|
Log-Analyse und Auswertung: Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
12.10.2013, 19:30 | #1 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome Hallo Leute, seit gerauemer Zeit habe ich auf jeder Webseite Flash Werbung und Popups im überfluss. Die üblichen Firefox Plugins wie Adblock sind installiert, bringen aber nur bedingt etwas. Es findet keine Umleitung auf andere Webseiten statt, lediglich Werbung wird Massenhaft angezeigt. Angehängt sind die Log Dateien wie in eurem Info Thread beschrieben. vielen Dank schonmal vorab für die Hilfe. Gruß, Michael |
12.10.2013, 22:11 | #2 |
/// the machine /// TB-Ausbilder | Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
12.10.2013, 22:57 | #3 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeCode:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 20:09 on 12/10/2013 (Wild-Pako) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. HKCU:DAEMON Tools Lite -> Removed Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013 Ran by Wild-Pako at 2013-10-12 20:11:02 Running from D:\! - - Transfer - - ! Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== 3DMark Vantage (x32 Version: 1.1.2) 3DMark06 (x32 Version: 1.2.1) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.32.18) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader 9.1 - Deutsch (x32 Version: 9.1.0) AMD Accelerated Video Transcoding (Version: 13.15.100.30830) AMD APP SDK Runtime (Version: 10.0.937.2) AMD Catalyst Control Center (x32 Version: 2013.0830.1944.33589) AMD Catalyst Install Manager (Version: 8.0.915.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.80830.1925) avast! Free Antivirus (x32 Version: 8.0.1497.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0830.1944.33589) Catalyst Control Center InstallProxy (x32 Version: 2013.0830.1944.33589) Catalyst Control Center Localization All (x32 Version: 2013.0830.1944.33589) CCC Help Chinese Standard (x32 Version: 2013.0830.1943.33589) CCC Help Chinese Traditional (x32 Version: 2013.0830.1943.33589) CCC Help Czech (x32 Version: 2013.0830.1943.33589) CCC Help Danish (x32 Version: 2013.0830.1943.33589) CCC Help Dutch (x32 Version: 2013.0830.1943.33589) CCC Help English (x32 Version: 2013.0830.1943.33589) CCC Help Finnish (x32 Version: 2013.0830.1943.33589) CCC Help French (x32 Version: 2013.0830.1943.33589) CCC Help German (x32 Version: 2013.0830.1943.33589) CCC Help Greek (x32 Version: 2013.0830.1943.33589) CCC Help Hungarian (x32 Version: 2013.0830.1943.33589) CCC Help Italian (x32 Version: 2013.0830.1943.33589) CCC Help Japanese (x32 Version: 2013.0830.1943.33589) CCC Help Korean (x32 Version: 2013.0830.1943.33589) CCC Help Norwegian (x32 Version: 2013.0830.1943.33589) CCC Help Polish (x32 Version: 2013.0830.1943.33589) CCC Help Portuguese (x32 Version: 2013.0830.1943.33589) CCC Help Russian (x32 Version: 2013.0830.1943.33589) CCC Help Spanish (x32 Version: 2013.0830.1943.33589) CCC Help Swedish (x32 Version: 2013.0830.1943.33589) CCC Help Thai (x32 Version: 2013.0830.1943.33589) CCC Help Turkish (x32 Version: 2013.0830.1943.33589) ccc-utility64 (Version: 2013.0830.1944.33589) CDBurnerXP (x32 Version: 4.5.2.4291) Core Temp 1.0 RC5 (Version: 1.0) CPUID CPU-Z 1.61.3 CrossLoop 2.82 (x32 Version: 2.82) DAEMON Tools Lite (x32 Version: 4.45.4.0314) Defraggler (Version: 2.15) DMUninstaller (x32) Dropbox (HKCU Version: 2.0.26) DU Meter (x32 Version: 4.16 Build R3102) EL3K My ELAS Remote Programmer 2.01.01 (x32 Version: 2.01.01) Far Cry 3 (x32 Version: 1.05) FBL Gyro Programmer version 1.15 (x32 Version: 1.15) Feven 1.5 (x32 Version: 1.28.153.2) FileZilla Client 3.7.3 (x32 Version: 3.7.3) FMS FMS (x32) Futuremark SystemInfo (x32 Version: 4.17.0) Google Chrome (x32 Version: 30.0.1599.69) Grand Theft Auto IV Complete Edition (x32 Version: v1.0.7.0/1.1.2.0) GTAIII (x32) HELI-X 4.2 Demo (x32) IrfanView (remove only) (x32) Java 7 Update 40 (x32 Version: 7.0.400) Java Auto Updater (x32 Version: 2.1.9.8) JDownloader 0.9 (x32 Version: 0.9) K-Lite Codec Pack 5.3.0 (64-bit) (Version: 5.3.0) K-Lite Mega Codec Pack 7.8.0 (x32 Version: 7.8.0) Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft .NET Framework 4.5 DEU Language Pack (Version: 4.5.50709) Microsoft Application Compatibility Toolkit 5.6 (x32 Version: 5.6.7324.0) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.67.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (x32 Version: 11.0.50727.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727) Miranda IM 0.10.17 (x32 Version: 0.10.17) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) Mozilla Maintenance Service (x32 Version: 24.0) Mozilla Thunderbird 24.0 (x86 de) (x32 Version: 24.0) MPC-HC 1.7.0 (64-bit) (Version: 1.7.0.7858) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Need for Speed Most Wanted (x32) NVIDIA Install Application (Version: 2.1002.133.902) NVIDIA PhysX (x32 Version: 9.12.1031) OpenAL (x32) OpenOffice 4.0.0 (x32 Version: 4.00.9702) PhoenixRC (x32 Version: 3.00.16) PL-2303 USB-to-Serial (x32 Version: 1.2.10) PlanetSide 2 PSG (HKCU Version: 1.0.3.183) QuickTime (x32 Version: 7.73.80.64) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5874) Shutdown Timer (x32 Version: 3.3.4) SKIP-BO Castaway Caper(TM) (HKCU Version: 1.0.0) SKIP-BO Castaway Caper(TM) (x32 Version: 1.0.0) Spybot - Search & Destroy (x32 Version: 2.1.21) Steamless Mafia II Pack (x32 Version: 1.0) TeamViewer 8 (x32 Version: 8.0.22298) TP-LINK Wireless Client Utility (x32 Version: 7.0) TrueCrypt (x32 Version: 6.2a) VLC media player 2.0.8 (x32 Version: 2.0.8) Winamp (x32 Version: 5.65 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) WinRAR ==================== Restore Points ========================= 12-10-2013 15:07:47 DirectX wurde installiert ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {07BDB5E2-AA29-4B7C-91B8-71BB500A2A3E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software) Task: {1640A659-5A2B-42FA-A5AC-614DEBF13519} - System32\Tasks\Feven 1.5-codedownloader => C:\Program Files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe [2013-09-28] (Feven) Task: {7C7EA6A6-2D24-4998-9FB9-14637657F46E} - System32\Tasks\Feven 1.5-chromeinstaller => C:\Program Files (x86)\Feven 1.5\Feven 1.5-chromeinstaller.exe [2013-09-28] (Feven) Task: {8A84B245-5A9A-4591-BBD4-D06072565B50} - System32\Tasks\Feven 1.5-updater => C:\Program Files (x86)\Feven 1.5\Feven 1.5-updater.exe [2013-09-28] (Feven) Task: {94D53870-9E08-47A6-B09E-A9833CB03411} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {9874408F-7AB0-4801-A87C-0818FB300148} - System32\Tasks\Feven 1.5-enabler => C:\Program Files (x86)\Feven 1.5\Feven 1.5-enabler.exe [2013-09-28] (Feven) Task: {9D88740A-0025-4EF0-9F2F-4B94A1B21E8E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {B9DFD4D9-898B-44D1-81BB-293619554FC7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {C49B32C5-483A-4C4A-9135-30E4A085EAD7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {D327A0ED-CDD5-43A3-8EC1-586FCBC839A0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25] (Google Inc.) Task: {E508E55C-2F35-4604-BD7A-E62EC5855868} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25] (Google Inc.) Task: {EDE4559D-3B9A-4EAE-AD25-2C03DA4048C1} - System32\Tasks\Feven 1.5-firefoxinstaller => C:\Program Files (x86)\Feven 1.5\Feven 1.5-firefoxinstaller.exe [2013-09-28] (Feven) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Feven 1.5-chromeinstaller.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-chromeinstaller.exe Task: C:\Windows\Tasks\Feven 1.5-codedownloader.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe Task: C:\Windows\Tasks\Feven 1.5-enabler.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-enabler.exe Task: C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-firefoxinstaller.exe Task: C:\Windows\Tasks\Feven 1.5-updater.job => C:\Program Files (x86)\Feven 1.5\Feven 1.5-updater.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2009-08-26 10:38 - 2009-08-16 17:06 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll 2013-10-12 19:53 - 2013-10-12 17:00 - 02105856 _____ () C:\Program Files\AVAST Software\Avast\defs\13101200\algo.dll 2013-10-07 21:38 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-10-07 21:38 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-10-07 21:38 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-10-07 21:38 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-10-07 21:38 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\libcef.dll 2012-07-25 18:41 - 2013-09-11 04:26 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Wild-Pako:zylomtest AlternateDataStreams: C:\Users\Wild-Pako:zylomtr{000HQ7FF-AD7A-3FG1-QCPB-27EJ7OREQVVU} ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/09/2013 10:58:34 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Need For Speed The Run.exe, Version: 1.0.0.0, Zeitstempel: 0x4eaa0448 Name des fehlerhaften Moduls: Need For Speed The Run.exe, Version: 1.0.0.0, Zeitstempel: 0x4eaa0448 Ausnahmecode: 0xc0000005 Fehleroffset: 0x012064b7 ID des fehlerhaften Prozesses: 0xaf8 Startzeit der fehlerhaften Anwendung: 0xNeed For Speed The Run.exe0 Pfad der fehlerhaften Anwendung: Need For Speed The Run.exe1 Pfad des fehlerhaften Moduls: Need For Speed The Run.exe2 Berichtskennung: Need For Speed The Run.exe3 Error: (10/09/2013 10:16:34 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Need For Speed The Run.exe, Version: 1.0.0.0, Zeitstempel: 0x4eaa0448 Name des fehlerhaften Moduls: atidxx32.dll, Version: 8.17.10.519, Zeitstempel: 0x52212a54 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0007265b ID des fehlerhaften Prozesses: 0x1820 Startzeit der fehlerhaften Anwendung: 0xNeed For Speed The Run.exe0 Pfad der fehlerhaften Anwendung: Need For Speed The Run.exe1 Pfad des fehlerhaften Moduls: Need For Speed The Run.exe2 Berichtskennung: Need For Speed The Run.exe3 Error: (10/09/2013 05:56:57 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: SDCleaner.exe, Version: 2.1.18.110, Zeitstempel: 0x51949f6e Name des fehlerhaften Moduls: rtl150.bpl, Version: 15.0.3953.35171, Zeitstempel: 0x4cca139f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000a116 ID des fehlerhaften Prozesses: 0x4fc Startzeit der fehlerhaften Anwendung: 0xSDCleaner.exe0 Pfad der fehlerhaften Anwendung: SDCleaner.exe1 Pfad des fehlerhaften Moduls: SDCleaner.exe2 Berichtskennung: SDCleaner.exe3 Error: (10/08/2013 06:44:00 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe Name des fehlerhaften Moduls: atidxx32.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x52212a54 Ausnahmecode: 0xc0000005 Fehleroffset: 0x66aecce9 ID des fehlerhaften Prozesses: 0x13c8 Startzeit der fehlerhaften Anwendung: 0xGTAIV.exe0 Pfad der fehlerhaften Anwendung: GTAIV.exe1 Pfad des fehlerhaften Moduls: GTAIV.exe2 Berichtskennung: GTAIV.exe3 Error: (10/07/2013 08:14:05 PM) (Source: WinMgmt) (User: ) Description: 0x8004107aC:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MOF Error: (10/07/2013 07:16:46 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe Name des fehlerhaften Moduls: QuickTime.qts_unloaded, Version: 0.0.0.0, Zeitstempel: 0x50890e53 Ausnahmecode: 0xc0000005 Fehleroffset: 0x60edcce9 ID des fehlerhaften Prozesses: 0x730 Startzeit der fehlerhaften Anwendung: 0xGTAIV.exe0 Pfad der fehlerhaften Anwendung: GTAIV.exe1 Pfad des fehlerhaften Moduls: GTAIV.exe2 Berichtskennung: GTAIV.exe3 Error: (10/03/2013 08:45:13 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x51406972 Name des fehlerhaften Moduls: phnxdll.dll, Version: 0.0.0.0, Zeitstempel: 0x4b2a2720 Ausnahmecode: 0xc0000417 Fehleroffset: 0x00002d01 ID des fehlerhaften Prozesses: 0x1394 Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0 Pfad der fehlerhaften Anwendung: phoenixRC.exe1 Pfad des fehlerhaften Moduls: phoenixRC.exe2 Berichtskennung: phoenixRC.exe3 Error: (10/03/2013 11:05:51 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x4f784c98 Name des fehlerhaften Moduls: phnxdll.dll, Version: 0.0.0.0, Zeitstempel: 0x4b2a2720 Ausnahmecode: 0xc0000417 Fehleroffset: 0x00002d01 ID des fehlerhaften Prozesses: 0x10b0 Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0 Pfad der fehlerhaften Anwendung: phoenixRC.exe1 Pfad des fehlerhaften Moduls: phoenixRC.exe2 Berichtskennung: phoenixRC.exe3 Error: (10/03/2013 10:35:58 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x51406972 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x69747475 ID des fehlerhaften Prozesses: 0x13fc Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0 Pfad der fehlerhaften Anwendung: phoenixRC.exe1 Pfad des fehlerhaften Moduls: phoenixRC.exe2 Berichtskennung: phoenixRC.exe3 Error: (10/03/2013 10:30:30 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version: 0.0.0.0, Zeitstempel: 0x51406972 Name des fehlerhaften Moduls: phnxdll.dll, Version: 0.0.0.0, Zeitstempel: 0x4b2a2720 Ausnahmecode: 0xc0000417 Fehleroffset: 0x00002d01 ID des fehlerhaften Prozesses: 0x13f8 Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0 Pfad der fehlerhaften Anwendung: phoenixRC.exe1 Pfad des fehlerhaften Moduls: phoenixRC.exe2 Berichtskennung: phoenixRC.exe3 System errors: ============= Error: (10/12/2013 04:53:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/12/2013 04:53:12 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (10/11/2013 05:42:52 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (10/10/2013 10:52:30 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (10/10/2013 06:56:03 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Update WebConnect" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (10/09/2013 06:45:41 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (10/09/2013 06:04:49 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (10/09/2013 05:55:53 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/09/2013 05:55:53 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (10/09/2013 05:49:33 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Überwachung verteilter Verknüpfungen (Client)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1115 Microsoft Office Sessions: ========================= Error: (10/09/2013 10:58:34 PM) (Source: Application Error)(User: ) Description: Need For Speed The Run.exe1.0.0.04eaa0448Need For Speed The Run.exe1.0.0.04eaa0448c0000005012064b7af801cec52e47418ff9K:\Program Files (x86)\NFS_Run\Need for Speed The Run\Need For Speed The Run.exeK:\Program Files (x86)\NFS_Run\Need for Speed The Run\Need For Speed The Run.exe8ee308b8-3125-11e3-8f7e-001fd08ec324 Error: (10/09/2013 10:16:34 PM) (Source: Application Error)(User: ) Description: Need For Speed The Run.exe1.0.0.04eaa0448atidxx32.dll8.17.10.51952212a54c00000050007265b182001cec5293d52a1beK:\Program Files (x86)\NFS_Run\Need for Speed The Run\Need For Speed The Run.exeC:\Windows\system32\atidxx32.dllb0f7c54c-311f-11e3-8f7e-001fd08ec324 Error: (10/09/2013 05:56:57 PM) (Source: Application Error)(User: ) Description: SDCleaner.exe2.1.18.11051949f6ertl150.bpl15.0.3953.351714cca139fc00000050000a1164fc01cec508237565eeC:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exeC:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl6ca27701-30fb-11e3-b7d7-001fd08ec324 Error: (10/08/2013 06:44:00 PM) (Source: Application Error)(User: ) Description: GTAIV.exe1.0.7.04bd9efbeatidxx32.dll_unloaded0.0.0.052212a54c000000566aecce913c801cec444d8ad870eE:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV Complete Edition\GTAIV.exeatidxx32.dlld482db56-3038-11e3-a82d-001fd08ec324 Error: (10/07/2013 08:14:05 PM) (Source: WinMgmt)(User: ) Description: 0x8004107aC:\WINDOWS\SYSTEM32\WBEM\SMTPCONS.MOF Error: (10/07/2013 07:16:46 PM) (Source: Application Error)(User: ) Description: GTAIV.exe1.0.7.04bd9efbeQuickTime.qts_unloaded0.0.0.050890e53c000000560edcce973001cec38076542fd4E:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV Complete Edition\GTAIV.exeQuickTime.qts3e32a351-2f74-11e3-9495-001fd08ec324 Error: (10/03/2013 08:45:13 PM) (Source: Application Error)(User: ) Description: phoenixRC.exe0.0.0.051406972phnxdll.dll0.0.0.04b2a2720c000041700002d01139401cec068b038094eK:\Program Files (x86)\PhoenixRC\phoenixRC.exeK:\Program Files (x86)\PhoenixRC\phnxdll.dllefce0472-2c5b-11e3-b0bd-001fd08ec324 Error: (10/03/2013 11:05:51 AM) (Source: Application Error)(User: ) Description: phoenixRC.exe0.0.0.04f784c98phnxdll.dll0.0.0.04b2a2720c000041700002d0110b001cec017c1535a9cD:\Program Files (x86)\PhoenixRC\phoenixRC.exeK:\Program Files (x86)\PhoenixRC\phnxdll.dllffa58662-2c0a-11e3-bd6e-001fd08ec324 Error: (10/03/2013 10:35:58 AM) (Source: Application Error)(User: ) Description: phoenixRC.exe0.0.0.051406972unknown0.0.0.000000000c00000056974747513fc01cec012d6ad7d63K:\Program Files (x86)\PhoenixRC\phoenixRC.exeunknownd339d1d7-2c06-11e3-bd6e-001fd08ec324 Error: (10/03/2013 10:30:30 AM) (Source: Application Error)(User: ) Description: phoenixRC.exe0.0.0.051406972phnxdll.dll0.0.0.04b2a2720c000041700002d0113f801cec012d0bb0888K:\Program Files (x86)\PhoenixRC\phoenixRC.exeK:\Program Files (x86)\PhoenixRC\phnxdll.dll0f896b00-2c06-11e3-bd6e-001fd08ec324 CodeIntegrity Errors: =================================== Date: 2012-11-10 18:09:59.681 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-11-10 18:04:32.048 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-11-01 14:45:50.678 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-11-01 14:19:27.887 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-11-01 14:09:36.725 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-10-25 19:57:25.923 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-10-25 19:43:49.397 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-07-26 20:19:10.501 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-07-23 11:12:49.613 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-07-23 11:05:30.782 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 43% Total physical RAM: 6142.49 MB Available physical RAM: 3489.04 MB Total Pagefile: 12283.17 MB Available Pagefile: 9262.5 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:29.29 GB) (Free:5.47 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Transfer) (Fixed) (Total:200 GB) (Free:42.58 GB) NTFS Drive e: (Daten_1) (Fixed) (Total:36.47 GB) (Free:5.79 GB) NTFS Drive f: (Musik + Bilder) (Fixed) (Total:200 GB) (Free:125.25 GB) NTFS Drive i: (NFS13) (CDROM) (Total:6.44 GB) (Free:0 GB) CDFS Drive j: (USB HDD) (Fixed) (Total:148.82 GB) (Free:114.27 GB) FAT32 Drive k: (Daten_2) (Fixed) (Total:1397.26 GB) (Free:1098.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 0D5D0D5C) Partition 1: (Active) - (Size=29 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=36 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=200 GB) - (Type=05) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1397 GB) (Disk ID: BA61BA15) Partition 1: (Not Active) - (Size=-698723860480) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 149 GB) (Disk ID: 17E1D90B) Partition: GPT Partition TypePartition 2: (Not Active) - (Size=149 GB) - (Type=0B) ==================== End Of Log ============================ |
12.10.2013, 23:00 | #4 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeCode:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-10-12 20:21:31 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-4 SAMSUNG_HD501LJ rev.CR100-11 465,76GB Running: gmer_2.1.19163.exe; Driver: C:\Users\WILD-P~1\AppData\Local\Temp\kxldquog.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\wininit.exe[584] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\services.exe[644] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\winlogon.exe[732] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[816] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\atiesrxx.exe[120] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[304] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[472] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[528] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1324] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\System32\spoolsv.exe[1748] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1776] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Program Files (x86)\DU Meter\DUMeterSvc.exe[1920] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Windows\system32\svchost.exe[1960] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[1008] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[1008] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[1008] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75] .text ... * 2 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 00000001002e075c .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001002e03a4 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 00000001002e0b14 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 00000001002e0ecc .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 00000001002e163c .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 00000001002e1284 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001002e19f4 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Windows\system32\taskhost.exe[2188] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 000000010013075c .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001001303a4 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 0000000100130b14 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 0000000100130ecc .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 000000010013163c .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 0000000100131284 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001001319f4 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Windows\system32\Dwm.exe[2272] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 000000010017075c .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001001703a4 .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 0000000100170b14 .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 0000000100170ecc .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 000000010017163c .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 0000000100171284 .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001001719f4 .text C:\Windows\Explorer.EXE[2320] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Windows\Explorer.EXE[2320] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100201014 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100200804 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100200a08 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100200c0c .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100200e10 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001002001f8 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001002003fc .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100200600 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000075fdee09 5 bytes JMP 00000001002101f8 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000075fe3982 5 bytes JMP 00000001002103fc .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075fe7603 5 bytes JMP 0000000100210804 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000075fe835c 5 bytes JMP 0000000100210600 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2680] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000075fff52b 5 bytes JMP 0000000100210a08 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 000000010019075c .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001001903a4 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 0000000100190b14 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 0000000100190ecc .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 000000010019163c .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 0000000100191284 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001001919f4 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2908] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000075fdee09 5 bytes JMP 00000001002401f8 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000075fe3982 5 bytes JMP 00000001002403fc .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075fe7603 5 bytes JMP 0000000100240804 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000075fe835c 5 bytes JMP 0000000100240600 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000075fff52b 5 bytes JMP 0000000100240a08 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100251014 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100250804 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100250a08 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100250c0c .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100250e10 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001002501f8 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001002503fc .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100250600 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75] .text ... * 2 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[2540] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000075fdee09 5 bytes JMP 00000001001001f8 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000075fe3982 5 bytes JMP 00000001001003fc .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075fe7603 5 bytes JMP 0000000100100804 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000075fe835c 5 bytes JMP 0000000100100600 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000075fff52b 5 bytes JMP 0000000100100a08 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100151014 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100150804 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100150a08 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100150c0c .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100150e10 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001001501f8 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001001503fc .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2632] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100150600 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100091014 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100090804 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100090a08 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100090c0c .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100090e10 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001000901f8 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001000903fc .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100090600 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000075fdee09 5 bytes JMP 00000001000a01f8 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000075fe3982 5 bytes JMP 00000001000a03fc .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075fe7603 5 bytes JMP 00000001000a0804 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000075fe835c 5 bytes JMP 00000001000a0600 .text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe[3172] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000075fff52b 5 bytes JMP 00000001000a0a08 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 000000010043075c .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001004303a4 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 0000000100430b14 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 0000000100430ecc .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 000000010043163c .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 0000000100431284 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001004319f4 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Windows\system32\SearchIndexer.exe[3304] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 00000001003f075c .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001003f03a4 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 00000001003f0b14 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 00000001003f0ecc .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 00000001003f163c .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 00000001003f1284 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001003f19f4 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3508] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\DU Meter\DUMeter.exe[3756] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 000000010010075c .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001001003a4 .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 0000000100100b14 .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 0000000100100ecc .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 000000010010163c .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 0000000100101284 .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001001019f4 .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Program Files\Windows Sidebar\sidebar.exe[3784] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 000000010020075c .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001002003a4 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 0000000100200b14 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 0000000100200ecc .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 000000010020163c .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 0000000100201284 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001002019f4 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Program Files\Core Temp\Core Temp.exe[3848] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100251014 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100250804 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100250a08 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100250c0c .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100250e10 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001002501f8 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001002503fc .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100250600 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000075fdee09 5 bytes JMP 00000001002601f8 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000075fe3982 5 bytes JMP 00000001002603fc .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075fe7603 5 bytes JMP 0000000100260804 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000075fe835c 5 bytes JMP 0000000100260600 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3900] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000075fff52b 5 bytes JMP 0000000100260a08 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3992] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75] .text ... * 2 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000075fdee09 5 bytes JMP 00000001002401f8 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000075fe3982 5 bytes JMP 00000001002403fc .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075fe7603 5 bytes JMP 0000000100240804 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000075fe835c 5 bytes JMP 0000000100240600 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000075fff52b 5 bytes JMP 0000000100240a08 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100251014 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100250804 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100250a08 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100250c0c .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100250e10 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001002501f8 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001002503fc .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100250600 .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000075e51465 2 bytes [E5, 75] .text C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe[3164] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 0000000075e514bb 2 bytes [E5, 75] .text ... * 2 .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Windows\system32\svchost.exe[2432] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100131014 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100130804 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100130a08 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100130c0c .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100130e10 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001001301f8 .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001001303fc .text C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe[1112] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100130600 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 00000001001c075c .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001001c03a4 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 00000001001c0b14 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 00000001001c0ecc .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 00000001001c163c .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 00000001001c1284 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001001c19f4 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe[3628] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 00000001002d075c .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001002d03a4 .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 00000001002d0b14 .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 00000001002d0ecc .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 00000001002d163c .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 00000001002d1284 .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001002d19f4 .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4780] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077b6eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077c53b10 5 bytes JMP 000000010017075c .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077c57ac0 5 bytes JMP 00000001001703a4 .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c81430 5 bytes JMP 0000000100170b14 .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c81490 5 bytes JMP 0000000100170ecc .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c81570 5 bytes JMP 000000010017163c .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c817b0 5 bytes JMP 0000000100171284 .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c827e0 5 bytes JMP 00000001001719f4 .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Windows\System32\svchost.exe[4968] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007feffb66e00 5 bytes JMP 000007ff7fb81dac .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007feffb66f2c 5 bytes JMP 000007ff7fb80ecc .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007feffb67220 5 bytes JMP 000007ff7fb81284 .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007feffb6739c 5 bytes JMP 000007ff7fb8163c .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007feffb67538 5 bytes JMP 000007ff7fb819f4 .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007feffb675e8 5 bytes JMP 000007ff7fb803a4 .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007feffb6790c 5 bytes JMP 000007ff7fb8075c .text C:\Windows\System32\svchost.exe[4308] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007feffb67ab4 5 bytes JMP 000007ff7fb80b14 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077e2fac0 5 bytes JMP 0000000100030600 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077e2fb58 5 bytes JMP 0000000100030804 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077e2fcb0 5 bytes JMP 0000000100030c0c .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077e30038 5 bytes JMP 0000000100030a08 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077e31920 5 bytes JMP 0000000100030e10 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077e4c4dd 5 bytes JMP 00000001000301f8 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077e51287 5 bytes JMP 00000001000303fc .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007663a2ba 1 byte [62] .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 0000000077925181 5 bytes JMP 0000000100241014 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 0000000077925254 5 bytes JMP 0000000100240804 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000779253d5 5 bytes JMP 0000000100240a08 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000779254c2 5 bytes JMP 0000000100240c0c .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000779255e2 5 bytes JMP 0000000100240e10 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 000000007792567c 5 bytes JMP 00000001002401f8 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 000000007792589f 5 bytes JMP 00000001002403fc .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\SysWOW64\sechost.dll!DeleteService 0000000077925a22 5 bytes JMP 0000000100240600 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000075fdee09 5 bytes JMP 00000001002501f8 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000075fe3982 5 bytes JMP 00000001002503fc .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000075fe7603 5 bytes JMP 0000000100250804 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000075fe835c 5 bytes JMP 0000000100250600 .text D:\! - - Transfer - - !\gmer_2.1.19163.exe[4320] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000075fff52b 5 bytes JMP 0000000100250a08 ---- Threads - GMER 2.1 ---- Thread C:\Windows\System32\svchost.exe [4308:2728] 000007fee36a9688 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DisplayName aswFsBlk Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Description avast! mini-filter driver (aswFsBlk) Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Tag 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances@DefaultInstance aswFsBlk Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude 388400 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ImagePath \??\C:\Windows\system32\drivers\aswMonFlt.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DisplayName aswMonFlt Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Group FSFilter Anti-Virus Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Description avast! mini-filter driver (aswMonFlt) Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances@DefaultInstance aswMonFlt Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude 320700 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ImagePath \SystemRoot\System32\Drivers\aswrdr2.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DisplayName aswRdr Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Group PNP_TDI Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DependOnService tcpip? Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Description avast! WFP Redirect driver Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@MSIgnoreLSPDefault Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@WSIgnoreLSPDefault nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@DisplayName aswRvrt Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Description avast! Revert Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@BootCounter 9 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@TickCounter 77010 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@SystemRoot \Device\Harddisk0\Partition1\Windows Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@ImproperShutdown 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DisplayName aswSnx Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Group FSFilter Virtualization Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Description avast! virtualization driver (aswSnx) Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Tag 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances@DefaultInstance aswSnx Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Altitude 137600 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@DisplayName aswSP Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Description avast! Self Protection Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@BehavShield 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFilesFolder \DosDevices\C:\Program Files Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@GadgetFolder \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DisplayName avast! Network Shield Support Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Group PNP_TDI Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DependOnService tcpip? Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Description avast! Network Shield TDI driver Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Tag 8 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@DisplayName aswVmm Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Description avast! VM Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Type 32 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ImagePath "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DisplayName avast! Antivirus Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Group ShellSvcGroup Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DependOnService aswMonFlt?RpcSS? Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@WOW64 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ObjectName LocalSystem Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ServiceSidType 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Description Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer. Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DisplayName aswFsBlk Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Description avast! mini-filter driver (aswFsBlk) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Tag 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances@DefaultInstance aswFsBlk Instance Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude 388400 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ImagePath \??\C:\Windows\system32\drivers\aswMonFlt.sys Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DisplayName aswMonFlt Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Group FSFilter Anti-Virus Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Description avast! mini-filter driver (aswMonFlt) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances@DefaultInstance aswMonFlt Instance Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude 320700 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@ImagePath \SystemRoot\System32\Drivers\aswrdr2.sys Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@DisplayName aswRdr Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Group PNP_TDI Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@DependOnService tcpip? Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Description avast! WFP Redirect driver Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@MSIgnoreLSPDefault Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@WSIgnoreLSPDefault nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Start 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@DisplayName aswRvrt Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Description avast! Revert Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@BootCounter 9 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@TickCounter 77010 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@SystemRoot \Device\Harddisk0\Partition1\Windows Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@ImproperShutdown 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@DisplayName aswSnx Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Group FSFilter Virtualization Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Description avast! virtualization driver (aswSnx) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Tag 2 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances@DefaultInstance aswSnx Instance Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Altitude 137600 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@DisplayName aswSP Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Description avast! Self Protection Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@BehavShield 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFilesFolder \DosDevices\C:\Program Files Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@GadgetFolder \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@DisplayName avast! Network Shield Support Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Group PNP_TDI Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@DependOnService tcpip? Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Description avast! Network Shield TDI driver Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Tag 8 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Start 0 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@DisplayName aswVmm Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Description avast! VM Monitor Reg HKLM\SYSTEM\ControlSet002\services\aswVmm\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Type 32 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ImagePath "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DisplayName avast! Antivirus Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Group ShellSvcGroup Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DependOnService aswMonFlt?RpcSS? Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@WOW64 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ObjectName LocalSystem Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ServiceSidType 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Description Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer. ---- EOF - GMER 2.1 ---- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Wild-Pako (administrator) on WILD-PAKO-PC on 12-10-2013 20:10:26 Running from D:\! - - Transfer - - ! Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeterSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeter.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files\Core Temp\Core Temp.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Dropbox, Inc.) C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7883296 2009-06-25] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-06-25] (Realtek Semiconductor Corp.) HKCU\...\Run: [Remote Control Editor] - "C:\Program Files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe" HKCU\...\Run: [MobileDocuments] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe HKCU\...\Run: [DU Meter] - C:\Program Files (x86)\DU Meter\DUMeter.exe [2749984 2013-09-27] (Hagel Technologies Ltd.) HKCU\...\Run: [CrossLoop] - "C:\Users\Wild-Pako\AppData\Local\CrossLoop\CrossLoopConnect.exe" -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server -noprompts -minimize HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.) MountPoints2: {5711135d-b34d-11de-b593-001fd08ec324} - I:\AutoRun.exe MountPoints2: {57111360-b34d-11de-b593-001fd08ec324} - I:\AutoRun.exe MountPoints2: {ad02c2d2-a265-11df-a90c-001fd08ec324} - I:\AutoRun.exe MountPoints2: {df46a678-1ebf-11e2-b35a-001fd08ec324} - I:\Setup.exe HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software) Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Core Temp.lnk ShortcutTarget: Core Temp.lnk -> C:\Program Files\Core Temp\Core Temp.exe () Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x01E862F5F4B9CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1286050903776 DPF: HKLM-x32 {971FC730-55F1-461F-83FD-B3BF5E1F039E} hxxp://wg.dyndns.ws/AVC_AX_742.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\foxmarks@kei.com FF Extension: VLC Media Player - Web Plugin - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\vlcplugin@radicalsoft.com FF Extension: Flagfox - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} FF Extension: Flashblock - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} FF Extension: adblockpopups - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\adblockpopups@jessehakanen.net.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF |
12.10.2013, 23:05 | #5 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeCode:
ATTFilter Chrome: ======= CHR HomePage: hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019 CHR RestoreOnStartup: "hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=119357&tt=240913_246&tsp=5016" CHR DefaultSearchURL: (SearchGol) - hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019 CHR DefaultSuggestURL: (SearchGol) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U40) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.400.43) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Google Docs) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (Feven 1.5) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.24.28_0 CHR Extension: (YouTube) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Gmail) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 DUMeterSvc; C:\Program Files (x86)\DU Meter\DUMeterSvc.exe [1391136 2009-09-04] (Hagel Technologies Ltd.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-25] (DT Soft Ltd) S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider) S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider) S3 MTSBDA; C:\Windows\System32\DRIVERS\MtsBda.sys [322080 2008-12-01] (TerraTec Provide) S3 MtsHID; C:\Windows\System32\DRIVERS\MtsHid.sys [27168 2008-12-01] (TerraTec Provide) S1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation) R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation) R3 ALSysIO; \??\C:\Users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 cpuz135; \??\C:\Users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [x] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST 2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable 2013-10-12 19:48 - 2013-10-12 19:49 - 00000000 ____D C:\AdwCleaner 2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk 2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk 2013-10-09 21:53 - 2013-10-09 21:54 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR 2013-10-09 18:24 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-09 18:24 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-09 18:24 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-09 18:24 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-09 18:24 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-09 18:24 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-09 18:24 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-09 18:24 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-09 18:24 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-09 18:24 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-09 18:03 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-09 18:03 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-09 18:03 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-09 18:03 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 18:03 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 18:03 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-09 18:03 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-09 18:03 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-09 18:03 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-09 18:03 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-09 18:03 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 18:03 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-09 18:03 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-09 18:03 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-09 18:03 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-09 18:03 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-09 18:03 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-09 18:03 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-09 18:03 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-09 18:03 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-09 18:03 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit 2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk 2013-10-08 19:58 - 2013-10-12 19:52 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-08 19:58 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-08 19:58 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-08 19:56 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-08 19:52 - 2013-10-08 19:56 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark 2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-07 21:59 - 2013-10-07 22:09 - 00001760 _____ C:\Windows\wininit.ini 2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg 2013-10-07 21:38 - 2013-10-07 21:59 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-07 21:38 - 2013-10-07 21:39 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-07 21:38 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI 2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log 2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-10-07 18:52 - 2013-10-07 18:53 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt 2013-10-03 18:20 - 2013-10-03 18:26 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-10-03 15:26 - 2008-09-24 10:38 - 01048576 _____ C:\Users\Wild-Pako\ep43ds3.f9 2013-10-03 15:26 - 2008-08-28 09:16 - 00026351 _____ C:\Users\Wild-Pako\FLASHSPI.EXE 2013-10-03 13:51 - 2013-10-03 14:47 - 00037130 _____ C:\pingstat.txt 2013-10-03 13:49 - 2013-10-03 13:50 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat 2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems 2013-10-02 21:26 - 2013-10-02 21:27 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover 2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech 2013-10-02 21:06 - 2013-10-10 19:08 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core 2013-10-01 12:42 - 2013-10-07 22:10 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop 2013-09-29 14:07 - 2013-10-11 19:53 - 00000000 ____D C:\Windows\Minidump 2013-09-29 13:45 - 2013-09-29 13:48 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95 2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-09-29 11:39 - 2013-10-03 10:23 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC 2013-09-29 11:35 - 2013-10-03 10:25 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC 2013-09-28 22:33 - 2013-10-12 19:51 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job 2013-09-28 22:33 - 2013-10-12 19:51 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job 2013-09-28 22:33 - 2013-10-12 19:51 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job 2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater 2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader 2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler 2013-09-28 22:32 - 2013-10-12 19:51 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job 2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID 2013-09-28 22:31 - 2013-10-12 19:51 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job 2013-09-28 22:31 - 2013-09-28 22:33 - 00000000 ____D C:\Program Files (x86)\Feven 1.5 2013-09-28 22:30 - 2013-09-28 22:30 - 00236248 _____ (Tuguu S.L.U) C:\Users\Wild-Pako\Downloads\cpu-z.exe 2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe 2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome 2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games 2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk 2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack 2013-09-28 18:04 - 2013-10-09 18:26 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk 2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client 2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-09-27 22:53 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2013-09-27 22:53 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2013-09-27 22:53 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2013-09-27 22:53 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2013-09-27 22:53 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2013-09-27 22:53 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2013-09-27 22:53 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2013-09-27 22:53 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2013-09-27 22:53 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2013-09-27 22:53 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2013-09-27 22:53 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2013-09-27 22:53 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2013-09-27 22:53 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2013-09-27 22:53 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2013-09-27 22:53 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2013-09-27 22:53 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2013-09-27 22:53 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2013-09-27 22:53 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2013-09-27 22:53 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2013-09-27 22:53 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2013-09-27 22:53 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2013-09-27 22:53 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2013-09-27 22:53 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2013-09-27 22:53 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2013-09-27 22:53 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2013-09-27 22:53 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2013-09-27 22:53 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2013-09-27 22:53 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2013-09-27 22:53 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2013-09-27 22:53 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2013-09-27 22:53 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2013-09-27 22:53 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2013-09-27 22:53 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2013-09-27 22:53 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2013-09-27 22:53 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2013-09-27 22:53 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2013-09-27 22:53 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2013-09-27 22:53 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2013-09-27 22:53 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2013-09-27 22:53 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2013-09-27 22:53 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2013-09-27 22:53 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2013-09-27 22:52 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2013-09-27 22:52 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2013-09-27 22:52 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2013-09-27 22:52 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2013-09-27 22:52 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2013-09-27 22:52 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2013-09-27 22:52 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2013-09-27 22:52 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2013-09-27 22:52 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2013-09-27 22:52 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2013-09-27 22:52 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2013-09-27 22:52 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2013-09-27 22:52 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2013-09-27 22:52 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2013-09-27 22:52 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2013-09-27 22:52 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2013-09-27 22:52 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2013-09-27 22:52 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2013-09-27 22:52 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2013-09-27 22:52 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2013-09-27 22:52 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2013-09-27 22:52 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2013-09-27 22:52 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2013-09-27 22:52 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2013-09-27 22:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2013-09-27 22:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2013-09-27 22:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2013-09-27 22:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2013-09-27 22:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2013-09-27 22:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2013-09-27 22:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2013-09-27 22:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk 2013-09-27 17:14 - 2013-09-27 17:18 - 00000000 ____D C:\tempvideo 2013-09-27 17:13 - 2013-09-27 23:05 - 00000044 _____ C:\DebugTraceAP.log 2013-09-27 12:43 - 2013-09-27 12:45 - 00000000 ____D C:\Program Files (x86)\DU Meter 2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies 2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk 2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-09-27 12:20 - 2013-10-12 19:52 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox 2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM 2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice 2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-09-27 08:18 - 2013-09-27 08:19 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-09-26 20:17 - 2013-10-03 04:52 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-26 07:52 - 2013-10-12 19:50 - 00004173 _____ C:\Windows\setupact.log 2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log 2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk 2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP 2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line 2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk 2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme 2013-09-25 20:29 - 2013-09-25 20:31 - 00000000 ____D C:\Windows\rescache 2013-09-25 19:58 - 2013-09-25 19:59 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part 2013-09-25 19:40 - 2013-10-12 19:53 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-25 19:40 - 2013-10-10 18:48 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-25 19:40 - 2013-10-10 18:48 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-25 19:40 - 2013-10-08 00:48 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-25 19:39 - 2013-10-12 19:51 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-25 19:39 - 2013-10-04 22:11 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk 2013-09-25 19:39 - 2013-10-04 22:11 - 00000000 ____D C:\Program Files\MPC-HC 2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google 2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe 2013-09-25 19:07 - 2013-10-09 18:23 - 00000000 ____D C:\Windows\system32\MRT 2013-09-25 18:00 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-09-25 18:00 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-09-25 18:00 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-09-25 18:00 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-09-25 18:00 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-09-25 18:00 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-09-25 18:00 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-09-25 18:00 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-09-25 18:00 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-09-25 18:00 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-09-25 18:00 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-09-25 18:00 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-09-25 18:00 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-09-25 17:59 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-25 17:59 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-25 17:59 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-25 17:59 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-25 17:59 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-25 17:59 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-25 17:59 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-25 17:59 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-25 17:59 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-25 17:59 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-25 17:59 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-25 17:59 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-25 17:59 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-25 17:59 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-25 17:59 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-25 17:59 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-25 17:59 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-25 17:59 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-25 17:59 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-25 17:59 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-25 17:43 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-25 17:43 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-25 17:43 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-25 17:43 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-25 17:43 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-25 17:43 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-09-25 17:43 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-09-25 17:43 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-09-25 17:43 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-09-25 17:43 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-09-25 17:43 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-09-25 17:43 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-09-25 17:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-09-25 17:43 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-09-25 17:43 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-09-25 17:43 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-09-25 17:43 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-09-25 17:43 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-09-25 17:43 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-09-25 17:43 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-09-25 17:43 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-09-25 17:43 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-09-25 17:43 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-09-25 17:43 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-09-25 17:43 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-09-25 17:43 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-09-25 17:43 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-09-25 17:43 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-09-25 17:43 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-09-25 17:43 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-09-25 17:43 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle 2013-09-25 17:38 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-09-25 17:38 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-09-25 17:37 - 2013-09-25 17:36 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-25 17:37 - 2013-09-25 17:36 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-25 17:37 - 2013-09-25 17:36 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip 2013-09-25 17:02 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-09-25 17:02 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2013-09-25 17:02 - 2012-06-02 16:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-09-25 16:55 - 2013-09-25 17:02 - 00008799 _____ C:\Windows\IE10_main.log 2013-09-25 16:54 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-09-25 16:54 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-09-25 16:54 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-09-25 16:54 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-09-25 16:54 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-09-25 16:54 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-09-25 16:54 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-09-25 16:54 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2013-09-25 16:54 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-09-25 16:54 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-09-25 16:54 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-09-25 16:54 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-09-25 16:54 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-09-25 16:54 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-09-25 16:54 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-09-25 16:54 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-09-25 16:54 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-09-25 16:54 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-09-25 16:54 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2013-09-25 16:54 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-09-25 16:54 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-09-25 16:54 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-09-25 16:54 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-09-25 16:54 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-09-25 16:51 - 2012-07-26 05:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-09-25 16:51 - 2012-07-26 04:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-09-25 16:51 - 2012-07-26 04:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-09-25 16:51 - 2012-06-02 16:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-09-25 16:48 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-09-25 16:48 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-09-25 16:48 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-09-25 16:48 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-09-25 16:48 - 2013-01-13 21:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-09-25 16:48 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-09-25 16:48 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-09-25 16:48 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-09-25 16:48 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-09-25 16:48 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-09-25 16:48 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-09-25 16:48 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-09-25 16:48 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-09-25 16:48 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-09-25 16:48 - 2013-01-13 21:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-09-25 16:48 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-09-25 16:48 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-09-25 16:48 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-09-25 16:48 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-09-25 16:48 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-09-25 16:48 - 2013-01-13 21:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-09-25 16:48 - 2013-01-13 21:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-09-25 16:48 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-09-25 16:48 - 2013-01-13 20:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-09-25 16:48 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-09-25 16:48 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-09-25 16:48 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-09-25 16:48 - 2013-01-04 08:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-09-25 16:48 - 2013-01-04 08:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-09-25 16:46 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-09-25 16:46 - 2012-12-07 15:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-09-25 16:46 - 2012-12-07 15:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-09-25 16:46 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-09-25 16:46 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-09-25 16:46 - 2012-12-07 13:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-09-25 16:46 - 2012-11-30 01:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2013-09-25 16:46 - 2012-11-30 01:15 - 00420064 _____ C:\Windows\system32\locale.nls 2013-09-25 16:46 - 2012-11-22 07:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2013-09-25 16:46 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2013-09-25 16:46 - 2012-10-09 20:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-09-25 16:46 - 2012-10-09 20:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-09-25 16:46 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-09-25 16:46 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2013-09-25 16:46 - 2012-10-03 19:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-09-25 16:46 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2013-09-25 16:46 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2013-09-25 16:46 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2013-09-25 16:46 - 2012-10-03 18:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2013-09-25 16:46 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-09-25 16:46 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-09-25 16:46 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-09-25 16:46 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-09-25 16:46 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-09-25 16:46 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-09-25 16:46 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-09-25 16:46 - 2012-08-22 20:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-09-25 16:46 - 2012-08-21 23:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2013-09-25 16:46 - 2012-07-04 22:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-09-25 16:46 - 2012-05-05 10:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-09-25 16:46 - 2012-05-05 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2013-09-25 16:46 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-09-25 16:46 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-09-25 16:46 - 2012-01-13 09:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-09-25 16:42 - 2012-02-11 08:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-09-25 16:42 - 2012-02-11 08:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2013-09-25 16:42 - 2011-05-04 07:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-09-25 16:42 - 2011-05-04 07:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-09-25 16:42 - 2011-05-04 07:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-09-25 16:42 - 2011-05-04 07:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-09-25 16:42 - 2011-05-04 06:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-09-25 16:42 - 2011-05-04 06:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-09-25 16:42 - 2011-05-04 06:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-09-25 16:42 - 2011-05-04 06:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-09-25 16:39 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2013-09-25 16:39 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe 2013-09-24 19:15 - 2013-09-25 16:39 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-09-24 19:14 - 2013-09-25 17:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp 2013-09-24 19:14 - 2013-09-25 16:39 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-09-24 19:14 - 2011-03-04 21:44 - 02095600 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxsfs.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00698864 ____N (Sonic Solutions) C:\Windows\SysWOW64\px.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00571888 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxdrv.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00440816 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxwave.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00219632 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxmas.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00133616 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxafs.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00100848 ____N (Sonic Solutions) C:\Windows\SysWOW64\vxblock.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00072176 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxhpinst.exe 2013-09-24 19:14 - 2011-03-04 21:44 - 00068592 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxinsa64.exe 2013-09-24 19:14 - 2011-03-04 21:44 - 00068080 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxcpya64.exe 2013-09-22 18:16 - 2013-09-27 08:11 - 00000000 ____D C:\Windows\system32\appmgmt 2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D} 2013-09-20 19:52 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2013-09-20 19:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk 2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI 2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-09-18 19:38 - 2013-10-07 18:57 - 00000000 ____D C:\Program Files\ATI Technologies 2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI ==================== One Month Modified Files and Folders ======= 2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST 2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable 2013-10-12 20:09 - 2009-08-13 17:20 - 00000000 ____D C:\Users\Wild-Pako 2013-10-12 19:56 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-12 19:56 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-12 19:54 - 2009-08-13 17:15 - 01258373 _____ C:\Windows\WindowsUpdate.log 2013-10-12 19:53 - 2013-09-25 19:40 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-12 19:52 - 2013-10-08 19:58 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-12 19:52 - 2013-09-27 12:20 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox 2013-10-12 19:51 - 2013-09-28 22:33 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job 2013-10-12 19:51 - 2013-09-28 22:33 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job 2013-10-12 19:51 - 2013-09-28 22:33 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job 2013-10-12 19:51 - 2013-09-28 22:32 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job 2013-10-12 19:51 - 2013-09-28 22:31 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job 2013-10-12 19:51 - 2013-09-25 19:39 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-12 19:51 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-12 19:50 - 2013-09-26 07:52 - 00004173 _____ C:\Windows\setupact.log 2013-10-12 19:49 - 2013-10-12 19:48 - 00000000 ____D C:\AdwCleaner 2013-10-12 19:38 - 2012-07-31 20:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-12 17:57 - 2009-08-13 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-10-12 17:16 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Thunderbird 2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk 2013-10-11 19:53 - 2013-09-29 14:07 - 00000000 ____D C:\Windows\Minidump 2013-10-11 15:14 - 2009-08-13 22:36 - 00196378 _____ C:\Windows\PFRO.log 2013-10-10 19:08 - 2013-10-02 21:06 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games 2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk 2013-10-10 18:48 - 2013-09-25 19:40 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-10 18:48 - 2013-09-25 19:40 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-10 18:45 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-09 21:54 - 2013-10-09 21:53 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR 2013-10-09 18:38 - 2012-07-31 20:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 18:38 - 2012-07-31 20:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 18:38 - 2012-07-31 20:20 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-09 18:31 - 2009-07-14 06:45 - 00295824 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-09 18:26 - 2013-09-28 18:04 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-09 18:26 - 2009-07-26 14:25 - 00699416 _____ C:\Windows\system32\perfh007.dat 2013-10-09 18:26 - 2009-07-26 14:25 - 00149556 _____ C:\Windows\system32\perfc007.dat 2013-10-09 18:26 - 2009-07-14 07:13 - 01593956 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-09 18:23 - 2013-09-25 19:07 - 00000000 ____D C:\Windows\system32\MRT 2013-10-09 18:22 - 2010-10-02 14:30 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit 2013-10-08 21:20 - 2012-11-04 16:24 - 00328221 _____ C:\Windows\DirectX.log 2013-10-08 21:03 - 2009-08-13 17:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk 2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-08 19:58 - 2009-08-13 20:26 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-08 19:56 - 2013-10-08 19:52 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark 2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-08 00:48 - 2013-09-25 19:40 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-07 22:10 - 2013-10-01 12:42 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop 2013-10-07 22:09 - 2013-10-07 21:59 - 00001760 _____ C:\Windows\wininit.ini 2013-10-07 21:59 - 2013-10-07 21:38 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg 2013-10-07 21:39 - 2013-10-07 21:38 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI 2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-10-07 18:57 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log 2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-10-07 18:53 - 2013-10-07 18:52 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt 2013-10-05 17:01 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\vlc 2013-10-04 22:11 - 2013-09-25 19:39 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk 2013-10-04 22:11 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files\MPC-HC 2013-10-03 18:26 - 2013-10-03 18:20 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-10-03 14:47 - 2013-10-03 13:51 - 00037130 _____ C:\pingstat.txt 2013-10-03 13:50 - 2013-10-03 13:49 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat 2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk 2013-10-03 10:25 - 2013-09-29 11:35 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC 2013-10-03 10:23 - 2013-09-29 11:39 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC 2013-10-03 04:52 - 2013-09-26 20:17 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems 2013-10-02 21:27 - 2013-10-02 21:26 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover 2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core 2013-10-02 19:29 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\dvdcss 2013-09-29 13:48 - 2013-09-29 13:45 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95 2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk 2013-09-29 12:29 - 2012-11-07 23:30 - 00000647 _____ C:\Users\Public\Desktop\HELI-X4.lnk 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater 2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader 2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler 2013-09-28 22:33 - 2013-09-28 22:31 - 00000000 ____D C:\Program Files (x86)\Feven 1.5 2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID 2013-09-28 22:30 - 2013-09-28 22:30 - 00236248 _____ (Tuguu S.L.U) C:\Users\Wild-Pako\Downloads\cpu-z.exe 2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe 2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome 2013-09-28 22:03 - 2010-04-09 20:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-09-28 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help 2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games 2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk 2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack 2013-09-28 20:02 - 2010-08-07 22:58 - 00043520 _____ C:\Windows\SysWOW64\CmdLineExt03.dll 2013-09-28 13:59 - 2012-11-10 19:12 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\FileZilla 2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk 2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client 2013-09-28 11:22 - 2012-07-25 18:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games 2013-09-27 23:05 - 2013-09-27 17:13 - 00000044 _____ C:\DebugTraceAP.log 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-09-27 22:54 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk 2013-09-27 17:18 - 2013-09-27 17:14 - 00000000 ____D C:\tempvideo 2013-09-27 12:45 - 2013-09-27 12:43 - 00000000 ____D C:\Program Files (x86)\DU Meter 2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies 2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk 2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM 2013-09-27 11:48 - 2009-08-13 18:07 - 00000990 _____ C:\Users\Wild-Pako\Desktop\Miranda IM.lnk 2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Miranda 2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Program Files (x86)\Miranda IM 2013-09-27 09:04 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Thunderbird 2013-09-27 09:04 - 2009-08-13 18:06 - 00002050 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2013-09-27 08:51 - 2009-08-13 17:52 - 00064024 _____ C:\Users\Wild-Pako\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice 2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-09-27 08:19 - 2013-09-27 08:18 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-09-27 08:14 - 2009-08-13 17:58 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2013-09-27 08:11 - 2013-09-22 18:16 - 00000000 ____D C:\Windows\system32\appmgmt 2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log 2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk 2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP 2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line 2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk 2013-09-25 20:41 - 2009-08-13 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme 2013-09-25 20:31 - 2013-09-25 20:29 - 00000000 ____D C:\Windows\rescache 2013-09-25 19:59 - 2013-09-25 19:58 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part 2013-09-25 19:59 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Mozilla 2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google 2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe 2013-09-25 19:33 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-09-25 17:49 - 2009-07-14 09:46 - 00000000 ____D C:\Program Files\Windows Journal 2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle 2013-09-25 17:36 - 2013-09-25 17:37 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-25 17:36 - 2013-09-25 17:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-25 17:36 - 2013-09-25 17:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-25 17:36 - 2010-10-02 14:28 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-09-25 17:36 - 2009-09-11 18:41 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-25 17:28 - 2009-08-13 17:21 - 00001413 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-25 17:22 - 2013-09-24 19:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp 2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip 2013-09-25 17:02 - 2013-09-25 16:55 - 00008799 _____ C:\Windows\IE10_main.log 2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-09-25 16:39 - 2013-09-24 19:15 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-09-25 16:39 - 2013-09-24 19:14 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe 2013-09-25 15:36 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-25 15:33 - 2009-08-13 18:04 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Adobe 2013-09-25 15:28 - 2009-08-13 18:06 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-23 01:28 - 2013-10-09 18:24 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-09 18:24 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll |
12.10.2013, 23:06 | #6 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeCode:
ATTFilter 2013-09-23 01:27 - 2013-10-09 18:24 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-09 18:24 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-09 18:24 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-09 18:24 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-09 18:24 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-22 18:27 - 2009-09-18 16:00 - 00000000 ____D C:\Program Files (x86)\Zylom Games 2013-09-22 18:25 - 2009-08-13 21:00 - 00000000 ____D C:\Program Files (x86)\Vuze 2013-09-22 18:25 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Mozilla 2013-09-22 18:24 - 2009-08-13 17:46 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\TerraTec 2013-09-22 18:21 - 2013-04-02 19:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-09-22 18:21 - 2009-08-13 18:02 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Apple Computer 2013-09-22 18:21 - 2009-08-13 18:00 - 00000000 ____D C:\ProgramData\Apple Computer 2013-09-22 18:16 - 2012-07-25 19:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ArcSoft 2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D} 2013-09-22 17:53 - 2010-07-08 16:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-09-21 17:09 - 2009-10-07 17:59 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\HCM Updater 2013-09-21 05:38 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-09 18:24 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-09 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-20 19:54 - 2013-09-20 19:49 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk 2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI 2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI Files to move or delete: ==================== C:\Users\Wild-Pako\FLASHSPI.EXE ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-11 17:44 ==================== End Of Log ============================ |
13.10.2013, 14:06 | #7 | |
/// the machine /// TB-Ausbilder | Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.10.2013, 14:31 | #8 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeCode:
ATTFilter ComboFix 13-10-13.01 - Wild-Pako 13.10.2013 15:18:38.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.6142.3288 [GMT 2:00] ausgeführt von:: c:\users\Wild-Pako\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\#Short company name# c:\programdata\#Short company name#\#settings_subfolder#\Timerlist.xml c:\users\Wild-Pako\AppData\Roaming\#Short company name# c:\users\Wild-Pako\AppData\Roaming\#Short company name#\#settings_subfolder#\#dvr.ini c:\users\Wild-Pako\AppData\Roaming\#Short company name#\#settings_subfolder#\Log\VersionCheck.log c:\users\Wild-Pako\AppData\Roaming\#Short company name#\#settings_subfolder#\Log\VersionCheck01.log c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2013-09-13 bis 2013-10-13 )))))))))))))))))))))))))))))) . . 2013-10-13 13:24 . 2013-10-13 13:24 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-10-13 09:15 . 2013-10-13 09:15 -------- d-----w- c:\users\Wild-Pako\AppData\Local\TransMac 2013-10-13 09:15 . 2013-10-13 09:15 -------- d-----w- c:\program files (x86)\TransMac 2013-10-12 23:16 . 2013-10-12 23:16 -------- d-----w- c:\program files (x86)\XeMu360 2013-10-12 18:10 . 2013-10-12 18:10 -------- d-----w- C:\FRST 2013-10-12 17:48 . 2013-10-12 17:49 -------- d-----w- C:\AdwCleaner 2013-10-12 15:56 . 2013-10-12 18:24 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2013-10-12 15:08 . 2013-10-12 15:08 -------- d-----w- c:\users\Wild-Pako\AppData\Local\SCE 2013-10-11 13:19 . 2013-09-15 22:50 9694160 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CE404130-0FE8-4176-A6D3-20F6AE8EE0CF}\mpengine.dll 2013-10-09 16:03 . 2013-07-04 12:50 633856 ----a-w- c:\windows\system32\comctl32.dll 2013-10-08 19:32 . 2013-10-08 19:32 -------- d-----w- c:\programdata\Orbit 2013-10-08 18:31 . 2013-10-08 18:31 -------- d--h--w- c:\program files (x86)\Common Files\EAInstaller 2013-10-08 17:58 . 2013-08-30 07:48 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-10-08 17:58 . 2013-08-30 07:48 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-10-08 17:58 . 2013-08-30 07:48 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-10-08 17:58 . 2013-08-30 07:48 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-10-08 17:58 . 2013-08-30 07:48 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-10-08 17:58 . 2013-08-30 07:48 204880 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-10-08 17:58 . 2013-08-30 07:48 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-10-08 17:58 . 2013-08-30 07:48 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-10-08 17:58 . 2013-08-30 07:47 287840 ----a-w- c:\windows\system32\aswBoot.exe 2013-10-08 17:56 . 2013-08-30 07:47 41664 ----a-w- c:\windows\avastSS.scr 2013-10-08 17:56 . 2013-10-08 17:56 -------- d-----w- c:\program files\AVAST Software 2013-10-08 17:52 . 2013-10-08 17:56 -------- d-----w- c:\programdata\AVAST Software 2013-10-08 17:08 . 2013-10-08 17:08 -------- d-----w- c:\programdata\Futuremark 2013-10-08 17:06 . 2013-10-08 17:06 -------- d-----w- c:\program files (x86)\NVIDIA Corporation 2013-10-08 17:06 . 2013-10-08 17:06 -------- d-----w- c:\program files (x86)\AGEIA Technologies 2013-10-07 19:38 . 2013-10-07 19:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2013-10-07 19:38 . 2009-01-25 11:14 17272 ----a-w- c:\windows\system32\sdnclean64.exe 2013-10-07 19:38 . 2013-10-07 19:39 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2 2013-10-07 17:10 . 2013-10-07 17:10 -------- d-----w- c:\programdata\ATI 2013-10-07 16:58 . 2013-10-07 16:58 -------- d-----w- c:\programdata\AMD 2013-10-07 16:58 . 2013-10-07 16:58 -------- d-----w- c:\program files (x86)\AMD AVT 2013-10-07 16:58 . 2013-10-07 16:58 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies 2013-10-07 16:55 . 2013-10-07 16:55 -------- d-----w- c:\program files\Common Files\ATI Technologies 2013-10-07 16:52 . 2013-10-07 16:53 -------- d-----w- c:\programdata\Package Cache 2013-10-03 16:20 . 2013-10-03 16:26 25640 ----a-w- c:\windows\gdrv.sys 2013-10-03 13:26 . 2008-08-28 07:16 26351 ----a-w- c:\users\Wild-Pako\FLASHSPI.EXE 2013-10-02 21:03 . 2013-10-02 21:03 -------- d-----w- c:\users\Wild-Pako\AppData\Roaming\Sinvise Systems 2013-10-02 21:03 . 2013-10-02 21:03 -------- d-----w- c:\program files (x86)\Sinvise Systems 2013-10-02 19:24 . 2013-10-02 19:24 -------- d-----w- c:\users\Wild-Pako\AppData\Roaming\Leadertech 2013-10-02 19:06 . 2013-10-02 19:06 -------- d-----w- c:\programdata\Electronic Arts 2013-10-02 19:06 . 2013-10-02 19:06 -------- d-----w- c:\programdata\EA Core 2013-10-01 10:42 . 2013-10-07 20:10 -------- d-----w- c:\users\Wild-Pako\AppData\Local\CrossLoop 2013-09-29 11:43 . 2013-09-29 11:43 -------- d-----w- c:\program files\Core Temp 2013-09-29 09:49 . 2013-09-29 09:49 49152 ----a-r- c:\users\Wild-Pako\AppData\Roaming\Microsoft\Installer\{AF80D8A3-CCEC-4CC2-BE6C-3E8512286993}\NewShortcut1_109A2A71E4394D28A5ACD8F8321BB21B.exe 2013-09-29 09:43 . 2013-09-29 09:43 49152 ----a-r- c:\users\Wild-Pako\AppData\Roaming\Microsoft\Installer\{12F865ED-8D74-427A-8F73-8687D37E9C5D}\NewShortcut2_B81EF528E6964545A57DCFB2387636B2.exe 2013-09-29 09:43 . 2013-09-29 09:43 49152 ----a-r- c:\users\Wild-Pako\AppData\Roaming\Microsoft\Installer\{12F865ED-8D74-427A-8F73-8687D37E9C5D}\NewShortcut1_D82E1A21FF374417B3E68D61F803C35D.exe 2013-09-28 20:35 . 2013-09-28 20:35 -------- d-----w- c:\program files\Uninstaller 2013-09-28 20:32 . 2013-09-28 20:32 -------- d-----w- c:\program files\CPUID 2013-09-28 20:31 . 2013-09-28 20:33 -------- d-----w- c:\program files (x86)\Feven 1.5 2013-09-28 20:12 . 2013-09-28 20:12 -------- d-----w- c:\program files\Defraggler 2013-09-28 20:07 . 2013-09-28 20:07 -------- d-----w- c:\users\Wild-Pako\AppData\Local\avgchrome 2013-09-28 19:41 . 2013-09-28 19:41 -------- d-----w- c:\users\Wild-Pako\AppData\Local\2K Games 2013-09-28 16:00 . 2013-09-28 16:00 -------- d-----w- c:\program files (x86)\Microsoft.NET 2013-09-28 11:51 . 2013-09-28 11:51 -------- d-----w- c:\program files (x86)\FileZilla FTP Client 2013-09-27 21:05 . 2013-09-27 21:05 -------- d-----w- c:\users\Wild-Pako\AppData\Local\Rockstar Games 2013-09-27 21:05 . 2013-09-27 21:05 -------- d-sh--w- c:\programdata\SecuROM 2013-09-27 20:54 . 2013-09-27 20:54 -------- d-----w- c:\windows\SysWow64\xlive 2013-09-27 20:54 . 2013-09-27 20:54 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE 2013-09-27 20:52 . 2007-03-05 10:42 15128 ----a-w- c:\windows\SysWow64\x3daudio1_1.dll 2013-09-27 15:14 . 2013-09-27 15:18 -------- d-----w- C:\tempvideo 2013-09-27 10:43 . 2013-09-27 10:43 -------- d-----w- c:\programdata\Hagel Technologies 2013-09-27 10:43 . 2013-09-27 10:45 -------- d-----w- c:\program files (x86)\DU Meter 2013-09-27 10:20 . 2013-10-13 09:03 -------- d-----w- c:\users\Wild-Pako\AppData\Roaming\Dropbox 2013-09-27 06:22 . 2013-09-27 06:22 -------- d-----w- c:\users\Wild-Pako\AppData\Roaming\OpenOffice 2013-09-27 06:18 . 2013-09-27 06:19 -------- d-----w- c:\program files (x86)\OpenOffice 4 2013-09-26 18:17 . 2013-09-26 18:17 -------- d-----w- c:\program files (x86)\TeamViewer 2013-09-26 13:00 . 2013-09-26 13:00 -------- d-----w- c:\windows\SysWow64\searchplugins 2013-09-26 13:00 . 2013-09-26 13:00 -------- d-----w- c:\windows\SysWow64\Extensions 2013-09-25 19:57 . 2013-09-25 19:57 -------- d-----w- c:\programdata\Canneverbe Limited 2013-09-25 19:56 . 2013-09-25 19:56 -------- d-----w- c:\users\Wild-Pako\AppData\Roaming\Canneverbe Limited 2013-09-25 19:56 . 2013-09-25 19:56 -------- d-----w- c:\program files (x86)\CDBurnerXP 2013-09-25 19:34 . 2013-09-25 19:34 -------- d-----w- c:\program files (x86)\Electronics Line 2013-09-25 18:40 . 2013-09-25 18:40 -------- d-----w- c:\users\Wild-Pako\Programme 2013-09-25 18:29 . 2013-09-25 18:31 -------- d-----w- c:\windows\rescache 2013-09-25 17:39 . 2013-09-25 17:40 -------- d-----w- c:\users\Wild-Pako\AppData\Local\Google 2013-09-25 17:39 . 2013-09-25 17:40 -------- d-----w- c:\program files (x86)\Google 2013-09-25 17:39 . 2013-10-04 20:11 -------- d-----w- c:\program files\MPC-HC 2013-09-25 17:07 . 2013-10-09 16:23 -------- d-----w- c:\windows\system32\MRT 2013-09-25 15:59 . 2013-08-02 02:23 5550528 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-09-25 15:43 . 2013-02-27 05:48 1930752 ----a-w- c:\windows\system32\authui.dll 2013-09-25 15:38 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2013-09-25 15:38 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll 2013-09-25 15:38 . 2013-09-25 15:38 -------- d-----w- c:\programdata\Oracle 2013-09-25 15:37 . 2013-09-25 15:37 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-09-25 15:37 . 2013-09-25 15:36 868264 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-09-25 15:37 . 2013-09-25 15:36 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-09-25 15:02 . 2012-07-26 07:46 2560 ----a-w- c:\windows\system32\drivers\de-DE\wdf01000.sys.mui 2013-09-25 15:02 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2013-09-25 15:02 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui 2013-09-25 15:02 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll 2013-09-25 14:54 . 2012-08-23 15:09 3584 ----a-w- c:\windows\system32\drivers\de-DE\tsusbflt.sys.mui 2013-09-25 14:51 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll 2013-09-25 14:51 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2013-09-25 14:51 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2013-09-25 14:51 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe 2013-09-25 14:51 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll 2013-09-25 14:51 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2013-09-25 14:51 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll 2013-09-25 14:46 . 2012-12-07 13:20 441856 ----a-w- c:\windows\system32\Wpc.dll 2013-09-25 14:42 . 2011-05-04 05:25 2315776 ----a-w- c:\windows\system32\tquery.dll 2013-09-25 14:39 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\SysWow64\D3DX9_42.dll 2013-09-25 14:39 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\SysWow64\d3dx9_31.dll 2013-09-25 14:38 . 2013-09-25 14:38 -------- d-----w- c:\program files (x86)\Winamp Detect 2013-09-25 14:38 . 2013-09-25 14:38 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine 2013-09-25 13:28 . 2013-09-11 02:28 271256 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll 2013-09-25 13:28 . 2013-09-11 02:27 107416 ----a-w- c:\program files (x86)\Mozilla Firefox\webapprt-stub.exe 2013-09-25 13:28 . 2013-09-11 02:27 170232 ----a-w- c:\program files (x86)\Mozilla Firefox\webapp-uninstaller.exe 2013-09-25 13:28 . 2013-09-11 02:27 27544 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-hang-ui.exe 2013-09-25 13:28 . 2013-09-11 02:26 74648 ----a-w- c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll 2013-09-24 17:14 . 2011-03-04 19:44 133616 ------w- c:\windows\SysWow64\pxafs.dll 2013-09-24 17:14 . 2013-09-25 15:22 -------- d-----w- c:\users\Wild-Pako\AppData\Roaming\Winamp 2013-09-24 17:14 . 2013-09-25 14:39 -------- d-----w- c:\program files (x86)\Winamp 2013-09-22 16:16 . 2013-09-27 06:11 -------- d-----w- c:\windows\system32\appmgmt 2013-09-22 08:15 . 2013-09-22 08:18 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2013-09-20 17:52 . 2005-12-05 16:09 3815120 ----a-w- c:\windows\system32\d3dx9_28.dll 2013-09-20 17:49 . 2013-09-20 17:54 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2013-09-20 17:49 . 2013-09-20 17:54 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2013-09-20 17:49 . 2013-09-20 17:54 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2013-09-20 17:49 . 2013-09-20 17:54 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll 2013-09-20 17:49 . 2013-09-20 17:49 -------- d-----w- c:\program files (x86)\OpenAL 2013-09-20 17:47 . 2013-09-20 17:47 -------- d-----w- c:\program files (x86)\Futuremark 2013-09-20 17:44 . 2013-09-20 17:44 -------- d-----w- c:\users\Wild-Pako\AppData\Roaming\ATI 2013-09-20 17:44 . 2013-09-20 17:44 -------- d-----w- c:\users\Wild-Pako\AppData\Local\ATI . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-10-09 16:38 . 2012-07-31 18:20 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-10-09 16:38 . 2012-07-31 18:20 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-10-09 16:22 . 2010-10-02 12:30 80541720 ----a-w- c:\windows\system32\MRT.exe 2013-09-29 16:23 . 2009-08-18 10:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll 2013-09-29 16:23 . 2009-08-18 09:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-09-28 18:02 . 2010-08-07 20:58 43520 ----a-w- c:\windows\SysWow64\CmdLineExt03.dll 2013-09-25 15:36 . 2010-10-02 12:28 790440 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-08-31 00:14 . 2013-08-31 00:14 78432 ----a-w- c:\windows\system32\atimpc64.dll 2013-08-31 00:14 . 2013-08-31 00:14 78432 ----a-w- c:\windows\system32\amdpcom64.dll 2013-08-31 00:14 . 2013-08-31 00:14 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll 2013-08-31 00:14 . 2013-08-31 00:14 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll 2013-08-31 00:14 . 2013-08-31 00:14 142792 ----a-w- c:\windows\system32\atiuxp64.dll 2013-08-31 00:14 . 2013-08-31 00:14 125824 ----a-w- c:\windows\SysWow64\atiuxpag.dll 2013-08-31 00:13 . 2013-08-31 00:13 97984 ----a-w- c:\windows\SysWow64\atiu9pag.dll 2013-08-31 00:13 . 2013-08-31 00:13 114488 ----a-w- c:\windows\system32\atiu9p64.dll 2013-08-31 00:13 . 2013-08-31 00:13 1233080 ----a-w- c:\windows\system32\aticfx64.dll 2013-08-31 00:13 . 2013-08-31 00:13 1027544 ----a-w- c:\windows\SysWow64\aticfx32.dll 2013-08-31 00:13 . 2013-08-31 00:13 9464840 ----a-w- c:\windows\system32\atidxx64.dll 2013-08-31 00:13 . 2013-08-31 00:13 8215992 ----a-w- c:\windows\SysWow64\atidxx32.dll 2013-08-31 00:13 . 2013-08-31 00:13 6176008 ----a-w- c:\windows\SysWow64\atiumdva.dll 2013-08-31 00:13 . 2013-08-31 00:13 6189416 ----a-w- c:\windows\SysWow64\atiumdag.dll 2013-08-31 00:13 . 2013-08-31 00:13 6767240 ----a-w- c:\windows\system32\atiumd6a.dll 2013-08-31 00:13 . 2013-08-31 00:13 7256496 ----a-w- c:\windows\system32\atiumd64.dll 2013-08-31 00:11 . 2013-08-31 00:11 12528640 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2013-08-30 23:48 . 2013-08-30 23:48 127488 ----a-w- c:\windows\system32\coinst_13.152.dll 2013-08-30 23:48 . 2013-08-30 23:48 229376 ----a-w- c:\windows\system32\clinfo.exe 2013-08-30 23:47 . 2013-08-30 23:47 995342 ----a-w- c:\windows\SysWow64\amdocl_as32.exe 2013-08-30 23:47 . 2013-08-30 23:47 798734 ----a-w- c:\windows\SysWow64\amdocl_ld32.exe 2013-08-30 23:47 . 2013-08-30 23:47 1187342 ----a-w- c:\windows\system32\amdocl_as64.exe 2013-08-30 23:47 . 2013-08-30 23:47 1061902 ----a-w- c:\windows\system32\amdocl_ld64.exe 2013-08-30 23:47 . 2013-08-30 23:47 98816 ----a-w- c:\windows\system32\OpenVideo64.dll 2013-08-30 23:47 . 2013-08-30 23:47 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll 2013-08-30 23:47 . 2013-08-30 23:47 86528 ----a-w- c:\windows\system32\OVDecode64.dll 2013-08-30 23:47 . 2013-08-30 23:47 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll 2013-08-30 23:47 . 2013-08-30 23:47 28192256 ----a-w- c:\windows\system32\amdocl64.dll 2013-08-30 23:45 . 2013-08-30 23:45 23760896 ----a-w- c:\windows\SysWow64\amdocl.dll 2013-08-30 23:43 . 2013-08-30 23:43 63488 ----a-w- c:\windows\system32\OpenCL.dll 2013-08-30 23:43 . 2013-08-30 23:43 57344 ----a-w- c:\windows\SysWow64\OpenCL.dll 2013-08-30 23:35 . 2013-08-30 23:35 25387520 ----a-w- c:\windows\system32\atio6axx.dll 2013-08-30 23:18 . 2013-08-30 23:18 368640 ----a-w- c:\windows\system32\atiapfxx.exe 2013-08-30 23:18 . 2013-08-30 23:18 62464 ----a-w- c:\windows\system32\aticalrt64.dll 2013-08-30 23:18 . 2013-08-30 23:18 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll 2013-08-30 23:18 . 2013-08-30 23:18 55808 ----a-w- c:\windows\system32\aticalcl64.dll 2013-08-30 23:18 . 2013-08-30 23:18 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll 2013-08-30 23:17 . 2013-08-30 23:17 15716352 ----a-w- c:\windows\system32\aticaldd64.dll 2013-08-30 23:14 . 2013-08-30 23:14 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll 2013-08-30 23:13 . 2013-08-30 23:13 21400064 ----a-w- c:\windows\SysWow64\atioglxx.dll 2013-08-30 22:59 . 2013-08-30 22:59 442368 ----a-w- c:\windows\system32\atidemgy.dll 2013-08-30 22:58 . 2013-08-30 22:58 26112 ----a-w- c:\windows\system32\atimuixx.dll 2013-08-30 22:58 . 2013-08-30 22:58 571904 ----a-w- c:\windows\system32\atieclxx.exe 2013-08-30 22:57 . 2013-08-30 22:57 239616 ----a-w- c:\windows\system32\atiesrxx.exe 2013-08-30 22:56 . 2013-08-30 22:56 190976 ----a-w- c:\windows\system32\atitmm64.dll 2013-08-30 22:33 . 2010-02-11 04:48 784384 ----a-w- c:\windows\system32\atiadlxx.dll 2013-08-30 22:33 . 2013-08-30 22:33 594944 ----a-w- c:\windows\SysWow64\atiadlxy.dll 2013-08-30 22:33 . 2013-08-30 22:33 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2013-08-30 22:32 . 2013-08-30 22:32 75264 ----a-w- c:\windows\system32\atig6pxx.dll 2013-08-30 22:32 . 2013-08-30 22:32 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll 2013-08-30 22:32 . 2013-08-30 22:32 69632 ----a-w- c:\windows\system32\atiglpxx.dll 2013-08-30 22:32 . 2013-08-30 22:32 100352 ----a-w- c:\windows\system32\atig6txx.dll 2013-08-30 22:32 . 2013-08-30 22:32 96768 ----a-w- c:\windows\SysWow64\atigktxx.dll 2013-08-30 22:32 . 2013-08-30 22:32 618496 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2013-08-30 17:58 . 2013-08-30 17:58 51200 ----a-w- c:\windows\system32\kdbsdk64.dll 2013-08-30 17:53 . 2013-08-30 17:53 38912 ----a-w- c:\windows\SysWow64\kdbsdk32.dll 2013-08-07 02:22 . 2009-10-03 12:03 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-08-02 01:48 . 2013-09-25 15:59 44032 ----a-w- c:\windows\apppatch\acwow64.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 130736 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DU Meter"="c:\program files (x86)\DU Meter\DUMeter.exe" [2013-09-27 2749984] "Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2013-05-16 3642312] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-08-30 766208] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-08-30 4858968] . c:\users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Core Temp.lnk - c:\program files\Core Temp\Core Temp.exe [2013-9-29 856016] Dropbox.lnk - c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-6-5 27370808] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "SoftwareSASGeneration"= 3 (0x3) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys;c:\windows\SYSNATIVE\DRIVERS\athurx.sys [x] R3 cpuz135;cpuz135;c:\users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x] R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x] R3 MTSBDA;Cinergy S2 BDA service;c:\windows\system32\DRIVERS\MtsBda.sys;c:\windows\SYSNATIVE\DRIVERS\MtsBda.sys [x] R3 MtsHID;Cinergy C/S2 PCI HID service;c:\windows\system32\DRIVERS\MtsHid.sys;c:\windows\SYSNATIVE\DRIVERS\MtsHid.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 DUMeterSvc;DU Meter Service;c:\program files (x86)\DU Meter\DUMeterSvc.exe;c:\program files (x86)\DU Meter\DUMeterSvc.exe [x] S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S3 ALSysIO;ALSysIO;c:\users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys;c:\users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-10-07 22:45 1185744 ----a-w- c:\program files (x86)\Google\Chrome\Application\30.0.1599.69\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-10-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-31 16:38] . 2013-10-13 c:\windows\Tasks\Feven 1.5-chromeinstaller.job - c:\program files (x86)\Feven 1.5\Feven 1.5-chromeinstaller.exe [2013-09-28 20:31] . 2013-10-13 c:\windows\Tasks\Feven 1.5-codedownloader.job - c:\program files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe [2013-09-28 20:33] . 2013-10-13 c:\windows\Tasks\Feven 1.5-enabler.job - c:\program files (x86)\Feven 1.5\Feven 1.5-enabler.exe [2013-09-28 20:33] . 2013-10-13 c:\windows\Tasks\Feven 1.5-firefoxinstaller.job - c:\program files (x86)\Feven 1.5\Feven 1.5-firefoxinstaller.exe [2013-09-28 20:32] . 2013-10-13 c:\windows\Tasks\Feven 1.5-updater.job - c:\program files (x86)\Feven 1.5\Feven 1.5-updater.exe [2013-09-28 20:33] . 2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25 17:39] . 2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-25 17:39] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-08-30 07:47 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-06-05 17:17 164016 ----a-w- c:\users\Wild-Pako\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-06-25 7883296] "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-06-25 1833504] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019 mLocal Page = c:\windows\SysWOW64\blank.htm Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 192.168.0.1 192.168.0.2 DPF: {971FC730-55F1-461F-83FD-B3BF5E1F039E} - hxxp://wg.dyndns.ws/AVC_AX_742.cab FF - ProfilePath - c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\ FF - ExtSQL: 2013-09-28 22:33; 249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com FF - ExtSQL: 2013-10-06 20:22; adblockpopups@jessehakanen.net; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\adblockpopups@jessehakanen.net.xpi FF - ExtSQL: 2013-10-07 21:30; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF - ExtSQL: 2013-10-08 19:57; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF FF - ExtSQL: 2013-10-10 19:02; {3d7eb24f-2740-49df-8937-200b1cc08f8a}; c:\users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} . . ------- Dateityp-Verknüpfung ------- . JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %* . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-Remote Control Editor - c:\program files (x86)\Common Files\TerraTec\Remote\TTTvRc.exe Wow6432Node-HKCU-Run-MobileDocuments - c:\program files (x86)\Common Files\Apple\Internet Services\ubd.exe Wow6432Node-HKCU-Run-CrossLoop - c:\users\Wild-Pako\AppData\Local\CrossLoop\CrossLoopConnect.exe Notify-SDWinLogon - SDWinLogon.dll HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-CrossLoop_is1 - c:\users\Wild-Pako\AppData\Local\CrossLoop\unins000.exe AddRemove-FMS - d:\fms\Uninstall.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DUMeterSvc] "ImagePath"="c:\program files (x86)\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3470926038-3106149513-4058150324-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{762233AF-A805-52A0-ED1A-E354D2EA0822}*] "paojgldoldphmghcbnplaikokdplmelp"=hex:6b,61,6a,6a,64,6e,62,6d,67,65,62,69,65, 68,62,61,66,6b,6a,67,6e,66,00,00 "oamjhkofbemkilijfbinnknafcgghf"=hex:6b,61,6a,6a,64,6e,62,6d,67,65,62,69,65,68, 62,61,66,6b,6a,67,6e,66,00,00 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-10-13 15:26:40 ComboFix-quarantined-files.txt 2013-10-13 13:26 . Vor Suchlauf: 5.755.215.872 Bytes frei Nach Suchlauf: 5.638.819.840 Bytes frei . - - End Of File - - 1A839589BDD099142F2E5F251F207A13 A36C5E4F47E84449FF07ED3517B43A31 |
14.10.2013, 08:06 | #9 |
/// the machine /// TB-Ausbilder | Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.10.2013, 18:23 | #10 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome Hi, hier die Logs Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.14.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 Wild-Pako :: WILD-PAKO-PC [Administrator] 14.10.2013 18:51:50 mbam-log-2013-10-14 (18-51-50).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 205967 Laufzeit: 2 Minute(n), 49 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage.A) -> Bösartig: (hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6CFE001FD08EC324&affID=120523&tt=240913_238&tsp=5019) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Wild-Pako\Downloads\cpu-z.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.007 - Bericht erstellt am 14/10/2013 um 19:03:38 # Updated 09/10/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : Wild-Pako - WILD-PAKO-PC # Gestartet von : C:\Users\Wild-Pako\Desktop\adwcleaner(1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\invalidprefs.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}] ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v24.0 (de) [ Datei : C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\prefs.js ] -\\ Google Chrome v30.0.1599.69 [ Datei : C:\Users\Wild-Pako\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage Gelöscht : icon_url Gelöscht : search_url Gelöscht : keyword Gelöscht : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [7042 octets] - [12/10/2013 19:48:07] AdwCleaner[R1].txt - [2447 octets] - [14/10/2013 19:01:56] AdwCleaner[S0].txt - [6632 octets] - [12/10/2013 19:48:51] AdwCleaner[S1].txt - [2352 octets] - [14/10/2013 19:03:38] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2412 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.4 (10.06.2013:1) OS: Windows 7 Ultimate x64 Ran by Wild-Pako on 14.10.2013 at 19:08:16,51 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3470926038-3106149513-4058150324-1001\Software\SweetIM ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [Folder] C:\Users\Wild-Pako\AppData\Roaming\mozilla\firefox\profiles\kueee1xm.default\extensions\249911bc-d1bd-4d66-8c17-df533609e6d8@c76f3de9-939e-4922-b73c-5d7a3139375d.com Emptied folder: C:\Users\Wild-Pako\AppData\Roaming\mozilla\firefox\profiles\kueee1xm.default\minidumps [31 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 14.10.2013 at 19:14:57,91 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Wild-Pako (administrator) on WILD-PAKO-PC on 14-10-2013 19:15:55 Running from D:\! - - Transfer - - ! Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeterSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Hagel Technologies Ltd.) C:\Program Files (x86)\DU Meter\DUMeter.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) K:\Program Files (x86)\Kies\Kies\Kies.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Samsung) K:\Program Files (x86)\Kies\Kies\External\FirmwareUpdate\KiesPDLR.exe () C:\Program Files\Core Temp\Core Temp.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Samsung Electronics Co., Ltd.) K:\Program Files (x86)\Kies\Kies\KiesTrayAgent.exe (Dropbox, Inc.) C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\system32\taskmgr.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7883296 2009-06-25] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-06-25] (Realtek Semiconductor Corp.) HKCU\...\Run: [DU Meter] - C:\Program Files (x86)\DU Meter\DUMeter.exe [2749984 2013-09-27] (Hagel Technologies Ltd.) HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.) HKCU\...\Run: [KiesPreload] - K:\Program Files (x86)\Kies\Kies\Kies.exe [1564528 2013-09-04] (Samsung) HKCU\...\Run: [KiesAirMessage] - K:\Program Files (x86)\Kies\Kies\KiesAirMessage.exe -startup HKCU\...\Run: [] - K:\Program Files (x86)\Kies\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [KiesTrayAgent] - K:\Program Files (x86)\Kies\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.) Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Core Temp.lnk ShortcutTarget: Core Temp.lnk -> C:\Program Files\Core Temp\Core Temp.exe () Startup: C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Wild-Pako\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x01E862F5F4B9CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1286050903776 DPF: HKLM-x32 {971FC730-55F1-461F-83FD-B3BF5E1F039E} hxxp://wg.dyndns.ws/AVC_AX_742.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\foxmarks@kei.com FF Extension: VLC Media Player - Web Plugin - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\vlcplugin@radicalsoft.com FF Extension: Flagfox - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} FF Extension: Flashblock - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} FF Extension: adblockpopups - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\adblockpopups@jessehakanen.net.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF Extension: No Name - C:\Users\Wild-Pako\AppData\Roaming\Mozilla\Firefox\Profiles\kueee1xm.default\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR DefaultSearchURL: (SearchGol) - hxxp://www.google.com CHR DefaultSuggestURL: (SearchGol) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U40) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll No File CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.400.43) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Google Docs) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (Feven 1.5) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\baodmgdpdoelldjmkhknbolcldnfjegg\1.24.28_0 CHR Extension: (YouTube) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Gmail) - C:\Users\WILD-P~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 DUMeterSvc; C:\Program Files (x86)\DU Meter\DUMeterSvc.exe [1391136 2009-09-04] (Hagel Technologies Ltd.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [x] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-25] (DT Soft Ltd) S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider) S3 gdrv; C:\Windows\gdrv.sys [25640 2013-10-03] (Windows (R) Server 2003 DDK provider) S3 MTSBDA; C:\Windows\System32\DRIVERS\MtsBda.sys [322080 2008-12-01] (TerraTec Provide) S3 MtsHID; C:\Windows\System32\DRIVERS\MtsHid.sys [27168 2008-12-01] (TerraTec Provide) S1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation) R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [221376 2009-08-15] (TrueCrypt Foundation) R3 ALSysIO; \??\C:\Users\WILD-P~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 cpuz135; \??\C:\Users\WILD-P~1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [x] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-14 19:14 - 2013-10-14 19:14 - 00001254 _____ C:\Users\Wild-Pako\Desktop\JRT.txt 2013-10-14 19:08 - 2013-10-14 19:08 - 00000000 ____D C:\Windows\ERUNT 2013-10-14 19:01 - 2013-10-14 19:01 - 01032220 _____ (Thisisu) C:\Users\Wild-Pako\Desktop\JRT.exe 2013-10-14 19:00 - 2013-10-14 19:00 - 01048960 _____ C:\Users\Wild-Pako\Desktop\adwcleaner(1).exe 2013-10-14 18:49 - 2013-10-14 18:49 - 00001073 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Malwarebytes 2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-14 18:49 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-13 17:14 - 2013-10-13 17:20 - 00000592 _____ C:\Users\Wild-Pako\ashot.log 2013-10-13 17:14 - 2013-10-13 17:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\mightypocket 2013-10-13 17:13 - 2013-10-13 17:13 - 00000000 ____D C:\Program Files (x86)\Android Screen Capture 2013-10-13 17:09 - 2013-10-13 17:09 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-10-13 17:08 - 2013-10-13 17:08 - 00000000 ____D C:\Users\Wild-Pako\.android 2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\MyPhoneExplorer 2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer 2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\Documents\samsung 2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Samsung 2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Samsung 2013-10-13 17:01 - 2013-06-21 02:07 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2013-10-13 17:01 - 2013-06-21 02:07 - 00103448 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2013-10-13 17:00 - 2013-07-18 14:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2013-10-13 17:00 - 2013-07-18 14:32 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2013-10-13 16:59 - 2013-10-13 17:01 - 00000000 ____D C:\ProgramData\Samsung 2013-10-13 16:58 - 2013-10-13 16:58 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Downloaded Installations 2013-10-13 15:26 - 2013-10-13 15:26 - 00035713 _____ C:\ComboFix.txt 2013-10-13 15:17 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-10-13 15:17 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-10-13 15:17 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-10-13 15:17 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-10-13 15:17 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-10-13 15:17 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-10-13 15:17 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-10-13 15:17 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-10-13 15:14 - 2013-10-13 15:26 - 00000000 ____D C:\Qoobox 2013-10-13 15:13 - 2013-10-13 15:25 - 00000000 ____D C:\Windows\erdnt 2013-10-13 15:13 - 2013-10-13 15:13 - 05132083 ____R (Swearware) C:\Users\Wild-Pako\Desktop\ComboFix.exe 2013-10-13 11:15 - 2013-10-13 11:15 - 00000971 _____ C:\Users\Wild-Pako\Desktop\TransMac.lnk 2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac 2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\TransMac 2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Program Files (x86)\TransMac 2013-10-13 01:16 - 2013-10-13 01:16 - 00000000 ____D C:\Program Files (x86)\XeMu360 2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST 2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable 2013-10-12 19:48 - 2013-10-14 19:03 - 00000000 ____D C:\AdwCleaner 2013-10-12 17:56 - 2013-10-12 20:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk 2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk 2013-10-09 21:53 - 2013-10-09 21:54 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR 2013-10-09 18:24 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-09 18:24 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-09 18:24 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-09 18:24 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-09 18:24 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-09 18:24 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-09 18:24 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-09 18:24 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-09 18:24 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-09 18:24 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-09 18:24 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-09 18:24 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-09 18:03 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-09 18:03 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-09 18:03 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-09 18:03 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-09 18:03 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 18:03 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 18:03 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-09 18:03 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-09 18:03 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-09 18:03 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-09 18:03 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-09 18:03 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 18:03 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-09 18:03 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-09 18:03 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-09 18:03 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-09 18:03 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-09 18:03 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-09 18:03 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-09 18:03 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-09 18:03 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-09 18:03 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit 2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk 2013-10-08 19:58 - 2013-10-14 18:57 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-08 19:58 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-08 19:58 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-08 19:58 - 2013-08-30 09:47 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-08 19:56 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-08 19:52 - 2013-10-08 19:56 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark 2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg 2013-10-07 21:38 - 2013-10-07 21:59 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-07 21:38 - 2013-10-07 21:39 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-07 21:38 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI 2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log 2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-10-07 18:52 - 2013-10-07 18:53 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt 2013-10-03 18:20 - 2013-10-03 18:26 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-10-03 15:26 - 2008-09-24 10:38 - 01048576 _____ C:\Users\Wild-Pako\ep43ds3.f9 2013-10-03 15:26 - 2008-08-28 09:16 - 00026351 _____ C:\Users\Wild-Pako\FLASHSPI.EXE 2013-10-03 13:51 - 2013-10-03 14:47 - 00037130 _____ C:\pingstat.txt 2013-10-03 13:49 - 2013-10-03 13:50 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat 2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems 2013-10-02 21:26 - 2013-10-02 21:27 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover 2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech 2013-10-02 21:06 - 2013-10-10 19:08 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core 2013-10-01 12:42 - 2013-10-07 22:10 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop 2013-09-29 14:07 - 2013-10-11 19:53 - 00000000 ____D C:\Windows\Minidump 2013-09-29 13:45 - 2013-09-29 13:48 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95 2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-09-29 11:39 - 2013-10-03 10:23 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC 2013-09-29 11:35 - 2013-10-03 10:25 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC 2013-09-28 22:33 - 2013-10-14 19:05 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job 2013-09-28 22:33 - 2013-10-14 19:05 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job 2013-09-28 22:33 - 2013-10-14 19:05 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job 2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater 2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader 2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler 2013-09-28 22:32 - 2013-10-14 19:05 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job 2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID 2013-09-28 22:31 - 2013-10-14 19:05 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job 2013-09-28 22:31 - 2013-09-28 22:33 - 00000000 ____D C:\Program Files (x86)\Feven 1.5 2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe 2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome 2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games 2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk 2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack 2013-09-28 18:04 - 2013-10-09 18:26 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk 2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client 2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-09-27 22:53 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2013-09-27 22:53 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2013-09-27 22:53 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2013-09-27 22:53 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2013-09-27 22:53 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2013-09-27 22:53 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2013-09-27 22:53 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2013-09-27 22:53 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2013-09-27 22:53 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2013-09-27 22:53 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2013-09-27 22:53 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll 2013-09-27 22:53 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2013-09-27 22:53 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll 2013-09-27 22:53 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll 2013-09-27 22:53 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2013-09-27 22:53 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2013-09-27 22:53 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll 2013-09-27 22:53 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll 2013-09-27 22:53 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2013-09-27 22:53 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2013-09-27 22:53 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll 2013-09-27 22:53 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll 2013-09-27 22:53 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2013-09-27 22:53 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll 2013-09-27 22:53 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2013-09-27 22:53 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll 2013-09-27 22:53 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll 2013-09-27 22:53 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2013-09-27 22:53 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2013-09-27 22:53 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2013-09-27 22:53 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll 2013-09-27 22:53 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2013-09-27 22:53 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll 2013-09-27 22:53 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2013-09-27 22:53 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll 2013-09-27 22:53 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2013-09-27 22:53 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2013-09-27 22:53 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll 2013-09-27 22:53 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2013-09-27 22:53 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll 2013-09-27 22:53 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2013-09-27 22:53 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2013-09-27 22:53 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll 2013-09-27 22:53 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2013-09-27 22:53 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2013-09-27 22:53 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll 2013-09-27 22:53 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2013-09-27 22:53 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll 2013-09-27 22:53 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2013-09-27 22:53 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll 2013-09-27 22:53 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2013-09-27 22:53 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2013-09-27 22:53 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll 2013-09-27 22:53 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2013-09-27 22:53 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll 2013-09-27 22:53 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll 2013-09-27 22:53 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2013-09-27 22:53 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2013-09-27 22:53 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll 2013-09-27 22:52 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2013-09-27 22:52 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll 2013-09-27 22:52 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2013-09-27 22:52 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll 2013-09-27 22:52 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2013-09-27 22:52 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll 2013-09-27 22:52 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2013-09-27 22:52 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2013-09-27 22:52 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2013-09-27 22:52 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll 2013-09-27 22:52 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll 2013-09-27 22:52 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll 2013-09-27 22:52 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2013-09-27 22:52 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2013-09-27 22:52 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2013-09-27 22:52 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll 2013-09-27 22:52 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2013-09-27 22:52 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll 2013-09-27 22:52 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2013-09-27 22:52 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll 2013-09-27 22:52 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2013-09-27 22:52 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll 2013-09-27 22:52 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2013-09-27 22:52 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll 2013-09-27 22:52 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2013-09-27 22:52 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll 2013-09-27 22:52 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2013-09-27 22:52 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll 2013-09-27 22:52 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2013-09-27 22:52 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll 2013-09-27 22:52 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2013-09-27 22:52 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll 2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk 2013-09-27 17:14 - 2013-09-27 17:18 - 00000000 ____D C:\tempvideo 2013-09-27 17:13 - 2013-09-27 23:05 - 00000044 _____ C:\DebugTraceAP.log 2013-09-27 12:43 - 2013-09-27 12:45 - 00000000 ____D C:\Program Files (x86)\DU Meter 2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies 2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk 2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-09-27 12:20 - 2013-10-14 19:06 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox 2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM 2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice 2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-09-27 08:18 - 2013-09-27 08:19 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-09-26 20:17 - 2013-10-03 04:52 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-26 07:52 - 2013-10-14 19:05 - 00009930 _____ C:\Windows\setupact.log 2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log 2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk 2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP 2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line 2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk 2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme 2013-09-25 20:29 - 2013-09-25 20:31 - 00000000 ____D C:\Windows\rescache 2013-09-25 19:58 - 2013-09-25 19:59 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part 2013-09-25 19:40 - 2013-10-14 18:53 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-25 19:40 - 2013-10-10 18:48 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-09-25 19:40 - 2013-10-10 18:48 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-09-25 19:40 - 2013-10-08 00:48 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-25 19:39 - 2013-10-14 19:05 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-25 19:39 - 2013-10-04 22:11 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk 2013-09-25 19:39 - 2013-10-04 22:11 - 00000000 ____D C:\Program Files\MPC-HC 2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google 2013-09-25 19:39 - 2013-09-25 19:40 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe 2013-09-25 19:07 - 2013-10-09 18:23 - 00000000 ____D C:\Windows\system32\MRT 2013-09-25 18:00 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-09-25 18:00 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-09-25 18:00 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-09-25 18:00 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-09-25 18:00 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-09-25 18:00 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-09-25 18:00 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-09-25 18:00 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-09-25 18:00 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-09-25 18:00 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-09-25 18:00 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-09-25 18:00 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-09-25 18:00 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-09-25 17:59 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-25 17:59 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-25 17:59 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-09-25 17:59 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-09-25 17:59 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-09-25 17:59 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-25 17:59 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-09-25 17:59 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-25 17:59 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-09-25 17:59 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-09-25 17:59 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-09-25 17:59 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-09-25 17:59 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-09-25 17:59 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-25 17:59 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-09-25 17:59 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-09-25 17:59 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-09-25 17:59 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-09-25 17:59 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-09-25 17:59 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-09-25 17:59 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-09-25 17:43 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-25 17:43 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-25 17:43 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-25 17:43 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-09-25 17:43 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-09-25 17:43 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-09-25 17:43 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-09-25 17:43 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-09-25 17:43 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-09-25 17:43 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-09-25 17:43 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-09-25 17:43 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-09-25 17:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-09-25 17:43 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-09-25 17:43 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-09-25 17:43 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-09-25 17:43 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-09-25 17:43 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-09-25 17:43 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-09-25 17:43 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-09-25 17:43 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-09-25 17:43 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-09-25 17:43 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-09-25 17:43 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-09-25 17:43 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-09-25 17:43 - 2013-03-19 07:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-09-25 17:43 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-09-25 17:43 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-09-25 17:43 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-09-25 17:43 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-09-25 17:43 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle 2013-09-25 17:38 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-09-25 17:38 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-09-25 17:37 - 2013-09-25 17:36 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-25 17:37 - 2013-09-25 17:36 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-25 17:37 - 2013-09-25 17:36 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-25 17:37 - 2013-09-25 17:36 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip 2013-09-25 17:02 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2013-09-25 17:02 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2013-09-25 17:02 - 2012-06-02 16:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-09-25 16:55 - 2013-09-25 17:02 - 00008799 _____ C:\Windows\IE10_main.log 2013-09-25 16:54 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2013-09-25 16:54 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2013-09-25 16:54 - 2012-08-23 16:07 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2013-09-25 16:54 - 2012-08-23 15:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-09-25 16:54 - 2012-08-23 15:46 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-09-25 16:54 - 2012-08-23 15:41 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2013-09-25 16:54 - 2012-08-23 15:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2013-09-25 16:54 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2013-09-25 16:54 - 2012-08-23 15:20 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2013-09-25 16:54 - 2012-08-23 15:18 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-09-25 16:54 - 2012-08-23 15:17 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2013-09-25 16:54 - 2012-08-23 15:06 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2013-09-25 16:54 - 2012-08-23 14:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-09-25 16:54 - 2012-08-23 13:20 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2013-09-25 16:54 - 2012-08-23 13:15 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-09-25 16:54 - 2012-08-23 13:14 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2013-09-25 16:54 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-09-25 16:54 - 2012-08-23 12:54 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-09-25 16:54 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2013-09-25 16:54 - 2012-08-23 12:39 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe |
14.10.2013, 18:24 | #11 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeCode:
ATTFilter 2013-09-25 16:54 - 2012-08-23 12:22 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2013-09-25 16:54 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-09-25 16:54 - 2012-08-23 10:19 - 04916224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-09-25 16:54 - 2012-08-23 10:13 - 05773824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2013-09-25 16:51 - 2012-07-26 05:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2013-09-25 16:51 - 2012-07-26 05:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2013-09-25 16:51 - 2012-07-26 04:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2013-09-25 16:51 - 2012-07-26 04:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2013-09-25 16:51 - 2012-06-02 16:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2013-09-25 16:48 - 2013-01-13 23:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 23:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-09-25 16:48 - 2013-01-13 22:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-09-25 16:48 - 2013-01-13 22:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-09-25 16:48 - 2013-01-13 22:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-09-25 16:48 - 2013-01-13 22:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-09-25 16:48 - 2013-01-13 21:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-09-25 16:48 - 2013-01-13 21:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-09-25 16:48 - 2013-01-13 21:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-09-25 16:48 - 2013-01-13 21:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-09-25 16:48 - 2013-01-13 21:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-09-25 16:48 - 2013-01-13 21:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-09-25 16:48 - 2013-01-13 21:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-09-25 16:48 - 2013-01-13 21:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-09-25 16:48 - 2013-01-13 21:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-09-25 16:48 - 2013-01-13 21:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-09-25 16:48 - 2013-01-13 21:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-09-25 16:48 - 2013-01-13 21:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-09-25 16:48 - 2013-01-13 21:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-09-25 16:48 - 2013-01-13 21:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-09-25 16:48 - 2013-01-13 21:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-09-25 16:48 - 2013-01-13 21:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-09-25 16:48 - 2013-01-13 21:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-09-25 16:48 - 2013-01-13 21:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-09-25 16:48 - 2013-01-13 20:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-09-25 16:48 - 2013-01-13 20:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-09-25 16:48 - 2013-01-13 20:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-09-25 16:48 - 2013-01-13 19:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-09-25 16:48 - 2013-01-13 19:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-09-25 16:48 - 2013-01-04 08:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-09-25 16:48 - 2013-01-04 08:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-09-25 16:46 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-09-25 16:46 - 2012-12-07 15:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2013-09-25 16:46 - 2012-12-07 15:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2013-09-25 16:46 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2013-09-25 16:46 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2013-09-25 16:46 - 2012-12-07 13:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2013-09-25 16:46 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2013-09-25 16:46 - 2012-12-07 13:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2013-09-25 16:46 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2013-09-25 16:46 - 2012-11-30 01:17 - 00420064 _____ C:\Windows\SysWOW64\locale.nls 2013-09-25 16:46 - 2012-11-30 01:15 - 00420064 _____ C:\Windows\system32\locale.nls 2013-09-25 16:46 - 2012-11-22 07:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2013-09-25 16:46 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2013-09-25 16:46 - 2012-10-09 20:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2013-09-25 16:46 - 2012-10-09 20:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2013-09-25 16:46 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2013-09-25 16:46 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2013-09-25 16:46 - 2012-10-03 19:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2013-09-25 16:46 - 2012-10-03 19:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2013-09-25 16:46 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2013-09-25 16:46 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2013-09-25 16:46 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2013-09-25 16:46 - 2012-10-03 18:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2013-09-25 16:46 - 2012-08-24 20:13 - 00154480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-09-25 16:46 - 2012-08-24 20:09 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-09-25 16:46 - 2012-08-24 20:05 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-09-25 16:46 - 2012-08-24 20:03 - 01448448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-09-25 16:46 - 2012-08-24 18:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-09-25 16:46 - 2012-08-24 18:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-09-25 16:46 - 2012-08-24 18:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-09-25 16:46 - 2012-08-22 20:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-09-25 16:46 - 2012-08-21 23:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2013-09-25 16:46 - 2012-07-04 22:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2013-09-25 16:46 - 2012-05-05 10:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2013-09-25 16:46 - 2012-05-05 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2013-09-25 16:46 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2013-09-25 16:46 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-09-25 16:46 - 2012-01-13 09:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2013-09-25 16:42 - 2012-02-11 08:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe 2013-09-25 16:42 - 2012-02-11 08:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe 2013-09-25 16:42 - 2011-05-04 07:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2013-09-25 16:42 - 2011-05-04 07:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2013-09-25 16:42 - 2011-05-04 07:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2013-09-25 16:42 - 2011-05-04 07:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2013-09-25 16:42 - 2011-05-04 07:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2013-09-25 16:42 - 2011-05-04 06:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-09-25 16:42 - 2011-05-04 06:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2013-09-25 16:42 - 2011-05-04 06:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-09-25 16:42 - 2011-05-04 06:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-09-25 16:42 - 2011-05-04 06:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-09-25 16:39 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2013-09-25 16:39 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe 2013-09-24 19:15 - 2013-09-25 16:39 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-09-24 19:14 - 2013-09-25 17:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp 2013-09-24 19:14 - 2013-09-25 16:39 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-09-24 19:14 - 2011-03-04 21:44 - 02095600 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxsfs.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00698864 ____N (Sonic Solutions) C:\Windows\SysWOW64\px.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00571888 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxdrv.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00440816 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxwave.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00219632 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxmas.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00133616 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxafs.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00100848 ____N (Sonic Solutions) C:\Windows\SysWOW64\vxblock.dll 2013-09-24 19:14 - 2011-03-04 21:44 - 00072176 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxhpinst.exe 2013-09-24 19:14 - 2011-03-04 21:44 - 00068592 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxinsa64.exe 2013-09-24 19:14 - 2011-03-04 21:44 - 00068080 ____N (Sonic Solutions) C:\Windows\SysWOW64\pxcpya64.exe 2013-09-22 18:16 - 2013-09-27 08:11 - 00000000 ____D C:\Windows\system32\appmgmt 2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D} 2013-09-20 19:52 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2013-09-20 19:52 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-20 19:49 - 2013-09-20 19:54 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk 2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI 2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-09-18 19:38 - 2013-10-07 18:57 - 00000000 ____D C:\Program Files\ATI Technologies 2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI ==================== One Month Modified Files and Folders ======= 2013-10-14 19:14 - 2013-10-14 19:14 - 00001254 _____ C:\Users\Wild-Pako\Desktop\JRT.txt 2013-10-14 19:10 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-14 19:10 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-14 19:08 - 2013-10-14 19:08 - 00000000 ____D C:\Windows\ERUNT 2013-10-14 19:06 - 2013-09-27 12:20 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Dropbox 2013-10-14 19:05 - 2013-09-28 22:33 - 00001286 _____ C:\Windows\Tasks\Feven 1.5-updater.job 2013-10-14 19:05 - 2013-09-28 22:33 - 00001190 _____ C:\Windows\Tasks\Feven 1.5-codedownloader.job 2013-10-14 19:05 - 2013-09-28 22:33 - 00001090 _____ C:\Windows\Tasks\Feven 1.5-enabler.job 2013-10-14 19:05 - 2013-09-28 22:32 - 00001818 _____ C:\Windows\Tasks\Feven 1.5-firefoxinstaller.job 2013-10-14 19:05 - 2013-09-28 22:31 - 00001894 _____ C:\Windows\Tasks\Feven 1.5-chromeinstaller.job 2013-10-14 19:05 - 2013-09-26 07:52 - 00009930 _____ C:\Windows\setupact.log 2013-10-14 19:05 - 2013-09-25 19:39 - 00001112 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-14 19:05 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-14 19:04 - 2009-08-13 17:15 - 01333441 _____ C:\Windows\WindowsUpdate.log 2013-10-14 19:03 - 2013-10-12 19:48 - 00000000 ____D C:\AdwCleaner 2013-10-14 19:01 - 2013-10-14 19:01 - 01032220 _____ (Thisisu) C:\Users\Wild-Pako\Desktop\JRT.exe 2013-10-14 19:00 - 2013-10-14 19:00 - 01048960 _____ C:\Users\Wild-Pako\Desktop\adwcleaner(1).exe 2013-10-14 18:57 - 2013-10-08 19:58 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-14 18:56 - 2009-08-13 22:36 - 00196706 _____ C:\Windows\PFRO.log 2013-10-14 18:53 - 2013-09-25 19:40 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-14 18:49 - 2013-10-14 18:49 - 00001073 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Malwarebytes 2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-14 18:49 - 2013-10-14 18:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-14 10:38 - 2012-07-31 20:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-13 17:20 - 2013-10-13 17:14 - 00000592 _____ C:\Users\Wild-Pako\ashot.log 2013-10-13 17:14 - 2013-10-13 17:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\mightypocket 2013-10-13 17:14 - 2009-08-13 17:20 - 00000000 ____D C:\Users\Wild-Pako 2013-10-13 17:13 - 2013-10-13 17:13 - 00000000 ____D C:\Program Files (x86)\Android Screen Capture 2013-10-13 17:09 - 2013-10-13 17:09 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-10-13 17:08 - 2013-10-13 17:08 - 00000000 ____D C:\Users\Wild-Pako\.android 2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\MyPhoneExplorer 2013-10-13 17:07 - 2013-10-13 17:07 - 00000000 ____D C:\Program Files (x86)\MyPhoneExplorer 2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-10-13 17:02 - 2013-10-13 17:02 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\Documents\samsung 2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Samsung 2013-10-13 17:01 - 2013-10-13 17:01 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Samsung 2013-10-13 17:01 - 2013-10-13 16:59 - 00000000 ____D C:\ProgramData\Samsung 2013-10-13 17:00 - 2009-08-13 17:34 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-13 16:58 - 2013-10-13 16:58 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Downloaded Installations 2013-10-13 16:58 - 2009-07-26 14:25 - 00699416 _____ C:\Windows\system32\perfh007.dat 2013-10-13 16:58 - 2009-07-26 14:25 - 00149556 _____ C:\Windows\system32\perfc007.dat 2013-10-13 16:58 - 2009-07-14 07:13 - 01620612 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-13 15:26 - 2013-10-13 15:26 - 00035713 _____ C:\ComboFix.txt 2013-10-13 15:26 - 2013-10-13 15:14 - 00000000 ____D C:\Qoobox 2013-10-13 15:26 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-10-13 15:25 - 2013-10-13 15:13 - 00000000 ____D C:\Windows\erdnt 2013-10-13 15:24 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-10-13 15:13 - 2013-10-13 15:13 - 05132083 ____R (Swearware) C:\Users\Wild-Pako\Desktop\ComboFix.exe 2013-10-13 11:15 - 2013-10-13 11:15 - 00000971 _____ C:\Users\Wild-Pako\Desktop\TransMac.lnk 2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TransMac 2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\TransMac 2013-10-13 11:15 - 2013-10-13 11:15 - 00000000 ____D C:\Program Files (x86)\TransMac 2013-10-13 11:02 - 2012-07-25 18:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-13 01:16 - 2013-10-13 01:16 - 00000000 ____D C:\Program Files (x86)\XeMu360 2013-10-12 20:24 - 2013-10-12 17:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-10-12 20:10 - 2013-10-12 20:10 - 00000000 ____D C:\FRST 2013-10-12 20:09 - 2013-10-12 20:09 - 00000168 _____ C:\Users\Wild-Pako\defogger_reenable 2013-10-12 17:16 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Thunderbird 2013-10-12 17:08 - 2013-10-12 17:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\SCE 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\Desktop\PlanetSide 2 PSG.lnk 2013-10-12 17:07 - 2013-10-12 17:07 - 00000810 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2 PSG.lnk 2013-10-11 19:53 - 2013-09-29 14:07 - 00000000 ____D C:\Windows\Minidump 2013-10-10 19:08 - 2013-10-02 21:06 - 00000000 ____D C:\Users\Wild-Pako\Documents\Criterion Games 2013-10-10 19:02 - 2013-10-10 19:02 - 00001084 _____ C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk 2013-10-10 18:48 - 2013-09-25 19:40 - 00004112 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-10 18:48 - 2013-09-25 19:40 - 00003860 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-10 18:45 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-09 21:54 - 2013-10-09 21:53 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFSTR 2013-10-09 18:38 - 2012-07-31 20:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 18:38 - 2012-07-31 20:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 18:38 - 2012-07-31 20:20 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-09 18:31 - 2009-07-14 06:45 - 00295824 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-09 18:26 - 2013-09-28 18:04 - 01593956 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-09 18:23 - 2013-09-25 19:07 - 00000000 ____D C:\Windows\system32\MRT 2013-10-09 18:22 - 2010-10-02 14:30 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-08 21:32 - 2013-10-08 21:32 - 00001374 _____ C:\Users\Wild-Pako\Desktop\farcry3.lnk 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\Users\Wild-Pako\Documents\My Games 2013-10-08 21:32 - 2013-10-08 21:32 - 00000000 ____D C:\ProgramData\Orbit 2013-10-08 21:20 - 2012-11-04 16:24 - 00328221 _____ C:\Windows\DirectX.log 2013-10-08 20:39 - 2013-10-08 20:39 - 00001513 _____ C:\Users\Wild-Pako\Desktop\Need For Speed The Run.lnk 2013-10-08 19:58 - 2013-10-08 19:58 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-08 19:58 - 2009-08-13 20:26 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-08 19:56 - 2013-10-08 19:56 - 00000000 ____D C:\Program Files\AVAST Software 2013-10-08 19:56 - 2013-10-08 19:52 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-08 19:08 - 2013-10-08 19:08 - 00000000 ____D C:\ProgramData\Futuremark 2013-10-08 19:07 - 2013-10-08 19:07 - 00000924 _____ C:\Users\Public\Desktop\3DMark Vantage.lnk 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-08 19:06 - 2013-10-08 19:06 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-08 00:48 - 2013-09-25 19:40 - 00002143 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-07 22:10 - 2013-10-01 12:42 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\CrossLoop 2013-10-07 21:59 - 2013-10-07 21:38 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-07 21:57 - 2013-10-07 21:57 - 00007601 _____ C:\Users\Wild-Pako\AppData\Local\Resmon.ResmonCfg 2013-10-07 21:39 - 2013-10-07 21:38 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-07 21:38 - 2013-10-07 21:38 - 00001343 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-07 21:38 - 2013-10-07 21:38 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2013-10-07 19:10 - 2013-10-07 19:10 - 00000000 ____D C:\ProgramData\ATI 2013-10-07 18:58 - 2013-10-07 18:58 - 00055617 _____ C:\Windows\SysWOW64\CCCInstall_201310071858030463.log 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\ProgramData\AMD 2013-10-07 18:58 - 2013-10-07 18:58 - 00000000 ____D C:\Program Files (x86)\AMD AVT 2013-10-07 18:57 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI Technologies 2013-10-07 18:56 - 2013-10-07 18:56 - 00018620 _____ C:\Windows\SysWOW64\CCCInstall_201310071856358562.log 2013-10-07 18:55 - 2013-10-07 18:55 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2013-10-07 18:53 - 2013-10-07 18:52 - 00000000 ____D C:\ProgramData\Package Cache 2013-10-06 23:20 - 2013-10-06 23:20 - 00000045 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.txt 2013-10-05 17:01 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\vlc 2013-10-04 22:11 - 2013-09-25 19:39 - 00001702 _____ C:\Users\Wild-Pako\Desktop\MPC-HC x64.lnk 2013-10-04 22:11 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files\MPC-HC 2013-10-03 18:26 - 2013-10-03 18:20 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2013-10-03 14:47 - 2013-10-03 13:51 - 00037130 _____ C:\pingstat.txt 2013-10-03 13:50 - 2013-10-03 13:49 - 00000332 _____ C:\Users\Wild-Pako\Desktop\Neues Textdokument.bat 2013-10-03 10:26 - 2013-10-03 10:26 - 00001160 _____ C:\Users\Wild-Pako\Desktop\launcher - Verknüpfung.lnk 2013-10-03 10:25 - 2013-09-29 11:35 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhoenixRC 2013-10-03 10:23 - 2013-09-29 11:39 - 00000000 ____D C:\Users\Wild-Pako\Documents\PhoenixRC 2013-10-03 04:52 - 2013-09-26 20:17 - 00001050 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Sinvise Systems 2013-10-02 23:03 - 2013-10-02 23:03 - 00000000 ____D C:\Program Files (x86)\Sinvise Systems 2013-10-02 21:27 - 2013-10-02 21:26 - 00000000 ____D C:\Users\Wild-Pako\Documents\NFS Undercover 2013-10-02 21:24 - 2013-10-02 21:24 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Leadertech 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\Electronic Arts 2013-10-02 21:06 - 2013-10-02 21:06 - 00000000 ____D C:\ProgramData\EA Core 2013-10-02 19:29 - 2009-08-14 12:09 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\dvdcss 2013-09-29 13:48 - 2013-09-29 13:45 - 00000000 ____D C:\Users\Wild-Pako\Desktop\Prime95 2013-09-29 13:43 - 2013-09-29 13:43 - 00000948 _____ C:\Users\Wild-Pako\Desktop\Core Temp.lnk 2013-09-29 12:29 - 2012-11-07 23:30 - 00000647 _____ C:\Users\Public\Desktop\HELI-X4.lnk 2013-09-29 11:43 - 2013-09-29 11:43 - 00000000 ____D C:\Windows\SysWOW64\directx 2013-09-28 22:33 - 2013-09-28 22:33 - 00004316 _____ C:\Windows\System32\Tasks\Feven 1.5-updater 2013-09-28 22:33 - 2013-09-28 22:33 - 00004220 _____ C:\Windows\System32\Tasks\Feven 1.5-codedownloader 2013-09-28 22:33 - 2013-09-28 22:33 - 00004120 _____ C:\Windows\System32\Tasks\Feven 1.5-enabler 2013-09-28 22:33 - 2013-09-28 22:31 - 00000000 ____D C:\Program Files (x86)\Feven 1.5 2013-09-28 22:32 - 2013-09-28 22:32 - 00000869 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2013-09-28 22:32 - 2013-09-28 22:32 - 00000000 ____D C:\Program Files\CPUID 2013-09-28 22:12 - 2013-09-28 22:12 - 00000000 ____D C:\Program Files\Defraggler 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim.exe 2013-09-28 22:11 - 2013-09-28 22:11 - 03084304 _____ (Piriform Ltd) C:\Users\Wild-Pako\Downloads\dfsetup215742_slim (1).exe 2013-09-28 22:07 - 2013-09-28 22:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\avgchrome 2013-09-28 22:03 - 2010-04-09 20:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-09-28 22:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\Help 2013-09-28 21:41 - 2013-09-28 21:41 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\2K Games 2013-09-28 21:39 - 2013-09-28 21:39 - 00000902 _____ C:\Users\Wild-Pako\Desktop\SteamLess Mafia II.lnk 2013-09-28 21:39 - 2013-09-28 21:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steamless Mafia II Pack 2013-09-28 20:02 - 2010-08-07 22:58 - 00043520 _____ C:\Windows\SysWOW64\CmdLineExt03.dll 2013-09-28 13:59 - 2012-11-10 19:12 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\FileZilla 2013-09-28 13:51 - 2013-09-28 13:51 - 00001964 _____ C:\Users\Public\Desktop\FileZilla Client.lnk 2013-09-28 13:51 - 2013-09-28 13:51 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client 2013-09-27 23:09 - 2013-09-27 23:09 - 00000000 ____D C:\Users\Wild-Pako\Documents\Rockstar Games 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 __SHD C:\ProgramData\SecuROM 2013-09-27 23:05 - 2013-09-27 23:05 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Rockstar Games 2013-09-27 23:05 - 2013-09-27 17:13 - 00000044 _____ C:\DebugTraceAP.log 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-09-27 22:54 - 2013-09-27 22:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-09-27 22:54 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-09-27 22:51 - 2013-09-27 22:51 - 00001045 _____ C:\Users\Public\Desktop\Grand Theft Auto IV Complete Edition.lnk 2013-09-27 17:18 - 2013-09-27 17:14 - 00000000 ____D C:\tempvideo 2013-09-27 12:45 - 2013-09-27 12:43 - 00000000 ____D C:\Program Files (x86)\DU Meter 2013-09-27 12:43 - 2013-09-27 12:43 - 00000000 ____D C:\ProgramData\Hagel Technologies 2013-09-27 12:23 - 2013-09-27 12:23 - 00001047 _____ C:\Users\Wild-Pako\Desktop\Dropbox.lnk 2013-09-27 12:21 - 2013-09-27 12:21 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-09-27 11:48 - 2013-09-27 11:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miranda IM 2013-09-27 11:48 - 2009-08-13 18:07 - 00000990 _____ C:\Users\Wild-Pako\Desktop\Miranda IM.lnk 2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Miranda 2013-09-27 11:48 - 2009-08-13 18:07 - 00000000 ____D C:\Program Files (x86)\Miranda IM 2013-09-27 09:04 - 2009-08-13 22:16 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Thunderbird 2013-09-27 09:04 - 2009-08-13 18:06 - 00002050 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2013-09-27 08:51 - 2009-08-13 17:52 - 00064024 _____ C:\Users\Wild-Pako\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-27 08:22 - 2013-09-27 08:22 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\OpenOffice 2013-09-27 08:19 - 2013-09-27 08:19 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk 2013-09-27 08:19 - 2013-09-27 08:18 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-09-27 08:14 - 2009-08-13 17:58 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2013-09-27 08:11 - 2013-09-22 18:16 - 00000000 ____D C:\Windows\system32\appmgmt 2013-09-26 20:17 - 2013-09-26 20:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-09-26 15:00 - 2013-09-26 15:00 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-09-26 07:52 - 2013-09-26 07:52 - 00000000 _____ C:\Windows\setuperr.log 2013-09-25 22:15 - 2013-09-25 22:15 - 00000783 _____ C:\Users\Wild-Pako\Desktop\! - - Transfer - - !.lnk 2013-09-25 21:57 - 2013-09-25 21:57 - 00000000 ____D C:\ProgramData\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00001913 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Canneverbe Limited 2013-09-25 21:56 - 2013-09-25 21:56 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP 2013-09-25 21:51 - 2013-09-25 21:51 - 00001501 _____ C:\Users\Wild-Pako\Desktop\Load.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00001282 _____ C:\Users\Public\Desktop\EL3K My ELAS Remote Programmer.lnk 2013-09-25 21:34 - 2013-09-25 21:34 - 00000000 ____D C:\Program Files (x86)\Electronics Line 2013-09-25 20:41 - 2013-09-25 20:41 - 00002050 _____ C:\Users\Wild-Pako\Desktop\JDownloader.lnk 2013-09-25 20:41 - 2009-08-13 18:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-25 20:40 - 2013-09-25 20:40 - 00000000 ____D C:\Users\Wild-Pako\Programme 2013-09-25 20:31 - 2013-09-25 20:29 - 00000000 ____D C:\Windows\rescache 2013-09-25 19:59 - 2013-09-25 19:58 - 175636928 _____ C:\Users\Wild-Pako\Downloads\130254498000.rar.part 2013-09-25 19:59 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Mozilla 2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Google 2013-09-25 19:40 - 2013-09-25 19:39 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-25 19:39 - 2013-09-25 19:39 - 00784872 _____ (Google Inc.) C:\Users\Wild-Pako\Downloads\ChromeSetup.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 07990240 _____ (MPC-HC Team ) C:\Users\Wild-Pako\Downloads\MPC-HC.1.6.8.x64.exe 2013-09-25 19:38 - 2013-09-25 19:38 - 00001030 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-09-25 19:37 - 2013-09-25 19:37 - 23003252 _____ C:\Users\Wild-Pako\Downloads\vlc-2.0.8-win32.exe 2013-09-25 19:33 - 2009-08-13 17:20 - 00000000 ___RD C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-09-25 19:13 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-09-25 17:49 - 2009-07-14 09:46 - 00000000 ____D C:\Program Files\Windows Journal 2013-09-25 17:38 - 2013-09-25 17:38 - 00000000 ____D C:\ProgramData\Oracle 2013-09-25 17:36 - 2013-09-25 17:37 - 00868264 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-09-25 17:36 - 2013-09-25 17:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-09-25 17:36 - 2013-09-25 17:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-09-25 17:36 - 2013-09-25 17:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-09-25 17:36 - 2010-10-02 14:28 - 00790440 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-09-25 17:36 - 2009-09-11 18:41 - 00000000 ____D C:\Program Files (x86)\Java 2013-09-25 17:28 - 2009-08-13 17:21 - 00001413 _____ C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-09-25 17:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-25 17:22 - 2013-09-24 19:14 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Winamp 2013-09-25 17:20 - 2013-09-25 17:20 - 02564703 _____ C:\Users\Wild-Pako\Downloads\CMI8738_WDM_0639XP.zip 2013-09-25 17:02 - 2013-09-25 16:55 - 00008799 _____ C:\Windows\IE10_main.log 2013-09-25 16:56 - 2013-09-25 16:56 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-09-25 16:56 - 2013-09-25 16:56 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-09-25 16:56 - 2013-09-25 16:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-09-25 16:56 - 2013-09-25 16:56 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-09-25 16:56 - 2013-09-25 16:56 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-09-25 16:56 - 2013-09-25 16:56 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-09-25 16:39 - 2013-09-24 19:15 - 00000943 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-09-25 16:39 - 2013-09-24 19:14 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-09-25 16:38 - 2013-09-25 16:38 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-09-25 16:37 - 2013-09-25 16:37 - 13385888 _____ (Nullsoft, Inc.) C:\Users\Wild-Pako\Downloads\winamp565_full_emusic-7plus_de-de.exe 2013-09-25 15:36 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-25 15:33 - 2009-08-13 18:04 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\Adobe 2013-09-25 15:28 - 2009-08-13 18:06 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-23 01:28 - 2013-10-09 18:24 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-09 18:24 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-09 18:24 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-09 18:24 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-09 18:24 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-09 18:24 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-09 18:24 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-09 18:24 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-22 18:27 - 2009-09-18 16:00 - 00000000 ____D C:\Program Files (x86)\Zylom Games 2013-09-22 18:25 - 2009-08-13 21:00 - 00000000 ____D C:\Program Files (x86)\Vuze 2013-09-22 18:25 - 2009-08-13 18:11 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Mozilla 2013-09-22 18:24 - 2009-08-13 17:46 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\TerraTec 2013-09-22 18:21 - 2013-04-02 19:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-09-22 18:21 - 2009-08-13 18:02 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Apple Computer 2013-09-22 18:21 - 2009-08-13 18:00 - 00000000 ____D C:\ProgramData\Apple Computer 2013-09-22 18:16 - 2012-07-25 19:08 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ArcSoft 2013-09-22 18:11 - 2013-09-22 18:11 - 00003196 _____ C:\Windows\System32\Tasks\{758CECE7-FCF0-43F8-9FAD-6E45BC86DE8D} 2013-09-22 17:53 - 2010-07-08 16:48 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-09-21 17:09 - 2009-10-07 17:59 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\HCM Updater 2013-09-21 05:38 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-09 18:24 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-09 18:24 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-09 18:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-20 19:54 - 2013-09-20 19:49 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2013-09-20 19:54 - 2013-09-20 19:49 - 00000628 _____ C:\Users\Public\Desktop\3DMark06.lnk 2013-09-20 19:49 - 2013-09-20 19:49 - 00000000 ____D C:\Program Files (x86)\OpenAL 2013-09-20 19:47 - 2013-09-20 19:47 - 00000000 ____D C:\Program Files (x86)\Futuremark 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Roaming\ATI 2013-09-20 19:44 - 2013-09-20 19:44 - 00000000 ____D C:\Users\Wild-Pako\AppData\Local\ATI 2013-09-20 19:43 - 2013-09-20 19:43 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2013-09-18 19:40 - 2013-09-18 19:40 - 00000000 _____ C:\Windows\ativpsrm.bin 2013-09-18 19:39 - 2013-09-18 19:39 - 00000000 ____D C:\Program Files (x86)\AMD APP 2013-09-18 19:38 - 2013-09-18 19:38 - 00000000 ____D C:\Program Files\ATI Files to move or delete: ==================== C:\Users\Wild-Pako\FLASHSPI.EXE Some content of TEMP: ==================== C:\Users\Wild-Pako\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-11 17:44 ==================== End Of Log ============================ |
15.10.2013, 09:07 | #12 |
/// the machine /// TB-Ausbilder | Windows 7 - Flashwerbung u. Popups in Firefox sowie google ChromeESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.10.2013, 21:46 | #13 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome Hi, vielen Dank soweit erstmal! Sieht schonmal gut aus, die meiste Werbung ist weg. Hier nochmal das Log von dem Online Scanner Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=34772e53e3191d488a35bb11f66580d2 # engine=15494 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-15 05:06:25 # local_time=2013-10-15 07:06:25 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 91 601701 158566657 0 0 # compatibility_mode=5893 16776573 100 94 38953 133486635 0 0 # scanned=96116 # found=1 # cleaned=0 # scan_time=2509 sh=9445111288F9D7822DB7E8748E0F1A1BA72A6221 ft=1 fh=1cf8df54d51c6459 vn="MSIL/Hoax.Agent.NAE application" ac=I fn="C:\Program Files (x86)\XeMu360\XeMu360.exe" # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=34772e53e3191d488a35bb11f66580d2 # engine=15494 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-10-15 08:37:47 # local_time=2013-10-15 10:37:47 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 91 614383 158579339 0 0 # compatibility_mode=5893 16776573 100 94 51635 133499317 0 0 # scanned=200721 # found=0 # cleaned=0 # scan_time=12112 Sind noch weitere Aktionen notwendig ? Gruß, Michael |
16.10.2013, 10:45 | #14 |
/// the machine /// TB-Ausbilder | Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.10.2013, 18:56 | #15 |
| Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome Hi, so alles erledigt! Vielen vielen Dank für deine Super Hilfe! Ich hoffe nicht das ich sobald wieder Hilfe brauchen werde, aber wenn doch darf ich mich ja wieder melden oder ? Viel Grüße, Michael |
Themen zu Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome |
adblock, andere, bedingt, chrome, dateien, firefox, google, installiert, massenhaft, plugins, popups, pup.optional.bundleinstaller.a, pup.optional.startpage.a, schonmal, umleitung, webseite, webseiten, windows, windows 7 |