tut mir leid, dass es so lange gedauert hat, aber ich denke ich hab alles hinbekommen
Code:
Alles auswählen Aufklappen ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=3d3be8f04e022043977a176d904d0dab
# engine=17105
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-17 10:31:19
# local_time=2014-02-17 11:31:19 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.2.9200 NT
# compatibility_mode=1799 16775165 100 94 102095 11251037 94756 0
# compatibility_mode=5893 16776574 100 94 12161677 17557572 0 0
# scanned=247267
# found=0
# cleaned=0
# scan_time=26464
Code:
Alles auswählen Aufklappen ATTFilter
Results of screen317's Security Check version 0.99.79
x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Defender
Avira Desktop
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Adobe Reader 10.1.9 Adobe Reader out of Date!
Google Chrome 32.0.1700.107
Google Chrome 32.0.1700.76
````````Process Check: objlist.exe by Laurent````````
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Symantec Norton Online Backup NOBuAgent.exe
Symantec Norton Online Backup NOBuClient.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-02-2014
Ran by Niklas (administrator) on WHITEBEARD on 20-02-2014 20:35:37
Running from C:\Users\Niklas\Desktop
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\WINDOWS\system32\atiesrxx.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\LiveComm.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(Intel Corporation) C:\WINDOWS\system32\igfxext.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
() C:\Users\Niklas\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [Bitcasa] - C:\Program Files\Bitcasa\Bitcasa.exe [3952128 2012-11-27] (Bitcasa, Inc)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2994880 2012-08-15] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2669165515-361187302-876288576-1001\...\Run: [Amazon Cloud Player] - C:\Users\Niklas\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] ()
HKU\S-1-5-21-2669165515-361187302-876288576-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2669165515-361187302-876288576-1001\...\Run: [Overwolf] - C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
HKU\S-1-5-21-2669165515-361187302-876288576-1001\...\MountPoints2: {6376f3a7-5867-11e3-824f-806e6f6e6963} - "D:\autorun.exe" -auto
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1390414372&from=amt&uid=ST500LM012XHN-M500MBB_S2RSJACD143009&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1390414372&from=amt&uid=ST500LM012XHN-M500MBB_S2RSJACD143009
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1390414372&from=amt&uid=ST500LM012XHN-M500MBB_S2RSJACD143009
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1390414372&from=amt&uid=ST500LM012XHN-M500MBB_S2RSJACD143009&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKCU - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL =
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR HomePage: hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP
CHR Extension: (Itachi Uchiha Theme) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\adngiebhcihhngjjhjfchfibhemcabaf [2014-01-22]
CHR Extension: (Google Docs) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-22]
CHR Extension: (Google Drive) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-22]
CHR Extension: (YouTube) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-22]
CHR Extension: (Google-Suche) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-22]
CHR Extension: (Media Player) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\fldgbbflmiajeijipchmdpmebldckcbd [2014-02-10]
CHR Extension: (AdBlock) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-22]
CHR Extension: (Google Wallet) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-22]
CHR Extension: (Google Mail) - C:\Users\Niklas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-22]
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171664 2012-11-05] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1591176 2012-11-30] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 SWUpdateService; C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe [2878152 2012-12-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
R1 cbfs3; C:\windows\system32\drivers\cbfs3.sys [352456 2012-08-06] (EldoS Corporation)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-09] (Corel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R3 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2013-10-25] (Razer, Inc.)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S3 skfiltv; C:\Windows\system32\drivers\skfiltv.sys [24064 2008-08-14] (Creative Technology Ltd.)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-28] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 BTATH_LWFLT; \SystemRoot\system32\DRIVERS\btath_lwflt.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-20 20:35 - 2014-02-20 20:35 - 00015856 _____ () C:\Users\Niklas\Desktop\FRST.txt
2014-02-20 20:35 - 2014-02-20 20:35 - 00000000 ____D () C:\Users\Niklas\Desktop\FRST-OlderVersion
2014-02-20 20:32 - 2014-02-20 20:32 - 00987425 _____ () C:\Users\Niklas\Desktop\SecurityCheck.exe
2014-02-20 17:20 - 2014-02-20 17:20 - 00000000 ___RD () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-02-20 16:10 - 2014-02-20 16:10 - 00000220 _____ () C:\Users\Niklas\Desktop\Garry's Mod.url
2014-02-17 16:08 - 2014-02-17 16:08 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-02-17 16:06 - 2014-02-17 16:06 - 02347384 _____ (ESET) C:\Users\Niklas\Downloads\esetsmartinstaller_enu.exe
2014-02-16 18:00 - 2013-12-09 01:34 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2014-02-16 18:00 - 2013-12-09 01:04 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2014-02-16 18:00 - 2013-11-27 16:34 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2014-02-16 18:00 - 2013-11-27 16:27 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-02-16 18:00 - 2013-11-27 15:00 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-02-16 18:00 - 2013-11-27 14:47 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2014-02-16 18:00 - 2013-11-27 13:02 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys
2014-02-16 18:00 - 2013-11-27 11:54 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-02-16 18:00 - 2013-11-27 11:24 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll
2014-02-16 18:00 - 2013-11-27 11:08 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2014-02-16 18:00 - 2013-11-27 10:46 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll
2014-02-16 18:00 - 2013-11-27 10:41 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2014-02-16 18:00 - 2013-11-27 10:17 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2014-02-16 18:00 - 2013-11-27 10:10 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2014-02-16 18:00 - 2013-11-27 09:58 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2014-02-16 18:00 - 2013-11-27 09:56 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2014-02-16 18:00 - 2013-11-27 05:01 - 00385614 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-02-16 18:00 - 2013-11-26 14:22 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2014-02-16 18:00 - 2013-11-26 14:20 - 02131120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2014-02-16 18:00 - 2013-11-26 14:20 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2014-02-16 18:00 - 2013-11-26 14:20 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2014-02-16 18:00 - 2013-11-26 12:50 - 01371312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2014-02-16 18:00 - 2013-11-26 12:44 - 02142936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2014-02-16 18:00 - 2013-11-26 12:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2014-02-16 18:00 - 2013-11-26 11:13 - 04191232 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-02-16 18:00 - 2013-11-26 10:21 - 18577920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-02-16 18:00 - 2013-11-26 09:28 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2014-02-16 18:00 - 2013-11-25 02:45 - 00142680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2014-02-16 18:00 - 2013-11-25 02:32 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2014-02-16 18:00 - 2013-11-25 00:30 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2014-02-16 18:00 - 2013-11-25 00:28 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2014-02-16 18:00 - 2013-11-23 13:47 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll
2014-02-16 18:00 - 2013-11-23 12:49 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-02-16 18:00 - 2013-11-23 09:19 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-02-16 18:00 - 2013-11-23 08:13 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll
2014-02-16 18:00 - 2013-11-23 08:13 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys
2014-02-16 18:00 - 2013-11-23 08:08 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-02-16 18:00 - 2013-11-23 05:50 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-02-16 18:00 - 2013-11-23 04:57 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2014-02-16 18:00 - 2013-11-23 04:48 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2014-02-16 18:00 - 2013-11-23 04:25 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2014-02-16 18:00 - 2013-11-23 04:25 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2014-02-16 18:00 - 2013-11-23 04:19 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-02-16 18:00 - 2013-11-23 04:15 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-02-16 18:00 - 2013-11-21 07:58 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll
2014-02-16 18:00 - 2013-11-21 07:26 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-02-16 18:00 - 2013-11-16 06:11 - 00764856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-02-16 18:00 - 2013-11-15 19:19 - 00669344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2014-02-16 18:00 - 2013-11-15 15:59 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2014-02-16 18:00 - 2013-11-15 15:25 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2014-02-16 18:00 - 2013-11-15 15:08 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-02-16 18:00 - 2013-11-15 14:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-02-16 18:00 - 2013-11-05 21:12 - 02551128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-02-16 18:00 - 2013-10-31 01:29 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2014-02-16 18:00 - 2013-10-31 00:41 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2014-02-16 15:59 - 2014-02-16 16:01 - 00001752 _____ () C:\sc-cleaner.txt
2014-02-16 15:59 - 2014-02-16 15:59 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Niklas\Desktop\sc-cleaner.exe
2014-02-16 15:55 - 2014-02-16 15:55 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-02-16 15:46 - 2014-02-16 15:51 - 00000000 ____D () C:\AdwCleaner
2014-02-16 15:25 - 2014-02-16 15:25 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Malwarebytes
2014-02-16 15:24 - 2014-02-16 15:24 - 00001121 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-16 15:24 - 2014-02-16 15:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-16 15:24 - 2014-02-16 15:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-16 15:24 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-02-16 15:23 - 2014-02-16 15:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Niklas\Downloads\mbam-setup-1.75.0.1300.exe
2014-02-16 15:23 - 2014-02-16 15:23 - 01166132 _____ () C:\Users\Niklas\Desktop\adwcleaner.exe
2014-02-15 16:29 - 2014-02-15 16:29 - 00000897 _____ () C:\Users\Public\Desktop\osu!.lnk
2014-02-15 16:28 - 2014-02-15 16:29 - 56952904 _____ (ppy Pty. Ltd.) C:\Users\Niklas\Downloads\osu!install.exe
2014-02-15 13:59 - 2014-02-20 20:35 - 00000000 ____D () C:\FRST
2014-02-15 13:59 - 2014-02-15 14:06 - 00038232 _____ () C:\Users\Niklas\Downloads\FRST.txt
2014-02-15 13:58 - 2014-02-20 20:35 - 02153984 _____ (Farbar) C:\Users\Niklas\Desktop\FRST64.exe
2014-02-14 23:00 - 2014-02-15 15:51 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-02-14 22:59 - 2014-02-15 15:46 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Overwolf
2014-02-14 22:59 - 2014-02-15 00:21 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\TS3Client
2014-02-14 22:59 - 2014-02-14 22:59 - 00001174 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-02-14 22:58 - 2014-02-14 22:59 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client
2014-02-14 22:58 - 2014-02-14 22:58 - 30095736 _____ (TeamSpeak Systems GmbH) C:\Users\Niklas\Downloads\TeamSpeak3-Client-win32-3.0.13.1.exe
2014-02-12 16:12 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-02-12 16:12 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-02-12 16:12 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-12 16:12 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-02-12 16:12 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-02-12 16:12 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-02-12 16:12 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-02-12 16:12 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-02-12 16:12 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-12 16:12 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-02-12 16:12 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-02-12 16:12 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-02-12 16:12 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-02-12 16:12 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-12 16:12 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-02-12 16:12 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-02-12 16:12 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-12 16:12 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-02-12 16:12 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-02-12 16:12 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-02-12 16:12 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-02-12 16:12 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-02-12 16:12 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-02-12 16:12 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-12 16:12 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-02-12 16:12 - 2014-01-07 06:00 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2014-02-12 16:12 - 2014-01-07 05:30 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2014-02-12 16:12 - 2013-12-09 01:27 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-02-12 16:12 - 2013-12-09 01:19 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll
2014-02-12 16:12 - 2013-12-09 00:55 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll
2014-02-12 16:12 - 2013-12-09 00:54 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-02-12 16:12 - 2013-11-21 07:42 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2014-02-12 16:12 - 2013-11-21 06:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2014-02-12 16:11 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-12 16:11 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-12 16:11 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-02-12 16:11 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-02-12 16:11 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-02-12 16:11 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-02-12 16:11 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-02-12 16:11 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-12 16:11 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-12 16:11 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-02-12 16:11 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-02-12 16:11 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-02-12 16:11 - 2014-01-09 09:25 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-02-12 16:11 - 2014-01-09 08:59 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-02-12 16:11 - 2014-01-09 08:59 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-02-12 16:11 - 2014-01-09 08:49 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-02-12 16:11 - 2014-01-09 08:44 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-02-12 16:11 - 2014-01-09 08:43 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-02-12 16:11 - 2014-01-09 08:29 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-02-12 16:11 - 2014-01-09 08:28 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-02-12 16:11 - 2014-01-09 08:28 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-02-12 16:11 - 2014-01-09 08:18 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-02-12 16:11 - 2014-01-07 08:03 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2014-02-12 16:11 - 2014-01-07 06:59 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2014-02-12 16:11 - 2014-01-04 21:50 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-02-12 16:11 - 2014-01-04 20:22 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-02-12 16:11 - 2014-01-04 15:30 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-02-12 16:11 - 2014-01-04 15:23 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-02-12 16:11 - 2014-01-04 14:42 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-02-12 16:11 - 2014-01-04 14:40 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-02-12 16:11 - 2014-01-04 14:36 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-02-12 16:11 - 2014-01-04 14:28 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-02-12 16:11 - 2013-12-21 03:10 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms
2014-02-12 16:11 - 2013-12-21 03:10 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms
2014-02-12 16:11 - 2013-12-20 11:10 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-02-12 16:11 - 2013-12-20 07:13 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-02-12 16:11 - 2013-12-09 03:57 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-02-12 16:11 - 2013-12-09 02:51 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-02-10 15:59 - 2014-02-16 15:37 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerV1
2014-02-10 15:59 - 2014-02-10 15:59 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-02-10 15:59 - 2014-02-10 15:59 - 00000092 _____ () C:\extensions.ini
2014-02-10 15:59 - 2014-02-10 15:59 - 00000000 _____ () C:\extensions.sqlite
2014-02-03 17:46 - 2014-02-20 18:29 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-01-26 20:12 - 2014-01-26 20:29 - 00000339 _____ () C:\Users\Niklas\Desktop\Japanisch.txt
2014-01-22 19:14 - 2014-01-22 19:15 - 00000000 ____D () C:\Users\Niklas\Documents\RegistryDr
2014-01-22 19:13 - 2014-02-16 15:39 - 00000000 ____D () C:\ProgramData\WPM
2014-01-22 19:13 - 2014-02-15 15:53 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-01-22 19:13 - 2014-01-22 19:15 - 00000000 ____D () C:\Program Files (x86)\Registry Dr
2014-01-22 19:12 - 2014-02-16 15:37 - 00000000 ____D () C:\Users\Niklas\AppData\Local\genienext
2014-01-22 19:12 - 2014-01-22 19:14 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Mobogenie
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\Documents\Mobogenie
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\AppData\Local\cache
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\.android
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 _____ () C:\Users\Niklas\daemonprocess.txt
2014-01-22 19:11 - 2014-02-05 16:17 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-22 19:11 - 2014-01-22 19:14 - 00000000 ____D () C:\Program Files (x86)\Mobogenie
2014-01-22 15:52 - 2014-02-20 20:07 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-22 15:52 - 2014-02-20 17:20 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-22 15:52 - 2014-02-20 17:19 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-22 15:52 - 2014-02-10 23:02 - 00004104 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-22 15:52 - 2014-02-10 23:02 - 00003868 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-22 15:50 - 2014-01-22 15:51 - 37739976 _____ (Google Inc.) C:\Users\Niklas\Downloads\ChromeStandalone32Setup.exe
2014-01-22 15:43 - 2014-01-22 15:44 - 00008107 _____ () C:\Users\Niklas\Documents\Uninstall Dragon Age Origins.log
==================== One Month Modified Files and Folders =======
2014-02-20 20:36 - 2014-02-20 20:35 - 00015856 _____ () C:\Users\Niklas\Desktop\FRST.txt
2014-02-20 20:35 - 2014-02-20 20:35 - 00000000 ____D () C:\Users\Niklas\Desktop\FRST-OlderVersion
2014-02-20 20:35 - 2014-02-15 13:59 - 00000000 ____D () C:\FRST
2014-02-20 20:35 - 2014-02-15 13:58 - 02153984 _____ (Farbar) C:\Users\Niklas\Desktop\FRST64.exe
2014-02-20 20:32 - 2014-02-20 20:32 - 00987425 _____ () C:\Users\Niklas\Desktop\SecurityCheck.exe
2014-02-20 20:25 - 2013-12-01 15:41 - 00003942 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{89627200-1BB3-48BD-9684-8C8E446AEC51}
2014-02-20 20:20 - 2013-12-28 16:44 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Skype
2014-02-20 20:15 - 2013-01-25 04:10 - 00000360 _____ () C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job
2014-02-20 20:07 - 2014-01-22 15:52 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-20 20:02 - 2013-08-19 15:24 - 00000000 ____D () C:\Users\Niklas\AppData\Local\PMB Files
2014-02-20 20:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-02-20 19:29 - 2014-01-19 12:02 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Battle.net
2014-02-20 18:49 - 2014-01-19 12:02 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-02-20 18:48 - 2013-08-19 15:24 - 00000000 ____D () C:\ProgramData\PMB Files
2014-02-20 18:29 - 2014-02-03 17:46 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-02-20 17:34 - 2013-11-28 21:29 - 01283564 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-20 17:24 - 2013-08-19 14:14 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2669165515-361187302-876288576-1001
2014-02-20 17:23 - 2013-09-30 05:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-02-20 17:23 - 2013-09-30 04:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2014-02-20 17:23 - 2013-09-30 04:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2014-02-20 17:22 - 2013-08-19 15:25 - 00000000 ____D () C:\Users\Niklas\AppData\Local\CrashDumps
2014-02-20 17:21 - 2013-11-28 21:46 - 00000000 __RDO () C:\Users\Niklas\SkyDrive
2014-02-20 17:20 - 2014-02-20 17:20 - 00000000 ___RD () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-02-20 17:20 - 2014-01-22 15:52 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-20 17:19 - 2014-01-22 15:52 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-20 17:19 - 2013-08-19 14:07 - 00000000 ___RD () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-20 17:19 - 2013-08-19 14:07 - 00000000 ___RD () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-20 17:19 - 2013-01-25 03:48 - 00000868 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-02-20 17:16 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-02-20 17:16 - 2013-08-22 15:44 - 03383256 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-02-20 17:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-02-20 17:13 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-02-20 17:13 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism
2014-02-20 17:13 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\Dism
2014-02-20 16:41 - 2013-12-08 22:51 - 00063903 _____ () C:\Users\Niklas\Desktop\NIk.odt
2014-02-20 16:41 - 2013-08-23 18:28 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-02-20 16:10 - 2014-02-20 16:10 - 00000220 _____ () C:\Users\Niklas\Desktop\Garry's Mod.url
2014-02-19 22:30 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-02-19 21:23 - 2013-08-22 15:46 - 00339443 _____ () C:\WINDOWS\setupact.log
2014-02-18 19:42 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-02-18 17:29 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-02-17 18:15 - 2013-11-17 12:13 - 00000142 _____ () C:\Users\Niklas\Desktop\Animes.txt
2014-02-17 16:08 - 2014-02-17 16:08 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-02-17 16:06 - 2014-02-17 16:06 - 02347384 _____ (ESET) C:\Users\Niklas\Downloads\esetsmartinstaller_enu.exe
2014-02-16 16:01 - 2014-02-16 15:59 - 00001752 _____ () C:\sc-cleaner.txt
2014-02-16 15:59 - 2014-02-16 15:59 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Niklas\Desktop\sc-cleaner.exe
2014-02-16 15:59 - 2013-11-28 21:42 - 00001450 _____ () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-16 15:58 - 2013-01-25 03:58 - 00000000 ____D () C:\ProgramData\WinClon
2014-02-16 15:55 - 2014-02-16 15:55 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-02-16 15:51 - 2014-02-16 15:46 - 00000000 ____D () C:\AdwCleaner
2014-02-16 15:39 - 2014-01-22 19:13 - 00000000 ____D () C:\ProgramData\WPM
2014-02-16 15:39 - 2013-09-29 20:04 - 00034688 _____ () C:\WINDOWS\PFRO.log
2014-02-16 15:37 - 2014-02-10 15:59 - 00000000 ____D () C:\Program Files (x86)\MediaPlayerV1
2014-02-16 15:37 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\AppData\Local\genienext
2014-02-16 15:25 - 2014-02-16 15:25 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Malwarebytes
2014-02-16 15:24 - 2014-02-16 15:24 - 00001121 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-16 15:24 - 2014-02-16 15:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-16 15:24 - 2014-02-16 15:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-16 15:23 - 2014-02-16 15:23 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Niklas\Downloads\mbam-setup-1.75.0.1300.exe
2014-02-16 15:23 - 2014-02-16 15:23 - 01166132 _____ () C:\Users\Niklas\Desktop\adwcleaner.exe
2014-02-16 13:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-02-16 13:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-02-16 13:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-02-15 23:17 - 2014-01-05 20:52 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Spotify
2014-02-15 16:29 - 2014-02-15 16:29 - 00000897 _____ () C:\Users\Public\Desktop\osu!.lnk
2014-02-15 16:29 - 2014-02-15 16:28 - 56952904 _____ (ppy Pty. Ltd.) C:\Users\Niklas\Downloads\osu!install.exe
2014-02-15 15:53 - 2014-01-22 19:13 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-02-15 15:51 - 2014-02-14 23:00 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-02-15 15:51 - 2013-10-12 19:59 - 00000000 ____D () C:\Program Files (x86)\RaidCall
2014-02-15 15:48 - 2013-09-28 18:53 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2014-02-15 15:48 - 2013-09-28 18:53 - 00000000 ____D () C:\Program Files\Image-Line
2014-02-15 15:48 - 2013-09-28 18:53 - 00000000 ____D () C:\Program Files (x86)\DSPRobotics
2014-02-15 15:48 - 2013-09-28 18:45 - 00000000 ____D () C:\Program Files (x86)\Image-Line
2014-02-15 15:46 - 2014-02-14 22:59 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Overwolf
2014-02-15 14:06 - 2014-02-15 13:59 - 00038232 _____ () C:\Users\Niklas\Downloads\FRST.txt
2014-02-15 00:21 - 2014-02-14 22:59 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\TS3Client
2014-02-14 22:59 - 2014-02-14 22:59 - 00001174 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-02-14 22:59 - 2014-02-14 22:58 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client
2014-02-14 22:58 - 2014-02-14 22:58 - 30095736 _____ (TeamSpeak Systems GmbH) C:\Users\Niklas\Downloads\TeamSpeak3-Client-win32-3.0.13.1.exe
2014-02-14 19:54 - 2013-08-24 18:47 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Paint.NET
2014-02-13 23:11 - 2013-10-24 21:53 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Mp3tag
2014-02-10 23:02 - 2014-01-22 15:52 - 00004104 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-10 23:02 - 2014-01-22 15:52 - 00003868 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-10 15:59 - 2014-02-10 15:59 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-02-10 15:59 - 2014-02-10 15:59 - 00000092 _____ () C:\extensions.ini
2014-02-10 15:59 - 2014-02-10 15:59 - 00000000 _____ () C:\extensions.sqlite
2014-02-10 15:59 - 2013-08-22 16:36 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
2014-02-10 15:59 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy
2014-02-07 23:37 - 2013-12-01 16:02 - 00000000 ____D () C:\Users\Niklas\Documents\StarCraft II
2014-02-06 17:13 - 2014-01-05 20:53 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Spotify
2014-02-06 13:16 - 2014-02-12 16:11 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-12 16:12 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-12 16:12 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-12 16:12 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-12 16:12 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-12 16:12 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-12 16:11 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-12 16:12 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-02-06 11:49 - 2014-02-12 16:11 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-12 16:12 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-02-06 11:48 - 2014-02-12 16:11 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-02-06 11:38 - 2014-02-12 16:12 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-12 16:12 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-12 16:12 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-12 16:11 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-02-06 11:11 - 2014-02-12 16:11 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-12 16:12 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-12 16:12 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-12 16:12 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-12 16:12 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-12 16:12 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-12 16:12 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-12 16:12 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-02-06 10:47 - 2014-02-12 16:12 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-12 16:12 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-12 16:12 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-02-06 10:25 - 2014-02-12 16:11 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-02-06 10:24 - 2014-02-12 16:11 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-02-06 10:22 - 2014-02-12 16:11 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-12 16:12 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-12 16:12 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-12 16:12 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-12 16:12 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-12 16:11 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-12 16:11 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-12 16:12 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-12 16:11 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-02-05 16:17 - 2014-01-22 19:11 - 00000000 ____D () C:\Users\Niklas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Lollipop
2014-01-30 21:47 - 2013-12-14 12:43 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-01-30 21:47 - 2013-12-14 12:43 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-26 20:29 - 2014-01-26 20:12 - 00000339 _____ () C:\Users\Niklas\Desktop\Japanisch.txt
2014-01-24 18:06 - 2013-12-01 16:02 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-01-24 07:14 - 2013-10-13 18:15 - 00000000 ____D () C:\Users\Niklas\Documents\Schule
2014-01-22 19:17 - 2013-11-28 21:06 - 00000000 ____D () C:\Users\Niklas
2014-01-22 19:15 - 2014-01-22 19:14 - 00000000 ____D () C:\Users\Niklas\Documents\RegistryDr
2014-01-22 19:15 - 2014-01-22 19:13 - 00000000 ____D () C:\Program Files (x86)\Registry Dr
2014-01-22 19:15 - 2013-08-19 15:27 - 00000000 __SHD () C:\WINDOWS\SysWOW64\AI_RecycleBin
2014-01-22 19:14 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Mobogenie
2014-01-22 19:14 - 2014-01-22 19:11 - 00000000 ____D () C:\Program Files (x86)\Mobogenie
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\Documents\Mobogenie
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\AppData\Local\cache
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 ____D () C:\Users\Niklas\.android
2014-01-22 19:12 - 2014-01-22 19:12 - 00000000 _____ () C:\Users\Niklas\daemonprocess.txt
2014-01-22 15:52 - 2013-08-19 14:14 - 00000000 ____D () C:\Program Files (x86)\Google
2014-01-22 15:52 - 2013-08-19 14:13 - 00000000 ____D () C:\Users\Niklas\AppData\Local\Google
2014-01-22 15:51 - 2014-01-22 15:50 - 37739976 _____ (Google Inc.) C:\Users\Niklas\Downloads\ChromeStandalone32Setup.exe
2014-01-22 15:44 - 2014-01-22 15:43 - 00008107 _____ () C:\Users\Niklas\Documents\Uninstall Dragon Age Origins.log
2014-01-22 15:42 - 2013-12-26 01:16 - 00000397 _____ () C:\Users\Niklas\Desktop\Neues Textdokument.txt
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
Some content of TEMP:
====================
C:\Users\Niklas\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-16 20:06
==================== End Of Log ============================
--- --- ---