek America Inc.) R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [479224 2012-09-26] (Cisco Systems, Inc.) S4 vToolbarUpdater15.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== R2 ACEDRV05; C:\Windows\system32\drivers\ACEDRV05.sys [97792 2008-12-25] (Protect Software GmbH) S3 acsint; C:\Windows\System32\DRIVERS\acsint.sys [38440 2012-09-26] (Cisco Systems, Inc.) S3 acsmux; C:\Windows\System32\DRIVERS\acsmux.sys [57256 2012-09-26] (Cisco Systems, Inc.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) S4 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-18] (AVG Technologies) R0 CLFS; C:\Windows\System32\CLFS.sys [247352 2008-01-21] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2010-01-01] (Elaborate Bytes AG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2008-06-25] (SAMSUNG ELECTRONICS CO., LTD.) R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [33792 2005-03-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2008-11-05] () R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-29] (Samsung Electronics) R3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1363088 2008-03-28] (Syntek) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [123392 2008-12-05] (Texas Instruments) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [10144 2005-04-12] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [22240 2005-04-12] (Logitech Inc.) S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [17632 2005-04-12] (Logitech Inc.) S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [5600 2005-04-12] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [45504 2005-04-12] (Logitech Inc.) S3 ADDMEM; \??\C:\Users\Gaga\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS [x] U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Gaga\AppData\Local\Temp\catchme.sys [x] S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-13 11:05 - 2013-09-13 11:05 - 00000786 _____ C:\Users\Gaga\Desktop\JRT.txt 2013-09-13 10:54 - 2013-09-13 10:54 - 01029509 _____ (Thisisu) C:\Users\Gaga\Downloads\JRT.exe 2013-09-13 10:46 - 2013-09-13 10:49 - 00000000 ____D C:\AdwCleaner 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Downloads\adwcleaner.exe 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Desktop\adwcleaner.exe 2013-09-13 10:22 - 2013-09-13 10:26 - 00000306 __RSH C:\ProgramData\ntuser.pol 2013-09-13 09:40 - 2013-09-13 09:42 - 00027275 _____ C:\Users\Gaga\Downloads\Addition.txt 2013-09-13 09:37 - 2013-09-13 10:24 - 00000000 ____D C:\FRST 2013-09-13 09:36 - 2013-09-13 09:36 - 01082459 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:29 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-12 23:41 - 2013-09-12 23:53 - 00000000 ____D C:\ComboFix 2013-09-12 21:45 - 2013-09-12 22:01 - 00000000 ____D C:\Windows\erdnt 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:27 - 2013-09-12 21:29 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:26 - 2013-09-12 21:27 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:25 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-13 00:01 - 00001267 _____ C:\DelFix.txt 2013-09-12 20:57 - 2013-09-12 21:13 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 20:33 - 2013-09-12 20:34 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 _____ C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 19:44 - 2013-09-12 21:02 - 00000000 ____D C:\SoloApp 2013-09-12 19:44 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:47 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:39 - 2013-09-12 18:51 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:28 - 2013-09-12 18:29 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:23 - 2013-09-12 18:25 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-12 23:11 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-12 21:54 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-01 01:09 - 2013-09-12 19:44 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-30 15:42 - 2013-08-30 17:20 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:42 - 2013-08-30 15:49 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:52 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:39 - 2013-08-30 15:40 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-09-12 19:44 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-30 10:59 - 2013-08-30 11:00 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 18:20 - 2013-08-30 11:07 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-13 11:05 - 2013-09-13 11:05 - 00000786 _____ C:\Users\Gaga\Desktop\JRT.txt 2013-09-13 11:05 - 2008-10-24 00:26 - 00000416 ____H C:\Windows\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD}.job 2013-09-13 11:03 - 2008-10-06 04:42 - 01430438 _____ C:\Windows\WindowsUpdate.log 2013-09-13 10:58 - 2012-10-08 11:33 - 00000430 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-09-13 10:58 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.001 2013-09-13 10:58 - 2010-01-02 20:29 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-13 10:58 - 2008-12-01 18:45 - 00000416 ____H C:\Windows\Tasks\SupBackGroundTask.job 2013-09-13 10:57 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-13 10:57 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-13 10:57 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-13 10:56 - 2008-06-25 23:08 - 00000836 _____ C:\Windows\bthservsdp.dat 2013-09-13 10:56 - 2006-11-02 15:01 - 00032514 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-13 10:54 - 2013-09-13 10:54 - 01029509 _____ (Thisisu) C:\Users\Gaga\Downloads\JRT.exe 2013-09-13 10:49 - 2013-09-13 10:46 - 00000000 ____D C:\AdwCleaner 2013-09-13 10:47 - 2011-04-07 10:28 - 00000000 ____D C:\ProgramData\ICQ 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Downloads\adwcleaner.exe 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Desktop\adwcleaner.exe 2013-09-13 10:26 - 2013-09-13 10:22 - 00000306 __RSH C:\ProgramData\ntuser.pol 2013-09-13 10:24 - 2013-09-13 09:37 - 00000000 ____D C:\FRST 2013-09-13 10:22 - 2006-11-02 13:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2013-09-13 10:18 - 2008-01-21 04:47 - 00107402 _____ C:\Windows\PFRO.log 2013-09-13 09:57 - 2010-01-02 20:29 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-13 09:42 - 2013-09-13 09:40 - 00027275 _____ C:\Users\Gaga\Downloads\Addition.txt 2013-09-13 09:36 - 2013-09-13 09:36 - 01082459 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-13 09:08 - 2012-09-26 00:02 - 00000858 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-09-13 09:08 - 2011-11-03 23:14 - 00000000 ____D C:\ProgramData\MFAData 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:01 - 2013-09-12 21:13 - 00001267 _____ C:\DelFix.txt 2013-09-12 23:53 - 2013-09-12 23:41 - 00000000 ____D C:\ComboFix 2013-09-12 23:51 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-09-12 23:34 - 2006-11-02 14:47 - 00392384 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 23:19 - 2006-11-02 12:33 - 01613470 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-12 23:13 - 2008-10-24 00:05 - 00105992 _____ C:\Users\Gaga\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-12 23:11 - 2013-09-04 18:41 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-09-12 22:01 - 2013-09-12 21:45 - 00000000 ____D C:\Windows\erdnt 2013-09-12 22:00 - 2008-10-24 00:03 - 00000000 ____D C:\Users\Gaga 2013-09-12 21:54 - 2013-09-04 18:14 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:29 - 2013-09-12 21:27 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:27 - 2013-09-12 21:26 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:26 - 2013-09-12 21:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:23 - 2009-01-05 08:00 - 00000000 ____D C:\Program Files\7-Zip 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-12 20:57 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 21:02 - 2013-09-12 19:44 - 00000000 ____D C:\SoloApp 2013-09-12 20:34 - 2013-09-12 20:33 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:26 - 2008-10-24 00:05 - 00000905 _____ C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 _____ C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 20:06 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.dat 2013-09-12 19:44 - 2013-09-01 01:09 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-12 19:44 - 2013-08-30 11:07 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-12 19:44 - 2008-12-18 19:44 - 00001724 _____ C:\Users\Gaga\Desktop\Mozilla Firefox.lnk 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:31 - 2008-06-25 07:38 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:51 - 2013-09-12 18:39 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:48 - 2013-09-12 18:47 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:29 - 2013-09-12 18:28 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:25 - 2013-09-12 18:23 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:24 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Spotify 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-11 23:45 - 2013-08-05 00:11 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:41 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-11 17:56 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Local\Spotify 2013-09-11 14:38 - 2012-04-09 14:53 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Skype 2013-09-11 12:01 - 2008-12-29 15:05 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\ICQ 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-09 19:33 - 2012-12-22 13:10 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\vlc 2013-09-09 11:06 - 2010-06-05 13:32 - 00000000 ___RD C:\Users\Gaga\Documents\My Dropbox 2013-09-09 11:06 - 2010-06-05 13:31 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Dropbox 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-03 07:06 - 2012-05-08 10:02 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-01 13:01 - 2008-12-22 18:19 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2013-09-01 01:09 - 2008-12-22 18:20 - 00000000 ____D C:\Users\Gaga\AppData\Local\Google 2013-09-01 01:09 - 2008-12-22 18:19 - 00000000 ____D C:\Program Files\Google 2013-08-30 17:20 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:52 - 2013-08-30 15:41 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:49 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:40 - 2013-08-30 15:39 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-08-18 18:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-30 11:00 - 2013-08-30 10:59 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 14:47 - 2013-06-27 08:40 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-18 14:46 - 2012-09-26 00:02 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys Files to move or delete: ==================== C:\Users\Gaga\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-13 11:03 ==================== End Of Log ============================ --- --- --- |
13.09.2013, 13:20 | #4 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfoESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.09.2013, 15:42 | #5 |
| Problem: Internet Explorer Meldung getwindowinfo Ok, ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0e4a28c4d8c1064497abe3f40177573c # engine=15118 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-09-14 02:00:23 # local_time=2013-09-14 04:00:23 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode=1039 16777213 100 91 30945 66258007 0 0 # compatibility_mode=5892 16776573 100 100 28891 216656751 0 0 # scanned=404212 # found=1 # cleaned=0 # scan_time=14300 sh=07B886AFAE416703934C86E49692FD207459D6B2 ft=1 fh=9e0d50613c9be38f vn="a variant of Win32/Adware.iBryte.G application" ac=I fn="C:\Users\Gaga\Downloads\Setup.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.73 Windows Vista Service Pack 1 x86 (UAC is enabled) Out of date service pack!! Internet Explorer 8 Out of date! Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` AVG AntiVirus Free Edition 2013 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java(TM) 6 Update 37 Java 7 Update 25 Adobe Flash Player 11.8.800.94 Adobe Reader 8 Adobe Reader out of Date! Mozilla Firefox (23.0.1) Google Chrome 29.0.1547.62 Google Chrome 29.0.1547.66 ````````Process Check: objlist.exe by Laurent```````` AVG avgwdsvc.exe AVG avgrsx.exe AVG avgnsx.exe AVG avgemc.exe Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 04 Ran by Gaga (administrator) on DAVID on 14-09-2013 16:40:44 Running from C:\Users\Gaga\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe () C:\Program Files\phonostar-Player\phonostarTimer.exe (Spotify Ltd) C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (combib) C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\libusbd-nt.exe () C:\Windows\system32\PnkBstrA.exe () C:\Windows\system32\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Syntek America Inc.) C:\Windows\System32\StkCSrv.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcfgex.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-07-22] (Intel Corporation) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-08-04] () HKLM\...\Run: [QuickTime Task] - C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe [417792 2009-09-05] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [141600 2009-10-28] (Apple Inc.) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CloneCDTray] - C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-08-31] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [522232 2012-09-26] (Cisco Systems, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2416368 2013-02-25] (Synaptics Incorporated) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [phonostarTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [phonostar-PlayerTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-07] (Spotify Ltd) HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Herrnhuter Losungen.LNK ShortcutTarget: Herrnhuter Losungen.LNK -> C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (combib) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG2012\avgpp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default FF NewTab: about:home FF DefaultSearchEngine: Amazon.de FF SelectedSearchEngine: Amazon.de FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=6.0.11.2321 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1483 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @phonostar.de/phonostar - C:\Program Files\phonostar-Player\npphonostarDetectNP.dll ( ) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Gaga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-lut.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-ng.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\imdb.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\wolframalpha.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: pricealarm - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: Microsoft .NET Framework Assistant - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: HomeTab - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} FF Extension: FoxyDeal - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} FF Extension: OberonGameHost - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\OberonGameHost@OberonGames.com.xpi FF Extension: toolbar - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\toolbar@web.de.xpi FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672 2009-08-28] (Apple Inc.) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 libusbd; C:\Windows\System32\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2009-09-11] () R2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [107832 2009-09-11] () R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [31248 2008-01-16] (Syntek America Inc.) R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [479224 2012-09-26] (Cisco Systems, Inc.) S4 vToolbarUpdater15.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== R2 ACEDRV05; C:\Windows\system32\drivers\ACEDRV05.sys [97792 2008-12-25] (Protect Software GmbH) S3 acsint; C:\Windows\System32\DRIVERS\acsint.sys [38440 2012-09-26] (Cisco Systems, Inc.) S3 acsmux; C:\Windows\System32\DRIVERS\acsmux.sys [57256 2012-09-26] (Cisco Systems, Inc.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) S4 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-18] (AVG Technologies) R0 CLFS; C:\Windows\System32\CLFS.sys [247352 2008-01-21] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2010-01-01] (Elaborate Bytes AG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2008-06-25] (SAMSUNG ELECTRONICS CO., LTD.) R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [33792 2005-03-09] () S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2008-11-05] () R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-29] (Samsung Electronics) R3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1363088 2008-03-28] (Syntek) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [123392 2008-12-05] (Texas Instruments) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [10144 2005-04-12] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [22240 2005-04-12] (Logitech Inc.) S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [17632 2005-04-12] (Logitech Inc.) S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [5600 2005-04-12] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [45504 2005-04-12] (Logitech Inc.) S3 ADDMEM; \??\C:\Users\Gaga\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS [x] U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Gaga\AppData\Local\Temp\catchme.sys [x] S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-14 16:40 - 2013-09-14 16:40 - 01083285 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-14 16:29 - 2013-09-14 16:29 - 00891144 _____ C:\Users\Gaga\Downloads\SecurityCheck.exe 2013-09-14 00:00 - 2013-09-14 00:00 - 00000000 ____D C:\Program Files\ESET 2013-09-13 23:58 - 2013-09-13 23:58 - 02347384 _____ (ESET) C:\Users\Gaga\Downloads\esetsmartinstaller_enu.exe 2013-09-13 12:25 - 2013-09-13 12:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Synaptics 2013-09-13 12:21 - 2013-09-13 12:21 - 00000000 ____D C:\ProgramData\Synaptics 2013-09-13 12:08 - 2013-02-25 23:28 - 00143088 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo16.dll 2013-09-13 12:07 - 2013-09-13 12:08 - 00000000 ____D C:\Users\Gaga\Desktop\Neuer Ordner (3) 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-09-13 12:06 - 2009-07-14 19:45 - 00445008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-09-13 12:06 - 2009-07-14 19:45 - 00038480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-09-13 12:06 - 2009-07-14 19:45 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf 2013-09-13 12:05 - 2013-09-13 12:05 - 00000000 ____D C:\Program Files\Synaptics 2013-09-13 12:03 - 2013-09-13 12:08 - 00001338 _____ C:\Windows\Synaptics.log 2013-09-13 12:02 - 2013-02-25 23:28 - 00532208 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-09-13 12:02 - 2013-02-25 23:28 - 00355056 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-09-13 12:02 - 2013-02-25 23:28 - 00175856 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-09-13 12:02 - 2011-09-14 19:11 - 01048576 _____ C:\Windows\system32\syndata.bin 2013-09-13 12:02 - 2009-08-07 09:49 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2013-09-13 12:01 - 2013-09-13 12:02 - 114922857 _____ C:\Users\Gaga\Downloads\Synaptics_v16_3_15_1_C_XP32_Vista32_Win7-32_XP64_Vista64_Win7-64_Signed_Acme_Inc.zip 2013-09-13 11:49 - 2013-09-13 11:49 - 00000237 _____ C:\Windows\SynInst.log 2013-09-13 11:05 - 2013-09-13 11:05 - 00000786 _____ C:\Users\Gaga\Desktop\JRT.txt 2013-09-13 10:54 - 2013-09-13 10:54 - 01029509 _____ (Thisisu) C:\Users\Gaga\Downloads\JRT.exe 2013-09-13 10:46 - 2013-09-13 10:49 - 00000000 ____D C:\AdwCleaner 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Downloads\adwcleaner.exe 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Desktop\adwcleaner.exe 2013-09-13 10:22 - 2013-09-13 10:26 - 00000306 __RSH C:\ProgramData\ntuser.pol 2013-09-13 09:40 - 2013-09-13 09:42 - 00027275 _____ C:\Users\Gaga\Downloads\Addition.txt 2013-09-13 09:37 - 2013-09-13 10:24 - 00000000 ____D C:\FRST 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:29 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-12 23:41 - 2013-09-12 23:53 - 00000000 ____D C:\ComboFix 2013-09-12 21:45 - 2013-09-12 22:01 - 00000000 ____D C:\Windows\erdnt 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:27 - 2013-09-12 21:29 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:26 - 2013-09-12 21:27 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:25 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-13 00:01 - 00001267 _____ C:\DelFix.txt 2013-09-12 20:57 - 2013-09-12 21:13 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 20:33 - 2013-09-12 20:34 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 _____ C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 19:44 - 2013-09-12 21:02 - 00000000 ____D C:\SoloApp 2013-09-12 19:44 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:47 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:39 - 2013-09-12 18:51 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:28 - 2013-09-12 18:29 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:23 - 2013-09-12 18:25 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-14 00:45 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-12 21:54 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-01 01:09 - 2013-09-12 19:44 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-30 15:42 - 2013-08-30 17:20 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:42 - 2013-08-30 15:49 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:52 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:39 - 2013-08-30 15:40 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-09-12 19:44 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-30 10:59 - 2013-08-30 11:00 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 18:20 - 2013-08-30 11:07 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-14 16:40 - 2013-09-14 16:40 - 01083285 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-14 16:40 - 2008-10-24 00:26 - 00000416 ____H C:\Windows\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD}.job 2013-09-14 16:29 - 2013-09-14 16:29 - 00891144 _____ C:\Users\Gaga\Downloads\SecurityCheck.exe 2013-09-14 16:25 - 2012-04-09 14:53 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Skype 2013-09-14 16:21 - 2011-11-03 23:14 - 00000000 ____D C:\ProgramData\MFAData 2013-09-14 16:15 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.dat 2013-09-14 16:15 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.001 2013-09-14 16:15 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-14 16:15 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-14 07:57 - 2010-01-02 20:29 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-14 03:00 - 2008-10-06 04:42 - 01630289 _____ C:\Windows\WindowsUpdate.log 2013-09-14 00:57 - 2010-01-02 20:29 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-14 00:45 - 2013-09-04 18:41 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-14 00:13 - 2010-06-05 13:31 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Dropbox 2013-09-14 00:12 - 2010-06-05 13:32 - 00000000 ___RD C:\Users\Gaga\Documents\My Dropbox 2013-09-14 00:02 - 2006-11-02 12:33 - 01613470 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-14 00:00 - 2013-09-14 00:00 - 00000000 ____D C:\Program Files\ESET 2013-09-13 23:58 - 2013-09-13 23:58 - 02347384 _____ (ESET) C:\Users\Gaga\Downloads\esetsmartinstaller_enu.exe 2013-09-13 19:48 - 2008-12-01 18:45 - 00000416 ____H C:\Windows\Tasks\SupBackGroundTask.job 2013-09-13 19:43 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-09-13 19:20 - 2012-10-08 11:33 - 00000431 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-09-13 19:19 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-13 12:34 - 2008-06-25 23:08 - 00000836 _____ C:\Windows\bthservsdp.dat 2013-09-13 12:34 - 2008-06-25 07:38 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-13 12:34 - 2006-11-02 15:01 - 00032514 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-13 12:32 - 2008-12-29 15:05 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\ICQ 2013-09-13 12:25 - 2013-09-13 12:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Synaptics 2013-09-13 12:21 - 2013-09-13 12:21 - 00000000 ____D C:\ProgramData\Synaptics 2013-09-13 12:13 - 2012-06-09 12:01 - 00018943 _____ C:\Windows\setupact.log 2013-09-13 12:13 - 2008-06-26 13:36 - 00000000 ____D C:\Windows\system32\Drivers\de-DE 2013-09-13 12:13 - 2008-06-25 07:17 - 00035218 _____ C:\Windows\DPINST.LOG 2013-09-13 12:09 - 2008-10-24 00:03 - 00000000 ____D C:\Users\Gaga 2013-09-13 12:08 - 2013-09-13 12:07 - 00000000 ____D C:\Users\Gaga\Desktop\Neuer Ordner (3) 2013-09-13 12:08 - 2013-09-13 12:03 - 00001338 _____ C:\Windows\Synaptics.log 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-09-13 12:05 - 2013-09-13 12:05 - 00000000 ____D C:\Program Files\Synaptics 2013-09-13 12:02 - 2013-09-13 12:01 - 114922857 _____ C:\Users\Gaga\Downloads\Synaptics_v16_3_15_1_C_XP32_Vista32_Win7-32_XP64_Vista64_Win7-64_Signed_Acme_Inc.zip 2013-09-13 11:49 - 2013-09-13 11:49 - 00000237 _____ C:\Windows\SynInst.log 2013-09-13 11:42 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Spotify 2013-09-13 11:05 - 2013-09-13 11:05 - 00000786 _____ C:\Users\Gaga\Desktop\JRT.txt 2013-09-13 10:54 - 2013-09-13 10:54 - 01029509 _____ (Thisisu) C:\Users\Gaga\Downloads\JRT.exe 2013-09-13 10:49 - 2013-09-13 10:46 - 00000000 ____D C:\AdwCleaner 2013-09-13 10:47 - 2011-04-07 10:28 - 00000000 ____D C:\ProgramData\ICQ 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Downloads\adwcleaner.exe 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Desktop\adwcleaner.exe 2013-09-13 10:26 - 2013-09-13 10:22 - 00000306 __RSH C:\ProgramData\ntuser.pol 2013-09-13 10:24 - 2013-09-13 09:37 - 00000000 ____D C:\FRST 2013-09-13 10:22 - 2006-11-02 13:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2013-09-13 10:18 - 2008-01-21 04:47 - 00107402 _____ C:\Windows\PFRO.log 2013-09-13 09:42 - 2013-09-13 09:40 - 00027275 _____ C:\Users\Gaga\Downloads\Addition.txt 2013-09-13 09:08 - 2012-09-26 00:02 - 00000858 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:01 - 2013-09-12 21:13 - 00001267 _____ C:\DelFix.txt 2013-09-12 23:53 - 2013-09-12 23:41 - 00000000 ____D C:\ComboFix 2013-09-12 23:51 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-09-12 23:34 - 2006-11-02 14:47 - 00392384 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 23:13 - 2008-10-24 00:05 - 00105992 _____ C:\Users\Gaga\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-09-12 22:01 - 2013-09-12 21:45 - 00000000 ____D C:\Windows\erdnt 2013-09-12 21:54 - 2013-09-04 18:14 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:29 - 2013-09-12 21:27 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:27 - 2013-09-12 21:26 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:26 - 2013-09-12 21:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:23 - 2009-01-05 08:00 - 00000000 ____D C:\Program Files\7-Zip 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-12 20:57 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 21:02 - 2013-09-12 19:44 - 00000000 ____D C:\SoloApp 2013-09-12 20:34 - 2013-09-12 20:33 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:26 - 2008-10-24 00:05 - 00000905 _____ C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 _____ C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 19:44 - 2013-09-01 01:09 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-12 19:44 - 2013-08-30 11:07 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-12 19:44 - 2008-12-18 19:44 - 00001724 _____ C:\Users\Gaga\Desktop\Mozilla Firefox.lnk 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:51 - 2013-09-12 18:39 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:48 - 2013-09-12 18:47 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:29 - 2013-09-12 18:28 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:25 - 2013-09-12 18:23 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-11 23:45 - 2013-08-05 00:11 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:41 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-11 17:56 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Local\Spotify 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-09 19:33 - 2012-12-22 13:10 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\vlc 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-03 07:06 - 2012-05-08 10:02 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-01 13:01 - 2008-12-22 18:19 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2013-09-01 01:09 - 2008-12-22 18:20 - 00000000 ____D C:\Users\Gaga\AppData\Local\Google 2013-09-01 01:09 - 2008-12-22 18:19 - 00000000 ____D C:\Program Files\Google 2013-08-30 17:20 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:52 - 2013-08-30 15:41 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:49 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:40 - 2013-08-30 15:39 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-08-18 18:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-30 11:00 - 2013-08-30 10:59 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 14:47 - 2013-06-27 08:40 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-18 14:46 - 2012-09-26 00:02 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys Some content of TEMP: ==================== C:\Users\Gaga\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-14 07:41 ==================== End Of Log ============================ Also der sich immer wieder öffnende Internet Explorer ist weg, also sieht ganz gut aus. Ich hab das gefühl, dass mein Rechner jetzt ein bisschen langsamer ist also voher. |
14.09.2013, 22:49 | #6 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Adobe und unbedingt Windows updaten. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Nach den Updates bitte ein frisches FRST log.
__________________ --> Problem: Internet Explorer Meldung getwindowinfo |
14.09.2013, 23:43 | #7 |
| Problem: Internet Explorer Meldung getwindowinfo Ok, alles upgedatet, Windows Service Pack hat jetzt auch endlich funktioniert. Hier der FRST Log. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 04 Ran by Gaga (administrator) on DAVID on 15-09-2013 00:40:50 Running from C:\Users\Gaga\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\libusbd-nt.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\system32\PnkBstrA.exe () C:\Windows\system32\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Syntek America Inc.) C:\Windows\System32\StkCSrv.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe () C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Spotify Ltd) C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (combib) C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (AVG) C:\Program Files\AVG\AVG PC TuneUp\integrator.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-07-22] (Intel Corporation) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-08-04] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CloneCDTray] - C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [522232 2012-09-26] (Cisco Systems, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2416368 2013-02-25] (Synaptics Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [phonostarTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [phonostar-PlayerTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-07] (Spotify Ltd) HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter IMEO\ccd-uninst.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\chrome.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\clonecd.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\clonecdtray.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\helplauncher.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\itunes.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\phonostar.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\presentationhost.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" IMEO\regclonecd.exe: [Debugger] "C:\Program Files\AVG\AVG PC TuneUp\TUAutoReactivator32.exe" Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Herrnhuter Losungen.LNK ShortcutTarget: Herrnhuter Losungen.LNK -> C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (combib) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default FF user.js: detected! => C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\user.js FF NewTab: about:home FF DefaultSearchEngine: YouTube-Videosuche FF SelectedSearchEngine: YouTube-Videosuche FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=6.0.11.2321 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1483 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @phonostar.de/phonostar - C:\Program Files\phonostar-Player\npphonostarDetectNP.dll ( ) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Gaga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-lut.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-ng.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\imdb.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\wolframalpha.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: pricealarm - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: Microsoft .NET Framework Assistant - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: HomeTab - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} FF Extension: FoxyDeal - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} FF Extension: OberonGameHost - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\OberonGameHost@OberonGames.com.xpi FF Extension: toolbar - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\toolbar@web.de.xpi FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ========================== Services (Whitelisted) ================= S4 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672 2009-08-28] (Apple Inc.) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 libusbd; C:\Windows\System32\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2009-09-11] () R2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [107832 2009-09-11] () R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [31248 2008-01-16] (Syntek America Inc.) R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [1740088 2013-09-09] (AVG) R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [35640 2013-09-09] (AVG) R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [479224 2012-09-26] (Cisco Systems, Inc.) ==================== Drivers (Whitelisted) ==================== R2 ACEDRV05; C:\Windows\system32\drivers\ACEDRV05.sys [97792 2008-12-25] (Protect Software GmbH) S3 acsint; C:\Windows\System32\DRIVERS\acsint.sys [38440 2012-09-26] (Cisco Systems, Inc.) S3 acsmux; C:\Windows\System32\DRIVERS\acsmux.sys [57256 2012-09-26] (Cisco Systems, Inc.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) S4 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-18] (AVG Technologies) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-10] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2010-01-01] (Elaborate Bytes AG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2008-06-25] (SAMSUNG ELECTRONICS CO., LTD.) S3 libusb0; C:\Windows\System32\drivers\libusb0.sys [33792 2005-03-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2008-11-05] () R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-29] (Samsung Electronics) R3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1363088 2008-03-28] (Syntek) R3 TuneUpUtilitiesDrv; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [12320 2013-08-21] (TuneUp Software) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [123392 2008-12-05] (Texas Instruments) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [10144 2005-04-12] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [22240 2005-04-12] (Logitech Inc.) S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [17632 2005-04-12] (Logitech Inc.) S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [5600 2005-04-12] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [45504 2005-04-12] (Logitech Inc.) S3 ADDMEM; \??\C:\Users\Gaga\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS [x] U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Gaga\AppData\Local\Temp\catchme.sys [x] S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-15 00:30 - 2013-09-15 00:30 - 00448512 _____ (OldTimer Tools) C:\Users\Gaga\Downloads\TFC.exe 2013-09-14 23:59 - 2013-09-14 23:59 - 00001892 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-09-14 23:58 - 2013-09-14 23:58 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-09-14 20:49 - 2013-09-09 15:40 - 00035640 _____ (AVG) C:\Windows\system32\uxtuneup.dll 2013-09-14 20:45 - 2013-09-09 15:40 - 00036152 _____ (AVG) C:\Windows\system32\TURegOpt.exe 2013-09-14 20:45 - 2013-09-09 15:40 - 00025400 _____ (AVG) C:\Windows\system32\authuitu.dll 2013-09-14 20:44 - 2013-09-14 20:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AVG 2013-09-14 20:42 - 2013-09-14 20:50 - 00000000 ____D C:\ProgramData\AVG 2013-09-14 20:42 - 2013-09-14 20:42 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2013-09-14 20:39 - 2013-09-14 20:40 - 78407592 _____ (AVG) C:\Users\Gaga\Downloads\avg_tuh_stf_all_2014_146_24c28.exe 2013-09-14 20:17 - 2013-09-14 20:18 - 00000000 ____D C:\Windows\system32\vi-VN 2013-09-14 20:17 - 2013-09-14 20:18 - 00000000 ____D C:\Windows\system32\eu-ES 2013-09-14 20:17 - 2013-09-14 20:18 - 00000000 ____D C:\Windows\system32\ca-ES 2013-09-14 20:13 - 2013-09-14 20:13 - 00000000 ____D C:\Windows\system32\SPReview 2013-09-14 19:55 - 2009-04-10 23:28 - 00928768 _____ (Microsoft Corporation) C:\Windows\system32\scavenge.dll 2013-09-14 19:55 - 2009-04-10 23:27 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\compcln.exe 2013-09-14 19:54 - 2009-04-10 23:32 - 01083880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00265688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00190424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00149480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00141288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00099816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2013-09-14 19:54 - 2009-04-10 23:32 - 00054248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00053736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00050664 _____ (Microsoft Corporation) C:\Windows\system32\PSHED.DLL 2013-09-14 19:54 - 2009-04-10 23:32 - 00035304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys 2013-09-14 19:54 - 2009-04-10 23:32 - 00027624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Dumpata.sys 2013-09-14 19:54 - 2009-04-10 23:28 - 02515968 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 02153472 _____ (Microsoft Corporation) C:\Windows\system32\oobefldr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\FunctionDiscoveryFolder.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01985024 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01856512 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01823744 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01788416 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01730560 _____ (Microsoft Corporation) C:\Windows\system32\apds.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01645568 _____ (Microsoft Corporation) C:\Windows\system32\connect.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01591296 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01459200 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01342464 _____ (Microsoft Corporation) C:\Windows\system32\brcpl.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01324032 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01209856 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01107968 _____ (Microsoft Corporation) C:\Windows\system32\pidgenx.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01078784 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00978944 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00978432 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00950784 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00825856 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00644608 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe 2013-09-14 19:54 - 2009-04-10 23:28 - 00612864 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-09-14 19:54 - 2009-04-10 23:28 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\comuid.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\prnntfy.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00550400 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00542720 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\pnpui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00516608 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\cmdial32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\IasMigReader.exe 2013-09-14 19:54 - 2009-04-10 23:28 - 00454144 _____ (Microsoft) C:\Windows\system32\IasMigPlugin.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\dsound.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00441344 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-09-14 19:54 - 2009-04-10 23:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\devmgr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\RelMon.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00334848 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2013-09-14 19:54 - 2009-04-10 23:28 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\P2PGraph.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL 2013-09-14 19:54 - 2009-04-10 23:28 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe 2013-09-14 19:54 - 2009-04-10 23:28 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\es.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\adsldpc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\offfilt.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-09-14 19:54 - 2009-04-10 23:28 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\pnpsetup.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceTypes.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\rasmontr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\fundisc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iasnap.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\dsprop.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\nlhtml.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\ntmarta.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00117248 _____ C:\Windows\system32\EhStorAuthn.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayDriverLib.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\EhStorShell.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\dmsynth.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\dmusic.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\oleprn.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\SCardSvr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceClassExtension.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\fdBth.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-09-14 19:54 - 2009-04-10 23:28 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\propdefs.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\iashlpr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\PNPXAssoc.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\fdSSDP.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\fdWSD.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingProxy.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\feclient.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\bthci.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dataclen.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\rtffilt.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\EhStorPwdMgr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\perfdisk.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\bitsigd.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelineprxy.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\hidserv.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2013-09-14 19:54 - 2009-04-10 23:28 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\fdBthProxy.dll 2013-09-14 19:54 - 2009-04-10 23:27 - 02926592 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 02092544 _____ (Microsoft Corporation) C:\Windows\system32\dfsr.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 01122304 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl 2013-09-14 19:54 - 2009-04-10 23:27 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr 2013-09-14 19:54 - 2009-04-10 23:27 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00636416 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00407040 _____ (Microsoft Corporation) C:\Windows\system32\dpapimig.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00241128 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll 2013-09-14 19:54 - 2009-04-10 23:27 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2013-09-14 19:54 - 2009-04-10 23:27 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\fsquirt.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\PresentationSettings.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00130024 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll 2013-09-14 19:54 - 2009-04-10 23:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\gpresult.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\dwm.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\hdwwiz.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\conime.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingWizard.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\cmmon32.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\rekeywiz.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\PnPutil.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEject.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\fc.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\rasdial.exe 2013-09-14 19:54 - 2009-04-10 23:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\gpupdate.exe 2013-09-14 19:54 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime 2013-09-14 19:54 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime 2013-09-14 19:54 - 2009-04-10 23:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime 2013-09-14 19:54 - 2009-04-10 23:23 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime 2013-09-14 19:54 - 2009-04-10 23:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\f3ahvoas.dll 2013-09-14 19:54 - 2009-04-10 22:42 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys 2013-09-14 19:54 - 2009-04-10 22:03 - 12240896 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0007.dll 2013-09-14 19:54 - 2009-04-10 22:03 - 02644480 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0009.dll 2013-09-14 19:54 - 2009-04-10 21:51 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2013-09-14 19:54 - 2009-04-10 21:48 - 00344698 _____ C:\Windows\system32\eaphost.tmf 2013-09-14 19:54 - 2009-04-10 21:46 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rassstp.sys 2013-09-14 19:54 - 2009-04-10 21:46 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspppoe.sys 2013-09-14 19:54 - 2009-04-10 21:46 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-09-14 19:54 - 2009-04-10 21:45 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2013-09-14 19:54 - 2009-04-10 21:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys 2013-09-14 19:54 - 2009-04-10 21:43 - 00442788 _____ C:\Windows\system32\dot3.tmf 2013-09-14 19:54 - 2009-04-10 21:43 - 00392170 _____ C:\Windows\system32\onex.tmf 2013-09-14 19:54 - 2009-04-10 21:43 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys 2013-09-14 19:54 - 2009-04-10 21:43 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2013-09-14 19:54 - 2009-04-10 21:43 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthenum.sys 2013-09-14 19:54 - 2009-04-10 21:42 - 00561152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys 2013-09-14 19:54 - 2009-04-10 21:42 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-09-14 19:54 - 2009-04-10 21:42 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-09-14 19:54 - 2009-04-10 21:42 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys 2013-09-14 19:54 - 2009-04-10 21:39 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2013-09-14 19:54 - 2009-04-10 21:23 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-09-14 19:54 - 2009-04-10 21:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxg.sys 2013-09-14 19:54 - 2009-04-10 21:14 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2013-09-14 19:54 - 2009-04-10 21:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys 2013-09-14 19:54 - 2009-04-10 21:13 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2013-09-14 19:54 - 2009-04-10 21:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys 2013-09-14 19:54 - 2009-04-10 21:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2013-09-14 19:54 - 2009-02-19 17:20 - 00009212 _____ C:\Windows\system32\RacUR.xml 2013-09-14 19:54 - 2009-02-18 11:43 - 00000153 _____ C:\Windows\system32\RacUREx.xml 2013-09-14 19:54 - 2009-02-18 11:39 - 00779136 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2013-09-14 19:54 - 2009-02-18 11:39 - 00102816 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-09-14 19:53 - 2009-04-10 23:33 - 00614376 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2013-09-14 19:53 - 2009-04-10 23:32 - 00527848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-09-14 19:53 - 2009-04-10 23:32 - 00245736 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2013-09-14 19:53 - 2009-04-10 23:32 - 00223208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2013-09-14 19:53 - 2009-04-10 23:32 - 00180712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2013-09-14 19:53 - 2009-04-10 23:32 - 00161752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys 2013-09-14 19:53 - 2009-04-10 23:32 - 00125928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2013-09-14 19:53 - 2009-04-10 23:32 - 00048104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys 2013-09-14 19:53 - 2009-04-10 23:28 - 06103040 _____ (Microsoft Corporation) C:\Windows\system32\chtbrkr.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 03174400 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 03072000 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 02226688 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 02225664 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 02012160 _____ (Microsoft Corporation) C:\Windows\system32\milcore.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\chsbrkr.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01589248 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01502720 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01480704 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01086464 _____ (Microsoft Corporation) C:\Windows\system32\NetProjW.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 01053696 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\mswdat10.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00807424 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00759296 _____ (Microsoft Corporation) C:\Windows\system32\ipsecsnp.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2013-09-14 19:53 - 2009-04-10 23:28 - 00679936 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00670720 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\msrepl40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\CertEnrollUI.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00618496 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2VDEC.DLL 2013-09-14 19:53 - 2009-04-10 23:28 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00469504 _____ (Microsoft Corporation) C:\Windows\system32\newdev.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\msxbde40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-09-14 19:53 - 2009-04-10 23:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\msexch40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\msvcp60.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00368640 _____ C:\Windows\system32\msjetoledb40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\mspbde40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00364032 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL 2013-09-14 19:53 - 2009-04-10 23:28 - 00351744 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00332800 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\msjtes40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\modemui.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\mstext40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\iassdo.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\msltus40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\msshsq.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\mscandui.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00200704 _____ (Microsoft Corporation) C:\Windows\system32\input.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\iassam.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00163328 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\imapi.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL 2013-09-14 19:53 - 2009-04-10 23:28 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\msctfui.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mstlsapi.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\msctfp.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\iassvcs.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\mpr.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\msjter40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msstrc.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\networkitemfactory.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\msscb.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\msimtf.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\ifmon.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\NcdProp.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\MsCtfMonitor.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msisip.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2013-09-14 19:53 - 2009-04-10 23:28 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\CHxReadingStringIME.dll 2013-09-14 19:53 - 2009-04-10 23:27 - 01102848 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl 2013-09-14 19:53 - 2009-04-10 23:27 - 00799744 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl 2013-09-14 19:53 - 2009-04-10 23:27 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\certreq.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax 2013-09-14 19:53 - 2009-04-10 23:27 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\newdev.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\cipher.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\csrstub.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cbsra.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\bthudtask.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\ipconfig.exe 2013-09-14 19:53 - 2009-04-10 23:27 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\msacm32.drv 2013-09-14 19:53 - 2009-04-10 23:23 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime 2013-09-14 19:53 - 2009-04-10 23:22 - 00883712 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME 2013-09-14 19:53 - 2009-04-10 23:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime 2013-09-14 19:53 - 2009-04-10 23:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime 2013-09-14 19:53 - 2009-04-10 23:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-09-14 19:53 - 2009-04-10 21:46 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys 2013-09-14 19:53 - 2009-04-10 21:45 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys 2013-09-14 19:53 - 2009-04-10 21:43 - 00507904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2013-09-14 19:53 - 2009-04-10 21:43 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthmodem.sys 2013-09-14 19:53 - 2009-04-10 21:43 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS 2013-09-14 19:53 - 2009-04-10 21:39 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys 2013-09-14 19:53 - 2009-04-10 21:39 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll 2013-09-14 19:53 - 2009-04-10 21:27 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2013-09-14 19:53 - 2009-04-10 21:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-09-14 19:53 - 2009-03-29 21:42 - 00155456 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2013-09-14 19:53 - 2009-03-29 21:42 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2013-09-14 19:53 - 2009-02-18 11:38 - 00619864 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2013-09-14 19:53 - 2009-02-18 11:38 - 00099680 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2013-09-14 19:53 - 2009-02-18 11:38 - 00035168 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl 2013-09-14 19:53 - 2009-02-18 11:38 - 00009048 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2013-09-14 19:52 - 2009-04-10 23:33 - 00986600 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-09-14 19:52 - 2009-04-10 23:33 - 00926184 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-09-14 19:52 - 2009-04-10 23:33 - 00292840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys 2013-09-14 19:52 - 2009-04-10 23:32 - 00438744 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll 2013-09-14 19:52 - 2009-04-10 23:32 - 00226280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-09-14 19:52 - 2009-04-10 23:32 - 00122344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Storport.sys 2013-09-14 19:52 - 2009-04-10 23:32 - 00053224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys 2013-09-14 19:52 - 2009-04-10 23:32 - 00019944 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll 2013-09-14 19:52 - 2009-04-10 23:32 - 00017896 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll 2013-09-14 19:52 - 2009-04-10 23:32 - 00017384 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 03217408 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 02205184 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 02167808 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01580544 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01576960 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01575936 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL 2013-09-14 19:52 - 2009-04-10 23:28 - 01533440 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01524736 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01382912 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL 2013-09-14 19:52 - 2009-04-10 23:28 - 01224192 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01152000 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\wercon.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01081344 _____ (Microsoft Corporation) C:\Windows\system32\SLCExt.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01055232 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 01017856 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00968192 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz2.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00876032 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00852992 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00777216 _____ (Microsoft Corporation) C:\Windows\system32\slcc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00712704 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00657408 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL 2013-09-14 19:52 - 2009-04-10 23:28 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00582144 _____ (Microsoft Corporation) C:\Windows\system32\SLCommDlg.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\wiaaut.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00532992 _____ (Microsoft Corporation) C:\Windows\system32\wpcao.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00507904 _____ (Microsoft Corporation) C:\Windows\system32\vdsdyn.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00449024 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\SLUI.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00356864 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00342528 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00313344 _____ (Microsoft Corporation) C:\Windows\system32\thawbrkr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\WscEapPr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\w32time.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\SnippingTool.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\wow32.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00250368 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\SLC.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\wscntfy.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\sperror.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\SLLUA.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\WcnNetsh.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\spoolss.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\korwbrkr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wpcsvc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\tcpmon.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\softkbd.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\ulib.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\wshext.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00083456 _____ (Microsoft) C:\Windows\system32\SMBHelperClass.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\wlgpclnt.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\slwmi.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\SLUINotify.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\xmlfilter.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Storprop.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\mmci.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\l2nacp.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\slcinst.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\TSTheme.exe 2013-09-14 19:52 - 2009-04-10 23:28 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\whealogr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\wsepno.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\uxsms.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\version.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\winrnr.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wscisvif.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\vdmdbg.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\midimap.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\spcmsg.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mmcico.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll 2013-09-14 19:52 - 2009-04-10 23:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\spwinsat.dll 2013-09-14 19:52 - 2009-04-10 23:27 - 03408896 _____ (Microsoft Corporation) C:\Windows\system32\SLsvc.exe 2013-09-14 19:52 - 2009-04-10 23:27 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe 2013-09-14 19:52 - 2009-04-10 23:27 - 01689600 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl 2013-09-14 19:52 - 2009-04-10 23:27 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe 2013-09-14 19:52 - 2009-04-10 23:27 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe 2013-09-14 19:52 - 2009-04-10 23:27 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx 2013-09-14 19:52 - 2009-04-10 23:27 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp 2013-09-14 19:52 - 2009-04-10 23:27 - 00258048 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv 2013-09-14 19:52 - 2009-04-10 23:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv 2013-09-14 19:52 - 2009-04-10 23:27 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-09-14 19:52 - 2009-04-10 23:27 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe 2013-09-14 19:52 - 2009-04-10 23:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax 2013-09-14 19:52 - 2009-04-10 23:27 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe 2013-09-14 19:52 - 2009-04-10 23:23 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime 2013-09-14 19:52 - 2009-04-10 21:46 - 00208966 _____ C:\Windows\system32\WFP.TMF 2013-09-14 19:52 - 2009-04-10 21:46 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-09-14 19:52 - 2009-04-10 21:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2013-09-14 19:52 - 2009-04-10 21:45 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\smb.sys 2013-09-14 19:52 - 2009-04-10 21:43 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-09-14 19:52 - 2009-04-10 21:42 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-09-14 19:52 - 2009-04-10 21:42 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2013-09-14 19:52 - 2009-04-10 21:42 - 00052992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys 2013-09-14 19:52 - 2009-04-10 21:42 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-09-14 19:52 - 2009-04-10 21:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys 2013-09-14 19:52 - 2009-04-10 21:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys 2013-09-14 19:52 - 2009-04-10 21:38 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys 2013-09-14 19:52 - 2009-04-10 21:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys 2013-09-14 19:52 - 2009-04-10 21:22 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\watchdog.sys 2013-09-14 19:52 - 2009-04-10 21:14 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys 2013-09-14 19:52 - 2009-04-10 19:52 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spsys.sys 2013-09-14 19:52 - 2009-04-10 18:59 - 00107612 _____ C:\Windows\system32\StructuredQuerySchema.bin 2013-09-14 19:52 - 2009-04-10 18:54 - 03662128 _____ C:\Windows\system32\locale.nls 2013-09-14 19:52 - 2009-03-06 18:11 - 00130008 _____ C:\Windows\system32\systemsf.ebd 2013-09-14 19:52 - 2009-02-19 17:20 - 00009239 _____ C:\Windows\system32\spcinstrumentation.man 2013-09-14 19:52 - 2009-02-18 11:39 - 00092918 _____ C:\Windows\system32\slmgr.vbs 2013-09-14 19:52 - 2009-02-18 11:39 - 00035680 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2013-09-14 17:53 - 2013-09-14 17:53 - 00000000 ____D C:\2a1e9537a02a9b853e8f5d 2013-09-14 17:02 - 2013-09-14 17:04 - 142594212 _____ C:\Users\Gaga\Downloads\Windows6.0-KB947821-v29-x86.msu 2013-09-14 16:51 - 2013-09-14 16:51 - 00347424 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\MicrosoftFixit.wu.LB.63302600877424124.3.1.Run.exe 2013-09-14 16:44 - 2013-09-14 16:48 - 365230920 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\Windows6.0-KB948465-X86.exe 2013-09-14 16:40 - 2013-09-14 16:40 - 01083285 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-14 16:29 - 2013-09-14 16:29 - 00891144 _____ C:\Users\Gaga\Downloads\SecurityCheck.exe 2013-09-13 23:58 - 2013-09-13 23:58 - 02347384 _____ (ESET) C:\Users\Gaga\Downloads\esetsmartinstaller_enu.exe 2013-09-13 12:25 - 2013-09-13 12:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Synaptics 2013-09-13 12:21 - 2013-09-13 12:21 - 00000000 ____D C:\ProgramData\Synaptics 2013-09-13 12:08 - 2013-02-25 23:28 - 00143088 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo16.dll 2013-09-13 12:07 - 2013-09-13 12:08 - 00000000 ____D C:\Users\Gaga\Desktop\Neuer Ordner (3) 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-09-13 12:06 - 2009-07-14 19:45 - 00445008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-09-13 12:06 - 2009-07-14 19:45 - 00038480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-09-13 12:06 - 2009-07-14 19:45 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf 2013-09-13 12:05 - 2013-09-13 12:05 - 00000000 ____D C:\Program Files\Synaptics 2013-09-13 12:03 - 2013-09-13 12:08 - 00001338 _____ C:\Windows\Synaptics.log 2013-09-13 12:02 - 2013-02-25 23:28 - 00532208 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-09-13 12:02 - 2013-02-25 23:28 - 00355056 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-09-13 12:02 - 2013-02-25 23:28 - 00175856 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-09-13 12:02 - 2011-09-14 19:11 - 01048576 _____ C:\Windows\system32\syndata.bin 2013-09-13 12:02 - 2009-08-07 09:49 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2013-09-13 12:01 - 2013-09-13 12:02 - 114922857 _____ C:\Users\Gaga\Downloads\Synaptics_v16_3_15_1_C_XP32_Vista32_Win7-32_XP64_Vista64_Win7-64_Signed_Acme_Inc.zip 2013-09-13 11:49 - 2013-09-13 11:49 - 00000237 _____ C:\Windows\SynInst.log 2013-09-13 11:05 - 2013-09-13 11:05 - 00000786 _____ C:\Users\Gaga\Desktop\JRT.txt 2013-09-13 10:54 - 2013-09-13 10:54 - 01029509 _____ (Thisisu) C:\Users\Gaga\Downloads\JRT.exe 2013-09-13 10:46 - 2013-09-13 10:49 - 00000000 ____D C:\AdwCleaner 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Downloads\adwcleaner.exe 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Desktop\adwcleaner.exe 2013-09-13 10:22 - 2013-09-13 10:26 - 00000306 __RSH C:\ProgramData\ntuser.pol 2013-09-13 09:40 - 2013-09-13 09:42 - 00027275 _____ C:\Users\Gaga\Downloads\Addition.txt 2013-09-13 09:37 - 2013-09-13 10:24 - 00000000 ____D C:\FRST 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:29 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-12 23:41 - 2013-09-12 23:53 - 00000000 ____D C:\ComboFix 2013-09-12 21:45 - 2013-09-12 22:01 - 00000000 ____D C:\Windows\erdnt 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:27 - 2013-09-12 21:29 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:26 - 2013-09-12 21:27 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:25 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-13 00:01 - 00001267 _____ C:\DelFix.txt 2013-09-12 20:57 - 2013-09-12 21:13 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 20:33 - 2013-09-12 20:34 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 _____ C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 19:44 - 2013-09-12 21:02 - 00000000 ____D C:\SoloApp 2013-09-12 19:44 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:47 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:39 - 2013-09-12 18:51 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:28 - 2013-09-12 18:29 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:23 - 2013-09-12 18:25 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-14 17:32 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-12 21:54 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-01 01:09 - 2013-09-12 19:44 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-30 15:42 - 2013-08-30 17:20 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:42 - 2013-08-30 15:49 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:52 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:39 - 2013-08-30 15:40 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-09-12 19:44 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-30 10:59 - 2013-08-30 11:00 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 18:20 - 2013-08-30 11:07 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-15 00:40 - 2008-10-24 00:26 - 00000416 ____H C:\Windows\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD}.job 2013-09-15 00:36 - 2012-10-08 11:33 - 00000431 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-09-15 00:36 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.dat 2013-09-15 00:36 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.001 2013-09-15 00:36 - 2008-12-01 18:45 - 00000416 ____H C:\Windows\Tasks\SupBackGroundTask.job 2013-09-15 00:35 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-15 00:35 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-15 00:35 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-15 00:34 - 2008-06-25 23:08 - 00001076 _____ C:\Windows\bthservsdp.dat 2013-09-15 00:34 - 2006-11-02 15:01 - 00032514 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-15 00:33 - 2008-10-06 04:42 - 01698539 _____ C:\Windows\WindowsUpdate.log 2013-09-15 00:30 - 2013-09-15 00:30 - 00448512 _____ (OldTimer Tools) C:\Users\Gaga\Downloads\TFC.exe 2013-09-15 00:22 - 2006-11-02 12:33 - 01613470 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-15 00:15 - 2010-01-02 20:29 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-15 00:15 - 2010-01-02 20:29 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-15 00:14 - 2008-01-21 04:47 - 00110794 _____ C:\Windows\PFRO.log 2013-09-15 00:05 - 2008-10-25 22:54 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Adobe 2013-09-15 00:05 - 2008-06-25 07:25 - 00000000 ____D C:\ProgramData\Adobe 2013-09-14 23:59 - 2013-09-14 23:59 - 00001892 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-09-14 23:59 - 2008-10-25 22:54 - 00000000 ____D C:\Users\Gaga\AppData\Local\Adobe 2013-09-14 23:58 - 2013-09-14 23:58 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-09-14 23:58 - 2008-12-24 02:55 - 00000000 ____D C:\Program Files\Adobe 2013-09-14 21:22 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-14 21:01 - 2013-09-14 20:42 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2013-09-14 21:01 - 2010-06-05 13:32 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-09-14 21:01 - 2009-10-18 21:12 - 00000000 ____D C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2013-09-14 21:01 - 2009-01-05 20:28 - 00000000 ____D C:\Users\Gaga\AppData\Local\Downloaded Installations 2013-09-14 21:01 - 2008-12-27 03:26 - 00000000 ____D C:\Users\Gaga\AppData\Local\Microsoft Help 2013-09-14 21:01 - 2008-06-25 07:43 - 00000000 ____D C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1} 2013-09-14 20:50 - 2013-09-14 20:42 - 00000000 ____D C:\ProgramData\AVG 2013-09-14 20:45 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-09-14 20:44 - 2013-09-14 20:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AVG 2013-09-14 20:44 - 2012-09-25 23:57 - 00000000 ____D C:\Program Files\AVG 2013-09-14 20:40 - 2013-09-14 20:39 - 78407592 _____ (AVG) C:\Users\Gaga\Downloads\avg_tuh_stf_all_2014_146_24c28.exe 2013-09-14 20:31 - 2008-10-24 00:04 - 00000915 _____ C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk 2013-09-14 20:23 - 2006-11-02 14:47 - 00392384 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-14 20:19 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-09-14 20:19 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Photo Gallery 2013-09-14 20:19 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-09-14 20:19 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Defender 2013-09-14 20:19 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Collaboration 2013-09-14 20:19 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Calendar 2013-09-14 20:19 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Movie Maker 2013-09-14 20:19 - 2006-11-02 13:18 - 00000000 ____D C:\Program Files\Common Files\System 2013-09-14 20:18 - 2013-09-14 20:17 - 00000000 ____D C:\Windows\system32\vi-VN 2013-09-14 20:18 - 2013-09-14 20:17 - 00000000 ____D C:\Windows\system32\eu-ES 2013-09-14 20:18 - 2013-09-14 20:17 - 00000000 ____D C:\Windows\system32\ca-ES 2013-09-14 20:18 - 2008-06-26 13:36 - 00000000 ____D C:\Windows\system32\Drivers\de-DE 2013-09-14 20:18 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\zh-TW 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\zh-CN 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\uk-UA 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\tr-TR 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\th-TH 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sv-SE 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sr-Latn-CS 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\SLUI 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sl-SI 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\sk-SK 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ru-RU 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ro-RO 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\pt-PT 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\pt-BR 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\pl-PL 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\nl-NL 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\nb-NO 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\lv-LV 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\lt-LT 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ko-KR 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ja-JP 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\it-IT 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\hu-HU 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\hr-HR 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\he-IL 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\fr-FR 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\fi-FI 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\et-EE 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\el-GR 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\bg-BG 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\ar-SA 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\AdvancedInstallers 2013-09-14 20:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\IME 2013-09-14 20:17 - 2012-06-09 12:01 - 00042536 _____ C:\Windows\setupact.log 2013-09-14 20:13 - 2013-09-14 20:13 - 00000000 ____D C:\Windows\system32\SPReview 2013-09-14 17:56 - 2012-04-09 14:53 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Skype 2013-09-14 17:53 - 2013-09-14 17:53 - 00000000 ____D C:\2a1e9537a02a9b853e8f5d 2013-09-14 17:32 - 2013-09-04 18:41 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-14 17:24 - 2011-11-03 23:14 - 00000000 ____D C:\ProgramData\MFAData 2013-09-14 17:04 - 2013-09-14 17:02 - 142594212 _____ C:\Users\Gaga\Downloads\Windows6.0-KB947821-v29-x86.msu 2013-09-14 16:51 - 2013-09-14 16:51 - 00347424 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\MicrosoftFixit.wu.LB.63302600877424124.3.1.Run.exe 2013-09-14 16:48 - 2013-09-14 16:44 - 365230920 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\Windows6.0-KB948465-X86.exe 2013-09-14 16:40 - 2013-09-14 16:40 - 01083285 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-14 16:29 - 2013-09-14 16:29 - 00891144 _____ C:\Users\Gaga\Downloads\SecurityCheck.exe 2013-09-14 00:13 - 2010-06-05 13:31 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Dropbox 2013-09-14 00:12 - 2010-06-05 13:32 - 00000000 ___RD C:\Users\Gaga\Documents\My Dropbox 2013-09-13 23:58 - 2013-09-13 23:58 - 02347384 _____ (ESET) C:\Users\Gaga\Downloads\esetsmartinstaller_enu.exe 2013-09-13 12:34 - 2008-06-25 07:38 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-13 12:32 - 2008-12-29 15:05 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\ICQ 2013-09-13 12:25 - 2013-09-13 12:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Synaptics 2013-09-13 12:21 - 2013-09-13 12:21 - 00000000 ____D C:\ProgramData\Synaptics 2013-09-13 12:13 - 2008-06-25 07:17 - 00035218 _____ C:\Windows\DPINST.LOG 2013-09-13 12:09 - 2008-10-24 00:03 - 00000000 ____D C:\Users\Gaga 2013-09-13 12:08 - 2013-09-13 12:07 - 00000000 ____D C:\Users\Gaga\Desktop\Neuer Ordner (3) 2013-09-13 12:08 - 2013-09-13 12:03 - 00001338 _____ C:\Windows\Synaptics.log 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2013-09-13 12:07 - 2013-09-13 12:07 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-09-13 12:05 - 2013-09-13 12:05 - 00000000 ____D C:\Program Files\Synaptics 2013-09-13 12:02 - 2013-09-13 12:01 - 114922857 _____ C:\Users\Gaga\Downloads\Synaptics_v16_3_15_1_C_XP32_Vista32_Win7-32_XP64_Vista64_Win7-64_Signed_Acme_Inc.zip 2013-09-13 11:49 - 2013-09-13 11:49 - 00000237 _____ C:\Windows\SynInst.log 2013-09-13 11:42 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Spotify 2013-09-13 11:05 - 2013-09-13 11:05 - 00000786 _____ C:\Users\Gaga\Desktop\JRT.txt 2013-09-13 10:54 - 2013-09-13 10:54 - 01029509 _____ (Thisisu) C:\Users\Gaga\Downloads\JRT.exe 2013-09-13 10:49 - 2013-09-13 10:46 - 00000000 ____D C:\AdwCleaner 2013-09-13 10:47 - 2011-04-07 10:28 - 00000000 ____D C:\ProgramData\ICQ 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Downloads\adwcleaner.exe 2013-09-13 10:45 - 2013-09-13 10:45 - 01037278 _____ C:\Users\Gaga\Desktop\adwcleaner.exe 2013-09-13 10:26 - 2013-09-13 10:22 - 00000306 __RSH C:\ProgramData\ntuser.pol 2013-09-13 10:24 - 2013-09-13 09:37 - 00000000 ____D C:\FRST 2013-09-13 10:22 - 2006-11-02 13:18 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2013-09-13 09:42 - 2013-09-13 09:40 - 00027275 _____ C:\Users\Gaga\Downloads\Addition.txt 2013-09-13 09:08 - 2012-09-26 00:02 - 00000858 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:01 - 2013-09-12 21:13 - 00001267 _____ C:\DelFix.txt 2013-09-12 23:53 - 2013-09-12 23:41 - 00000000 ____D C:\ComboFix 2013-09-12 23:51 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-09-12 23:13 - 2008-10-24 00:05 - 00105992 _____ C:\Users\Gaga\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-09-12 22:01 - 2013-09-12 21:45 - 00000000 ____D C:\Windows\erdnt 2013-09-12 21:54 - 2013-09-04 18:14 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:29 - 2013-09-12 21:27 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:27 - 2013-09-12 21:26 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:26 - 2013-09-12 21:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:23 - 2009-01-05 08:00 - 00000000 ____D C:\Program Files\7-Zip 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-12 20:57 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 21:02 - 2013-09-12 19:44 - 00000000 ____D C:\SoloApp 2013-09-12 20:34 - 2013-09-12 20:33 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:26 - 2008-10-24 00:05 - 00000905 _____ C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 _____ C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 19:44 - 2013-09-01 01:09 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-12 19:44 - 2013-08-30 11:07 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-12 19:44 - 2008-12-18 19:44 - 00001724 _____ C:\Users\Gaga\Desktop\Mozilla Firefox.lnk 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:51 - 2013-09-12 18:39 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:48 - 2013-09-12 18:47 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:29 - 2013-09-12 18:28 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:25 - 2013-09-12 18:23 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-11 23:45 - 2013-08-05 00:11 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:41 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-11 17:56 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Local\Spotify 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-09 19:33 - 2012-12-22 13:10 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\vlc 2013-09-09 15:40 - 2013-09-14 20:49 - 00035640 _____ (AVG) C:\Windows\system32\uxtuneup.dll 2013-09-09 15:40 - 2013-09-14 20:45 - 00036152 _____ (AVG) C:\Windows\system32\TURegOpt.exe 2013-09-09 15:40 - 2013-09-14 20:45 - 00025400 _____ (AVG) C:\Windows\system32\authuitu.dll 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-03 07:06 - 2012-05-08 10:02 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-01 13:01 - 2008-12-22 18:19 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2013-09-01 01:09 - 2008-12-22 18:20 - 00000000 ____D C:\Users\Gaga\AppData\Local\Google 2013-09-01 01:09 - 2008-12-22 18:19 - 00000000 ____D C:\Program Files\Google 2013-08-30 17:20 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:52 - 2013-08-30 15:41 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:49 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:40 - 2013-08-30 15:39 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-08-18 18:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-30 11:00 - 2013-08-30 10:59 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 14:47 - 2013-06-27 08:40 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-18 14:46 - 2012-09-26 00:02 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-15 00:41 ==================== End Of Log ============================ |
15.09.2013, 15:30 | #8 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.09.2013, 17:13 | #9 |
| Problem: Internet Explorer Meldung getwindowinfo Jo, läuft alles wieder gut. Vielen Dank für deine Unterstützung. |
17.09.2013, 20:13 | #10 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |