|
Plagegeister aller Art und deren Bekämpfung: Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen]Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
24.11.2013, 17:34 | #1 |
| Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Hallo Trojaner Board Team, Ich hab ein Problem mit meinem Browser. Es sind einzelne Wörter zum Beispiel verlinkt und es öffnen sich beim klicken auf zum Beispiel Google Links neue Tabs mit Werbung. Ich hab schon einen Virenscann versucht und auch adwcleaner benutzt. Dies hat aber logischer weise nicht geholfen. Es währe schön wenn ich durch ihre Hilfe dieses Problem in den Griff bekommen würde. mfg Magix |
24.11.2013, 18:25 | #2 |
/// TB-Ausbilder | Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Hi,
__________________mach bitte einen FRST-Scan: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
24.11.2013, 18:46 | #3 |
| Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Addition
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-11-2013 Ran by MAGIC at 2013-11-24 18:43:10 Running from C:\Users\MAGIC\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {3F839487-C7A2-C958-E30C-E2825BA31FB5} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {84E27563-E198-C6D6-D9BC-D9F020245508} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32) 4K YouTube to MP3 2.5 (x32 Version: 2.5.2.700) 7-Zip 9.20 (x32) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Aeria Ignite (x32 Version: 1.12.2553) Age of Empires II: HD Edition (x32) AION Free-To-Play (x32 Version: 2.70.0000) Arma 3 Alpha (x32) ASIO4ALL (x32 Version: 2.10) Battlefield 3™ (x32 Version: 1.6.0.0) Battlelog Web Plugins (x32 Version: 2.3.0) BlackBoard (x32 Version: 1.1.0) Burnout Paradise: The Ultimate Box (x32) Burnout(TM) Paradise The Ultimate Box (x32 Version: 1.1.0.0) C9 (x32) Call of Duty: Ghosts - Multiplayer (x32) Call of Duty: Ghosts (x32) CCleaner (Version: 4.07) CodeBlocks (HKCU Version: 12.11) Command & Conquer™ Alarmstufe Rot 3 Der Aufstand (x32 Version: 1.0.1.0) Core Temp 1.0 RC3 (Version: 1.0) Counter-Strike: Source v17 (x32) Crysis® 2 (x32 Version: 1.9.0.0) Crystal Reports for Visual Studio (x32 Version: 12.51.0.240) DAEMON Tools Lite (x32 Version: 4.47.1.0333) Darksiders II (x32) Dead Space™ 3 (x32 Version: 1.0.0.0) Deckadance 2 (x32 Version: 2.0) DisplayFusion 5.0 (x32 Version: 5.0.0.0) Dotfuscator Software Services - Community Edition - DEU (x32 Version: 5.0.2300.0) Dotfuscator Software Services - Community Edition (x32 Version: 5.0.2500.0) Druckerdeinstallation für EPSON SX430 Series EPSON Scan (x32) Etron USB3.0 Host Controller (x32 Version: 0.96) EXPERTool 7.21 (x32) f.lux (HKCU) Firefall (x32) FL Studio 10 (x32) Fraps (remove only) (x32) GameRanger (HKCU) GeForce Experience NvStream Client Components (Version: 1.6.28) Google Chrome (HKCU Version: 31.0.1650.57) Google Earth Plug-in (x32 Version: 7.1.1.1888) Google Talk Plugin (x32 Version: 4.9.1.16010) Google Update Helper (x32 Version: 1.3.21.165) Guild Wars 2 (x32) Happy Cloud Client (HKCU Version: 1.386) Hi-Rez Studios Authenticate and Update Service (x32 Version: 3.0.0.0) Hotfix für Microsoft Team Foundation Server 2010-Objektmodell - DEU (KB2736182) (x32 Version: 1) Hotfix für Microsoft Team Foundation Server 2010-Objektmodell - DEU (KB2813041) (x32 Version: 1) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2529927) (x32 Version: 1) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2548139) (x32 Version: 1) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2549864) (x32 Version: 1) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2635973) (x32 Version: 1) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2736182) (x32 Version: 1) Hotfix für Microsoft Visual Studio 2010 Ultimate - DEU (KB2813041) (x32 Version: 1) IL Download Manager (x32) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144) Java 7 Update 21 (x32 Version: 7.0.210) Java Auto Updater (x32 Version: 2.1.9.5) Java(TM) 7 Update 2 (64-bit) (Version: 7.0.20) JDownloader 0.9 (x32 Version: 0.9) Just Aion Launcher (x32 Version: 1.00.0000) K-Lite Mega Codec Pack 7.9.0 (x32 Version: 7.9.0) Logitech Gaming Software (Version: 8.35.18) Logitech Gaming Software 8.35 (Version: 8.35.18) Medal of Honor (TM) (x32 Version: 1.0.0.0) Mein CEWE FOTOBUCH (x32 Version: 5.0.6) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Multi-Targeting Pack (x32 Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000) Microsoft ASP.NET MVC 2 - DEU (x32 Version: 2.0.50331.0) Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools - DEU (x32 Version: 2.0.50331.0) Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (x32 Version: 2.0.50217.0) Microsoft ASP.NET MVC 2 (x32 Version: 2.0.50217.0) Microsoft Help Viewer 1.1 (Version: 1.1.40219) Microsoft Office 2007 Service Pack 2 (SP2) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6425.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6425.1000) Microsoft Office Word Viewer 2003 (x32 Version: 11.0.8173.0) Microsoft Security Client (Version: 4.2.0223.1) Microsoft Security Essentials (Version: 4.2.223.1) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft Silverlight 3 SDK - Deutsch (x32 Version: 3.0.40818.0) Microsoft Silverlight 4 SDK - Deutsch (x32 Version: 4.0.50826.0) Microsoft SQL Server 2008 (64-bit) Microsoft SQL Server 2008 Browser (x32 Version: 10.3.5500.0) Microsoft SQL Server 2008 Common Files (Version: 10.3.5500.0) Microsoft SQL Server 2008 Database Engine Services (Version: 10.3.5500.0) Microsoft SQL Server 2008 Database Engine Shared (Version: 10.3.5500.0) Microsoft SQL Server 2008 Native Client (Version: 10.3.5500.0) Microsoft SQL Server 2008 R2 Management Objects (x32 Version: 10.50.1750.9) Microsoft SQL Server 2008 R2 Management Objects (x64) (Version: 10.50.1750.9) Microsoft SQL Server 2008 R2 Transact-SQL-Sprachdienst (x32 Version: 10.50.1752.9) Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Framework (x32 Version: 10.50.1750.9) Microsoft SQL Server 2008 R2-Datenebenenanwendungs-Projekt (x32 Version: 10.50.1750.9) Microsoft SQL Server 2008 RsFx Driver (Version: 10.3.5500.0) Microsoft SQL Server Compact 3.5 SP2 DEU (x32 Version: 3.5.8080.0) Microsoft SQL Server Compact 3.5 SP2 x64 DEU (Version: 3.5.8080.0) Microsoft SQL Server Database Publishing Wizard 1.4 (x32 Version: 10.1.2512.8) Microsoft SQL Server System CLR Types (x32 Version: 10.50.1750.9) Microsoft SQL Server System CLR Types (x64) (Version: 10.50.1750.9) Microsoft SQL Server VSS Writer (Version: 10.3.5500.0) Microsoft Sync Framework Runtime v1.0 SP1 (x64) de (Version: 1.0.3010.0) Microsoft Sync Framework SDK v1.0 SP1 de (x32 Version: 1.0.3010.0) Microsoft Sync Framework Services v1.0 SP1 (x64) de (Version: 1.0.3010.0) Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) de (Version: 2.0.3010.0) Microsoft Team Foundation Server 2010 Object Model - DEU (Version: 10.0.40219) Microsoft Team Foundation Server 2010-Objektmodell - DEU (Version: 10.0.40219) Microsoft Visual C++ Compilers 2010 Standard - enu - x64 (Version: 10.0.40219) Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (x32 Version: 10.0.40219) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (x32 Version: 9.0.30729.4974) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual F# 2.0 Runtime (x32 Version: 10.0.40219) Microsoft Visual F# 2.0 Runtime Language Pack - DEU (x32 Version: 10.0.30319) Microsoft Visual Studio 2010 IntelliTrace Collection (x64) (Version: 10.0.40219) Microsoft Visual Studio 2010 Office Developer Tools (x64) (Version: 10.0.40219) Microsoft Visual Studio 2010 Office Developer Tools (x64) Language Pack - DEU (Version: 10.0.40219) Microsoft Visual Studio 2010 Performance Collection Tools SP1 - DEU (Version: 10.0.40219) Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219) Microsoft Visual Studio 2010 SharePoint Developer Tools (x32 Version: 10.0.40219) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40303) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40308) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU (Version: 10.0.40303) Microsoft Visual Studio 2010 Ultimate - DEU (x32 Version: 10.0.30319) Microsoft Visual Studio 2010 Ultimate - DEU (x32 Version: 10.0.40219) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (Version: 10.0.40303) Microsoft Visual Studio Macro Tools - DEU Language Pack (x32 Version: 9.0.30729) Microsoft Visual Studio Macro Tools (x32 Version: 9.0.30729) Microsoft Windows Application Compatibility Database Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0) Mirror's Edge™ (x32 Version: 1.0.1.0) Mozilla Firefox 25.0.1 (x86 en-US) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) MySQL Connector/ODBC 5.1 (x32 Version: 5.1.5) NC Launcher (GameForge) (x32) Need for Speed Most Wanted (x32) Need for Speed™ Most Wanted (x32) Netzmanager (Version: 1.071) Netzmanager (x32 Version: 1.071) NVIDIA 3D Vision Controller Driver (x32 Version: 280.19) NVIDIA 3D Vision Controller-Treiber 331.58 (Version: 331.58) NVIDIA 3D Vision Treiber 331.58 (Version: 331.58) NVIDIA GeForce Experience 1.7.1 (Version: 1.7.1) NVIDIA Grafiktreiber 331.58 (Version: 331.58) NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4) NVIDIA Install Application (Version: 2.1002.140.952) NVIDIA LED Visualizer 1.0 (Version: 1.0) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA ShadowPlay 9.3.21 (Version: 9.3.21) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3158) NVIDIA Systemsteuerung 331.58 (Version: 331.58) NVIDIA Update 9.3.21 (Version: 9.3.21) NVIDIA Update Components (Version: 9.3.21) NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9) OnlineFotoservice (x32 Version: 5.1.1) Opera 12.16 (x32 Version: 12.16.1860) Origin (x32 Version: 9.3.1.4482) Overwolf (x32 Version: 0.33.199) Path of Exile (x32 Version: 0.10.7.24409) Philips SPC210NC Webcam (x32 Version: 1.0.0.0) Philips VLounge (x32) piaip AppLocale (x32 Version: 1.0.0) PunkBuster Services (x32 Version: 0.991) RaidCall (x32 Version: 7.2.6-1.0.8500.17) Raptr (x32) Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6378) Service Pack 3 für SQL Server 2008 (KB2546951) (64-bit) (Version: 10.3.5500.0) SHIELD Streaming (Version: 1.6.53) Sicherheitsupdate für Microsoft Visual Studio 2010 Ultimate - DEU (KB2645410) (x32 Version: 1) Skype Click to Call (x32 Version: 5.9.9216) Skype™ 6.9 (x32 Version: 6.9.106) Smart Technology Programming Software 7.0.27.13 (Version: 7.0.27.13) Smite Closed Beta (x32 Version: 0.1.1113.1) Snap.Do (x32 Version: 1.47.1.11067) Spotify (HKCU Version: 0.9.0.128.g3134f863) Sql Server Customer Experience Improvement Program (Version: 10.3.5500.0) StarCraft II (x32) Steam (x32 Version: 1.0.0.0) System Requirements Lab Detection (x32 Version: 1.0.5.0) TeamViewer 8 (x32 Version: 8.0.22298) TERA (x32 Version: 7) Tunngle beta (x32) Unterstützungsdateien für Microsoft SQL Server 2008-Setup (Version: 10.3.5500.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Update for Microsoft Office Outlook 2007 Help (KB957246) (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition (x32) Update for Office 2007 (KB946691) (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) Visual Studio 2010 Prerequisites - English (Version: 10.0.40219) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 DEU (x32 Version: 4.0.8080.0) Warframe (x32 Version: 1.0.0) WCF RIA Services V1.0 SP1 (x32 Version: 4.1.60114.0) Web Deployment Tool (Version: 1.1.0618) WEBZEN Browser Extension (x32 Version: 1.01.020) WinRAR 5.00 (64-bit) (Version: 5.00.0) XFastUsb (x32) ==================== Restore Points ========================= 24-11-2013 11:38:39 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {04FA1ED6-74D1-4CBB-A801-55DA3538875F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-05] (Google Inc.) Task: {1435EB60-47BD-4DB9-8C7D-094B1137B252} - \Lyrics-Pal Update No Task File Task: {2A05493A-8428-4CF2-A95E-135CE322CC2D} - System32\Tasks\RunOW => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [2012-06-21] () Task: {38D2D7D3-9D80-46DC-9387-930C36886D30} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) Task: {9DA8E354-8D9F-44E3-852E-3D1D0A681C48} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-05] (Google Inc.) Task: {C13BA3FC-7A44-438A-B86B-28DC47F581ED} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000Core => C:\Users\MAGIC\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-03] (Google Inc.) Task: {F10BD363-E528-482C-B972-56E80B7B279A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated) Task: {F1F650F1-5D3F-4722-B9C5-57BF2A7B52CE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000UA => C:\Users\MAGIC\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-03] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000Core.job => C:\Users\MAGIC\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000UA.job => C:\Users\MAGIC\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-07-20 12:45 - 2011-03-18 16:51 - 00030208 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\imageformats\_old_qgif4.dll 2011-07-20 12:45 - 2011-03-18 16:51 - 00236032 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\imageformats\_old_qjpeg4.dll 2011-07-20 12:45 - 2013-10-24 16:49 - 00302056 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\directsound_win64.dll 2011-07-20 12:45 - 2013-10-24 16:49 - 00320488 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll 2013-07-10 16:19 - 2012-10-13 19:29 - 00020992 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\plugins\TS3MassMover.dll 2011-07-20 12:45 - 2013-10-24 16:49 - 00186344 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\plugins\appscanner_plugin.dll 2011-07-20 12:45 - 2013-10-24 16:49 - 00565224 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\plugins\clientquery_plugin.dll 2013-09-09 13:36 - 2013-10-24 16:49 - 00700904 _____ () G:\Program Files (x86)\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll 2012-04-18 17:43 - 1998-10-31 09:55 - 00005120 _____ () C:\Program Files (x86)\EXPERTool\TBManage.dll 2013-04-23 17:30 - 2013-10-24 18:45 - 00691200 _____ () D:\Download\Games\Steam\SDL2.dll 2013-03-08 00:13 - 2013-10-30 20:25 - 01123240 _____ () D:\Download\Games\Steam\bin\chromehtml.DLL 2013-03-08 00:13 - 2013-10-23 21:07 - 20625832 _____ () D:\Download\Games\Steam\bin\libcef.dll 2013-03-08 00:13 - 2013-06-15 00:49 - 01100800 _____ () D:\Download\Games\Steam\bin\avcodec-53.dll 2013-03-08 00:13 - 2013-06-15 00:49 - 00124416 _____ () D:\Download\Games\Steam\bin\avutil-51.dll 2013-03-08 00:13 - 2013-06-15 00:49 - 00192000 _____ () D:\Download\Games\Steam\bin\avformat-53.dll 2013-09-04 16:00 - 2013-11-23 13:53 - 00117760 _____ () G:\Riot Games Real\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.193\deploy\RiotLauncher.dll 2013-10-06 14:27 - 2013-10-06 14:27 - 00857600 _____ () C:\Program Files (x86)\Ss.Helper\psupport.dll 2013-11-14 23:02 - 2013-11-14 12:28 - 00702416 _____ () C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\libglesv2.dll 2013-11-14 23:02 - 2013-11-14 12:28 - 00099792 _____ () C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\libegl.dll 2013-11-14 23:02 - 2013-11-14 12:29 - 04055504 _____ () C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll 2013-11-14 23:02 - 2013-11-14 12:29 - 00399312 _____ () C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll 2013-11-14 23:02 - 2013-11-14 12:28 - 01619408 _____ () C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll 2013-11-14 23:02 - 2013-11-14 12:29 - 13582800 _____ () C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:373E1720 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: iSafeNetFilter Description: iSafeNetFilter Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: iSafeNetFilter Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Programmable Root Enumerator Description: Programming Support Class Guid: {678dcf40-e2e6-11d5-8cd5-e960089ea00a} Manufacturer: Mad Catz Service: SaiNtBus Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (11/24/2013 00:29:35 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/24/2013 03:43:57 AM) (Source: Application Hang) (User: ) Description: Programm SC2.exe, Version 2.0.11.26825 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: cf4 Startzeit: 01cee8bef0ef71fa Endzeit: 30 Anwendungspfad: G:\Program Files (x86)\StarCraft II\Versions\Base26490\SC2.exe Berichts-ID: 3259beca-54b2-11e3-857c-bc5ff4186d2f Error: (11/23/2013 01:55:08 PM) (Source: Application Hang) (User: ) Description: Programm rads_user_kernel.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1330 Startzeit: 01cee84b06ae2182 Endzeit: 2 Anwendungspfad: G:\Riot Games Real\League of Legends\RADS\system\rads_user_kernel.exe Berichts-ID: 75e450c6-543e-11e3-857c-bc5ff4186d2f Error: (11/23/2013 01:48:58 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/22/2013 03:49:54 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2013 05:04:05 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2013 01:26:31 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 04:53:54 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/19/2013 05:43:20 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/18/2013 04:54:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (11/24/2013 06:39:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 06:29:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 06:19:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 06:09:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 05:59:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 05:49:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 05:39:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 05:29:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 05:19:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (11/24/2013 05:09:13 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 51% Total physical RAM: 7414.68 MB Available physical RAM: 3591.89 MB Total Pagefile: 14827.54 MB Available Pagefile: 10023.31 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:62.4 GB) (Free:4.26 GB) NTFS Drive d: (Volume) (Fixed) (Total:869.01 GB) (Free:54.89 GB) NTFS Drive f: () (Fixed) (Total:64.06 GB) (Free:14.02 GB) NTFS Drive g: (Volume) (Fixed) (Total:401.5 GB) (Free:23.9 GB) NTFS Drive k: (Seagate Expansion Drive) (Fixed) (Total:2794.51 GB) (Free:1390.66 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 953D44FA) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=62 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=869 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 45294528) Partition 1: (Not Active) - (Size=64 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=402 GB) - (Type=07 NTFS) Attempted reading MBR returned 0 bytes. Could not read MBR for disk 2. ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 Ran by MAGIC (administrator) on MAGIC-PC on 24-11-2013 18:42:20 Running from C:\Users\MAGIC\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) D:\Download\Programme\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (TeamViewer GmbH) D:\Download\Programme\Version8\TeamViewer.exe (TeamViewer GmbH) D:\Download\Programme\Version8\tv_w32.exe (TeamViewer GmbH) D:\Download\Programme\Version8\tv_x64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Gainward Co.) C:\Program Files (x86)\EXPERTool\TBPANEL.exe (Valve Corporation) D:\Download\Games\Steam\Steam.exe (Flux Software LLC) C:\Users\MAGIC\AppData\Local\FluxSoftware\Flux\flux.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe () G:\Riot Games Real\League of Legends\RADS\system\rads_user_kernel.exe () G:\Riot Games Real\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.193\deploy\LoLLauncher.exe (TeamSpeak Systems GmbH) G:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe () G:\Riot Games Real\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.58\deploy\LolClient.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [6900024 2012-07-24] (Logitech Inc.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKCU\...\Run: [GAINWARD] - C:\Program Files (x86)\EXPERTool\TBPANEL.exe [2273608 2011-08-02] (Gainward Co.) HKCU\...\Run: [Steam] - D:\Download\Games\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKCU\...\Run: [F.lux] - C:\Users\MAGIC\AppData\Local\FluxSoftware\Flux\flux.exe [1013128 2013-10-15] (Flux Software LLC) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKCU\...\Run: [DisplayFusion] - C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7203712 2013-02-11] (Binary Fortress Software) HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 MountPoints2: {3c0babf7-bc9b-11e1-876e-bc5ff4186d2f} - K:\pushinst.exe MountPoints2: {4c576ba5-c1e1-11e2-a9d9-bc5ff4186d2f} - H:\Autorun.exe AppInit_DLLs: [ ] () AppInit_DLLs-x32: c:\progra~2\ssde96~1.hel\psupport.dll [857600 2013-10-06] () Startup: C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFB11C3DD7A55CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - G:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507 FF NewTab: about:blank FF SearchEngineOrder.1: Google FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Google FF Homepage: about:blank FF Keyword.URL: user_pref("keyword.URL", ""); FF DefaultSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @raidcall.en/RCplugin - C:\Users\MAGIC\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk - F:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @Webzen.com/NPBrowserExt - C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\MAGIC\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\MAGIC\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) FF Extension: Downlooad keeper - C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\detjmm@iia-.net FF Extension: Adblock Plus - C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR Extension: (ProxTube) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (YouTube) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (https://www.facebook.com/) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\celnaknmndcdcjcagffhbhciignkeokb\2013.6.9.21780_0 CHR Extension: (League of Legends stream browser) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmikndlmnfbgjppgganafponieclmjbm\0.0.10_0 CHR Extension: (Google Search) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (hxxp://chinurarete-subs.org/chinurarete/front) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gddacjooileimimhoadcieigiciaomkb\2013.6.9.21671_0 CHR Extension: (AdBlock) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.14_0 CHR Extension: (Downlooad keeper) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6 CHR Extension: (Google Wallet) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR StartMenuInternet: Google Chrome - c:\users\magic\appdata\local\google\chrome\application\chrome.exe ==================== Services (Whitelisted) ================= S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [484592 2013-09-28] (BitRaider, LLC) R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1243024 2013-02-11] (Binary Fortress Software) S3 HiPatchService; G:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2012-11-14] (Hi-Rez Studios) S3 Microsoft Office Groove Audit Service; F:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [65824 2006-10-27] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) S4 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [58345832 2011-09-22] (Microsoft Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2012-06-21] (Overwolf Ltd) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-28] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [431464 2011-09-22] (Microsoft Corporation) R2 TeamViewer8; D:\Download\Programme\Version8\TeamViewer_Service.exe [5087584 2013-10-01] (TeamViewer GmbH) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) S3 xsherlock; C:\Windows\SysWow64\xsherlock.xem [666720 2012-11-18] (Wellbia.com Co., Ltd.) S2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [x] ==================== Drivers (Whitelisted) ==================== S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-10] (DT Soft Ltd) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-04-18] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-04-18] (FNet Co., Ltd.) S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 SaiH5F0D; C:\Windows\System32\DRIVERS\SaiH5F0D.sys [171144 2007-05-01] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek) S3 SaiU5F0D; C:\Windows\System32\DRIVERS\SaiU5F0D.sys [34304 2007-05-01] (Saitek) S3 slb; G:\AeriaGames\ScarletBlade\avital\scarlb64.sys [81880 2013-04-12] () R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 TBPanel; No ImagePath R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 VSPerfDrv100; G:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [68440 2011-01-18] (Microsoft Corporation) S3 ZSMC301b; C:\Windows\System32\Drivers\usbVM31b.sys [432512 2006-06-06] (VM) S3 ALSysIO; \??\C:\Users\MAGIC\AppData\Local\Temp\ALSysIO64.sys [x] S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [x] S3 DIRECTIO; \??\C:\Program Files\PerformanceTest\DirectIo64.sys [x] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 GGSAFERDriver; \??\F:\Program Files (x86)\Garena Plus\Room\safedrv.sys [x] S3 iSafeKrnl; \??\C:\Program Files (x86)\iSafe\iSafeKrnl.sys [x] S1 iSafeNetFilter; \??\C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [x] S0 mv91xx; system32\DRIVERS\mv91xx.sys [x] S3 vtany; \??\C:\Windows\vtany.sys [x] S3 xhunter1; \??\C:\Windows\xhunter1.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-24 18:42 - 2013-11-24 18:42 - 00019376 _____ C:\Users\MAGIC\Downloads\FRST.txt 2013-11-24 18:41 - 2013-11-24 18:41 - 01958440 _____ (Farbar) C:\Users\MAGIC\Downloads\FRST64.exe 2013-11-24 18:41 - 2013-11-24 18:41 - 00000000 ____D C:\FRST 2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-21 18:37 - 2013-11-21 18:38 - 00017358 _____ C:\Users\MAGIC\Downloads\GeneralCharacterData_Legacy.ini 2013-11-13 01:45 - 2013-11-13 20:09 - 00000000 ____D C:\ProgramData\Tunngle 2013-11-13 01:45 - 2013-11-13 03:02 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Tunngle 2013-11-13 01:45 - 2013-11-13 01:46 - 00000000 ____D C:\Program Files (x86)\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000991 _____ C:\Users\Public\Desktop\Tunngle beta.lnk 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\Documents\Tunngle 2013-11-13 01:45 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys 2013-11-13 01:40 - 2013-11-13 01:40 - 04029596 _____ (Tunngle.net GmbH ) C:\Users\MAGIC\Downloads\Tunngle_Setup_v4.5.1.4.exe 2013-11-13 01:40 - 2013-11-13 01:40 - 00114579 _____ C:\Users\MAGIC\Downloads\Naruto.Shippuden.Ultimate.Ninja.3.Steamworks.Fix-RVTFiX(2).rar 2013-11-13 00:57 - 2013-11-13 01:05 - 129201056 _____ (Mad catz ) C:\Users\MAGIC\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-11-13 00:49 - 2013-11-13 00:50 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad (1).exe 2013-11-13 00:44 - 2013-11-13 00:44 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad.exe 2013-11-13 00:44 - 2007-05-01 15:48 - 00018512 _____ C:\Windows\system32\SaiD5F0D.pr0 2013-11-13 00:42 - 2013-11-13 00:42 - 04030936 _____ C:\Users\MAGIC\Downloads\installer_driver_saitek_p2600_1_51_32bit_Deutsch.exe 2013-11-13 00:34 - 2013-11-13 00:34 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EMU 2013-11-12 22:19 - 2013-11-12 22:19 - 00000000 ____D C:\Users\MAGIC\AppData\Local\NVIDIA Corporation 2013-11-12 20:01 - 2013-11-12 20:01 - 00000000 ____D C:\Users\MAGIC\AppData\Local\4kdownload.com 2013-11-12 19:55 - 2013-11-12 19:58 - 21544992 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kyoutubetomp3_2.5.exe 2013-11-12 19:54 - 2013-11-12 19:54 - 00524288 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kvideodownloader_3.0.exe 2013-11-11 00:41 - 2013-11-11 00:41 - 00278016 _____ C:\Users\MAGIC\Downloads\excelbern.exe 2013-11-10 17:23 - 2013-11-24 12:28 - 00003239 _____ C:\Windows\setupact.log 2013-11-10 17:23 - 2013-11-10 17:27 - 00002792 _____ C:\Windows\PFRO.log 2013-11-10 17:23 - 2013-11-10 17:23 - 00000000 _____ C:\Windows\setuperr.log 2013-11-10 17:07 - 2013-11-10 17:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\eCyber 2013-11-10 17:05 - 2013-11-10 17:27 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\iSafe 2013-11-10 17:05 - 2013-11-10 17:05 - 00000000 ____D C:\Windows\system32\log 2013-11-10 17:03 - 2013-11-10 17:03 - 00757864 _____ C:\Users\MAGIC\Downloads\yet_another_cleaner.exe 2013-11-07 23:22 - 2013-11-07 23:22 - 00000146 _____ C:\Users\MAGIC\Desktop\Sound - Verknüpfung.lnk 2013-11-06 17:50 - 2013-11-06 17:50 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 17:50 - 2013-11-06 17:50 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 17:49 - 2013-11-06 17:49 - 04379048 _____ (Piriform Ltd) C:\Users\MAGIC\Downloads\ccsetup407.exe 2013-11-06 17:44 - 2013-11-06 17:44 - 02347384 _____ (ESET) C:\Users\MAGIC\Downloads\esetsmartinstaller_enu.exe 2013-10-29 00:32 - 2013-11-08 21:47 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-10-29 00:32 - 2013-11-08 21:47 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-10-29 00:30 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-10-29 00:30 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-10-28 02:03 - 2013-10-28 02:03 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EA Games 2013-10-26 03:42 - 2013-10-26 03:42 - 03820328 _____ C:\Users\MAGIC\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-26 00:33 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-26 00:33 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-26 00:33 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-26 00:33 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-26 00:33 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-26 00:33 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-26 00:33 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-26 00:33 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-26 00:33 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-26 00:33 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-26 00:33 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-26 00:33 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-26 00:33 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-26 00:33 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-26 00:33 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-26 00:33 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-26 00:33 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-26 00:33 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-26 00:33 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-26 00:33 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-26 00:33 - 2013-07-12 11:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-26 00:33 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-26 00:33 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-26 00:33 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-26 00:33 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-26 00:33 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-26 00:33 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-26 00:33 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-26 00:33 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-26 00:33 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-26 00:33 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-26 00:33 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-26 00:33 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-26 00:33 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-26 00:33 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-26 00:33 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-26 00:33 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-26 00:33 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-26 00:33 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-26 00:33 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-26 00:33 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-26 00:32 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-26 00:32 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-26 00:31 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-26 00:31 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 22933280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 15858664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 12537632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-26 00:21 - 2013-10-16 01:48 - 11415232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 11362672 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 09516872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 09472600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-10-25 22:34 - 2013-10-28 02:03 - 00000000 ____D C:\Users\MAGIC\Documents\EA Games 2013-10-25 21:20 - 2013-10-25 21:20 - 00000894 _____ C:\Users\Public\Desktop\Dead Space 3.lnk ==================== One Month Modified Files and Folders ======= 2013-11-24 18:42 - 2013-11-24 18:42 - 00019376 _____ C:\Users\MAGIC\Downloads\FRST.txt 2013-11-24 18:41 - 2013-11-24 18:41 - 01958440 _____ (Farbar) C:\Users\MAGIC\Downloads\FRST64.exe 2013-11-24 18:41 - 2013-11-24 18:41 - 00000000 ____D C:\FRST 2013-11-24 18:39 - 2012-07-04 23:11 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\DisplayFusion 2013-11-24 17:59 - 2012-06-03 00:12 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000UA.job 2013-11-24 17:55 - 2013-03-05 13:29 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-24 17:49 - 2012-04-18 17:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-24 17:45 - 2012-04-18 17:23 - 02053027 _____ C:\Windows\WindowsUpdate.log 2013-11-24 12:35 - 2013-03-05 13:29 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-24 12:35 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-24 12:35 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-24 12:28 - 2013-11-10 17:23 - 00003239 _____ C:\Windows\setupact.log 2013-11-24 12:27 - 2012-11-18 14:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-24 12:27 - 2012-04-18 17:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-24 12:27 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-23 23:59 - 2012-06-03 00:12 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000Core.job 2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-21 18:38 - 2013-11-21 18:37 - 00017358 _____ C:\Users\MAGIC\Downloads\GeneralCharacterData_Legacy.ini 2013-11-20 01:03 - 2012-04-28 15:24 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Skype 2013-11-19 11:21 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-17 16:25 - 2013-08-16 11:55 - 00000000 ____D C:\Users\MAGIC\Documents\StarCraft II 2013-11-13 20:09 - 2013-11-13 01:45 - 00000000 ____D C:\ProgramData\Tunngle 2013-11-13 16:59 - 2012-04-19 12:33 - 00110064 _____ C:\Users\MAGIC\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-13 16:54 - 2009-07-14 05:45 - 00415104 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-13 03:02 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Tunngle 2013-11-13 01:46 - 2013-11-13 01:45 - 00000000 ____D C:\Program Files (x86)\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000991 _____ C:\Users\Public\Desktop\Tunngle beta.lnk 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\Documents\Tunngle 2013-11-13 01:40 - 2013-11-13 01:40 - 04029596 _____ (Tunngle.net GmbH ) C:\Users\MAGIC\Downloads\Tunngle_Setup_v4.5.1.4.exe 2013-11-13 01:40 - 2013-11-13 01:40 - 00114579 _____ C:\Users\MAGIC\Downloads\Naruto.Shippuden.Ultimate.Ninja.3.Steamworks.Fix-RVTFiX(2).rar 2013-11-13 01:05 - 2013-11-13 00:57 - 129201056 _____ (Mad catz ) C:\Users\MAGIC\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-11-13 00:50 - 2013-11-13 00:49 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad (1).exe 2013-11-13 00:44 - 2013-11-13 00:44 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad.exe 2013-11-13 00:42 - 2013-11-13 00:42 - 04030936 _____ C:\Users\MAGIC\Downloads\installer_driver_saitek_p2600_1_51_32bit_Deutsch.exe 2013-11-13 00:34 - 2013-11-13 00:34 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EMU 2013-11-12 22:19 - 2013-11-12 22:19 - 00000000 ____D C:\Users\MAGIC\AppData\Local\NVIDIA Corporation 2013-11-12 20:01 - 2013-11-12 20:01 - 00000000 ____D C:\Users\MAGIC\AppData\Local\4kdownload.com 2013-11-12 19:58 - 2013-11-12 19:55 - 21544992 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kyoutubetomp3_2.5.exe 2013-11-12 19:54 - 2013-11-12 19:54 - 00524288 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kvideodownloader_3.0.exe 2013-11-11 18:00 - 2012-11-18 14:53 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Mozilla 2013-11-11 00:41 - 2013-11-11 00:41 - 00278016 _____ C:\Users\MAGIC\Downloads\excelbern.exe 2013-11-10 18:02 - 2012-05-17 01:23 - 01777024 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-10 18:02 - 2011-04-12 08:43 - 00763004 _____ C:\Windows\system32\perfh007.dat 2013-11-10 18:02 - 2011-04-12 08:43 - 00173390 _____ C:\Windows\system32\perfc007.dat 2013-11-10 18:02 - 2009-07-14 06:13 - 01777024 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-10 17:27 - 2013-11-10 17:23 - 00002792 _____ C:\Windows\PFRO.log 2013-11-10 17:27 - 2013-11-10 17:05 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\iSafe 2013-11-10 17:23 - 2013-11-10 17:23 - 00000000 _____ C:\Windows\setuperr.log 2013-11-10 17:14 - 2013-10-21 12:22 - 00000000 ____D C:\Windows\Minidump 2013-11-10 17:10 - 2013-05-04 00:19 - 00000000 ____D C:\ProgramData\HappyCloud 2013-11-10 17:07 - 2013-11-10 17:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\eCyber 2013-11-10 17:05 - 2013-11-10 17:05 - 00000000 ____D C:\Windows\system32\log 2013-11-10 17:03 - 2013-11-10 17:03 - 00757864 _____ C:\Users\MAGIC\Downloads\yet_another_cleaner.exe 2013-11-08 21:47 - 2013-10-29 00:32 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-11-08 21:47 - 2013-10-29 00:32 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-11-07 23:22 - 2013-11-07 23:22 - 00000146 _____ C:\Users\MAGIC\Desktop\Sound - Verknüpfung.lnk 2013-11-07 23:19 - 2013-01-24 19:16 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Just Aion Launcher 2013-11-07 21:12 - 2013-08-04 11:32 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-06 17:50 - 2013-11-06 17:50 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 17:50 - 2013-11-06 17:50 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 17:49 - 2013-11-06 17:49 - 04379048 _____ (Piriform Ltd) C:\Users\MAGIC\Downloads\ccsetup407.exe 2013-11-06 17:44 - 2013-11-06 17:44 - 02347384 _____ (ESET) C:\Users\MAGIC\Downloads\esetsmartinstaller_enu.exe 2013-11-03 08:52 - 2012-06-23 04:18 - 00000000 ____D C:\Users\MAGIC\Documents\Visual Studio 2010 2013-11-02 20:39 - 2012-04-18 17:51 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-29 00:32 - 2012-04-18 17:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-10-29 00:32 - 2012-04-18 17:50 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-28 02:03 - 2013-10-28 02:03 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EA Games 2013-10-28 02:03 - 2013-10-25 22:34 - 00000000 ____D C:\Users\MAGIC\Documents\EA Games 2013-10-28 02:03 - 2013-08-26 16:06 - 00000000 ____D C:\ProgramData\Origin 2013-10-26 14:43 - 2012-12-11 13:40 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-10-26 14:43 - 2012-12-11 11:50 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-26 14:43 - 2012-12-11 11:50 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-26 14:42 - 2013-08-28 12:39 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-10-26 03:42 - 2013-10-26 03:42 - 03820328 _____ C:\Users\MAGIC\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-10-26 00:59 - 2012-04-18 17:26 - 00001421 _____ C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-26 00:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-10-26 00:55 - 2013-03-10 14:07 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-26 00:47 - 2013-10-26 00:47 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-26 00:45 - 2013-03-10 14:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2013-10-26 00:42 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini 2013-10-26 00:39 - 2013-09-21 10:59 - 00000000 ____D C:\Windows\system32\MRT 2013-10-26 00:37 - 2012-09-28 17:31 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-10-26 00:24 - 2012-08-27 18:57 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\.minecraft 2013-10-25 21:20 - 2013-10-25 21:20 - 00000894 _____ C:\Users\Public\Desktop\Dead Space 3.lnk Files to move or delete: ==================== C:\Users\MAGIC\AppData\Roaming\mBot.ini Some content of TEMP: ==================== C:\Users\MAGIC\AppData\Local\Temp\instloffer.exe C:\Users\MAGIC\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 17:39 ==================== End Of Log ============================ |
24.11.2013, 19:17 | #4 |
/// TB-Ausbilder | Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] In welchem Browser tritt dieses Problem denn auf? Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter AppInit_DLLs-x32: c:\progra~2\ssde96~1.hel\psupport.dll [857600 2013-10-06] () HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013 2013-11-10 17:07 - 2013-11-10 17:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\eCyber 2013-11-10 17:05 - 2013-11-10 17:27 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\iSafe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 ESET Online Scanner
Schritt 4 Starte noch einmal FRST.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
25.11.2013, 13:52 | #5 |
| Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Fixlog von FRST Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-11-2013 Ran by MAGIC at 2013-11-24 23:53:16 Run:1 Running from C:\Users\MAGIC\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs-x32: c:\progra~2\ssde96~1.hel\psupport.dll [857600 2013-10-06] () HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013 2013-11-10 17:07 - 2013-11-10 17:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\eCyber 2013-11-10 17:05 - 2013-11-10 17:27 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\iSafe ***************** HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully. C:\Users\MAGIC\AppData\Roaming\eCyber => Moved successfully. C:\Users\MAGIC\AppData\Roaming\iSafe => Moved successfully. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.24.11 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 MAGIC :: MAGIC-PC [Administrator] 25.11.2013 00:00:35 mbam-log-2013-11-25 (00-00-35).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 245313 Laufzeit: 4 Minute(n), 14 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 2 HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=0be01cfe-8d57-4faf-8188-edaa8ba5fa95&searchtype=ds&q={searchTerms}&installDate=10/08/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 1 C:\Users\MAGIC\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 6 C:\Program Files (x86)\Ss.Helper\psupport.dll (PUP.Optional.SProtect.A) -> Löschen bei Neustart. C:\Users\MAGIC\Downloads\DTLite4471-0333.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\MAGIC\Downloads\installer_driver_saitek_p2600_1_51_32bit_Deutsch.exe (PUP.Optional.VIT) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\MAGIC\Downloads\yet_another_cleaner.exe (PUP.Optional.Elex.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Windows\Installer\a305b.msi (PUP.Optional.SmartBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\MAGIC\AppData\Roaming\Minecraft.exe (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Log von ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3be65966738c674d8074890fa696fbbf # engine=16009 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-25 01:58:35 # local_time=2013-11-25 02:58:35 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 5558618 136974565 0 0 # scanned=286397 # found=4 # cleaned=0 # scan_time=9479 sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\$Recycle.Bin\S-1-5-21-3469555374-377849015-2099901113-1000\$RNQ1WF2\Quarantine\C\ProgramData\Downlooad keeper\2.dll.vir" sh=971D4E74DF2CBA083362F76FAD63E1421A86A8FB ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6\4F.js" sh=971D4E74DF2CBA083362F76FAD63E1421A86A8FB ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6\4F.js" sh=EEC343B653D7B12F3477FC74481B8BA299EF4F0F ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\extensions\detjmm@iia-.net\content\bg.js" # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3be65966738c674d8074890fa696fbbf # engine=16009 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-25 07:18:32 # local_time=2013-11-25 08:18:32 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 5577815 136993762 0 0 # scanned=834853 # found=5 # cleaned=0 # scan_time=15590 sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\$Recycle.Bin\S-1-5-21-3469555374-377849015-2099901113-1000\$RNQ1WF2\Quarantine\C\ProgramData\Downlooad keeper\2.dll.vir" sh=971D4E74DF2CBA083362F76FAD63E1421A86A8FB ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6\4F.js" sh=971D4E74DF2CBA083362F76FAD63E1421A86A8FB ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6\4F.js" sh=EEC343B653D7B12F3477FC74481B8BA299EF4F0F ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\extensions\detjmm@iia-.net\content\bg.js" sh=480FA2E02978E8173DE15B98EC3C8FEC9A4A424C ft=1 fh=1e3ce5e42604fd71 vn="a variant of Win32/Packed.VMProtect.AAD trojan" ac=I fn="G:\Games\Bulletstorm\Binaries\Win32\xlive.dll" FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 Ran by MAGIC (administrator) on MAGIC-PC on 25-11-2013 13:49:40 Running from C:\Users\MAGIC\Desktop\anti Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) D:\Download\Programme\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (TeamViewer GmbH) D:\Download\Programme\Version8\TeamViewer.exe (TeamViewer GmbH) D:\Download\Programme\Version8\tv_w32.exe (TeamViewer GmbH) D:\Download\Programme\Version8\tv_x64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Gainward Co.) C:\Program Files (x86)\EXPERTool\TBPANEL.exe (Valve Corporation) D:\Download\Games\Steam\Steam.exe (Flux Software LLC) C:\Users\MAGIC\AppData\Local\FluxSoftware\Flux\flux.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [6900024 2012-07-24] (Logitech Inc.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKCU\...\Run: [GAINWARD] - C:\Program Files (x86)\EXPERTool\TBPANEL.exe [2273608 2011-08-02] (Gainward Co.) HKCU\...\Run: [Steam] - D:\Download\Games\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKCU\...\Run: [F.lux] - C:\Users\MAGIC\AppData\Local\FluxSoftware\Flux\flux.exe [1013128 2013-10-15] (Flux Software LLC) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKCU\...\Run: [DisplayFusion] - C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7203712 2013-02-11] (Binary Fortress Software) HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 MountPoints2: {3c0babf7-bc9b-11e1-876e-bc5ff4186d2f} - K:\pushinst.exe MountPoints2: {4c576ba5-c1e1-11e2-a9d9-bc5ff4186d2f} - H:\Autorun.exe AppInit_DLLs: [ ] () Startup: C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFB11C3DD7A55CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - G:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507 FF NewTab: about:blank FF SearchEngineOrder.1: Google FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Google FF Homepage: about:blank FF Keyword.URL: user_pref("keyword.URL", ""); FF DefaultSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @raidcall.en/RCplugin - C:\Users\MAGIC\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk - F:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @Webzen.com/NPBrowserExt - C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\MAGIC\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\MAGIC\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) FF Extension: Downlooad keeper - C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\detjmm@iia-.net FF Extension: Adblock Plus - C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: about:blank CHR RestoreOnStartup: "about:blank" CHR DefaultSearchURL: (Google) - hxxp://www.google.com/search?q={searchTerms} CHR DefaultSuggestURL: (Google) - "suggest_url": "", CHR Plugin: (Shockwave Flash) - C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (WEBZEN Browser Extension) - C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN) CHR Plugin: (Happy Cloud Plugin) - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Extension: (ProxTube) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (YouTube) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (https://www.facebook.com/) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\celnaknmndcdcjcagffhbhciignkeokb\2013.6.9.21780_0 CHR Extension: (League of Legends stream browser) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmikndlmnfbgjppgganafponieclmjbm\0.0.10_0 CHR Extension: (Google Search) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (hxxp://chinurarete-subs.org/chinurarete/front) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gddacjooileimimhoadcieigiciaomkb\2013.6.9.21671_0 CHR Extension: (AdBlock) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.14_0 CHR Extension: (Downlooad keeper) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6 CHR Extension: (Google Wallet) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR StartMenuInternet: Google Chrome - c:\users\magic\appdata\local\google\chrome\application\chrome.exe ==================== Services (Whitelisted) ================= S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [484592 2013-09-28] (BitRaider, LLC) R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1243024 2013-02-11] (Binary Fortress Software) S3 HiPatchService; G:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2012-11-14] (Hi-Rez Studios) S3 Microsoft Office Groove Audit Service; F:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [65824 2006-10-27] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) S4 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [58345832 2011-09-22] (Microsoft Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2012-06-21] (Overwolf Ltd) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-28] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [431464 2011-09-22] (Microsoft Corporation) R2 TeamViewer8; D:\Download\Programme\Version8\TeamViewer_Service.exe [5087584 2013-10-01] (TeamViewer GmbH) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) S3 xsherlock; C:\Windows\SysWow64\xsherlock.xem [666720 2012-11-18] (Wellbia.com Co., Ltd.) S2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [x] ==================== Drivers (Whitelisted) ==================== S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-10] (DT Soft Ltd) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-04-18] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-04-18] (FNet Co., Ltd.) S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 SaiH5F0D; C:\Windows\System32\DRIVERS\SaiH5F0D.sys [171144 2007-05-01] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek) S3 SaiU5F0D; C:\Windows\System32\DRIVERS\SaiU5F0D.sys [34304 2007-05-01] (Saitek) S3 slb; G:\AeriaGames\ScarletBlade\avital\scarlb64.sys [81880 2013-04-12] () R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 TBPanel; No ImagePath R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 VSPerfDrv100; G:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [68440 2011-01-18] (Microsoft Corporation) S3 ZSMC301b; C:\Windows\System32\Drivers\usbVM31b.sys [432512 2006-06-06] (VM) S3 ALSysIO; \??\C:\Users\MAGIC\AppData\Local\Temp\ALSysIO64.sys [x] S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [x] S3 DIRECTIO; \??\C:\Program Files\PerformanceTest\DirectIo64.sys [x] R3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 GGSAFERDriver; \??\F:\Program Files (x86)\Garena Plus\Room\safedrv.sys [x] S3 iSafeKrnl; \??\C:\Program Files (x86)\iSafe\iSafeKrnl.sys [x] S1 iSafeNetFilter; \??\C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [x] S0 mv91xx; system32\DRIVERS\mv91xx.sys [x] S3 vtany; \??\C:\Windows\vtany.sys [x] S3 xhunter1; \??\C:\Windows\xhunter1.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-25 03:08 - 2013-11-25 03:19 - 00000000 ____D C:\Users\MAGIC\Documents\DragonNest 2013-11-25 03:07 - 2013-11-25 03:07 - 00001022 _____ C:\Users\MAGIC\Desktop\Dragon Nest Europe.lnk 2013-11-25 03:07 - 2013-11-25 03:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SDGi Europe 2013-11-24 23:59 - 2013-11-24 23:59 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-24 23:58 - 2013-11-24 23:58 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-24 23:58 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-24 18:41 - 2013-11-24 18:41 - 00000000 ____D C:\FRST 2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-21 18:37 - 2013-11-21 18:38 - 00017358 _____ C:\Users\MAGIC\Downloads\GeneralCharacterData_Legacy.ini 2013-11-13 01:45 - 2013-11-13 20:09 - 00000000 ____D C:\ProgramData\Tunngle 2013-11-13 01:45 - 2013-11-13 03:02 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Tunngle 2013-11-13 01:45 - 2013-11-13 01:46 - 00000000 ____D C:\Program Files (x86)\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000991 _____ C:\Users\Public\Desktop\Tunngle beta.lnk 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\Documents\Tunngle 2013-11-13 01:45 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys 2013-11-13 01:40 - 2013-11-13 01:40 - 04029596 _____ (Tunngle.net GmbH ) C:\Users\MAGIC\Downloads\Tunngle_Setup_v4.5.1.4.exe 2013-11-13 01:40 - 2013-11-13 01:40 - 00114579 _____ C:\Users\MAGIC\Downloads\Naruto.Shippuden.Ultimate.Ninja.3.Steamworks.Fix-RVTFiX(2).rar 2013-11-13 00:57 - 2013-11-13 01:05 - 129201056 _____ (Mad catz ) C:\Users\MAGIC\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-11-13 00:49 - 2013-11-13 00:50 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad (1).exe 2013-11-13 00:44 - 2013-11-13 00:44 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad.exe 2013-11-13 00:44 - 2007-05-01 15:48 - 00018512 _____ C:\Windows\system32\SaiD5F0D.pr0 2013-11-13 00:34 - 2013-11-13 00:34 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EMU 2013-11-12 22:19 - 2013-11-12 22:19 - 00000000 ____D C:\Users\MAGIC\AppData\Local\NVIDIA Corporation 2013-11-12 20:01 - 2013-11-12 20:01 - 00000000 ____D C:\Users\MAGIC\AppData\Local\4kdownload.com 2013-11-12 19:55 - 2013-11-12 19:58 - 21544992 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kyoutubetomp3_2.5.exe 2013-11-12 19:54 - 2013-11-12 19:54 - 00524288 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kvideodownloader_3.0.exe 2013-11-11 00:41 - 2013-11-11 00:41 - 00278016 _____ C:\Users\MAGIC\Downloads\excelbern.exe 2013-11-10 17:23 - 2013-11-25 03:02 - 00003911 _____ C:\Windows\setupact.log 2013-11-10 17:23 - 2013-11-25 00:07 - 00004314 _____ C:\Windows\PFRO.log 2013-11-10 17:23 - 2013-11-10 17:23 - 00000000 _____ C:\Windows\setuperr.log 2013-11-10 17:05 - 2013-11-10 17:05 - 00000000 ____D C:\Windows\system32\log 2013-11-07 23:22 - 2013-11-07 23:22 - 00000146 _____ C:\Users\MAGIC\Desktop\Sound - Verknüpfung.lnk 2013-11-06 17:50 - 2013-11-06 17:50 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 17:50 - 2013-11-06 17:50 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 17:49 - 2013-11-06 17:49 - 04379048 _____ (Piriform Ltd) C:\Users\MAGIC\Downloads\ccsetup407.exe 2013-11-06 17:44 - 2013-11-06 17:44 - 02347384 _____ (ESET) C:\Users\MAGIC\Downloads\esetsmartinstaller_enu.exe 2013-10-29 00:32 - 2013-11-08 21:47 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-10-29 00:32 - 2013-11-08 21:47 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-10-29 00:30 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-10-29 00:30 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-10-28 02:03 - 2013-10-28 02:03 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EA Games 2013-10-26 03:42 - 2013-10-26 03:42 - 03820328 _____ C:\Users\MAGIC\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-26 00:33 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-26 00:33 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-26 00:33 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-26 00:33 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-26 00:33 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-26 00:33 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-26 00:33 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-26 00:33 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-26 00:33 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-26 00:33 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-26 00:33 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-26 00:33 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-26 00:33 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-26 00:33 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-26 00:33 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-26 00:33 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-26 00:33 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-26 00:33 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-26 00:33 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-26 00:33 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-26 00:33 - 2013-07-12 11:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-26 00:33 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-26 00:33 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-26 00:33 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-26 00:33 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-26 00:33 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-26 00:33 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-26 00:33 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-26 00:33 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-26 00:33 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-26 00:33 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-26 00:33 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-26 00:33 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-26 00:33 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-26 00:33 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-26 00:33 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-26 00:33 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-26 00:33 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-26 00:33 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-26 00:33 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-26 00:33 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-26 00:32 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-26 00:32 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-26 00:31 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-26 00:31 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 22933280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 15858664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 12537632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-26 00:21 - 2013-10-16 01:48 - 11415232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 11362672 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 09516872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 09472600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll ==================== One Month Modified Files and Folders ======= 2013-11-25 13:49 - 2013-06-15 15:07 - 00000000 ____D C:\Users\MAGIC\Desktop\anti 2013-11-25 13:49 - 2012-04-18 17:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-25 13:48 - 2012-07-04 23:11 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\DisplayFusion 2013-11-25 12:59 - 2012-06-03 00:12 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000UA.job 2013-11-25 12:55 - 2013-03-05 13:29 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-25 06:37 - 2012-04-18 17:23 - 01055718 _____ C:\Windows\WindowsUpdate.log 2013-11-25 03:19 - 2013-11-25 03:08 - 00000000 ____D C:\Users\MAGIC\Documents\DragonNest 2013-11-25 03:10 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-25 03:10 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-25 03:07 - 2013-11-25 03:07 - 00001022 _____ C:\Users\MAGIC\Desktop\Dragon Nest Europe.lnk 2013-11-25 03:07 - 2013-11-25 03:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SDGi Europe 2013-11-25 03:02 - 2013-11-10 17:23 - 00003911 _____ C:\Windows\setupact.log 2013-11-25 03:00 - 2013-03-05 13:29 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-25 03:00 - 2012-04-18 17:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-25 03:00 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-25 00:07 - 2013-11-10 17:23 - 00004314 _____ C:\Windows\PFRO.log 2013-11-25 00:07 - 2013-10-18 15:11 - 00000000 ____D C:\Program Files (x86)\Ss.Helper 2013-11-24 23:59 - 2013-11-24 23:59 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-24 23:59 - 2012-06-03 00:12 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000Core.job 2013-11-24 23:58 - 2013-11-24 23:58 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-24 18:41 - 2013-11-24 18:41 - 00000000 ____D C:\FRST 2013-11-24 12:27 - 2012-11-18 14:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-21 18:38 - 2013-11-21 18:37 - 00017358 _____ C:\Users\MAGIC\Downloads\GeneralCharacterData_Legacy.ini 2013-11-20 01:03 - 2012-04-28 15:24 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Skype 2013-11-19 11:21 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-17 16:25 - 2013-08-16 11:55 - 00000000 ____D C:\Users\MAGIC\Documents\StarCraft II 2013-11-13 20:09 - 2013-11-13 01:45 - 00000000 ____D C:\ProgramData\Tunngle 2013-11-13 16:59 - 2012-04-19 12:33 - 00110064 _____ C:\Users\MAGIC\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-13 16:54 - 2009-07-14 05:45 - 00415104 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-13 03:02 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Tunngle 2013-11-13 01:46 - 2013-11-13 01:45 - 00000000 ____D C:\Program Files (x86)\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000991 _____ C:\Users\Public\Desktop\Tunngle beta.lnk 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\Documents\Tunngle 2013-11-13 01:40 - 2013-11-13 01:40 - 04029596 _____ (Tunngle.net GmbH ) C:\Users\MAGIC\Downloads\Tunngle_Setup_v4.5.1.4.exe 2013-11-13 01:05 - 2013-11-13 00:57 - 129201056 _____ (Mad catz ) C:\Users\MAGIC\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-11-13 00:50 - 2013-11-13 00:49 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad (1).exe 2013-11-13 00:44 - 2013-11-13 00:44 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad.exe 2013-11-13 00:34 - 2013-11-13 00:34 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EMU 2013-11-12 22:19 - 2013-11-12 22:19 - 00000000 ____D C:\Users\MAGIC\AppData\Local\NVIDIA Corporation 2013-11-12 20:01 - 2013-11-12 20:01 - 00000000 ____D C:\Users\MAGIC\AppData\Local\4kdownload.com 2013-11-12 19:58 - 2013-11-12 19:55 - 21544992 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kyoutubetomp3_2.5.exe 2013-11-12 19:54 - 2013-11-12 19:54 - 00524288 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kvideodownloader_3.0.exe 2013-11-11 18:00 - 2012-11-18 14:53 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Mozilla 2013-11-11 00:41 - 2013-11-11 00:41 - 00278016 _____ C:\Users\MAGIC\Downloads\excelbern.exe 2013-11-10 18:02 - 2012-05-17 01:23 - 01777024 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-10 18:02 - 2011-04-12 08:43 - 00763004 _____ C:\Windows\system32\perfh007.dat 2013-11-10 18:02 - 2011-04-12 08:43 - 00173390 _____ C:\Windows\system32\perfc007.dat 2013-11-10 18:02 - 2009-07-14 06:13 - 01777024 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-10 17:23 - 2013-11-10 17:23 - 00000000 _____ C:\Windows\setuperr.log 2013-11-10 17:14 - 2013-10-21 12:22 - 00000000 ____D C:\Windows\Minidump 2013-11-10 17:10 - 2013-05-04 00:19 - 00000000 ____D C:\ProgramData\HappyCloud 2013-11-10 17:05 - 2013-11-10 17:05 - 00000000 ____D C:\Windows\system32\log 2013-11-08 21:47 - 2013-10-29 00:32 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-11-08 21:47 - 2013-10-29 00:32 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-11-07 23:22 - 2013-11-07 23:22 - 00000146 _____ C:\Users\MAGIC\Desktop\Sound - Verknüpfung.lnk 2013-11-07 23:19 - 2013-01-24 19:16 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Just Aion Launcher 2013-11-07 21:12 - 2013-08-04 11:32 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-06 17:50 - 2013-11-06 17:50 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 17:50 - 2013-11-06 17:50 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 17:49 - 2013-11-06 17:49 - 04379048 _____ (Piriform Ltd) C:\Users\MAGIC\Downloads\ccsetup407.exe 2013-11-06 17:44 - 2013-11-06 17:44 - 02347384 _____ (ESET) C:\Users\MAGIC\Downloads\esetsmartinstaller_enu.exe 2013-11-03 08:52 - 2012-06-23 04:18 - 00000000 ____D C:\Users\MAGIC\Documents\Visual Studio 2010 2013-11-02 20:39 - 2012-04-18 17:51 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-29 00:32 - 2012-04-18 17:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-10-29 00:32 - 2012-04-18 17:50 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-28 02:03 - 2013-10-28 02:03 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EA Games 2013-10-28 02:03 - 2013-10-25 22:34 - 00000000 ____D C:\Users\MAGIC\Documents\EA Games 2013-10-28 02:03 - 2013-08-26 16:06 - 00000000 ____D C:\ProgramData\Origin 2013-10-26 14:43 - 2012-12-11 13:40 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-10-26 14:43 - 2012-12-11 11:50 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-26 14:43 - 2012-12-11 11:50 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-26 14:42 - 2013-08-28 12:39 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-10-26 03:42 - 2013-10-26 03:42 - 03820328 _____ C:\Users\MAGIC\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-10-26 00:59 - 2012-04-18 17:26 - 00001421 _____ C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-26 00:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-10-26 00:55 - 2013-03-10 14:07 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-26 00:47 - 2013-10-26 00:47 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-26 00:45 - 2013-03-10 14:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2013-10-26 00:42 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini 2013-10-26 00:39 - 2013-09-21 10:59 - 00000000 ____D C:\Windows\system32\MRT 2013-10-26 00:37 - 2012-09-28 17:31 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-10-26 00:24 - 2012-08-27 18:57 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\.minecraft Files to move or delete: ==================== C:\Users\MAGIC\AppData\Roaming\mBot.ini Some content of TEMP: ==================== C:\Users\MAGIC\AppData\Local\Temp\instloffer.exe C:\Users\MAGIC\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 17:39 ==================== End Of Log ============================ --- --- --- |
25.11.2013, 14:42 | #6 |
/// TB-Ausbilder | Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Ist das Problem nach diesem Fix verschwunden? Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter S2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [x] FF Extension: Downlooad keeper - C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\detjmm@iia-.net CHR Extension: (Downlooad keeper) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6 CHR Extension: (Downlooad keeper) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Starte noch einmal FRST.
__________________ --> Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] |
25.11.2013, 15:17 | #7 |
| Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Fixlog Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-11-2013 Ran by MAGIC at 2013-11-25 15:15:31 Run:2 Running from C:\Users\MAGIC\Desktop\anti Boot Mode: Normal ============================================== Content of fixlist: ***************** S2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [x] FF Extension: Downlooad keeper - C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\detjmm@iia-.net CHR Extension: (Downlooad keeper) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6 CHR Extension: (Downlooad keeper) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6 ***************** iSafeService => Service deleted successfully. C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\detjmm@iia-.net => Moved successfully. C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim => Moved successfully. CHR Extension: (Downlooad keeper) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\njnnalfmfgnjbemlhcnicjbmklnaonim\1.6 directory not found. ==== End of Fixlog ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 Ran by MAGIC (administrator) on MAGIC-PC on 25-11-2013 15:15:41 Running from C:\Users\MAGIC\Desktop\anti Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) D:\Download\Programme\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (TeamViewer GmbH) D:\Download\Programme\Version8\TeamViewer.exe (TeamViewer GmbH) D:\Download\Programme\Version8\tv_w32.exe (TeamViewer GmbH) D:\Download\Programme\Version8\tv_x64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Gainward Co.) C:\Program Files (x86)\EXPERTool\TBPANEL.exe (Valve Corporation) D:\Download\Games\Steam\Steam.exe (Flux Software LLC) C:\Users\MAGIC\AppData\Local\FluxSoftware\Flux\flux.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (TeamSpeak Systems GmbH) G:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe (Microsoft Corporation) C:\Windows\System32\SndVol.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [6900024 2012-07-24] (Logitech Inc.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKCU\...\Run: [GAINWARD] - C:\Program Files (x86)\EXPERTool\TBPANEL.exe [2273608 2011-08-02] (Gainward Co.) HKCU\...\Run: [Steam] - D:\Download\Games\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKCU\...\Run: [F.lux] - C:\Users\MAGIC\AppData\Local\FluxSoftware\Flux\flux.exe [1013128 2013-10-15] (Flux Software LLC) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKCU\...\Run: [DisplayFusion] - C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7203712 2013-02-11] (Binary Fortress Software) HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 MountPoints2: {3c0babf7-bc9b-11e1-876e-bc5ff4186d2f} - K:\pushinst.exe MountPoints2: {4c576ba5-c1e1-11e2-a9d9-bc5ff4186d2f} - H:\Autorun.exe AppInit_DLLs: [ ] () Startup: C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFB11C3DD7A55CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - G:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507 FF NewTab: about:blank FF SearchEngineOrder.1: Google FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF SelectedSearchEngine: Google FF Homepage: about:blank FF Keyword.URL: user_pref("keyword.URL", ""); FF DefaultSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @raidcall.en/RCplugin - C:\Users\MAGIC\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall) FF Plugin-x32: @t.garena.com/garenatalk - F:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @Webzen.com/NPBrowserExt - C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\MAGIC\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\MAGIC\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\MAGIC\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) FF Extension: Adblock Plus - C:\Users\MAGIC\AppData\Roaming\Mozilla\Firefox\Profiles\9h08m0kx.default-1379260108507\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: about:blank CHR RestoreOnStartup: "about:blank" CHR DefaultSearchURL: (Google) - hxxp://www.google.com/search?q={searchTerms} CHR DefaultSuggestURL: (Google) - "suggest_url": "", CHR Plugin: (Shockwave Flash) - C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\MAGIC\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (WEBZEN Browser Extension) - C:\Program Files (x86)\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN) CHR Plugin: (Happy Cloud Plugin) - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Extension: (ProxTube) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek\1.2.4_0 CHR Extension: (YouTube) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (https://www.facebook.com/) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\celnaknmndcdcjcagffhbhciignkeokb\2013.6.9.21780_0 CHR Extension: (League of Legends stream browser) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmikndlmnfbgjppgganafponieclmjbm\0.0.10_0 CHR Extension: (Google Search) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (hxxp://chinurarete-subs.org/chinurarete/front) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gddacjooileimimhoadcieigiciaomkb\2013.6.9.21671_0 CHR Extension: (AdBlock) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.14_0 CHR Extension: (Google Wallet) - C:\Users\MAGIC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR StartMenuInternet: Google Chrome - c:\users\magic\appdata\local\google\chrome\application\chrome.exe ==================== Services (Whitelisted) ================= S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [484592 2013-09-28] (BitRaider, LLC) R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1243024 2013-02-11] (Binary Fortress Software) S3 HiPatchService; G:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2012-11-14] (Hi-Rez Studios) S3 Microsoft Office Groove Audit Service; F:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [65824 2006-10-27] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) S4 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [58345832 2011-09-22] (Microsoft Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2012-06-21] (Overwolf Ltd) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-08-28] () S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [431464 2011-09-22] (Microsoft Corporation) R2 TeamViewer8; D:\Download\Programme\Version8\TeamViewer_Service.exe [5087584 2013-10-01] (TeamViewer GmbH) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) S3 xsherlock; C:\Windows\SysWow64\xsherlock.xem [666720 2012-11-18] (Wellbia.com Co., Ltd.) ==================== Drivers (Whitelisted) ==================== S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-10] (DT Soft Ltd) S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-04-18] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-04-18] (FNet Co., Ltd.) S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 SaiH5F0D; C:\Windows\System32\DRIVERS\SaiH5F0D.sys [171144 2007-05-01] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek) S3 SaiU5F0D; C:\Windows\System32\DRIVERS\SaiU5F0D.sys [34304 2007-05-01] (Saitek) S3 slb; G:\AeriaGames\ScarletBlade\avital\scarlb64.sys [81880 2013-04-12] () R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 TBPanel; No ImagePath R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 VSPerfDrv100; G:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [68440 2011-01-18] (Microsoft Corporation) S3 ZSMC301b; C:\Windows\System32\Drivers\usbVM31b.sys [432512 2006-06-06] (VM) S3 ALSysIO; \??\C:\Users\MAGIC\AppData\Local\Temp\ALSysIO64.sys [x] S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [x] S3 DIRECTIO; \??\C:\Program Files\PerformanceTest\DirectIo64.sys [x] R3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 GGSAFERDriver; \??\F:\Program Files (x86)\Garena Plus\Room\safedrv.sys [x] S3 iSafeKrnl; \??\C:\Program Files (x86)\iSafe\iSafeKrnl.sys [x] S1 iSafeNetFilter; \??\C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [x] S4 iSafeService; S0 mv91xx; system32\DRIVERS\mv91xx.sys [x] S3 vtany; \??\C:\Windows\vtany.sys [x] S3 xhunter1; \??\C:\Windows\xhunter1.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-25 03:08 - 2013-11-25 03:19 - 00000000 ____D C:\Users\MAGIC\Documents\DragonNest 2013-11-25 03:07 - 2013-11-25 03:07 - 00001022 _____ C:\Users\MAGIC\Desktop\Dragon Nest Europe.lnk 2013-11-25 03:07 - 2013-11-25 03:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SDGi Europe 2013-11-24 23:59 - 2013-11-24 23:59 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-24 23:58 - 2013-11-24 23:58 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-24 23:58 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-24 18:41 - 2013-11-24 18:41 - 00000000 ____D C:\FRST 2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-21 18:37 - 2013-11-21 18:38 - 00017358 _____ C:\Users\MAGIC\Downloads\GeneralCharacterData_Legacy.ini 2013-11-13 01:45 - 2013-11-13 20:09 - 00000000 ____D C:\ProgramData\Tunngle 2013-11-13 01:45 - 2013-11-13 03:02 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Tunngle 2013-11-13 01:45 - 2013-11-13 01:46 - 00000000 ____D C:\Program Files (x86)\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000991 _____ C:\Users\Public\Desktop\Tunngle beta.lnk 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\Documents\Tunngle 2013-11-13 01:45 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys 2013-11-13 01:40 - 2013-11-13 01:40 - 04029596 _____ (Tunngle.net GmbH ) C:\Users\MAGIC\Downloads\Tunngle_Setup_v4.5.1.4.exe 2013-11-13 01:40 - 2013-11-13 01:40 - 00114579 _____ C:\Users\MAGIC\Downloads\Naruto.Shippuden.Ultimate.Ninja.3.Steamworks.Fix-RVTFiX(2).rar 2013-11-13 00:57 - 2013-11-13 01:05 - 129201056 _____ (Mad catz ) C:\Users\MAGIC\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-11-13 00:49 - 2013-11-13 00:50 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad (1).exe 2013-11-13 00:44 - 2013-11-13 00:44 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad.exe 2013-11-13 00:44 - 2007-05-01 15:48 - 00018512 _____ C:\Windows\system32\SaiD5F0D.pr0 2013-11-13 00:34 - 2013-11-13 00:34 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EMU 2013-11-12 22:19 - 2013-11-12 22:19 - 00000000 ____D C:\Users\MAGIC\AppData\Local\NVIDIA Corporation 2013-11-12 20:01 - 2013-11-12 20:01 - 00000000 ____D C:\Users\MAGIC\AppData\Local\4kdownload.com 2013-11-12 19:55 - 2013-11-12 19:58 - 21544992 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kyoutubetomp3_2.5.exe 2013-11-12 19:54 - 2013-11-12 19:54 - 00524288 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kvideodownloader_3.0.exe 2013-11-11 00:41 - 2013-11-11 00:41 - 00278016 _____ C:\Users\MAGIC\Downloads\excelbern.exe 2013-11-10 17:23 - 2013-11-25 03:02 - 00003911 _____ C:\Windows\setupact.log 2013-11-10 17:23 - 2013-11-25 00:07 - 00004314 _____ C:\Windows\PFRO.log 2013-11-10 17:23 - 2013-11-10 17:23 - 00000000 _____ C:\Windows\setuperr.log 2013-11-10 17:05 - 2013-11-10 17:05 - 00000000 ____D C:\Windows\system32\log 2013-11-07 23:22 - 2013-11-07 23:22 - 00000146 _____ C:\Users\MAGIC\Desktop\Sound - Verknüpfung.lnk 2013-11-06 17:50 - 2013-11-06 17:50 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 17:50 - 2013-11-06 17:50 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 17:49 - 2013-11-06 17:49 - 04379048 _____ (Piriform Ltd) C:\Users\MAGIC\Downloads\ccsetup407.exe 2013-11-06 17:44 - 2013-11-06 17:44 - 02347384 _____ (ESET) C:\Users\MAGIC\Downloads\esetsmartinstaller_enu.exe 2013-10-29 00:32 - 2013-11-08 21:47 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-10-29 00:32 - 2013-11-08 21:47 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-10-29 00:30 - 2013-09-28 00:01 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-10-29 00:30 - 2013-09-28 00:01 - 00028960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-10-28 02:03 - 2013-10-28 02:03 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EA Games 2013-10-26 03:42 - 2013-10-26 03:42 - 03820328 _____ C:\Users\MAGIC\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-26 00:33 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-26 00:33 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-26 00:33 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-26 00:33 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-26 00:33 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-26 00:33 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-26 00:33 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-26 00:33 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-26 00:33 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-26 00:33 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-26 00:33 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-26 00:33 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-26 00:33 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-26 00:33 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-26 00:33 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-26 00:33 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-26 00:33 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-26 00:33 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-26 00:33 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-26 00:33 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-26 00:33 - 2013-07-12 11:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-26 00:33 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-26 00:33 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-26 00:33 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-26 00:33 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-26 00:33 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-26 00:33 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-26 00:33 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-26 00:33 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-26 00:33 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-26 00:33 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-26 00:33 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-26 00:33 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-26 00:33 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-26 00:33 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-26 00:33 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-26 00:33 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-26 00:33 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-26 00:33 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-26 00:33 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-26 00:33 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-26 00:32 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-26 00:32 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-26 00:31 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-26 00:31 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 22933280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 15858664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 12537632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-26 00:21 - 2013-10-16 01:48 - 11415232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 11362672 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 09516872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 09472600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-10-26 00:21 - 2013-10-16 01:48 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll ==================== One Month Modified Files and Folders ======= 2013-11-25 15:15 - 2013-06-15 15:07 - 00000000 ____D C:\Users\MAGIC\Desktop\anti 2013-11-25 15:08 - 2012-07-04 23:11 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\DisplayFusion 2013-11-25 14:59 - 2012-06-03 00:12 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000UA.job 2013-11-25 14:55 - 2013-03-05 13:29 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-25 14:49 - 2012-04-18 17:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-25 06:37 - 2012-04-18 17:23 - 01055718 _____ C:\Windows\WindowsUpdate.log 2013-11-25 03:19 - 2013-11-25 03:08 - 00000000 ____D C:\Users\MAGIC\Documents\DragonNest 2013-11-25 03:10 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-25 03:10 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-25 03:07 - 2013-11-25 03:07 - 00001022 _____ C:\Users\MAGIC\Desktop\Dragon Nest Europe.lnk 2013-11-25 03:07 - 2013-11-25 03:07 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SDGi Europe 2013-11-25 03:02 - 2013-11-10 17:23 - 00003911 _____ C:\Windows\setupact.log 2013-11-25 03:00 - 2013-03-05 13:29 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-25 03:00 - 2012-04-18 17:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-25 03:00 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-25 00:07 - 2013-11-10 17:23 - 00004314 _____ C:\Windows\PFRO.log 2013-11-25 00:07 - 2013-10-18 15:11 - 00000000 ____D C:\Program Files (x86)\Ss.Helper 2013-11-24 23:59 - 2013-11-24 23:59 - 00000000 ____D C:\Program Files (x86)\ESET 2013-11-24 23:59 - 2012-06-03 00:12 - 00001068 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3469555374-377849015-2099901113-1000Core.job 2013-11-24 23:58 - 2013-11-24 23:58 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-24 23:58 - 2013-11-24 23:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-24 18:41 - 2013-11-24 18:41 - 00000000 ____D C:\FRST 2013-11-24 12:27 - 2012-11-18 14:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-21 20:12 - 2013-11-21 20:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-21 18:38 - 2013-11-21 18:37 - 00017358 _____ C:\Users\MAGIC\Downloads\GeneralCharacterData_Legacy.ini 2013-11-20 01:03 - 2012-04-28 15:24 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Skype 2013-11-19 11:21 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-17 16:25 - 2013-08-16 11:55 - 00000000 ____D C:\Users\MAGIC\Documents\StarCraft II 2013-11-13 20:09 - 2013-11-13 01:45 - 00000000 ____D C:\ProgramData\Tunngle 2013-11-13 16:59 - 2012-04-19 12:33 - 00110064 _____ C:\Users\MAGIC\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-13 16:54 - 2009-07-14 05:45 - 00415104 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-13 03:02 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Tunngle 2013-11-13 01:46 - 2013-11-13 01:45 - 00000000 ____D C:\Program Files (x86)\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000991 _____ C:\Users\Public\Desktop\Tunngle beta.lnk 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\Public\Documents\Tunngle 2013-11-13 01:45 - 2013-11-13 01:45 - 00000000 ____D C:\Users\MAGIC\Documents\Tunngle 2013-11-13 01:40 - 2013-11-13 01:40 - 04029596 _____ (Tunngle.net GmbH ) C:\Users\MAGIC\Downloads\Tunngle_Setup_v4.5.1.4.exe 2013-11-13 01:40 - 2013-11-13 01:40 - 00114579 _____ C:\Users\MAGIC\Downloads\Naruto.Shippuden.Ultimate.Ninja.3.Steamworks.Fix-RVTFiX(2).rar 2013-11-13 01:05 - 2013-11-13 00:57 - 129201056 _____ (Mad catz ) C:\Users\MAGIC\Downloads\Smart Technology 7_0_27_13 64Bit.exe 2013-11-13 00:50 - 2013-11-13 00:49 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad (1).exe 2013-11-13 00:44 - 2013-11-13 00:44 - 05109384 _____ (Saitek ) C:\Users\MAGIC\Downloads\P2600Gamepad.exe 2013-11-13 00:34 - 2013-11-13 00:34 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EMU 2013-11-12 22:19 - 2013-11-12 22:19 - 00000000 ____D C:\Users\MAGIC\AppData\Local\NVIDIA Corporation 2013-11-12 20:01 - 2013-11-12 20:01 - 00000000 ____D C:\Users\MAGIC\AppData\Local\4kdownload.com 2013-11-12 19:58 - 2013-11-12 19:55 - 21544992 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kyoutubetomp3_2.5.exe 2013-11-12 19:54 - 2013-11-12 19:54 - 00524288 _____ (Open Media LLC ) C:\Users\MAGIC\Downloads\4kvideodownloader_3.0.exe 2013-11-11 18:00 - 2012-11-18 14:53 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Mozilla 2013-11-11 00:41 - 2013-11-11 00:41 - 00278016 _____ C:\Users\MAGIC\Downloads\excelbern.exe 2013-11-10 18:02 - 2012-05-17 01:23 - 01777024 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-10 18:02 - 2011-04-12 08:43 - 00763004 _____ C:\Windows\system32\perfh007.dat 2013-11-10 18:02 - 2011-04-12 08:43 - 00173390 _____ C:\Windows\system32\perfc007.dat 2013-11-10 18:02 - 2009-07-14 06:13 - 01777024 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-10 17:23 - 2013-11-10 17:23 - 00000000 _____ C:\Windows\setuperr.log 2013-11-10 17:14 - 2013-10-21 12:22 - 00000000 ____D C:\Windows\Minidump 2013-11-10 17:10 - 2013-05-04 00:19 - 00000000 ____D C:\ProgramData\HappyCloud 2013-11-10 17:05 - 2013-11-10 17:05 - 00000000 ____D C:\Windows\system32\log 2013-11-08 21:47 - 2013-10-29 00:32 - 01064224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2013-11-08 21:47 - 2013-10-29 00:32 - 00955168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2013-11-07 23:22 - 2013-11-07 23:22 - 00000146 _____ C:\Users\MAGIC\Desktop\Sound - Verknüpfung.lnk 2013-11-07 23:19 - 2013-01-24 19:16 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\Just Aion Launcher 2013-11-07 21:12 - 2013-08-04 11:32 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-06 17:50 - 2013-11-06 17:50 - 00002772 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 17:50 - 2013-11-06 17:50 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 17:49 - 2013-11-06 17:49 - 04379048 _____ (Piriform Ltd) C:\Users\MAGIC\Downloads\ccsetup407.exe 2013-11-06 17:44 - 2013-11-06 17:44 - 02347384 _____ (ESET) C:\Users\MAGIC\Downloads\esetsmartinstaller_enu.exe 2013-11-03 08:52 - 2012-06-23 04:18 - 00000000 ____D C:\Users\MAGIC\Documents\Visual Studio 2010 2013-11-02 20:39 - 2012-04-18 17:51 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-29 00:32 - 2012-04-18 17:51 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-10-29 00:32 - 2012-04-18 17:50 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-28 02:03 - 2013-10-28 02:03 - 00000000 ____D C:\Users\MAGIC\AppData\Local\EA Games 2013-10-28 02:03 - 2013-10-25 22:34 - 00000000 ____D C:\Users\MAGIC\Documents\EA Games 2013-10-28 02:03 - 2013-08-26 16:06 - 00000000 ____D C:\ProgramData\Origin 2013-10-26 14:43 - 2012-12-11 13:40 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-10-26 14:43 - 2012-12-11 11:50 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-26 14:43 - 2012-12-11 11:50 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-26 14:42 - 2013-08-28 12:39 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-10-26 03:42 - 2013-10-26 03:42 - 03820328 _____ C:\Users\MAGIC\Downloads\battlelog-web-plugins_2.3.0_119.exe 2013-10-26 00:59 - 2012-04-18 17:26 - 00001421 _____ C:\Users\MAGIC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-10-26 00:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-10-26 00:55 - 2013-03-10 14:07 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-26 00:47 - 2013-10-26 00:47 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-26 00:47 - 2013-10-26 00:47 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-10-26 00:47 - 2013-10-26 00:47 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-10-26 00:47 - 2013-10-26 00:47 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-10-26 00:47 - 2013-10-26 00:47 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-10-26 00:47 - 2013-10-26 00:47 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-10-26 00:47 - 2013-10-26 00:47 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-10-26 00:45 - 2013-03-10 14:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Works 2013-10-26 00:42 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini 2013-10-26 00:39 - 2013-09-21 10:59 - 00000000 ____D C:\Windows\system32\MRT 2013-10-26 00:37 - 2012-09-28 17:31 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2013-10-26 00:33 - 2013-10-26 00:33 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2013-10-26 00:24 - 2012-08-27 18:57 - 00000000 ____D C:\Users\MAGIC\AppData\Roaming\.minecraft Files to move or delete: ==================== C:\Users\MAGIC\AppData\Roaming\mBot.ini Some content of TEMP: ==================== C:\Users\MAGIC\AppData\Local\Temp\instloffer.exe C:\Users\MAGIC\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 17:39 ==================== End Of Log ============================ |
25.11.2013, 15:24 | #8 |
/// TB-Ausbilder | Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Und wie sieht es jetzt aus..? Noch Probleme vorhanden?
__________________ cheers, Leo |
25.11.2013, 16:05 | #9 |
| Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Ja sind es. Der Browser zeigt die selben Symtome. Zudem Lagt diese Seite hier komplett. Es ist mir nur mit einem gewissen Zeitaufwand moglich was zu schreiben. |
25.11.2013, 16:32 | #10 |
/// TB-Ausbilder | Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Was passt genau nicht? Und welche Browser sind betroffen?
__________________ cheers, Leo |
25.11.2013, 16:52 | #11 |
| Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Ich habe zur Zeit 3 Browser (+ Internet Explorer den ich nicht Zähle) Opera funtioniert ohne probleme, Firefox und Chrome machen mir diese Probleme. - Einzelne Wörter sind verlinkt auf irgendwelche Werbund das heißt wenn ich mit der Maus drüber gehe kommt ein kleines Fenster wo etwas drin steht. - Es öffnet sich auch alle so und soviele Seiten die ich öffne ein neues Fenster wo noch einmal Extra Werbung verpackt ist. (Diese wird jedoch nicht angezeigt da ich adblock benutzte) Ich habe nun diese Seite mit Firefox gestartet weil ich unter Chrome nicht wirklich machen kann was ich will. (Also nur auf dieser Seite) |
25.11.2013, 17:08 | #12 |
/// TB-Ausbilder | Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Kannst du bei diesen Browsern mal die Addons/Extensions durchsehen, ob da was drin ist, das du nicht selbst installiert hast?
__________________ cheers, Leo |
25.11.2013, 18:29 | #13 |
| Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] Ich glaube das war es nun Vielen Dank für die schnelle und gute hilfe |
Themen zu Unerwünschte Veränderung durch einen Virus im Browser [Werbung + Verlinkungen] |
board, browser, einzelne, google links, klicken, neue tabs, problem, pup.optional.delta.a, pup.optional.elex.a, pup.optional.opencandy, pup.optional.smartbar.a, pup.optional.snapdo, pup.optional.sprotect.a, pup.optional.vit, troja, trojan.agent, trojaner, trojaner board, unerwünschte, virenscan, virenscann, werbung, win32/adware.multiplug.h, win32/adware.multiplug.i, win32/packed.vmprotect.aad |