|
Plagegeister aller Art und deren Bekämpfung: Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom SeitenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.01.2014, 19:54 | #1 |
| Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten Guten Tag liebe TrojanerBoard Helfer, ich habe heute ein paar Videos geschaut und bei einem ist ein Download gestartet den ich noch abbrechen wollte aber ohne Erfolg. Danach habe ich in all meinen Internet Browsern eine Startseite die www.nationzoom.com heisst und ich bekomme diese nicht weg. Ich möchte mich dafür entschuldigen das ich schon selbstständig versucht habe diese Seite loszuwerden nach folgenden beiden Anleitungen: hxxp://praxistipps.chip.de/nationzoom-virus-entfernen-so-gehts_20339 und hxxp://www.browserdoktor.de/nationzoom-entfernen/ Die ersten beiden Links wenn man bei Google "Nation Zoom Entfernen" eingibt falls ihr die Links als unsicher ansehen solltet. Keine dieser beiden Anleitungen hat geholfen somit wende ich mich nun an dieses Forum weil das hier ja professionelle Hilfe bietet. Ich habe ausserdem einen FRST Scan durchgeführt den ich nachfolgend poste. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by Ozoma (administrator) on OZOMA-PC on 06-01-2014 19:47:26 Running from C:\Users\Ozoma\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1389015938&from=amt&uid=ST31000524AS_9VPFBC69XXXX9VPFBC69 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" FireFox: ======== FF ProfilePath: C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\nationzoom.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afurladvisor@anchorfree.com FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (AdBlock) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (Google Wallet) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Ozoma\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1389015938&from=amt&uid=ST31000524AS_9VPFBC69XXXX9VPFBC69 CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-07-12] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-31] (DT Soft Ltd) S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation) R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-07-24] (AnchorFree Inc.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Downloads\FRST64.exe 2014-01-06 19:47 - 2014-01-06 19:47 - 00011153 _____ C:\Users\Ozoma\Downloads\FRST.txt 2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt 2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox 2014-01-06 19:23 - 2014-01-06 19:23 - 00000000 ____D C:\Users\Ozoma\Desktop\Alte Firefox-Daten 2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat 2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-06 19:12 - 2014-01-06 19:13 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe 2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-06 15:17 - 2014-01-06 15:18 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe 2014-01-06 14:46 - 2014-01-06 14:48 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Mobogenie 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\Documents\Mobogenie 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt 2014-01-06 14:45 - 2014-01-06 14:55 - 00000000 ____D C:\ProgramData\WPM 2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url 2014-01-05 16:01 - 2014-01-05 16:02 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar 2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip 2014-01-05 12:47 - 2014-01-05 12:48 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar 2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer 2014-01-02 20:13 - 2014-01-02 20:14 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip 2014-01-02 18:52 - 2014-01-02 20:42 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt 2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip 2014-01-02 14:50 - 2013-11-15 04:48 - 00336896 _____ C:\Users\Ozoma\Desktop\WSplit.exe 2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip 2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url 2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip 2013-12-31 15:19 - 2013-12-31 15:20 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip 2013-12-31 14:41 - 2013-12-31 14:42 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar 2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip 2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url 2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url 2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV 2013-12-21 22:10 - 2013-12-31 04:08 - 00000050 _____ C:\Users\Ozoma\Desktop\save1 2013-12-21 22:09 - 2013-12-31 04:12 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime 2013-12-21 22:09 - 2013-11-23 09:22 - 147172145 _____ () C:\Users\Ozoma\Desktop\I wanna go the Parallel World.exe 2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4 2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url 2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg 2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg 2013-12-18 21:50 - 2013-12-31 00:35 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1 2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip 2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url 2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk 2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe 2013-12-14 22:12 - 2013-12-14 23:26 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip 2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar 2013-12-12 03:01 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-12 03:01 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-12 03:01 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-12 03:01 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-12 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-12 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-12 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-12 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-12 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-12 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-12 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-12 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-12 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-12 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-12 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-12 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-12 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-12 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-12 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 15:28 - 2013-12-11 16:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 12:45 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 12:45 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 12:45 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 12:45 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 12:45 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 12:45 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 12:45 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 12:45 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 12:45 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 12:45 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 12:45 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 12:45 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 12:45 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 12:45 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 12:45 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 12:45 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 12:45 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 12:45 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 12:45 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 03:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-11 02:59 - 2013-12-11 03:03 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-08 00:51 - 2014-01-04 23:15 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update 2013-12-08 00:50 - 2013-12-31 14:52 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode 2013-12-07 19:33 - 2013-12-07 19:33 - 00000000 ____D C:\Users\Ozoma\AppData\Local\{919835E6-46EA-4053-B5E2-458DB270630D} 2013-12-07 15:49 - 2013-12-07 15:52 - 79259754 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited.zip 2013-12-07 15:48 - 2013-12-07 15:50 - 79316716 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited1.1.0SR.zip ==================== One Month Modified Files and Folders ======= 2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Downloads\FRST64.exe 2014-01-06 19:47 - 2014-01-06 19:47 - 00011153 _____ C:\Users\Ozoma\Downloads\FRST.txt 2014-01-06 19:47 - 2012-04-24 07:18 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Skype 2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt 2014-01-06 19:42 - 2012-07-31 10:22 - 00000000 ____D C:\Qoobox 2014-01-06 19:40 - 2013-04-29 19:53 - 00000000 ____D C:\Users\Ozoma\AppData\Local\LogMeIn Hamachi 2014-01-06 19:40 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-06 19:35 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-06 19:35 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-06 19:31 - 2012-04-20 22:40 - 01311990 _____ C:\Windows\WindowsUpdate.log 2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox 2014-01-06 19:28 - 2013-01-03 23:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-06 19:27 - 2013-05-11 13:54 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-06 19:27 - 2012-04-18 06:46 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-06 19:27 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-06 19:27 - 2009-07-14 05:51 - 00876558 _____ C:\Windows\setupact.log 2014-01-06 19:26 - 2013-11-25 15:24 - 00000000 ____D C:\AdwCleaner 2014-01-06 19:23 - 2014-01-06 19:23 - 00000000 ____D C:\Users\Ozoma\Desktop\Alte Firefox-Daten 2014-01-06 19:21 - 2013-05-11 13:54 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat 2014-01-06 19:16 - 2013-11-25 15:28 - 05160001 ____R (Swearware) C:\Users\Ozoma\Downloads\ComboFix.exe 2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-06 19:13 - 2014-01-06 19:12 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe 2014-01-06 19:03 - 2010-11-21 04:47 - 00907684 _____ C:\Windows\PFRO.log 2014-01-06 18:53 - 2012-04-20 22:59 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\TS3Client 2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-06 15:30 - 2013-11-25 16:34 - 00000000 ____D C:\ProgramData\AVAST Software 2014-01-06 15:27 - 2012-04-20 22:45 - 00000000 ___RD C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-06 15:24 - 2013-01-20 02:32 - 00000000 ____D C:\Program Files (x86)\Sony 2014-01-06 15:18 - 2014-01-06 15:17 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe 2014-01-06 14:55 - 2014-01-06 14:45 - 00000000 ____D C:\ProgramData\WPM 2014-01-06 14:48 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Mobogenie 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\Documents\Mobogenie 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt 2014-01-06 14:46 - 2012-04-20 22:45 - 00000000 ____D C:\Users\Ozoma 2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2014-01-06 14:45 - 2013-05-11 13:54 - 00002373 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-06 14:45 - 2013-03-02 11:33 - 00001328 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-06 14:45 - 2012-04-20 22:45 - 00001631 _____ C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-06 13:46 - 2012-08-16 23:56 - 00029696 _____ C:\Users\Ozoma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-06 12:42 - 2012-04-21 10:44 - 00000000 ____D C:\Users\Ozoma\Desktop\Let's plays und fails 2014-01-05 21:18 - 2013-08-15 19:52 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Mumble 2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url 2014-01-05 16:02 - 2014-01-05 16:01 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar 2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip 2014-01-05 12:49 - 2012-10-01 16:39 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Paint.NET 2014-01-05 12:48 - 2014-01-05 12:47 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar 2014-01-04 23:15 - 2013-12-08 00:51 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update 2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer 2014-01-02 20:42 - 2014-01-02 18:52 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt 2014-01-02 20:14 - 2014-01-02 20:13 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip 2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip 2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip 2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url 2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip 2013-12-31 15:20 - 2013-12-31 15:19 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip 2013-12-31 14:52 - 2013-12-08 00:50 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode 2013-12-31 14:42 - 2013-12-31 14:41 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar 2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip 2013-12-31 04:12 - 2013-12-21 22:09 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime 2013-12-31 04:08 - 2013-12-21 22:10 - 00000050 _____ C:\Users\Ozoma\Desktop\save1 2013-12-31 00:35 - 2013-12-18 21:50 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1 2013-12-30 10:21 - 2013-11-11 06:09 - 00001945 _____ C:\Users\Ozoma\Desktop\Warp 9,975.txt 2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url 2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url 2013-12-23 04:55 - 2013-06-27 19:58 - 00000000 ____D C:\Users\Ozoma\Desktop\JoyToKey_en 2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV 2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4 2013-12-21 04:20 - 2012-05-11 14:51 - 00000000 ____D C:\Users\Ozoma\Documents\StarCraft II 2013-12-20 21:16 - 2012-04-20 22:44 - 00407840 _____ C:\Windows\DirectX.log 2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url 2013-12-20 07:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-19 15:42 - 2012-05-23 10:35 - 00002884 _____ C:\Users\Ozoma\Desktop\Tag.txt 2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg 2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg 2013-12-18 21:50 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplit 2013-12-18 18:58 - 2013-11-25 15:29 - 00001467 _____ C:\Users\Ozoma\Desktop\ComboFix - Verknüpfung.lnk 2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip 2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url 2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk 2013-12-15 22:49 - 2012-04-18 06:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe 2013-12-14 23:26 - 2013-12-14 22:12 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip 2013-12-14 18:43 - 2012-07-08 22:49 - 00007601 _____ C:\Users\Ozoma\AppData\Local\Resmon.ResmonCfg 2013-12-14 03:02 - 2013-09-06 00:05 - 00000000 ____D C:\Windows\system32\MRT 2013-12-14 03:00 - 2012-07-23 16:49 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 14:56 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar 2013-12-12 14:02 - 2011-04-12 08:43 - 05873572 _____ C:\Windows\system32\perfh007.dat 2013-12-12 14:02 - 2011-04-12 08:43 - 01756324 _____ C:\Windows\system32\perfc007.dat 2013-12-12 14:02 - 2009-07-14 06:13 - 00005884 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-12 13:56 - 2009-07-14 05:45 - 04918320 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 16:28 - 2013-12-11 15:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 16:28 - 2013-01-03 23:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 16:28 - 2012-04-21 18:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 12:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-11 03:03 - 2013-12-11 02:59 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-07 19:33 - 2013-12-07 19:33 - 00000000 ____D C:\Users\Ozoma\AppData\Local\{919835E6-46EA-4053-B5E2-458DB270630D} 2013-12-07 15:52 - 2013-12-07 15:49 - 79259754 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited.zip 2013-12-07 15:50 - 2013-12-07 15:48 - 79316716 _____ C:\Users\Ozoma\Downloads\MegaManUnlimited1.1.0SR.zip 2013-12-07 15:41 - 2013-07-17 06:09 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Orginal Files to move or delete: ==================== C:\Users\Ozoma\AppData\Roaming\Camdata.ini C:\Users\Ozoma\AppData\Roaming\CamLayout.ini C:\Users\Ozoma\AppData\Roaming\CamShapes.ini C:\Users\Ozoma\AppData\Roaming\CamStudio.Producer.Data.ini ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 15:55 ==================== End Of Log ============================ |
07.01.2014, 09:21 | #2 |
/// the machine /// TB-Ausbilder | Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten hi,
__________________Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade dir bitte Shortcut Cleaner (by Grinler) auf deinen Desktop.
und ein frisches FRST log bitte.
__________________ |
07.01.2014, 13:20 | #3 |
| Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom SeitenCode:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.07.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Ozoma :: OZOMA-PC [Administrator] 07.01.2014 12:52:12 mbam-log-2014-01-07 (12-52-12).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 251291 Laufzeit: 4 Minute(n), 33 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 07/01/2014 um 13:06:35 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Ozoma - OZOMA-PC # Gestartet von : C:\Users\Ozoma\Desktop\adwcleaner (1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\WinterSoft Ordner Gelöscht : C:\ProgramData\WPM Ordner Gelöscht : C:\Users\Ozoma\AppData\Local\Mobogenie Ordner Gelöscht : C:\Users\Ozoma\Documents\Mobogenie Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\nationzoom.xml Datei Gelöscht : C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (2).lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (3).lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\BabylonToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command Schlüssel Gelöscht : HKLM\Software\supWPM ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v21.0 (de) [ Datei : C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445\prefs.js ] -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [84667 octets] - [25/11/2013 15:25:03] AdwCleaner[R1].txt - [3877 octets] - [06/01/2014 18:36:43] AdwCleaner[R2].txt - [1182 octets] - [06/01/2014 19:26:03] AdwCleaner[R3].txt - [5424 octets] - [07/01/2014 13:05:55] AdwCleaner[S0].txt - [83297 octets] - [25/11/2013 15:25:39] AdwCleaner[S1].txt - [3854 octets] - [06/01/2014 18:53:12] AdwCleaner[S2].txt - [1244 octets] - [06/01/2014 19:26:46] AdwCleaner[S3].txt - [3845 octets] - [07/01/2014 13:06:35] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [3905 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.9 (01.01.2014:1) OS: Windows 7 Home Premium x64 Ran by Ozoma on 07.01.2014 at 13:10:58,03 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3620531602-815428446-3748077359-1001\Software\Microsoft\Internet Explorer\Main\\Start Page ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{00E890CA-5DA7-4904-AE0F-43458599A628} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{03C50279-C4C6-46CF-A4B3-F68EB0587FC1} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{05443243-56DA-4485-A753-3E14B983AF11} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{05A195B3-E966-4187-9AED-5B013E926ACA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0614505A-B061-453F-8385-236AADCF4FF3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{069C4023-D72E-48A2-9BB8-3428CECB706B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{06E99575-174B-4BA6-BE90-B84A22C7FA77} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{08265246-73E1-46B4-8363-31EC2B0B1AE5} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0896BB66-47B1-4A6C-9D87-7B78D9E1F79B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{092F806D-5906-487A-B9D6-2DEE9875FD73} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0944BDCA-DD69-42B2-AC6E-A4B6E4AB45FE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0966C301-5756-4117-BCB5-12B14BB158DE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{09909E29-F17C-491D-A332-30445BE68EFF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0B064596-335F-4BA1-AE12-877861C8FA50} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0B9FE55D-F937-44A3-9B0B-01FEE99569AB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0CCF3722-CB5B-487A-8CB2-8483F8F34467} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0D6FA4A3-34A8-4C54-89A6-EF42F619A204} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0DD1A340-F165-40AC-A06C-BBD4299310D6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0F5392A3-29B6-4177-A52A-3FCA2661C99F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0F565785-E0DF-45D8-8E17-F94EDD61D6FF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{0FDC1137-78FD-4345-8B95-647379CDAD30} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{10579BF5-41A2-4528-AAAC-047EF18F15AC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{10FF4500-C137-4E51-932C-A3C94BB32982} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1233B42F-6683-457D-9290-C9A3A8A7E74B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{13834694-03BB-49F7-878C-AB77E5B68808} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{13CA2F5F-EC22-41D5-8D36-5E53C4776201} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{14AEC8AA-377A-4230-839B-B46542D7DC57} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{152639DD-0FF3-4F4D-BF53-1F64BA344784} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{15948382-87C6-46E9-9AF7-15CE928D26EC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1596EB92-C099-439A-BFFB-E7B66B7F51AE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{16184A2C-181C-4732-90F4-033F06D08542} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{166A947E-97DD-4EFF-A781-222240A7B20A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{16A7D8DA-7CBC-4687-8A99-5084C09FFEEB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{17C99D51-22DE-4A84-8FF3-4BCF9E2BE46B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{17C9F14A-8013-4AA8-9034-AB300D5C1C88} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{18BD8025-B48F-44E5-AC2E-02BC8669C290} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1A8203E9-0205-427A-9585-0381E001AE53} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1B6E6BDC-E360-410A-BB6F-4B90489FB30C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1C11969D-5965-4F79-B6EE-C88259E0A2D6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1C3AC2EA-0D55-4F96-B0C3-0592C82E0074} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1D712AE4-D2C2-460C-964D-006D2B4C7980} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1D99DBA6-2EDE-4C80-ACF8-B1CC5EEAA8FE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1E629045-62A7-4452-88F4-6AF93AE33AF2} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{1F5F4FA0-4ADD-4FD7-A739-AB4DFCE40B5C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2215024F-2C1D-4C33-AE4F-1B5A4DC00AEF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{22F145C0-F239-4013-AF72-91CB35566FDE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{23140DDE-2714-400C-AC5B-AF60FC4EFC68} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{240DCD8C-471E-4FAF-A1A0-82C208B88AF9} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2418FBA9-671E-41D8-9C22-EFCCDCA1514C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2463CF50-1AD5-48A8-A44E-1F4540471E0E} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2552EE75-002F-48AA-BD01-6292DE4445CC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{25C5DE14-6877-45EB-8570-9DCF5CBDF47D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{29687332-8DAC-42CC-94D2-2188CCA85C43} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2BBB07A6-A471-47C6-971C-F946555968CA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2C571CFD-BFF6-461D-84ED-17969801EFEB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2D62BD86-008A-4A81-8F88-DDF4E0F1E5B7} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{2F44D841-D198-4CA6-8D47-350675AA6DC0} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3154D09C-FF74-4949-879F-DB10DEA228BA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{320C7864-90FF-4365-8A69-FA0CF7FB8EDE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{32BD9E0B-B27B-4DC1-B435-80E53132FD95} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{33B95BBE-6834-40FF-8209-82B56B1C0EF5} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{34166FCC-8A65-4C80-82B6-48D854C6FA3A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3594448E-D3FF-42B1-83F4-93C2DD948ECA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{36726F9D-763B-45AB-9BC2-105A10236A34} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{371D3A9B-E9AE-4F65-9B97-1E8F66A0B1E0} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{37D3A92F-7824-41A0-8B1D-37FD284615A0} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3A57E227-B546-40C9-B2D3-DED7E049C33A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3CB2F653-C076-464B-A319-E0F04FE22FE3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3CCD6ABB-727B-42E5-8B58-C5872A8450E5} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3E08B27B-6EF6-48AE-B515-C36124EDCDBA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3E3F7224-322C-4B91-82F8-0CE6AE973B91} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3E93AEA9-CC2A-488C-942A-0FBE82D962EB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3ED03836-7B5E-47B7-A1B6-F2711B09FD94} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{3FF33901-DA5C-4C0B-9932-71C38BA50B04} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4003B4BD-7DB3-4CA4-BD48-E435F77FFAC7} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{400CAEA1-5C4D-44FD-BD4C-11AA13C40447} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{41B7120B-21B7-4760-B956-EDBEDEC200DD} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{42EB5208-6469-4458-94D7-DF94395A5269} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{438B6E86-BD39-42B0-A58B-12AB01806A1F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4523082B-C738-4CF8-8B6A-50191B5FBCFB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{46626621-0EE2-4598-A3FE-2D8C07F98496} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{46F9B856-87D9-4D8C-BFB0-A78C85203D91} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{47AF3EA7-968E-47F5-B9B6-58F5C3C0EB1A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{481E5860-5E9D-4B7A-AB2F-5683C826DDD3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{48BD1D50-F291-488D-B64D-586F80FBECBA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{49474A40-9D65-4EFE-B44E-D23D7CBFB541} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4A027F35-8460-4F39-BFB5-ACEBC1FEAE57} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4BAEE690-9A44-4148-A752-CCC0278E836A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4D788C01-6882-4046-B273-106A0E8EB8C7} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4DD23670-2EDE-49D2-B6B6-C223B27DF9DF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{4E5D583A-BE44-4F4B-8FD2-32F1BDFCCD7B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{521AA4BC-ED5B-4032-99F6-C2A5BBB19A83} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{529D91B9-61EC-4D7D-B93F-734A146CEC1C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{529E9C52-F228-45E8-A194-01754B457819} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5322707D-4658-4B81-A3CF-A816C25BAD17} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{54EF7A75-7D2E-4354-971B-8B81BEA9306D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{554C4003-C023-4D9B-AAB6-49D184101C84} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5721259C-B49B-4AC2-8690-EB45DADC45E7} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{572EC9CA-C513-4825-B288-322BC36067D8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5784899E-DBCE-4675-9175-C3F8B4653375} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{57B906D7-D069-4E00-91A8-1589D3D1BA5B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{590CCCD9-EDDD-4818-9A45-661AB22D51FB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{592360E6-E87F-49B4-A486-35BDEFDB3ACF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5BF75791-D2F9-4C9A-8333-4BD4AEDB6BBD} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5C0255C6-CF51-4D62-A192-43368ADBC74B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5E145337-25DB-4D0B-8D5A-ECD2AB259872} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5E87AA61-CACA-4926-A18C-2592B2C19B14} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5F7229E3-F0A3-4CC5-9F1D-0638286FF25C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{5F730C31-DB67-4923-8974-5CF9C8693DCE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{61524252-FA76-4E43-87E4-9C14DFDA05A4} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6250F42D-BA92-4C39-BD05-95B1A64D3620} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{628F124B-022F-4EA9-978E-7AF33D9733F9} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{635B5EF3-C35F-42C2-8521-10C9EFD27514} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{635DB9F6-3CB8-4A93-BB9A-119B17141AEA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{66C42329-6E4A-451E-BEBF-9B7733983EB4} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{66D2124C-D76B-49AF-95E1-ADD45F4EF05C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{67C5301E-61D6-45A8-BC88-EE7AF1A2DE01} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{67FC886C-15BE-4FCA-B6DC-025AC4E6B23C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{698BFEDB-7F27-4231-B387-85636F8F1DB2} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{69B27FBE-984E-4E9E-A7EB-4D4BFCE18CBD} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A10F672-FA32-49A5-B002-61FCB6C6FFA5} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A4F3E07-9E43-4E61-9541-95CB50BEB9D3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A6854F6-4297-40FC-BDA2-0436CE5C2D26} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6A8A52D0-8C78-479C-BFF5-75615FE1C677} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6B1A79FD-8139-42C0-AF7F-ABE4F0B1289D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6CAC6493-AFF1-4798-BD73-1087AF350DE5} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6D7F568D-1436-42C9-810A-38FB72ACDBBC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6E24DC49-B1A1-4A59-BB24-FB653F22100D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6ECE3E56-7CBC-41DF-A815-0E1308ABBD84} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{6FB9C092-1C68-45AD-9139-44B56A189672} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{704A56BE-3FBE-48C2-B9AB-932C4AD85590} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{708879C7-8E56-4B49-8410-41CD76A636B6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{714C3802-9A1F-41A2-AFA4-7382B753D659} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{71BE9908-BA2B-48AF-BA79-9A44EAF2598C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7220B662-D000-4E27-9E5B-F3FE7D21362A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7241E997-D3F2-4CC3-BA53-33538380DF07} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{73733C01-91E9-4687-B423-897944142130} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{76F41AB7-C07E-4854-A4BE-D812BF151DDA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{77B08B2F-09AE-4861-A444-DDD4A5190183} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{77E46581-2940-4848-8073-83FA589F8939} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{77ED0A12-EB8E-4F8C-922D-524C5E929132} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{785D0824-2384-482F-ABBB-B62FEBDC84ED} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{78A81688-37F1-490E-B03E-CA9246A989F9} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7A4352E9-6114-4A61-A498-D7D204683A5F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7B2634B0-91F8-4E85-908F-41B505A7E34C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7D63BABF-8AF1-4ABA-96B2-AFEC1EC97C30} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7DA4E5C8-F777-4073-9820-374AC559FBCC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7E579D4B-C2DF-4DB3-8BC9-E6E59C696582} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7E811C44-5F72-424C-A655-B917A6E6F555} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7E9686A4-8429-45A3-BE04-5366934B8C96} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{7FC3CF13-BD6E-4E4B-9D6B-6806F6399EB8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{809D6D0A-823A-4B42-9875-D931FAD0014C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8143F5C3-4080-4477-BB76-DA7162407E9C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{82A3EFA3-8756-4863-B153-F3B8EEF2CD6D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{832089FB-F92E-4A2D-ADCB-925725ADE2F6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{83857151-587C-462D-AEC4-FEA414E20C0B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{83FD7A45-8850-43C2-85A5-088B75F63556} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{84FF0A5D-246E-468F-B898-0DFD9D57563B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{850CFAF8-6377-4756-AC42-90B776FE7F7B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{87FD4072-D6C1-43E8-AC41-602C802119FF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8888F3EC-9141-405B-BF67-D412A16D74B4} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{88BF4937-9DD4-42EB-A13A-4BF0240C5169} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{88C4B221-A0C7-4491-B119-52699FA44D9F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8B123261-B006-428A-B545-C941AE0B6F29} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8C5C6119-6F82-4841-B4DC-54B34B77607C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8CC6DA17-D960-4562-A247-29C78917B6EB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8CEF4658-63EB-480E-9420-7186DE8F1033} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{8EFF9786-53DB-4F6B-8D23-10A717531C37} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{90337936-711D-4848-9BA9-A67C86CDD570} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{907C7E17-0BA1-485E-85DF-C88986C0A0CA} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{919835E6-46EA-4053-B5E2-458DB270630D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{934EB8CB-9BF9-4CB9-9808-5996B943D163} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{93AF923A-C3C7-4833-AC68-01021D16ECD0} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{93F01C1B-9ABD-4A31-9BF1-624806D4617D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9488362A-0D60-447F-A7F3-DEE012E5C31F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{94AB8D78-8F01-4FEF-B48B-E93983E9FB72} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{951F128C-24A5-45BD-BB5F-FA50F047F1AD} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{95C53204-5FC2-463F-8D4D-F692477C34F8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{961DA1F0-39FA-4B1E-BB35-5D5AB0643A7A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{96F96DF6-CD70-4930-98BE-EC0A3B903A07} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9751E9E8-40EC-40D5-BE01-FE4EE8E9B109} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{97D396BD-0DD7-49B2-A5B8-40E450A57A31} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{97D59104-3AA7-46F8-A02F-9023CBE193B8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{980285C4-5621-43B2-A461-F1467CB424E4} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{989F9309-BADE-4CF3-A64F-24C743CDC7ED} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9ABEF256-E396-4EA8-9629-D26C5D4A3A51} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9AC5E05F-359A-4D5D-8F6F-40C0C9708C05} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9B683DC0-3B0B-43E8-9575-D66D54F49AB1} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9D1A64F9-27A9-4A4D-8981-EC4177F66291} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9EDDEA89-777F-4029-9F37-E7FCAA2D9EF5} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{9F3288FC-07DA-4E9F-8E90-4BA3F98B7F41} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A07906B0-C79C-47D1-981C-6967597C84AF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A0BD4373-5D50-45AF-AD4C-FE2113C29AAB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A10F0F80-B0F0-4B65-ADDA-DF8A471DF072} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A316777A-E193-433A-92BD-13881CF3EB77} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A35DA85D-ECDE-480C-9BEB-F2A26772EC0E} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A48BED54-3AFD-49B2-82D9-C38DB69408EB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A49AB1EE-B95F-4372-9467-4BAC438A729F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A4E4D98E-B0DA-48F9-82FB-A07A63F71F8C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A5722E92-17C8-43DA-9038-7F000EA94F52} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A6CDE583-DA03-4F29-82A8-58D31B860147} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A7CE685A-8882-4053-8B98-474BDB50149E} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A8ACD05A-5B3A-48BF-AE80-4896658B37B6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A92453C1-58D4-4446-9AD3-AA768B42B5D1} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{A94C7DE6-E983-4E92-BF3A-57F311F03CEE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AB47EC36-E700-4442-A75E-8D5BD6A9C67C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD050927-4CA8-4B0D-9E74-3E09764CB655} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD06BEE4-BB40-4642-9C38-B9EA34E4D932} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD2C033C-F34A-438C-9C8C-7E1AB9DC104E} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AD52454A-A645-4E72-BD9E-051AFCCFC90A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{AFB41E9B-EE88-40DC-8928-5F0DAC9CFE85} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B04466FE-F2C8-4317-8580-0345E7A57277} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B0B68426-A168-47D9-99DF-3673496737B1} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B1110580-B873-4AAE-A6F5-1F7C5AEC6591} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B2D632BB-94D7-473D-9120-1B0CA23B66A8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B34A2F77-7D16-4CA3-826C-8FD4886B36D8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B536A5CA-8A52-4FB2-8557-63FD807B5ACE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B577F428-42E2-4371-A3D6-601176551B85} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B63F125C-74D4-4EF2-A18A-2F1F39048E10} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{B7FBBFC2-E237-40F2-B4E2-0C8A1E801D57} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BBA947A5-551A-4736-BF90-DBED7B11E3CB} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BBFBD7EE-A5EF-479B-B516-AA9E5B6F6B2B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BCE5EA73-9027-4F02-97C2-77578362894F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BD9F495D-713F-49F6-9545-932D709F210C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{BE676B08-1388-4DC8-BBB1-71A6FB01F19D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C0F60B30-D716-4452-8B90-3FFD75C1152C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C1BCD1FA-F078-4355-8D3C-F648AE479DF9} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C217BB74-5D34-4443-928A-AB4D0A5B48AC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C285303F-6A8B-40A4-83FE-9070A1C04792} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C40BCC1F-B789-4F54-B353-00474F6CFFC7} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C4919A7C-2D1A-4CF6-A0F7-89CBE8403890} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C5829563-5B65-402F-AC67-0772F2976FCE} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C59389EA-FB2E-4E72-BE85-E586BE9E6E20} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C5F19DB6-4B0D-4BE2-AD59-95ECDEE8D8D9} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C732E86B-0AE7-49C4-9949-4D842B8A5FBF} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C77AC8CB-B644-410D-81CC-1F894D75D493} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C79ED3A8-BD19-496C-B9C3-C3179977FBB3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{C97E06A0-FEAC-4040-B7CA-31CD9B1C2A41} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CA967193-6809-47B1-BF65-442138185A7A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CB4B801A-FBB7-4208-AECC-0C5F6B452DB3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CB714EC0-F0CB-43D6-8B1C-77788DFA2763} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CC117AB0-2E58-480B-971C-F8EF01611E27} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CC1DDFFA-9B54-41B7-BC19-9BBF415E8217} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CCE9580B-DFFD-4BD3-9D25-8CA9CFC7A916} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CD8E2581-2395-4448-A5BA-39136B452C7A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{CE26D183-D616-4DB4-8898-5BE72E50410D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D1AAF9BB-4554-4C0E-9915-4A10C1C59322} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D30C8EA8-2F82-47CE-8187-C32ABFA8C930} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D39FE9EA-F405-47D7-B707-F9814DE04011} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D3DEA3D0-44EF-46C3-BB89-18510E613C98} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D6611F76-13BA-4903-B7B7-754D1B57843A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D7732F92-CAFD-42A5-995D-FDBE05AEA601} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D80A650B-4320-433F-9792-F10E04C494D3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{D867F407-E793-4F54-AA05-B21ED2931AD8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DA65A950-81BF-414E-9053-43AF4FE847A3} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DB76D859-C906-4A9B-AF22-615594AC1E8F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DC36058E-E761-4B7B-AD19-AADCFCFA1803} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DE3EF15D-02BF-47E1-BB97-D32C7D82220A} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{DF83E91C-549E-42D0-B6CA-75DCA617CE1C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E07664ED-95A2-43C6-A673-50DB7A6D59DD} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E10365DD-38B3-4EFF-8206-99FDB2960230} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E1328159-5BD5-4690-BA6B-C022498D04B5} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E3085623-0C2A-4007-B133-769C5434E0C6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E4271EAC-4C48-4D8B-97A4-5032D980F6CD} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E54719C8-D211-43A5-99AE-E659129B5A2F} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E57A5E75-22EF-43CB-9074-55B0BABB9D7E} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E59FFA01-3899-4B1D-B0E9-4217EBA96F3B} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E7DA4EB2-104D-4362-AFCE-FCB7A39644B6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{E9EE2942-8172-4D1F-953F-E90AE398CB11} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EA12E7DB-993F-4303-8189-DCCD659719A8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EBB6F81A-96D0-44AD-9DC6-90E74B8B5602} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EC6E2DCF-415F-4F91-9299-02A64ADD6E9E} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EC80ECBB-88DD-4034-A946-C58B5586B3E8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{ED8F9247-E0C2-4424-B567-E04463A45123} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EED4A8A4-0BC2-42AC-8266-932F460FF668} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EF06118D-88E1-4971-9D97-BFF13C3C091C} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{EF43DE86-FBD7-4EC0-98C8-BC7E5C1014DC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F2A77E3C-0E19-4749-A891-03365523D4F0} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F2F3163C-9338-4965-9E6E-96D05749FE1D} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F51A623B-2B6A-4727-96E4-0AC29A1175D9} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F66BACB7-B595-43F7-8179-439413D5F5E8} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F8E5F179-1505-4160-B6D0-9C44BF9BCAC6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{F90CBC14-6AE9-46A6-987B-EDE1F631EBAC} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FA97A7B8-56AF-46CB-A1CB-C9DF10C66401} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FD2E149E-AFFD-46B4-B2A1-3B6BC96ED8C2} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FE53B363-F0D1-4A9E-8EC0-9A1F0EBFF0B7} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FEFEF785-F04E-45A4-9602-BD9667C64ED4} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FFB4C941-4849-4C0D-A76C-73B3F87E57B6} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FFC95BBC-A658-4105-9537-EC5FC1C54017} Successfully deleted: [Empty Folder] C:\Users\Ozoma\appdata\local\{FFD37BA4-4C01-4FB6-8B29-55FC9CE2D7FC} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 07.01.2014 at 13:15:09,59 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler) hxxp://www.bleepingcomputer.com/ Copyright 2008-2014 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/ Windows Version: Windows 7 Home Premium Service Pack 1 Program started at: 01/07/2014 01:16:53 PM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\ Searching C:\ProgramData\Microsoft\Windows\Start Menu\ Searching C:\Users\Ozoma\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ Searching C:\Users\Public\Desktop\ Searching C:\Users\Ozoma\Desktop 0 bad shortcuts found. Program finished at: 01/07/2014 01:16:59 PM Execution time: 0 hours(s), 0 minute(s), and 5 seconds(s) Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by Ozoma (administrator) on OZOMA-PC on 07-01-2014 13:17:48 Running from C:\Users\Ozoma\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" FireFox: ======== FF ProfilePath: C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afurladvisor@anchorfree.com FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (AdBlock) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (Google Wallet) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Ozoma\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-07-12] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-31] (DT Soft Ltd) S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation) R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-07-24] (AnchorFree Inc.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe 2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt 2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt 2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT 2014-01-07 13:09 - 2014-01-07 13:10 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe 2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt 2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe 2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware 2014-01-07 12:47 - 2014-01-07 12:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe 2014-01-06 19:47 - 2014-01-07 13:17 - 00011895 _____ C:\Users\Ozoma\Downloads\FRST.txt 2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe 2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt 2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox 2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat 2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-06 19:12 - 2014-01-06 19:13 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe 2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-06 15:17 - 2014-01-06 15:18 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt 2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url 2014-01-05 16:01 - 2014-01-05 16:02 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar 2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip 2014-01-05 12:47 - 2014-01-05 12:48 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar 2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer 2014-01-02 20:13 - 2014-01-02 20:14 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip 2014-01-02 18:52 - 2014-01-02 20:42 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt 2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip 2014-01-02 14:50 - 2013-11-15 04:48 - 00336896 _____ C:\Users\Ozoma\Desktop\WSplit.exe 2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip 2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url 2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip 2013-12-31 15:19 - 2013-12-31 15:20 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip 2013-12-31 14:41 - 2013-12-31 14:42 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar 2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip 2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url 2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url 2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV 2013-12-21 22:10 - 2013-12-31 04:08 - 00000050 _____ C:\Users\Ozoma\Desktop\save1 2013-12-21 22:09 - 2013-12-31 04:12 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime 2013-12-21 22:09 - 2013-11-23 09:22 - 147172145 _____ () C:\Users\Ozoma\Desktop\I wanna go the Parallel World.exe 2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4 2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url 2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg 2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg 2013-12-18 21:50 - 2013-12-31 00:35 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1 2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip 2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url 2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk 2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe 2013-12-14 22:12 - 2013-12-14 23:26 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip 2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar 2013-12-12 03:01 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-12 03:01 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-12 03:01 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-12 03:01 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-12 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-12 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-12 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-12 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-12 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-12 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-12 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-12 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-12 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-12 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-12 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-12 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-12 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-12 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-12 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 15:28 - 2013-12-11 16:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 12:45 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 12:45 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 12:45 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 12:45 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 12:45 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 12:45 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 12:45 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 12:45 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 12:45 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 12:45 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 12:45 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 12:45 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 12:45 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 12:45 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 12:45 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 12:45 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 12:45 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 12:45 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 12:45 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 03:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-11 02:59 - 2013-12-11 03:03 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-08 00:51 - 2014-01-04 23:15 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update 2013-12-08 00:50 - 2013-12-31 14:52 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode ==================== One Month Modified Files and Folders ======= 2014-01-07 13:18 - 2014-01-06 19:47 - 00011895 _____ C:\Users\Ozoma\Downloads\FRST.txt 2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe 2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt 2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt 2014-01-07 13:14 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-07 13:14 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT 2014-01-07 13:10 - 2014-01-07 13:09 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe 2014-01-07 13:10 - 2012-04-24 07:18 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Skype 2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt 2014-01-07 13:08 - 2013-05-11 13:54 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-07 13:08 - 2013-04-29 19:53 - 00000000 ____D C:\Users\Ozoma\AppData\Local\LogMeIn Hamachi 2014-01-07 13:07 - 2012-04-18 06:46 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-07 13:07 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-07 13:07 - 2009-07-14 05:51 - 00876670 _____ C:\Windows\setupact.log 2014-01-07 13:06 - 2013-11-25 15:24 - 00000000 ____D C:\AdwCleaner 2014-01-07 13:06 - 2013-05-11 13:54 - 00001284 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-07 13:06 - 2013-03-02 11:33 - 00001055 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-07 13:06 - 2012-04-20 22:45 - 00001001 _____ C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-07 13:06 - 2012-04-20 22:40 - 01358085 _____ C:\Windows\WindowsUpdate.log 2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe 2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware 2014-01-07 12:48 - 2014-01-07 12:47 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe 2014-01-07 12:48 - 2013-11-25 16:42 - 00000791 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-07 00:53 - 2012-04-20 22:59 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\TS3Client 2014-01-07 00:28 - 2013-01-03 23:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-07 00:21 - 2013-05-11 13:54 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-06 19:47 - 2014-01-06 19:47 - 01931762 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe 2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt 2014-01-06 19:42 - 2012-07-31 10:22 - 00000000 ____D C:\Qoobox 2014-01-06 19:40 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox 2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat 2014-01-06 19:16 - 2013-11-25 15:28 - 05160001 ____R (Swearware) C:\Users\Ozoma\Downloads\ComboFix.exe 2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-06 19:13 - 2014-01-06 19:12 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe 2014-01-06 19:03 - 2010-11-21 04:47 - 00907684 _____ C:\Windows\PFRO.log 2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-06 15:30 - 2013-11-25 16:34 - 00000000 ____D C:\ProgramData\AVAST Software 2014-01-06 15:27 - 2012-04-20 22:45 - 00000000 ___RD C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-06 15:24 - 2013-01-20 02:32 - 00000000 ____D C:\Program Files (x86)\Sony 2014-01-06 15:18 - 2014-01-06 15:17 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt 2014-01-06 14:46 - 2012-04-20 22:45 - 00000000 ____D C:\Users\Ozoma 2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2014-01-06 13:46 - 2012-08-16 23:56 - 00029696 _____ C:\Users\Ozoma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-06 12:42 - 2012-04-21 10:44 - 00000000 ____D C:\Users\Ozoma\Desktop\Let's plays und fails 2014-01-05 21:18 - 2013-08-15 19:52 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Mumble 2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url 2014-01-05 16:02 - 2014-01-05 16:01 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar 2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip 2014-01-05 12:49 - 2012-10-01 16:39 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Paint.NET 2014-01-05 12:48 - 2014-01-05 12:47 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar 2014-01-04 23:15 - 2013-12-08 00:51 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update 2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer 2014-01-02 20:42 - 2014-01-02 18:52 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt 2014-01-02 20:14 - 2014-01-02 20:13 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip 2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip 2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip 2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url 2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip 2013-12-31 15:20 - 2013-12-31 15:19 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip 2013-12-31 14:52 - 2013-12-08 00:50 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode 2013-12-31 14:42 - 2013-12-31 14:41 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar 2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip 2013-12-31 04:12 - 2013-12-21 22:09 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime 2013-12-31 04:08 - 2013-12-21 22:10 - 00000050 _____ C:\Users\Ozoma\Desktop\save1 2013-12-31 00:35 - 2013-12-18 21:50 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1 2013-12-30 10:21 - 2013-11-11 06:09 - 00001945 _____ C:\Users\Ozoma\Desktop\Warp 9,975.txt 2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url 2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url 2013-12-23 04:55 - 2013-06-27 19:58 - 00000000 ____D C:\Users\Ozoma\Desktop\JoyToKey_en 2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV 2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4 2013-12-21 04:20 - 2012-05-11 14:51 - 00000000 ____D C:\Users\Ozoma\Documents\StarCraft II 2013-12-20 21:16 - 2012-04-20 22:44 - 00407840 _____ C:\Windows\DirectX.log 2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url 2013-12-20 07:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-19 15:42 - 2012-05-23 10:35 - 00002884 _____ C:\Users\Ozoma\Desktop\Tag.txt 2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg 2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg 2013-12-18 21:50 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplit 2013-12-18 18:58 - 2013-11-25 15:29 - 00001467 _____ C:\Users\Ozoma\Desktop\ComboFix - Verknüpfung.lnk 2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip 2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url 2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk 2013-12-15 22:49 - 2012-04-18 06:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe 2013-12-14 23:26 - 2013-12-14 22:12 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip 2013-12-14 18:43 - 2012-07-08 22:49 - 00007601 _____ C:\Users\Ozoma\AppData\Local\Resmon.ResmonCfg 2013-12-14 03:02 - 2013-09-06 00:05 - 00000000 ____D C:\Windows\system32\MRT 2013-12-14 03:00 - 2012-07-23 16:49 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 14:56 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar 2013-12-12 14:02 - 2011-04-12 08:43 - 05873572 _____ C:\Windows\system32\perfh007.dat 2013-12-12 14:02 - 2011-04-12 08:43 - 01756324 _____ C:\Windows\system32\perfc007.dat 2013-12-12 14:02 - 2009-07-14 06:13 - 00005884 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-12 13:56 - 2009-07-14 05:45 - 04918320 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 16:28 - 2013-12-11 15:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 16:28 - 2013-01-03 23:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 16:28 - 2012-04-21 18:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 12:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-11 03:03 - 2013-12-11 02:59 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe Files to move or delete: ==================== C:\Users\Ozoma\AppData\Roaming\Camdata.ini C:\Users\Ozoma\AppData\Roaming\CamLayout.ini C:\Users\Ozoma\AppData\Roaming\CamShapes.ini C:\Users\Ozoma\AppData\Roaming\CamStudio.Producer.Data.ini Some content of TEMP: ==================== C:\Users\Ozoma\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 15:55 ==================== End Of Log ============================ |
08.01.2014, 08:31 | #4 |
/// the machine /// TB-Ausbilder | Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom SeitenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.01.2014, 15:01 | #5 |
| Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom SeitenCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=12 esets_scanner_update returned -1 esets_gle=12 esets_scanner_update returned -1 esets_gle=12 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=f5c96da94935ef42b00bb4b6d20c77d4 # engine=16559 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-08 01:32:32 # local_time=2014-01-08 02:32:32 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1023 16777215 0 0 0 0 0 0 # compatibility_mode=5893 16776573 100 94 68312 140817802 0 0 # scanned=486697 # found=61 # cleaned=0 # scan_time=8980 sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Doiwneload keepeeRa\2TW6QpDS.dll.vir" sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Downllooad keeper\bOdeIA2.dll.vir" sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\DownloAud. kkEeper\O612R0Wa.dll.vir" sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\DowNNlooad keepper\oOqvgRBUz4.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Savensharee a\UBU6gV_BMo.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\sAvEnshhare u\XlxJ.dll.vir" sh=6C5F221B49AD2693D21EE0528FE6286A410D7517 ft=1 fh=fdf8e68f729f4ef4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\cconttiNiUUetoosaavee\51890f78706ce.dll.vir" sh=6C5F221B49AD2693D21EE0528FE6286A410D7517 ft=1 fh=fdf8e68f729f4ef4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\conetinuetioSaVaee\5189151046e35.dll.vir" sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\DownlOaad keeper\ct.dll.vir" sh=0B9E805077320B0CE1E6620488BD34F1C4D7827E ft=1 fh=c71c00111d2b8c05 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Download keeper\V.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavenshare\v1MKeDC4i.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Saavenshaure!\4rFWvTdOyc.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\sAfe save\IVx_.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Safe savee\GIXbk1.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\safe suaveo\knDMXJW8FJ.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffE save\51cd8a0c24fc5.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffE save\51cd8e76413d4.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffE save\51cd9d4110dc1.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saffee Savoe\51cd671634e49.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\C9pNbcMIma.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\iqqe.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\K3Fw1No8nE.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\KobvF.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saveNShare\wt2wpcGR.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SaVensharei\JhowIhcU.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\savoenshaRe\aqo982hBl2.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\savveNSharE\Grk0gv3w.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\sayfE savee\51e646373678e.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SeaaRCh-NewTaB\lQ8yX.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Searceh-NeawTiab\VhW_.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearcH-NEwwTabo\psIP.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\4v.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51c3211fa3b49.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51c323b1267e7.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd671d72a13.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd7ec006cb0.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd7ed4c2630.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd7ee448708.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd8e7c5d2ff.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51cd921990a5f.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\51e6464288497.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\7U82.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\bU.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\gPzTF.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\I.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\jy.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\kpyb5m6kg.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\Mm1F.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\ObQBXt0WAL.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\rihb1QfH.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\rr.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\SyUR7.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SearchNewTab\wm.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\Seariceh--NewTab\vMGawD6.dll.vir" sh=20338DC859A5652F5661280DC508F4E5B533E76D ft=1 fh=acec80819253f8e4 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\seavensharei\Jt.dll.vir" sh=20E8C9E17A36043AC922703B987C32B9ADE1B9EE ft=1 fh=30b45569e53da363 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SEearcch-NewTaab\dejw9mQdHP.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\soafuE sauve\51c323ab2aeb7.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SSaafe save\51c3211bd4b7e.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SSafe savvee\51cd7eb9837d6.dll.vir" sh=078FB2A3E5DE54C3737A4541242A4725C02C6B9C ft=1 fh=d760d12103e04038 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\SSafe savvee\51cd7ecdeffbc.dll.vir" sh=1BE8D19F044D98320BBB7A0942924735233BCD26 ft=1 fh=1a64171e126b0516 vn="Win64/Agent.BA trojan" ac=I fn="C:\Qoobox\Quarantine\C\Windows\Installer\{52d7caf4-d0aa-4ad1-625a-8ff9241a22be}\U\00000008.@.vir" Code:
ATTFilter Results of screen317's Security Check version 0.99.78 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 JavaFX 2.1.1 Java(TM) 7 Update 5 Java version out of Date! Adobe Flash Player 11.9.900.170 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox 21.0 Firefox out of Date! Google Chrome 31.0.1650.57 Google Chrome 31.0.1650.63 ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014 Ran by Ozoma (administrator) on OZOMA-PC on 08-01-2014 14:58:57 Running from C:\Users\Ozoma\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe () C:\Users\Ozoma\Desktop\Let's plays und fails\zsnesw.exe (Microsoft Corporation) C:\Windows\System32\SndVol.exe (TechSmith Corporation) D:\Camtasia\CamRecorder.exe (TechSmith Corporation) D:\Camtasia\TscHelp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKCU\...\Run: [DAEMON Tools Lite] - D:\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll" Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Ozoma\AppData\Roaming\Mozilla\Firefox\Profiles\xf4j3rjr.default-1389032603445 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afurladvisor@anchorfree.com FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (AdBlock) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (Google Wallet) - C:\Users\Ozoma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Ozoma\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) S4 RemoteAccess; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-07-12] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-31] (DT Soft Ltd) S3 E100B; C:\Windows\System32\DRIVERS\efe5b32e.sys [192256 2009-06-10] (Intel Corporation) R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [46792 2013-07-24] (AnchorFree Inc.) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-08 14:58 - 2014-01-08 14:58 - 00000000 ____D C:\Users\Ozoma\Desktop\FRST-OlderVersion 2014-01-08 14:55 - 2014-01-08 14:55 - 00987410 _____ C:\Users\Ozoma\Desktop\SecurityCheck.exe 2014-01-08 11:59 - 2014-01-08 11:59 - 02347384 _____ (ESET) C:\Users\Ozoma\Downloads\esetsmartinstaller_enu (1).exe 2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe 2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt 2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt 2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT 2014-01-07 13:09 - 2014-01-07 13:10 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe 2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt 2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe 2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware 2014-01-07 12:47 - 2014-01-07 12:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe 2014-01-06 19:47 - 2014-01-08 14:58 - 01932624 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe 2014-01-06 19:47 - 2014-01-07 13:18 - 00053458 _____ C:\Users\Ozoma\Downloads\FRST.txt 2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt 2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox 2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat 2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-06 19:12 - 2014-01-06 19:13 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe 2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-06 15:17 - 2014-01-06 15:18 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt 2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url 2014-01-05 16:01 - 2014-01-05 16:02 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar 2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip 2014-01-05 12:47 - 2014-01-05 12:48 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar 2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer 2014-01-02 20:13 - 2014-01-02 20:14 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip 2014-01-02 18:52 - 2014-01-02 20:42 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt 2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip 2014-01-02 14:50 - 2013-11-15 04:48 - 00336896 _____ C:\Users\Ozoma\Desktop\WSplit.exe 2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip 2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url 2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip 2013-12-31 15:19 - 2013-12-31 15:20 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip 2013-12-31 14:41 - 2013-12-31 14:42 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar 2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip 2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url 2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url 2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV 2013-12-21 22:10 - 2013-12-31 04:08 - 00000050 _____ C:\Users\Ozoma\Desktop\save1 2013-12-21 22:09 - 2013-12-31 04:12 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime 2013-12-21 22:09 - 2013-11-23 09:22 - 147172145 _____ () C:\Users\Ozoma\Desktop\I wanna go the Parallel World.exe 2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4 2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url 2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg 2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg 2013-12-18 21:50 - 2013-12-31 00:35 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1 2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip 2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url 2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk 2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe 2013-12-14 22:12 - 2013-12-14 23:26 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip 2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar 2013-12-12 03:01 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-12 03:01 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-12 03:01 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-12 03:01 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-12 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-12 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-12 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-12 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-12 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-12 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-12 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-12 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-12 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-12 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-12 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-12 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-12 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-12 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-12 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-12 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-12 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-12 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-12 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-12 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-12 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-12 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-12 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-12 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-12 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-12 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-12 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-12 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-12 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-12 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-12 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 15:28 - 2013-12-11 16:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 12:45 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 12:45 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 12:45 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 12:45 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 12:45 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 12:45 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 12:45 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 12:45 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 12:45 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 12:45 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 12:45 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 12:45 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 12:45 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 12:45 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 12:45 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 12:45 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 12:45 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 12:45 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 12:45 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 03:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-11 02:59 - 2013-12-11 03:03 - 00010277 _____ C:\Windows\IE11_main.log ==================== One Month Modified Files and Folders ======= 2014-01-08 14:58 - 2014-01-08 14:58 - 00000000 ____D C:\Users\Ozoma\Desktop\FRST-OlderVersion 2014-01-08 14:58 - 2014-01-06 19:47 - 01932624 _____ (Farbar) C:\Users\Ozoma\Desktop\FRST64.exe 2014-01-08 14:58 - 2013-11-25 14:51 - 00011487 _____ C:\Users\Ozoma\Desktop\FRST.txt 2014-01-08 14:58 - 2013-11-25 14:51 - 00000000 ____D C:\FRST 2014-01-08 14:58 - 2012-04-24 07:18 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Skype 2014-01-08 14:55 - 2014-01-08 14:55 - 00987410 _____ C:\Users\Ozoma\Desktop\SecurityCheck.exe 2014-01-08 14:51 - 2012-08-16 23:56 - 00029696 _____ C:\Users\Ozoma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-08 14:28 - 2013-01-03 23:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-08 14:21 - 2013-05-11 13:54 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-08 13:31 - 2012-04-20 22:40 - 01399449 _____ C:\Windows\WindowsUpdate.log 2014-01-08 12:00 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-08 12:00 - 2009-07-14 05:45 - 00020288 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-08 11:59 - 2014-01-08 11:59 - 02347384 _____ (ESET) C:\Users\Ozoma\Downloads\esetsmartinstaller_enu (1).exe 2014-01-08 11:54 - 2013-04-29 19:53 - 00000000 ____D C:\Users\Ozoma\AppData\Local\LogMeIn Hamachi 2014-01-08 11:53 - 2013-05-11 13:54 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-08 11:53 - 2012-04-18 06:46 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-08 11:53 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-08 11:53 - 2009-07-14 05:51 - 00939670 _____ C:\Windows\setupact.log 2014-01-07 13:31 - 2013-02-19 23:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2014-01-07 13:18 - 2014-01-06 19:47 - 00053458 _____ C:\Users\Ozoma\Downloads\FRST.txt 2014-01-07 13:16 - 2014-01-07 13:16 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Ozoma\Desktop\sc-cleaner.exe 2014-01-07 13:16 - 2014-01-07 13:16 - 00001796 _____ C:\sc-cleaner.txt 2014-01-07 13:15 - 2014-01-07 13:15 - 00032162 _____ C:\Users\Ozoma\Desktop\JRT.txt 2014-01-07 13:10 - 2014-01-07 13:10 - 00000000 ____D C:\Windows\ERUNT 2014-01-07 13:10 - 2014-01-07 13:09 - 01036305 _____ (Thisisu) C:\Users\Ozoma\Desktop\JRT.exe 2014-01-07 13:08 - 2014-01-07 13:08 - 00003993 _____ C:\Users\Ozoma\Desktop\ADWCleanerscan.txt 2014-01-07 13:06 - 2013-11-25 15:24 - 00000000 ____D C:\AdwCleaner 2014-01-07 13:06 - 2013-05-11 13:54 - 00001284 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-07 13:06 - 2013-03-02 11:33 - 00001055 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-01-07 13:06 - 2012-04-20 22:45 - 00001001 _____ C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-07 12:58 - 2014-01-07 12:58 - 01233962 _____ C:\Users\Ozoma\Desktop\adwcleaner (1).exe 2014-01-07 12:48 - 2014-01-07 12:48 - 00000000 ____D C:\Users\Ozoma\Desktop\Malwarebytes' Anti-Malware 2014-01-07 12:48 - 2014-01-07 12:47 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ozoma\Desktop\mbam-setup-1.75.0.1300 (1).exe 2014-01-07 12:48 - 2013-11-25 16:42 - 00000791 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-07 00:53 - 2012-04-20 22:59 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\TS3Client 2014-01-06 19:42 - 2014-01-06 19:42 - 00015608 _____ C:\ComboFix.txt 2014-01-06 19:42 - 2012-07-31 10:22 - 00000000 ____D C:\Qoobox 2014-01-06 19:40 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-06 19:29 - 2014-01-06 19:29 - 00000000 ____D C:\avast! sandbox 2014-01-06 19:17 - 2014-01-06 19:17 - 00000000 _____ C:\autoexec.bat 2014-01-06 19:16 - 2013-11-25 15:28 - 05160001 ____R (Swearware) C:\Users\Ozoma\Downloads\ComboFix.exe 2014-01-06 19:13 - 2014-01-06 19:13 - 00002260 _____ C:\Users\Ozoma\Desktop\SpyHunter.lnk 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\sh4ldr 2014-01-06 19:13 - 2014-01-06 19:13 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-06 19:13 - 2014-01-06 19:12 - 00000000 ____D C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2014-01-06 19:11 - 2014-01-06 19:11 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Ozoma\Downloads\SpyHunter-Installer.exe 2014-01-06 19:03 - 2010-11-21 04:47 - 00907684 _____ C:\Windows\PFRO.log 2014-01-06 15:30 - 2014-01-06 15:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-01-06 15:30 - 2013-11-25 16:34 - 00000000 ____D C:\ProgramData\AVAST Software 2014-01-06 15:27 - 2012-04-20 22:45 - 00000000 ___RD C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-06 15:24 - 2013-01-20 02:32 - 00000000 ____D C:\Program Files (x86)\Sony 2014-01-06 15:18 - 2014-01-06 15:17 - 91412976 _____ (AVAST Software) C:\Users\Ozoma\Downloads\avast_free_antivirus_setup.exe 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\genienext 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\AppData\Local\cache 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 ____D C:\Users\Ozoma\.android 2014-01-06 14:46 - 2014-01-06 14:46 - 00000000 _____ C:\Users\Ozoma\daemonprocess.txt 2014-01-06 14:46 - 2012-04-20 22:45 - 00000000 ____D C:\Users\Ozoma 2014-01-06 14:45 - 2014-01-06 14:45 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop 2014-01-06 12:42 - 2012-04-21 10:44 - 00000000 ____D C:\Users\Ozoma\Desktop\Let's plays und fails 2014-01-05 21:18 - 2013-08-15 19:52 - 00000000 ____D C:\Users\Ozoma\AppData\Roaming\Mumble 2014-01-05 19:36 - 2014-01-05 19:36 - 00000202 _____ C:\Users\Ozoma\Desktop\Eryi's Action.url 2014-01-05 16:02 - 2014-01-05 16:01 - 63332844 _____ C:\Users\Ozoma\Downloads\v. 0.5.rar 2014-01-05 16:00 - 2014-01-05 16:00 - 00215642 _____ C:\Users\Ozoma\Downloads\tMorph.zip 2014-01-05 12:49 - 2012-10-01 16:39 - 00000000 ____D C:\Users\Ozoma\AppData\Local\Paint.NET 2014-01-05 12:48 - 2014-01-05 12:47 - 11182439 _____ C:\Users\Ozoma\Downloads\suprise_download_1_by_gagfan01-d70of0q.rar 2014-01-04 23:15 - 2013-12-08 00:51 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Update 2014-01-02 23:43 - 2014-01-02 23:43 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplitTimer 2014-01-02 20:42 - 2014-01-02 18:52 - 00000091 _____ C:\Users\Ozoma\Desktop\SM64 70Star.txt 2014-01-02 20:14 - 2014-01-02 20:13 - 16277032 _____ C:\Users\Ozoma\Downloads\moriya_1100a.zip 2014-01-02 14:50 - 2014-01-02 14:50 - 00146117 _____ C:\Users\Ozoma\Downloads\WSplit 1.5.2.zip 2014-01-01 13:19 - 2014-01-01 13:19 - 00095665 _____ C:\Users\Ozoma\Downloads\pt_BR.zip 2013-12-31 23:20 - 2013-12-31 23:20 - 00000200 _____ C:\Users\Ozoma\Desktop\Shadowgrounds.url 2013-12-31 15:28 - 2013-12-31 15:28 - 00938490 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Seasons (D, F, E).zip 2013-12-31 15:20 - 2013-12-31 15:19 - 01020607 _____ C:\Users\Ozoma\Downloads\Legend of Zelda, The - Oracle of Ages (D, F, E).zip 2013-12-31 14:52 - 2013-12-08 00:50 - 00000000 ____D C:\Users\Ozoma\Desktop\MegaMan Unlimited Speedrunmode 2013-12-31 14:42 - 2013-12-31 14:41 - 47542730 _____ C:\Users\Ozoma\Downloads\v. 0.4.2.rar 2013-12-31 14:34 - 2013-12-31 14:34 - 08338122 _____ C:\Users\Ozoma\Downloads\WoW_17688-patched_64bit.zip 2013-12-31 04:12 - 2013-12-21 22:09 - 00000024 _____ C:\Users\Ozoma\Desktop\DeathTime 2013-12-31 04:08 - 2013-12-21 22:10 - 00000050 _____ C:\Users\Ozoma\Desktop\save1 2013-12-31 00:35 - 2013-12-18 21:50 - 00000456 _____ C:\Users\Ozoma\Desktop\Megaman Unlimited Speedrun 1 2013-12-30 10:21 - 2013-11-11 06:09 - 00001945 _____ C:\Users\Ozoma\Desktop\Warp 9,975.txt 2013-12-26 22:36 - 2013-12-26 22:36 - 00000202 _____ C:\Users\Ozoma\Desktop\7 Days to Die.url 2013-12-26 17:02 - 2013-12-26 17:02 - 00000199 _____ C:\Users\Ozoma\Desktop\Left 4 Dead 2.url 2013-12-23 04:55 - 2013-06-27 19:58 - 00000000 ____D C:\Users\Ozoma\Desktop\JoyToKey_en 2013-12-23 04:53 - 2013-12-23 04:53 - 00000000 ____D C:\Users\Ozoma\Documents\VVVVVV 2013-12-21 18:22 - 2013-12-21 18:22 - 07471137 _____ C:\Users\Ozoma\Downloads\BloodElfxFleshbeast_V.mp4 2013-12-21 04:20 - 2012-05-11 14:51 - 00000000 ____D C:\Users\Ozoma\Documents\StarCraft II 2013-12-20 21:16 - 2012-04-20 22:44 - 00407840 _____ C:\Windows\DirectX.log 2013-12-20 20:15 - 2013-12-20 20:15 - 00000202 _____ C:\Users\Ozoma\Desktop\Starbound.url 2013-12-20 07:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-19 15:42 - 2012-05-23 10:35 - 00002884 _____ C:\Users\Ozoma\Desktop\Tag.txt 2013-12-19 00:31 - 2013-12-19 00:31 - 00160989 _____ C:\Users\Ozoma\Downloads\dfef536d5aade075c46c26009b77ce80.jpeg 2013-12-19 00:31 - 2013-12-19 00:31 - 00153385 _____ C:\Users\Ozoma\Downloads\a093cb2782a9934ee1eeeadf05688b14.jpeg 2013-12-18 21:50 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Ozoma\AppData\Local\WSplit 2013-12-18 18:58 - 2013-11-25 15:29 - 00001467 _____ C:\Users\Ozoma\Desktop\ComboFix - Verknüpfung.lnk 2013-12-18 00:36 - 2013-12-18 00:36 - 00205935 _____ C:\Users\Ozoma\Downloads\Battle Kid 2 - Mountain of Torment.zip 2013-12-16 19:24 - 2013-12-16 19:24 - 00000201 _____ C:\Users\Ozoma\Desktop\VVVVVV.url 2013-12-15 22:49 - 2013-12-15 22:49 - 00000621 _____ C:\Users\Public\Desktop\Age of Wulin.lnk 2013-12-15 22:49 - 2012-04-18 06:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-15 21:26 - 2013-12-15 21:26 - 00696824 _____ C:\Users\Ozoma\Downloads\Wulin_DE.exe 2013-12-14 23:26 - 2013-12-14 22:12 - 146138520 _____ C:\Users\Ozoma\Desktop\I wanna go the Parallel World.zip 2013-12-14 18:43 - 2012-07-08 22:49 - 00007601 _____ C:\Users\Ozoma\AppData\Local\Resmon.ResmonCfg 2013-12-14 03:02 - 2013-09-06 00:05 - 00000000 ____D C:\Windows\system32\MRT 2013-12-14 03:00 - 2012-07-23 16:49 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 14:56 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-12-12 22:36 - 2013-12-12 22:36 - 00017189 _____ C:\Users\Ozoma\Desktop\SRL Emotes.rar 2013-12-12 14:02 - 2011-04-12 08:43 - 05873572 _____ C:\Windows\system32\perfh007.dat 2013-12-12 14:02 - 2011-04-12 08:43 - 01756324 _____ C:\Windows\system32\perfc007.dat 2013-12-12 14:02 - 2009-07-14 06:13 - 00005884 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-12 13:56 - 2009-07-14 05:45 - 04918320 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 16:28 - 2013-12-11 15:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-11 16:28 - 2013-01-03 23:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-11 16:28 - 2012-04-21 18:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-11 12:35 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-11 03:03 - 2013-12-11 02:59 - 00010277 _____ C:\Windows\IE11_main.log 2013-12-11 03:00 - 2013-12-11 03:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:00 - 2013-12-11 03:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:00 - 2013-12-11 03:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:00 - 2013-12-11 03:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:00 - 2013-12-11 03:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:00 - 2013-12-11 03:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe Files to move or delete: ==================== C:\Users\Ozoma\AppData\Roaming\Camdata.ini C:\Users\Ozoma\AppData\Roaming\CamLayout.ini C:\Users\Ozoma\AppData\Roaming\CamShapes.ini C:\Users\Ozoma\AppData\Roaming\CamStudio.Producer.Data.ini Some content of TEMP: ==================== C:\Users\Ozoma\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 15:55 ==================== End Of Log ============================ Hier die verlangten Logs was Nation Zoom angeht: Beim Starten meiner Internet Browser ist die seite bisher nicht wieder aufgetaucht ich denke das ist ein gutes Zeichen Aber ihr seit der Fachmann ist mein Pc wieder sauber nach den Logs zu urteilen? |
09.01.2014, 11:02 | #6 |
/// the machine /// TB-Ausbilder | Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten Java, Adobe und Firefox updaten. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten |
Themen zu Nach versehentlichem Download öffnen sich im IE Firefox und Google Chrome Nation Zoom Seiten |
adblock, administrator, antivirus, combofix, desktop, firefox, flash player, helper, hotspot, installation, internet browser, mobogenie, mobogenie entfernen, nation zoom, nation zoom entfernen, nationzoom, nationzoom entfernen, plug-in, registry, services.exe, software, spyhunter, spyhunter entfernen, svchost.exe, win32/adware.multiplug.i, win32/adware.multiplug.n, win64/agent.ba, winlogon.exe |