|
Plagegeister aller Art und deren Bekämpfung: hab ich was oder nicht?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.10.2013, 06:26 | #1 |
| hab ich was oder nicht? ich weiß nicht ob ich was hab oder nicht. am besten von vorne erzählen. wollte meine filme auf tablet kucken und bekam den tip dvdx runterzuladen was ich dann getan habe oder besser gesagt zu tun glaubte. da alles in englisch konnte ich nicht erkennen ob ein zusatzprogramm dabei ist. bekommen hab ich quick share (iminent).dvdx hab ich auf meinem rechner nicht gefunden. als ich wieder internetseite neu auf machte, bekam ich von wot den roten kringel mit warnung und plötzlich war da andauernd der rote smilie zu sehen. ich hab im add-one gekuckt ob was mir fremdes zu sehen ist und entdeckte iminent und glindorus. hab ich sofort entfernen lassen. da ich meinte schnell handeln zu müssen hab ich in systemsteuerung bei den programmen iminent deinstalliert, bei regedit alles wo iminent drauf stand gelöscht und zum schluß noch mit adwcleaner "adwcleaner-download-filepony" versucht den todesstoß zu machen. war alles falsch? bin ich jetzt verseucht? ich mach ja kein online-banking und auch kein einkauf mit bankeinzugsermächtigung. bin ich damit uninteressant für wen auch immer??? hab ne kleinigkeit vergessen zu erwähnen, daß ich um das los zu werden ein anti maleware benutzt habe und während das am arbeiten war hab ich im internet auch noch lesen müssen finger weg von dem programm und hab das sofort gestoppt indem ich auf das kreuz gedrückt habe. ich muß erst noch rausfinden welches programm das war. da war ne zecke drauf. hab das programm gefunden. es war "spy hunter 4 anti spyware free download". Geändert von wolfsbrut (27.10.2013 um 05:54 Uhr) Grund: vergesslichkeit |
27.10.2013, 06:55 | #2 |
/// the machine /// TB-Ausbilder | hab ich was oder nicht? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.10.2013, 15:15 | #3 |
| hab ich was oder nicht? [CODE] FRST.txt-Editor
__________________FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2013 01 Ran by Traumhexe (administrator) on WOLFSBRUT on 27-10-2013 08:23:39 Running from D:\neu v save tv Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Informer Technologies, Inc.) C:\Program Files (x86)\Software Informer\softinfo.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-01] (Realtek Semiconductor) HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-11] (Alcor Micro Corp.) HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Software Informer] - C:\Program Files (x86)\Software Informer\softinfo.exe [2859077 2011-03-22] (Informer Technologies, Inc.) HKCU\...\Run: [fsm] - [x] MountPoints2: {adc3d838-f2f1-11e0-8db8-14dae9247551} - F:\LaunchU3.exe -a HKLM-x32\...\Run: [Nuance PDF Reader-reminder] - C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini [414 2013-10-27] () HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3567800 2013-10-26] (AVAST Software) AppInit_DLLs: C:\Windows\system32\nvinitx.dll [226920 2011-02-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [192616 2011-02-08] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files (x86)\FlashGet\Jccatch.dll (FlashGet) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files (x86)\FlashGet\getflash.dll () Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\fgiebar.dll (Amaze Soft) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default FF Homepage: hxxp://www.google.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\StartWeb.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Flashblock - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} FF Extension: WOT - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: DownloadHelper - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc@jetpack.xpi FF Extension: flashgot - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi FF Extension: No Name - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi FF Extension: Adblock Plus - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR Extension: (YouTube) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0 CHR Extension: (Google Search) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0 CHR Extension: (avast! WebRep) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0 CHR Extension: (Gmail) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0 ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-26] (AVAST Software) S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-26] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-10-26] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-26] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-27 08:23 - 2013-10-27 08:23 - 00000000 ____D C:\FRST 2013-10-27 07:43 - 2013-10-27 07:44 - 00241288 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-27 07:43 - 2013-10-27 07:43 - 00000056 _____ C:\Windows\setupact.log 2013-10-27 07:43 - 2013-10-27 07:43 - 00000000 _____ C:\Windows\setuperr.log 2013-10-26 21:31 - 2013-10-26 21:34 - 00000000 ____D C:\AdwCleaner 2013-10-26 20:21 - 2013-10-26 20:21 - 00000000 _____ C:\autoexec.bat 2013-10-26 20:20 - 2013-10-26 20:34 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-26 20:20 - 2013-10-26 20:20 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-26 19:21 - 2013-10-26 19:21 - 00000000 ____D C:\Users\Traumhexe\AppData\Roaming\AVAST Software 2013-10-26 19:16 - 2013-10-26 19:18 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-26 19:16 - 2013-10-26 19:18 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-26 19:12 - 2013-10-26 19:12 - 00000635 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-10-26 10:03 - 2013-10-26 10:03 - 00000763 _____ C:\Users\Traumhexe\Desktop\Filme f Tablet - Verknüpfung.lnk 2013-10-22 14:39 - 2013-10-22 14:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-10-22 02:16 - 2013-10-22 02:16 - 00000000 ____D C:\ProgramData\Oracle 2013-10-22 02:15 - 2013-10-22 02:15 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 02:15 - 2013-10-22 02:15 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-18 19:29 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-10-18 19:29 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-12 15:51 - 2013-10-12 15:51 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 15:34 - 2013-10-12 15:36 - 00000000 ____D C:\Windows\system32\MRT 2013-10-12 15:30 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-12 15:30 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-12 15:30 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-12 15:30 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-12 15:30 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-12 15:30 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-12 15:30 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-12 15:30 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-12 15:30 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-12 15:30 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-12 15:30 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-12 15:30 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-12 15:30 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-12 15:30 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-12 15:30 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-12 15:30 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-12 15:30 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-12 15:30 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-12 15:30 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-12 15:29 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-10-12 15:29 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-10-12 15:29 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-10-12 15:29 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-10-12 15:29 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-10-12 15:29 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-10-12 15:29 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-10-12 15:29 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-10-12 15:29 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-10-12 15:29 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-10-12 15:29 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-10-12 15:29 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-10-12 15:29 - 2013-07-09 06:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-10-12 15:29 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-10-12 15:29 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-10-12 15:29 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-10-12 15:29 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-10-12 15:29 - 2013-07-09 05:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-10-12 15:29 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-10-12 15:29 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-10-12 15:29 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-10-12 15:29 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-10-12 15:29 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-10-12 15:29 - 2013-02-27 07:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-10-12 15:29 - 2013-02-27 06:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-10-12 15:29 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-10-12 15:29 - 2013-02-27 05:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-10-12 15:29 - 2013-02-15 07:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-10-12 15:29 - 2013-02-15 07:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-10-12 15:29 - 2013-02-15 07:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-10-12 15:29 - 2013-02-15 05:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-10-12 15:29 - 2013-02-15 05:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-10-12 15:29 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-10-12 15:29 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-10-12 15:28 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-12 15:28 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-10-12 15:28 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-10-12 15:28 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-10-12 15:28 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-10-12 15:28 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-10-12 15:28 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-12 15:28 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-12 15:28 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-12 15:28 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-12 15:28 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-12 15:28 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-12 15:28 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-12 15:28 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-12 15:28 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-12 15:28 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-12 15:28 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-12 15:28 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-12 15:28 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-12 15:28 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-10-12 15:28 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-12 15:28 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-12 15:28 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-12 15:28 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-12 15:28 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-12 15:28 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-12 15:28 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-12 15:28 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-12 15:28 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-12 15:28 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-12 15:28 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-10-12 15:28 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-10-12 15:28 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-10-12 15:28 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-10-12 15:28 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-10-12 15:28 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-10-12 15:28 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-10-12 15:28 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-10-12 15:28 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-10-12 15:28 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-10-12 15:28 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-10-12 15:27 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-12 15:27 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-12 15:27 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-12 15:27 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-10-12 15:27 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-10-12 15:27 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-10-12 15:27 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-10-12 15:25 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-12 14:55 - 2013-10-12 14:55 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Macromedia 2013-10-12 14:54 - 2013-10-27 08:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-12 14:54 - 2013-10-12 14:54 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Adobe 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-09-29 05:42 - 2013-10-26 10:25 - 00000000 ____D C:\Users\Traumhexe\Desktop\für Fotoautomat bei Müller ==================== One Month Modified Files and Folders ======= 2013-10-27 08:23 - 2013-10-27 08:23 - 00000000 ____D C:\FRST 2013-10-27 08:20 - 2012-09-01 09:08 - 01922158 _____ C:\Windows\WindowsUpdate.log 2013-10-27 08:06 - 2013-10-12 14:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-27 07:51 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-27 07:51 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-27 07:48 - 2011-02-19 05:24 - 00666264 _____ C:\Windows\system32\perfh007.dat 2013-10-27 07:48 - 2011-02-19 05:24 - 00134186 _____ C:\Windows\system32\perfc007.dat 2013-10-27 07:48 - 2009-07-14 06:13 - 01531054 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-27 07:44 - 2013-10-27 07:43 - 00241288 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-27 07:44 - 2011-10-01 19:23 - 00000000 ____D C:\Users\Traumhexe\AppData\Roaming\Software Informer 2013-10-27 07:44 - 2011-10-01 16:47 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2013-10-27 07:44 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-27 07:43 - 2013-10-27 07:43 - 00000056 _____ C:\Windows\setupact.log 2013-10-27 07:43 - 2013-10-27 07:43 - 00000000 _____ C:\Windows\setuperr.log 2013-10-27 06:14 - 2011-10-02 04:57 - 00000202 _____ C:\Users\Traumhexe\AppData\Roaming\default.rss 2013-10-27 06:13 - 2012-12-15 02:53 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\SMPlayer2 2013-10-26 21:34 - 2013-10-26 21:31 - 00000000 ____D C:\AdwCleaner 2013-10-26 20:34 - 2013-10-26 20:20 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-26 20:21 - 2013-10-26 20:21 - 00000000 _____ C:\autoexec.bat 2013-10-26 20:20 - 2013-10-26 20:20 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-26 19:21 - 2013-10-26 19:21 - 00000000 ____D C:\Users\Traumhexe\AppData\Roaming\AVAST Software 2013-10-26 19:20 - 2011-07-12 10:11 - 00002408 _____ C:\Windows\system32\AutoRunFilter.ini 2013-10-26 19:20 - 2011-07-12 10:11 - 00001351 _____ C:\Windows\system32\ServiceFilter.ini 2013-10-26 19:18 - 2013-10-26 19:16 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-26 19:18 - 2013-10-26 19:16 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-26 19:18 - 2012-07-07 03:04 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-26 19:18 - 2012-04-16 09:01 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-26 19:18 - 2012-04-16 09:01 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-26 19:18 - 2012-04-16 09:01 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00001974 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-26 19:16 - 2012-04-16 09:01 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-26 19:16 - 2012-04-16 09:01 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-26 19:12 - 2013-10-26 19:12 - 00000635 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-10-26 10:26 - 2013-05-04 17:16 - 00000000 ____D C:\Users\Traumhexe\Desktop\spielerei 2013-10-26 10:25 - 2013-09-29 05:42 - 00000000 ____D C:\Users\Traumhexe\Desktop\für Fotoautomat bei Müller 2013-10-26 10:03 - 2013-10-26 10:03 - 00000763 _____ C:\Users\Traumhexe\Desktop\Filme f Tablet - Verknüpfung.lnk 2013-10-22 14:39 - 2013-10-22 14:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-10-22 02:16 - 2013-10-22 02:16 - 00000000 ____D C:\ProgramData\Oracle 2013-10-22 02:15 - 2013-10-22 02:15 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 02:15 - 2013-10-22 02:15 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-22 02:15 - 2012-10-23 14:24 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-22 02:15 - 2012-10-23 14:24 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-22 02:15 - 2012-06-22 05:00 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-20 05:29 - 2011-10-05 05:29 - 00000000 ___RD C:\Users\Traumhexe\Desktop\Mix 2013-10-19 05:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-15 18:38 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-12 18:03 - 2009-07-29 07:03 - 00000000 ____D C:\Windows\Panther 2013-10-12 16:19 - 2011-10-01 16:48 - 00000000 ___RD C:\Users\Traumhexe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-12 16:19 - 2011-10-01 16:48 - 00000000 ___RD C:\Users\Traumhexe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-12 16:18 - 2011-10-05 04:40 - 00001427 _____ C:\Users\Traumhexe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-12 16:13 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal 2013-10-12 16:13 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-10-12 16:13 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-10-12 16:07 - 2012-02-21 10:06 - 01558672 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-12 16:07 - 2012-02-21 10:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client 2013-10-12 15:52 - 2013-10-12 15:52 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-12 15:51 - 2013-10-12 15:51 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 15:36 - 2013-10-12 15:34 - 00000000 ____D C:\Windows\system32\MRT 2013-10-12 14:55 - 2013-10-12 14:55 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Macromedia 2013-10-12 14:54 - 2013-10-12 14:54 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Adobe 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-10-12 14:54 - 2012-10-14 06:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-12 14:54 - 2011-10-31 23:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-10 17:25 - 2012-09-10 05:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-10 17:25 - 2011-10-02 06:26 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Mozilla ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 04:11 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- Code:
ATTFilter Addition.txt-Editor Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2013 01 Ran by Traumhexe at 2013-10-27 08:24:21 Running from D:\neu v save tv Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== "Nero SoundTrax Help (x32 Version: 4.2.5.0) Adobe Flash Player 11 ActiveX (x32 Version: 11.4.402.287) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Shockwave Player 11.6 (x32 Version: 11.6.5.635) Adobe SVG Viewer (x32 Version: 1.0) Advertising Center (x32 Version: 0.0.0.2) Alcor Micro USB Card Reader (x32 Version: 1.8.17.26026) Aqua Bubble 2 (x32) Aqua Words (x32) ArcSoft MediaImpression 2 (x32 Version: 2.0.15.667) ArcSoft PhotoStudio 2000 (x32) Ashampoo WinOptimizer 6.60 (x32 Version: 6.6.0) ASUS AI Recovery (x32 Version: 1.0.13) ASUS FancyStart (x32 Version: 1.1.0) ASUS LifeFrame3 (x32 Version: 3.0.21) ASUS Live Update (x32 Version: 2.5.9) ASUS Power4Gear Hybrid (Version: 1.1.43) ASUS SmartLogon (x32 Version: 1.0.0011) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0031) ASUS Virtual Camera (x32 Version: 1.0.21) ASUS WebStorage (x32 Version: 3.0.84.161) AsusScr_K3 Series_ENG_Basic (x32 Version: 1.0.0001) AsusVibe2.0 (x32 Version: 2.0.6.125) ATK Package (x32 Version: 1.0.0008) avast! Free Antivirus (x32 Version: 9.0.2006) Carl's Classics (x32) CCleaner (Version: 3.11) Cisco EAP-FAST Module (x32 Version: 2.2.14) Cisco LEAP Module (x32 Version: 1.0.19) Cisco PEAP Module (x32 Version: 1.1.6) Color LaserJet 1600 (x32) Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2) Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2) CyberLink LabelPrint (x32 Version: 2.5.1908) CyberLink Power2Go (x32 Version: 6.1.3602c) D3DX10 (x32 Version: 15.4.2368.0902) DolbyFiles (x32 Version: 2.0) ETDWare PS/2-X64 8.0.5.0_WHQL (Version: 8.0.5.0) Fast Boot (Version: 1.0.8) FlashGet(JetCar) (x32) Flip Words (x32) Free Download Manager 3.9.2 (x32) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922) Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922) Galerie de photos Windows Live (x32 Version: 15.4.3502.0922) ImagXpress (x32 Version: 7.0.74.0) Iminent (x32 Version: 6.42.32.0) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 7.0.0.1118) Intel(R) Processor Graphics (x32 Version: 8.15.10.2291) Intel(R) Turbo Boost Technology Monitor 2.0 (Version: 2.1.23.0) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) Java(TM) 6 Update 37 (x32 Version: 6.0.370) Junk Mail filter update (x32 Version: 15.4.3502.0922) McAfee Security Scan Plus (x32 Version: 3.0.285.6) Media Player Utilities 4.35 (x32 Version: 4.35) Menu Templates - Starter Kit (x32 Version: 9.6.0.0) Mesh Runtime (x32 Version: 15.4.5722.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Movie Templates - Starter Kit (x32 Version: 9.6.0.0) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) Nero 9 (x32) Nero Burning ROM Help (x32 Version: 9.2.5.100) Nero BurnRights (x32 Version: 2.99.6.100) Nero BurnRights (x32 Version: 3.4.13.100) Nero ControlCenter (x32 Version: 9.0.0.1) Nero CoverDesigner (x32 Version: 1.0.0.0) Nero CoverDesigner Help (x32 Version: 4.2.4.100) Nero Disc Copy Gadget (x32 Version: 2.4.43.0) Nero Disc Copy Gadget Help (x32 Version: 2.2.7.0) Nero DiscSpeed (x32 Version: 4.99.5.105) Nero DiscSpeed (x32 Version: 5.4.13.100) Nero DriveSpeed (x32 Version: 3.99.5.105) Nero DriveSpeed (x32 Version: 4.4.12.100) Nero Express Help (x32 Version: 9.2.6.100) Nero InfoTool (x32 Version: 5.99.5.105) Nero InfoTool (x32 Version: 6.4.12.100) Nero Installer (x32 Version: 4.4.9.0) Nero Live (x32 Version: 1.2.4.0) Nero Live Help (x32 Version: 1.2.4.0) Nero PhotoSnap (x32 Version: 2.4.29.0) Nero PhotoSnap Help (x32 Version: 1.53.2.0) Nero Recode (x32 Version: 4.4.40.0) Nero Recode Help (x32 Version: 3.53.0.0) Nero Rescue Agent (x32 Version: 2.4.14.100) Nero RescueAgent Help (x32 Version: 1.99.0.1) Nero ShowTime (x32 Version: 4.99.0.0) Nero ShowTime (x32 Version: 5.4.27.100) Nero StartSmart (x32 Version: 9.4.40.100) Nero StartSmart Help (x32 Version: 9.2.7.100) Nero Vision (x32 Version: 6.2.5.100) Nero Vision (x32 Version: 6.4.19.100) Nero WaveEditor (x32 Version: 5.4.39.0) Nero WaveEditor Help (x32 Version: 5.2.5.0) NeroBurningROM (x32 Version: 1.0.0.0) NeroExpress (x32 Version: 1.0.0.0) NeroLiveGadget (x32 Version: 1.0.8.100) NeroLiveGadget Help (x32 Version: 1.0.4.100) neroxml (x32 Version: 1.0.0) Nuance PDF Reader (x32 Version: 6.00.0041) NVIDIA Control Panel 266.86 (Version: 266.86) NVIDIA Graphics Driver 266.86 (Version: 266.86) NVIDIA Install Application (Version: 2.265.39.0) NVIDIA Optimus 1.0.18 (Version: 1.0.18) NVIDIA Update Components (Version: 1.0.18) OpenOffice.org 3.3 (x32 Version: 3.3.9567) PDFCreator (x32 Version: 1.4.1) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922) Ralink RT2860 Wireless LAN Card (x32 Version: 1.5.9.0) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6324) Software Informer 1.1 (x32) SoundTrax (x32 Version: 4.4.39.0) Supermarket Management (x32 Version: 1.1.6) swMSM (x32 Version: 12.0.0.1) syncables desktop SE (x32 Version: 5.5.746.11492) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3508.1109) Windows Live Family Safety (Version: 15.4.3502.0922) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3508.1109) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Live 影像中心 (x32 Version: 15.4.3502.0922) Windows Live 程式集 (x32 Version: 15.4.3502.0922) WinFlash (x32 Version: 2.31.1) Wireless Console 3 (x32 Version: 3.0.19) XMedia Recode 3.0.3.4 (x32 Version: 3.0.3.4) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922) Основные компоненты Windows Live (x32 Version: 15.4.3502.0922) Почта Windows Live (x32 Version: 15.4.3502.0922) Фотоальбом Windows Live (x32 Version: 15.4.3502.0922) Элемент управления Windows Live Mesh ActiveX для удаленных подключений (x32 Version: 15.4.5722.2) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922) פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (x32 Version: 15.4.5722.2) بريد Windows Live (x32 Version: 15.4.3502.0922) عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (x32 Version: 15.4.5722.2) معرض صور Windows Live (x32 Version: 15.4.3502.0922) 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (x32 Version: 15.4.5722.2) ==================== Restore Points ========================= 26-09-2013 15:25:44 Geplanter Prüfpunkt 05-10-2013 06:14:33 Geplanter Prüfpunkt 12-10-2013 14:30:27 Windows Update 12-10-2013 17:04:02 Windows Update 18-10-2013 18:29:45 Windows Update 18-10-2013 18:37:43 Windows Update 22-10-2013 01:14:17 Installed Java 7 Update 45 22-10-2013 12:23:20 Windows Update 26-10-2013 18:16:44 avast! antivirus system restore point 26-10-2013 18:47:52 Windows Update 26-10-2013 19:20:24 Installed SpyHunter 26-10-2013 19:32:01 Removed SpyHunter 26-10-2013 19:33:45 Removed SpyHunter ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0E0734B5-EC46-46AF-A1F5-3E83C135C7DA} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: {17D0CB3E-919B-4606-AFA8-C9D3B1DD301E} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS) Task: {1E03D6A9-90F4-4F11-A9B4-A184FA7058B8} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {2707CBDE-1A7A-4A80-8A2A-E45E38F9C44C} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-10-26] (AVAST Software) Task: {3D4370BA-01FD-4582-B93A-608150BE6BA5} - \Plus-HD-1.6-chromeinstaller No Task File Task: {4224FC42-2B90-4433-B332-42FEDE548FE5} - \Plus-HD-1.6-firefoxinstaller No Task File Task: {57377C6D-D27A-47E9-9F90-7CE71A12E5DB} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS) Task: {5C770FB1-0120-4356-9145-83BEBD7EF224} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {69CBC151-FA0D-44AB-A2B8-31795B00D30A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-12] (Adobe Systems Incorporated) Task: {80851545-D6EA-49E3-A48D-4AF8DE65C092} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {893910F9-DEFA-41C5-964F-46EA42360B6B} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {8E6EF5CD-33D2-402B-B954-29CC9134A5D4} - \Plus-HD-1.6-enabler No Task File Task: {9A9F582D-309A-435A-9660-D3602D527804} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {D2F2E2F2-1997-476D-9E50-0F5D31F0BB0A} - \Plus-HD-1.6-codedownloader No Task File Task: {D6989F3B-BDE3-4C24-80FC-05C47BD35223} - \Plus-HD-1.6-updater No Task File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2010-04-02 18:21 - 2008-09-30 22:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2010-07-15 00:11 - 2010-07-15 00:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2011-04-20 09:18 - 2011-01-27 01:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-10-26 19:18 - 2013-10-26 09:32 - 02136576 _____ () C:\Program Files\AVAST Software\Avast\defs\13102601\algo.dll 2009-11-02 22:20 - 2009-11-02 22:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 22:23 - 2009-11-02 22:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-10-26 19:18 - 2013-10-26 19:18 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2012-10-12 08:30 - 2013-10-10 17:25 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2012-12-29 04:01 - 2012-12-26 08:11 - 00105984 _____ () C:\Program Files (x86)\Free Download Manager\fdmumsp.dll 2011-10-05 06:25 - 2012-12-26 08:13 - 03547136 _____ () C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:3E7393FC AlternateDataStreams: C:\ProgramData\Temp:7C4DF735 AlternateDataStreams: C:\ProgramData\Temp:81F83028 AlternateDataStreams: C:\ProgramData\Temp:981884E7 AlternateDataStreams: C:\ProgramData\Temp:AD7183FA AlternateDataStreams: C:\ProgramData\Temp:B1FCBEB0 AlternateDataStreams: C:\ProgramData\Temp:B64F7263 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/26/2013 09:36:01 PM) (Source: ESENT) (User: ) Description: taskhost (2732) WebCacheLocal: Fehler -1811 beim Öffnen von Protokolldatei C:\Users\Traumhexe\AppData\Local\Microsoft\Windows\WebCache\V0100022.log. Error: (10/26/2013 09:04:24 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Bootstrapper.exe, Version: 1.14.1.0, Zeitstempel: 0x51dd112d Name des fehlerhaften Moduls: nvdxgiwrap.dll, Version: 8.17.12.6686, Zeitstempel: 0x4d4347c5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000282a ID des fehlerhaften Prozesses: 0x1590 Startzeit der fehlerhaften Anwendung: 0xBootstrapper.exe0 Pfad der fehlerhaften Anwendung: Bootstrapper.exe1 Pfad des fehlerhaften Moduls: Bootstrapper.exe2 Berichtskennung: Bootstrapper.exe3 Error: (10/26/2013 09:04:12 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Bootstrapper.exe, Version: 1.14.1.0, Zeitstempel: 0x51dd112d Name des fehlerhaften Moduls: nvdxgiwrap.dll, Version: 8.17.12.6686, Zeitstempel: 0x4d4347c5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000282a ID des fehlerhaften Prozesses: 0x1228 Startzeit der fehlerhaften Anwendung: 0xBootstrapper.exe0 Pfad der fehlerhaften Anwendung: Bootstrapper.exe1 Pfad des fehlerhaften Moduls: Bootstrapper.exe2 Berichtskennung: Bootstrapper.exe3 Error: (10/26/2013 08:33:09 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 24.0.0.5001, Zeitstempel: 0x522fd29f Name des fehlerhaften Moduls: xul.dll, Version: 24.0.0.5001, Zeitstempel: 0x522fd1a4 Ausnahmecode: 0xc0000005 Fehleroffset: 0x001b72a8 ID des fehlerhaften Prozesses: 0x166c Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (10/26/2013 08:11:04 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Bootstrapper.exe, Version: 1.14.1.0, Zeitstempel: 0x51dd112d Name des fehlerhaften Moduls: nvdxgiwrap.dll, Version: 8.17.12.6686, Zeitstempel: 0x4d4347c5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000282a ID des fehlerhaften Prozesses: 0x1594 Startzeit der fehlerhaften Anwendung: 0xBootstrapper.exe0 Pfad der fehlerhaften Anwendung: Bootstrapper.exe1 Pfad des fehlerhaften Moduls: Bootstrapper.exe2 Berichtskennung: Bootstrapper.exe3 Error: (10/26/2013 08:08:04 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Bootstrapper.exe, Version: 1.14.1.0, Zeitstempel: 0x51dd112d Name des fehlerhaften Moduls: nvdxgiwrap.dll, Version: 8.17.12.6686, Zeitstempel: 0x4d4347c5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000282a ID des fehlerhaften Prozesses: 0x1110 Startzeit der fehlerhaften Anwendung: 0xBootstrapper.exe0 Pfad der fehlerhaften Anwendung: Bootstrapper.exe1 Pfad des fehlerhaften Moduls: Bootstrapper.exe2 Berichtskennung: Bootstrapper.exe3 Error: (10/26/2013 08:06:58 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Bootstrapper.exe, Version: 1.14.1.0, Zeitstempel: 0x51dd112d Name des fehlerhaften Moduls: nvdxgiwrap.dll, Version: 8.17.12.6686, Zeitstempel: 0x4d4347c5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000282a ID des fehlerhaften Prozesses: 0x1798 Startzeit der fehlerhaften Anwendung: 0xBootstrapper.exe0 Pfad der fehlerhaften Anwendung: Bootstrapper.exe1 Pfad des fehlerhaften Moduls: Bootstrapper.exe2 Berichtskennung: Bootstrapper.exe3 Error: (10/26/2013 08:06:43 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Bootstrapper.exe, Version: 1.14.1.0, Zeitstempel: 0x51dd112d Name des fehlerhaften Moduls: nvdxgiwrap.dll, Version: 8.17.12.6686, Zeitstempel: 0x4d4347c5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000282a ID des fehlerhaften Prozesses: 0x163c Startzeit der fehlerhaften Anwendung: 0xBootstrapper.exe0 Pfad der fehlerhaften Anwendung: Bootstrapper.exe1 Pfad des fehlerhaften Moduls: Bootstrapper.exe2 Berichtskennung: Bootstrapper.exe3 Error: (10/26/2013 08:05:49 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Bootstrapper.exe, Version: 1.14.1.0, Zeitstempel: 0x51dd112d Name des fehlerhaften Moduls: nvdxgiwrap.dll, Version: 8.17.12.6686, Zeitstempel: 0x4d4347c5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000282a ID des fehlerhaften Prozesses: 0xe58 Startzeit der fehlerhaften Anwendung: 0xBootstrapper.exe0 Pfad der fehlerhaften Anwendung: Bootstrapper.exe1 Pfad des fehlerhaften Moduls: Bootstrapper.exe2 Berichtskennung: Bootstrapper.exe3 Error: (10/26/2013 09:46:19 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. System errors: ============= Error: (10/26/2013 09:35:42 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 26.10.2013 um 22:33:51 unerwartet heruntergefahren. Error: (10/26/2013 07:18:37 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "avast! Antivirus" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (10/26/2013 07:12:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (10/24/2013 06:34:14 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/24/2013 06:34:06 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/24/2013 06:33:59 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/24/2013 06:33:51 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/24/2013 06:33:44 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/24/2013 06:33:37 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Error: (10/24/2013 06:33:30 AM) (Source: cdrom) (User: ) Description: Fehlerhafter Block bei Gerät \Device\CdRom0. Microsoft Office Sessions: ========================= Error: (10/26/2013 09:36:01 PM) (Source: ESENT)(User: ) Description: taskhost2732WebCacheLocal: C:\Users\Traumhexe\AppData\Local\Microsoft\Windows\WebCache\V0100022.log-1811 Error: (10/26/2013 09:04:24 PM) (Source: Application Error)(User: ) Description: Bootstrapper.exe1.14.1.051dd112dnvdxgiwrap.dll8.17.12.66864d4347c5c00000050000282a159001ced2869105cf59C:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exeC:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dllceceeabd-3e79-11e3-8ada-14dae9247551 Error: (10/26/2013 09:04:12 PM) (Source: Application Error)(User: ) Description: Bootstrapper.exe1.14.1.051dd112dnvdxgiwrap.dll8.17.12.66864d4347c5c00000050000282a122801ced286885ec777C:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exeC:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dllc77ea902-3e79-11e3-8ada-14dae9247551 Error: (10/26/2013 08:33:09 PM) (Source: Application Error)(User: ) Description: firefox.exe24.0.0.5001522fd29fxul.dll24.0.0.5001522fd1a4c0000005001b72a8166c01ced281c5828f24C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dll718fa4bb-3e75-11e3-8ada-14dae9247551 Error: (10/26/2013 08:11:04 PM) (Source: Application Error)(User: ) Description: Bootstrapper.exe1.14.1.051dd112dnvdxgiwrap.dll8.17.12.66864d4347c5c00000050000282a159401ced27f1ca62dddC:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exeC:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dll5bd457aa-3e72-11e3-8ada-14dae9247551 Error: (10/26/2013 08:08:04 PM) (Source: Application Error)(User: ) Description: Bootstrapper.exe1.14.1.051dd112dnvdxgiwrap.dll8.17.12.66864d4347c5c00000050000282a111001ced27eb29550ebC:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exeC:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dllf060cdaf-3e71-11e3-8ada-14dae9247551 Error: (10/26/2013 08:06:58 PM) (Source: Application Error)(User: ) Description: Bootstrapper.exe1.14.1.051dd112dnvdxgiwrap.dll8.17.12.66864d4347c5c00000050000282a179801ced27e8b1f00d9C:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exeC:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dllc8f6647e-3e71-11e3-8ada-14dae9247551 Error: (10/26/2013 08:06:43 PM) (Source: Application Error)(User: ) Description: Bootstrapper.exe1.14.1.051dd112dnvdxgiwrap.dll8.17.12.66864d4347c5c00000050000282a163c01ced27e82173b4bC:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exeC:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dllbff10051-3e71-11e3-8ada-14dae9247551 Error: (10/26/2013 08:05:49 PM) (Source: Application Error)(User: ) Description: Bootstrapper.exe1.14.1.051dd112dnvdxgiwrap.dll8.17.12.66864d4347c5c00000050000282ae5801ced27e614afa5eC:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exeC:\Program Files (x86)\NVIDIA Corporation\CoProcManager\nvdxgiwrap.dll9f9868cd-3e71-11e3-8ada-14dae9247551 Error: (10/26/2013 09:46:19 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Program Files (x86)\Nero\Nero 9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest CodeIntegrity Errors: =================================== Date: 2013-03-08 13:06:45.245 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\nvoptimusmft.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-03-08 12:19:37.329 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\nvoptimusmft.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 26% Total physical RAM: 8104.16 MB Available physical RAM: 5988.91 MB Total Pagefile: 16206.5 MB Available Pagefile: 14074.36 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:123.19 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:254.45 GB) (Free:117.04 GB) NTFS Drive e: (ARTHUR) (CDROM) (Total:7.79 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 38601C96) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=186 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=254 GB) - (Type=OF Extended) ==================== End Of Log ============================ gerade spiele ich flip words (das ist auf meinem laptop drauf) und plötzlich erscheint ein neues logo (als verknüpfung) "McAfee Security Scan" auf meinem desktop bildschirm. kommen programme schon von alleine hab es normal deinstalliert bei systemsteuerung. auf c, programme (x86) ist ein ordner von denen drin. das ist gegen 15.10 uhr gewesen. Geändert von wolfsbrut (27.10.2013 um 15:21 Uhr) |
27.10.2013, 18:59 | #4 | |
/// the machine /// TB-Ausbilder | hab ich was oder nicht?Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.10.2013, 00:47 | #5 |
| hab ich was oder nicht? erst einmale vielen dank für deine hilfe und viel erfolg bei deinem studium! Code:
ATTFilter ComboFix 13-10-26.01 - Traumhexe 28.10.2013 0:32.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8104.6089 [GMT 1:00] ausgeführt von:: d:\neu v save tv\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Windows Live\Messenger\msacm32.dll c:\programdata\fullscreen=true c:\programdata\fullscreen=true\Amazing Adventures\akos.mse c:\programdata\fullscreen=true\Amazing Adventures\highscore.mse c:\programdata\fullscreen=true\Amazing Adventures\options.mso c:\programdata\fullscreen=true\Amazing Adventures\players.mse c:\windows\IsUn0407.exe c:\windows\msvcr71.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-09-27 bis 2013-10-27 )))))))))))))))))))))))))))))) . . 2013-10-27 23:37 . 2013-10-27 23:37 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-10-27 23:37 . 2013-10-27 23:37 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-10-27 23:16 . 2013-09-04 12:12 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2013-10-27 23:16 . 2013-09-04 12:11 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2013-10-27 23:16 . 2013-09-04 12:11 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2013-10-27 23:16 . 2013-09-04 12:11 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys 2013-10-27 23:16 . 2013-09-04 12:11 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2013-10-27 23:16 . 2013-09-04 12:11 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2013-10-27 23:16 . 2013-09-04 12:11 7808 ----a-w- c:\windows\system32\drivers\usbd.sys 2013-10-27 14:02 . 2013-10-27 14:02 -------- d-----w- c:\programdata\McAfee Security Scan 2013-10-27 07:23 . 2013-10-27 07:23 -------- d-----w- C:\FRST 2013-10-26 20:31 . 2013-10-26 20:34 -------- d-----w- C:\AdwCleaner 2013-10-26 19:20 . 2013-10-26 19:20 -------- d-----w- c:\program files\Enigma Software Group 2013-10-26 19:20 . 2013-10-26 19:34 -------- d-----w- c:\windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-26 19:19 . 2013-10-26 19:19 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2013-10-26 18:48 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{585977B4-0C3C-464C-9E4F-DD9CA424B880}\mpengine.dll 2013-10-26 18:40 . 2013-10-26 18:40 -------- d-----w- C:\Temp 2013-10-26 18:21 . 2013-10-26 18:21 -------- d-----w- c:\users\Traumhexe\AppData\Roaming\AVAST Software 2013-10-26 18:16 . 2013-10-26 18:18 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-10-26 18:16 . 2013-10-26 18:18 205320 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-10-22 01:16 . 2013-10-22 01:16 -------- d-----w- c:\programdata\Oracle 2013-10-22 01:15 . 2013-10-22 01:15 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-10-22 01:15 . 2013-10-22 01:15 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-10-18 18:29 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2013-10-18 18:29 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2013-10-12 14:51 . 2013-10-12 14:51 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 14:44 . 2013-10-12 14:44 -------- d-----w- c:\program files\Microsoft Silverlight 2013-10-12 14:44 . 2013-10-12 14:44 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2013-10-12 14:34 . 2013-10-12 14:36 -------- d-----w- c:\windows\system32\MRT 2013-10-12 14:29 . 2013-08-02 02:13 424448 ----a-w- c:\windows\system32\KernelBase.dll 2013-10-12 14:28 . 2013-07-25 09:25 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-10-12 14:27 . 2013-04-26 05:51 751104 ----a-w- c:\windows\system32\win32spl.dll 2013-10-12 14:27 . 2013-04-26 04:55 492544 ----a-w- c:\windows\SysWow64\win32spl.dll 2013-10-12 14:27 . 2013-07-20 10:33 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll 2013-10-12 14:27 . 2013-07-20 10:33 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-12 14:27 . 2013-08-01 12:09 983488 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-10-12 14:27 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-10-12 14:27 . 2011-02-03 11:25 144384 ----a-w- c:\windows\system32\cdd.dll 2013-10-12 14:25 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll 2013-10-12 13:55 . 2013-10-12 13:55 -------- d-----w- c:\users\Traumhexe\AppData\Local\Macromedia 2013-10-12 13:54 . 2013-10-27 13:56 -------- d-----w- c:\program files (x86)\McAfee Security Scan 2013-10-12 13:54 . 2013-10-12 13:54 -------- d-----w- c:\users\Traumhexe\AppData\Local\Adobe 2013-10-10 16:25 . 2013-10-10 16:25 271256 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll 2013-10-10 16:25 . 2013-10-10 16:25 27544 ----a-w- c:\program files (x86)\Mozilla Firefox\plugin-hang-ui.exe . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-10-27 14:09 . 2011-10-01 15:47 45056 ----a-w- c:\windows\system32\acovcnt.exe 2013-10-26 18:18 . 2012-04-16 08:01 409832 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-10-26 18:18 . 2012-04-16 08:01 38984 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-10-26 18:18 . 2012-04-16 08:01 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-10-26 18:18 . 2012-04-16 08:01 65264 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-10-26 18:18 . 2012-04-16 08:01 1032416 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-10-26 18:18 . 2012-04-16 08:01 84328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-10-26 18:18 . 2012-04-16 08:01 334648 ----a-w- c:\windows\system32\aswBoot.exe 2013-10-26 18:18 . 2012-04-16 08:01 43152 ----a-w- c:\windows\avastSS.scr 2013-10-12 13:54 . 2012-10-14 05:30 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-10-12 13:54 . 2011-10-31 22:34 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-10-11 12:47 . 2010-06-24 18:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-09-25 23:46 . 2011-10-03 04:06 80541720 ----a-w- c:\windows\system32\MRT.exe 2013-09-03 12:35 . 2011-10-03 04:29 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-08-29 01:48 . 2013-10-12 14:30 44032 ----a-w- c:\windows\apppatch\acwow64.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Software Informer"="c:\program files (x86)\Software Informer\softinfo.exe" [2011-03-22 2859077] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032] "ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536] "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-10-26 3567800] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x] R3 DfSdkS;Defragmentation-Service;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe;c:\program files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys;c:\windows\SYSNATIVE\drivers\aswFsBlk.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . Inhalt des "geplante Tasks" Ordners . 2013-10-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-12 13:54] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-10-26 18:18 326944 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-10 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-10 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-10 418328] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-01 2189416] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-08-11 324096] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm IE: Alles mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dlall.htm IE: Alles mit FlashGet laden - c:\program files (x86)\FlashGet\jc_all.htm IE: Auswahl mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dlselected.htm IE: Datei mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dllink.htm IE: Mit FlashGet laden - c:\program files (x86)\FlashGet\jc_link.htm IE: Videos mit FDM herunterladen - file://c:\program files (x86)\Free Download Manager\dlfvideo.htm TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.de FF - prefs.js: network.proxy.type - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-fsm - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd AddRemove-Adobe SVG Viewer - c:\windows\IsUn0407.exe AddRemove-ArcSoft PhotoStudio 2000 - c:\windows\IsUn0407.exe AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}\bm_installer.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-10-28 00:39:23 ComboFix-quarantined-files.txt 2013-10-27 23:39 . Vor Suchlauf: 15 Verzeichnis(se), 132.357.636.096 Bytes frei Nach Suchlauf: 21 Verzeichnis(se), 131.693.473.792 Bytes frei . - - End Of File - - F1C96ABA9E6934DDFFC583F5C319B3F1 |
28.10.2013, 12:37 | #6 |
/// the machine /// TB-Ausbilder | hab ich was oder nicht? Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> hab ich was oder nicht? |
28.10.2013, 23:39 | #7 |
| hab ich was oder nicht? schon mal das erste von malwarebytes Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.10.28.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 Traumhexe :: WOLFSBRUT [Administrator] Schutz: Aktiviert 28.10.2013 16:02:04 mbam-log-2013-10-28 (16-02-04).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 364551 Laufzeit: 42 Minute(n), 26 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 12 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\Umbrella\Umbrella.exe.vir (PUP.Optional.Iminent) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-bg.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-bho.dll.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-bho64.dll.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-buttonutil.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-buttonutil64.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-chromeinstaller.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-enabler.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-updater.exe.vir (PUP.Optional.PlusHD.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\2af7b79.msi (PUP.Optional.Iminent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.010 - Bericht erstellt am 28/10/2013 um 16:56:50 # Updated 20/10/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Traumhexe - WOLFSBRUT # Gestartet von : D:\neu v save tv\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Traumhexe\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16720 -\\ Mozilla Firefox v24.0 (de) [ Datei : C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Traumhexe\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [33176 octets] - [26/10/2013 21:31:31] AdwCleaner[R1].txt - [1169 octets] - [28/10/2013 16:55:31] AdwCleaner[S0].txt - [31806 octets] - [26/10/2013 21:34:12] AdwCleaner[S1].txt - [1091 octets] - [28/10/2013 16:56:50] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1151 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.7 (10.15.2013:3) OS: Windows 7 Home Premium x64 Ran by Traumhexe on 28.10.2013 at 17:07:16,09 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\software informer ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322202202} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220322202202} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Traumhexe\AppData\Roaming\big fish games" Successfully deleted: [Folder] "C:\Users\Traumhexe\AppData\Roaming\software informer" Successfully deleted: [Folder] "C:\Program Files (x86)\software informer" ~~~ FireFox Successfully deleted the following from C:\Users\Traumhexe\AppData\Roaming\mozilla\firefox\profiles\s2dv7mhb.default\prefs.js user_pref("extensions.iminent.admin", false); user_pref("extensions.iminent.aflt", "orgnl"); user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}"); user_pref("extensions.iminent.autoRvrt", "false"); user_pref("extensions.iminent.dfltLng", ""); user_pref("extensions.iminent.excTlbr", false); user_pref("extensions.iminent.ffxUnstlRst", false); user_pref("extensions.iminent.id", "a6f0b0c5000000000000485d60f99b58"); user_pref("extensions.iminent.instlDay", "16004"); user_pref("extensions.iminent.instlRef", ""); user_pref("extensions.iminent.newTab", false); user_pref("extensions.iminent.prdct", "iminent"); user_pref("extensions.iminent.prtnrId", "iminent"); user_pref("extensions.iminent.rvrt", "false"); user_pref("extensions.iminent.smplGrp", "none"); user_pref("extensions.iminent.tlbrId", "base"); user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q="); user_pref("extensions.iminent.vrsn", "1.8.26.8"); user_pref("extensions.iminent.vrsnTs", "1.8.26.820:12:17"); user_pref("extensions.iminent.vrsni", "1.8.26.8"); user_pref("iminent.LayoutId", "1"); user_pref("iminent.ShowThankyouPixel", "0"); user_pref("iminent.newtabredirect", "true"); user_pref("iminent.searchindex", "1"); user_pref("iminent.version", "7.43.4.1"); user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.43.4.1\",\"InstallEventCTime\":1382811183535,\"InstallEvent\":\"True\"}"); Emptied folder: C:\Users\Traumhexe\AppData\Roaming\mozilla\firefox\profiles\s2dv7mhb.default\minidumps [14 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.10.2013 at 17:14:50,88 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ zu guter letzt FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-10-2013 Ran by Traumhexe (administrator) on WOLFSBRUT on 28-10-2013 17:22:00 Running from D:\neu v save tv Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Windows\AsScrPro.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe (Farbar) D:\neu v save tv\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-01] (Realtek Semiconductor) HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-11] (Alcor Micro Corp.) HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] - C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini [414 2013-10-28] () HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\aprp.exe [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\avastui.exe [3567800 2013-10-26] (AVAST Software) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [226920 2011-02-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [192616 2011-02-08] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files (x86)\FlashGet\Jccatch.dll (FlashGet) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files (x86)\FlashGet\getflash.dll () Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\fgiebar.dll (Amaze Soft) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default FF Homepage: hxxp://www.google.de FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\StartWeb.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Flashblock - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} FF Extension: WOT - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: DownloadHelper - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc@jetpack.xpi FF Extension: flashgot - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi FF Extension: No Name - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi FF Extension: Adblock Plus - C:\Users\Traumhexe\AppData\Roaming\Mozilla\Firefox\Profiles\s2dv7mhb.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR Extension: (YouTube) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0 CHR Extension: (Google Search) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0 CHR Extension: (avast! WebRep) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0 CHR Extension: (Gmail) - C:\Users\TRAUMH~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0 ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-10-26] (AVAST Software) S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-10-26] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-10-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-10-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-10-26] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-10-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-10-26] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-28 17:14 - 2013-10-28 17:14 - 00002931 _____ C:\Users\Traumhexe\Desktop\JRT.txt 2013-10-28 17:07 - 2013-10-28 17:07 - 00000000 ____D C:\Windows\ERUNT 2013-10-28 16:00 - 2013-10-28 16:00 - 00001115 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-28 16:00 - 2013-10-28 16:00 - 00000000 ____D C:\Users\Traumhexe\AppData\Roaming\Malwarebytes 2013-10-28 16:00 - 2013-10-28 16:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-28 16:00 - 2013-10-28 16:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-28 16:00 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-10-28 15:50 - 2013-10-28 16:47 - 00004390 _____ C:\Windows\PFRO.log 2013-10-28 00:39 - 2013-10-28 00:39 - 00021643 _____ C:\ComboFix.txt 2013-10-28 00:31 - 2013-10-28 00:39 - 00000000 ____D C:\Qoobox 2013-10-28 00:31 - 2013-10-28 00:38 - 00000000 ____D C:\Windows\erdnt 2013-10-28 00:31 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-10-28 00:31 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-10-28 00:31 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-10-28 00:31 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-10-28 00:31 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-10-28 00:31 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-10-28 00:31 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-10-28 00:31 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-10-28 00:16 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-28 00:16 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-28 00:16 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-28 00:16 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-28 00:16 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-28 00:16 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-28 00:16 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-28 00:06 - 2013-10-28 16:59 - 00000280 _____ C:\Windows\setupact.log 2013-10-28 00:06 - 2013-10-28 00:06 - 00241288 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-28 00:06 - 2013-10-28 00:06 - 00000000 _____ C:\Windows\setuperr.log 2013-10-27 15:02 - 2013-10-27 15:02 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-27 08:23 - 2013-10-27 08:23 - 00000000 ____D C:\FRST 2013-10-26 21:31 - 2013-10-28 16:56 - 00000000 ____D C:\AdwCleaner 2013-10-26 20:21 - 2013-10-26 20:21 - 00000000 _____ C:\autoexec.bat 2013-10-26 20:20 - 2013-10-26 20:34 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-26 20:20 - 2013-10-26 20:20 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-26 19:21 - 2013-10-26 19:21 - 00000000 ____D C:\Users\Traumhexe\AppData\Roaming\AVAST Software 2013-10-26 19:16 - 2013-10-26 19:18 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-26 19:16 - 2013-10-26 19:18 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-26 19:12 - 2013-10-26 19:12 - 00000635 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-10-26 10:03 - 2013-10-26 10:03 - 00000763 _____ C:\Users\Traumhexe\Desktop\Filme f Tablet - Verknüpfung.lnk 2013-10-22 14:39 - 2013-10-22 14:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-10-22 02:16 - 2013-10-22 02:16 - 00000000 ____D C:\ProgramData\Oracle 2013-10-22 02:15 - 2013-10-22 02:15 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 02:15 - 2013-10-22 02:15 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-18 19:29 - 2013-04-17 08:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-10-18 19:29 - 2013-04-17 07:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-12 15:51 - 2013-10-12 15:51 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 15:34 - 2013-10-12 15:36 - 00000000 ____D C:\Windows\system32\MRT 2013-10-12 15:30 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-12 15:30 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-12 15:30 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-12 15:30 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-12 15:30 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-12 15:30 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-12 15:30 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-12 15:30 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-12 15:30 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-12 15:30 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-12 15:30 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-12 15:30 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-12 15:30 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-12 15:30 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-12 15:30 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-12 15:30 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-12 15:30 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-12 15:30 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-12 15:30 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-12 15:29 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-10-12 15:29 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-10-12 15:29 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-10-12 15:29 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-10-12 15:29 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-10-12 15:29 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-10-12 15:29 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-10-12 15:29 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-10-12 15:29 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-10-12 15:29 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-10-12 15:29 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-10-12 15:29 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-10-12 15:29 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-10-12 15:29 - 2013-07-09 06:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-10-12 15:29 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-10-12 15:29 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-10-12 15:29 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-10-12 15:29 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-10-12 15:29 - 2013-07-09 05:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-10-12 15:29 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-10-12 15:29 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-10-12 15:29 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-10-12 15:29 - 2013-04-12 15:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2013-10-12 15:29 - 2013-03-31 23:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-10-12 15:29 - 2013-02-27 07:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2013-10-12 15:29 - 2013-02-27 06:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-10-12 15:29 - 2013-02-27 06:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2013-10-12 15:29 - 2013-02-27 05:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-10-12 15:29 - 2013-02-15 07:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2013-10-12 15:29 - 2013-02-15 07:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2013-10-12 15:29 - 2013-02-15 07:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2013-10-12 15:29 - 2013-02-15 05:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-10-12 15:29 - 2013-02-15 05:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-10-12 15:29 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-10-12 15:29 - 2013-02-12 05:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2013-10-12 15:28 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-12 15:28 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-10-12 15:28 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-10-12 15:28 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-10-12 15:28 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-10-12 15:28 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-10-12 15:28 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-12 15:28 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-12 15:28 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-12 15:28 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-12 15:28 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-12 15:28 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-12 15:28 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-12 15:28 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-12 15:28 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-12 15:28 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-12 15:28 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-12 15:28 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-12 15:28 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-12 15:28 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-10-12 15:28 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-12 15:28 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-12 15:28 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-12 15:28 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-12 15:28 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-12 15:28 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-12 15:28 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-12 15:28 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-12 15:28 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-12 15:28 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-12 15:28 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-10-12 15:28 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-10-12 15:28 - 2013-05-13 06:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-10-12 15:28 - 2013-05-13 04:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-10-12 15:28 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-10-12 15:28 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-10-12 15:28 - 2013-05-10 06:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-10-12 15:28 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-10-12 15:28 - 2013-03-19 06:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-10-12 15:28 - 2013-03-19 06:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2013-10-12 15:28 - 2013-01-24 07:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2013-10-12 15:27 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-12 15:27 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-12 15:27 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-12 15:27 - 2013-04-26 06:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-10-12 15:27 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-10-12 15:27 - 2013-04-10 07:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2013-10-12 15:27 - 2011-02-03 12:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-10-12 15:25 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-12 14:55 - 2013-10-12 14:55 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Macromedia 2013-10-12 14:54 - 2013-10-28 17:06 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-12 14:54 - 2013-10-27 14:56 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-10-12 14:54 - 2013-10-12 14:54 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Adobe 2013-09-29 05:42 - 2013-10-26 10:25 - 00000000 ____D C:\Users\Traumhexe\Desktop\für Fotoautomat bei Müller ==================== One Month Modified Files and Folders ======= 2013-10-28 17:14 - 2013-10-28 17:14 - 00002931 _____ C:\Users\Traumhexe\Desktop\JRT.txt 2013-10-28 17:07 - 2013-10-28 17:07 - 00000000 ____D C:\Windows\ERUNT 2013-10-28 17:07 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-28 17:07 - 2009-07-14 05:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-28 17:06 - 2013-10-12 14:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-28 17:04 - 2011-02-19 05:24 - 00666264 _____ C:\Windows\system32\perfh007.dat 2013-10-28 17:04 - 2011-02-19 05:24 - 00134186 _____ C:\Windows\system32\perfc007.dat 2013-10-28 17:04 - 2009-07-14 06:13 - 01531054 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-28 17:00 - 2011-10-01 16:47 - 00045056 _____ C:\Windows\system32\acovcnt.exe 2013-10-28 16:59 - 2013-10-28 00:06 - 00000280 _____ C:\Windows\setupact.log 2013-10-28 16:59 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-28 16:58 - 2012-09-01 09:08 - 02032280 _____ C:\Windows\WindowsUpdate.log 2013-10-28 16:56 - 2013-10-26 21:31 - 00000000 ____D C:\AdwCleaner 2013-10-28 16:48 - 2011-07-12 10:11 - 00001377 _____ C:\Windows\system32\ServiceFilter.ini 2013-10-28 16:47 - 2013-10-28 15:50 - 00004390 _____ C:\Windows\PFRO.log 2013-10-28 16:00 - 2013-10-28 16:00 - 00001115 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-28 16:00 - 2013-10-28 16:00 - 00000000 ____D C:\Users\Traumhexe\AppData\Roaming\Malwarebytes 2013-10-28 16:00 - 2013-10-28 16:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-28 16:00 - 2013-10-28 16:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-10-28 00:39 - 2013-10-28 00:39 - 00021643 _____ C:\ComboFix.txt 2013-10-28 00:39 - 2013-10-28 00:31 - 00000000 ____D C:\Qoobox 2013-10-28 00:39 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-10-28 00:38 - 2013-10-28 00:31 - 00000000 ____D C:\Windows\erdnt 2013-10-28 00:37 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-10-28 00:06 - 2013-10-28 00:06 - 00241288 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-28 00:06 - 2013-10-28 00:06 - 00000000 _____ C:\Windows\setuperr.log 2013-10-27 16:32 - 2012-12-15 02:53 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\SMPlayer2 2013-10-27 15:02 - 2013-10-27 15:02 - 00000000 ____D C:\ProgramData\McAfee Security Scan 2013-10-27 14:56 - 2013-10-12 14:54 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan 2013-10-27 08:23 - 2013-10-27 08:23 - 00000000 ____D C:\FRST 2013-10-27 06:14 - 2011-10-02 04:57 - 00000202 _____ C:\Users\Traumhexe\AppData\Roaming\default.rss 2013-10-26 20:34 - 2013-10-26 20:20 - 00000000 ____D C:\Windows\86CA3695A4124BAE92B649A60C2AC663.TMP 2013-10-26 20:21 - 2013-10-26 20:21 - 00000000 _____ C:\autoexec.bat 2013-10-26 20:20 - 2013-10-26 20:20 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-26 19:21 - 2013-10-26 19:21 - 00000000 ____D C:\Users\Traumhexe\AppData\Roaming\AVAST Software 2013-10-26 19:20 - 2011-07-12 10:11 - 00002408 _____ C:\Windows\system32\AutoRunFilter.ini 2013-10-26 19:18 - 2013-10-26 19:16 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-26 19:18 - 2013-10-26 19:16 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-26 19:18 - 2012-07-07 03:04 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-26 19:18 - 2012-04-16 09:01 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-26 19:18 - 2012-04-16 09:01 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-26 19:18 - 2012-04-16 09:01 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-26 19:18 - 2012-04-16 09:01 - 00001974 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-10-26 19:16 - 2012-04-16 09:01 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-26 19:16 - 2012-04-16 09:01 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-26 19:12 - 2013-10-26 19:12 - 00000635 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-10-26 10:26 - 2013-05-04 17:16 - 00000000 ____D C:\Users\Traumhexe\Desktop\spielerei 2013-10-26 10:25 - 2013-09-29 05:42 - 00000000 ____D C:\Users\Traumhexe\Desktop\für Fotoautomat bei Müller 2013-10-26 10:03 - 2013-10-26 10:03 - 00000763 _____ C:\Users\Traumhexe\Desktop\Filme f Tablet - Verknüpfung.lnk 2013-10-22 14:39 - 2013-10-22 14:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-10-22 02:16 - 2013-10-22 02:16 - 00000000 ____D C:\ProgramData\Oracle 2013-10-22 02:15 - 2013-10-22 02:15 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-22 02:15 - 2013-10-22 02:15 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-22 02:15 - 2012-10-23 14:24 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-22 02:15 - 2012-10-23 14:24 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-22 02:15 - 2012-06-22 05:00 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-20 05:29 - 2011-10-05 05:29 - 00000000 ___RD C:\Users\Traumhexe\Desktop\Mix 2013-10-19 05:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-15 18:38 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-12 18:03 - 2009-07-29 07:03 - 00000000 ____D C:\Windows\Panther 2013-10-12 16:19 - 2011-10-01 16:48 - 00000000 ___RD C:\Users\Traumhexe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-12 16:19 - 2011-10-01 16:48 - 00000000 ___RD C:\Users\Traumhexe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-12 16:18 - 2011-10-05 04:40 - 00001427 _____ C:\Users\Traumhexe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-12 16:13 - 2009-07-14 08:45 - 00000000 ____D C:\Program Files\Windows Journal 2013-10-12 16:13 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-10-12 16:13 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\he-IL 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\ar-SA 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-10-12 16:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-10-12 16:07 - 2012-02-21 10:06 - 01558672 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-12 16:07 - 2012-02-21 10:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client 2013-10-12 15:52 - 2013-10-12 15:52 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-12 15:52 - 2013-10-12 15:52 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-12 15:52 - 2013-10-12 15:52 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-12 15:52 - 2013-10-12 15:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-12 15:52 - 2013-10-12 15:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-12 15:52 - 2013-10-12 15:52 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-12 15:52 - 2013-10-12 15:52 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-12 15:51 - 2013-10-12 15:51 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:51 - 2013-10-12 15:51 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 15:44 - 2013-10-12 15:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 15:36 - 2013-10-12 15:34 - 00000000 ____D C:\Windows\system32\MRT 2013-10-12 14:55 - 2013-10-12 14:55 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Macromedia 2013-10-12 14:54 - 2013-10-12 14:54 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-12 14:54 - 2013-10-12 14:54 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Adobe 2013-10-12 14:54 - 2012-10-14 06:30 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-12 14:54 - 2011-10-31 23:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-10 17:25 - 2012-09-10 05:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-10 17:25 - 2011-10-02 06:26 - 00000000 ____D C:\Users\Traumhexe\AppData\Local\Mozilla Some content of TEMP: ==================== C:\Users\Traumhexe\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 04:11 ==================== End Of Log ============================ --- --- --- --- --- --- ich hoffe mal daß du das gemeint hast. wenn wir schon dabei sind,da ja evtl. schon reingehen in seiten reicht um was abzukriegen ist es überhaupt ratsam da rein zu gehen "www.spiele-kostenlos-online.de (ohne anmeldung) da spiel ich halt gerne mal "stop the bus oder andere 5 minuten spielen oder ist es besser sowas in zukunft nichtmehr zu betreten? was meinst du dazu? |
29.10.2013, 14:00 | #8 |
/// the machine /// TB-Ausbilder | hab ich was oder nicht? ich spiel sowas auch gern ab und zu. Halt aufpassen, java und Flash aktuell halten, oder wenn möglich deaktivieren im Browser. ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.10.2013, 14:58 | #9 |
| hab ich was oder nicht? bevor ich weiter mache - hast du was bisher gefunden? meine externe festplatten sind hauptsächlich im schrank verwahrt und ganz selten am laptop dran, was ne weile her ist. ich kann die beim besten willen nicht scannen lassen, da dort echte daten von mir drauf sind die ich grundsätzlich aus dem internet raus halte und auf meinem laptop findet man auch nichts persönliches von mir. datenschutz steht bei mir an erster stelle und jetzt steht schon alles was auf meinem laptop war hier im forum. klar kannst du mir nur so helfen und allein diesen ganzen datenmist durchzukämmen braucht bestimmt einige zeit. hast du bisher was bedrohliches gefunden? was? wie gefährlich ist das und was macht das? wenn es nicht anderst geht stöpsel ich diesen rechner vom internet komplett ab und benutz ihn nur noch zum filme kucken. ich hoffe du verstehst, daß ich keine persönlichen daten ins netz packe. da verzicht ich eher aufs internet. es gibt zu viele lügner und betrüger auf dieser welt und ich hab genug gauner kennengelernt. ich find es echt super wie du anderen hilfst! wenn du bei meinen wechseldatenträger ein problem siehst, wie wäre es wenn ich einfach alle sticks und festplatten formatiere??? alle daten zerstören ist mir immer noch lieber als sie im netz wiederfinden. im moment fühl ich mich gerade so mies als hätte mir jemand gesagt ich soll mich ausziehen und übern marktplatz laufen. was meinst du zum formatieren? Geändert von wolfsbrut (29.10.2013 um 15:13 Uhr) |
30.10.2013, 09:43 | #10 |
/// the machine /// TB-Ausbilder | hab ich was oder nicht? Die Externen sollten nur dran um sie grad mit zu scannen, wenn Du magst, kein Muss Wir haben jede Menge Kran und adware entfernt, aber nix bedrohliches.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.10.2013, 17:57 | #11 |
| hab ich was oder nicht? ! wie krieg ich Malwarebytes wieder rückstandslos von meinem laptop runter? das ist ja ein probe-programm und ich möchte das eigentlich nicht kaufen. mc afee security ist auch noch auf meinem laptop. vielleicht ist es besser diesen laptop nur noch zum abspielen von meinen filmen zu benutzen, denn da ist immer noch müll drauf. oh mann, wenn man sich ungeziefer eingefangen hat ist es schwer das wieder los zu werden. wenn ich diesen laptop nur zum filmekucken benutze, dann brauch ich auch keine updates mehr machen. dürfte kein problem sein oder werden, oder? ich hab das malware-programm einfach normal deinstalliert und hoffe mal daß nichtsmehr drauf ist. mcAfee läßt sich nicht einfach deinstallieren. das mit mcafee hat sich erledigt. hab es weggekriegt. |
01.11.2013, 11:26 | #12 |
/// the machine /// TB-Ausbilder | hab ich was oder nicht? Wenn Du obige Scans noch machst kannste auch wieder normal ins Internet mit dem Rechner Ansonsten, wenn er offline bleibt, kannste es so lassen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.11.2013, 13:03 | #13 |
| hab ich was oder nicht? danke schrauber! |
02.11.2013, 19:09 | #14 |
/// the machine /// TB-Ausbilder | hab ich was oder nicht? Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu hab ich was oder nicht? |
besser, beste, e-banking, englisch, entdeck, entfernen, erkennen, free download, gelöscht, interessant, internetseite, online-banking, programme, pup.optional.iminent, pup.optional.plushd.a, rechner, seite, smilie, systemsteuerung, tablet, verseucht, verseucht?, warnung |